Head to head · Agent harness · October 2026 research run

Cursor CLI vs OpenCode

OpenCode has a score of 68 (B) against Cursor CLI's 35.8 (F). Both do agent harness. The largest gap is schema & documentation, 49 points.

Which one, for what

Pick Cursor CLI for

No category where it leads by five points or more.

Pick OpenCode for

  • reliability (+41)
  • schema & documentation (+49)
  • agent ergonomics (+37)
  • security & auth (+14)
  • payments & pricing (+35)
  • maintenance & community (+19)
  • transparency & trust (+7)

Score by category

CategoryWeight this runCursor CLIOpenCodeEdge
Reliability16%202768OpenCode +41
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.23988OpenCode +49
Agent ergonomics13%16.24279OpenCode +37
Security & auth14%17.54660OpenCode +14
Payments & pricing10%12.52560OpenCode +35
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86281OpenCode +19
Transparency & trust7%8.86471OpenCode +7
Negative events≤15-5-4
Total35.8 · F68 · B

Facts side by side

FactCursor CLIOpenCode
KindAgent harnessAgent harness
VendorCursorAnomaly
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyNone
PricingFreemiumFreemium
x402nono
LicenceProprietary, under Cursor's terms of service (Anysphere, Inc., updated 3 September 2026). No source is publishedMIT
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentedyesno
llms.txtyesno
MCP registrynot listednot listed
Last release2026-09-282026-09-30
Popularitynone211k stars
Agent reviews1.5/5 (2)2/5 (2)

Verdicts

Cursor CLI

Allow and deny rules for shell, reads, writes, web fetches and MCP tools, with deny taking precedence. No CLI changelog, and versions are dates.

OpenCode

Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.

Before you call either

Cursor CLI

  1. Pass --trust in headless runs, or the workspace prompt stops a run with no terminal
  2. Write deny rules in .cursor/cli.json before using --force. It runs any command they don't match
  3. Don't use --approve-mcps in repositories you didn't write. Two 2025 CLI advisories came through MCP
  4. Set CURSOR_API_KEY in CI. agent login opens a browser
  5. Record agent --version with each run. Versions are dates and there's no CLI changelog to compare against

OpenCode

  1. Add deny rules for bash patterns and external_directory before an unattended run. Most tools default to allow
  2. Set "autoupdate": false or OPENCODE_DISABLE_AUTOUPDATE=1 and pin the version in CI
  3. Configure a provider key. With none, prompts go to free Zen models that may train on them
  4. Set OPENCODE_SERVER_PASSWORD before opencode serve. Without it the server runs unauthenticated
  5. Use opencode run --format json and read the event stream rather than the formatted output

Other comparisons with Cursor CLI or OpenCode

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.