Head to head · Agent harness · October 2026 research run
Pi vs Kilo Code CLI
Kilo Code CLI scores 75.4 (BB) on agent readiness against Pi's 68.4 (B), and leads in 4 of 7 scored categories. Pi leads on payments & pricing. Both do agent harness.
Which one, for what
Pi B
Good for Developers and pipelines that want a small, scriptable coding agent they can extend in TypeScript and drive over JSONL or RPC, inside their own container.
Ahead on
- Payments & pricing, 60 against 50
Also in its favour
- No key needed to call it
Watch for
No permission system or sandbox. Tool calls run with the user's rights and without an approval prompt
Good for Developers who want an open-source terminal agent with per-tool permission rules, an optional sandbox and a choice of provider, and the same engine in VS Code and JetBrains.
Ahead on
- Reliability, 85 against 75
- Schema & documentation, 90 against 84
- Security & auth, 66 against 61
- Transparency & trust, 76 against 64
Also in its favour
- Agent-ready, a grade of BB or better
- No incidents deducted, where Pi loses 4 points for them
Watch for
Telemetry to PostHog is on by default, and the privacy policy and PRIVACY.md don't mention it
Score by category
| Category | Weight this run | Pi | Kilo Code CLI | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 75 | 85 | Kilo Code CLI +10 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 84 | 90 | Kilo Code CLI +6 |
| Agent ergonomics | 13%16.2 | 76 | 72 | Pi +4 |
| Security & auth | 14%17.5 | 61 | 66 | Kilo Code CLI +5 |
| Payments & pricing | 10%12.5 | 60 | 50 | Pi +10 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 87 | 87 | even |
| Transparency & trust | 7%8.8 | 64 | 76 | Kilo Code CLI +12 |
| Negative events | ≤15 | -4 | 0 | |
| Total | 68.4 · B | 75.4 · BB |
Facts side by side
| Fact | Pi | Kilo Code CLI |
|---|---|---|
| Kind | Agent harness | Agent harness |
| Vendor | Earendil | Kilo Code Inc. |
| Hosted endpoint | no (local only) | no (local only) |
| Transports | ||
| Auth | None | OAuth or key |
| Pricing | Free | Freemium |
| x402 | no | no |
| Licence | MIT | MIT |
| Read-only variant documented | no | no |
| llms.txt | no | yes |
| Last release | 2026-10-07 | 2026-10-07 |
| Terms last updated | no document linked | 2026-09-30 |
| Privacy policy last updated | no document linked | 2026-05-29 |
| Customer content may train models | not found in the text | |
| Terms restrict automated access | yes | |
| Terms restrict benchmarking | not found in the text | |
| Terms or service can change without notice | yes | |
| Arbitration or class-action waiver | yes | |
| Popularity | 113k stars, 5.2M npm/wk | 28k stars, 33k npm/wk |
Verdicts
Pi
Four default tools, a JSONL event stream, an RPC mode and MCP tools kept out of the model's declarations by default keep context small and scripting simple. Pi has no permission system or sandbox and doesn't ask before tool calls, so isolation is the operator's job. Version 1.0.0 is dated 1 October 2026.
Kilo Code CLI
Shell commands ask before running by default, and an optional operating-system sandbox blocks writes outside the workspace and outbound network. Telemetry to PostHog is on by default and the sandbox is off, so an unattended kilo run --auto approves everything not denied unless both are configured first.
Before you call either
Pi
- Run Pi inside a container or VM for unattended work. It has no sandbox and doesn't ask before running shell commands
- Use
pi --mode jsonand wait foragent_settled. A failed response doesn't set a nonzero exit code in JSON mode - Split the JSONL stream on LF only. Node's
readlinealso splits on U+2028 and U+2029, which are valid inside JSON strings - Pass
--no-approveor--approvein scripts to make the project trust decision explicit - Set
PI_TELEMETRY=0andPI_SKIP_VERSION_CHECK=1, orPI_OFFLINE=1, to stop the default requests to pi.dev
Kilo Code CLI
- Set
sandbox.enabledto true in the globalkilo.jsoncbeforekilo run --auto.--autoapproves every permission request not explicitly denied - Set
experimental.openTelemetryto false, orKILO_TELEMETRY_LEVELto a value other thanall, to stop telemetry - Add needed hosts to
sandbox.allowed_hostsin global config. MCP tool calls are unavailable while network restriction is on - Without
--autoa non-interactive run rejects every permission prompt and exits 1 - Put provider keys in global config or the environment.
{env:VAR}in a projectkilo.jsonis ignored
Questions
Which is better for AI agents, Pi or Kilo Code CLI?
Kilo Code CLI scores 75.4 (BB) on agent readiness against Pi's 68.4 (B), and leads in 4 of 7 scored categories. Pi leads on payments & pricing.
Are Pi and Kilo Code CLI open source?
Yes. Pi is open source (MIT). Kilo Code CLI is open source (MIT).
Other comparisons with Pi or Kilo Code CLI
- Aider vs Pi
- Aider vs Kilo Code CLI
- Amp vs Pi
- Amp vs Kilo Code CLI
- Claude Code vs Pi
- Claude Code vs Kilo Code CLI
- Cline vs Pi
- Cline vs Kilo Code CLI
- Cursor CLI vs Pi
- Cursor CLI vs Kilo Code CLI
- Devin vs Pi
- Devin vs Kilo Code CLI
- Pi vs Gemini CLI
- Pi vs GitHub Copilot CLI
- Pi vs goose
- Pi vs Kiro CLI
- Pi vs OpenAI Codex
- Pi vs OpenCode
- Pi vs OpenHands
- Pi vs Prime Agent
- Pi vs Qwen Code
- Gemini CLI vs Kilo Code CLI
- GitHub Copilot CLI vs Kilo Code CLI
- goose vs Kilo Code CLI
- Kilo Code CLI vs Kiro CLI
- Kilo Code CLI vs OpenAI Codex
- Kilo Code CLI vs OpenCode
- Kilo Code CLI vs OpenHands
- Kilo Code CLI vs Prime Agent
- Kilo Code CLI vs Qwen Code
- Kilo Code CLI vs Paperclip
Machine-readable
- This page as Markdown
/compare/earendil-pi-vs-kilo-code-cli.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/earendil-pi.json·/api/v1/tools/kilo-code-cli.json - From a terminal
anchor compare earendil-pi kilo-code-cli(the CLI) - Over MCP
compare_tools {"a": "earendil-pi", "b": "kilo-code-cli"}at/mcp, no key