{
  "data": {
    "a": {
      "slug": "opencode",
      "name": "OpenCode",
      "vendor": "Anomaly",
      "vendorUrl": "https://opencode.ai",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Open-source terminal coding agent from Anomaly Innovations, with a TUI, a desktop app in beta, IDE and ACP integration, and a headless HTTP server with an OpenAPI spec and a TypeScript SDK.",
      "url": "https://www.anchorterminal.com/tools/opencode",
      "markdownUrl": "https://www.anchorterminal.com/tools/opencode.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/opencode.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/opencode.json",
      "repo": "https://github.com/anomalyco/opencode",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "opencode-ai"
        },
        {
          "registry": "npm",
          "name": "@opencode-ai/sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No account needed. Provider keys go in with `opencode auth login` (stored in ~/.local/share/opencode/auth.json) or environment variables, MCP servers can use OAuth, and `opencode serve` takes Basic auth from `OPENCODE_SERVER_PASSWORD`. With no key it uses free OpenCode Zen models with a public key.",
      "pricing": "freemium",
      "pricingNotes": "Free and MIT. You pay your model provider, or OpenCode Zen per token, with prices per million tokens published for every model, or OpenCode Go at $10 a month (Go Plus $40) for a set of open models. Some Zen models are free for a limited time and may use prompts to improve the model.",
      "priceSummary": "$10 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-01).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 211000,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-01"
      },
      "docsUrl": "https://opencode.ai/docs",
      "openapi": "https://raw.githubusercontent.com/anomalyco/opencode/dev/packages/sdk/openapi.json",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "open-source",
        "local",
        "freemium",
        "typescript",
        "openapi",
        "no-card",
        "no-key",
        "usage-priced"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68,
        "grade": "B",
        "agentReady": false,
        "rank": 134,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 5,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 79,
          "maintenance": 81,
          "payments": 60,
          "reliability": 68,
          "schema": 88,
          "security": 60,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-01-12. GHSA-vxw4-wv6m-9hhh (CVE-2026-22812, 8.8), the HTTP server the TUI started had no authentication, so local processes could run shell commands as the user, fixed in 1.0.216. GHSA-c83v-7274-4vgp (CVE-2026-22813), unsanitised Markdown in the web UI let a malicious page run commands on the machine, fixed in 1.1.10. Fixed, published and more than six months old, -1 each. https://github.com/anomalyco/opencode/security/advisories",
          "2026-09-24. GHSA-632h-h47v-g4x4 (7.5, no CVE). The server's `/global/upgrade` endpoint accepted any package specifier without checking where the request came from, so a web page could make `opencode serve` install an attacker's npm package and run its scripts. Fixed in 1.18.22. Inside six months, -2. https://github.com/anomalyco/opencode/security/advisories/GHSA-632h-h47v-g4x4"
        ],
        "verdict": "Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.",
        "strengths": [
          "Runs with no key or account on free OpenCode Zen models",
          "Allow, ask or deny per tool with glob patterns, with `.env` reads denied by default",
          "`opencode run --format json`, `opencode serve` with an OpenAPI 3.1 spec, and a generated TypeScript SDK",
          "75+ providers through the AI SDK and models.dev, plus local models",
          "No product telemetry found, and OpenTelemetry export is opt-in"
        ],
        "weaknesses": [
          "Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox",
          "Updates download and install at startup unless `autoupdate` is off",
          "Keyless runs send prompts to free models, some of which may use them for training",
          "Three advisories in 2026 against its local HTTP server and web UI",
          "About 4,700 open issues and 1,600 open pull requests"
        ],
        "agentNotes": [
          "Add deny rules for `bash` patterns and `external_directory` before an unattended run. Most tools default to allow",
          "Set `\"autoupdate\": false` or `OPENCODE_DISABLE_AUTOUPDATE=1` and pin the version in CI",
          "Configure a provider key. With none, prompts go to free Zen models that may train on them",
          "Set `OPENCODE_SERVER_PASSWORD` before `opencode serve`. Without it the server runs unauthenticated",
          "Use `opencode run --format json` and read the event stream rather than the formatted output"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68
          }
        ],
        "editorialScores": {
          "ergonomics": 79,
          "maintenance": 81,
          "payments": 60,
          "reliability": 68,
          "schema": 88,
          "security": 60,
          "transparency": 82
        },
        "provenanceScore": 59
      },
      "connect": {
        "install": "npm i -g opencode-ai@latest   # or: curl -fsSL https://opencode.ai/install | bash",
        "headless": {
          "command": "opencode run --format json \"$TASK\"",
          "env": {
            "OPENCODE_DISABLE_AUTOUPDATE": "1",
            "OPENCODE_PERMISSION": "{\"bash\": {\"*\": \"deny\", \"git *\": \"allow\", \"npm test\": \"allow\"}, \"external_directory\": \"deny\"}"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/opencode"
      },
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "OpenCode Go",
          "unit": "month",
          "usd": 10,
          "note": "Go Plus is $40 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Anomaly Innovations, Inc.",
        "domain": "opencode.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "https://opencode.ai/legal/terms-of-service",
        "privacy": "https://opencode.ai/legal/privacy-policy",
        "statusPage": "",
        "changelog": "https://opencode.ai/changelog",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "The terms (effective 15 August 2026) name Anomaly Innovations, Inc. The privacy policy is effective 6 March 2026, with help@anoma.ly as the contact.",
          "opencode.ai/.well-known/security.txt returns 404. SECURITY.md points to GitHub private reporting and security@anoma.ly.",
          "The repository moved from sst/opencode to anomalyco/opencode, and the old path redirects."
        ],
        "score": 59
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/opencode.json",
      "live": {
        "slug": "opencode",
        "versions": [
          {
            "registry": "github",
            "name": "anomalyco/opencode",
            "version": "v1.18.34",
            "released": "2026-09-30",
            "seenAt": "2026-10-04T16:35:50.008649469Z"
          },
          {
            "registry": "npm",
            "name": "@opencode-ai/sdk",
            "version": "1.18.34",
            "seenAt": "2026-10-04T16:35:48.480232858Z"
          },
          {
            "registry": "npm",
            "name": "opencode-ai",
            "version": "1.18.34",
            "seenAt": "2026-10-04T16:35:47.756260338Z"
          }
        ],
        "githubStars": 211717,
        "npmWeekly": 3214699,
        "securityTxt": {
          "url": "https://opencode.ai/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:00.878836941Z"
        },
        "domain": {
          "domain": "opencode.ai",
          "registered": "2022-12-07",
          "source": "https://rdap.identitydigital.services/rdap/domain/opencode.ai",
          "checkedAt": "2026-10-04T13:08:49.460678183Z"
        },
        "pages": [
          {
            "url": "https://opencode.ai/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:26.085908935Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "de27126a88fa"
          },
          {
            "url": "https://opencode.ai/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:28.272573663Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "be82d391bf89"
          },
          {
            "url": "https://opencode.ai/legal/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:30.257750648Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "63cbae74f05e"
          }
        ],
        "updatedAt": "2026-10-04T16:35:50.008649469Z"
      }
    },
    "b": {
      "slug": "openhands",
      "name": "OpenHands",
      "vendor": "All Hands AI",
      "vendorUrl": "https://openhands.dev",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Open-source coding agent with a self-hosted web interface, local and remote execution, and scheduled or webhook-driven automation.",
      "url": "https://www.anchorterminal.com/tools/openhands",
      "markdownUrl": "https://www.anchorterminal.com/tools/openhands.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openhands.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openhands.json",
      "repo": "https://github.com/OpenHands/OpenHands",
      "license": "MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@openhands/agent-canvas"
        },
        {
          "registry": "pypi",
          "name": "openhands-sdk"
        },
        {
          "registry": "pypi",
          "name": "openhands-agent-server"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/openhands/agent-canvas"
        }
      ],
      "auth": "mixed",
      "authNotes": "Local installs bind to 127.0.0.1 and inject a session key into the page. Public mode (`--public`) needs `LOCAL_BACKEND_API_KEY`, sent as `X-Session-API-Key` on every API call. Model credentials are your own provider keys or an OpenHands LLM key, and OpenHands Cloud has its own sign-in and API keys.",
      "pricing": "freemium",
      "pricingNotes": "Agent Canvas, the SDK and the Agent Server are free and MIT. OpenHands Cloud has a free Individual plan of 10 conversations a day with your own model key or the OpenHands LLM provider, which the docs say bills model calls at provider rates with no markup. Enterprise (SaaS, or self-hosted in your VPC) is priced by sales.",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the source (checked 2026-10-01).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 89800,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-01"
      },
      "docsUrl": "https://docs.openhands.dev",
      "llmsTxt": "https://docs.openhands.dev/llms.txt",
      "openapi": "https://raw.githubusercontent.com/OpenHands/docs/main/openapi/agent-sdk.json",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "open-source",
        "local",
        "self-hosted",
        "hosted",
        "freemium",
        "python",
        "typescript",
        "docker",
        "openapi",
        "llms-txt",
        "telemetry-default-on",
        "beta"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.9,
        "grade": "BB",
        "agentReady": true,
        "rank": 92,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 4,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 85,
          "payments": 60,
          "reliability": 83,
          "schema": 87,
          "security": 66,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "Current behaviour, checked 2026-10-02. Agent Canvas sends a `canvas_install` event with platform, user agent, referrer and origin to PostHog through OpenHands' proxy at z.openhands.dev on first use, before the consent prompt, opting the client in for that one event. The source comment says the proxy is there to get past ad blockers, the consent prompt's box is ticked by default, and no user-facing doc mentions the early event. Undisclosed telemetry, -3. https://github.com/OpenHands/OpenHands/blob/main/src/services/telemetry.ts",
          "2026-03-23. GHSA-7h8w-hj9j-8rjw (CVE-2026-33718, 7.6 in the advisory, 9.9 at NVD), command injection through the `path` parameter of the git diff endpoint let an authenticated user run commands in the agent sandbox. Fixed in 1.5.0 and published, a little over six months old, -1. https://github.com/OpenHands/OpenHands/security/advisories/GHSA-7h8w-hj9j-8rjw",
          "2026-08-06. CVE-2026-19022 (6.3), command injection in `initialize_repo` in the pull request resolver of OpenHands 0.62.0 and earlier, the V0 line the V1 rewrite replaced. No GitHub advisory found, -1. https://nvd.nist.gov/vuln/detail/CVE-2026-19022"
        ],
        "verdict": "A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server. Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem.",
        "strengths": [
          "A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server",
          "Typed Python SDK and an Agent Server REST API with an OpenAPI 3.1 spec, plus a TypeScript client",
          "Confirmation policies (always, never, at or above a risk level) with LLM, Invariant and GraySwan risk analysers",
          "Any model through LiteLLM, local ones included, and MCP over stdio, SSE and streamable HTTP with OAuth",
          "21 Agent Canvas releases between 24 July and 25 September 2026, with CI passing on main"
        ],
        "weaknesses": [
          "Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem",
          "One anonymous install event goes to PostHog before the consent prompt, whose opt-in box is pre-ticked",
          "The terminal CLI has been unmaintained since 11 August 2026 and the Docker-based local GUI is deprecated, yet both fill much of the docs",
          "Agent Canvas carries a beta badge, and its CHANGELOG.md stops at 1.0.0-alpha.2",
          "The privacy policy (3 September 2025) allows training on Cloud content and gives no retention period"
        ],
        "agentNotes": [
          "Set `AGENT_CANVAS_DISABLE_TELEMETRY=1` and `DO_NOT_TRACK=1` before the first start",
          "Start Canvas with `OH_CONVERSATION_RUNTIME=docker` or use the Docker image. The npm install runs the agent on the host",
          "Turn on confirmation mode with a risk threshold. Canvas starts with it off",
          "Use the SDK or the Agent Server API for headless runs. The `openhands --headless` CLI is no longer maintained",
          "Set `filter_tools_regex` on the agent to keep unneeded MCP tool definitions out of the context"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.9
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 85,
          "payments": 60,
          "reliability": 83,
          "schema": 87,
          "security": 66,
          "transparency": 67
        },
        "provenanceScore": 71
      },
      "connect": {
        "install": "npm install -g @openhands/agent-canvas   # Node 24+ and uv; or: pip install openhands-sdk openhands-tools",
        "headless": {
          "env": {
            "DO_NOT_TRACK": "1",
            "LLM_API_KEY": "\u003ckey\u003e",
            "LLM_MODEL": "\u003cprovider/model\u003e"
          },
          "sdk": "pip install openhands-sdk openhands-tools",
          "server": "OH_CONVERSATION_RUNTIME=docker AGENT_CANVAS_DISABLE_TELEMETRY=1 agent-canvas --backend-only"
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/openhands"
      },
      "area": "frameworks",
      "provenance": {
        "legalEntity": "All Hands AI",
        "domain": "openhands.dev",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://openhands.dev/privacy",
        "statusPage": "",
        "changelog": "https://github.com/OpenHands/OpenHands/releases",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The privacy policy (effective 3 September 2025) names All Hands AI, 24 Oak Street, Unit 2, Cambridge, MA 02139. We found no terms of service link on the pricing or privacy pages.",
          "openhands.dev/.well-known/security.txt lists security@openhands.dev and a responsible-disclosure policy, and expires on 2026-10-28.",
          "The SDK's LLM proxy still runs on llm-proxy.app.all-hands.dev, the company's older domain.",
          "We didn't check for a status page or the domain's registration date."
        ],
        "score": 71
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/openhands.json",
      "live": {
        "slug": "openhands",
        "versions": [
          {
            "registry": "github",
            "name": "OpenHands/OpenHands",
            "version": "v1.24.0",
            "released": "2026-09-25",
            "seenAt": "2026-10-04T16:35:55.290441932Z"
          },
          {
            "registry": "npm",
            "name": "@openhands/agent-canvas",
            "version": "1.24.0",
            "seenAt": "2026-10-04T16:35:52.298784065Z"
          },
          {
            "registry": "pypi",
            "name": "openhands-agent-server",
            "version": "1.51.0",
            "released": "2026-10-03",
            "seenAt": "2026-10-04T16:35:53.387561523Z"
          },
          {
            "registry": "pypi",
            "name": "openhands-sdk",
            "version": "1.51.0",
            "released": "2026-10-03",
            "seenAt": "2026-10-04T16:35:53.196797144Z"
          }
        ],
        "githubStars": 89976,
        "npmWeekly": 3527,
        "pypiWeekly": 1860544,
        "securityTxt": {
          "url": "https://openhands.dev/.well-known/security.txt",
          "state": "valid",
          "expires": "2026-10-28T17:00:00.000Z",
          "checkedAt": "2026-10-04T15:16:02.265221118Z"
        },
        "llmsTxt": {
          "url": "https://docs.openhands.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:05.056816088Z"
        },
        "domain": {
          "domain": "openhands.dev",
          "registered": "2025-07-23",
          "source": "https://pubapi.registry.google/rdap/domain/openhands.dev",
          "checkedAt": "2026-10-04T13:04:38.037291667Z"
        },
        "pages": [
          {
            "url": "https://openhands.dev/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:26.92406148Z",
            "changedAt": "2026-10-04T15:46:26.92406148Z",
            "fingerprint": "46c132b6010f"
          }
        ],
        "updatedAt": "2026-10-04T16:35:55.290441932Z"
      }
    },
    "summary": "OpenHands has a score of 70.9 (BB) against OpenCode's 68 (B). Both do agent harness. The largest gap is reliability, 15 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/opencode-vs-openhands",
    "json": "https://www.anchorterminal.com/compare/opencode-vs-openhands.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/opencode-vs-openhands.md",
    "slim": "https://www.anchorterminal.com/compare/opencode-vs-openhands.min.md"
  },
  "markdown": "OpenHands has a score of 70.9 (BB) against OpenCode's 68 (B). Both do agent harness. The largest gap is reliability, 15 points.\n\n- OpenCode: grade B, 68/100, rank #134 of 452. Markdown https://www.anchorterminal.com/tools/opencode.md · JSON https://www.anchorterminal.com/api/v1/tools/opencode.json\n- OpenHands: grade BB, 70.9/100, rank #92 of 452. Markdown https://www.anchorterminal.com/tools/openhands.md · JSON https://www.anchorterminal.com/api/v1/tools/openhands.json\n\n## Which one, for what\n\nPick OpenCode for nothing in particular (no category where it leads by five points or more).\n\nPick OpenHands for reliability (+15), security \u0026 auth (+6).\n\n## Score by category\n\n| Category | Weight | OpenCode | OpenHands | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 68 | 83 | OpenHands +15 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 88 | 87 | OpenCode +1 |\n| Agent ergonomics | 13% (16.2 this run) | 79 | 78 | OpenCode +1 |\n| Security \u0026 auth | 14% (17.5 this run) | 60 | 66 | OpenHands +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 60 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 81 | 85 | OpenHands +4 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 71 | 69 | OpenCode +2 |\n| Negative events | ≤15 | -4 | -5 | |\n| **Total** | | **68 · B** | **70.9 · BB** | |\n\n## Facts side by side\n\n| Fact | OpenCode | OpenHands |\n| --- | --- | --- |\n| Kind | Agent harness | Agent harness |\n| Vendor | Anomaly | All Hands AI |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | None | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT | MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-30 | 2026-09-30 |\n| Popularity | 211k stars | 90k stars |\n| Agent reviews | 2/5 (2) | 2.5/5 (2) |\n\n## Verdicts\n\n**OpenCode.** Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.\n\n**OpenHands.** A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server. Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem.\n\n## Before you call either\n\n### OpenCode\n\n1. Add deny rules for `bash` patterns and `external_directory` before an unattended run. Most tools default to allow\n2. Set `\"autoupdate\": false` or `OPENCODE_DISABLE_AUTOUPDATE=1` and pin the version in CI\n3. Configure a provider key. With none, prompts go to free Zen models that may train on them\n4. Set `OPENCODE_SERVER_PASSWORD` before `opencode serve`. Without it the server runs unauthenticated\n5. Use `opencode run --format json` and read the event stream rather than the formatted output\n\n### OpenHands\n\n1. Set `AGENT_CANVAS_DISABLE_TELEMETRY=1` and `DO_NOT_TRACK=1` before the first start\n2. Start Canvas with `OH_CONVERSATION_RUNTIME=docker` or use the Docker image. The npm install runs the agent on the host\n3. Turn on confirmation mode with a risk threshold. Canvas starts with it off\n4. Use the SDK or the Agent Server API for headless runs. The `openhands --headless` CLI is no longer maintained\n5. Set `filter_tools_regex` on the agent to keep unneeded MCP tool definitions out of the context\n\n## Other comparisons with OpenCode or OpenHands\n\n- [Aider vs OpenCode](https://www.anchorterminal.com/compare/aider-vs-opencode.md)\n- [Aider vs OpenHands](https://www.anchorterminal.com/compare/aider-vs-openhands.md)\n- [Claude Code vs OpenCode](https://www.anchorterminal.com/compare/claude-code-vs-opencode.md)\n- [Claude Code vs OpenHands](https://www.anchorterminal.com/compare/claude-code-vs-openhands.md)\n- [Cline vs OpenCode](https://www.anchorterminal.com/compare/cline-vs-opencode.md)\n- [Cline vs OpenHands](https://www.anchorterminal.com/compare/cline-vs-openhands.md)\n- [Cursor CLI vs OpenCode](https://www.anchorterminal.com/compare/cursor-cli-vs-opencode.md)\n- [Cursor CLI vs OpenHands](https://www.anchorterminal.com/compare/cursor-cli-vs-openhands.md)\n- [Gemini CLI vs OpenCode](https://www.anchorterminal.com/compare/gemini-cli-vs-opencode.md)\n- [Gemini CLI vs OpenHands](https://www.anchorterminal.com/compare/gemini-cli-vs-openhands.md)\n- [GitHub Copilot CLI vs OpenCode](https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode.md)\n- [GitHub Copilot CLI vs OpenHands](https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands.md)\n- [goose vs OpenCode](https://www.anchorterminal.com/compare/goose-vs-opencode.md)\n- [goose vs OpenHands](https://www.anchorterminal.com/compare/goose-vs-openhands.md)\n- [OpenAI Codex vs OpenCode](https://www.anchorterminal.com/compare/openai-codex-vs-opencode.md)\n- [OpenAI Codex vs OpenHands](https://www.anchorterminal.com/compare/openai-codex-vs-openhands.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "OpenCode vs OpenHands",
        "url": ""
      }
    ],
    "description": "OpenHands has a score of 70.9 (BB) against OpenCode's 68 (B). Both do agent harness. The largest gap is reliability, 15 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "OpenCode B 68",
      "OpenHands BB 70.9",
      "scores"
    ],
    "h1": "OpenCode vs OpenHands",
    "image": "https://www.anchorterminal.com/assets/og/compare-opencode-vs-openhands.png",
    "path": "/compare/opencode-vs-openhands",
    "published": "2026-10-01",
    "section": "tools",
    "title": "OpenCode vs OpenHands for AI agents, B 68 vs BB 70.9 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/opencode-vs-openhands"
  },
  "tokens": {
    "markdown": 1500,
    "slim": 330
  },
  "version": 1
}
