Head to head · Agent harnesses · October 2026 research run

Devin vs Droid CLI

Droid CLI scores 59.1 (C) on agent readiness against Devin's 55.7 (C), and leads in 3 of 7 scored categories. Devin leads on security & auth, payments & pricing and transparency & trust. Both do agent harnesses.

Best agent harnesses and coding agents · All 167 harnesses comparisons

Which one, for what

Devin C

Good for A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.

Ahead on

  • Security & auth, 72 against 63
  • Payments & pricing, 20 against 10
  • Transparency & trust, 69 against 64

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026

Droid CLI C

Good for Teams that want a terminal coding agent with tiered autonomy, command rules and an optional sandbox, and that will pay for a Factory plan.

Ahead on

  • Reliability, 49 against 30
  • Agent ergonomics, 72 against 62
  • Maintenance & community, 79 against 63

Watch for

No free tier or trial was found. Plans start at $20 a month and included usage is stated only as rolling rate limits without numbers

Score by category

CategoryWeight this runDevinDroid CLIEdge
Reliability16%203049Droid CLI +19
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28079Devin +1
Agent ergonomics13%16.26272Droid CLI +10
Security & auth14%17.57263Devin +9
Payments & pricing10%12.52010Devin +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86379Droid CLI +16
Transparency & trust7%8.86964Devin +5
Negative events≤1500
Total55.7 · C59.1 · C

Facts side by side

FactDevinDroid CLI
KindAgent harnessAgent harness
VendorCognition AI, Inc.Factory
Hosted endpointhttps://mcp.devin.ai/mcpno (local only)
TransportsHTTP
AuthAPI keyOAuth or key
PricingFreemiumPaid
x402nono
LicenceProprietary service under Cognition's Platform Terms of ServiceProprietary, under Factory's Terms and Conditions. The droid npm package is marked UNLICENSED and the public repository holds documentation only. The Python SDK is Apache-2.0
Tools exposed13none
Read-only variant documentedyesyes
llms.txtyesyes
Last release2026-10-072026-10-08
Terms last updated2026-06-302026-07-14
Privacy policy last updated2026-03-092026-08-20
Customer content may train modelsyes, with an opt-outnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingyesyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waiveryesyes
Popularitynone49 stars, 7.8k npm/wk

Verdicts

Devin

The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.

Droid CLI

droid exec is read-only unless --auto raises the autonomy level, with command rules, an optional kernel-enforced sandbox, JSON output and documented exit codes. No free tier, status page or security.txt was found, the source is closed, and usage metrics go to Factory by default.

Before you call either

Devin

  1. Use a cog_ service-user key with the Member role. Legacy apk_ keys fail against v3 and the MCP server with 401 or 403
  2. Set max_acu_limit on every session you create. Usage is metered by the work done and has no published unit rate
  3. Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again
  4. Enterprise keys and personal access tokens must send X-Org-Id to the MCP server. Organisation-scoped keys resolve it automatically
  5. Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026

Droid CLI

  1. Set FACTORY_API_KEY (starts fk-) from the API keys page in Factory settings for headless runs. Interactive use signs in through a browser
  2. Start with droid exec and no flags for analysis. Add --auto low for edits and --auto medium for installs, tests and local commits
  3. Use --output-format json and read is_error, num_turns and session_id. Treat a non-zero exit code as failure
  4. Set sandbox.enabled to true before running on untrusted code. In droid exec a sandbox violation is denied without a prompt
  5. Pin the version in CI with npm install -g droid@<version>, or set FACTORY_DROID_AUTO_UPDATE_ENABLED=false on standalone installs, which update themselves

Questions

Which is better for AI agents, Devin or Droid CLI?

Droid CLI scores 59.1 (C) on agent readiness against Devin's 55.7 (C), and leads in 3 of 7 scored categories. Devin leads on security & auth, payments & pricing and transparency & trust.

Other comparisons with Devin or Droid CLI

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.