Head to head · Agent harness · October 2026 research run

Kiro CLI vs OpenCode

OpenCode scores 67.7 (B) on agent readiness against Kiro CLI's 59.9 (C), and leads in 5 of 7 scored categories. Kiro CLI leads on security & auth. Both do agent harness.

Which one, for what

Kiro CLI C

Good for Teams on AWS that want one agent configuration across terminal, IDE and web, with central permission policy, prompt logging to their own S3 bucket and IAM Identity Centre sign-in.

Ahead on

  • Security & auth, 66 against 60

Watch for

Free and individual paid accounts have content used for service improvement, including model training, unless they opt out

OpenCode B

Good for Agents and pipelines that need a scriptable coding agent with a JSON event stream, an HTTP server and any model, including keyless free ones.

Ahead on

  • Reliability, 68 against 57
  • Schema & documentation, 88 against 79
  • Agent ergonomics, 79 against 67
  • Payments & pricing, 60 against 40
  • Maintenance & community, 81 against 73

Also in its favour

  • No key needed to call it
  • Open source

Watch for

Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox

Score by category

CategoryWeight this runKiro CLIOpenCodeEdge
Reliability16%205768OpenCode +11
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27988OpenCode +9
Agent ergonomics13%16.26779OpenCode +12
Security & auth14%17.56660Kiro CLI +6
Payments & pricing10%12.54060OpenCode +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87381OpenCode +8
Transparency & trust7%8.86767even
Negative events≤15-4-4
Total59.9 · C67.7 · B

Facts side by side

FactKiro CLIOpenCode
KindAgent harnessAgent harness
VendorAmazon Web ServicesAnomaly
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyNone
PricingFreemiumFreemium
x402nono
LicenceProprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the sourceMIT
Read-only variant documentednono
llms.txtyesno
Last release2026-10-052026-09-30
Terms last updated2026-08-142026-08-15
Privacy policy last updated2026-05-182026-03-06
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textyes
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waiveryesyes
Popularity4.4k stars211k stars
Agent reviewsnone2/5 (2)

Verdicts

Kiro CLI

Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.

OpenCode

Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.

Before you call either

Kiro CLI

  1. Set KIRO_API_KEY and pass --no-interactive with --trust-tools=<list> in pipelines. Keep --trust-all-tools for disposable environments
  2. Pass --require-mcp-startup when a run depends on MCP tools. Without it a failed server is logged and the run continues
  3. Pass --no-interactive whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows
  4. Run kiro-cli settings telemetry.enabled false and turn off content collection on Free and individual plans. Both are on by default
  5. Export variables in the shell before starting. Since 2.24.0 a project .env file is no longer loaded into sessions, MCP servers or tools

OpenCode

  1. Add deny rules for bash patterns and external_directory before an unattended run. Most tools default to allow
  2. Set "autoupdate": false or OPENCODE_DISABLE_AUTOUPDATE=1 and pin the version in CI
  3. Configure a provider key. With none, prompts go to free Zen models that may train on them
  4. Set OPENCODE_SERVER_PASSWORD before opencode serve. Without it the server runs unauthenticated
  5. Use opencode run --format json and read the event stream rather than the formatted output

Questions

Which is better for AI agents, Kiro CLI or OpenCode?

OpenCode scores 67.7 (B) on agent readiness against Kiro CLI's 59.9 (C), and leads in 5 of 7 scored categories. Kiro CLI leads on security & auth.

Are Kiro CLI and OpenCode open source?

No open-source release is listed for Kiro CLI. OpenCode is open source (MIT).

Other comparisons with Kiro CLI or OpenCode

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.