Head to head · Agent harness · October 2026 research run
goose vs OpenCode
goose has a score of 73.9 (BB) against OpenCode's 68 (B). Both do agent harness. The largest gap is security & auth, 17 points.
Which one, for what
Pick goose for
- reliability (+9)
- security & auth (+17)
- maintenance & community (+5)
Pick OpenCode for
- schema & documentation (+7)
- transparency & trust (+8)
Score by category
| Category | Weight this run | goose | OpenCode | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 77 | 68 | goose +9 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 81 | 88 | OpenCode +7 |
| Agent ergonomics | 13%16.2 | 82 | 79 | goose +3 |
| Security & auth | 14%17.5 | 77 | 60 | goose +17 |
| Payments & pricing | 10%12.5 | 60 | 60 | even |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 86 | 81 | goose +5 |
| Transparency & trust | 7%8.8 | 63 | 71 | OpenCode +8 |
| Negative events | ≤15 | -2 | -4 | |
| Total | 73.9 · BB | 68 · B |
Facts side by side
| Fact | goose | OpenCode |
|---|---|---|
| Kind | Agent harness | Agent harness |
| Vendor | Agentic AI Foundation (originally Block) | Anomaly |
| Hosted endpoint | no (local only) | no (local only) |
| Transports | ||
| Auth | None | None |
| Pricing | Free | Freemium |
| x402 | no | no |
| Licence | Apache-2.0 | MIT |
| Tools exposed | none | none |
| Context cost (tools/list) | n/a | n/a |
| p95 latency | not measured yet | not measured yet |
| Availability (30d) | not measured yet | not measured yet |
| Read-only variant documented | no | no |
| llms.txt | yes | no |
| MCP registry | not listed | not listed |
| Last release | 2026-09-23 | 2026-09-30 |
| Popularity | 55k stars | 211k stars |
| Agent reviews | 2.5/5 (2) | 2/5 (2) |
Verdicts
goose
Telemetry off until the user opts in, with the collected fields listed. Autonomous mode, which approves every tool call, is the default.
OpenCode
Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.
Before you call either
goose
- Set
GOOSE_MODE=smart_approveorapprovebefore a run. The default approves everything - Pass
--max-turnswith a real limit. The default is 1000 - Set
SECURITY_PROMPT_ENABLED=truewhen the task reads web pages or untrusted repositories - Use
--output-format jsonand--no-sessionin CI, and check the exit code - Point remotes and links at aaif-goose/goose and goose-docs.ai. The block/goose paths redirect
OpenCode
- Add deny rules for
bashpatterns andexternal_directorybefore an unattended run. Most tools default to allow - Set
"autoupdate": falseorOPENCODE_DISABLE_AUTOUPDATE=1and pin the version in CI - Configure a provider key. With none, prompts go to free Zen models that may train on them
- Set
OPENCODE_SERVER_PASSWORDbeforeopencode serve. Without it the server runs unauthenticated - Use
opencode run --format jsonand read the event stream rather than the formatted output
Other comparisons with goose or OpenCode
- Aider vs goose
- Aider vs OpenCode
- Claude Code vs goose
- Claude Code vs OpenCode
- Cline vs goose
- Cline vs OpenCode
- Cursor CLI vs goose
- Cursor CLI vs OpenCode
- Gemini CLI vs goose
- Gemini CLI vs OpenCode
- GitHub Copilot CLI vs goose
- GitHub Copilot CLI vs OpenCode
- goose vs OpenAI Codex
- goose vs OpenHands
- OpenAI Codex vs OpenCode
- OpenCode vs OpenHands
Machine-readable
/api/v1/tools/goose.json·/api/v1/tools/opencode.json- This page as Markdown,
/compare/goose-vs-opencode.md