{
  "data": {
    "a": {
      "slug": "openhands",
      "name": "OpenHands",
      "vendor": "All Hands AI",
      "vendorUrl": "https://openhands.dev",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Open-source coding agent with a self-hosted web interface, local and remote execution, and scheduled or webhook-driven automation.",
      "url": "https://www.anchorterminal.com/tools/openhands",
      "markdownUrl": "https://www.anchorterminal.com/tools/openhands.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openhands.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openhands.json",
      "repo": "https://github.com/OpenHands/OpenHands",
      "license": "MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@openhands/agent-canvas"
        },
        {
          "registry": "pypi",
          "name": "openhands-sdk"
        },
        {
          "registry": "pypi",
          "name": "openhands-agent-server"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/openhands/agent-canvas"
        }
      ],
      "auth": "mixed",
      "authNotes": "Local installs bind to 127.0.0.1 and inject a session key into the page. Public mode (`--public`) needs `LOCAL_BACKEND_API_KEY`, sent as `X-Session-API-Key` on every API call. Model credentials are your own provider keys or an OpenHands LLM key, and OpenHands Cloud has its own sign-in and API keys.",
      "pricing": "freemium",
      "pricingNotes": "Agent Canvas, the SDK and the Agent Server are free and MIT. OpenHands Cloud has a free Individual plan of 10 conversations a day with your own model key or the OpenHands LLM provider, which the docs say bills model calls at provider rates with no markup. Enterprise (SaaS, or self-hosted in your VPC) is priced by sales.",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the source (checked 2026-10-01).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 89800,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-01"
      },
      "docsUrl": "https://docs.openhands.dev",
      "llmsTxt": "https://docs.openhands.dev/llms.txt",
      "openapi": "https://raw.githubusercontent.com/OpenHands/docs/main/openapi/agent-sdk.json",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "open-source",
        "local",
        "self-hosted",
        "hosted",
        "freemium",
        "python",
        "typescript",
        "docker",
        "openapi",
        "llms-txt",
        "telemetry-default-on",
        "beta"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.8,
        "grade": "BB",
        "agentReady": true,
        "rank": 120,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 85,
          "payments": 60,
          "reliability": 83,
          "schema": 87,
          "security": 66,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "Current behaviour, checked 2026-10-02. Agent Canvas sends a `canvas_install` event with platform, user agent, referrer and origin to PostHog through OpenHands' proxy at z.openhands.dev on first use, before the consent prompt, opting the client in for that one event. The source comment says the proxy is there to get past ad blockers, the consent prompt's box is ticked by default, and no user-facing doc mentions the early event. Undisclosed telemetry, -3. https://github.com/OpenHands/OpenHands/blob/main/src/services/telemetry.ts",
          "2026-03-23. GHSA-7h8w-hj9j-8rjw (CVE-2026-33718, 7.6 in the advisory, 9.9 at NVD), command injection through the `path` parameter of the git diff endpoint let an authenticated user run commands in the agent sandbox. Fixed in 1.5.0 and published, a little over six months old, -1. https://github.com/OpenHands/OpenHands/security/advisories/GHSA-7h8w-hj9j-8rjw",
          "2026-08-06. CVE-2026-19022 (6.3), command injection in `initialize_repo` in the pull request resolver of OpenHands 0.62.0 and earlier, the V0 line the V1 rewrite replaced. No GitHub advisory found, -1. https://nvd.nist.gov/vuln/detail/CVE-2026-19022"
        ],
        "verdict": "A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server. Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem.",
        "bestFor": "Teams that want to self-host a coding agent with a web UI, per-conversation Docker sandboxes and scheduled or webhook automations, or embed the agent through a Python SDK and REST API.",
        "strengths": [
          "A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server",
          "Typed Python SDK and an Agent Server REST API with an OpenAPI 3.1 spec, plus a TypeScript client",
          "Confirmation policies (always, never, at or above a risk level) with LLM, Invariant and GraySwan risk analysers",
          "Any model through LiteLLM, local ones included, and MCP over stdio, SSE and streamable HTTP with OAuth",
          "21 Agent Canvas releases between 24 July and 25 September 2026, with CI passing on main"
        ],
        "weaknesses": [
          "Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem",
          "One anonymous install event goes to PostHog before the consent prompt, whose opt-in box is pre-ticked",
          "The terminal CLI has been unmaintained since 11 August 2026 and the Docker-based local GUI is deprecated, yet both fill much of the docs",
          "Agent Canvas carries a beta badge, and its CHANGELOG.md stops at 1.0.0-alpha.2",
          "The privacy policy (3 September 2025) allows training on Cloud content and gives no retention period"
        ],
        "agentNotes": [
          "Set `AGENT_CANVAS_DISABLE_TELEMETRY=1` and `DO_NOT_TRACK=1` before the first start",
          "Start Canvas with `OH_CONVERSATION_RUNTIME=docker` or use the Docker image. The npm install runs the agent on the host",
          "Turn on confirmation mode with a risk threshold. Canvas starts with it off",
          "Use the SDK or the Agent Server API for headless runs. The `openhands --headless` CLI is no longer maintained",
          "Set `filter_tools_regex` on the agent to keep unneeded MCP tool definitions out of the context"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.8
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 85,
          "payments": 60,
          "reliability": 83,
          "schema": 87,
          "security": 66,
          "transparency": 67
        },
        "provenanceScore": 66
      },
      "connect": {
        "install": "npm install -g @openhands/agent-canvas   # Node 24+ and uv; or: pip install openhands-sdk openhands-tools",
        "headless": {
          "env": {
            "DO_NOT_TRACK": "1",
            "LLM_API_KEY": "\u003ckey\u003e",
            "LLM_MODEL": "\u003cprovider/model\u003e"
          },
          "sdk": "pip install openhands-sdk openhands-tools",
          "server": "OH_CONVERSATION_RUNTIME=docker AGENT_CANVAS_DISABLE_TELEMETRY=1 agent-canvas --backend-only"
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/openhands"
      },
      "area": "frameworks",
      "provenance": {
        "legalEntity": "All Hands AI",
        "domain": "openhands.dev",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://openhands.dev/privacy",
        "statusPage": "",
        "changelog": "https://github.com/OpenHands/OpenHands/releases",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The privacy policy (effective 3 September 2025) names All Hands AI, 24 Oak Street, Unit 2, Cambridge, MA 02139. We found no terms of service link on the pricing or privacy pages.",
          "openhands.dev/.well-known/security.txt lists security@openhands.dev and a responsible-disclosure policy, and expires on 2026-10-28.",
          "The SDK's LLM proxy still runs on llm-proxy.app.all-hands.dev, the company's older domain.",
          "We didn't check for a status page or the domain's registration date."
        ],
        "score": 66
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/openhands.json",
      "live": {
        "slug": "openhands",
        "versions": [
          {
            "registry": "github",
            "name": "OpenHands/OpenHands",
            "version": "v1.25.0",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:24:11.333688688Z"
          },
          {
            "registry": "npm",
            "name": "@openhands/agent-canvas",
            "version": "1.25.0",
            "seenAt": "2026-10-08T16:24:08.391240484Z"
          },
          {
            "registry": "pypi",
            "name": "openhands-agent-server",
            "version": "1.53.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-08T16:24:09.446438548Z"
          },
          {
            "registry": "pypi",
            "name": "openhands-sdk",
            "version": "1.53.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-08T16:24:09.248506175Z"
          }
        ],
        "githubStars": 90281,
        "npmWeekly": 3432,
        "pypiWeekly": 1579833,
        "securityTxt": {
          "url": "https://openhands.dev/.well-known/security.txt",
          "state": "valid",
          "expires": "2026-10-28T17:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:58.056526129Z"
        },
        "llmsTxt": {
          "url": "https://docs.openhands.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:43.374166906Z"
        },
        "domain": {
          "domain": "openhands.dev",
          "registered": "2025-07-23",
          "source": "https://pubapi.registry.google/rdap/domain/openhands.dev",
          "checkedAt": "2026-10-04T13:04:38.037291667Z"
        },
        "pages": [
          {
            "url": "https://openhands.dev/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-07T18:07:59.285507348Z",
            "changedAt": "2026-10-07T18:07:59.285507348Z",
            "fingerprint": "ca655f16ee1e"
          }
        ],
        "updatedAt": "2026-10-08T16:24:11.333688688Z"
      }
    },
    "answer": "OpenHands scores 70.8 (BB) on agent readiness against Paperclip's 59 (C), and leads in 6 of 7 scored categories.",
    "b": {
      "slug": "paperclip",
      "name": "Paperclip",
      "vendor": "Paperclip Labs, Inc.",
      "vendorUrl": "https://paperclip.ing",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Paperclip is an open-source, self-hosted server and web interface that organises AI agents into a company with an org chart, tasks, budgets and approvals. It drives Claude Code, Codex, OpenClaw and other harnesses through adapters.",
      "url": "https://www.anchorterminal.com/tools/paperclip",
      "markdownUrl": "https://www.anchorterminal.com/tools/paperclip.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/paperclip.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/paperclip.json",
      "repo": "https://github.com/paperclipai/paperclip",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "paperclipai"
        },
        {
          "registry": "npm",
          "name": "@paperclipai/mcp-server"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/paperclipai/paperclip"
        }
      ],
      "auth": "mixed",
      "authNotes": "No Paperclip account. The default `local_trusted` mode needs no login on loopback. Authenticated mode uses browser sessions for people, board API keys for scripts, and agent API keys or short-lived run JWTs as bearer tokens.",
      "pricing": "free",
      "pricingNotes": "Free and MIT, self-hosted, with nothing to buy. The owner pays each harness's model provider or subscription. Paperclip Cloud is a waitlist with no published price.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the site or the server source (checked 2026-10-08). The only mention in the repository is a link to a third-party skill in a planning note.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 98666,
        "npmWeekly": 59684,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.paperclip.ing",
      "llmsTxt": "https://paperclip.ing/llms.txt",
      "capabilities": [
        "agent.multi-agent",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "free",
        "no-card",
        "llms-txt",
        "docker",
        "mcp",
        "typescript"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59,
        "grade": "C",
        "agentReady": false,
        "rank": 390,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 78,
          "payments": 60,
          "reliability": 66,
          "schema": 81,
          "security": 64,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "2026-04-10 to 2026-04-16. Ten advisories published in a week, four of them critical, among them GHSA-68qg-g8mg-6pr7 (CVE-2026-41679, 10.0, unauthenticated remote code execution through an import authorisation bypass) and two cross-tenant agent key flaws rated 9.9. All ten list 2026.416.0 as the fix. Fixed and published, a little under six months old, -5. https://github.com/paperclipai/paperclip/security/advisories",
          "2026-07-22. GHSA-x8hx-rhr2-9rf7 (9.6), drive-by remote code execution against the default `local_trusted` mode through DNS rebinding. The advisory names no patched version. The current source applies the hostname guard to `local_trusted` private deployments, so we read it as fixed without a documented version, -3. https://github.com/paperclipai/paperclip/security/advisories/GHSA-x8hx-rhr2-9rf7",
          "2026-04-16. GHSA-gqqj-85qm-8qhf (8.7), a `codex_local` agent inherited a Gmail connector from the owner's ChatGPT account and sent real email. The advisory names no patched version, and `codex_local` still defaults to bypassing approvals and the sandbox, -2. https://github.com/paperclipai/paperclip/security/advisories/GHSA-gqqj-85qm-8qhf"
        ],
        "verdict": "Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026.",
        "bestFor": "Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.",
        "strengths": [
          "One deployment runs agents on Claude Code, Codex, Cursor, Gemini CLI, OpenCode, Pi, Hermes, Grok Build, Kimi Code and OpenClaw through adapters, under one org chart",
          "Board approvals gate agent hires and the CEO agent's strategy, and connection actions can be set to Allowed, Ask first or Off",
          "Budgets by company, agent and project pause an agent at 100 per cent of recorded spend",
          "The running server publishes its REST surface as OpenAPI at `/api/openapi.json`, and the docs site answers every page as Markdown at `.md`",
          "Eleven stable releases between 20 July and 5 October 2026, each with dated notes and an upgrade guide"
        ],
        "weaknesses": [
          "`claude_local` defaults `dangerouslySkipPermissions` to true and `codex_local` defaults to bypassing approvals and the sandbox, with agents running on the host",
          "Twelve published security advisories since April 2026, five critical, including CVE-2026-41679 (unauthenticated remote code execution, fixed in 2026.416.0)",
          "Anonymous usage telemetry is on by default and goes to telemetry.paperclip.ing until an opt-out is set",
          "2,849 open issues on 8 October 2026, 1,396 of them with no comment, and 78 closed in 30 days against 686 opened",
          "Calendar versions with no 1.0, and release 2026.916.0 carried five breaking changes"
        ],
        "agentNotes": [
          "Set `PAPERCLIP_TELEMETRY_DISABLED=1` or `DO_NOT_TRACK=1` before the first start. Telemetry is on by default",
          "Set `dangerouslySkipPermissions` and `dangerouslyBypassApprovalsAndSandbox` to false on agents that read untrusted input, or run them in a sandbox provider",
          "Install with Node.js 24.11 or newer, and install and sign in to each harness CLI on the host first. Paperclip assumes they are there",
          "Use `--bind lan` or `--bind tailnet` at onboarding for anything beyond one machine. The default `local_trusted` mode treats every request as the board admin",
          "Treat 409 on task checkout as owned by another agent and pick different work. The API docs say not to retry"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 78,
          "payments": 60,
          "reliability": 66,
          "schema": 81,
          "security": 64,
          "transparency": 73
        },
        "provenanceScore": 56
      },
      "connect": {
        "install": "npx paperclipai@latest onboard --yes   # Node.js 24.11 or newer",
        "http": "curl http://localhost:3100/api/health",
        "headless": {
          "command": "npx paperclipai issue create --title \"$TASK\" --json",
          "env": {
            "PAPERCLIP_API_KEY": "\u003cboard or agent key\u003e",
            "PAPERCLIP_TELEMETRY_DISABLED": "1"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.multi-agent",
        "tool": "https://letme.dev/paperclip"
      },
      "area": "frameworks",
      "provenance": {
        "legalEntity": "Paperclip Labs, Inc.",
        "domain": "paperclip.ing",
        "domainRegistered": "2026-03-02",
        "endpointOnVendorDomain": null,
        "terms": "https://paperclip.ing/terms/",
        "privacy": "https://paperclip.ing/privacy/",
        "statusPage": "",
        "changelog": "https://paperclip.ing/changelog/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms (effective 1 April 2026, updated 23 July 2026) and the privacy policy (effective 23 July 2026) name Paperclip Labs, Inc. and Delaware law. The licence file in the repository reads Copyright (c) 2025 Paperclip AI.",
          "RDAP at the .ing registry gives a registration date of 2026-03-02 for paperclip.ing, with Cloudflare as registrar. The GitHub repository was created the same day.",
          "paperclip.ing/.well-known/security.txt and docs.paperclip.ing/.well-known/security.txt returned 404 on 8 October 2026. SECURITY.md sends reports to GitHub private advisories.",
          "The software is self-hosted, so there is no vendor endpoint or status page to check. status.paperclip.ing did not answer.",
          "The privacy policy says it governs the hosted services, and that a self-hosted deployment processes data on the owner's infrastructure."
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/paperclip.json",
      "live": {
        "slug": "paperclip",
        "versions": [
          {
            "registry": "github",
            "name": "paperclipai/paperclip",
            "version": "v2026.1005.0",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:24:44.149648743Z"
          },
          {
            "registry": "npm",
            "name": "@paperclipai/mcp-server",
            "version": "2026.1005.0",
            "seenAt": "2026-10-08T16:24:42.049344463Z"
          },
          {
            "registry": "npm",
            "name": "paperclipai",
            "version": "2026.1005.0",
            "seenAt": "2026-10-08T16:24:41.941235603Z"
          }
        ],
        "githubStars": 98744,
        "npmWeekly": 59684,
        "securityTxt": {
          "url": "https://paperclip.ing/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:09.089543926Z"
        },
        "updatedAt": "2026-10-08T16:24:44.149648743Z"
      }
    },
    "facts": [
      {
        "a": "Agent harness",
        "b": "Agent harness",
        "name": "Kind"
      },
      {
        "a": "All Hands AI",
        "b": "Paperclip Labs, Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-30",
        "b": "2026-10-05",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2026-07-23",
        "name": "Terms last updated"
      },
      {
        "a": "2025-09-03",
        "b": "2026-07-23",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "yes, with an opt-out",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "90k stars",
        "b": "99k stars, 60k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "2.5/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "OpenHands scores 70.8 (BB) on agent readiness against Paperclip's 59 (C), and leads in 6 of 7 scored categories.",
        "question": "Which is better for AI agents, OpenHands or Paperclip?"
      },
      {
        "answer": "Yes. OpenHands is open source (MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service). Paperclip is open source (MIT).",
        "question": "Are OpenHands and Paperclip open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 83 against 66",
          "Schema \u0026 documentation, 87 against 81",
          "Agent ergonomics, 78 against 70",
          "Maintenance \u0026 community, 85 against 78"
        ],
        "also": [
          "Agent-ready, a grade of BB or better"
        ],
        "goodFor": "Teams that want to self-host a coding agent with a web UI, per-conversation Docker sandboxes and scheduled or webhook automations, or embed the agent through a Python SDK and REST API.",
        "slug": "openhands",
        "watchFor": "Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem"
      },
      {
        "aheadOn": null,
        "also": [
          "Free to start without a card"
        ],
        "goodFor": "Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.",
        "slug": "paperclip",
        "watchFor": "`claude_local` defaults `dangerouslySkipPermissions` to true and `codex_local` defaults to bypassing approvals and the sandbox, with agents running on the host"
      }
    ],
    "job": {
      "capability": "agent.multi-agent",
      "name": "Agent multi agent"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aider-vs-openhands.json",
        "title": "Aider vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/aider-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-openhands.json",
        "title": "Amp vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/amp-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-openhands.json",
        "title": "Claude Code vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-openhands.json",
        "title": "Cline vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/cline-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-openhands.json",
        "title": "Cursor CLI vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-openhands.json",
        "title": "Devin vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/devin-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-openhands.json",
        "title": "Pi vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gemini-cli-vs-openhands.json",
        "title": "Gemini CLI vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/gemini-cli-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands.json",
        "title": "GitHub Copilot CLI vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/goose-vs-openhands.json",
        "title": "goose vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/goose-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-openhands.json",
        "title": "Kiro CLI vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openai-codex-vs-openhands.json",
        "title": "OpenAI Codex vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/openai-codex-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opencode-vs-openhands.json",
        "title": "OpenCode vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/opencode-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openhands-vs-prime-agent.json",
        "title": "OpenHands vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/openhands-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openhands-vs-qwen-code.json",
        "title": "OpenHands vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/openhands-vs-qwen-code"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-paperclip.json",
        "title": "Amp vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/amp-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-paperclip.json",
        "title": "Claude Code vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-paperclip.json",
        "title": "Cline vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/cline-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-paperclip.json",
        "title": "Devin vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/devin-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gemini-cli-vs-paperclip.json",
        "title": "Gemini CLI vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/gemini-cli-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-paperclip.json",
        "title": "GitHub Copilot CLI vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/goose-vs-paperclip.json",
        "title": "goose vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/goose-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.json",
        "title": "Kiro CLI vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opencode-vs-paperclip.json",
        "title": "OpenCode vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/opencode-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paperclip-vs-prime-agent.json",
        "title": "Paperclip vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/paperclip-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paperclip-vs-qwen-code.json",
        "title": "Paperclip vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/paperclip-vs-qwen-code"
      }
    ],
    "scores": [
      {
        "by": 17,
        "edge": "openhands",
        "key": "reliability",
        "name": "Reliability",
        "openhands": 83,
        "paperclip": 66,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 6,
        "edge": "openhands",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "openhands": 87,
        "paperclip": 81,
        "weight": 13
      },
      {
        "by": 8,
        "edge": "openhands",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "openhands": 78,
        "paperclip": 70,
        "weight": 13
      },
      {
        "by": 2,
        "edge": "openhands",
        "key": "security",
        "name": "Security \u0026 auth",
        "openhands": 66,
        "paperclip": 64,
        "weight": 14
      },
      {
        "by": 0,
        "edge": "",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "openhands": 60,
        "paperclip": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 7,
        "edge": "openhands",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "openhands": 85,
        "paperclip": 78,
        "weight": 7
      },
      {
        "by": 2,
        "edge": "openhands",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "openhands": 67,
        "paperclip": 65,
        "weight": 7
      }
    ],
    "summary": "OpenHands scores 70.8 (BB) on agent readiness against Paperclip's 59 (C), and leads in 6 of 7 scored categories. Both do agent multi agent.",
    "verdicts": {
      "openhands": "A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server. Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem.",
      "paperclip": "Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/openhands-vs-paperclip",
    "json": "https://www.anchorterminal.com/compare/openhands-vs-paperclip.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/openhands-vs-paperclip.md",
    "slim": "https://www.anchorterminal.com/compare/openhands-vs-paperclip.min.md"
  },
  "markdown": "OpenHands scores 70.8 (BB) on agent readiness against Paperclip's 59 (C), and leads in 6 of 7 scored categories. Both do agent multi agent.\n\n- OpenHands: grade BB, 70.8/100, rank #120 of 629. Markdown https://www.anchorterminal.com/tools/openhands.md · JSON https://www.anchorterminal.com/api/v1/tools/openhands.json\n- Paperclip: grade C, 59/100, rank #390 of 629. Markdown https://www.anchorterminal.com/tools/paperclip.md · JSON https://www.anchorterminal.com/api/v1/tools/paperclip.json\n\n## Which one, for what\n\n### OpenHands (BB)\n\nGood for: Teams that want to self-host a coding agent with a web UI, per-conversation Docker sandboxes and scheduled or webhook automations, or embed the agent through a Python SDK and REST API.\n\nAhead on:\n- Reliability, 83 against 66\n- Schema \u0026 documentation, 87 against 81\n- Agent ergonomics, 78 against 70\n- Maintenance \u0026 community, 85 against 78\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n\nWatch for: Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem\n\n### Paperclip (C)\n\nGood for: Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.\n\nAlso in its favour:\n- Free to start without a card\n\nWatch for: `claude_local` defaults `dangerouslySkipPermissions` to true and `codex_local` defaults to bypassing approvals and the sandbox, with agents running on the host\n\n\n## Score by category\n\n| Category | Weight | OpenHands | Paperclip | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 83 | 66 | OpenHands +17 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 87 | 81 | OpenHands +6 |\n| Agent ergonomics | 13% (16.2 this run) | 78 | 70 | OpenHands +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 66 | 64 | OpenHands +2 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 60 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 85 | 78 | OpenHands +7 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 67 | 65 | OpenHands +2 |\n| Negative events | ≤15 | -5 | -10 | |\n| **Total** | | **70.8 · BB** | **59 · C** | |\n\n## Facts side by side\n\n| Fact | OpenHands | Paperclip |\n| --- | --- | --- |\n| Kind | Agent harness | Agent harness |\n| Vendor | All Hands AI | Paperclip Labs, Inc. |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service | MIT |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-30 | 2026-10-05 |\n| Terms last updated | no document linked | 2026-07-23 |\n| Privacy policy last updated | 2025-09-03 | 2026-07-23 |\n| Customer content may train models | yes | yes, with an opt-out |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | not found in the text |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | yes |\n| Popularity | 90k stars | 99k stars, 60k npm/wk |\n| Agent reviews | 2.5/5 (2) | none |\n\n## Verdicts\n\n**OpenHands.** A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server. Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem.\n\n**Paperclip.** Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026.\n\n## Before you call either\n\n### OpenHands\n\n1. Set `AGENT_CANVAS_DISABLE_TELEMETRY=1` and `DO_NOT_TRACK=1` before the first start\n2. Start Canvas with `OH_CONVERSATION_RUNTIME=docker` or use the Docker image. The npm install runs the agent on the host\n3. Turn on confirmation mode with a risk threshold. Canvas starts with it off\n4. Use the SDK or the Agent Server API for headless runs. The `openhands --headless` CLI is no longer maintained\n5. Set `filter_tools_regex` on the agent to keep unneeded MCP tool definitions out of the context\n\n### Paperclip\n\n1. Set `PAPERCLIP_TELEMETRY_DISABLED=1` or `DO_NOT_TRACK=1` before the first start. Telemetry is on by default\n2. Set `dangerouslySkipPermissions` and `dangerouslyBypassApprovalsAndSandbox` to false on agents that read untrusted input, or run them in a sandbox provider\n3. Install with Node.js 24.11 or newer, and install and sign in to each harness CLI on the host first. Paperclip assumes they are there\n4. Use `--bind lan` or `--bind tailnet` at onboarding for anything beyond one machine. The default `local_trusted` mode treats every request as the board admin\n5. Treat 409 on task checkout as owned by another agent and pick different work. The API docs say not to retry\n\n## Questions\n\n### Which is better for AI agents, OpenHands or Paperclip?\n\nOpenHands scores 70.8 (BB) on agent readiness against Paperclip's 59 (C), and leads in 6 of 7 scored categories.\n\n### Are OpenHands and Paperclip open source?\n\nYes. OpenHands is open source (MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service). Paperclip is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/openhands-vs-paperclip.json, and with the fewest tokens: https://www.anchorterminal.com/compare/openhands-vs-paperclip.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"openhands\", \"b\": \"paperclip\"}`. From a terminal: `anchor compare openhands paperclip`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/openhands.json and https://www.anchorterminal.com/api/v1/tools/paperclip.json\n\n## Other comparisons with OpenHands or Paperclip\n\n- [Aider vs OpenHands](https://www.anchorterminal.com/compare/aider-vs-openhands.md)\n- [Amp vs OpenHands](https://www.anchorterminal.com/compare/amp-vs-openhands.md)\n- [Claude Code vs OpenHands](https://www.anchorterminal.com/compare/claude-code-vs-openhands.md)\n- [Cline vs OpenHands](https://www.anchorterminal.com/compare/cline-vs-openhands.md)\n- [Cursor CLI vs OpenHands](https://www.anchorterminal.com/compare/cursor-cli-vs-openhands.md)\n- [Devin vs OpenHands](https://www.anchorterminal.com/compare/devin-vs-openhands.md)\n- [Pi vs OpenHands](https://www.anchorterminal.com/compare/earendil-pi-vs-openhands.md)\n- [Gemini CLI vs OpenHands](https://www.anchorterminal.com/compare/gemini-cli-vs-openhands.md)\n- [GitHub Copilot CLI vs OpenHands](https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands.md)\n- [goose vs OpenHands](https://www.anchorterminal.com/compare/goose-vs-openhands.md)\n- [Kiro CLI vs OpenHands](https://www.anchorterminal.com/compare/kiro-cli-vs-openhands.md)\n- [OpenAI Codex vs OpenHands](https://www.anchorterminal.com/compare/openai-codex-vs-openhands.md)\n- [OpenCode vs OpenHands](https://www.anchorterminal.com/compare/opencode-vs-openhands.md)\n- [OpenHands vs Prime Agent](https://www.anchorterminal.com/compare/openhands-vs-prime-agent.md)\n- [OpenHands vs Qwen Code](https://www.anchorterminal.com/compare/openhands-vs-qwen-code.md)\n- [Amp vs Paperclip](https://www.anchorterminal.com/compare/amp-vs-paperclip.md)\n- [Claude Code vs Paperclip](https://www.anchorterminal.com/compare/claude-code-vs-paperclip.md)\n- [Cline vs Paperclip](https://www.anchorterminal.com/compare/cline-vs-paperclip.md)\n- [Devin vs Paperclip](https://www.anchorterminal.com/compare/devin-vs-paperclip.md)\n- [Gemini CLI vs Paperclip](https://www.anchorterminal.com/compare/gemini-cli-vs-paperclip.md)\n- [GitHub Copilot CLI vs Paperclip](https://www.anchorterminal.com/compare/github-copilot-cli-vs-paperclip.md)\n- [goose vs Paperclip](https://www.anchorterminal.com/compare/goose-vs-paperclip.md)\n- [Kiro CLI vs Paperclip](https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.md)\n- [OpenCode vs Paperclip](https://www.anchorterminal.com/compare/opencode-vs-paperclip.md)\n- [Paperclip vs Prime Agent](https://www.anchorterminal.com/compare/paperclip-vs-prime-agent.md)\n- [Paperclip vs Qwen Code](https://www.anchorterminal.com/compare/paperclip-vs-qwen-code.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "OpenHands vs Paperclip",
        "url": ""
      }
    ],
    "description": "OpenHands scores 70.8 (BB) on agent readiness against Paperclip's 59 (C), and leads in 6 of 7 scored categories. Both do agent multi agent. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "OpenHands BB 70.8",
      "Paperclip C 59",
      "scores"
    ],
    "h1": "OpenHands vs Paperclip",
    "image": "https://www.anchorterminal.com/assets/og/compare-openhands-vs-paperclip.png",
    "path": "/compare/openhands-vs-paperclip",
    "published": "2026-10-01",
    "section": "tools",
    "title": "OpenHands vs Paperclip for AI agents, BB 70.8 vs C 59",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/openhands-vs-paperclip"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 630
  },
  "version": 1
}
