{"slug": "free-coding-agent-with-unlimited-frontier-models", "title": "Free Coding Agent With Unlimited frontier models", "summary": "Free Coding Agent has launched as an open-source, provider-neutral MCP execution layer that gives any MCP-capable frontier model controlled access to files, terminals, Git, language servers, browsers, Windows UI, jobs, checkpoints, tests and diagnostics, with no relay, domain, account, API key, tunnel or backend operated by the project. The tool ships a provider-neutral task kernel for autonomous and multi-agent coding whose durable loop runs task_submit, task_next/task_claim, worker edits, task_ready and task_verify, backed by an append-only fsync'd task journal, idempotency keys, explicit task DAGs, exclusive leaseKey ownership, cross-process journal locking, lease expiry that fails to interrupted rather than faking success, and configurable maximum repair rounds. Installation is a ZIP download, extraction and double-clicking install.cmd, after which the user chooses the folder the agent may access and optionally configures a personal HTTPS endpoint.", "body_md": "**Give frontier AI models real hands on a real developer workstation.**\n\nFree Coding Agent is an open-source, provider-neutral MCP execution layer that turns a capable model from a chat box into a hands-on software engineer. The model supplies the intelligence; Free Coding Agent supplies controlled access to files, terminals, Git, language servers, browsers, Windows UI, jobs, checkpoints, tests, and diagnostics.\n\nLM Arena describes Code Arena as a place to build and compare with frontier AI models. Free Coding Agent is designed to be a compatible execution layer for any host that supports MCP or equivalent remote tools. It is independent software and is not an LM Arena product.\n\nFree Coding Agent does **not** require a relay, domain, account, API key, tunnel, or backend operated by this project.\n\nEvery installation is independent:\n\n- its own local configuration;\n- its own workspace allowlist;\n- its own MCP bearer token;\n- its own HTTP server;\n- its own HTTPS hostname/tunnel when remote access is enabled;\n- its own third-party account, if the user chooses a tunneling provider.\n\nThere is no common Free Coding Agent relay and no common remote credential.\n\n- transactional filesystem reads/writes;\n- atomic multi-file patches and rollback checkpoints;\n- optimistic SHA-256 concurrency protection;\n- shell commands and long-running processes;\n- real PTY / ConPTY for REPLs, debuggers, SSH and TUIs;\n- Git status, diff, history and repository operations;\n- headless LSP diagnostics, definitions, references, hover and symbols;\n- project inspection and project-local memory;\n- Playwright browser automation;\n- optional real-Chrome companion extension;\n- optional VS Code companion extension;\n- Windows UI automation;\n- FFmpeg/media workflows;\n- resource admission to avoid CPU/RAM stampedes;\n- MCP batching and capability discovery;\n- local stdio MCP;\n- authenticated local HTTP MCP;\n- optional personal public HTTPS MCP.\n\nFree Coding Agent includes a provider-neutral task kernel for autonomous and multi-agent coding. It does not call or hardcode a model vendor: any MCP-capable model can act as a worker.\n\nThe durable loop is:\n\n```\ntask_submit\n    ↓\ntask_next / task_claim\n    ↓\nworker edits + targeted checks\n    ↓\ntask_ready\n    ↓\ntask_verify\n   ↙       ↘\nrepairing  succeeded\n   ↓\ntask_claim → repair → task_ready → task_verify\n```\n\nImportant guarantees:\n\n- append-only task journal with fsync;\n- idempotency keys prevent duplicate submissions;\n- dependencies form explicit task DAGs;\n- exclusive `leaseKey` ownership prevents two workers from editing the same worktree at once;\n- cross-process journal locking prevents two MCP processes from racing the same task;\n- lease expiry and dead-owner recovery fail to `interrupted` , never fake success;\n- `task_next` atomically assigns the highest-priority runnable work;\n- verification commands are executed as real processes in the task workspace;\n- tasks can require an independent logical verifier identity distinct from every implementation worker;\n- failed gates create an evidence-backed repair loop;\n- configurable maximum repair rounds prevent infinite retry loops;\n- only `task_verify` can transition verified work to`succeeded` ;\n- task events provide a durable audit trail.\n\nCore tools:\n\n```\ntask_submit\ntask_next\ntask_claim\ntask_heartbeat\ntask_ready\ntask_verify\ntask_update\ntask_reconcile\ntask_contract\ntask_status\ntask_list\ntask_events\ntask_stats\ntask_cancel\n```\n\nThis is the portable agent-control layer: the model may come from OpenCode, an MCP desktop host, an IDE, a self-hosted model, or another compatible client. The task kernel only coordinates ownership, state, evidence and verification.\n\nWorker/verifier IDs are logical identities supplied by the MCP host for coordination and audit; they are not authentication credentials.\n\nThe normal installation flow is:\n\n```\nDownload ZIP\n→ extract\n→ double-click install.cmd\n→ choose the folder the agent may access\n→ optionally configure YOUR personal HTTPS endpoint\n→ Ready\n```\n\nThe installer:\n\n1. verifies Node.js 20+;\n2. can install Node.js LTS when Windows Package Manager is available;\n3. installs `free-coding-agent` globally;\n4. configures the user's own workspace;\n5. runs `free-coding-agent doctor` ;\n6. optionally guides the user through personal HTTPS setup.\n\nThe extracted installer folder can be deleted afterwards.\n\nFor an MCP client running on the same machine, nothing public is needed:\n\n```\n{\n  \"mcpServers\": {\n    \"free-coding-agent\": {\n      \"command\": \"free-coding-agent\",\n      \"args\": [\"stdio\"]\n    }\n  }\n}\n```\n\nNo domain. No TLS. No exposed port. No external service.\n\nFor HTTP clients, Free Coding Agent uses the current MCP **Streamable HTTP** transport at `POST /mcp`. Deprecated legacy HTTP+SSE endpoints are intentionally not exposed in v3.\n\nWhen the model host is remote/cloud-based, it needs a public HTTPS URL that reaches the user's machine.\n\nFree Coding Agent's official remote model is **personal self-configuration**, not a shared relay.\n\nRun:\n\n```\nfree-coding-agent remote setup\n```\n\nThe setup uses the current user's own Tailscale account.\n\nTailscale Funnel gives that machine its own stable HTTPS hostname under the user's tailnet:\n\n```\nhttps://<device>.<tailnet>.ts.net/mcp\n```\n\nFree Coding Agent then:\n\n- generates a strong MCP bearer token locally;\n- keeps the HTTP origin bound to `127.0.0.1` ;\n- exposes it only through that user's Funnel;\n- stores the URL/token only in that user's application-data directory;\n- adds a current-user startup entry for the local HTTP server;\n- prints the exact MCP configuration.\n\nExample output shape:\n\n```\n{\n  \"mcpServers\": {\n    \"free-coding-agent\": {\n      \"url\": \"https://YOUR-PERSONAL-HOST.ts.net/mcp\",\n      \"headers\": {\n        \"Authorization\": \"Bearer YOUR_LOCAL_TOKEN\"\n      }\n    }\n  }\n}\n```\n\nTailscale documents Funnel hostnames as predictable/stable, automatically TLS-protected, and publicly reachable while the user's machine is online.\n\nUsers who own a domain on Cloudflare can use a locally managed named Cloudflare Tunnel instead.\n\nThe ownership model remains the same:\n\n```\ntheir Cloudflare account\n+ their domain\n+ their tunnel\n+ their DNS record\n+ their local MCP token\n```\n\nCloudflare's documented flow is:\n\n```\ncloudflared tunnel login\ncloudflared tunnel create <name>\ncloudflared tunnel route dns <name-or-id> <hostname>\ncloudflared tunnel run <name-or-id>\n```\n\nA named tunnel can also be installed as an OS service. Free Coding Agent does not own or operate it.\n\nBecause the open-source project should keep working independently of its author.\n\nWith personal endpoints:\n\n- no project-operated server can go offline and break everybody;\n- no project operator sees MCP traffic;\n- no shared credential exists;\n- no shared customer/device database exists;\n- no central billing requirement exists;\n- users can replace Tailscale/Cloudflare with another provider;\n- users can self-host everything indefinitely.\n\n```\nfree-coding-agent\nfree-coding-agent stdio\nfree-coding-agent setup\nfree-coding-agent remote setup\nfree-coding-agent remote start\nfree-coding-agent remote status\nfree-coding-agent remote off\nfree-coding-agent doctor\nfree-coding-agent print-config\n```\n\nThe package is structured for public npm installation:\n\n```\nnpm install -g free-coding-agent\nfree-coding-agent setup\n```\n\nThe npm package must exist in the registry before those commands can be used from npm directly.\n\nThe agent can modify files and execute code, so remote exposure must fail closed.\n\nThe personal HTTPS setup enforces:\n\n- a random local `MCP_API_KEY` ;\n- bearer authentication for every remote MCP request;\n- loopback-only local HTTP binding;\n- filesystem allowlisting via `FCA_ALLOWED_ROOTS` ;\n- no anonymous proxy access;\n- no secret committed to Git;\n- no project-wide tunnel or account;\n- no remote credentials shared between users.\n\nA remote URL without the user's bearer token cannot use the agent.\n\nNormal users should use the CLI instead of editing config manually.\n\nImportant variables:\n\n| Variable | Purpose | \n|---|---|\n| `FCA_WORKSPACES` | User's known workspaces | \n| `FCA_DEFAULT_WORKSPACE` | Default workspace | \n| `FCA_ALLOWED_ROOTS` | Filesystem sandbox | \n| `FCA_REMOTE_PROVIDER` | Personal remote provider | \n| `FCA_REMOTE_URL` | User's personal public MCP URL | \n| `FCA_TAILSCALE_DNS_NAME` | User's personal Tailscale DNS name | \n| `MCP_API_KEY` | User's own HTTP bearer token | \n| `MCP_HOST` | Local HTTP bind address | \n| `PORT` | Local HTTP port | \n| `TASKS_DIR` | Durable task journal directory | \n| `TASK_LEASE_TTL_MS` | Worker lease lifetime | \n| `TASK_MAX_ACTIVE` | Maximum simultaneously running task workers | \n| `TASK_MAX_REPAIR_ROUNDS` | Maximum evidence-backed repair rounds | \n| `TASK_VERIFY_TIMEOUT_MS` | Per verification-command timeout | \n| `FCA_CHROME_BRIDGE_ENABLED` | Enable real-Chrome integration | \n| `CHROME_BRIDGE_TOKEN` | Local Chrome pairing secret | \n| `CHROME_EXTENSION_ID` | Optional extension identity pin | \n| `VSCODE_BRIDGE_URL` | Local VS Code companion endpoint | \n\nConfiguration and runtime state live in standard per-user application-data directories, outside the repository.\n\nOpenCode supports both local and remote MCP servers. A personal Free Coding Agent HTTPS endpoint can be configured as a remote MCP server with bearer authentication.\n\nConceptually:\n\n```\n{\n  \"type\": \"remote\",\n  \"url\": \"https://YOUR-PERSONAL-HOST/mcp\",\n  \"oauth\": false,\n  \"headers\": {\n    \"Authorization\": \"Bearer YOUR_LOCAL_TOKEN\"\n  }\n}\n```\n\nUse OpenCode's current configuration schema/documentation for the surrounding config structure.\n\nArena's public documentation describes Agent Mode and Code Arena as environments for agentic coding and frontier-model comparison.\n\nFree Coding Agent does not scrape or automate Arena's private UI/API. If Arena exposes a supported MCP or compatible remote-tool integration, the user's personal HTTPS MCP endpoint is ready for it.\n\nThis distinction is intentional: the open-source agent remains standards-based and does not depend on undocumented consumer-site behavior.\n\nReferences:\n\nThe optional extension gives the local MCP server controlled access to the user's real Chrome.\n\n1. Load `chrome-extension` as an unpacked extension.\n2. Configure a local `CHROME_BRIDGE_TOKEN` .\n3. Enter the same token in the extension popup.\n4. Optionally pin the assigned extension ID.\n\nNo fixed extension identity key is stored in this repository.\n\nThe optional extension exposes loopback-only editor state:\n\n- diagnostics;\n- references;\n- definitions;\n- open files;\n- debugger state.\n\nConfiguration key:\n\n```\nfreeCodingAgent.port\n```\n\nDefault port: `3005`.\n\n```\nnpm install\nnpm run check\nnpm run privacy\nnpm run preflight\nnpm test\n```\n\nThe public source tree intentionally excludes:\n\n- local `.env` files;\n- API keys;\n- tunnel credentials;\n- machine-specific paths;\n- user names and email addresses;\n- conversation archives;\n- browser profiles;\n- screenshots and clips;\n- logs, checkpoints and job state;\n- local memory;\n- fixed Chrome extension identity keys;\n- provider-account-specific orchestration.\n\n`npm run privacy` fails if common secrets, email addresses, absolute Windows paths, or user-home paths appear in publishable source.\n\nISC. See `LICENSE`.", "url": "https://wpnews.pro/news/free-coding-agent-with-unlimited-frontier-models", "canonical_source": "https://github.com/office233/free-coding-agent", "published_at": "2026-10-02 09:53:31+00:00", "updated_at": "2026-10-02 10:06:14.916431+00:00", "lang": "en", "topics": ["ai-agents", "agent-protocols", "developer-tools", "ai-tools", "artificial-intelligence"], "entities": ["Free Coding Agent", "LM Arena", "Code Arena", "OpenCode", "Playwright", "VS Code", "FFmpeg", "Git"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/free-coding-agent-with-unlimited-frontier-models", "markdown": "https://wpnews.pro/news/free-coding-agent-with-unlimited-frontier-models.md", "text": "https://wpnews.pro/news/free-coding-agent-with-unlimited-frontier-models.txt", "jsonld": "https://wpnews.pro/news/free-coding-agent-with-unlimited-frontier-models.jsonld"}}