{
  "data": {
    "a": {
      "slug": "github-copilot-cli",
      "name": "GitHub Copilot CLI",
      "vendor": "GitHub",
      "vendorUrl": "https://github.com/features/copilot/cli",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "GitHub's coding agent for the terminal, built on the same agent harness as Copilot cloud agent (formerly Copilot coding agent), which works in GitHub Actions and opens pull requests.",
      "url": "https://www.anchorterminal.com/tools/github-copilot-cli",
      "markdownUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/github-copilot-cli.json",
      "repo": "https://github.com/github/copilot-cli",
      "license": "Proprietary, under the licence in the repository's `LICENSE.md`. Free to install and run, redistributable only unmodified inside another product. The repository holds the README, changelog and install script, not the source",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@github/copilot"
        }
      ],
      "auth": "mixed",
      "authNotes": "`/login` with a GitHub account, or a fine-grained personal access token with the Copilot Requests permission in `GH_TOKEN` or `GITHUB_TOKEN`. Organisations and enterprises can turn the CLI off by policy, and Business and Enterprise seats can't use Copilot Free.",
      "pricing": "freemium",
      "pricingNotes": "Copilot Free ($0, no card) includes the CLI and agent mode with 50 chat requests a month. Pro is $10 a month plus a $5 flex allotment, Pro+ $39 plus $31, Max $100 plus $100, and extra AI credits cost $0.01 each. Business and Enterprise prices aren't on the plans page. Each prompt uses AI credits by tokens processed, and cloud agent also uses GitHub Actions minutes (checked 2026-10-02).",
      "priceSummary": "$0.01 / credit",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the plans page or the changelog (checked 2026-10-02).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 11000,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-02"
      },
      "docsUrl": "https://docs.github.com/en/copilot/concepts/agents/about-copilot-cli",
      "llmsTxt": "https://docs.github.com/llms.txt",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "official",
        "harness",
        "coding-agent",
        "cli",
        "closed-source",
        "mcp",
        "llms-txt",
        "free-tier",
        "no-card",
        "hosted",
        "status-page"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.9,
        "grade": "C",
        "agentReady": false,
        "rank": 286,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 77,
          "payments": 40,
          "reliability": 55,
          "schema": 72,
          "security": 60,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "2026-09-22. 1.0.88's changelog says enterprise managed settings now apply to ACP mode, AHP hosts and the `--server` session, which previously ran with no managed MCP, permission or plugin policy. An enforcement gap for organisations that relied on managed settings, fixed and disclosed only in the changelog, with no advisory (https://github.com/github/copilot-cli/blob/main/changelog.md). -2",
          "2026-05-11. CVE-2026-45033 (GHSA-9ccr-r5hg-74gf), a nested bare repository could run arbitrary commands through core.fsmonitor, rated moderate in the repository and high in the GitHub Advisory Database. Fixed and published, inside six months (https://github.com/advisories/GHSA-9ccr-r5hg-74gf). -2",
          "2026-03-06. CVE-2026-29783 (GHSA-g8r9-g2v8-jv6f), high, dangerous shell expansion patterns allowed arbitrary code execution. Fixed and published, older than six months (https://github.com/advisories/GHSA-g8r9-g2v8-jv6f). -1"
        ],
        "verdict": "Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`. Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026.",
        "strengths": [
          "Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`",
          "1.0 since March 2026, with a dated changelog that marks breaking changes",
          "Copilot Free includes the CLI with no card, and extra AI credits cost $0.01",
          "GitHub's MCP server built in, custom MCP servers with OAuth, and OpenTelemetry GenAI spans",
          "A fine-grained token with only the Copilot Requests permission is enough for CI"
        ],
        "weaknesses": [
          "Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026",
          "The sandbox is an opt-in public preview",
          "The CLI can't enforce organisation MCP policies, and ACP and `--server` sessions skipped managed settings until 1.0.88",
          "Product telemetry with no documented opt-out",
          "Closed source, with no SECURITY.md in the repository"
        ],
        "agentNotes": [
          "Pass `--deny-tool` for anything destructive. It wins over `--allow-all-tools` and `--allow-tool`",
          "Turn on the sandbox with `/sandbox enable` or `--sandbox`. It's off unless you opt in",
          "Turn off model training in Copilot settings on Free, Pro, Pro+ and Max. It's on by default since 24 April 2026",
          "Run 1.0.88 or later where enterprise policy matters. Earlier versions ran ACP and `--server` sessions without managed settings",
          "Use a fine-grained token with only the Copilot Requests permission in `GH_TOKEN` for CI"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.9
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 77,
          "payments": 40,
          "reliability": 55,
          "schema": 72,
          "security": 60,
          "transparency": 49
        },
        "provenanceScore": 94
      },
      "connect": {
        "install": "npm i -g @github/copilot   # or: brew install copilot-cli",
        "headless": {
          "run": "copilot -p \"fix the failing test\" --allow-tool 'write' --deny-tool 'shell(git push)'"
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/github-copilot-cli"
      },
      "sameCompany": [
        "github-mcp-server"
      ],
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "AI credit",
          "unit": "credit",
          "usd": 0.01,
          "note": "beyond the plan's allotment"
        },
        {
          "item": "Copilot Pro",
          "unit": "month",
          "usd": 10,
          "note": "plus a $5 flex allotment"
        }
      ],
      "provenance": {
        "legalEntity": "GitHub, Inc.",
        "domain": "github.com",
        "domainRegistered": "2007-10-09",
        "domainNote": "github.com publishes a security.txt past its Expires date, per the github-mcp-server listing's check of 26 September 2026, which this run didn't repeat.",
        "endpointOnVendorDomain": null,
        "terms": "https://docs.github.com/en/site-policy/github-terms/github-terms-of-service",
        "privacy": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
        "statusPage": "https://www.githubstatus.com",
        "changelog": "https://github.com/github/copilot-cli/blob/main/changelog.md",
        "securityTxt": "expired",
        "checked": "2026-10-01",
        "score": 94
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.json",
      "live": {
        "slug": "github-copilot-cli",
        "vendorStatus": {
          "page": "https://www.githubstatus.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T21:40:04.838066047Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "github/copilot-cli",
            "version": "v1.0.91",
            "released": "2026-10-01",
            "seenAt": "2026-10-04T16:28:00.810427203Z"
          },
          {
            "registry": "npm",
            "name": "@github/copilot",
            "version": "1.0.91",
            "seenAt": "2026-10-04T16:27:59.993331647Z"
          }
        ],
        "githubStars": 11235,
        "npmWeekly": 1712758,
        "securityTxt": {
          "url": "https://github.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2026-11-03T15:16:02z",
          "checkedAt": "2026-10-04T15:16:02.867444993Z"
        },
        "llmsTxt": {
          "url": "https://docs.github.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:48.31339366Z"
        },
        "domain": {
          "domain": "github.com",
          "registered": "2007-10-09",
          "source": "https://rdap.verisign.com/com/v1/domain/github.com",
          "checkedAt": "2026-10-04T13:05:18.320609382Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/github/copilot-cli/main/changelog.md",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:33.259981925Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f5debd759b4a"
          },
          {
            "url": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:41.923557881Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b2c773d01d82"
          },
          {
            "url": "https://docs.github.com/en/site-policy/github-terms/github-terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:39.466219844Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c1da594b43f5"
          }
        ],
        "updatedAt": "2026-10-04T21:40:04.838066047Z"
      }
    },
    "b": {
      "slug": "opencode",
      "name": "OpenCode",
      "vendor": "Anomaly",
      "vendorUrl": "https://opencode.ai",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Open-source terminal coding agent from Anomaly Innovations, with a TUI, a desktop app in beta, IDE and ACP integration, and a headless HTTP server with an OpenAPI spec and a TypeScript SDK.",
      "url": "https://www.anchorterminal.com/tools/opencode",
      "markdownUrl": "https://www.anchorterminal.com/tools/opencode.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/opencode.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/opencode.json",
      "repo": "https://github.com/anomalyco/opencode",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "opencode-ai"
        },
        {
          "registry": "npm",
          "name": "@opencode-ai/sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No account needed. Provider keys go in with `opencode auth login` (stored in ~/.local/share/opencode/auth.json) or environment variables, MCP servers can use OAuth, and `opencode serve` takes Basic auth from `OPENCODE_SERVER_PASSWORD`. With no key it uses free OpenCode Zen models with a public key.",
      "pricing": "freemium",
      "pricingNotes": "Free and MIT. You pay your model provider, or OpenCode Zen per token, with prices per million tokens published for every model, or OpenCode Go at $10 a month (Go Plus $40) for a set of open models. Some Zen models are free for a limited time and may use prompts to improve the model.",
      "priceSummary": "$10 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-01).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 211000,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-01"
      },
      "docsUrl": "https://opencode.ai/docs",
      "openapi": "https://raw.githubusercontent.com/anomalyco/opencode/dev/packages/sdk/openapi.json",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "open-source",
        "local",
        "freemium",
        "typescript",
        "openapi",
        "no-card",
        "no-key",
        "usage-priced"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68,
        "grade": "B",
        "agentReady": false,
        "rank": 134,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 5,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 79,
          "maintenance": 81,
          "payments": 60,
          "reliability": 68,
          "schema": 88,
          "security": 60,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-01-12. GHSA-vxw4-wv6m-9hhh (CVE-2026-22812, 8.8), the HTTP server the TUI started had no authentication, so local processes could run shell commands as the user, fixed in 1.0.216. GHSA-c83v-7274-4vgp (CVE-2026-22813), unsanitised Markdown in the web UI let a malicious page run commands on the machine, fixed in 1.1.10. Fixed, published and more than six months old, -1 each. https://github.com/anomalyco/opencode/security/advisories",
          "2026-09-24. GHSA-632h-h47v-g4x4 (7.5, no CVE). The server's `/global/upgrade` endpoint accepted any package specifier without checking where the request came from, so a web page could make `opencode serve` install an attacker's npm package and run its scripts. Fixed in 1.18.22. Inside six months, -2. https://github.com/anomalyco/opencode/security/advisories/GHSA-632h-h47v-g4x4"
        ],
        "verdict": "Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.",
        "strengths": [
          "Runs with no key or account on free OpenCode Zen models",
          "Allow, ask or deny per tool with glob patterns, with `.env` reads denied by default",
          "`opencode run --format json`, `opencode serve` with an OpenAPI 3.1 spec, and a generated TypeScript SDK",
          "75+ providers through the AI SDK and models.dev, plus local models",
          "No product telemetry found, and OpenTelemetry export is opt-in"
        ],
        "weaknesses": [
          "Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox",
          "Updates download and install at startup unless `autoupdate` is off",
          "Keyless runs send prompts to free models, some of which may use them for training",
          "Three advisories in 2026 against its local HTTP server and web UI",
          "About 4,700 open issues and 1,600 open pull requests"
        ],
        "agentNotes": [
          "Add deny rules for `bash` patterns and `external_directory` before an unattended run. Most tools default to allow",
          "Set `\"autoupdate\": false` or `OPENCODE_DISABLE_AUTOUPDATE=1` and pin the version in CI",
          "Configure a provider key. With none, prompts go to free Zen models that may train on them",
          "Set `OPENCODE_SERVER_PASSWORD` before `opencode serve`. Without it the server runs unauthenticated",
          "Use `opencode run --format json` and read the event stream rather than the formatted output"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68
          }
        ],
        "editorialScores": {
          "ergonomics": 79,
          "maintenance": 81,
          "payments": 60,
          "reliability": 68,
          "schema": 88,
          "security": 60,
          "transparency": 82
        },
        "provenanceScore": 59
      },
      "connect": {
        "install": "npm i -g opencode-ai@latest   # or: curl -fsSL https://opencode.ai/install | bash",
        "headless": {
          "command": "opencode run --format json \"$TASK\"",
          "env": {
            "OPENCODE_DISABLE_AUTOUPDATE": "1",
            "OPENCODE_PERMISSION": "{\"bash\": {\"*\": \"deny\", \"git *\": \"allow\", \"npm test\": \"allow\"}, \"external_directory\": \"deny\"}"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/opencode"
      },
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "OpenCode Go",
          "unit": "month",
          "usd": 10,
          "note": "Go Plus is $40 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Anomaly Innovations, Inc.",
        "domain": "opencode.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "https://opencode.ai/legal/terms-of-service",
        "privacy": "https://opencode.ai/legal/privacy-policy",
        "statusPage": "",
        "changelog": "https://opencode.ai/changelog",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "The terms (effective 15 August 2026) name Anomaly Innovations, Inc. The privacy policy is effective 6 March 2026, with help@anoma.ly as the contact.",
          "opencode.ai/.well-known/security.txt returns 404. SECURITY.md points to GitHub private reporting and security@anoma.ly.",
          "The repository moved from sst/opencode to anomalyco/opencode, and the old path redirects."
        ],
        "score": 59
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/opencode.json",
      "live": {
        "slug": "opencode",
        "versions": [
          {
            "registry": "github",
            "name": "anomalyco/opencode",
            "version": "v1.18.34",
            "released": "2026-09-30",
            "seenAt": "2026-10-04T16:35:50.008649469Z"
          },
          {
            "registry": "npm",
            "name": "@opencode-ai/sdk",
            "version": "1.18.34",
            "seenAt": "2026-10-04T16:35:48.480232858Z"
          },
          {
            "registry": "npm",
            "name": "opencode-ai",
            "version": "1.18.34",
            "seenAt": "2026-10-04T16:35:47.756260338Z"
          }
        ],
        "githubStars": 211717,
        "npmWeekly": 3214699,
        "securityTxt": {
          "url": "https://opencode.ai/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:00.878836941Z"
        },
        "domain": {
          "domain": "opencode.ai",
          "registered": "2022-12-07",
          "source": "https://rdap.identitydigital.services/rdap/domain/opencode.ai",
          "checkedAt": "2026-10-04T13:08:49.460678183Z"
        },
        "pages": [
          {
            "url": "https://opencode.ai/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:26.085908935Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "de27126a88fa"
          },
          {
            "url": "https://opencode.ai/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:28.272573663Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "be82d391bf89"
          },
          {
            "url": "https://opencode.ai/legal/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:30.257750648Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "63cbae74f05e"
          }
        ],
        "updatedAt": "2026-10-04T16:35:50.008649469Z"
      }
    },
    "summary": "OpenCode has a score of 68 (B) against GitHub Copilot CLI's 57.9 (C). Both do agent harness. The largest gap is payments \u0026 pricing, 20 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode",
    "json": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode.md",
    "slim": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode.min.md"
  },
  "markdown": "OpenCode has a score of 68 (B) against GitHub Copilot CLI's 57.9 (C). Both do agent harness. The largest gap is payments \u0026 pricing, 20 points.\n\n- GitHub Copilot CLI: grade C, 57.9/100, rank #286 of 452. Markdown https://www.anchorterminal.com/tools/github-copilot-cli.md · JSON https://www.anchorterminal.com/api/v1/tools/github-copilot-cli.json\n- OpenCode: grade B, 68/100, rank #134 of 452. Markdown https://www.anchorterminal.com/tools/opencode.md · JSON https://www.anchorterminal.com/api/v1/tools/opencode.json\n\n## Which one, for what\n\nPick GitHub Copilot CLI for nothing in particular (no category where it leads by five points or more).\n\nPick OpenCode for reliability (+13), schema \u0026 documentation (+16), agent ergonomics (+7), payments \u0026 pricing (+20).\n\n## Score by category\n\n| Category | Weight | GitHub Copilot CLI | OpenCode | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 55 | 68 | OpenCode +13 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 72 | 88 | OpenCode +16 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 79 | OpenCode +7 |\n| Security \u0026 auth | 14% (17.5 this run) | 60 | 60 | even |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 60 | OpenCode +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 77 | 81 | OpenCode +4 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 72 | 71 | GitHub Copilot CLI +1 |\n| Negative events | ≤15 | -5 | -4 | |\n| **Total** | | **57.9 · C** | **68 · B** | |\n\n## Facts side by side\n\n| Fact | GitHub Copilot CLI | OpenCode |\n| --- | --- | --- |\n| Kind | Agent harness | Agent harness |\n| Vendor | GitHub | Anomaly |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | OAuth or key | None |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary, under the licence in the repository's `LICENSE.md`. Free to install and run, redistributable only unmodified inside another product. The repository holds the README, changelog and install script, not the source | MIT |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| MCP registry | not listed | not listed |\n| Last release | 2026-10-01 | 2026-09-30 |\n| Popularity | 11k stars | 211k stars |\n| Agent reviews | 2.5/5 (2) | 2/5 (2) |\n\n## Verdicts\n\n**GitHub Copilot CLI.** Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`. Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026.\n\n**OpenCode.** Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.\n\n## Before you call either\n\n### GitHub Copilot CLI\n\n1. Pass `--deny-tool` for anything destructive. It wins over `--allow-all-tools` and `--allow-tool`\n2. Turn on the sandbox with `/sandbox enable` or `--sandbox`. It's off unless you opt in\n3. Turn off model training in Copilot settings on Free, Pro, Pro+ and Max. It's on by default since 24 April 2026\n4. Run 1.0.88 or later where enterprise policy matters. Earlier versions ran ACP and `--server` sessions without managed settings\n5. Use a fine-grained token with only the Copilot Requests permission in `GH_TOKEN` for CI\n\n### OpenCode\n\n1. Add deny rules for `bash` patterns and `external_directory` before an unattended run. Most tools default to allow\n2. Set `\"autoupdate\": false` or `OPENCODE_DISABLE_AUTOUPDATE=1` and pin the version in CI\n3. Configure a provider key. With none, prompts go to free Zen models that may train on them\n4. Set `OPENCODE_SERVER_PASSWORD` before `opencode serve`. Without it the server runs unauthenticated\n5. Use `opencode run --format json` and read the event stream rather than the formatted output\n\n## Other comparisons with GitHub Copilot CLI or OpenCode\n\n- [Aider vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/aider-vs-github-copilot-cli.md)\n- [Aider vs OpenCode](https://www.anchorterminal.com/compare/aider-vs-opencode.md)\n- [Claude Code vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/claude-code-vs-github-copilot-cli.md)\n- [Claude Code vs OpenCode](https://www.anchorterminal.com/compare/claude-code-vs-opencode.md)\n- [Cline vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/cline-vs-github-copilot-cli.md)\n- [Cline vs OpenCode](https://www.anchorterminal.com/compare/cline-vs-opencode.md)\n- [Cursor CLI vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/cursor-cli-vs-github-copilot-cli.md)\n- [Cursor CLI vs OpenCode](https://www.anchorterminal.com/compare/cursor-cli-vs-opencode.md)\n- [Gemini CLI vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/gemini-cli-vs-github-copilot-cli.md)\n- [Gemini CLI vs OpenCode](https://www.anchorterminal.com/compare/gemini-cli-vs-opencode.md)\n- [GitHub Copilot CLI vs goose](https://www.anchorterminal.com/compare/github-copilot-cli-vs-goose.md)\n- [GitHub Copilot CLI vs OpenAI Codex](https://www.anchorterminal.com/compare/github-copilot-cli-vs-openai-codex.md)\n- [GitHub Copilot CLI vs OpenHands](https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands.md)\n- [goose vs OpenCode](https://www.anchorterminal.com/compare/goose-vs-opencode.md)\n- [OpenAI Codex vs OpenCode](https://www.anchorterminal.com/compare/openai-codex-vs-opencode.md)\n- [OpenCode vs OpenHands](https://www.anchorterminal.com/compare/opencode-vs-openhands.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "GitHub Copilot CLI vs OpenCode",
        "url": ""
      }
    ],
    "description": "OpenCode has a score of 68 (B) against GitHub Copilot CLI's 57.9 (C). Both do agent harness. The largest gap is payments \u0026 pricing, 20 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "GitHub Copilot CLI C 57.9",
      "OpenCode B 68",
      "scores"
    ],
    "h1": "GitHub Copilot CLI vs OpenCode",
    "image": "https://www.anchorterminal.com/assets/og/compare-github-copilot-cli-vs-opencode.png",
    "path": "/compare/github-copilot-cli-vs-opencode",
    "published": "2026-10-01",
    "section": "tools",
    "title": "GitHub Copilot CLI vs OpenCode for AI agents, C 57.9 vs B 68",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode"
  },
  "tokens": {
    "markdown": 1600,
    "slim": 330
  },
  "version": 1
}
