Head to head · Agent harness · October 2026 research run

Kilo Code CLI vs Kiro CLI

Kilo Code CLI scores 75.4 (BB) on agent readiness against Kiro CLI's 59.9 (C), and leads in 6 of 7 scored categories. Both do agent harness.

Which one, for what

Kilo Code CLI BB

Good for Developers who want an open-source terminal agent with per-tool permission rules, an optional sandbox and a choice of provider, and the same engine in VS Code and JetBrains.

Ahead on

  • Reliability, 85 against 57
  • Schema & documentation, 90 against 79
  • Agent ergonomics, 72 against 67
  • Payments & pricing, 50 against 40
  • Maintenance & community, 87 against 73
  • Transparency & trust, 76 against 67

Also in its favour

  • Agent-ready, a grade of BB or better
  • Open source
  • No incidents deducted, where Kiro CLI loses 4 points for them

Watch for

Telemetry to PostHog is on by default, and the privacy policy and PRIVACY.md don't mention it

Kiro CLI C

Good for Teams on AWS that want one agent configuration across terminal, IDE and web, with central permission policy, prompt logging to their own S3 bucket and IAM Identity Centre sign-in.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

Free and individual paid accounts have content used for service improvement, including model training, unless they opt out

Score by category

CategoryWeight this runKilo Code CLIKiro CLIEdge
Reliability16%208557Kilo Code CLI +28
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29079Kilo Code CLI +11
Agent ergonomics13%16.27267Kilo Code CLI +5
Security & auth14%17.56666even
Payments & pricing10%12.55040Kilo Code CLI +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88773Kilo Code CLI +14
Transparency & trust7%8.87667Kilo Code CLI +9
Negative events≤150-4
Total75.4 · BB59.9 · C

Facts side by side

FactKilo Code CLIKiro CLI
KindAgent harnessAgent harness
VendorKilo Code Inc.Amazon Web Services
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMITProprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the source
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-072026-10-05
Terms last updated2026-09-302026-08-14
Privacy policy last updated2026-05-292026-05-18
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waiveryesyes
Popularity28k stars, 33k npm/wk4.4k stars

Verdicts

Kilo Code CLI

Shell commands ask before running by default, and an optional operating-system sandbox blocks writes outside the workspace and outbound network. Telemetry to PostHog is on by default and the sandbox is off, so an unattended kilo run --auto approves everything not denied unless both are configured first.

Kiro CLI

Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.

Before you call either

Kilo Code CLI

  1. Set sandbox.enabled to true in the global kilo.jsonc before kilo run --auto. --auto approves every permission request not explicitly denied
  2. Set experimental.openTelemetry to false, or KILO_TELEMETRY_LEVEL to a value other than all, to stop telemetry
  3. Add needed hosts to sandbox.allowed_hosts in global config. MCP tool calls are unavailable while network restriction is on
  4. Without --auto a non-interactive run rejects every permission prompt and exits 1
  5. Put provider keys in global config or the environment. {env:VAR} in a project kilo.json is ignored

Kiro CLI

  1. Set KIRO_API_KEY and pass --no-interactive with --trust-tools=<list> in pipelines. Keep --trust-all-tools for disposable environments
  2. Pass --require-mcp-startup when a run depends on MCP tools. Without it a failed server is logged and the run continues
  3. Pass --no-interactive whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows
  4. Run kiro-cli settings telemetry.enabled false and turn off content collection on Free and individual plans. Both are on by default
  5. Export variables in the shell before starting. Since 2.24.0 a project .env file is no longer loaded into sessions, MCP servers or tools

Questions

Which is better for AI agents, Kilo Code CLI or Kiro CLI?

Kilo Code CLI scores 75.4 (BB) on agent readiness against Kiro CLI's 59.9 (C), and leads in 6 of 7 scored categories.

Are Kilo Code CLI and Kiro CLI open source?

Kilo Code CLI is open source (MIT). No open-source release is listed for Kiro CLI.

Other comparisons with Kilo Code CLI or Kiro CLI

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.