{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "qwen-code",
    "name": "Qwen Code",
    "vendor": "Alibaba (Qwen team)",
    "vendorUrl": "https://qwenlm.github.io/qwen-code-docs/en/users/overview/",
    "kind": "harness",
    "category": "agent-harnesses",
    "summary": "Open-source coding agent from Alibaba's Qwen team for the terminal, with desktop, browser and editor interfaces. It runs Qwen, OpenAI, Anthropic and Gemini-compatible models or a local one, and runs headless with `qwen -p`.",
    "url": "https://www.anchorterminal.com/tools/qwen-code",
    "markdownUrl": "https://www.anchorterminal.com/tools/qwen-code.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/qwen-code.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/qwen-code.json",
    "repo": "https://github.com/QwenLM/qwen-code",
    "license": "Apache-2.0",
    "transports": [],
    "packages": [
      {
        "registry": "npm",
        "name": "@qwen-code/qwen-code"
      },
      {
        "registry": "npm",
        "name": "@qwen-code/sdk"
      },
      {
        "registry": "pypi",
        "name": "qwen-code-sdk"
      },
      {
        "registry": "oci",
        "name": "ghcr.io/qwenlm/qwen-code"
      }
    ],
    "auth": "api-key",
    "authNotes": "No account of its own. A model key goes in an environment variable or `~/.qwen/settings.json`, for Alibaba Cloud Model Studio (Coding Plan, Token Plan or a standard key), a listed third-party provider, or any OpenAI, Anthropic or Gemini-compatible endpoint including a local server. Vertex AI credentials also work. The Qwen OAuth sign-in was discontinued on 15 April 2026.",
    "pricing": "free",
    "pricingNotes": "Free and Apache-2.0, with nothing to buy for the CLI. The owner pays the model provider, or nothing with a local model. The Qwen OAuth free tier ended on 15 April 2026. Alibaba Cloud sells a fixed-fee Coding Plan and a usage-billed Token Plan for it, and we couldn't load their price pages on 8 October 2026.",
    "priceSummary": "Free · OSS",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 28362,
      "npmWeekly": 104819,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://qwenlm.github.io/qwen-code-docs/en/users/overview/",
    "llmsTxt": "https://qwenlm.github.io/qwen-code-docs/llms.txt",
    "capabilities": [
      "agent.harness",
      "agent.mcp-client",
      "agent.multi-agent"
    ],
    "tags": [
      "official",
      "harness",
      "coding-agent",
      "cli",
      "open-source",
      "typescript",
      "mcp",
      "llms-txt",
      "telemetry-default-on",
      "pre-1.0",
      "free",
      "no-card",
      "local",
      "docker"
    ],
    "lastRelease": "2026-10-05",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 72.4,
      "grade": "BB",
      "agentReady": true,
      "rank": 88,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 3,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 85,
        "maintenance": 88,
        "payments": 60,
        "reliability": 69,
        "schema": 91,
        "security": 53,
        "transparency": 63
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 69,
          "points": 13.8,
          "reason": "Local-package reading. npm with engines node 22 or newer, Homebrew at 0.25.0 and a standalone installer, with stable, preview and nightly channels (20). Public CI, and of the 15 most recent completed CI runs on main on 8 October, 12 passed, 3 were cancelled and none failed, though two issues opened by automation the same day report a failed end-to-end test and a failed Java SDK job on main (22). 1,402 open issues and 334 open pull requests. The ten newest issues each had labels and one to five comments within the day, much of it from the project's own triage automation (15). The changelog states Keep a Changelog and semver and every release has a Breaking Changes heading, but breaking changes shipped in patch releases 0.23.4 and 0.24.1 (12). 0.25.0, pre-1.0 (0)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 91,
          "points": 14.79,
          "reason": "Framework reading. A settings.schema.json in the repository, a settings reference with the type and default of each key, and an OpenAPI file for the daemon's REST API (25). llms.txt on the docs site lists the pages with a line each, though it links to HTML and the Markdown path we tried returned 404 (8). The approval-mode page says when to use each mode and the sandbox page what each method and Seatbelt profile allows (15). Approval modes, sandbox backends, filesystem and network policies are enums (13). The headless page documents json and stream-json output, and exit codes 41, 42, 44, 52, 53, 55 and 130 are documented (15). A dated changelog generated from releases (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 85,
          "points": 13.81,
          "reason": "Framework reading, adapted to a harness driven by a pipeline. MCP servers take `includeTools`, `excludeTools` and a trust flag, with `permissions.allow`, `ask` and `deny` rules and `--exclude-tools` (20). Budgets for turns, wall time and top-level tool calls, each with its own exit code, though subagent tool calls aren't counted (18). Documented exit codes (18). `--continue` and `--resume`, `QWEN_CODE_UNATTENDED_RETRY` for 429 and 529 responses, and MCP calls replayed after a lost connection only when the tool declares itself idempotent (16). A TypeScript SDK on npm at 0.1.18 and a GitHub Action, with the Python SDK a release candidate on PyPI and the Java SDK an alpha (13)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 53,
          "points": 9.28,
          "reason": "Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. Usage statistics are on by default, documented as tool names, model names, timings and configuration without prompts, responses, file contents or personal information, with a setting and an environment variable to turn them off. Credentials are API keys in environment variables or settings.json (15). Five approval modes with a read-only plan mode and allow, ask and deny rules, but the settings default is Auto, where an LLM classifier approves tool calls, folder trust is disabled by default and sandboxing is opt-in (10). A Linux tool sandbox with `network: closed`, `--safe-mode` and a stderr warning for yolo without a sandbox, but the default macOS Seatbelt profile allows network and we found no guidance on prompt injection in the pages read (7). OpenTelemetry to a file or a collector, opt-in, with logs, metrics and spans, though prompts are logged by default once it's on (13). SECURITY.md gives only an Alibaba Cloud console portal with no response time, the repository has no published advisories, no security.txt was found, and CodeQL and scorecard workflows run in CI (8)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 60,
          "points": 7.5,
          "reason": "Self-hosted rule. No payment protocol (0). The CLI is free under Apache-2.0 with nothing to buy (20). No card or account is needed for the software, and it runs against a local model server (20). An agent can install and run it with no sign-up, given a model endpoint (20). Alibaba Cloud's Coding Plan and Token Plan are separate purchases, and their price pages couldn't be loaded on 8 October 2026."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 88,
          "points": 7.7,
          "reason": "0.25.0 on 5 October 2026 (30). 39 stable releases since 10 July, plus previews and nightlies (20). Issues are labelled and commented on within a day, largely by automation, against 1,402 open issues and 334 open pull requests (17). A TypeScript SDK released on 5 October, with the Python SDK last published to PyPI as a release candidate on 9 May 2026 and the Java SDK an alpha (11). CI, CodeQL, a monthly scorecard and Dependabot (10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 63,
          "points": 5.51,
          "note": "editorial 77, provenance 48",
          "reason": "Apache-2.0 (30). One terms and privacy page maps each sign-in method to the model provider's terms, says the project doesn't train on prompts or code, and lists what usage statistics hold, but gives no retention period, doesn't name the Alibaba Cloud endpoint the statistics go to, and names no legal entity (18). The end of the Qwen OAuth free tier is dated 15 April 2026 and `tools.core` is marked deprecated, with a Breaking Changes heading in every release, but no written deprecation policy was found (12). Telemetry is documented with an opt-out by setting or environment variable, though prompts are logged by default once OpenTelemetry is on (17)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Framework reading, adapted to a harness driven by a pipeline. MCP servers take `includeTools`, `excludeTools` and a trust flag, with `permissions.allow`, `ask` and `deny` rules and `--exclude-tools` (20). Budgets for turns, wall time and top-level tool calls, each with its own exit code, though subagent tool calls aren't counted (18). Documented exit codes (18). `--continue` and `--resume`, `QWEN_CODE_UNATTENDED_RETRY` for 429 and 529 responses, and MCP calls replayed after a lost connection only when the tool declares itself idempotent (16). A TypeScript SDK on npm at 0.1.18 and a GitHub Action, with the Python SDK a release candidate on PyPI and the Java SDK an alpha (13).",
          "maintenance": "0.25.0 on 5 October 2026 (30). 39 stable releases since 10 July, plus previews and nightlies (20). Issues are labelled and commented on within a day, largely by automation, against 1,402 open issues and 334 open pull requests (17). A TypeScript SDK released on 5 October, with the Python SDK last published to PyPI as a release candidate on 9 May 2026 and the Java SDK an alpha (11). CI, CodeQL, a monthly scorecard and Dependabot (10).",
          "payments": "Self-hosted rule. No payment protocol (0). The CLI is free under Apache-2.0 with nothing to buy (20). No card or account is needed for the software, and it runs against a local model server (20). An agent can install and run it with no sign-up, given a model endpoint (20). Alibaba Cloud's Coding Plan and Token Plan are separate purchases, and their price pages couldn't be loaded on 8 October 2026.",
          "reliability": "Local-package reading. npm with engines node 22 or newer, Homebrew at 0.25.0 and a standalone installer, with stable, preview and nightly channels (20). Public CI, and of the 15 most recent completed CI runs on main on 8 October, 12 passed, 3 were cancelled and none failed, though two issues opened by automation the same day report a failed end-to-end test and a failed Java SDK job on main (22). 1,402 open issues and 334 open pull requests. The ten newest issues each had labels and one to five comments within the day, much of it from the project's own triage automation (15). The changelog states Keep a Changelog and semver and every release has a Breaking Changes heading, but breaking changes shipped in patch releases 0.23.4 and 0.24.1 (12). 0.25.0, pre-1.0 (0).",
          "schema": "Framework reading. A settings.schema.json in the repository, a settings reference with the type and default of each key, and an OpenAPI file for the daemon's REST API (25). llms.txt on the docs site lists the pages with a line each, though it links to HTML and the Markdown path we tried returned 404 (8). The approval-mode page says when to use each mode and the sandbox page what each method and Seatbelt profile allows (15). Approval modes, sandbox backends, filesystem and network policies are enums (13). The headless page documents json and stream-json output, and exit codes 41, 42, 44, 52, 53, 55 and 130 are documented (15). A dated changelog generated from releases (15).",
          "security": "Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. Usage statistics are on by default, documented as tool names, model names, timings and configuration without prompts, responses, file contents or personal information, with a setting and an environment variable to turn them off. Credentials are API keys in environment variables or settings.json (15). Five approval modes with a read-only plan mode and allow, ask and deny rules, but the settings default is Auto, where an LLM classifier approves tool calls, folder trust is disabled by default and sandboxing is opt-in (10). A Linux tool sandbox with `network: closed`, `--safe-mode` and a stderr warning for yolo without a sandbox, but the default macOS Seatbelt profile allows network and we found no guidance on prompt injection in the pages read (7). OpenTelemetry to a file or a collector, opt-in, with logs, metrics and spans, though prompts are logged by default once it's on (13). SECURITY.md gives only an Alibaba Cloud console portal with no response time, the repository has no published advisories, no security.txt was found, and CodeQL and scorecard workflows run in CI (8).",
          "transparency": "Apache-2.0 (30). One terms and privacy page maps each sign-in method to the model provider's terms, says the project doesn't train on prompts or code, and lists what usage statistics hold, but gives no retention period, doesn't name the Alibaba Cloud endpoint the statistics go to, and names no legal entity (18). The end of the Qwen OAuth free tier is dated 15 April 2026 and `tools.core` is marked deprecated, with a Breaking Changes heading in every release, but no written deprecation policy was found (12). Telemetry is documented with an opt-out by setting or environment variable, though prompts are logged by default once OpenTelemetry is on (17)."
        },
        "sources": [
          {
            "what": "repository, README, SECURITY.md, CHANGELOG.md, docs and workflows (git clone at 29aef7d)",
            "url": "https://github.com/QwenLM/qwen-code",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog with release dates and Breaking Changes headings",
            "url": "https://github.com/QwenLM/qwen-code/blob/main/CHANGELOG.md",
            "seen": "2026-10-08"
          },
          {
            "what": "npm registry, versions and dates, engines",
            "url": "https://registry.npmjs.org/@qwen-code/qwen-code",
            "seen": "2026-10-08"
          },
          {
            "what": "npm weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/@qwen-code/qwen-code",
            "seen": "2026-10-08"
          },
          {
            "what": "stars, licence and CI runs on main (GitHub API)",
            "url": "https://api.github.com/repos/QwenLM/qwen-code/actions/workflows/ci.yml/runs?branch=main",
            "seen": "2026-10-08"
          },
          {
            "what": "open issues and pull requests",
            "url": "https://github.com/QwenLM/qwen-code/issues",
            "seen": "2026-10-08"
          },
          {
            "what": "repository advisories (none published)",
            "url": "https://github.com/QwenLM/qwen-code/security/advisories",
            "seen": "2026-10-08"
          },
          {
            "what": "settings reference (approval mode default, usage statistics, MCP keys)",
            "url": "https://qwenlm.github.io/qwen-code-docs/en/users/configuration/settings/",
            "seen": "2026-10-08"
          },
          {
            "what": "headless mode, output formats and run budgets",
            "url": "https://qwenlm.github.io/qwen-code-docs/en/users/features/headless/",
            "seen": "2026-10-08"
          },
          {
            "what": "approval modes",
            "url": "https://qwenlm.github.io/qwen-code-docs/en/users/features/approval-mode/",
            "seen": "2026-10-08"
          },
          {
            "what": "sandboxing",
            "url": "https://qwenlm.github.io/qwen-code-docs/en/users/features/sandbox/",
            "seen": "2026-10-08"
          },
          {
            "what": "trusted folders",
            "url": "https://qwenlm.github.io/qwen-code-docs/en/users/configuration/trusted-folders/",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication and the end of the Qwen OAuth free tier",
            "url": "https://qwenlm.github.io/qwen-code-docs/en/users/configuration/auth/",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service and privacy notice",
            "url": "https://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "exit codes",
            "url": "https://qwenlm.github.io/qwen-code-docs/en/users/support/troubleshooting/",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenTelemetry settings",
            "url": "https://github.com/QwenLM/qwen-code/blob/main/docs/developers/development/telemetry.md",
            "seen": "2026-10-08"
          },
          {
            "what": "usage statistics endpoint in source",
            "url": "https://github.com/QwenLM/qwen-code/blob/main/packages/core/src/telemetry/qwen-logger/qwen-logger.ts",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt",
            "url": "https://qwenlm.github.io/qwen-code-docs/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Homebrew formula at 0.25.0",
            "url": "https://formulae.brew.sh/api/formula/qwen-code.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK on PyPI (0.1.0rc0)",
            "url": "https://pypi.org/pypi/qwen-code-sdk/json",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: Alibaba Cloud Coding Plan and Token Plan prices and quotas. alibabacloud.com and help.aliyun.com couldn't be reached from our network on 8 October 2026",
          "unchecked: the Qwen terms of service and privacy policy at qwen.ai, which render only with JavaScript",
          "unchecked: security.txt on alibabacloud.com, and the registration date of any vendor domain",
          "unchecked: how many of the 1,402 open issues are bugs, and how old the oldest are. GitHub's search API refused us for its rate limit",
          "The settings reference gives `auto` as the default approval mode, while the approval-mode page says headless runs default to Ask Permissions. We didn't run it to see which holds",
          "The docs don't name where usage statistics go. The source sends them to gb4w8c3ygj-default-sea.rum.aliyuncs.com",
          "Whether the Java SDK is published to Maven Central wasn't checked",
          "The lead was right on licence, stars (28,362), headless `qwen -p` and MCP. Its docs link was the repository, and the docs site is qwenlm.github.io/qwen-code-docs"
        ]
      },
      "negative": 0,
      "verdict": "Apache-2.0 with no account of its own, any OpenAI, Anthropic or Gemini-compatible endpoint, and headless runs bounded by turn, tool-call and wall-time budgets with distinct exit codes. Out of the box, Auto mode lets an LLM classifier approve tool calls, with the sandbox and folder trust both off. Usage statistics are on by default.",
      "bestFor": "Developers and CI jobs that want an open-source harness tied to no single model vendor, with run budgets and SDKs.",
      "strengths": [
        "Apache-2.0, with CI on main showing 12 passes and 3 cancelled runs in the last 15, none failed",
        "Headless `qwen -p` with json and stream-json output, and exit codes 53 for the turn limit and 55 for a wall-time or tool-call budget",
        "Works with any OpenAI, Anthropic or Gemini-compatible endpoint, including a local server, with keys set by environment variable",
        "39 stable releases in the 90 days to 8 October 2026, each with a Breaking Changes heading in a generated changelog",
        "A Linux tool sandbox (Bubblewrap or Landlock) with `network: closed`, plus Seatbelt, Docker and Podman"
      ],
      "weaknesses": [
        "The default approval mode is Auto, where an LLM classifier approves tool calls, and sandboxing and folder trust are both off by default",
        "Usage statistics are on by default and go to an Alibaba Cloud endpoint that the docs don't name",
        "SECURITY.md points only to an Alibaba Cloud console portal, with no response time, and the repository has no published advisories",
        "Pre-1.0 at 0.25.0, with breaking changes shipped in patch releases such as 0.23.4 and 0.24.1",
        "1,402 open issues and 334 open pull requests on 8 October 2026",
        "The Qwen OAuth free tier ended on 15 April 2026, so every run needs a paid key or a local model"
      ],
      "agentNotes": [
        "Pass `--approval-mode` on every run. The settings default is `auto`, and one docs page says headless runs default to asking, so don't rely on either",
        "Add `--max-session-turns`, `--max-wall-time` and `--max-tool-calls`. All three are unlimited by default. Exit 53 is the turn limit and 55 a budget",
        "`--yolo` doesn't turn on a sandbox. Add `--sandbox`, or on Linux set `tools.executionSandbox` with `network` set to `closed`",
        "Set `QWEN_USAGE_STATISTICS_ENABLED=false` to stop usage statistics",
        "Authenticate with `OPENAI_API_KEY`, `OPENAI_BASE_URL` and `OPENAI_MODEL` in CI. The browser sign-in is discontinued"
      ],
      "metrics": {
        "kind": "local",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "BB",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 72.4
        }
      ],
      "editorialScores": {
        "ergonomics": 85,
        "maintenance": 88,
        "payments": 60,
        "reliability": 69,
        "schema": 91,
        "security": 53,
        "transparency": 77
      },
      "provenanceScore": 48
    },
    "connect": {
      "install": "npm install -g @qwen-code/qwen-code@latest   # or: brew install qwen-code",
      "headless": {
        "command": "qwen -p \"$TASK\" --output-format json --approval-mode auto-edit --max-session-turns 30 --max-wall-time 10m",
        "env": {
          "OPENAI_API_KEY": "\u003ckey\u003e",
          "OPENAI_BASE_URL": "\u003cendpoint\u003e",
          "OPENAI_MODEL": "\u003cmodel\u003e",
          "QWEN_USAGE_STATISTICS_ENABLED": "false"
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/agent.harness",
      "tool": "https://letme.dev/qwen-code"
    },
    "notable": [
      "The default approval mode is `auto`, where an LLM classifier approves or blocks each tool call (https://qwenlm.github.io/qwen-code-docs/en/users/configuration/settings/)",
      "Usage statistics are on by default (`privacy.usageStatisticsEnabled`). The docs say they hold tool names, model names and timings, never prompts, responses or file contents (https://qwenlm.github.io/qwen-code-docs/en/users/configuration/settings/)",
      "The Qwen OAuth free tier was discontinued on 15 April 2026 (https://qwenlm.github.io/qwen-code-docs/en/users/configuration/auth/)",
      "Forked from Google Gemini CLI 0.8.2, and developed independently since Qwen Code 0.1 (https://github.com/QwenLM/qwen-code#acknowledgments)",
      "Folder trust is disabled by default, and sandboxing is opt-in (https://qwenlm.github.io/qwen-code-docs/en/users/configuration/trusted-folders/)"
    ],
    "area": "frameworks",
    "details": [
      {
        "label": "Interfaces",
        "value": "Terminal CLI, desktop app (macOS, Windows, Linux), `qwen serve` daemon and web UI (experimental), VS Code, Zed and JetBrains, chat channels, SDKs for TypeScript, Python and Java"
      },
      {
        "label": "Install",
        "value": "npm (Node 22 or newer), Homebrew, a standalone install script. Stable, preview and nightly channels"
      },
      {
        "label": "Models",
        "value": "Qwen, OpenAI, Anthropic and Gemini protocols. Alibaba Cloud Model Studio, DeepSeek, OpenRouter and other listed providers, Vertex AI, or a custom or local endpoint"
      },
      {
        "label": "Approval modes",
        "value": "plan (read-only), default (ask), auto-edit, auto (LLM classifier, the settings default) and yolo. `permissions.allow`, `ask` and `deny` rules"
      },
      {
        "label": "Sandbox",
        "value": "Off unless enabled. Linux tool sandbox with Bubblewrap or Landlock and `network` open or closed, macOS Seatbelt (default profile permissive-open allows network), Docker or Podman"
      },
      {
        "label": "Folder trust",
        "value": "Disabled by default (`security.folderTrust.enabled`)"
      },
      {
        "label": "MCP client",
        "value": "stdio, SSE and streamable HTTP, OAuth 2.0, per-server `trust`, `includeTools` and `excludeTools`"
      },
      {
        "label": "Headless",
        "value": "`qwen -p` with text, json or stream-json output, `--continue` and `--resume`, `--json-schema`. Exit codes 41, 42, 44, 52, 53 (turn limit), 55 (budget) and 130"
      },
      {
        "label": "Run budgets",
        "value": "`--max-session-turns`, `--max-wall-time` and `--max-tool-calls`, each unlimited by default"
      },
      {
        "label": "Telemetry",
        "value": "Usage statistics on by default, off with `privacy.usageStatisticsEnabled` or `QWEN_USAGE_STATISTICS_ENABLED`. OpenTelemetry off by default, with prompts logged by default once on"
      },
      {
        "label": "CI",
        "value": "GitHub Action qwen-code-action"
      },
      {
        "label": "Releases in 90 days",
        "value": "39 stable (10 July to 8 October 2026)"
      }
    ],
    "provenance": {
      "legalEntity": "Qwen team, Alibaba Group (no legal entity is named in the repository or the docs)",
      "domain": "qwenlm.github.io",
      "domainRegistered": "",
      "endpointOnVendorDomain": null,
      "terms": "https://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/",
      "privacy": "https://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/",
      "statusPage": "",
      "changelog": "https://github.com/QwenLM/qwen-code/blob/main/CHANGELOG.md",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The project's own Terms of Service and Privacy Notice is one page. It covers usage statistics and the Chrome extension, and maps each sign-in method to the model provider's terms and privacy policy. The project publishes no separate privacy policy for the CLI, so both fields point at that page.",
        "The LICENSE file carries Copyright 2025 Google LLC and Copyright 2025 Qwen. The docs describe the project as Alibaba's, and SECURITY.md sends reports to an Alibaba Cloud console portal.",
        "The docs are on GitHub Pages. qwen.ai returned its application page for /.well-known/security.txt, so no security.txt was found. alibabacloud.com couldn't be reached from our network on 8 October 2026.",
        "The qwen.ai terms and privacy pages render only with JavaScript and weren't read."
      ],
      "score": 48,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Qwen team, Alibaba Group (no legal entity is named in the repository or the docs)",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "qwenlm.github.io, no registry record we could read",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "no hosted endpoint",
          "points": 0,
          "max": 0,
          "state": "na"
        },
        {
          "check": "Terms of service",
          "value": "read, states 1 of the 7 things a reader expects",
          "points": 4.9,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 2 of the 8 things a reader expects",
          "points": 5.5,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-10-01",
          "words": 2452,
          "points": 4.9,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated on October 1, 2026",
              "says": "Last updated 2026-10-01"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": false
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": false
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": false
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "A user who signs in with their own API key is subject to the terms and privacy policy of the chosen API provider and not to terms of Qwen Code.",
              "quote": "When using your own API key, you are subject to the terms and privacy policies of your chosen API provider, not Qwen Code’s terms."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-10-01",
          "words": 2452,
          "points": 5.5,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated on October 1, 2026",
              "says": "Last updated 2026-10-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": false
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": false
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "For each authentication method, different Terms of Service and Privacy Notices may apply depending on the underlying service provider."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": false
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": false
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Results from the browser tools may be added to the conversation context and sent to the AI provider configured for the session.",
              "quote": "Qwen Code may include those results in conversation context and transmit them to the AI provider configured for that session."
            },
            {
              "date": "2026-10-08",
              "text": "Any use of data for model training is governed by the policy of the AI provider the user authenticates with.",
              "quote": "Any data usage for training purposes would be governed by the policies of the AI service provider you authenticate with."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/qwen-code.json",
    "live": {
      "slug": "qwen-code",
      "pages": [
        {
          "url": "https://raw.githubusercontent.com/QwenLM/qwen-code/main/CHANGELOG.md",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:23:49.8394153Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "0782fd2dec4a"
        },
        {
          "url": "https://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:23:34.139570921Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "11f3bc6ce7da"
        }
      ],
      "updatedAt": "2026-10-08T18:23:49.8394153Z"
    }
  }
}
