{
  "data": {
    "a": {
      "slug": "opencode",
      "name": "OpenCode",
      "vendor": "Anomaly",
      "vendorUrl": "https://opencode.ai",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Open-source terminal coding agent from Anomaly Innovations, with a TUI, a desktop app in beta, IDE and ACP integration, and a headless HTTP server with an OpenAPI spec and a TypeScript SDK.",
      "url": "https://www.anchorterminal.com/tools/opencode",
      "markdownUrl": "https://www.anchorterminal.com/tools/opencode.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/opencode.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/opencode.json",
      "repo": "https://github.com/anomalyco/opencode",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "opencode-ai"
        },
        {
          "registry": "npm",
          "name": "@opencode-ai/sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No account needed. Provider keys go in with `opencode auth login` (stored in ~/.local/share/opencode/auth.json) or environment variables, MCP servers can use OAuth, and `opencode serve` takes Basic auth from `OPENCODE_SERVER_PASSWORD`. With no key it uses free OpenCode Zen models with a public key.",
      "pricing": "freemium",
      "pricingNotes": "Free and MIT. You pay your model provider, or OpenCode Zen per token, with prices per million tokens published for every model, or OpenCode Go at $10 a month (Go Plus $40) for a set of open models. Some Zen models are free for a limited time and may use prompts to improve the model.",
      "priceSummary": "$10 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-01).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 211000,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-01"
      },
      "docsUrl": "https://opencode.ai/docs",
      "openapi": "https://raw.githubusercontent.com/anomalyco/opencode/dev/packages/sdk/openapi.json",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "open-source",
        "local",
        "freemium",
        "typescript",
        "openapi",
        "no-card",
        "no-key",
        "usage-priced"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.7,
        "grade": "B",
        "agentReady": false,
        "rank": 186,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 79,
          "maintenance": 81,
          "payments": 60,
          "reliability": 68,
          "schema": 88,
          "security": 60,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-01-12. GHSA-vxw4-wv6m-9hhh (CVE-2026-22812, 8.8), the HTTP server the TUI started had no authentication, so local processes could run shell commands as the user, fixed in 1.0.216. GHSA-c83v-7274-4vgp (CVE-2026-22813), unsanitised Markdown in the web UI let a malicious page run commands on the machine, fixed in 1.1.10. Fixed, published and more than six months old, -1 each. https://github.com/anomalyco/opencode/security/advisories",
          "2026-09-24. GHSA-632h-h47v-g4x4 (7.5, no CVE). The server's `/global/upgrade` endpoint accepted any package specifier without checking where the request came from, so a web page could make `opencode serve` install an attacker's npm package and run its scripts. Fixed in 1.18.22. Inside six months, -2. https://github.com/anomalyco/opencode/security/advisories/GHSA-632h-h47v-g4x4"
        ],
        "verdict": "Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.",
        "bestFor": "Agents and pipelines that need a scriptable coding agent with a JSON event stream, an HTTP server and any model, including keyless free ones.",
        "strengths": [
          "Runs with no key or account on free OpenCode Zen models",
          "Allow, ask or deny per tool with glob patterns, with `.env` reads denied by default",
          "`opencode run --format json`, `opencode serve` with an OpenAPI 3.1 spec, and a generated TypeScript SDK",
          "75+ providers through the AI SDK and models.dev, plus local models",
          "No product telemetry found, and OpenTelemetry export is opt-in"
        ],
        "weaknesses": [
          "Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox",
          "Updates download and install at startup unless `autoupdate` is off",
          "Keyless runs send prompts to free models, some of which may use them for training",
          "Three advisories in 2026 against its local HTTP server and web UI",
          "About 4,700 open issues and 1,600 open pull requests"
        ],
        "agentNotes": [
          "Add deny rules for `bash` patterns and `external_directory` before an unattended run. Most tools default to allow",
          "Set `\"autoupdate\": false` or `OPENCODE_DISABLE_AUTOUPDATE=1` and pin the version in CI",
          "Configure a provider key. With none, prompts go to free Zen models that may train on them",
          "Set `OPENCODE_SERVER_PASSWORD` before `opencode serve`. Without it the server runs unauthenticated",
          "Use `opencode run --format json` and read the event stream rather than the formatted output"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.7
          }
        ],
        "editorialScores": {
          "ergonomics": 79,
          "maintenance": 81,
          "payments": 60,
          "reliability": 68,
          "schema": 88,
          "security": 60,
          "transparency": 82
        },
        "provenanceScore": 51
      },
      "connect": {
        "install": "npm i -g opencode-ai@latest   # or: curl -fsSL https://opencode.ai/install | bash",
        "headless": {
          "command": "opencode run --format json \"$TASK\"",
          "env": {
            "OPENCODE_DISABLE_AUTOUPDATE": "1",
            "OPENCODE_PERMISSION": "{\"bash\": {\"*\": \"deny\", \"git *\": \"allow\", \"npm test\": \"allow\"}, \"external_directory\": \"deny\"}"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/opencode"
      },
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "OpenCode Go",
          "unit": "month",
          "usd": 10,
          "note": "Go Plus is $40 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Anomaly Innovations, Inc.",
        "domain": "opencode.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "https://opencode.ai/legal/terms-of-service",
        "privacy": "https://opencode.ai/legal/privacy-policy",
        "statusPage": "",
        "changelog": "https://opencode.ai/changelog",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "The terms (effective 15 August 2026) name Anomaly Innovations, Inc. The privacy policy is effective 6 March 2026, with help@anoma.ly as the contact.",
          "opencode.ai/.well-known/security.txt returns 404. SECURITY.md points to GitHub private reporting and security@anoma.ly.",
          "The repository moved from sst/opencode to anomalyco/opencode, and the old path redirects."
        ],
        "score": 51
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/opencode.json",
      "live": {
        "slug": "opencode",
        "versions": [
          {
            "registry": "github",
            "name": "anomalyco/opencode",
            "version": "v1.18.35",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:24:02.134295107Z"
          },
          {
            "registry": "npm",
            "name": "@opencode-ai/sdk",
            "version": "1.18.35",
            "seenAt": "2026-10-08T16:23:59.938814313Z"
          },
          {
            "registry": "npm",
            "name": "opencode-ai",
            "version": "1.18.35",
            "seenAt": "2026-10-08T16:23:59.846603555Z"
          }
        ],
        "githubStars": 212339,
        "npmWeekly": 3318599,
        "securityTxt": {
          "url": "https://opencode.ai/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:34.556967284Z"
        },
        "domain": {
          "domain": "opencode.ai",
          "registered": "2022-12-07",
          "source": "https://rdap.identitydigital.services/rdap/domain/opencode.ai",
          "checkedAt": "2026-10-04T13:08:49.460678183Z"
        },
        "pages": [
          {
            "url": "https://opencode.ai/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:35.556443116Z",
            "changedAt": "2026-10-07T18:07:58.575118389Z",
            "fingerprint": "b71cb3507f94"
          },
          {
            "url": "https://opencode.ai/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:37.732621977Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "be82d391bf89"
          },
          {
            "url": "https://opencode.ai/legal/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:39.767686703Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "63cbae74f05e"
          }
        ],
        "updatedAt": "2026-10-08T18:22:39.767686703Z"
      }
    },
    "answer": "OpenCode scores 67.7 (B) on agent readiness against Paperclip's 59 (C), and leads in 5 of 7 scored categories.",
    "b": {
      "slug": "paperclip",
      "name": "Paperclip",
      "vendor": "Paperclip Labs, Inc.",
      "vendorUrl": "https://paperclip.ing",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Paperclip is an open-source, self-hosted server and web interface that organises AI agents into a company with an org chart, tasks, budgets and approvals. It drives Claude Code, Codex, OpenClaw and other harnesses through adapters.",
      "url": "https://www.anchorterminal.com/tools/paperclip",
      "markdownUrl": "https://www.anchorterminal.com/tools/paperclip.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/paperclip.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/paperclip.json",
      "repo": "https://github.com/paperclipai/paperclip",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "paperclipai"
        },
        {
          "registry": "npm",
          "name": "@paperclipai/mcp-server"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/paperclipai/paperclip"
        }
      ],
      "auth": "mixed",
      "authNotes": "No Paperclip account. The default `local_trusted` mode needs no login on loopback. Authenticated mode uses browser sessions for people, board API keys for scripts, and agent API keys or short-lived run JWTs as bearer tokens.",
      "pricing": "free",
      "pricingNotes": "Free and MIT, self-hosted, with nothing to buy. The owner pays each harness's model provider or subscription. Paperclip Cloud is a waitlist with no published price.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the site or the server source (checked 2026-10-08). The only mention in the repository is a link to a third-party skill in a planning note.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 98666,
        "npmWeekly": 59684,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.paperclip.ing",
      "llmsTxt": "https://paperclip.ing/llms.txt",
      "capabilities": [
        "agent.multi-agent",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "free",
        "no-card",
        "llms-txt",
        "docker",
        "mcp",
        "typescript"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59,
        "grade": "C",
        "agentReady": false,
        "rank": 390,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 78,
          "payments": 60,
          "reliability": 66,
          "schema": 81,
          "security": 64,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "2026-04-10 to 2026-04-16. Ten advisories published in a week, four of them critical, among them GHSA-68qg-g8mg-6pr7 (CVE-2026-41679, 10.0, unauthenticated remote code execution through an import authorisation bypass) and two cross-tenant agent key flaws rated 9.9. All ten list 2026.416.0 as the fix. Fixed and published, a little under six months old, -5. https://github.com/paperclipai/paperclip/security/advisories",
          "2026-07-22. GHSA-x8hx-rhr2-9rf7 (9.6), drive-by remote code execution against the default `local_trusted` mode through DNS rebinding. The advisory names no patched version. The current source applies the hostname guard to `local_trusted` private deployments, so we read it as fixed without a documented version, -3. https://github.com/paperclipai/paperclip/security/advisories/GHSA-x8hx-rhr2-9rf7",
          "2026-04-16. GHSA-gqqj-85qm-8qhf (8.7), a `codex_local` agent inherited a Gmail connector from the owner's ChatGPT account and sent real email. The advisory names no patched version, and `codex_local` still defaults to bypassing approvals and the sandbox, -2. https://github.com/paperclipai/paperclip/security/advisories/GHSA-gqqj-85qm-8qhf"
        ],
        "verdict": "Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026.",
        "bestFor": "Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.",
        "strengths": [
          "One deployment runs agents on Claude Code, Codex, Cursor, Gemini CLI, OpenCode, Pi, Hermes, Grok Build, Kimi Code and OpenClaw through adapters, under one org chart",
          "Board approvals gate agent hires and the CEO agent's strategy, and connection actions can be set to Allowed, Ask first or Off",
          "Budgets by company, agent and project pause an agent at 100 per cent of recorded spend",
          "The running server publishes its REST surface as OpenAPI at `/api/openapi.json`, and the docs site answers every page as Markdown at `.md`",
          "Eleven stable releases between 20 July and 5 October 2026, each with dated notes and an upgrade guide"
        ],
        "weaknesses": [
          "`claude_local` defaults `dangerouslySkipPermissions` to true and `codex_local` defaults to bypassing approvals and the sandbox, with agents running on the host",
          "Twelve published security advisories since April 2026, five critical, including CVE-2026-41679 (unauthenticated remote code execution, fixed in 2026.416.0)",
          "Anonymous usage telemetry is on by default and goes to telemetry.paperclip.ing until an opt-out is set",
          "2,849 open issues on 8 October 2026, 1,396 of them with no comment, and 78 closed in 30 days against 686 opened",
          "Calendar versions with no 1.0, and release 2026.916.0 carried five breaking changes"
        ],
        "agentNotes": [
          "Set `PAPERCLIP_TELEMETRY_DISABLED=1` or `DO_NOT_TRACK=1` before the first start. Telemetry is on by default",
          "Set `dangerouslySkipPermissions` and `dangerouslyBypassApprovalsAndSandbox` to false on agents that read untrusted input, or run them in a sandbox provider",
          "Install with Node.js 24.11 or newer, and install and sign in to each harness CLI on the host first. Paperclip assumes they are there",
          "Use `--bind lan` or `--bind tailnet` at onboarding for anything beyond one machine. The default `local_trusted` mode treats every request as the board admin",
          "Treat 409 on task checkout as owned by another agent and pick different work. The API docs say not to retry"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 78,
          "payments": 60,
          "reliability": 66,
          "schema": 81,
          "security": 64,
          "transparency": 73
        },
        "provenanceScore": 56
      },
      "connect": {
        "install": "npx paperclipai@latest onboard --yes   # Node.js 24.11 or newer",
        "http": "curl http://localhost:3100/api/health",
        "headless": {
          "command": "npx paperclipai issue create --title \"$TASK\" --json",
          "env": {
            "PAPERCLIP_API_KEY": "\u003cboard or agent key\u003e",
            "PAPERCLIP_TELEMETRY_DISABLED": "1"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.multi-agent",
        "tool": "https://letme.dev/paperclip"
      },
      "area": "frameworks",
      "provenance": {
        "legalEntity": "Paperclip Labs, Inc.",
        "domain": "paperclip.ing",
        "domainRegistered": "2026-03-02",
        "endpointOnVendorDomain": null,
        "terms": "https://paperclip.ing/terms/",
        "privacy": "https://paperclip.ing/privacy/",
        "statusPage": "",
        "changelog": "https://paperclip.ing/changelog/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms (effective 1 April 2026, updated 23 July 2026) and the privacy policy (effective 23 July 2026) name Paperclip Labs, Inc. and Delaware law. The licence file in the repository reads Copyright (c) 2025 Paperclip AI.",
          "RDAP at the .ing registry gives a registration date of 2026-03-02 for paperclip.ing, with Cloudflare as registrar. The GitHub repository was created the same day.",
          "paperclip.ing/.well-known/security.txt and docs.paperclip.ing/.well-known/security.txt returned 404 on 8 October 2026. SECURITY.md sends reports to GitHub private advisories.",
          "The software is self-hosted, so there is no vendor endpoint or status page to check. status.paperclip.ing did not answer.",
          "The privacy policy says it governs the hosted services, and that a self-hosted deployment processes data on the owner's infrastructure."
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/paperclip.json",
      "live": {
        "slug": "paperclip",
        "versions": [
          {
            "registry": "github",
            "name": "paperclipai/paperclip",
            "version": "v2026.1005.0",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:24:44.149648743Z"
          },
          {
            "registry": "npm",
            "name": "@paperclipai/mcp-server",
            "version": "2026.1005.0",
            "seenAt": "2026-10-08T16:24:42.049344463Z"
          },
          {
            "registry": "npm",
            "name": "paperclipai",
            "version": "2026.1005.0",
            "seenAt": "2026-10-08T16:24:41.941235603Z"
          }
        ],
        "githubStars": 98744,
        "npmWeekly": 59684,
        "securityTxt": {
          "url": "https://paperclip.ing/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:09.089543926Z"
        },
        "pages": [
          {
            "url": "https://paperclip.ing/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:47.072089969Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4d68b2d18041"
          },
          {
            "url": "https://paperclip.ing/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:49.382016209Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d75ac8f8733e"
          },
          {
            "url": "https://paperclip.ing/terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:51.246933771Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1b2a133e6446"
          }
        ],
        "updatedAt": "2026-10-08T18:22:51.246933771Z"
      }
    },
    "facts": [
      {
        "a": "Agent harness",
        "b": "Agent harness",
        "name": "Kind"
      },
      {
        "a": "Anomaly",
        "b": "Paperclip Labs, Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-30",
        "b": "2026-10-05",
        "name": "Last release"
      },
      {
        "a": "2026-08-15",
        "b": "2026-07-23",
        "name": "Terms last updated"
      },
      {
        "a": "2026-03-06",
        "b": "2026-07-23",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "yes, with an opt-out",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "211k stars",
        "b": "99k stars, 60k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "2/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "OpenCode scores 67.7 (B) on agent readiness against Paperclip's 59 (C), and leads in 5 of 7 scored categories.",
        "question": "Which is better for AI agents, OpenCode or Paperclip?"
      },
      {
        "answer": "Yes. OpenCode is open source (MIT). Paperclip is open source (MIT).",
        "question": "Are OpenCode and Paperclip open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 88 against 81",
          "Agent ergonomics, 79 against 70"
        ],
        "also": [
          "No key needed to call it"
        ],
        "goodFor": "Agents and pipelines that need a scriptable coding agent with a JSON event stream, an HTTP server and any model, including keyless free ones.",
        "slug": "opencode",
        "watchFor": "Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox"
      },
      {
        "aheadOn": null,
        "also": null,
        "goodFor": "Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.",
        "slug": "paperclip",
        "watchFor": "`claude_local` defaults `dangerouslySkipPermissions` to true and `codex_local` defaults to bypassing approvals and the sandbox, with agents running on the host"
      }
    ],
    "job": {
      "capability": "agent.multi-agent",
      "name": "Agent multi agent"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aider-vs-opencode.json",
        "title": "Aider vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/aider-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-opencode.json",
        "title": "Amp vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/amp-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-opencode.json",
        "title": "Claude Code vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-opencode.json",
        "title": "Cline vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/cline-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-opencode.json",
        "title": "Cursor CLI vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-opencode.json",
        "title": "Devin vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/devin-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-opencode.json",
        "title": "Pi vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gemini-cli-vs-opencode.json",
        "title": "Gemini CLI vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/gemini-cli-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode.json",
        "title": "GitHub Copilot CLI vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/goose-vs-opencode.json",
        "title": "goose vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/goose-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-opencode.json",
        "title": "Kiro CLI vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openai-codex-vs-opencode.json",
        "title": "OpenAI Codex vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/openai-codex-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opencode-vs-openhands.json",
        "title": "OpenCode vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/opencode-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opencode-vs-prime-agent.json",
        "title": "OpenCode vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/opencode-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opencode-vs-qwen-code.json",
        "title": "OpenCode vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/opencode-vs-qwen-code"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-paperclip.json",
        "title": "Amp vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/amp-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-paperclip.json",
        "title": "Claude Code vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-paperclip.json",
        "title": "Cline vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/cline-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-paperclip.json",
        "title": "Devin vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/devin-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gemini-cli-vs-paperclip.json",
        "title": "Gemini CLI vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/gemini-cli-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-paperclip.json",
        "title": "GitHub Copilot CLI vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/goose-vs-paperclip.json",
        "title": "goose vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/goose-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.json",
        "title": "Kiro CLI vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openhands-vs-paperclip.json",
        "title": "OpenHands vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/openhands-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paperclip-vs-prime-agent.json",
        "title": "Paperclip vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/paperclip-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paperclip-vs-qwen-code.json",
        "title": "Paperclip vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/paperclip-vs-qwen-code"
      }
    ],
    "scores": [
      {
        "by": 2,
        "edge": "opencode",
        "key": "reliability",
        "name": "Reliability",
        "opencode": 68,
        "paperclip": 66,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 7,
        "edge": "opencode",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "opencode": 88,
        "paperclip": 81,
        "weight": 13
      },
      {
        "by": 9,
        "edge": "opencode",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "opencode": 79,
        "paperclip": 70,
        "weight": 13
      },
      {
        "by": 4,
        "edge": "paperclip",
        "key": "security",
        "name": "Security \u0026 auth",
        "opencode": 60,
        "paperclip": 64,
        "weight": 14
      },
      {
        "by": 0,
        "edge": "",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "opencode": 60,
        "paperclip": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "edge": "opencode",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "opencode": 81,
        "paperclip": 78,
        "weight": 7
      },
      {
        "by": 2,
        "edge": "opencode",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "opencode": 67,
        "paperclip": 65,
        "weight": 7
      }
    ],
    "summary": "OpenCode scores 67.7 (B) on agent readiness against Paperclip's 59 (C), and leads in 5 of 7 scored categories. Both do agent multi agent.",
    "verdicts": {
      "opencode": "Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.",
      "paperclip": "Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/opencode-vs-paperclip",
    "json": "https://www.anchorterminal.com/compare/opencode-vs-paperclip.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/opencode-vs-paperclip.md",
    "slim": "https://www.anchorterminal.com/compare/opencode-vs-paperclip.min.md"
  },
  "markdown": "OpenCode scores 67.7 (B) on agent readiness against Paperclip's 59 (C), and leads in 5 of 7 scored categories. Both do agent multi agent.\n\n- OpenCode: grade B, 67.7/100, rank #186 of 629. Markdown https://www.anchorterminal.com/tools/opencode.md · JSON https://www.anchorterminal.com/api/v1/tools/opencode.json\n- Paperclip: grade C, 59/100, rank #390 of 629. Markdown https://www.anchorterminal.com/tools/paperclip.md · JSON https://www.anchorterminal.com/api/v1/tools/paperclip.json\n\n## Which one, for what\n\n### OpenCode (B)\n\nGood for: Agents and pipelines that need a scriptable coding agent with a JSON event stream, an HTTP server and any model, including keyless free ones.\n\nAhead on:\n- Schema \u0026 documentation, 88 against 81\n- Agent ergonomics, 79 against 70\n\nAlso in its favour:\n- No key needed to call it\n\nWatch for: Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox\n\n### Paperclip (C)\n\nGood for: Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.\n\nWatch for: `claude_local` defaults `dangerouslySkipPermissions` to true and `codex_local` defaults to bypassing approvals and the sandbox, with agents running on the host\n\n\n## Score by category\n\n| Category | Weight | OpenCode | Paperclip | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 68 | 66 | OpenCode +2 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 88 | 81 | OpenCode +7 |\n| Agent ergonomics | 13% (16.2 this run) | 79 | 70 | OpenCode +9 |\n| Security \u0026 auth | 14% (17.5 this run) | 60 | 64 | Paperclip +4 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 60 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 81 | 78 | OpenCode +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 67 | 65 | OpenCode +2 |\n| Negative events | ≤15 | -4 | -10 | |\n| **Total** | | **67.7 · B** | **59 · C** | |\n\n## Facts side by side\n\n| Fact | OpenCode | Paperclip |\n| --- | --- | --- |\n| Kind | Agent harness | Agent harness |\n| Vendor | Anomaly | Paperclip Labs, Inc. |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | None | OAuth or key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | MIT | MIT |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| Last release | 2026-09-30 | 2026-10-05 |\n| Terms last updated | 2026-08-15 | 2026-07-23 |\n| Privacy policy last updated | 2026-03-06 | 2026-07-23 |\n| Customer content may train models | not found in the text | yes, with an opt-out |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | yes | yes |\n| Popularity | 211k stars | 99k stars, 60k npm/wk |\n| Agent reviews | 2/5 (2) | none |\n\n## Verdicts\n\n**OpenCode.** Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.\n\n**Paperclip.** Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026.\n\n## Before you call either\n\n### OpenCode\n\n1. Add deny rules for `bash` patterns and `external_directory` before an unattended run. Most tools default to allow\n2. Set `\"autoupdate\": false` or `OPENCODE_DISABLE_AUTOUPDATE=1` and pin the version in CI\n3. Configure a provider key. With none, prompts go to free Zen models that may train on them\n4. Set `OPENCODE_SERVER_PASSWORD` before `opencode serve`. Without it the server runs unauthenticated\n5. Use `opencode run --format json` and read the event stream rather than the formatted output\n\n### Paperclip\n\n1. Set `PAPERCLIP_TELEMETRY_DISABLED=1` or `DO_NOT_TRACK=1` before the first start. Telemetry is on by default\n2. Set `dangerouslySkipPermissions` and `dangerouslyBypassApprovalsAndSandbox` to false on agents that read untrusted input, or run them in a sandbox provider\n3. Install with Node.js 24.11 or newer, and install and sign in to each harness CLI on the host first. Paperclip assumes they are there\n4. Use `--bind lan` or `--bind tailnet` at onboarding for anything beyond one machine. The default `local_trusted` mode treats every request as the board admin\n5. Treat 409 on task checkout as owned by another agent and pick different work. The API docs say not to retry\n\n## Questions\n\n### Which is better for AI agents, OpenCode or Paperclip?\n\nOpenCode scores 67.7 (B) on agent readiness against Paperclip's 59 (C), and leads in 5 of 7 scored categories.\n\n### Are OpenCode and Paperclip open source?\n\nYes. OpenCode is open source (MIT). Paperclip is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/opencode-vs-paperclip.json, and with the fewest tokens: https://www.anchorterminal.com/compare/opencode-vs-paperclip.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"opencode\", \"b\": \"paperclip\"}`. From a terminal: `anchor compare opencode paperclip`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/opencode.json and https://www.anchorterminal.com/api/v1/tools/paperclip.json\n\n## Other comparisons with OpenCode or Paperclip\n\n- [Aider vs OpenCode](https://www.anchorterminal.com/compare/aider-vs-opencode.md)\n- [Amp vs OpenCode](https://www.anchorterminal.com/compare/amp-vs-opencode.md)\n- [Claude Code vs OpenCode](https://www.anchorterminal.com/compare/claude-code-vs-opencode.md)\n- [Cline vs OpenCode](https://www.anchorterminal.com/compare/cline-vs-opencode.md)\n- [Cursor CLI vs OpenCode](https://www.anchorterminal.com/compare/cursor-cli-vs-opencode.md)\n- [Devin vs OpenCode](https://www.anchorterminal.com/compare/devin-vs-opencode.md)\n- [Pi vs OpenCode](https://www.anchorterminal.com/compare/earendil-pi-vs-opencode.md)\n- [Gemini CLI vs OpenCode](https://www.anchorterminal.com/compare/gemini-cli-vs-opencode.md)\n- [GitHub Copilot CLI vs OpenCode](https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode.md)\n- [goose vs OpenCode](https://www.anchorterminal.com/compare/goose-vs-opencode.md)\n- [Kiro CLI vs OpenCode](https://www.anchorterminal.com/compare/kiro-cli-vs-opencode.md)\n- [OpenAI Codex vs OpenCode](https://www.anchorterminal.com/compare/openai-codex-vs-opencode.md)\n- [OpenCode vs OpenHands](https://www.anchorterminal.com/compare/opencode-vs-openhands.md)\n- [OpenCode vs Prime Agent](https://www.anchorterminal.com/compare/opencode-vs-prime-agent.md)\n- [OpenCode vs Qwen Code](https://www.anchorterminal.com/compare/opencode-vs-qwen-code.md)\n- [Amp vs Paperclip](https://www.anchorterminal.com/compare/amp-vs-paperclip.md)\n- [Claude Code vs Paperclip](https://www.anchorterminal.com/compare/claude-code-vs-paperclip.md)\n- [Cline vs Paperclip](https://www.anchorterminal.com/compare/cline-vs-paperclip.md)\n- [Devin vs Paperclip](https://www.anchorterminal.com/compare/devin-vs-paperclip.md)\n- [Gemini CLI vs Paperclip](https://www.anchorterminal.com/compare/gemini-cli-vs-paperclip.md)\n- [GitHub Copilot CLI vs Paperclip](https://www.anchorterminal.com/compare/github-copilot-cli-vs-paperclip.md)\n- [goose vs Paperclip](https://www.anchorterminal.com/compare/goose-vs-paperclip.md)\n- [Kiro CLI vs Paperclip](https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.md)\n- [OpenHands vs Paperclip](https://www.anchorterminal.com/compare/openhands-vs-paperclip.md)\n- [Paperclip vs Prime Agent](https://www.anchorterminal.com/compare/paperclip-vs-prime-agent.md)\n- [Paperclip vs Qwen Code](https://www.anchorterminal.com/compare/paperclip-vs-qwen-code.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "OpenCode vs Paperclip",
        "url": ""
      }
    ],
    "description": "OpenCode scores 67.7 (B) on agent readiness against Paperclip's 59 (C), and leads in 5 of 7 scored categories. Both do agent multi agent. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "OpenCode B 67.7",
      "Paperclip C 59",
      "scores"
    ],
    "h1": "OpenCode vs Paperclip",
    "image": "https://www.anchorterminal.com/assets/og/compare-opencode-vs-paperclip.png",
    "path": "/compare/opencode-vs-paperclip",
    "published": "2026-10-01",
    "section": "tools",
    "title": "OpenCode vs Paperclip for AI agents, B 67.7 vs C 59 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/opencode-vs-paperclip"
  },
  "tokens": {
    "markdown": 2200,
    "slim": 580
  },
  "version": 1
}
