Head to head · Agent multi agent · October 2026 research run

Kiro CLI vs Paperclip

Kiro CLI and Paperclip score within a point of each other on agent readiness, 59.9 (C) and 59 (C). Paperclip leads on reliability, payments & pricing and maintenance & community. Both do agent multi agent.

Which one, for what

Kiro CLI C

Good for Teams on AWS that want one agent configuration across terminal, IDE and web, with central permission policy, prompt logging to their own S3 bucket and IAM Identity Centre sign-in.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

Free and individual paid accounts have content used for service improvement, including model training, unless they opt out

Paperclip C

Good for Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.

Ahead on

  • Reliability, 66 against 57
  • Payments & pricing, 60 against 40
  • Maintenance & community, 78 against 73

Also in its favour

  • Open source

Watch for

claude_local defaults dangerouslySkipPermissions to true and codex_local defaults to bypassing approvals and the sandbox, with agents running on the host

Score by category

CategoryWeight this runKiro CLIPaperclipEdge
Reliability16%205766Paperclip +9
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27981Paperclip +2
Agent ergonomics13%16.26770Paperclip +3
Security & auth14%17.56664Kiro CLI +2
Payments & pricing10%12.54060Paperclip +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87378Paperclip +5
Transparency & trust7%8.86765Kiro CLI +2
Negative events≤15-4-10
Total59.9 · C59 · C

Facts side by side

FactKiro CLIPaperclip
KindAgent harnessAgent harness
VendorAmazon Web ServicesPaperclip Labs, Inc.
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyOAuth or key
PricingFreemiumFree
x402nono
LicenceProprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the sourceMIT
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-052026-10-05
Terms last updated2026-08-142026-07-23
Privacy policy last updated2026-05-182026-07-23
Customer content may train modelsnot found in the textyes, with an opt-out
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waiveryesyes
Popularity4.4k stars99k stars, 60k npm/wk

Verdicts

Kiro CLI

Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.

Paperclip

Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026.

Before you call either

Kiro CLI

  1. Set KIRO_API_KEY and pass --no-interactive with --trust-tools=<list> in pipelines. Keep --trust-all-tools for disposable environments
  2. Pass --require-mcp-startup when a run depends on MCP tools. Without it a failed server is logged and the run continues
  3. Pass --no-interactive whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows
  4. Run kiro-cli settings telemetry.enabled false and turn off content collection on Free and individual plans. Both are on by default
  5. Export variables in the shell before starting. Since 2.24.0 a project .env file is no longer loaded into sessions, MCP servers or tools

Paperclip

  1. Set PAPERCLIP_TELEMETRY_DISABLED=1 or DO_NOT_TRACK=1 before the first start. Telemetry is on by default
  2. Set dangerouslySkipPermissions and dangerouslyBypassApprovalsAndSandbox to false on agents that read untrusted input, or run them in a sandbox provider
  3. Install with Node.js 24.11 or newer, and install and sign in to each harness CLI on the host first. Paperclip assumes they are there
  4. Use --bind lan or --bind tailnet at onboarding for anything beyond one machine. The default local_trusted mode treats every request as the board admin
  5. Treat 409 on task checkout as owned by another agent and pick different work. The API docs say not to retry

Questions

Which is better for AI agents, Kiro CLI or Paperclip?

Kiro CLI and Paperclip score within a point of each other on agent readiness, 59.9 (C) and 59 (C). Paperclip leads on reliability, payments & pricing and maintenance & community.

Are Kiro CLI and Paperclip open source?

No open-source release is listed for Kiro CLI. Paperclip is open source (MIT).

Other comparisons with Kiro CLI or Paperclip

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.