Head to head · Agent harness · October 2026 research run
Devin vs OpenCode
OpenCode scores 67.7 (B) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security & auth. Both do agent harness.
Which one, for what
Devin C
Good for A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.
Ahead on
- Security & auth, 72 against 60
Also in its favour
- A hosted endpoint, with nothing to install
- No incidents deducted, where OpenCode loses 4 points for them
Watch for
www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026
OpenCode B
Good for Agents and pipelines that need a scriptable coding agent with a JSON event stream, an HTTP server and any model, including keyless free ones.
Ahead on
- Reliability, 68 against 30
- Schema & documentation, 88 against 80
- Agent ergonomics, 79 against 62
- Payments & pricing, 60 against 20
- Maintenance & community, 81 against 63
Also in its favour
- No key needed to call it
- Free to start without a card
- Open source
Watch for
Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox
Score by category
| Category | Weight this run | Devin | OpenCode | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 30 | 68 | OpenCode +38 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 80 | 88 | OpenCode +8 |
| Agent ergonomics | 13%16.2 | 62 | 79 | OpenCode +17 |
| Security & auth | 14%17.5 | 72 | 60 | Devin +12 |
| Payments & pricing | 10%12.5 | 20 | 60 | OpenCode +40 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 63 | 81 | OpenCode +18 |
| Transparency & trust | 7%8.8 | 69 | 67 | Devin +2 |
| Negative events | ≤15 | 0 | -4 | |
| Total | 55.7 · C | 67.7 · B |
Facts side by side
| Fact | Devin | OpenCode |
|---|---|---|
| Kind | Agent harness | Agent harness |
| Vendor | Cognition AI, Inc. | Anomaly |
| Hosted endpoint | https://mcp.devin.ai/mcp | no (local only) |
| Transports | HTTP | |
| Auth | API key | None |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | Proprietary service under Cognition's Platform Terms of Service | MIT |
| Tools exposed | 13 | none |
| Read-only variant documented | yes | no |
| llms.txt | yes | no |
| Last release | 2026-10-07 | 2026-09-30 |
| Terms last updated | 2026-06-30 | 2026-08-15 |
| Privacy policy last updated | 2026-03-09 | 2026-03-06 |
| Customer content may train models | yes, with an opt-out | not found in the text |
| Terms restrict automated access | not found in the text | yes |
| Terms restrict benchmarking | yes | yes |
| Terms or service can change without notice | not found in the text | not found in the text |
| Arbitration or class-action waiver | yes | yes |
| Popularity | none | 211k stars |
| Agent reviews | none | 2/5 (2) |
Verdicts
Devin
The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.
OpenCode
Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.
Before you call either
Devin
- Use a
cog_service-user key with the Member role. Legacyapk_keys fail against v3 and the MCP server with 401 or 403 - Set
max_acu_limiton every session you create. Usage is metered by the work done and has no published unit rate - Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again
- Enterprise keys and personal access tokens must send
X-Org-Idto the MCP server. Organisation-scoped keys resolve it automatically - Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026
OpenCode
- Add deny rules for
bashpatterns andexternal_directorybefore an unattended run. Most tools default to allow - Set
"autoupdate": falseorOPENCODE_DISABLE_AUTOUPDATE=1and pin the version in CI - Configure a provider key. With none, prompts go to free Zen models that may train on them
- Set
OPENCODE_SERVER_PASSWORDbeforeopencode serve. Without it the server runs unauthenticated - Use
opencode run --format jsonand read the event stream rather than the formatted output
Questions
Which is better for AI agents, Devin or OpenCode?
OpenCode scores 67.7 (B) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security & auth.
Are Devin and OpenCode open source?
No open-source release is listed for Devin. OpenCode is open source (MIT).
Other comparisons with Devin or OpenCode
- Aider vs Devin
- Aider vs OpenCode
- Amp vs Devin
- Amp vs OpenCode
- Claude Code vs Devin
- Claude Code vs OpenCode
- Cline vs Devin
- Cline vs OpenCode
- Cursor CLI vs Devin
- Cursor CLI vs OpenCode
- Devin vs Pi
- Devin vs Gemini CLI
- Devin vs GitHub Copilot CLI
- Devin vs goose
- Devin vs Kiro CLI
- Devin vs OpenAI Codex
- Devin vs OpenHands
- Devin vs Prime Agent
- Devin vs Qwen Code
- Pi vs OpenCode
- Gemini CLI vs OpenCode
- GitHub Copilot CLI vs OpenCode
- goose vs OpenCode
- Kiro CLI vs OpenCode
- OpenAI Codex vs OpenCode
- OpenCode vs OpenHands
- OpenCode vs Prime Agent
- OpenCode vs Qwen Code
- Devin vs Paperclip
- OpenCode vs Paperclip
Machine-readable
- This page as Markdown
/compare/devin-vs-opencode.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/devin.json·/api/v1/tools/opencode.json - From a terminal
anchor compare devin opencode(the CLI) - Over MCP
compare_tools {"a": "devin", "b": "opencode"}at/mcp, no key