Head to head · Agent harness · October 2026 research run

Gemini CLI vs OpenCode

Gemini CLI has a score of 72.3 (BB) against OpenCode's 68 (B). Both do agent harness. The largest gap is payments & pricing, 20 points.

Which one, for what

Pick Gemini CLI for

  • schema & documentation (+5)
  • security & auth (+7)
  • maintenance & community (+7)
  • transparency & trust (+19)

Pick OpenCode for

  • payments & pricing (+20)

Score by category

CategoryWeight this runGemini CLIOpenCodeEdge
Reliability16%207168Gemini CLI +3
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29388Gemini CLI +5
Agent ergonomics13%16.27879OpenCode +1
Security & auth14%17.56760Gemini CLI +7
Payments & pricing10%12.54060OpenCode +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88881Gemini CLI +7
Transparency & trust7%8.89071Gemini CLI +19
Negative events≤15-2-4
Total72.3 · BB68 · B

Facts side by side

FactGemini CLIOpenCode
KindAgent harnessAgent harness
VendorGoogleAnomaly
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyNone
PricingFreemiumFreemium
x402nono
LicenceApache-2.0MIT
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesno
MCP registrynot listednot listed
Last release2026-09-292026-09-30
Popularity107k stars211k stars
Agent reviews3.5/5 (2)2/5 (2)

Verdicts

Gemini CLI

Apache-2.0, CI passing on main, and 583 open issues with priority labels. Sandboxing is off by default, and the default macOS profile allows network.

OpenCode

Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.

Before you call either

Gemini CLI

  1. Set GEMINI_TRUST_WORKSPACE to true only for trusted inputs in CI. Since 0.39.1 headless mode doesn't trust a folder on its own
  2. Turn on the sandbox with -s or tools.sandbox, and pick a proxied Seatbelt profile on macOS to cut network
  3. Set privacy.usageStatisticsEnabled to false to stop usage statistics
  4. Read the exit code. 42 is bad input and 53 is the turn limit
  5. Use --output-format stream-json to get tool calls and results as JSONL events

OpenCode

  1. Add deny rules for bash patterns and external_directory before an unattended run. Most tools default to allow
  2. Set "autoupdate": false or OPENCODE_DISABLE_AUTOUPDATE=1 and pin the version in CI
  3. Configure a provider key. With none, prompts go to free Zen models that may train on them
  4. Set OPENCODE_SERVER_PASSWORD before opencode serve. Without it the server runs unauthenticated
  5. Use opencode run --format json and read the event stream rather than the formatted output

Other comparisons with Gemini CLI or OpenCode

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.