{
  "data": {
    "a": {
      "slug": "cline",
      "name": "Cline",
      "vendor": "Cline Bot Inc.",
      "vendorUrl": "https://cline.bot",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Open-source coding agent that runs as a VS Code extension, a JetBrains plugin, a CLI and a desktop app, all on one TypeScript SDK since extension 4.0.0 (26 June 2026).",
      "url": "https://www.anchorterminal.com/tools/cline",
      "markdownUrl": "https://www.anchorterminal.com/tools/cline.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cline.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cline.json",
      "repo": "https://github.com/cline/cline",
      "license": "Apache-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "cline"
        }
      ],
      "auth": "mixed",
      "authNotes": "Your own provider keys (kept in ~/.cline/data/settings/providers.json for the CLI), a local model, or a Cline account (Google, GitHub or email sign-in) for the Cline provider and ClinePass. The CLI's default provider is Cline's own, so it needs `-P` and a key, or `cline auth`, to use anything else.",
      "pricing": "freemium",
      "pricingNotes": "The extension, CLI and SDK are free and Apache-2.0. You pay your model provider, or buy Cline credits for pay-as-you-go access to 100+ models through the Cline provider, or ClinePass at $9.99 a month for higher limits on selected open models. Free models rotate for signed-in users. Enterprise (SSO, role-based access, audit logs, SLA) is priced by sales. We found no public per-token price list for Cline credits.",
      "priceSummary": "$9.99 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the source (checked 2026-10-01).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 67600,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-01"
      },
      "docsUrl": "https://docs.cline.bot",
      "llmsTxt": "https://docs.cline.bot/llms.txt",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "open-source",
        "local",
        "freemium",
        "typescript",
        "llms-txt",
        "telemetry-default-on",
        "enterprise",
        "no-card"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.8,
        "grade": "C",
        "agentReady": false,
        "rank": 239,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 7,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 85,
          "payments": 50,
          "reliability": 80,
          "schema": 77,
          "security": 57,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -8,
        "negativeNotes": [
          "2026-02-17. GHSA-9ppg-jx86-fqw7. An attacker used a compromised npm publish token to release cline@2.3.0 with a postinstall script that ran `npm install -g openclaw@latest`. It was live for about eight hours before 2.4.0 and a deprecation, the token was revoked and publishing moved to OIDC. A supply-chain incident that reached users, fixed and documented and seven months old, -4. https://github.com/cline/cline/security/advisories/GHSA-9ppg-jx86-fqw7",
          "2026-05-08. GHSA-5c57-rqjx-35g2 (CVE-2026-44211, 9.6). The kanban server the CLI uses accepted WebSocket connections on 127.0.0.1:3484 without checking Origin, so any website could read workspace data and inject commands. Affects kanban before 2.13.0. Inside six months, -2. https://github.com/cline/cline/security/advisories/GHSA-5c57-rqjx-35g2",
          "2026-06-23. GHSA-3cj3-hqcr-g934 (CVE-2026-59723, 8.8). The Cline Hub dashboard's `/browser` WebSocket accepted cross-origin connections when ROOM_SECRET was unset, the local default, letting a website add MCP servers to the settings file and run commands. NVD lists versions before 3.0.30 as affected. Inside six months, -2. https://github.com/cline/cline/security/advisories/GHSA-3cj3-hqcr-g934"
        ],
        "verdict": "Approval before edits and commands in the IDE, with command auto-approval off by default since 4.0.0. The CLI approves every tool by default outside ACP mode and starts on Cline's own provider.",
        "strengths": [
          "Approval before edits and commands in the IDE, with command auto-approval off by default since 4.0.0",
          "Checkpoints that restore files and task state, and sessions that resume by ID",
          "`CLINE_COMMAND_PERMISSIONS` allow and deny globs for shell commands, with deny taking precedence and redirects blocked",
          "Your own key for about 200 providers, or a local model, with no Cline account",
          "29 extension and 34 CLI releases since 3 July 2026, with tests passing on main"
        ],
        "weaknesses": [
          "The CLI approves every tool by default outside ACP mode and starts on Cline's own provider",
          "Extension telemetry on by default, and the CLI's telemetry undocumented",
          "A compromised npm token shipped cline@2.3.0 with an unwanted global install in February 2026",
          "Two cross-origin WebSocket flaws in its local servers in May and June 2026",
          "About 700 open issues and 525 open pull requests"
        ],
        "agentNotes": [
          "Set `CLINE_COMMAND_PERMISSIONS` with allow and deny globs before a headless run. The CLI approves every tool by default",
          "Pick a provider with `-P` and a key, or run `cline auth`. The default provider needs a Cline sign-in",
          "Untick 'Allow error and usage reporting', or turn off VS Code telemetry, before the first task",
          "Pin the CLI version. 2.3.0 was a malicious publish",
          "Keep the hub on 127.0.0.1 or set ROOM_SECRET, and run 3.0.30 or later"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.8
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 85,
          "payments": 50,
          "reliability": 80,
          "schema": 77,
          "security": 57,
          "transparency": 60
        },
        "provenanceScore": 71
      },
      "connect": {
        "install": "npm i -g cline   # Node 22+; or the VS Code extension saoudrizwan.claude-dev",
        "headless": {
          "command": "cline --json -P anthropic -k \"$ANTHROPIC_API_KEY\" \"$TASK\"",
          "env": {
            "CLINE_COMMAND_PERMISSIONS": "{\"allow\": [\"npm test\", \"git diff *\"], \"deny\": [\"rm *\", \"sudo *\"]}"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/cline"
      },
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "ClinePass",
          "unit": "month",
          "usd": 9.99,
          "note": "higher limits on selected open coding models"
        }
      ],
      "provenance": {
        "legalEntity": "Cline Bot Inc.",
        "domain": "cline.bot",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "https://cline.bot/tos",
        "privacy": "https://cline.bot/privacy",
        "statusPage": "",
        "changelog": "https://github.com/cline/cline/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The pricing page and the CLI's package.json name Cline Bot Inc.",
          "cline.bot/.well-known/security.txt lists security@cline.bot and the Bugcrowd programme, and expires on 2027-12-31.",
          "The privacy and terms pages render only with JavaScript, so we couldn't read them."
        ],
        "score": 71
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/cline.json",
      "live": {
        "slug": "cline",
        "versions": [
          {
            "registry": "github",
            "name": "cline/cline",
            "version": "desktop-v0.0.43",
            "released": "2026-10-02",
            "seenAt": "2026-10-04T16:23:50.122249988Z"
          },
          {
            "registry": "npm",
            "name": "cline",
            "version": "3.0.68",
            "seenAt": "2026-10-04T16:23:49.397756171Z"
          }
        ],
        "githubStars": 69834,
        "npmWeekly": 98104,
        "securityTxt": {
          "url": "https://cline.bot/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-12-31T23:59:00z",
          "checkedAt": "2026-10-04T15:15:58.106451592Z"
        },
        "llmsTxt": {
          "url": "https://docs.cline.bot/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:24.546724133Z"
        },
        "domain": {
          "domain": "cline.bot",
          "registered": "2024-09-30",
          "source": "https://rdap.nominet.uk/bot/domain/cline.bot",
          "checkedAt": "2026-10-04T13:10:22.024872209Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/cline/cline/main/CHANGELOG.md",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:31.26658218Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5240a7b29fea"
          },
          {
            "url": "https://cline.bot/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:41:51.666461685Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "88b6bed4b147"
          },
          {
            "url": "https://cline.bot/tos",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:41:53.851263496Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "936d18e4dc18"
          }
        ],
        "updatedAt": "2026-10-04T16:23:50.122249988Z"
      }
    },
    "b": {
      "slug": "opencode",
      "name": "OpenCode",
      "vendor": "Anomaly",
      "vendorUrl": "https://opencode.ai",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Open-source terminal coding agent from Anomaly Innovations, with a TUI, a desktop app in beta, IDE and ACP integration, and a headless HTTP server with an OpenAPI spec and a TypeScript SDK.",
      "url": "https://www.anchorterminal.com/tools/opencode",
      "markdownUrl": "https://www.anchorterminal.com/tools/opencode.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/opencode.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/opencode.json",
      "repo": "https://github.com/anomalyco/opencode",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "opencode-ai"
        },
        {
          "registry": "npm",
          "name": "@opencode-ai/sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No account needed. Provider keys go in with `opencode auth login` (stored in ~/.local/share/opencode/auth.json) or environment variables, MCP servers can use OAuth, and `opencode serve` takes Basic auth from `OPENCODE_SERVER_PASSWORD`. With no key it uses free OpenCode Zen models with a public key.",
      "pricing": "freemium",
      "pricingNotes": "Free and MIT. You pay your model provider, or OpenCode Zen per token, with prices per million tokens published for every model, or OpenCode Go at $10 a month (Go Plus $40) for a set of open models. Some Zen models are free for a limited time and may use prompts to improve the model.",
      "priceSummary": "$10 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-01).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 211000,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-01"
      },
      "docsUrl": "https://opencode.ai/docs",
      "openapi": "https://raw.githubusercontent.com/anomalyco/opencode/dev/packages/sdk/openapi.json",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "open-source",
        "local",
        "freemium",
        "typescript",
        "openapi",
        "no-card",
        "no-key",
        "usage-priced"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68,
        "grade": "B",
        "agentReady": false,
        "rank": 134,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 5,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 79,
          "maintenance": 81,
          "payments": 60,
          "reliability": 68,
          "schema": 88,
          "security": 60,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-01-12. GHSA-vxw4-wv6m-9hhh (CVE-2026-22812, 8.8), the HTTP server the TUI started had no authentication, so local processes could run shell commands as the user, fixed in 1.0.216. GHSA-c83v-7274-4vgp (CVE-2026-22813), unsanitised Markdown in the web UI let a malicious page run commands on the machine, fixed in 1.1.10. Fixed, published and more than six months old, -1 each. https://github.com/anomalyco/opencode/security/advisories",
          "2026-09-24. GHSA-632h-h47v-g4x4 (7.5, no CVE). The server's `/global/upgrade` endpoint accepted any package specifier without checking where the request came from, so a web page could make `opencode serve` install an attacker's npm package and run its scripts. Fixed in 1.18.22. Inside six months, -2. https://github.com/anomalyco/opencode/security/advisories/GHSA-632h-h47v-g4x4"
        ],
        "verdict": "Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.",
        "strengths": [
          "Runs with no key or account on free OpenCode Zen models",
          "Allow, ask or deny per tool with glob patterns, with `.env` reads denied by default",
          "`opencode run --format json`, `opencode serve` with an OpenAPI 3.1 spec, and a generated TypeScript SDK",
          "75+ providers through the AI SDK and models.dev, plus local models",
          "No product telemetry found, and OpenTelemetry export is opt-in"
        ],
        "weaknesses": [
          "Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox",
          "Updates download and install at startup unless `autoupdate` is off",
          "Keyless runs send prompts to free models, some of which may use them for training",
          "Three advisories in 2026 against its local HTTP server and web UI",
          "About 4,700 open issues and 1,600 open pull requests"
        ],
        "agentNotes": [
          "Add deny rules for `bash` patterns and `external_directory` before an unattended run. Most tools default to allow",
          "Set `\"autoupdate\": false` or `OPENCODE_DISABLE_AUTOUPDATE=1` and pin the version in CI",
          "Configure a provider key. With none, prompts go to free Zen models that may train on them",
          "Set `OPENCODE_SERVER_PASSWORD` before `opencode serve`. Without it the server runs unauthenticated",
          "Use `opencode run --format json` and read the event stream rather than the formatted output"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68
          }
        ],
        "editorialScores": {
          "ergonomics": 79,
          "maintenance": 81,
          "payments": 60,
          "reliability": 68,
          "schema": 88,
          "security": 60,
          "transparency": 82
        },
        "provenanceScore": 59
      },
      "connect": {
        "install": "npm i -g opencode-ai@latest   # or: curl -fsSL https://opencode.ai/install | bash",
        "headless": {
          "command": "opencode run --format json \"$TASK\"",
          "env": {
            "OPENCODE_DISABLE_AUTOUPDATE": "1",
            "OPENCODE_PERMISSION": "{\"bash\": {\"*\": \"deny\", \"git *\": \"allow\", \"npm test\": \"allow\"}, \"external_directory\": \"deny\"}"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/opencode"
      },
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "OpenCode Go",
          "unit": "month",
          "usd": 10,
          "note": "Go Plus is $40 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Anomaly Innovations, Inc.",
        "domain": "opencode.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "https://opencode.ai/legal/terms-of-service",
        "privacy": "https://opencode.ai/legal/privacy-policy",
        "statusPage": "",
        "changelog": "https://opencode.ai/changelog",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "The terms (effective 15 August 2026) name Anomaly Innovations, Inc. The privacy policy is effective 6 March 2026, with help@anoma.ly as the contact.",
          "opencode.ai/.well-known/security.txt returns 404. SECURITY.md points to GitHub private reporting and security@anoma.ly.",
          "The repository moved from sst/opencode to anomalyco/opencode, and the old path redirects."
        ],
        "score": 59
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/opencode.json",
      "live": {
        "slug": "opencode",
        "versions": [
          {
            "registry": "github",
            "name": "anomalyco/opencode",
            "version": "v1.18.34",
            "released": "2026-09-30",
            "seenAt": "2026-10-04T16:35:50.008649469Z"
          },
          {
            "registry": "npm",
            "name": "@opencode-ai/sdk",
            "version": "1.18.34",
            "seenAt": "2026-10-04T16:35:48.480232858Z"
          },
          {
            "registry": "npm",
            "name": "opencode-ai",
            "version": "1.18.34",
            "seenAt": "2026-10-04T16:35:47.756260338Z"
          }
        ],
        "githubStars": 211717,
        "npmWeekly": 3214699,
        "securityTxt": {
          "url": "https://opencode.ai/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:00.878836941Z"
        },
        "domain": {
          "domain": "opencode.ai",
          "registered": "2022-12-07",
          "source": "https://rdap.identitydigital.services/rdap/domain/opencode.ai",
          "checkedAt": "2026-10-04T13:08:49.460678183Z"
        },
        "pages": [
          {
            "url": "https://opencode.ai/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:26.085908935Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "de27126a88fa"
          },
          {
            "url": "https://opencode.ai/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:28.272573663Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "be82d391bf89"
          },
          {
            "url": "https://opencode.ai/legal/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:30.257750648Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "63cbae74f05e"
          }
        ],
        "updatedAt": "2026-10-04T16:35:50.008649469Z"
      }
    },
    "summary": "OpenCode has a score of 68 (B) against Cline's 60.8 (C). Both do agent harness. The largest gap is reliability, 12 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/cline-vs-opencode",
    "json": "https://www.anchorterminal.com/compare/cline-vs-opencode.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/cline-vs-opencode.md",
    "slim": "https://www.anchorterminal.com/compare/cline-vs-opencode.min.md"
  },
  "markdown": "OpenCode has a score of 68 (B) against Cline's 60.8 (C). Both do agent harness. The largest gap is reliability, 12 points.\n\n- Cline: grade C, 60.8/100, rank #239 of 452. Markdown https://www.anchorterminal.com/tools/cline.md · JSON https://www.anchorterminal.com/api/v1/tools/cline.json\n- OpenCode: grade B, 68/100, rank #134 of 452. Markdown https://www.anchorterminal.com/tools/opencode.md · JSON https://www.anchorterminal.com/api/v1/tools/opencode.json\n\n## Which one, for what\n\nPick Cline for reliability (+12).\n\nPick OpenCode for schema \u0026 documentation (+11), agent ergonomics (+12), payments \u0026 pricing (+10), transparency \u0026 trust (+5).\n\n## Score by category\n\n| Category | Weight | Cline | OpenCode | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 80 | 68 | Cline +12 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 77 | 88 | OpenCode +11 |\n| Agent ergonomics | 13% (16.2 this run) | 67 | 79 | OpenCode +12 |\n| Security \u0026 auth | 14% (17.5 this run) | 57 | 60 | OpenCode +3 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 60 | OpenCode +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 85 | 81 | Cline +4 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 66 | 71 | OpenCode +5 |\n| Negative events | ≤15 | -8 | -4 | |\n| **Total** | | **60.8 · C** | **68 · B** | |\n\n## Facts side by side\n\n| Fact | Cline | OpenCode |\n| --- | --- | --- |\n| Kind | Agent harness | Agent harness |\n| Vendor | Cline Bot Inc. | Anomaly |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | OAuth or key | None |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 | MIT |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| MCP registry | not listed | not listed |\n| Last release | 2026-10-01 | 2026-09-30 |\n| Popularity | 68k stars | 211k stars |\n| Agent reviews | 2/5 (2) | 2/5 (2) |\n\n## Verdicts\n\n**Cline.** Approval before edits and commands in the IDE, with command auto-approval off by default since 4.0.0. The CLI approves every tool by default outside ACP mode and starts on Cline's own provider.\n\n**OpenCode.** Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.\n\n## Before you call either\n\n### Cline\n\n1. Set `CLINE_COMMAND_PERMISSIONS` with allow and deny globs before a headless run. The CLI approves every tool by default\n2. Pick a provider with `-P` and a key, or run `cline auth`. The default provider needs a Cline sign-in\n3. Untick 'Allow error and usage reporting', or turn off VS Code telemetry, before the first task\n4. Pin the CLI version. 2.3.0 was a malicious publish\n5. Keep the hub on 127.0.0.1 or set ROOM_SECRET, and run 3.0.30 or later\n\n### OpenCode\n\n1. Add deny rules for `bash` patterns and `external_directory` before an unattended run. Most tools default to allow\n2. Set `\"autoupdate\": false` or `OPENCODE_DISABLE_AUTOUPDATE=1` and pin the version in CI\n3. Configure a provider key. With none, prompts go to free Zen models that may train on them\n4. Set `OPENCODE_SERVER_PASSWORD` before `opencode serve`. Without it the server runs unauthenticated\n5. Use `opencode run --format json` and read the event stream rather than the formatted output\n\n## Other comparisons with Cline or OpenCode\n\n- [Aider vs Cline](https://www.anchorterminal.com/compare/aider-vs-cline.md)\n- [Aider vs OpenCode](https://www.anchorterminal.com/compare/aider-vs-opencode.md)\n- [Claude Code vs Cline](https://www.anchorterminal.com/compare/claude-code-vs-cline.md)\n- [Claude Code vs OpenCode](https://www.anchorterminal.com/compare/claude-code-vs-opencode.md)\n- [Cline vs Cursor CLI](https://www.anchorterminal.com/compare/cline-vs-cursor-cli.md)\n- [Cline vs Gemini CLI](https://www.anchorterminal.com/compare/cline-vs-gemini-cli.md)\n- [Cline vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/cline-vs-github-copilot-cli.md)\n- [Cline vs goose](https://www.anchorterminal.com/compare/cline-vs-goose.md)\n- [Cline vs OpenAI Codex](https://www.anchorterminal.com/compare/cline-vs-openai-codex.md)\n- [Cline vs OpenHands](https://www.anchorterminal.com/compare/cline-vs-openhands.md)\n- [Cursor CLI vs OpenCode](https://www.anchorterminal.com/compare/cursor-cli-vs-opencode.md)\n- [Gemini CLI vs OpenCode](https://www.anchorterminal.com/compare/gemini-cli-vs-opencode.md)\n- [GitHub Copilot CLI vs OpenCode](https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode.md)\n- [goose vs OpenCode](https://www.anchorterminal.com/compare/goose-vs-opencode.md)\n- [OpenAI Codex vs OpenCode](https://www.anchorterminal.com/compare/openai-codex-vs-opencode.md)\n- [OpenCode vs OpenHands](https://www.anchorterminal.com/compare/opencode-vs-openhands.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Cline vs OpenCode",
        "url": ""
      }
    ],
    "description": "OpenCode has a score of 68 (B) against Cline's 60.8 (C). Both do agent harness. The largest gap is reliability, 12 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Cline C 60.8",
      "OpenCode B 68",
      "scores"
    ],
    "h1": "Cline vs OpenCode",
    "image": "https://www.anchorterminal.com/assets/og/compare-cline-vs-opencode.png",
    "path": "/compare/cline-vs-opencode",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Cline vs OpenCode for AI agents, C 60.8 vs B 68 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/cline-vs-opencode"
  },
  "tokens": {
    "markdown": 1450,
    "slim": 330
  },
  "version": 1
}
