Head to head · Agent harnesses · October 2026 research run

Droid CLI vs Kiro CLI

Kiro CLI and Droid CLI score within a point of each other on agent readiness, 59.9 (C) and 59.1 (C). Droid CLI leads on agent ergonomics and maintenance & community. Both do agent harnesses.

Best agent harnesses and coding agents · All 167 harnesses comparisons

Which one, for what

Droid CLI C

Good for Teams that want a terminal coding agent with tiered autonomy, command rules and an optional sandbox, and that will pay for a Factory plan.

Ahead on

  • Agent ergonomics, 72 against 67
  • Maintenance & community, 79 against 73

Also in its favour

  • No incidents deducted, where Kiro CLI loses 4 points for them

Watch for

No free tier or trial was found. Plans start at $20 a month and included usage is stated only as rolling rate limits without numbers

Kiro CLI C

Good for Teams on AWS that want one agent configuration across terminal, IDE and web, with central permission policy, prompt logging to their own S3 bucket and IAM Identity Centre sign-in.

Ahead on

  • Reliability, 57 against 49
  • Payments & pricing, 40 against 10

Also in its favour

  • Free to start without a card

Watch for

Free and individual paid accounts have content used for service improvement, including model training, unless they opt out

Score by category

CategoryWeight this runDroid CLIKiro CLIEdge
Reliability16%204957Kiro CLI +8
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27979even
Agent ergonomics13%16.27267Droid CLI +5
Security & auth14%17.56366Kiro CLI +3
Payments & pricing10%12.51040Kiro CLI +30
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87973Droid CLI +6
Transparency & trust7%8.86467Kiro CLI +3
Negative events≤150-4
Total59.1 · C59.9 · C

Facts side by side

FactDroid CLIKiro CLI
KindAgent harnessAgent harness
VendorFactoryAmazon Web Services
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyOAuth or key
PricingPaidFreemium
x402nono
LicenceProprietary, under Factory's Terms and Conditions. The droid npm package is marked UNLICENSED and the public repository holds documentation only. The Python SDK is Apache-2.0Proprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the source
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-10-082026-10-05
Terms last updated2026-07-142026-08-14
Privacy policy last updated2026-08-202026-05-18
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waiveryesyes
Popularity49 stars, 7.8k npm/wk4.4k stars

Verdicts

Droid CLI

droid exec is read-only unless --auto raises the autonomy level, with command rules, an optional kernel-enforced sandbox, JSON output and documented exit codes. No free tier, status page or security.txt was found, the source is closed, and usage metrics go to Factory by default.

Kiro CLI

Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.

Before you call either

Droid CLI

  1. Set FACTORY_API_KEY (starts fk-) from the API keys page in Factory settings for headless runs. Interactive use signs in through a browser
  2. Start with droid exec and no flags for analysis. Add --auto low for edits and --auto medium for installs, tests and local commits
  3. Use --output-format json and read is_error, num_turns and session_id. Treat a non-zero exit code as failure
  4. Set sandbox.enabled to true before running on untrusted code. In droid exec a sandbox violation is denied without a prompt
  5. Pin the version in CI with npm install -g droid@<version>, or set FACTORY_DROID_AUTO_UPDATE_ENABLED=false on standalone installs, which update themselves

Kiro CLI

  1. Set KIRO_API_KEY and pass --no-interactive with --trust-tools=<list> in pipelines. Keep --trust-all-tools for disposable environments
  2. Pass --require-mcp-startup when a run depends on MCP tools. Without it a failed server is logged and the run continues
  3. Pass --no-interactive whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows
  4. Run kiro-cli settings telemetry.enabled false and turn off content collection on Free and individual plans. Both are on by default
  5. Export variables in the shell before starting. Since 2.24.0 a project .env file is no longer loaded into sessions, MCP servers or tools

Questions

Which is better for AI agents, Droid CLI or Kiro CLI?

Kiro CLI and Droid CLI score within a point of each other on agent readiness, 59.9 (C) and 59.1 (C). Droid CLI leads on agent ergonomics and maintenance & community.

Other comparisons with Droid CLI or Kiro CLI

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.