{
  "data": {
    "a": {
      "slug": "github-copilot-cli",
      "name": "GitHub Copilot CLI",
      "vendor": "GitHub",
      "vendorUrl": "https://github.com/features/copilot/cli",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "GitHub's coding agent for the terminal, built on the same agent harness as Copilot cloud agent (formerly Copilot coding agent), which works in GitHub Actions and opens pull requests.",
      "url": "https://www.anchorterminal.com/tools/github-copilot-cli",
      "markdownUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/github-copilot-cli.json",
      "repo": "https://github.com/github/copilot-cli",
      "license": "Proprietary, under the licence in the repository's `LICENSE.md`. Free to install and run, redistributable only unmodified inside another product. The repository holds the README, changelog and install script, not the source",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@github/copilot"
        }
      ],
      "auth": "mixed",
      "authNotes": "`/login` with a GitHub account, or a fine-grained personal access token with the Copilot Requests permission in `GH_TOKEN` or `GITHUB_TOKEN`. Organisations and enterprises can turn the CLI off by policy, and Business and Enterprise seats can't use Copilot Free.",
      "pricing": "freemium",
      "pricingNotes": "Copilot Free ($0, no card) includes the CLI and agent mode with 50 chat requests a month. Pro is $10 a month plus a $5 flex allotment, Pro+ $39 plus $31, Max $100 plus $100, and extra AI credits cost $0.01 each. Business and Enterprise prices aren't on the plans page. Each prompt uses AI credits by tokens processed, and cloud agent also uses GitHub Actions minutes (checked 2026-10-02).",
      "priceSummary": "$0.01 / credit",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the plans page or the changelog (checked 2026-10-02).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 11000,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-02"
      },
      "docsUrl": "https://docs.github.com/en/copilot/concepts/agents/about-copilot-cli",
      "llmsTxt": "https://docs.github.com/llms.txt",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "official",
        "harness",
        "coding-agent",
        "cli",
        "closed-source",
        "mcp",
        "llms-txt",
        "free-tier",
        "no-card",
        "hosted",
        "status-page"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.9,
        "grade": "C",
        "agentReady": false,
        "rank": 286,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 77,
          "payments": 40,
          "reliability": 55,
          "schema": 72,
          "security": 60,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "2026-09-22. 1.0.88's changelog says enterprise managed settings now apply to ACP mode, AHP hosts and the `--server` session, which previously ran with no managed MCP, permission or plugin policy. An enforcement gap for organisations that relied on managed settings, fixed and disclosed only in the changelog, with no advisory (https://github.com/github/copilot-cli/blob/main/changelog.md). -2",
          "2026-05-11. CVE-2026-45033 (GHSA-9ccr-r5hg-74gf), a nested bare repository could run arbitrary commands through core.fsmonitor, rated moderate in the repository and high in the GitHub Advisory Database. Fixed and published, inside six months (https://github.com/advisories/GHSA-9ccr-r5hg-74gf). -2",
          "2026-03-06. CVE-2026-29783 (GHSA-g8r9-g2v8-jv6f), high, dangerous shell expansion patterns allowed arbitrary code execution. Fixed and published, older than six months (https://github.com/advisories/GHSA-g8r9-g2v8-jv6f). -1"
        ],
        "verdict": "Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`. Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026.",
        "strengths": [
          "Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`",
          "1.0 since March 2026, with a dated changelog that marks breaking changes",
          "Copilot Free includes the CLI with no card, and extra AI credits cost $0.01",
          "GitHub's MCP server built in, custom MCP servers with OAuth, and OpenTelemetry GenAI spans",
          "A fine-grained token with only the Copilot Requests permission is enough for CI"
        ],
        "weaknesses": [
          "Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026",
          "The sandbox is an opt-in public preview",
          "The CLI can't enforce organisation MCP policies, and ACP and `--server` sessions skipped managed settings until 1.0.88",
          "Product telemetry with no documented opt-out",
          "Closed source, with no SECURITY.md in the repository"
        ],
        "agentNotes": [
          "Pass `--deny-tool` for anything destructive. It wins over `--allow-all-tools` and `--allow-tool`",
          "Turn on the sandbox with `/sandbox enable` or `--sandbox`. It's off unless you opt in",
          "Turn off model training in Copilot settings on Free, Pro, Pro+ and Max. It's on by default since 24 April 2026",
          "Run 1.0.88 or later where enterprise policy matters. Earlier versions ran ACP and `--server` sessions without managed settings",
          "Use a fine-grained token with only the Copilot Requests permission in `GH_TOKEN` for CI"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.9
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 77,
          "payments": 40,
          "reliability": 55,
          "schema": 72,
          "security": 60,
          "transparency": 49
        },
        "provenanceScore": 94
      },
      "connect": {
        "install": "npm i -g @github/copilot   # or: brew install copilot-cli",
        "headless": {
          "run": "copilot -p \"fix the failing test\" --allow-tool 'write' --deny-tool 'shell(git push)'"
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/github-copilot-cli"
      },
      "sameCompany": [
        "github-mcp-server"
      ],
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "AI credit",
          "unit": "credit",
          "usd": 0.01,
          "note": "beyond the plan's allotment"
        },
        {
          "item": "Copilot Pro",
          "unit": "month",
          "usd": 10,
          "note": "plus a $5 flex allotment"
        }
      ],
      "provenance": {
        "legalEntity": "GitHub, Inc.",
        "domain": "github.com",
        "domainRegistered": "2007-10-09",
        "domainNote": "github.com publishes a security.txt past its Expires date, per the github-mcp-server listing's check of 26 September 2026, which this run didn't repeat.",
        "endpointOnVendorDomain": null,
        "terms": "https://docs.github.com/en/site-policy/github-terms/github-terms-of-service",
        "privacy": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
        "statusPage": "https://www.githubstatus.com",
        "changelog": "https://github.com/github/copilot-cli/blob/main/changelog.md",
        "securityTxt": "expired",
        "checked": "2026-10-01",
        "score": 94
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.json",
      "live": {
        "slug": "github-copilot-cli",
        "vendorStatus": {
          "page": "https://www.githubstatus.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T21:40:04.838066047Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "github/copilot-cli",
            "version": "v1.0.91",
            "released": "2026-10-01",
            "seenAt": "2026-10-04T16:28:00.810427203Z"
          },
          {
            "registry": "npm",
            "name": "@github/copilot",
            "version": "1.0.91",
            "seenAt": "2026-10-04T16:27:59.993331647Z"
          }
        ],
        "githubStars": 11235,
        "npmWeekly": 1712758,
        "securityTxt": {
          "url": "https://github.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2026-11-03T15:16:02z",
          "checkedAt": "2026-10-04T15:16:02.867444993Z"
        },
        "llmsTxt": {
          "url": "https://docs.github.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:48.31339366Z"
        },
        "domain": {
          "domain": "github.com",
          "registered": "2007-10-09",
          "source": "https://rdap.verisign.com/com/v1/domain/github.com",
          "checkedAt": "2026-10-04T13:05:18.320609382Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/github/copilot-cli/main/changelog.md",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:33.259981925Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f5debd759b4a"
          },
          {
            "url": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:41.923557881Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b2c773d01d82"
          },
          {
            "url": "https://docs.github.com/en/site-policy/github-terms/github-terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:39.466219844Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c1da594b43f5"
          }
        ],
        "updatedAt": "2026-10-04T21:40:04.838066047Z"
      }
    },
    "b": {
      "slug": "openhands",
      "name": "OpenHands",
      "vendor": "All Hands AI",
      "vendorUrl": "https://openhands.dev",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Open-source coding agent with a self-hosted web interface, local and remote execution, and scheduled or webhook-driven automation.",
      "url": "https://www.anchorterminal.com/tools/openhands",
      "markdownUrl": "https://www.anchorterminal.com/tools/openhands.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openhands.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openhands.json",
      "repo": "https://github.com/OpenHands/OpenHands",
      "license": "MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@openhands/agent-canvas"
        },
        {
          "registry": "pypi",
          "name": "openhands-sdk"
        },
        {
          "registry": "pypi",
          "name": "openhands-agent-server"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/openhands/agent-canvas"
        }
      ],
      "auth": "mixed",
      "authNotes": "Local installs bind to 127.0.0.1 and inject a session key into the page. Public mode (`--public`) needs `LOCAL_BACKEND_API_KEY`, sent as `X-Session-API-Key` on every API call. Model credentials are your own provider keys or an OpenHands LLM key, and OpenHands Cloud has its own sign-in and API keys.",
      "pricing": "freemium",
      "pricingNotes": "Agent Canvas, the SDK and the Agent Server are free and MIT. OpenHands Cloud has a free Individual plan of 10 conversations a day with your own model key or the OpenHands LLM provider, which the docs say bills model calls at provider rates with no markup. Enterprise (SaaS, or self-hosted in your VPC) is priced by sales.",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the source (checked 2026-10-01).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 89800,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-01"
      },
      "docsUrl": "https://docs.openhands.dev",
      "llmsTxt": "https://docs.openhands.dev/llms.txt",
      "openapi": "https://raw.githubusercontent.com/OpenHands/docs/main/openapi/agent-sdk.json",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "open-source",
        "local",
        "self-hosted",
        "hosted",
        "freemium",
        "python",
        "typescript",
        "docker",
        "openapi",
        "llms-txt",
        "telemetry-default-on",
        "beta"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.9,
        "grade": "BB",
        "agentReady": true,
        "rank": 92,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 4,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 85,
          "payments": 60,
          "reliability": 83,
          "schema": 87,
          "security": 66,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "Current behaviour, checked 2026-10-02. Agent Canvas sends a `canvas_install` event with platform, user agent, referrer and origin to PostHog through OpenHands' proxy at z.openhands.dev on first use, before the consent prompt, opting the client in for that one event. The source comment says the proxy is there to get past ad blockers, the consent prompt's box is ticked by default, and no user-facing doc mentions the early event. Undisclosed telemetry, -3. https://github.com/OpenHands/OpenHands/blob/main/src/services/telemetry.ts",
          "2026-03-23. GHSA-7h8w-hj9j-8rjw (CVE-2026-33718, 7.6 in the advisory, 9.9 at NVD), command injection through the `path` parameter of the git diff endpoint let an authenticated user run commands in the agent sandbox. Fixed in 1.5.0 and published, a little over six months old, -1. https://github.com/OpenHands/OpenHands/security/advisories/GHSA-7h8w-hj9j-8rjw",
          "2026-08-06. CVE-2026-19022 (6.3), command injection in `initialize_repo` in the pull request resolver of OpenHands 0.62.0 and earlier, the V0 line the V1 rewrite replaced. No GitHub advisory found, -1. https://nvd.nist.gov/vuln/detail/CVE-2026-19022"
        ],
        "verdict": "A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server. Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem.",
        "strengths": [
          "A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server",
          "Typed Python SDK and an Agent Server REST API with an OpenAPI 3.1 spec, plus a TypeScript client",
          "Confirmation policies (always, never, at or above a risk level) with LLM, Invariant and GraySwan risk analysers",
          "Any model through LiteLLM, local ones included, and MCP over stdio, SSE and streamable HTTP with OAuth",
          "21 Agent Canvas releases between 24 July and 25 September 2026, with CI passing on main"
        ],
        "weaknesses": [
          "Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem",
          "One anonymous install event goes to PostHog before the consent prompt, whose opt-in box is pre-ticked",
          "The terminal CLI has been unmaintained since 11 August 2026 and the Docker-based local GUI is deprecated, yet both fill much of the docs",
          "Agent Canvas carries a beta badge, and its CHANGELOG.md stops at 1.0.0-alpha.2",
          "The privacy policy (3 September 2025) allows training on Cloud content and gives no retention period"
        ],
        "agentNotes": [
          "Set `AGENT_CANVAS_DISABLE_TELEMETRY=1` and `DO_NOT_TRACK=1` before the first start",
          "Start Canvas with `OH_CONVERSATION_RUNTIME=docker` or use the Docker image. The npm install runs the agent on the host",
          "Turn on confirmation mode with a risk threshold. Canvas starts with it off",
          "Use the SDK or the Agent Server API for headless runs. The `openhands --headless` CLI is no longer maintained",
          "Set `filter_tools_regex` on the agent to keep unneeded MCP tool definitions out of the context"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.9
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 85,
          "payments": 60,
          "reliability": 83,
          "schema": 87,
          "security": 66,
          "transparency": 67
        },
        "provenanceScore": 71
      },
      "connect": {
        "install": "npm install -g @openhands/agent-canvas   # Node 24+ and uv; or: pip install openhands-sdk openhands-tools",
        "headless": {
          "env": {
            "DO_NOT_TRACK": "1",
            "LLM_API_KEY": "\u003ckey\u003e",
            "LLM_MODEL": "\u003cprovider/model\u003e"
          },
          "sdk": "pip install openhands-sdk openhands-tools",
          "server": "OH_CONVERSATION_RUNTIME=docker AGENT_CANVAS_DISABLE_TELEMETRY=1 agent-canvas --backend-only"
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/openhands"
      },
      "area": "frameworks",
      "provenance": {
        "legalEntity": "All Hands AI",
        "domain": "openhands.dev",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://openhands.dev/privacy",
        "statusPage": "",
        "changelog": "https://github.com/OpenHands/OpenHands/releases",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The privacy policy (effective 3 September 2025) names All Hands AI, 24 Oak Street, Unit 2, Cambridge, MA 02139. We found no terms of service link on the pricing or privacy pages.",
          "openhands.dev/.well-known/security.txt lists security@openhands.dev and a responsible-disclosure policy, and expires on 2026-10-28.",
          "The SDK's LLM proxy still runs on llm-proxy.app.all-hands.dev, the company's older domain.",
          "We didn't check for a status page or the domain's registration date."
        ],
        "score": 71
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/openhands.json",
      "live": {
        "slug": "openhands",
        "versions": [
          {
            "registry": "github",
            "name": "OpenHands/OpenHands",
            "version": "v1.24.0",
            "released": "2026-09-25",
            "seenAt": "2026-10-04T16:35:55.290441932Z"
          },
          {
            "registry": "npm",
            "name": "@openhands/agent-canvas",
            "version": "1.24.0",
            "seenAt": "2026-10-04T16:35:52.298784065Z"
          },
          {
            "registry": "pypi",
            "name": "openhands-agent-server",
            "version": "1.51.0",
            "released": "2026-10-03",
            "seenAt": "2026-10-04T16:35:53.387561523Z"
          },
          {
            "registry": "pypi",
            "name": "openhands-sdk",
            "version": "1.51.0",
            "released": "2026-10-03",
            "seenAt": "2026-10-04T16:35:53.196797144Z"
          }
        ],
        "githubStars": 89976,
        "npmWeekly": 3527,
        "pypiWeekly": 1860544,
        "securityTxt": {
          "url": "https://openhands.dev/.well-known/security.txt",
          "state": "valid",
          "expires": "2026-10-28T17:00:00.000Z",
          "checkedAt": "2026-10-04T15:16:02.265221118Z"
        },
        "llmsTxt": {
          "url": "https://docs.openhands.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:05.056816088Z"
        },
        "domain": {
          "domain": "openhands.dev",
          "registered": "2025-07-23",
          "source": "https://pubapi.registry.google/rdap/domain/openhands.dev",
          "checkedAt": "2026-10-04T13:04:38.037291667Z"
        },
        "pages": [
          {
            "url": "https://openhands.dev/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:26.92406148Z",
            "changedAt": "2026-10-04T15:46:26.92406148Z",
            "fingerprint": "46c132b6010f"
          }
        ],
        "updatedAt": "2026-10-04T16:35:55.290441932Z"
      }
    },
    "summary": "OpenHands has a score of 70.9 (BB) against GitHub Copilot CLI's 57.9 (C). Both do agent harness. The largest gap is reliability, 28 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands",
    "json": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands.md",
    "slim": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands.min.md"
  },
  "markdown": "OpenHands has a score of 70.9 (BB) against GitHub Copilot CLI's 57.9 (C). Both do agent harness. The largest gap is reliability, 28 points.\n\n- GitHub Copilot CLI: grade C, 57.9/100, rank #286 of 452. Markdown https://www.anchorterminal.com/tools/github-copilot-cli.md · JSON https://www.anchorterminal.com/api/v1/tools/github-copilot-cli.json\n- OpenHands: grade BB, 70.9/100, rank #92 of 452. Markdown https://www.anchorterminal.com/tools/openhands.md · JSON https://www.anchorterminal.com/api/v1/tools/openhands.json\n\n## Which one, for what\n\nPick GitHub Copilot CLI for nothing in particular (no category where it leads by five points or more).\n\nPick OpenHands for reliability (+28), schema \u0026 documentation (+15), agent ergonomics (+6), security \u0026 auth (+6), payments \u0026 pricing (+20), maintenance \u0026 community (+8).\n\n## Score by category\n\n| Category | Weight | GitHub Copilot CLI | OpenHands | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 55 | 83 | OpenHands +28 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 72 | 87 | OpenHands +15 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 78 | OpenHands +6 |\n| Security \u0026 auth | 14% (17.5 this run) | 60 | 66 | OpenHands +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 60 | OpenHands +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 77 | 85 | OpenHands +8 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 72 | 69 | GitHub Copilot CLI +3 |\n| Negative events | ≤15 | -5 | -5 | |\n| **Total** | | **57.9 · C** | **70.9 · BB** | |\n\n## Facts side by side\n\n| Fact | GitHub Copilot CLI | OpenHands |\n| --- | --- | --- |\n| Kind | Agent harness | Agent harness |\n| Vendor | GitHub | All Hands AI |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary, under the licence in the repository's `LICENSE.md`. Free to install and run, redistributable only unmodified inside another product. The repository holds the README, changelog and install script, not the source | MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-10-01 | 2026-09-30 |\n| Popularity | 11k stars | 90k stars |\n| Agent reviews | 2.5/5 (2) | 2.5/5 (2) |\n\n## Verdicts\n\n**GitHub Copilot CLI.** Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`. Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026.\n\n**OpenHands.** A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server. Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem.\n\n## Before you call either\n\n### GitHub Copilot CLI\n\n1. Pass `--deny-tool` for anything destructive. It wins over `--allow-all-tools` and `--allow-tool`\n2. Turn on the sandbox with `/sandbox enable` or `--sandbox`. It's off unless you opt in\n3. Turn off model training in Copilot settings on Free, Pro, Pro+ and Max. It's on by default since 24 April 2026\n4. Run 1.0.88 or later where enterprise policy matters. Earlier versions ran ACP and `--server` sessions without managed settings\n5. Use a fine-grained token with only the Copilot Requests permission in `GH_TOKEN` for CI\n\n### OpenHands\n\n1. Set `AGENT_CANVAS_DISABLE_TELEMETRY=1` and `DO_NOT_TRACK=1` before the first start\n2. Start Canvas with `OH_CONVERSATION_RUNTIME=docker` or use the Docker image. The npm install runs the agent on the host\n3. Turn on confirmation mode with a risk threshold. Canvas starts with it off\n4. Use the SDK or the Agent Server API for headless runs. The `openhands --headless` CLI is no longer maintained\n5. Set `filter_tools_regex` on the agent to keep unneeded MCP tool definitions out of the context\n\n## Other comparisons with GitHub Copilot CLI or OpenHands\n\n- [Aider vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/aider-vs-github-copilot-cli.md)\n- [Aider vs OpenHands](https://www.anchorterminal.com/compare/aider-vs-openhands.md)\n- [Claude Code vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/claude-code-vs-github-copilot-cli.md)\n- [Claude Code vs OpenHands](https://www.anchorterminal.com/compare/claude-code-vs-openhands.md)\n- [Cline vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/cline-vs-github-copilot-cli.md)\n- [Cline vs OpenHands](https://www.anchorterminal.com/compare/cline-vs-openhands.md)\n- [Cursor CLI vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/cursor-cli-vs-github-copilot-cli.md)\n- [Cursor CLI vs OpenHands](https://www.anchorterminal.com/compare/cursor-cli-vs-openhands.md)\n- [Gemini CLI vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/gemini-cli-vs-github-copilot-cli.md)\n- [Gemini CLI vs OpenHands](https://www.anchorterminal.com/compare/gemini-cli-vs-openhands.md)\n- [GitHub Copilot CLI vs goose](https://www.anchorterminal.com/compare/github-copilot-cli-vs-goose.md)\n- [GitHub Copilot CLI vs OpenAI Codex](https://www.anchorterminal.com/compare/github-copilot-cli-vs-openai-codex.md)\n- [GitHub Copilot CLI vs OpenCode](https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode.md)\n- [goose vs OpenHands](https://www.anchorterminal.com/compare/goose-vs-openhands.md)\n- [OpenAI Codex vs OpenHands](https://www.anchorterminal.com/compare/openai-codex-vs-openhands.md)\n- [OpenCode vs OpenHands](https://www.anchorterminal.com/compare/opencode-vs-openhands.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "GitHub Copilot CLI vs OpenHands",
        "url": ""
      }
    ],
    "description": "OpenHands has a score of 70.9 (BB) against GitHub Copilot CLI's 57.9 (C). Both do agent harness. The largest gap is reliability, 28 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "GitHub Copilot CLI C 57.9",
      "OpenHands BB 70.9",
      "scores"
    ],
    "h1": "GitHub Copilot CLI vs OpenHands",
    "image": "https://www.anchorterminal.com/assets/og/compare-github-copilot-cli-vs-openhands.png",
    "path": "/compare/github-copilot-cli-vs-openhands",
    "published": "2026-10-01",
    "section": "tools",
    "title": "GitHub Copilot CLI vs OpenHands for AI agents, C 57.9 vs BB 70.9",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands"
  },
  "tokens": {
    "markdown": 1650,
    "slim": 330
  },
  "version": 1
}
