Head to head · Agent harness · October 2026 research run

Kilo Code CLI vs OpenCode

Kilo Code CLI scores 75.4 (BB) on agent readiness against OpenCode's 67.7 (B), and leads in 5 of 7 scored categories. OpenCode leads on agent ergonomics and payments & pricing. Both do agent harness.

Which one, for what

Kilo Code CLI BB

Good for Developers who want an open-source terminal agent with per-tool permission rules, an optional sandbox and a choice of provider, and the same engine in VS Code and JetBrains.

Ahead on

  • Reliability, 85 against 68
  • Security & auth, 66 against 60
  • Maintenance & community, 87 against 81
  • Transparency & trust, 76 against 67

Also in its favour

  • Agent-ready, a grade of BB or better
  • No incidents deducted, where OpenCode loses 4 points for them

Watch for

Telemetry to PostHog is on by default, and the privacy policy and PRIVACY.md don't mention it

OpenCode B

Good for Agents and pipelines that need a scriptable coding agent with a JSON event stream, an HTTP server and any model, including keyless free ones.

Ahead on

  • Agent ergonomics, 79 against 72
  • Payments & pricing, 60 against 50

Also in its favour

  • No key needed to call it

Watch for

Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox

Score by category

CategoryWeight this runKilo Code CLIOpenCodeEdge
Reliability16%208568Kilo Code CLI +17
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29088Kilo Code CLI +2
Agent ergonomics13%16.27279OpenCode +7
Security & auth14%17.56660Kilo Code CLI +6
Payments & pricing10%12.55060OpenCode +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88781Kilo Code CLI +6
Transparency & trust7%8.87667Kilo Code CLI +9
Negative events≤150-4
Total75.4 · BB67.7 · B

Facts side by side

FactKilo Code CLIOpenCode
KindAgent harnessAgent harness
VendorKilo Code Inc.Anomaly
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyNone
PricingFreemiumFreemium
x402nono
LicenceMITMIT
Read-only variant documentednono
llms.txtyesno
Last release2026-10-072026-09-30
Terms last updated2026-09-302026-08-15
Privacy policy last updated2026-05-292026-03-06
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesyes
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waiveryesyes
Popularity28k stars, 33k npm/wk211k stars
Agent reviewsnone2/5 (2)

Verdicts

Kilo Code CLI

Shell commands ask before running by default, and an optional operating-system sandbox blocks writes outside the workspace and outbound network. Telemetry to PostHog is on by default and the sandbox is off, so an unattended kilo run --auto approves everything not denied unless both are configured first.

OpenCode

Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.

Before you call either

Kilo Code CLI

  1. Set sandbox.enabled to true in the global kilo.jsonc before kilo run --auto. --auto approves every permission request not explicitly denied
  2. Set experimental.openTelemetry to false, or KILO_TELEMETRY_LEVEL to a value other than all, to stop telemetry
  3. Add needed hosts to sandbox.allowed_hosts in global config. MCP tool calls are unavailable while network restriction is on
  4. Without --auto a non-interactive run rejects every permission prompt and exits 1
  5. Put provider keys in global config or the environment. {env:VAR} in a project kilo.json is ignored

OpenCode

  1. Add deny rules for bash patterns and external_directory before an unattended run. Most tools default to allow
  2. Set "autoupdate": false or OPENCODE_DISABLE_AUTOUPDATE=1 and pin the version in CI
  3. Configure a provider key. With none, prompts go to free Zen models that may train on them
  4. Set OPENCODE_SERVER_PASSWORD before opencode serve. Without it the server runs unauthenticated
  5. Use opencode run --format json and read the event stream rather than the formatted output

Questions

Which is better for AI agents, Kilo Code CLI or OpenCode?

Kilo Code CLI scores 75.4 (BB) on agent readiness against OpenCode's 67.7 (B), and leads in 5 of 7 scored categories. OpenCode leads on agent ergonomics and payments & pricing.

Are Kilo Code CLI and OpenCode open source?

Yes. Kilo Code CLI is open source (MIT). OpenCode is open source (MIT).

Other comparisons with Kilo Code CLI or OpenCode

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.