Head to head · Agent harnesses · October 2026 research run

Droid CLI vs Qwen Code

Qwen Code scores 72.4 (BB) on agent readiness against Droid CLI's 59.1 (C), and leads in 5 of 7 scored categories. Droid CLI leads on security & auth. Both do agent harnesses.

Best agent harnesses and coding agents · All 167 harnesses comparisons

Which one, for what

Droid CLI C

Good for Teams that want a terminal coding agent with tiered autonomy, command rules and an optional sandbox, and that will pay for a Factory plan.

Ahead on

  • Security & auth, 63 against 53

Watch for

No free tier or trial was found. Plans start at $20 a month and included usage is stated only as rolling rate limits without numbers

Qwen Code BB

Good for Developers and CI jobs that want an open-source harness tied to no single model vendor, with run budgets and SDKs.

Ahead on

  • Reliability, 69 against 49
  • Schema & documentation, 91 against 79
  • Agent ergonomics, 85 against 72
  • Payments & pricing, 60 against 10
  • Maintenance & community, 88 against 79

Also in its favour

  • Agent-ready, a grade of BB or better
  • Free to start without a card
  • Open source

Watch for

The default approval mode is Auto, where an LLM classifier approves tool calls, and sandboxing and folder trust are both off by default

Score by category

CategoryWeight this runDroid CLIQwen CodeEdge
Reliability16%204969Qwen Code +20
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27991Qwen Code +12
Agent ergonomics13%16.27285Qwen Code +13
Security & auth14%17.56353Droid CLI +10
Payments & pricing10%12.51060Qwen Code +50
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87988Qwen Code +9
Transparency & trust7%8.86463Droid CLI +1
Negative events≤1500
Total59.1 · C72.4 · BB

Facts side by side

FactDroid CLIQwen Code
KindAgent harnessAgent harness
VendorFactoryAlibaba (Qwen team)
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyAPI key
PricingPaidFree
x402nono
LicenceProprietary, under Factory's Terms and Conditions. The droid npm package is marked UNLICENSED and the public repository holds documentation only. The Python SDK is Apache-2.0Apache-2.0
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-10-082026-10-05
Terms last updated2026-07-142026-10-01
Privacy policy last updated2026-08-202026-10-01
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waiveryesnot found in the text
Popularity49 stars, 7.8k npm/wk28k stars, 105k npm/wk

Verdicts

Droid CLI

droid exec is read-only unless --auto raises the autonomy level, with command rules, an optional kernel-enforced sandbox, JSON output and documented exit codes. No free tier, status page or security.txt was found, the source is closed, and usage metrics go to Factory by default.

Qwen Code

Apache-2.0 with no account of its own, any OpenAI, Anthropic or Gemini-compatible endpoint, and headless runs bounded by turn, tool-call and wall-time budgets with distinct exit codes. Out of the box, Auto mode lets an LLM classifier approve tool calls, with the sandbox and folder trust both off. Usage statistics are on by default.

Before you call either

Droid CLI

  1. Set FACTORY_API_KEY (starts fk-) from the API keys page in Factory settings for headless runs. Interactive use signs in through a browser
  2. Start with droid exec and no flags for analysis. Add --auto low for edits and --auto medium for installs, tests and local commits
  3. Use --output-format json and read is_error, num_turns and session_id. Treat a non-zero exit code as failure
  4. Set sandbox.enabled to true before running on untrusted code. In droid exec a sandbox violation is denied without a prompt
  5. Pin the version in CI with npm install -g droid@<version>, or set FACTORY_DROID_AUTO_UPDATE_ENABLED=false on standalone installs, which update themselves

Qwen Code

  1. Pass --approval-mode on every run. The settings default is auto, and one docs page says headless runs default to asking, so don't rely on either
  2. Add --max-session-turns, --max-wall-time and --max-tool-calls. All three are unlimited by default. Exit 53 is the turn limit and 55 a budget
  3. --yolo doesn't turn on a sandbox. Add --sandbox, or on Linux set tools.executionSandbox with network set to closed
  4. Set QWEN_USAGE_STATISTICS_ENABLED=false to stop usage statistics
  5. Authenticate with OPENAI_API_KEY, OPENAI_BASE_URL and OPENAI_MODEL in CI. The browser sign-in is discontinued

Questions

Which is better for AI agents, Droid CLI or Qwen Code?

Qwen Code scores 72.4 (BB) on agent readiness against Droid CLI's 59.1 (C), and leads in 5 of 7 scored categories. Droid CLI leads on security & auth.

Are Droid CLI and Qwen Code open source?

No open-source release is listed for Droid CLI. Qwen Code is open source (Apache-2.0).

Other comparisons with Droid CLI or Qwen Code

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.