Head to head · Agent harness · October 2026 research run

Kiro CLI vs Qwen Code

Qwen Code scores 72.4 (BB) on agent readiness against Kiro CLI's 59.9 (C), and leads in 5 of 7 scored categories. Kiro CLI leads on security & auth. Both do agent harness.

Which one, for what

Kiro CLI C

Good for Teams on AWS that want one agent configuration across terminal, IDE and web, with central permission policy, prompt logging to their own S3 bucket and IAM Identity Centre sign-in.

Ahead on

  • Security & auth, 66 against 53

Watch for

Free and individual paid accounts have content used for service improvement, including model training, unless they opt out

Qwen Code BB

Good for Developers and CI jobs that want an open-source harness tied to no single model vendor, with run budgets and SDKs.

Ahead on

  • Reliability, 69 against 57
  • Schema & documentation, 91 against 79
  • Agent ergonomics, 85 against 67
  • Payments & pricing, 60 against 40
  • Maintenance & community, 88 against 73

Also in its favour

  • Agent-ready, a grade of BB or better
  • Open source
  • No incidents deducted, where Kiro CLI loses 4 points for them

Watch for

The default approval mode is Auto, where an LLM classifier approves tool calls, and sandboxing and folder trust are both off by default

Score by category

CategoryWeight this runKiro CLIQwen CodeEdge
Reliability16%205769Qwen Code +12
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27991Qwen Code +12
Agent ergonomics13%16.26785Qwen Code +18
Security & auth14%17.56653Kiro CLI +13
Payments & pricing10%12.54060Qwen Code +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87388Qwen Code +15
Transparency & trust7%8.86763Kiro CLI +4
Negative events≤15-40
Total59.9 · C72.4 · BB

Facts side by side

FactKiro CLIQwen Code
KindAgent harnessAgent harness
VendorAmazon Web ServicesAlibaba (Qwen team)
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyAPI key
PricingFreemiumFree
x402nono
LicenceProprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the sourceApache-2.0
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-052026-10-05
Terms last updated2026-08-142026-10-01
Privacy policy last updated2026-05-182026-10-01
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waiveryesnot found in the text
Popularity4.4k stars28k stars, 105k npm/wk

Verdicts

Kiro CLI

Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.

Qwen Code

Apache-2.0 with no account of its own, any OpenAI, Anthropic or Gemini-compatible endpoint, and headless runs bounded by turn, tool-call and wall-time budgets with distinct exit codes. Out of the box, Auto mode lets an LLM classifier approve tool calls, with the sandbox and folder trust both off. Usage statistics are on by default.

Before you call either

Kiro CLI

  1. Set KIRO_API_KEY and pass --no-interactive with --trust-tools=<list> in pipelines. Keep --trust-all-tools for disposable environments
  2. Pass --require-mcp-startup when a run depends on MCP tools. Without it a failed server is logged and the run continues
  3. Pass --no-interactive whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows
  4. Run kiro-cli settings telemetry.enabled false and turn off content collection on Free and individual plans. Both are on by default
  5. Export variables in the shell before starting. Since 2.24.0 a project .env file is no longer loaded into sessions, MCP servers or tools

Qwen Code

  1. Pass --approval-mode on every run. The settings default is auto, and one docs page says headless runs default to asking, so don't rely on either
  2. Add --max-session-turns, --max-wall-time and --max-tool-calls. All three are unlimited by default. Exit 53 is the turn limit and 55 a budget
  3. --yolo doesn't turn on a sandbox. Add --sandbox, or on Linux set tools.executionSandbox with network set to closed
  4. Set QWEN_USAGE_STATISTICS_ENABLED=false to stop usage statistics
  5. Authenticate with OPENAI_API_KEY, OPENAI_BASE_URL and OPENAI_MODEL in CI. The browser sign-in is discontinued

Questions

Which is better for AI agents, Kiro CLI or Qwen Code?

Qwen Code scores 72.4 (BB) on agent readiness against Kiro CLI's 59.9 (C), and leads in 5 of 7 scored categories. Kiro CLI leads on security & auth.

Are Kiro CLI and Qwen Code open source?

No open-source release is listed for Kiro CLI. Qwen Code is open source (Apache-2.0).

Other comparisons with Kiro CLI or Qwen Code

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.