Which login bills what
The CLI decides this, not the plugin, and apiKeySource is the field that tells the truth.
The claude CLI decides this, not the plugin, and the plugin only reports it.
- An OAuth subscription login (
claude auth login) is the normal case: turns run on your Claude plan. The default transport here is headless--print, which is the Agent SDK path, and what that draws from is Anthropic’s policy to set: read the dated note under Billing rather than assuming. The interactive transport drives the real TUI instead and bills as normal plan usage. - An API key in the environment.
ANTHROPIC_API_KEYorANTHROPIC_AUTH_TOKENin the environment that launched opencode reaches the CLI, which prefers it over your subscription login and bills the Platform account pay as you go. This is the one routeignoreAnthropicApiKeycan strip, and the plugin warns at startup whenever it sees one, whatever that option is set to. - An API key the CLI found by itself, from its own
user,projectororgsettings scopes or from anapiKeyHelper. That is the CLI’s configuration rather than opencode’s, so no plugin option removes it. apiKeySourceis the field that tells the truth. The CLI reports it on thesysteminit event of every session, and anything other thanoauth(the subscription) ornonemeans a key is in effect. The plugin warns once per process when that happens. An absentANTHROPIC_API_KEYdoes not prove pay-as-you-go is off, because of the route above;apiKeySourcedoes.- Bedrock and Vertex are the other two things the CLI’s authentication can be, and if it is one of them then neither a Claude subscription nor an Anthropic key is in play for that turn. Fast mode is first-party only, so it is excluded on Bedrock, on Vertex and on Foundry.
With more than one account configured, an account that runs out mid-task ends the turn on a form instead of an error, and the pick is sticky for the limited account until its reset time: see Account failover. The one cost worth knowing before you pick is that the conversation is replayed into a fresh session on the target account, because Claude transcripts live under each account’s own CLAUDE_CONFIG_DIR and --resume cannot cross accounts.
