{
  "data": {
    "a": {
      "slug": "kiro-cli",
      "name": "Kiro CLI",
      "vendor": "Amazon Web Services",
      "vendorUrl": "https://kiro.dev/cli/",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "AWS's coding agent for the terminal and the successor to the Amazon Q Developer CLI. It runs interactive chat, non-interactive runs for pipelines with an API key, MCP servers and an Agent Client Protocol server for editors.",
      "url": "https://www.anchorterminal.com/tools/kiro-cli",
      "markdownUrl": "https://www.anchorterminal.com/tools/kiro-cli.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kiro-cli.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kiro-cli.json",
      "repo": "https://github.com/kirodotdev/Kiro",
      "license": "Proprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the source",
      "transports": [],
      "packages": [],
      "auth": "mixed",
      "authNotes": "`kiro-cli login` with GitHub, Google, AWS Builder ID, AWS IAM Identity Centre or an external identity provider, in a browser or by device flow on a remote machine. Pipelines use an API key in `KIRO_API_KEY`, created at app.kiro.dev by Pro, Pro+, Pro Max and Power subscribers. Keys are long-lived, named and revocable, with no scopes, and API key generation is off by default for subscriptions an administrator manages. An active browser session takes precedence over the key.",
      "pricing": "freemium",
      "pricingNotes": "Kiro Free is $0 with 50 credits a month and a reduced model list. Pro is $20 a user a month with 1,000 credits, Pro+ $40 with 2,000, Pro Max $100 with 5,000 and Power $200 with 10,000, and extra credits cost $0.04 each. Models use credits at different rates (Auto is the 1.0x baseline). API keys for headless runs need a paid plan, and a paid plan needs a card. GovCloud prices are about 20 per cent higher with no free tier (checked 2026-10-08).",
      "priceSummary": "$20 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the CLI changelog (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4356,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://kiro.dev/docs/cli/",
      "llmsTxt": "https://kiro.dev/llms.txt",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "official",
        "harness",
        "coding-agent",
        "cli",
        "closed-source",
        "mcp",
        "acp",
        "llms-txt",
        "free-tier",
        "no-card",
        "telemetry-default-on"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.9,
        "grade": "C",
        "agentReady": false,
        "rank": 419,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 11,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 73,
          "payments": 40,
          "reliability": 57,
          "schema": 79,
          "security": 66,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-08-04. CVE-2026-18656 and CVE-2026-18657 (bulletin 2026-074-AWS), an uncontrolled search path on Windows let a planted executable in a crafted project directory run when a user opened it. Kiro CLI for Windows before 2.10.0 and Kiro IDE 1.0.0 to 1.0.212. Fixed and published with credit to the reporters, inside six months (https://aws.amazon.com/security/security-bulletins/2026-074-aws/). -2",
          "2026-05-22. CVE-2026-9255 (bulletin 2026-035-AWS), content piped to kiro-cli on stdin could answer the tool approval prompt, so a local actor could run tools and shell commands without the user's approval. kiro-cli before 1.28.0. Fixed and published, inside six months (https://aws.amazon.com/security/security-bulletins/2026-035-aws/). -2"
        ],
        "verdict": "Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.",
        "bestFor": "Teams on AWS that want one agent configuration across terminal, IDE and web, with central permission policy, prompt logging to their own S3 bucket and IAM Identity Centre sign-in.",
        "strengths": [
          "Capability permissions with deny over ask over allow, stored outside the repository so a clone can't add rules",
          "An untrusted workspace doesn't load its own agents, steering files, MCP configuration or skills, and asks before every shell command",
          "Headless runs with `--no-interactive`, JSON Lines output, and exit codes 3 and 4 for MCP startup and missing-agent failures",
          "Eleven minor releases between 26 August and 5 October 2026 in a dated changelog",
          "Plan prices, the $0.04 credit price and per-model credit multipliers are public, with a free tier of 50 credits a month"
        ],
        "weaknesses": [
          "Free and individual paid accounts have content used for service improvement, including model training, unless they opt out",
          "Closed source since it replaced the Apache 2.0 Amazon Q Developer CLI, with no public CI or test suite",
          "API keys for headless runs need a paid plan, are long-lived and carry no scopes",
          "No local sandbox in the CLI, and AWS says its managed permission policies are client-enforced and can be circumvented",
          "Two CVEs in 2026 (CVE-2026-9255 in May, CVE-2026-18656 and CVE-2026-18657 in August), both fixed"
        ],
        "agentNotes": [
          "Set `KIRO_API_KEY` and pass `--no-interactive` with `--trust-tools=\u003clist\u003e` in pipelines. Keep `--trust-all-tools` for disposable environments",
          "Pass `--require-mcp-startup` when a run depends on MCP tools. Without it a failed server is logged and the run continues",
          "Pass `--no-interactive` whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows",
          "Run `kiro-cli settings telemetry.enabled false` and turn off content collection on Free and individual plans. Both are on by default",
          "Export variables in the shell before starting. Since 2.24.0 a project `.env` file is no longer loaded into sessions, MCP servers or tools"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.9
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 73,
          "payments": 40,
          "reliability": 57,
          "schema": 79,
          "security": 66,
          "transparency": 62
        },
        "provenanceScore": 72
      },
      "connect": {
        "install": "curl -fsSL https://cli.kiro.dev/install | bash",
        "headless": {
          "run": "KIRO_API_KEY=ksk_... kiro-cli chat --no-interactive --trust-tools=read,grep \"Find all TODO comments in src/\""
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/kiro-cli"
      },
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "Kiro Pro",
          "unit": "month",
          "usd": 20,
          "note": "per user, with 1,000 credits"
        },
        {
          "item": "Add-on credit",
          "unit": "credit",
          "usd": 0.04,
          "note": "paid plans, beyond the plan's credits"
        }
      ],
      "provenance": {
        "legalEntity": "Amazon Web Services, Inc.",
        "domain": "kiro.dev",
        "domainRegistered": "2019-03-01",
        "endpointOnVendorDomain": null,
        "terms": "https://aws.amazon.com/agreement/",
        "privacy": "https://aws.amazon.com/privacy/",
        "statusPage": "",
        "changelog": "https://kiro.dev/changelog/cli/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "Kiro's licence page says the Kiro IDE and CLI are licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence. Section 50.14 of the AWS Service Terms names Amazon Web Services, Inc. as the contracting party for subscriptions bought through the Stripe portal.",
          "The AWS Customer Agreement (last updated 14 August 2026) governs use, with the AWS Service Terms sections 50.3 and 50.14 for Kiro. The AWS Privacy Notice (last updated 18 May 2026) is the privacy link in Kiro's footer.",
          "kiro.dev/.well-known/security.txt answers 404. aws.amazon.com publishes a security.txt whose Expires line reads 24 September 2026, which had passed when we read it.",
          "No status page for Kiro was found on kiro.dev or in its docs.",
          "RDAP (Google Registry) gives kiro.dev a registration date of 1 March 2019, before the product."
        ],
        "score": 72
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kiro-cli.json",
      "live": {
        "slug": "kiro-cli",
        "pages": [
          {
            "url": "https://kiro.dev/changelog/cli/",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-08T18:21:05.911888808Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f2b1951f0330"
          }
        ],
        "updatedAt": "2026-10-08T18:21:05.911888808Z"
      }
    },
    "answer": "Kiro CLI and Paperclip score within a point of each other on agent readiness, 59.9 (C) and 59 (C). Paperclip leads on reliability, payments \u0026 pricing and maintenance \u0026 community.",
    "b": {
      "slug": "paperclip",
      "name": "Paperclip",
      "vendor": "Paperclip Labs, Inc.",
      "vendorUrl": "https://paperclip.ing",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Paperclip is an open-source, self-hosted server and web interface that organises AI agents into a company with an org chart, tasks, budgets and approvals. It drives Claude Code, Codex, OpenClaw and other harnesses through adapters.",
      "url": "https://www.anchorterminal.com/tools/paperclip",
      "markdownUrl": "https://www.anchorterminal.com/tools/paperclip.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/paperclip.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/paperclip.json",
      "repo": "https://github.com/paperclipai/paperclip",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "paperclipai"
        },
        {
          "registry": "npm",
          "name": "@paperclipai/mcp-server"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/paperclipai/paperclip"
        }
      ],
      "auth": "mixed",
      "authNotes": "No Paperclip account. The default `local_trusted` mode needs no login on loopback. Authenticated mode uses browser sessions for people, board API keys for scripts, and agent API keys or short-lived run JWTs as bearer tokens.",
      "pricing": "free",
      "pricingNotes": "Free and MIT, self-hosted, with nothing to buy. The owner pays each harness's model provider or subscription. Paperclip Cloud is a waitlist with no published price.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the site or the server source (checked 2026-10-08). The only mention in the repository is a link to a third-party skill in a planning note.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 98666,
        "npmWeekly": 59684,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.paperclip.ing",
      "llmsTxt": "https://paperclip.ing/llms.txt",
      "capabilities": [
        "agent.multi-agent",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "free",
        "no-card",
        "llms-txt",
        "docker",
        "mcp",
        "typescript"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59,
        "grade": "C",
        "agentReady": false,
        "rank": 441,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 78,
          "payments": 60,
          "reliability": 66,
          "schema": 81,
          "security": 64,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "2026-04-10 to 2026-04-16. Ten advisories published in a week, four of them critical, among them GHSA-68qg-g8mg-6pr7 (CVE-2026-41679, 10.0, unauthenticated remote code execution through an import authorisation bypass) and two cross-tenant agent key flaws rated 9.9. All ten list 2026.416.0 as the fix. Fixed and published, a little under six months old, -5. https://github.com/paperclipai/paperclip/security/advisories",
          "2026-07-22. GHSA-x8hx-rhr2-9rf7 (9.6), drive-by remote code execution against the default `local_trusted` mode through DNS rebinding. The advisory names no patched version. The current source applies the hostname guard to `local_trusted` private deployments, so we read it as fixed without a documented version, -3. https://github.com/paperclipai/paperclip/security/advisories/GHSA-x8hx-rhr2-9rf7",
          "2026-04-16. GHSA-gqqj-85qm-8qhf (8.7), a `codex_local` agent inherited a Gmail connector from the owner's ChatGPT account and sent real email. The advisory names no patched version, and `codex_local` still defaults to bypassing approvals and the sandbox, -2. https://github.com/paperclipai/paperclip/security/advisories/GHSA-gqqj-85qm-8qhf"
        ],
        "verdict": "Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026.",
        "bestFor": "Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.",
        "strengths": [
          "One deployment runs agents on Claude Code, Codex, Cursor, Gemini CLI, OpenCode, Pi, Hermes, Grok Build, Kimi Code and OpenClaw through adapters, under one org chart",
          "Board approvals gate agent hires and the CEO agent's strategy, and connection actions can be set to Allowed, Ask first or Off",
          "Budgets by company, agent and project pause an agent at 100 per cent of recorded spend",
          "The running server publishes its REST surface as OpenAPI at `/api/openapi.json`, and the docs site answers every page as Markdown at `.md`",
          "Eleven stable releases between 20 July and 5 October 2026, each with dated notes and an upgrade guide"
        ],
        "weaknesses": [
          "`claude_local` defaults `dangerouslySkipPermissions` to true and `codex_local` defaults to bypassing approvals and the sandbox, with agents running on the host",
          "Twelve published security advisories since April 2026, five critical, including CVE-2026-41679 (unauthenticated remote code execution, fixed in 2026.416.0)",
          "Anonymous usage telemetry is on by default and goes to telemetry.paperclip.ing until an opt-out is set",
          "2,849 open issues on 8 October 2026, 1,396 of them with no comment, and 78 closed in 30 days against 686 opened",
          "Calendar versions with no 1.0, and release 2026.916.0 carried five breaking changes"
        ],
        "agentNotes": [
          "Set `PAPERCLIP_TELEMETRY_DISABLED=1` or `DO_NOT_TRACK=1` before the first start. Telemetry is on by default",
          "Set `dangerouslySkipPermissions` and `dangerouslyBypassApprovalsAndSandbox` to false on agents that read untrusted input, or run them in a sandbox provider",
          "Install with Node.js 24.11 or newer, and install and sign in to each harness CLI on the host first. Paperclip assumes they are there",
          "Use `--bind lan` or `--bind tailnet` at onboarding for anything beyond one machine. The default `local_trusted` mode treats every request as the board admin",
          "Treat 409 on task checkout as owned by another agent and pick different work. The API docs say not to retry"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 78,
          "payments": 60,
          "reliability": 66,
          "schema": 81,
          "security": 64,
          "transparency": 73
        },
        "provenanceScore": 56
      },
      "connect": {
        "install": "npx paperclipai@latest onboard --yes   # Node.js 24.11 or newer",
        "http": "curl http://localhost:3100/api/health",
        "headless": {
          "command": "npx paperclipai issue create --title \"$TASK\" --json",
          "env": {
            "PAPERCLIP_API_KEY": "\u003cboard or agent key\u003e",
            "PAPERCLIP_TELEMETRY_DISABLED": "1"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.multi-agent",
        "tool": "https://letme.dev/paperclip"
      },
      "area": "frameworks",
      "provenance": {
        "legalEntity": "Paperclip Labs, Inc.",
        "domain": "paperclip.ing",
        "domainRegistered": "2026-03-02",
        "endpointOnVendorDomain": null,
        "terms": "https://paperclip.ing/terms/",
        "privacy": "https://paperclip.ing/privacy/",
        "statusPage": "",
        "changelog": "https://paperclip.ing/changelog/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms (effective 1 April 2026, updated 23 July 2026) and the privacy policy (effective 23 July 2026) name Paperclip Labs, Inc. and Delaware law. The licence file in the repository reads Copyright (c) 2025 Paperclip AI.",
          "RDAP at the .ing registry gives a registration date of 2026-03-02 for paperclip.ing, with Cloudflare as registrar. The GitHub repository was created the same day.",
          "paperclip.ing/.well-known/security.txt and docs.paperclip.ing/.well-known/security.txt returned 404 on 8 October 2026. SECURITY.md sends reports to GitHub private advisories.",
          "The software is self-hosted, so there is no vendor endpoint or status page to check. status.paperclip.ing did not answer.",
          "The privacy policy says it governs the hosted services, and that a self-hosted deployment processes data on the owner's infrastructure."
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/paperclip.json",
      "live": {
        "slug": "paperclip",
        "versions": [
          {
            "registry": "github",
            "name": "paperclipai/paperclip",
            "version": "v2026.1005.0",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:24:44.149648743Z"
          },
          {
            "registry": "npm",
            "name": "@paperclipai/mcp-server",
            "version": "2026.1005.0",
            "seenAt": "2026-10-08T16:24:42.049344463Z"
          },
          {
            "registry": "npm",
            "name": "paperclipai",
            "version": "2026.1005.0",
            "seenAt": "2026-10-08T16:24:41.941235603Z"
          }
        ],
        "githubStars": 98744,
        "npmWeekly": 59684,
        "securityTxt": {
          "url": "https://paperclip.ing/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:09.089543926Z"
        },
        "pages": [
          {
            "url": "https://paperclip.ing/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:47.072089969Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4d68b2d18041"
          },
          {
            "url": "https://paperclip.ing/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:49.382016209Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d75ac8f8733e"
          },
          {
            "url": "https://paperclip.ing/terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:51.246933771Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1b2a133e6446"
          }
        ],
        "updatedAt": "2026-10-08T18:22:51.246933771Z"
      }
    },
    "facts": [
      {
        "a": "Agent harness",
        "b": "Agent harness",
        "name": "Kind"
      },
      {
        "a": "Amazon Web Services",
        "b": "Paperclip Labs, Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the source",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-05",
        "b": "2026-10-05",
        "name": "Last release"
      },
      {
        "a": "2026-08-14",
        "b": "2026-07-23",
        "name": "Terms last updated"
      },
      {
        "a": "2026-05-18",
        "b": "2026-07-23",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "yes, with an opt-out",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "4.4k stars",
        "b": "99k stars, 60k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Kiro CLI and Paperclip score within a point of each other on agent readiness, 59.9 (C) and 59 (C). Paperclip leads on reliability, payments \u0026 pricing and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Kiro CLI or Paperclip?"
      },
      {
        "answer": "No open-source release is listed for Kiro CLI. Paperclip is open source (MIT).",
        "question": "Are Kiro CLI and Paperclip open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": null,
        "goodFor": "Teams on AWS that want one agent configuration across terminal, IDE and web, with central permission policy, prompt logging to their own S3 bucket and IAM Identity Centre sign-in.",
        "slug": "kiro-cli",
        "watchFor": "Free and individual paid accounts have content used for service improvement, including model training, unless they opt out"
      },
      {
        "aheadOn": [
          "Reliability, 66 against 57",
          "Payments \u0026 pricing, 60 against 40",
          "Maintenance \u0026 community, 78 against 73"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.",
        "slug": "paperclip",
        "watchFor": "`claude_local` defaults `dangerouslySkipPermissions` to true and `codex_local` defaults to bypassing approvals and the sandbox, with agents running on the host"
      }
    ],
    "job": {
      "capability": "agent.multi-agent",
      "name": "Agent multi agent"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aider-vs-kiro-cli.json",
        "title": "Aider vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/aider-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-kiro-cli.json",
        "title": "Amp vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/amp-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-kiro-cli.json",
        "title": "Claude Code vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-kiro-cli.json",
        "title": "Cline vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/cline-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-kiro-cli.json",
        "title": "Cursor CLI vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-kiro-cli.json",
        "title": "Devin vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/devin-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli.json",
        "title": "Pi vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gemini-cli-vs-kiro-cli.json",
        "title": "Gemini CLI vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/gemini-cli-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-kiro-cli.json",
        "title": "GitHub Copilot CLI vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/goose-vs-kiro-cli.json",
        "title": "goose vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/goose-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-openai-codex.json",
        "title": "Kiro CLI vs OpenAI Codex",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-openai-codex"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-opencode.json",
        "title": "Kiro CLI vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-openhands.json",
        "title": "Kiro CLI vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-prime-agent.json",
        "title": "Kiro CLI vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-qwen-code.json",
        "title": "Kiro CLI vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-qwen-code"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-paperclip.json",
        "title": "Amp vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/amp-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-paperclip.json",
        "title": "Claude Code vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-paperclip.json",
        "title": "Cline vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/cline-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-paperclip.json",
        "title": "Devin vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/devin-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gemini-cli-vs-paperclip.json",
        "title": "Gemini CLI vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/gemini-cli-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-paperclip.json",
        "title": "GitHub Copilot CLI vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/goose-vs-paperclip.json",
        "title": "goose vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/goose-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opencode-vs-paperclip.json",
        "title": "OpenCode vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/opencode-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openhands-vs-paperclip.json",
        "title": "OpenHands vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/openhands-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paperclip-vs-prime-agent.json",
        "title": "Paperclip vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/paperclip-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paperclip-vs-qwen-code.json",
        "title": "Paperclip vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/paperclip-vs-qwen-code"
      }
    ],
    "scores": [
      {
        "by": 9,
        "edge": "paperclip",
        "key": "reliability",
        "kiro-cli": 57,
        "name": "Reliability",
        "paperclip": 66,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "paperclip",
        "key": "schema",
        "kiro-cli": 79,
        "name": "Schema \u0026 documentation",
        "paperclip": 81,
        "weight": 13
      },
      {
        "by": 3,
        "edge": "paperclip",
        "key": "ergonomics",
        "kiro-cli": 67,
        "name": "Agent ergonomics",
        "paperclip": 70,
        "weight": 13
      },
      {
        "by": 2,
        "edge": "kiro-cli",
        "key": "security",
        "kiro-cli": 66,
        "name": "Security \u0026 auth",
        "paperclip": 64,
        "weight": 14
      },
      {
        "by": 20,
        "edge": "paperclip",
        "key": "payments",
        "kiro-cli": 40,
        "name": "Payments \u0026 pricing",
        "paperclip": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 5,
        "edge": "paperclip",
        "key": "maintenance",
        "kiro-cli": 73,
        "name": "Maintenance \u0026 community",
        "paperclip": 78,
        "weight": 7
      },
      {
        "by": 2,
        "edge": "kiro-cli",
        "key": "transparency",
        "kiro-cli": 67,
        "name": "Transparency \u0026 trust",
        "paperclip": 65,
        "weight": 7
      }
    ],
    "summary": "Kiro CLI and Paperclip score within a point of each other on agent readiness, 59.9 (C) and 59 (C). Paperclip leads on reliability, payments \u0026 pricing and maintenance \u0026 community. Both do agent multi agent.",
    "verdicts": {
      "kiro-cli": "Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.",
      "paperclip": "Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip",
    "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.md",
    "slim": "https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.min.md"
  },
  "markdown": "Kiro CLI and Paperclip score within a point of each other on agent readiness, 59.9 (C) and 59 (C). Paperclip leads on reliability, payments \u0026 pricing and maintenance \u0026 community. Both do agent multi agent.\n\n- Kiro CLI: grade C, 59.9/100, rank #419 of 722. Markdown https://www.anchorterminal.com/tools/kiro-cli.md · JSON https://www.anchorterminal.com/api/v1/tools/kiro-cli.json\n- Paperclip: grade C, 59/100, rank #441 of 722. Markdown https://www.anchorterminal.com/tools/paperclip.md · JSON https://www.anchorterminal.com/api/v1/tools/paperclip.json\n\n## Which one, for what\n\n### Kiro CLI (C)\n\nGood for: Teams on AWS that want one agent configuration across terminal, IDE and web, with central permission policy, prompt logging to their own S3 bucket and IAM Identity Centre sign-in.\n\nWatch for: Free and individual paid accounts have content used for service improvement, including model training, unless they opt out\n\n### Paperclip (C)\n\nGood for: Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.\n\nAhead on:\n- Reliability, 66 against 57\n- Payments \u0026 pricing, 60 against 40\n- Maintenance \u0026 community, 78 against 73\n\nAlso in its favour:\n- Open source\n\nWatch for: `claude_local` defaults `dangerouslySkipPermissions` to true and `codex_local` defaults to bypassing approvals and the sandbox, with agents running on the host\n\n\n## Score by category\n\n| Category | Weight | Kiro CLI | Paperclip | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 57 | 66 | Paperclip +9 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 79 | 81 | Paperclip +2 |\n| Agent ergonomics | 13% (16.2 this run) | 67 | 70 | Paperclip +3 |\n| Security \u0026 auth | 14% (17.5 this run) | 66 | 64 | Kiro CLI +2 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 60 | Paperclip +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 73 | 78 | Paperclip +5 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 67 | 65 | Kiro CLI +2 |\n| Negative events | ≤15 | -4 | -10 | |\n| **Total** | | **59.9 · C** | **59 · C** | |\n\n## Facts side by side\n\n| Fact | Kiro CLI | Paperclip |\n| --- | --- | --- |\n| Kind | Agent harness | Agent harness |\n| Vendor | Amazon Web Services | Paperclip Labs, Inc. |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | Proprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the source | MIT |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-05 | 2026-10-05 |\n| Terms last updated | 2026-08-14 | 2026-07-23 |\n| Privacy policy last updated | 2026-05-18 | 2026-07-23 |\n| Customer content may train models | not found in the text | yes, with an opt-out |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | not found in the text | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | yes | yes |\n| Popularity | 4.4k stars | 99k stars, 60k npm/wk |\n\n## Verdicts\n\n**Kiro CLI.** Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.\n\n**Paperclip.** Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026.\n\n## Before you call either\n\n### Kiro CLI\n\n1. Set `KIRO_API_KEY` and pass `--no-interactive` with `--trust-tools=\u003clist\u003e` in pipelines. Keep `--trust-all-tools` for disposable environments\n2. Pass `--require-mcp-startup` when a run depends on MCP tools. Without it a failed server is logged and the run continues\n3. Pass `--no-interactive` whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows\n4. Run `kiro-cli settings telemetry.enabled false` and turn off content collection on Free and individual plans. Both are on by default\n5. Export variables in the shell before starting. Since 2.24.0 a project `.env` file is no longer loaded into sessions, MCP servers or tools\n\n### Paperclip\n\n1. Set `PAPERCLIP_TELEMETRY_DISABLED=1` or `DO_NOT_TRACK=1` before the first start. Telemetry is on by default\n2. Set `dangerouslySkipPermissions` and `dangerouslyBypassApprovalsAndSandbox` to false on agents that read untrusted input, or run them in a sandbox provider\n3. Install with Node.js 24.11 or newer, and install and sign in to each harness CLI on the host first. Paperclip assumes they are there\n4. Use `--bind lan` or `--bind tailnet` at onboarding for anything beyond one machine. The default `local_trusted` mode treats every request as the board admin\n5. Treat 409 on task checkout as owned by another agent and pick different work. The API docs say not to retry\n\n## Questions\n\n### Which is better for AI agents, Kiro CLI or Paperclip?\n\nKiro CLI and Paperclip score within a point of each other on agent readiness, 59.9 (C) and 59 (C). Paperclip leads on reliability, payments \u0026 pricing and maintenance \u0026 community.\n\n### Are Kiro CLI and Paperclip open source?\n\nNo open-source release is listed for Kiro CLI. Paperclip is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"kiro-cli\", \"b\": \"paperclip\"}`. From a terminal: `anchor compare kiro-cli paperclip`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/kiro-cli.json and https://www.anchorterminal.com/api/v1/tools/paperclip.json\n\n## Other comparisons with Kiro CLI or Paperclip\n\n- [Aider vs Kiro CLI](https://www.anchorterminal.com/compare/aider-vs-kiro-cli.md)\n- [Amp vs Kiro CLI](https://www.anchorterminal.com/compare/amp-vs-kiro-cli.md)\n- [Claude Code vs Kiro CLI](https://www.anchorterminal.com/compare/claude-code-vs-kiro-cli.md)\n- [Cline vs Kiro CLI](https://www.anchorterminal.com/compare/cline-vs-kiro-cli.md)\n- [Cursor CLI vs Kiro CLI](https://www.anchorterminal.com/compare/cursor-cli-vs-kiro-cli.md)\n- [Devin vs Kiro CLI](https://www.anchorterminal.com/compare/devin-vs-kiro-cli.md)\n- [Pi vs Kiro CLI](https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli.md)\n- [Gemini CLI vs Kiro CLI](https://www.anchorterminal.com/compare/gemini-cli-vs-kiro-cli.md)\n- [GitHub Copilot CLI vs Kiro CLI](https://www.anchorterminal.com/compare/github-copilot-cli-vs-kiro-cli.md)\n- [goose vs Kiro CLI](https://www.anchorterminal.com/compare/goose-vs-kiro-cli.md)\n- [Kiro CLI vs OpenAI Codex](https://www.anchorterminal.com/compare/kiro-cli-vs-openai-codex.md)\n- [Kiro CLI vs OpenCode](https://www.anchorterminal.com/compare/kiro-cli-vs-opencode.md)\n- [Kiro CLI vs OpenHands](https://www.anchorterminal.com/compare/kiro-cli-vs-openhands.md)\n- [Kiro CLI vs Prime Agent](https://www.anchorterminal.com/compare/kiro-cli-vs-prime-agent.md)\n- [Kiro CLI vs Qwen Code](https://www.anchorterminal.com/compare/kiro-cli-vs-qwen-code.md)\n- [Amp vs Paperclip](https://www.anchorterminal.com/compare/amp-vs-paperclip.md)\n- [Claude Code vs Paperclip](https://www.anchorterminal.com/compare/claude-code-vs-paperclip.md)\n- [Cline vs Paperclip](https://www.anchorterminal.com/compare/cline-vs-paperclip.md)\n- [Devin vs Paperclip](https://www.anchorterminal.com/compare/devin-vs-paperclip.md)\n- [Gemini CLI vs Paperclip](https://www.anchorterminal.com/compare/gemini-cli-vs-paperclip.md)\n- [GitHub Copilot CLI vs Paperclip](https://www.anchorterminal.com/compare/github-copilot-cli-vs-paperclip.md)\n- [goose vs Paperclip](https://www.anchorterminal.com/compare/goose-vs-paperclip.md)\n- [OpenCode vs Paperclip](https://www.anchorterminal.com/compare/opencode-vs-paperclip.md)\n- [OpenHands vs Paperclip](https://www.anchorterminal.com/compare/openhands-vs-paperclip.md)\n- [Paperclip vs Prime Agent](https://www.anchorterminal.com/compare/paperclip-vs-prime-agent.md)\n- [Paperclip vs Qwen Code](https://www.anchorterminal.com/compare/paperclip-vs-qwen-code.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Kiro CLI vs Paperclip",
        "url": ""
      }
    ],
    "description": "Kiro CLI and Paperclip score within a point of each other on agent readiness, 59.9 (C) and 59 (C). Paperclip leads on reliability, payments \u0026 pricing and maintenance \u0026 community. Both do agent multi agent. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Kiro CLI C 59.9",
      "Paperclip C 59",
      "scores"
    ],
    "h1": "Kiro CLI vs Paperclip",
    "image": "https://www.anchorterminal.com/assets/og/compare-kiro-cli-vs-paperclip.png",
    "path": "/compare/kiro-cli-vs-paperclip",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Kiro CLI vs Paperclip for AI agents, C 59.9 vs C 59 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip"
  },
  "tokens": {
    "markdown": 2400,
    "slim": 580
  },
  "version": 1
}
