{
  "data": {
    "a": {
      "slug": "kiro-cli",
      "name": "Kiro CLI",
      "vendor": "Amazon Web Services",
      "vendorUrl": "https://kiro.dev/cli/",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "AWS's coding agent for the terminal and the successor to the Amazon Q Developer CLI. It runs interactive chat, non-interactive runs for pipelines with an API key, MCP servers and an Agent Client Protocol server for editors.",
      "url": "https://www.anchorterminal.com/tools/kiro-cli",
      "markdownUrl": "https://www.anchorterminal.com/tools/kiro-cli.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kiro-cli.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kiro-cli.json",
      "repo": "https://github.com/kirodotdev/Kiro",
      "license": "Proprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the source",
      "transports": [],
      "packages": [],
      "auth": "mixed",
      "authNotes": "`kiro-cli login` with GitHub, Google, AWS Builder ID, AWS IAM Identity Centre or an external identity provider, in a browser or by device flow on a remote machine. Pipelines use an API key in `KIRO_API_KEY`, created at app.kiro.dev by Pro, Pro+, Pro Max and Power subscribers. Keys are long-lived, named and revocable, with no scopes, and API key generation is off by default for subscriptions an administrator manages. An active browser session takes precedence over the key.",
      "pricing": "freemium",
      "pricingNotes": "Kiro Free is $0 with 50 credits a month and a reduced model list. Pro is $20 a user a month with 1,000 credits, Pro+ $40 with 2,000, Pro Max $100 with 5,000 and Power $200 with 10,000, and extra credits cost $0.04 each. Models use credits at different rates (Auto is the 1.0x baseline). API keys for headless runs need a paid plan, and a paid plan needs a card. GovCloud prices are about 20 per cent higher with no free tier (checked 2026-10-08).",
      "priceSummary": "$20 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the CLI changelog (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4356,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://kiro.dev/docs/cli/",
      "llmsTxt": "https://kiro.dev/llms.txt",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "official",
        "harness",
        "coding-agent",
        "cli",
        "closed-source",
        "mcp",
        "acp",
        "llms-txt",
        "free-tier",
        "no-card",
        "telemetry-default-on"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.9,
        "grade": "C",
        "agentReady": false,
        "rank": 370,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 11,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 73,
          "payments": 40,
          "reliability": 57,
          "schema": 79,
          "security": 66,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-08-04. CVE-2026-18656 and CVE-2026-18657 (bulletin 2026-074-AWS), an uncontrolled search path on Windows let a planted executable in a crafted project directory run when a user opened it. Kiro CLI for Windows before 2.10.0 and Kiro IDE 1.0.0 to 1.0.212. Fixed and published with credit to the reporters, inside six months (https://aws.amazon.com/security/security-bulletins/2026-074-aws/). -2",
          "2026-05-22. CVE-2026-9255 (bulletin 2026-035-AWS), content piped to kiro-cli on stdin could answer the tool approval prompt, so a local actor could run tools and shell commands without the user's approval. kiro-cli before 1.28.0. Fixed and published, inside six months (https://aws.amazon.com/security/security-bulletins/2026-035-aws/). -2"
        ],
        "verdict": "Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.",
        "bestFor": "Teams on AWS that want one agent configuration across terminal, IDE and web, with central permission policy, prompt logging to their own S3 bucket and IAM Identity Centre sign-in.",
        "strengths": [
          "Capability permissions with deny over ask over allow, stored outside the repository so a clone can't add rules",
          "An untrusted workspace doesn't load its own agents, steering files, MCP configuration or skills, and asks before every shell command",
          "Headless runs with `--no-interactive`, JSON Lines output, and exit codes 3 and 4 for MCP startup and missing-agent failures",
          "Eleven minor releases between 26 August and 5 October 2026 in a dated changelog",
          "Plan prices, the $0.04 credit price and per-model credit multipliers are public, with a free tier of 50 credits a month"
        ],
        "weaknesses": [
          "Free and individual paid accounts have content used for service improvement, including model training, unless they opt out",
          "Closed source since it replaced the Apache 2.0 Amazon Q Developer CLI, with no public CI or test suite",
          "API keys for headless runs need a paid plan, are long-lived and carry no scopes",
          "No local sandbox in the CLI, and AWS says its managed permission policies are client-enforced and can be circumvented",
          "Two CVEs in 2026 (CVE-2026-9255 in May, CVE-2026-18656 and CVE-2026-18657 in August), both fixed"
        ],
        "agentNotes": [
          "Set `KIRO_API_KEY` and pass `--no-interactive` with `--trust-tools=\u003clist\u003e` in pipelines. Keep `--trust-all-tools` for disposable environments",
          "Pass `--require-mcp-startup` when a run depends on MCP tools. Without it a failed server is logged and the run continues",
          "Pass `--no-interactive` whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows",
          "Run `kiro-cli settings telemetry.enabled false` and turn off content collection on Free and individual plans. Both are on by default",
          "Export variables in the shell before starting. Since 2.24.0 a project `.env` file is no longer loaded into sessions, MCP servers or tools"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.9
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 73,
          "payments": 40,
          "reliability": 57,
          "schema": 79,
          "security": 66,
          "transparency": 62
        },
        "provenanceScore": 72
      },
      "connect": {
        "install": "curl -fsSL https://cli.kiro.dev/install | bash",
        "headless": {
          "run": "KIRO_API_KEY=ksk_... kiro-cli chat --no-interactive --trust-tools=read,grep \"Find all TODO comments in src/\""
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/kiro-cli"
      },
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "Kiro Pro",
          "unit": "month",
          "usd": 20,
          "note": "per user, with 1,000 credits"
        },
        {
          "item": "Add-on credit",
          "unit": "credit",
          "usd": 0.04,
          "note": "paid plans, beyond the plan's credits"
        }
      ],
      "provenance": {
        "legalEntity": "Amazon Web Services, Inc.",
        "domain": "kiro.dev",
        "domainRegistered": "2019-03-01",
        "endpointOnVendorDomain": null,
        "terms": "https://aws.amazon.com/agreement/",
        "privacy": "https://aws.amazon.com/privacy/",
        "statusPage": "",
        "changelog": "https://kiro.dev/changelog/cli/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "Kiro's licence page says the Kiro IDE and CLI are licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence. Section 50.14 of the AWS Service Terms names Amazon Web Services, Inc. as the contracting party for subscriptions bought through the Stripe portal.",
          "The AWS Customer Agreement (last updated 14 August 2026) governs use, with the AWS Service Terms sections 50.3 and 50.14 for Kiro. The AWS Privacy Notice (last updated 18 May 2026) is the privacy link in Kiro's footer.",
          "kiro.dev/.well-known/security.txt answers 404. aws.amazon.com publishes a security.txt whose Expires line reads 24 September 2026, which had passed when we read it.",
          "No status page for Kiro was found on kiro.dev or in its docs.",
          "RDAP (Google Registry) gives kiro.dev a registration date of 1 March 2019, before the product."
        ],
        "score": 72
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kiro-cli.json",
      "live": {
        "slug": "kiro-cli",
        "pages": [
          {
            "url": "https://kiro.dev/changelog/cli/",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-08T18:21:05.911888808Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f2b1951f0330"
          }
        ],
        "updatedAt": "2026-10-08T18:21:05.911888808Z"
      }
    },
    "answer": "OpenCode scores 67.7 (B) on agent readiness against Kiro CLI's 59.9 (C), and leads in 5 of 7 scored categories. Kiro CLI leads on security \u0026 auth.",
    "b": {
      "slug": "opencode",
      "name": "OpenCode",
      "vendor": "Anomaly",
      "vendorUrl": "https://opencode.ai",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Open-source terminal coding agent from Anomaly Innovations, with a TUI, a desktop app in beta, IDE and ACP integration, and a headless HTTP server with an OpenAPI spec and a TypeScript SDK.",
      "url": "https://www.anchorterminal.com/tools/opencode",
      "markdownUrl": "https://www.anchorterminal.com/tools/opencode.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/opencode.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/opencode.json",
      "repo": "https://github.com/anomalyco/opencode",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "opencode-ai"
        },
        {
          "registry": "npm",
          "name": "@opencode-ai/sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No account needed. Provider keys go in with `opencode auth login` (stored in ~/.local/share/opencode/auth.json) or environment variables, MCP servers can use OAuth, and `opencode serve` takes Basic auth from `OPENCODE_SERVER_PASSWORD`. With no key it uses free OpenCode Zen models with a public key.",
      "pricing": "freemium",
      "pricingNotes": "Free and MIT. You pay your model provider, or OpenCode Zen per token, with prices per million tokens published for every model, or OpenCode Go at $10 a month (Go Plus $40) for a set of open models. Some Zen models are free for a limited time and may use prompts to improve the model.",
      "priceSummary": "$10 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-01).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 211000,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-01"
      },
      "docsUrl": "https://opencode.ai/docs",
      "openapi": "https://raw.githubusercontent.com/anomalyco/opencode/dev/packages/sdk/openapi.json",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "open-source",
        "local",
        "freemium",
        "typescript",
        "openapi",
        "no-card",
        "no-key",
        "usage-priced"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.7,
        "grade": "B",
        "agentReady": false,
        "rank": 186,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 79,
          "maintenance": 81,
          "payments": 60,
          "reliability": 68,
          "schema": 88,
          "security": 60,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-01-12. GHSA-vxw4-wv6m-9hhh (CVE-2026-22812, 8.8), the HTTP server the TUI started had no authentication, so local processes could run shell commands as the user, fixed in 1.0.216. GHSA-c83v-7274-4vgp (CVE-2026-22813), unsanitised Markdown in the web UI let a malicious page run commands on the machine, fixed in 1.1.10. Fixed, published and more than six months old, -1 each. https://github.com/anomalyco/opencode/security/advisories",
          "2026-09-24. GHSA-632h-h47v-g4x4 (7.5, no CVE). The server's `/global/upgrade` endpoint accepted any package specifier without checking where the request came from, so a web page could make `opencode serve` install an attacker's npm package and run its scripts. Fixed in 1.18.22. Inside six months, -2. https://github.com/anomalyco/opencode/security/advisories/GHSA-632h-h47v-g4x4"
        ],
        "verdict": "Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.",
        "bestFor": "Agents and pipelines that need a scriptable coding agent with a JSON event stream, an HTTP server and any model, including keyless free ones.",
        "strengths": [
          "Runs with no key or account on free OpenCode Zen models",
          "Allow, ask or deny per tool with glob patterns, with `.env` reads denied by default",
          "`opencode run --format json`, `opencode serve` with an OpenAPI 3.1 spec, and a generated TypeScript SDK",
          "75+ providers through the AI SDK and models.dev, plus local models",
          "No product telemetry found, and OpenTelemetry export is opt-in"
        ],
        "weaknesses": [
          "Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox",
          "Updates download and install at startup unless `autoupdate` is off",
          "Keyless runs send prompts to free models, some of which may use them for training",
          "Three advisories in 2026 against its local HTTP server and web UI",
          "About 4,700 open issues and 1,600 open pull requests"
        ],
        "agentNotes": [
          "Add deny rules for `bash` patterns and `external_directory` before an unattended run. Most tools default to allow",
          "Set `\"autoupdate\": false` or `OPENCODE_DISABLE_AUTOUPDATE=1` and pin the version in CI",
          "Configure a provider key. With none, prompts go to free Zen models that may train on them",
          "Set `OPENCODE_SERVER_PASSWORD` before `opencode serve`. Without it the server runs unauthenticated",
          "Use `opencode run --format json` and read the event stream rather than the formatted output"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.7
          }
        ],
        "editorialScores": {
          "ergonomics": 79,
          "maintenance": 81,
          "payments": 60,
          "reliability": 68,
          "schema": 88,
          "security": 60,
          "transparency": 82
        },
        "provenanceScore": 51
      },
      "connect": {
        "install": "npm i -g opencode-ai@latest   # or: curl -fsSL https://opencode.ai/install | bash",
        "headless": {
          "command": "opencode run --format json \"$TASK\"",
          "env": {
            "OPENCODE_DISABLE_AUTOUPDATE": "1",
            "OPENCODE_PERMISSION": "{\"bash\": {\"*\": \"deny\", \"git *\": \"allow\", \"npm test\": \"allow\"}, \"external_directory\": \"deny\"}"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/opencode"
      },
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "OpenCode Go",
          "unit": "month",
          "usd": 10,
          "note": "Go Plus is $40 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Anomaly Innovations, Inc.",
        "domain": "opencode.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "https://opencode.ai/legal/terms-of-service",
        "privacy": "https://opencode.ai/legal/privacy-policy",
        "statusPage": "",
        "changelog": "https://opencode.ai/changelog",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "The terms (effective 15 August 2026) name Anomaly Innovations, Inc. The privacy policy is effective 6 March 2026, with help@anoma.ly as the contact.",
          "opencode.ai/.well-known/security.txt returns 404. SECURITY.md points to GitHub private reporting and security@anoma.ly.",
          "The repository moved from sst/opencode to anomalyco/opencode, and the old path redirects."
        ],
        "score": 51
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/opencode.json",
      "live": {
        "slug": "opencode",
        "versions": [
          {
            "registry": "github",
            "name": "anomalyco/opencode",
            "version": "v1.18.35",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:24:02.134295107Z"
          },
          {
            "registry": "npm",
            "name": "@opencode-ai/sdk",
            "version": "1.18.35",
            "seenAt": "2026-10-08T16:23:59.938814313Z"
          },
          {
            "registry": "npm",
            "name": "opencode-ai",
            "version": "1.18.35",
            "seenAt": "2026-10-08T16:23:59.846603555Z"
          }
        ],
        "githubStars": 212339,
        "npmWeekly": 3318599,
        "securityTxt": {
          "url": "https://opencode.ai/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:34.556967284Z"
        },
        "domain": {
          "domain": "opencode.ai",
          "registered": "2022-12-07",
          "source": "https://rdap.identitydigital.services/rdap/domain/opencode.ai",
          "checkedAt": "2026-10-04T13:08:49.460678183Z"
        },
        "pages": [
          {
            "url": "https://opencode.ai/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:35.556443116Z",
            "changedAt": "2026-10-07T18:07:58.575118389Z",
            "fingerprint": "b71cb3507f94"
          },
          {
            "url": "https://opencode.ai/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:37.732621977Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "be82d391bf89"
          },
          {
            "url": "https://opencode.ai/legal/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:39.767686703Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "63cbae74f05e"
          }
        ],
        "updatedAt": "2026-10-08T18:22:39.767686703Z"
      }
    },
    "facts": [
      {
        "a": "Agent harness",
        "b": "Agent harness",
        "name": "Kind"
      },
      {
        "a": "Amazon Web Services",
        "b": "Anomaly",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the source",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-05",
        "b": "2026-09-30",
        "name": "Last release"
      },
      {
        "a": "2026-08-14",
        "b": "2026-08-15",
        "name": "Terms last updated"
      },
      {
        "a": "2026-05-18",
        "b": "2026-03-06",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "4.4k stars",
        "b": "211k stars",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "2/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "OpenCode scores 67.7 (B) on agent readiness against Kiro CLI's 59.9 (C), and leads in 5 of 7 scored categories. Kiro CLI leads on security \u0026 auth.",
        "question": "Which is better for AI agents, Kiro CLI or OpenCode?"
      },
      {
        "answer": "No open-source release is listed for Kiro CLI. OpenCode is open source (MIT).",
        "question": "Are Kiro CLI and OpenCode open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Security \u0026 auth, 66 against 60"
        ],
        "also": null,
        "goodFor": "Teams on AWS that want one agent configuration across terminal, IDE and web, with central permission policy, prompt logging to their own S3 bucket and IAM Identity Centre sign-in.",
        "slug": "kiro-cli",
        "watchFor": "Free and individual paid accounts have content used for service improvement, including model training, unless they opt out"
      },
      {
        "aheadOn": [
          "Reliability, 68 against 57",
          "Schema \u0026 documentation, 88 against 79",
          "Agent ergonomics, 79 against 67",
          "Payments \u0026 pricing, 60 against 40",
          "Maintenance \u0026 community, 81 against 73"
        ],
        "also": [
          "No key needed to call it",
          "Open source"
        ],
        "goodFor": "Agents and pipelines that need a scriptable coding agent with a JSON event stream, an HTTP server and any model, including keyless free ones.",
        "slug": "opencode",
        "watchFor": "Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox"
      }
    ],
    "job": {
      "capability": "agent.harness",
      "name": "Agent harness"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aider-vs-kiro-cli.json",
        "title": "Aider vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/aider-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aider-vs-opencode.json",
        "title": "Aider vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/aider-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-kiro-cli.json",
        "title": "Amp vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/amp-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-opencode.json",
        "title": "Amp vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/amp-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-kiro-cli.json",
        "title": "Claude Code vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-opencode.json",
        "title": "Claude Code vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-kiro-cli.json",
        "title": "Cline vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/cline-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-opencode.json",
        "title": "Cline vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/cline-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-kiro-cli.json",
        "title": "Cursor CLI vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-opencode.json",
        "title": "Cursor CLI vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-kiro-cli.json",
        "title": "Devin vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/devin-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-opencode.json",
        "title": "Devin vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/devin-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli.json",
        "title": "Pi vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-opencode.json",
        "title": "Pi vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gemini-cli-vs-kiro-cli.json",
        "title": "Gemini CLI vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/gemini-cli-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gemini-cli-vs-opencode.json",
        "title": "Gemini CLI vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/gemini-cli-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-kiro-cli.json",
        "title": "GitHub Copilot CLI vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode.json",
        "title": "GitHub Copilot CLI vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/goose-vs-kiro-cli.json",
        "title": "goose vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/goose-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/goose-vs-opencode.json",
        "title": "goose vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/goose-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-openai-codex.json",
        "title": "Kiro CLI vs OpenAI Codex",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-openai-codex"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-openhands.json",
        "title": "Kiro CLI vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-prime-agent.json",
        "title": "Kiro CLI vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-qwen-code.json",
        "title": "Kiro CLI vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-qwen-code"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openai-codex-vs-opencode.json",
        "title": "OpenAI Codex vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/openai-codex-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opencode-vs-openhands.json",
        "title": "OpenCode vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/opencode-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opencode-vs-prime-agent.json",
        "title": "OpenCode vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/opencode-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opencode-vs-qwen-code.json",
        "title": "OpenCode vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/opencode-vs-qwen-code"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.json",
        "title": "Kiro CLI vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opencode-vs-paperclip.json",
        "title": "OpenCode vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/opencode-vs-paperclip"
      }
    ],
    "scores": [
      {
        "by": 11,
        "edge": "opencode",
        "key": "reliability",
        "kiro-cli": 57,
        "name": "Reliability",
        "opencode": 68,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 9,
        "edge": "opencode",
        "key": "schema",
        "kiro-cli": 79,
        "name": "Schema \u0026 documentation",
        "opencode": 88,
        "weight": 13
      },
      {
        "by": 12,
        "edge": "opencode",
        "key": "ergonomics",
        "kiro-cli": 67,
        "name": "Agent ergonomics",
        "opencode": 79,
        "weight": 13
      },
      {
        "by": 6,
        "edge": "kiro-cli",
        "key": "security",
        "kiro-cli": 66,
        "name": "Security \u0026 auth",
        "opencode": 60,
        "weight": 14
      },
      {
        "by": 20,
        "edge": "opencode",
        "key": "payments",
        "kiro-cli": 40,
        "name": "Payments \u0026 pricing",
        "opencode": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 8,
        "edge": "opencode",
        "key": "maintenance",
        "kiro-cli": 73,
        "name": "Maintenance \u0026 community",
        "opencode": 81,
        "weight": 7
      },
      {
        "by": 0,
        "edge": "",
        "key": "transparency",
        "kiro-cli": 67,
        "name": "Transparency \u0026 trust",
        "opencode": 67,
        "weight": 7
      }
    ],
    "summary": "OpenCode scores 67.7 (B) on agent readiness against Kiro CLI's 59.9 (C), and leads in 5 of 7 scored categories. Kiro CLI leads on security \u0026 auth. Both do agent harness.",
    "verdicts": {
      "kiro-cli": "Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.",
      "opencode": "Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/kiro-cli-vs-opencode",
    "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-opencode.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/kiro-cli-vs-opencode.md",
    "slim": "https://www.anchorterminal.com/compare/kiro-cli-vs-opencode.min.md"
  },
  "markdown": "OpenCode scores 67.7 (B) on agent readiness against Kiro CLI's 59.9 (C), and leads in 5 of 7 scored categories. Kiro CLI leads on security \u0026 auth. Both do agent harness.\n\n- Kiro CLI: grade C, 59.9/100, rank #370 of 629. Markdown https://www.anchorterminal.com/tools/kiro-cli.md · JSON https://www.anchorterminal.com/api/v1/tools/kiro-cli.json\n- OpenCode: grade B, 67.7/100, rank #186 of 629. Markdown https://www.anchorterminal.com/tools/opencode.md · JSON https://www.anchorterminal.com/api/v1/tools/opencode.json\n\n## Which one, for what\n\n### Kiro CLI (C)\n\nGood for: Teams on AWS that want one agent configuration across terminal, IDE and web, with central permission policy, prompt logging to their own S3 bucket and IAM Identity Centre sign-in.\n\nAhead on:\n- Security \u0026 auth, 66 against 60\n\nWatch for: Free and individual paid accounts have content used for service improvement, including model training, unless they opt out\n\n### OpenCode (B)\n\nGood for: Agents and pipelines that need a scriptable coding agent with a JSON event stream, an HTTP server and any model, including keyless free ones.\n\nAhead on:\n- Reliability, 68 against 57\n- Schema \u0026 documentation, 88 against 79\n- Agent ergonomics, 79 against 67\n- Payments \u0026 pricing, 60 against 40\n- Maintenance \u0026 community, 81 against 73\n\nAlso in its favour:\n- No key needed to call it\n- Open source\n\nWatch for: Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox\n\n\n## Score by category\n\n| Category | Weight | Kiro CLI | OpenCode | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 57 | 68 | OpenCode +11 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 79 | 88 | OpenCode +9 |\n| Agent ergonomics | 13% (16.2 this run) | 67 | 79 | OpenCode +12 |\n| Security \u0026 auth | 14% (17.5 this run) | 66 | 60 | Kiro CLI +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 60 | OpenCode +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 73 | 81 | OpenCode +8 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 67 | 67 | even |\n| Negative events | ≤15 | -4 | -4 | |\n| **Total** | | **59.9 · C** | **67.7 · B** | |\n\n## Facts side by side\n\n| Fact | Kiro CLI | OpenCode |\n| --- | --- | --- |\n| Kind | Agent harness | Agent harness |\n| Vendor | Amazon Web Services | Anomaly |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | OAuth or key | None |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the source | MIT |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| Last release | 2026-10-05 | 2026-09-30 |\n| Terms last updated | 2026-08-14 | 2026-08-15 |\n| Privacy policy last updated | 2026-05-18 | 2026-03-06 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | yes | yes |\n| Popularity | 4.4k stars | 211k stars |\n| Agent reviews | none | 2/5 (2) |\n\n## Verdicts\n\n**Kiro CLI.** Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.\n\n**OpenCode.** Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.\n\n## Before you call either\n\n### Kiro CLI\n\n1. Set `KIRO_API_KEY` and pass `--no-interactive` with `--trust-tools=\u003clist\u003e` in pipelines. Keep `--trust-all-tools` for disposable environments\n2. Pass `--require-mcp-startup` when a run depends on MCP tools. Without it a failed server is logged and the run continues\n3. Pass `--no-interactive` whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows\n4. Run `kiro-cli settings telemetry.enabled false` and turn off content collection on Free and individual plans. Both are on by default\n5. Export variables in the shell before starting. Since 2.24.0 a project `.env` file is no longer loaded into sessions, MCP servers or tools\n\n### OpenCode\n\n1. Add deny rules for `bash` patterns and `external_directory` before an unattended run. Most tools default to allow\n2. Set `\"autoupdate\": false` or `OPENCODE_DISABLE_AUTOUPDATE=1` and pin the version in CI\n3. Configure a provider key. With none, prompts go to free Zen models that may train on them\n4. Set `OPENCODE_SERVER_PASSWORD` before `opencode serve`. Without it the server runs unauthenticated\n5. Use `opencode run --format json` and read the event stream rather than the formatted output\n\n## Questions\n\n### Which is better for AI agents, Kiro CLI or OpenCode?\n\nOpenCode scores 67.7 (B) on agent readiness against Kiro CLI's 59.9 (C), and leads in 5 of 7 scored categories. Kiro CLI leads on security \u0026 auth.\n\n### Are Kiro CLI and OpenCode open source?\n\nNo open-source release is listed for Kiro CLI. OpenCode is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/kiro-cli-vs-opencode.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kiro-cli-vs-opencode.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"kiro-cli\", \"b\": \"opencode\"}`. From a terminal: `anchor compare kiro-cli opencode`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/kiro-cli.json and https://www.anchorterminal.com/api/v1/tools/opencode.json\n\n## Other comparisons with Kiro CLI or OpenCode\n\n- [Aider vs Kiro CLI](https://www.anchorterminal.com/compare/aider-vs-kiro-cli.md)\n- [Aider vs OpenCode](https://www.anchorterminal.com/compare/aider-vs-opencode.md)\n- [Amp vs Kiro CLI](https://www.anchorterminal.com/compare/amp-vs-kiro-cli.md)\n- [Amp vs OpenCode](https://www.anchorterminal.com/compare/amp-vs-opencode.md)\n- [Claude Code vs Kiro CLI](https://www.anchorterminal.com/compare/claude-code-vs-kiro-cli.md)\n- [Claude Code vs OpenCode](https://www.anchorterminal.com/compare/claude-code-vs-opencode.md)\n- [Cline vs Kiro CLI](https://www.anchorterminal.com/compare/cline-vs-kiro-cli.md)\n- [Cline vs OpenCode](https://www.anchorterminal.com/compare/cline-vs-opencode.md)\n- [Cursor CLI vs Kiro CLI](https://www.anchorterminal.com/compare/cursor-cli-vs-kiro-cli.md)\n- [Cursor CLI vs OpenCode](https://www.anchorterminal.com/compare/cursor-cli-vs-opencode.md)\n- [Devin vs Kiro CLI](https://www.anchorterminal.com/compare/devin-vs-kiro-cli.md)\n- [Devin vs OpenCode](https://www.anchorterminal.com/compare/devin-vs-opencode.md)\n- [Pi vs Kiro CLI](https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli.md)\n- [Pi vs OpenCode](https://www.anchorterminal.com/compare/earendil-pi-vs-opencode.md)\n- [Gemini CLI vs Kiro CLI](https://www.anchorterminal.com/compare/gemini-cli-vs-kiro-cli.md)\n- [Gemini CLI vs OpenCode](https://www.anchorterminal.com/compare/gemini-cli-vs-opencode.md)\n- [GitHub Copilot CLI vs Kiro CLI](https://www.anchorterminal.com/compare/github-copilot-cli-vs-kiro-cli.md)\n- [GitHub Copilot CLI vs OpenCode](https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode.md)\n- [goose vs Kiro CLI](https://www.anchorterminal.com/compare/goose-vs-kiro-cli.md)\n- [goose vs OpenCode](https://www.anchorterminal.com/compare/goose-vs-opencode.md)\n- [Kiro CLI vs OpenAI Codex](https://www.anchorterminal.com/compare/kiro-cli-vs-openai-codex.md)\n- [Kiro CLI vs OpenHands](https://www.anchorterminal.com/compare/kiro-cli-vs-openhands.md)\n- [Kiro CLI vs Prime Agent](https://www.anchorterminal.com/compare/kiro-cli-vs-prime-agent.md)\n- [Kiro CLI vs Qwen Code](https://www.anchorterminal.com/compare/kiro-cli-vs-qwen-code.md)\n- [OpenAI Codex vs OpenCode](https://www.anchorterminal.com/compare/openai-codex-vs-opencode.md)\n- [OpenCode vs OpenHands](https://www.anchorterminal.com/compare/opencode-vs-openhands.md)\n- [OpenCode vs Prime Agent](https://www.anchorterminal.com/compare/opencode-vs-prime-agent.md)\n- [OpenCode vs Qwen Code](https://www.anchorterminal.com/compare/opencode-vs-qwen-code.md)\n- [Kiro CLI vs Paperclip](https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.md)\n- [OpenCode vs Paperclip](https://www.anchorterminal.com/compare/opencode-vs-paperclip.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Kiro CLI vs OpenCode",
        "url": ""
      }
    ],
    "description": "OpenCode scores 67.7 (B) on agent readiness against Kiro CLI's 59.9 (C), and leads in 5 of 7 scored categories. Kiro CLI leads on security \u0026 auth. Both do agent harness. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Kiro CLI C 59.9",
      "OpenCode B 67.7",
      "scores"
    ],
    "h1": "Kiro CLI vs OpenCode",
    "image": "https://www.anchorterminal.com/assets/og/compare-kiro-cli-vs-opencode.png",
    "path": "/compare/kiro-cli-vs-opencode",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Kiro CLI vs OpenCode for AI agents, C 59.9 vs B 67.7 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-opencode"
  },
  "tokens": {
    "markdown": 2400,
    "slim": 630
  },
  "version": 1
}
