Head to head · Agent harness · October 2026 research run

Pi vs Kilo Code CLI

Kilo Code CLI scores 75.4 (BB) on agent readiness against Pi's 68.4 (B), and leads in 4 of 7 scored categories. Pi leads on payments & pricing. Both do agent harness.

Which one, for what

Pi B

Good for Developers and pipelines that want a small, scriptable coding agent they can extend in TypeScript and drive over JSONL or RPC, inside their own container.

Ahead on

  • Payments & pricing, 60 against 50

Also in its favour

  • No key needed to call it

Watch for

No permission system or sandbox. Tool calls run with the user's rights and without an approval prompt

Kilo Code CLI BB

Good for Developers who want an open-source terminal agent with per-tool permission rules, an optional sandbox and a choice of provider, and the same engine in VS Code and JetBrains.

Ahead on

  • Reliability, 85 against 75
  • Schema & documentation, 90 against 84
  • Security & auth, 66 against 61
  • Transparency & trust, 76 against 64

Also in its favour

  • Agent-ready, a grade of BB or better
  • No incidents deducted, where Pi loses 4 points for them

Watch for

Telemetry to PostHog is on by default, and the privacy policy and PRIVACY.md don't mention it

Score by category

CategoryWeight this runPiKilo Code CLIEdge
Reliability16%207585Kilo Code CLI +10
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28490Kilo Code CLI +6
Agent ergonomics13%16.27672Pi +4
Security & auth14%17.56166Kilo Code CLI +5
Payments & pricing10%12.56050Pi +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88787even
Transparency & trust7%8.86476Kilo Code CLI +12
Negative events≤15-40
Total68.4 · B75.4 · BB

Facts side by side

FactPiKilo Code CLI
KindAgent harnessAgent harness
VendorEarendilKilo Code Inc.
Hosted endpointno (local only)no (local only)
Transports
AuthNoneOAuth or key
PricingFreeFreemium
x402nono
LicenceMITMIT
Read-only variant documentednono
llms.txtnoyes
Last release2026-10-072026-10-07
Terms last updatedno document linked2026-09-30
Privacy policy last updatedno document linked2026-05-29
Customer content may train modelsnot found in the text
Terms restrict automated accessyes
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticeyes
Arbitration or class-action waiveryes
Popularity113k stars, 5.2M npm/wk28k stars, 33k npm/wk

Verdicts

Pi

Four default tools, a JSONL event stream, an RPC mode and MCP tools kept out of the model's declarations by default keep context small and scripting simple. Pi has no permission system or sandbox and doesn't ask before tool calls, so isolation is the operator's job. Version 1.0.0 is dated 1 October 2026.

Kilo Code CLI

Shell commands ask before running by default, and an optional operating-system sandbox blocks writes outside the workspace and outbound network. Telemetry to PostHog is on by default and the sandbox is off, so an unattended kilo run --auto approves everything not denied unless both are configured first.

Before you call either

Pi

  1. Run Pi inside a container or VM for unattended work. It has no sandbox and doesn't ask before running shell commands
  2. Use pi --mode json and wait for agent_settled. A failed response doesn't set a nonzero exit code in JSON mode
  3. Split the JSONL stream on LF only. Node's readline also splits on U+2028 and U+2029, which are valid inside JSON strings
  4. Pass --no-approve or --approve in scripts to make the project trust decision explicit
  5. Set PI_TELEMETRY=0 and PI_SKIP_VERSION_CHECK=1, or PI_OFFLINE=1, to stop the default requests to pi.dev

Kilo Code CLI

  1. Set sandbox.enabled to true in the global kilo.jsonc before kilo run --auto. --auto approves every permission request not explicitly denied
  2. Set experimental.openTelemetry to false, or KILO_TELEMETRY_LEVEL to a value other than all, to stop telemetry
  3. Add needed hosts to sandbox.allowed_hosts in global config. MCP tool calls are unavailable while network restriction is on
  4. Without --auto a non-interactive run rejects every permission prompt and exits 1
  5. Put provider keys in global config or the environment. {env:VAR} in a project kilo.json is ignored

Questions

Which is better for AI agents, Pi or Kilo Code CLI?

Kilo Code CLI scores 75.4 (BB) on agent readiness against Pi's 68.4 (B), and leads in 4 of 7 scored categories. Pi leads on payments & pricing.

Are Pi and Kilo Code CLI open source?

Yes. Pi is open source (MIT). Kilo Code CLI is open source (MIT).

Other comparisons with Pi or Kilo Code CLI

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.