Head to head · Agent harness · October 2026 research run

Kiro CLI vs OpenAI Codex

OpenAI Codex scores 73 (BB) on agent readiness against Kiro CLI's 59.9 (C), and leads in 6 of 7 scored categories. Both do agent harness.

Which one, for what

Kiro CLI C

Good for Teams on AWS that want one agent configuration across terminal, IDE and web, with central permission policy, prompt logging to their own S3 bucket and IAM Identity Centre sign-in.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

Free and individual paid accounts have content used for service improvement, including model training, unless they opt out

OpenAI Codex BB

Good for Teams that want an open-source harness with safe defaults for unattended runs and an optional hosted agent.

Ahead on

  • Schema & documentation, 90 against 79
  • Agent ergonomics, 80 against 67
  • Security & auth, 82 against 66
  • Payments & pricing, 60 against 40
  • Maintenance & community, 87 against 73
  • Transparency & trust, 79 against 67

Also in its favour

  • Agent-ready, a grade of BB or better
  • Open source

Watch for

Pre-1.0 at 0.160.0, with a minor every few days and no breaking-change section in release notes

Score by category

CategoryWeight this runKiro CLIOpenAI CodexEdge
Reliability16%205755Kiro CLI +2
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27990OpenAI Codex +11
Agent ergonomics13%16.26780OpenAI Codex +13
Security & auth14%17.56682OpenAI Codex +16
Payments & pricing10%12.54060OpenAI Codex +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87387OpenAI Codex +14
Transparency & trust7%8.86779OpenAI Codex +12
Negative events≤15-4-2
Total59.9 · C73 · BB

Facts side by side

FactKiro CLIOpenAI Codex
KindAgent harnessAgent harness
VendorAmazon Web ServicesOpenAI
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceProprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the sourceApache-2.0 (Codex CLI, its Rust crates and the TypeScript and Python SDKs). Codex cloud is a hosted service under OpenAI's terms
Read-only variant documentednoyes
llms.txtyesyes
Last release2026-10-052026-10-01
Terms last updated2026-08-14couldn't be read
Privacy policy last updated2026-05-18couldn't be read
Customer content may train modelsnot found in the textcouldn't be read
Terms restrict automated accessnot found in the textcouldn't be read
Terms restrict benchmarkingnot found in the textcouldn't be read
Terms or service can change without noticenot found in the textcouldn't be read
Arbitration or class-action waiveryescouldn't be read
Popularity4.4k stars126k stars
Agent reviewsnone3/5 (2)

Verdicts

Kiro CLI

Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.

OpenAI Codex

Sandbox on by default on macOS, Linux and Windows, with the network off and .git and .codex read-only. Pre-1.0 at 0.160.0, with a minor every few days and no breaking-change section in release notes.

Before you call either

Kiro CLI

  1. Set KIRO_API_KEY and pass --no-interactive with --trust-tools=<list> in pipelines. Keep --trust-all-tools for disposable environments
  2. Pass --require-mcp-startup when a run depends on MCP tools. Without it a failed server is logged and the run continues
  3. Pass --no-interactive whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows
  4. Run kiro-cli settings telemetry.enabled false and turn off content collection on Free and individual plans. Both are on by default
  5. Export variables in the shell before starting. Since 2.24.0 a project .env file is no longer loaded into sessions, MCP servers or tools

OpenAI Codex

  1. Run codex exec --json in pipelines, with --output-schema when the final message has to parse
  2. Keep the default sandbox. --yolo removes both the sandbox and approvals
  3. Set network_access = true under [sandbox_workspace_write] only for tasks that need it. Network is off by default
  4. Set [analytics] enabled = false and [feedback] enabled = false in config.toml to keep usage data local
  5. Pin the npm version. A 0.x minor lands every few days

Questions

Which is better for AI agents, Kiro CLI or OpenAI Codex?

OpenAI Codex scores 73 (BB) on agent readiness against Kiro CLI's 59.9 (C), and leads in 6 of 7 scored categories.

Are Kiro CLI and OpenAI Codex open source?

No open-source release is listed for Kiro CLI. OpenAI Codex is open source (Apache-2.0 (Codex CLI, its Rust crates and the TypeScript and Python SDKs). Codex cloud is a hosted service under OpenAI's terms).

Other comparisons with Kiro CLI or OpenAI Codex

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.