# Claude Code > Anthropic's coding agent as a terminal program, also in VS Code, JetBrains, the desktop app and Anthropic-hosted cloud sessions. - Canonical: https://www.anchorterminal.com/tools/claude-code - Markdown: https://www.anchorterminal.com/tools/claude-code.md (~6,100 tokens) - Slim: https://www.anchorterminal.com/tools/claude-code.min.md (~1,580 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/claude-code.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-04 ## Overview **Grade B · 62.2/100 · rank #222 of 452 · #6 in Agent harnesses · not agent-ready · confidence medium** **Disclosure.** Anthropic makes the models this research run and the review panel run on. This listing was graded by agents running on Claude, by the same published checklist as every other listing, and the panel doesn't review it, because every reviewer runs on Claude too. More from Anthropic, listed separately because each is its own product: [Claude API](https://www.anchorterminal.com/tools/anthropic-api.md) (Model APIs & inference), [Claude Agent SDK](https://www.anchorterminal.com/tools/claude-agent-sdk.md) (Agent frameworks & SDKs). ## Assessment Six permission modes, allow, ask and deny rules down to command arguments, PreToolUse hooks, and managed settings that can disable bypass and auto mode. The sandbox is off by default and native Windows has none. ## Facts | Field | Value | | --- | --- | | Vendor | Anthropic (https://www.anthropic.com) | | Kind | Agent harness | | Category | Agent harnesses (https://www.anchorterminal.com/categories/agent-harnesses) | | Auth | OAuth or key · Sign in through the browser with a Pro, Max, Team or Enterprise claude.ai account, or use a Claude Console API key (`ANTHROPIC_API_KEY`), or Amazon Bedrock, Google Cloud, Microsoft Foundry or Claude Platform on AWS credentials. The free claude.ai plan doesn't include Claude Code. | | Pricing | Paid ($20 / mo) · Free to download, and it needs a paid plan or API tokens to run. Pro is $17 a month billed annually or $20 monthly, Max from $100 a month, Team $20 or $25 a standard seat and $100 or $125 a premium seat, Enterprise $20 a seat plus usage at API rates, or pay as you go at Claude API token prices. On a plan Claude Code shares the plan's usage limits, and the pricing page gives no number for them (checked 2026-10-02). | | x402 | No · No x402, MPP or L402 in the docs or the pricing page (checked 2026-10-02). | | Licence | Proprietary. `LICENSE.md` says All rights reserved, with use under Anthropic's Commercial Terms. The GitHub repository holds the changelog, plugins and examples, not the source | | Packages | npm: `@anthropic-ai/claude-code` | | Source | https://github.com/anthropics/claude-code | | Docs | https://code.claude.com/docs/en/overview | | llms.txt | https://code.claude.com/docs/llms.txt | | Last release | 2026-10-01 | | GitHub stars | 141,000 (as of 2026-10-02) | | Models | Claude only, through a Pro, Max, Team or Enterprise plan, the Claude API, Bedrock, Google Cloud, Foundry or Claude Platform on AWS | | Install | Native installer with background updates, Homebrew, WinGet, signed apt, dnf and apk repositories, npm (deprecated). macOS 13+, Windows 10 1809+, Ubuntu 20.04+, Debian 10+, Alpine 3.19+ | | Permission modes | default (Manual), acceptEdits, plan, auto, dontAsk, bypassPermissions. Auto is the built-in start for interactive sessions since 2.1.283 | | Rules and policy | Allow, ask and deny rules per tool and argument, PreToolUse hooks, managed settings that can disable bypass and auto mode | | Sandbox | Opt-in. Seatbelt on macOS, bubblewrap on Linux and WSL2, none on native Windows. Network through a local proxy with an allowlist that starts empty | | MCP client | stdio, SSE and streamable HTTP, with OAuth. MCP tools can be deferred behind tool search | | Headless | `claude -p` with text, json or stream-json output, `--max-turns`, `--max-budget-usd`, resume and fork. Python and TypeScript Agent SDKs run the same loop | | Telemetry | Usage metrics on by default on the Claude API (`DISABLE_TELEMETRY=1`), error reports on Pro and Max (`DISABLE_ERROR_REPORTING=1`), WebFetch hostname check on every provider (`skipWebFetchPreflight`). OpenTelemetry export opt-in | | Cloud agent | Cloud sessions in Anthropic-managed VMs, with outbound traffic through a logging proxy and GitHub credentials kept outside the VM | | Releases in 90 days | 76 (3 July to 1 October 2026) | | Capabilities | agent.harness, agent.mcp-client, agent.multi-agent | | Tags | official, harness, coding-agent, cli, closed-source, claude-only, mcp, llms-txt, telemetry-default-on, status-page, card-required | | JSON | https://www.anchorterminal.com/api/v1/tools/claude-code.json | ## Score breakdown (methodology v0.3, October 2026 research run) Assessed 2026-10-01 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 50 | 10.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 80 | 13.0 | | Agent ergonomics | 13% | 16.2 | 87 | 14.1 | | Security & auth | 14% | 17.5 | 80 | 14.0 | | Payments & pricing | 10% | 12.5 | 20 | 2.5 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 82 | 7.2 | | Transparency & trust (editorial 68, provenance 100) | 7% | 8.8 | 84 | 7.3 | | Negative events | up to −15 | up to −15 | 2025-10-03 to 2026-06-25. 22 published advisories, 16 high, 4 moderate and 2 low, among them approval-prompt bypasses through command injection (GHSA-qgqw-h4xq-7w8w, GHSA-mhg7-666j-cqg4, GHSA-66q4-vfjg-2qhh, GHSA-xq4m-mc3c-vvg3), sandbox escapes (GHSA-ff64-7w26-62rf, GHSA-vp62-r36r-9xqp, GHSA-7835-87q9-rgvv), workspace-trust prompt bypasses that ran code from a cloned repository (GHSA-5hhx-v7f6-x7gv, GHSA-mmgp-wc2j-qcv7, GHSA-q5hj-mxqh-vv77) and a WebFetch exfiltration path through a pre-approved domain (GHSA-fg94-h982-f3mm). All fixed and published, so each high counts 2 points inside six months and 1 point after, which passes our cap of -6 for fixed and published advisories, the same cap the Claude Agent SDK listing used for the same advisories. None published since 25 June 2026 (https://github.com/anthropics/claude-code/security/advisories) | -6 | | **Total** | | | | **62.2 → B** | ### Why each score - Reliability 50: Local-package reading. Official installers for macOS 13+, Windows 10 1809+, Ubuntu 20.04+, Debian 10+ and Alpine 3.19+, signed apt, dnf and apk repositories and a GPG-signed manifest of checksums for every binary (20). No public CI or test suite for the program, since the source isn't published, and the repository's workflows are issue triage and tests for mods (0). Over 5,000 open issues and 735 open pull requests, with area, platform and regression labels on new reports but no maintainer replies visible on the first page (10). Every change ships as a 2.1.x patch, including the switch of the starting permission mode to auto in 2.1.284, and the changelog has no dates and no breaking-change heading, though a stable channel skips releases with major regressions (5). 2.1.287 (15). Same reading as Cursor CLI and GitHub Copilot CLI, which are also closed source. - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 80: Framework reading. No published JSON Schema for settings that we checked, but the settings reference types every key, and the stream-json output has typed message classes in the Python and TypeScript Agent SDKs (18). llms.txt at code.claude.com/docs/llms.txt with a Markdown version of each page (10). The permission-mode table says what each mode is best for, but the rules carry many version-specific exceptions (mods, protected paths, carve-outs by settings source) that a model has to read closely (15). Permission modes, sandbox settings and rule syntax are enumerated, though rules are strings parsed at runtime (12). Examples on every page and a troubleshooting section for install and auth errors (13). A changelog for every release, versions without dates, dated only through git tags (12). - Agent ergonomics 87: Framework reading, adapted to a harness driven by a pipeline. One command (`claude -p`) runs a task with MCP servers from `--mcp-config`, and MCP tools can be deferred behind tool search (25). `--max-turns`, `--max-budget-usd` and a background-command timeout of 30 minutes by default stop runs, and large MCP results go to a file (20). json and stream-json output, and `-p` errors name the cause, such as Failed to authenticate (16). `--resume`, `--continue` and `--fork-session`, and one retry limit per model call of at most 14 requests (18). Python and TypeScript Agent SDKs, but the starting permission mode now depends on version, plan, provider and telemetry, so a pipeline has to set it (8). - Security & auth 80: Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. Usage metrics on by default on the Claude API, without code, prompts or file paths, error reports on by default for Pro and Max sign-ins since v2.1.198, and every provider sends WebFetch hostnames to api.anthropic.com for a blocklist check, each with an opt-out. All off by default on Bedrock, Google Cloud and Foundry. Consumer plans train on data when the user's setting allows it (18). Six modes, allow, ask and deny rules, protected paths, and managed settings that can disable bypass and auto mode and that nothing else overrides. The sandbox is opt-in and absent on native Windows, and auto mode, a classifier rather than a person, is now the starting mode (16). The auto-mode classifier blocks named exfiltration patterns, the sandbox proxy denies hosts outside an allowlist that starts empty, and WebFetch checks a blocklist, but since 1 October 2026 a mod can approve a call a deny rule refuses unless managed settings or a Team or Enterprise sign-in hold it (11). Opt-in OpenTelemetry with tool content behind `OTEL_LOG_TOOL_CONTENT`, local transcripts for 30 days, and cloud sessions logged through a proxy (15). HackerOne bug bounty, SECURITY.md, advisories published with GHSA ids, and a valid security.txt per the 26 September check (20). SOC 2 isn't scored on the framework reading. Advisories count under negative events. Judgement call, written by an agent on Claude, and this is the same checklist the other four harnesses got. - Payments & pricing 20: Harness reading of the published rubric. No payment protocol (0). Plan prices and per-token API prices are public without a login, though plan usage limits aren't given as numbers (20). No free route. The free claude.ai plan excludes Claude Code, and the API, Bedrock, Google Cloud and Foundry are paid (0). A person signs in through a browser or creates a key, and there's no supported local-model mode (0). Judgement call, against Anthropic's own product. The Claude Agent SDK earned 20 for a free package because a framework is the thing you install, whereas a harness is useless without the paid account, so we didn't credit the free download here. - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 82: 2.1.287 on 2026-10-01 (30). 76 releases between 3 July and 1 October (20). A public issue tracker with automatic triage, duplicate detection and labels, but over 5,000 open issues and no visible maintainer replies on the page we read (12). The Python and TypeScript Agent SDKs that run the same loop are current (15). Signed releases and a stable channel, but no public CI for the program (5). - Transparency & trust 84: Closed source with clear terms, `LICENSE.md` pointing to the Commercial Terms (15). The data-usage page states retention per account type (consumer 30 days or 5 years with training on, commercial 30 days, zero retention for qualified Enterprise), 30 days of plaintext local transcripts, 5 years for /feedback reports and 6 months for shared survey transcripts, and these agree with the privacy policy links, but the logging and error-tracking services are named only as third parties (25). No written deprecation policy. The README and setup page mark npm installs deprecated without a date, and default changes appear in an undated changelog (8). Telemetry is documented per provider and per service with an opt-out for each (20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (13 items): https://www.anchorterminal.com/fixes/claude-code.md (JSON https://www.anchorterminal.com/fixes/claude-code.json) ### What we couldn't check - status.claude.com/history didn't render for our reader and its JSON is disallowed by robots.txt, so we have no incident record for the Claude Code component - unchecked: whether a JSON Schema for settings.json is published - The pricing page gives no numbers for plan usage limits - security.txt rests on the claude-agent-sdk listing's check of 26 September 2026 - The issue page our reader loaded listed issues from 12 August 2026, so the counts may be cached ### Sources - changelog and release tags (git clone): (seen 2026-10-02) - security advisories, pages 1 to 3: (seen 2026-10-02) - SECURITY.md and `LICENSE.md` (git clone): (seen 2026-10-02) - open issues and pull requests: (seen 2026-10-02) - setup, system requirements, signing: (seen 2026-10-02) - permissions: (seen 2026-10-02) - permission modes and auto mode: (seen 2026-10-02) - sandboxing: (seen 2026-10-02) - data usage and telemetry: (seen 2026-10-02) - plans and prices: (seen 2026-10-02) ## Who's behind it (provenance 100/100, checked 2026-10-01) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Anthropic, PBC | 20/20 | | Domain age | claude.com, registered 1995-05-24 (31 years) | 15/15 | | Endpoint on the vendor's domain | no hosted endpoint | n/a | | Terms of service | published | 10/10 | | Privacy policy | published | 10/10 | | Status page | status.claude.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | claude.com was registered in 1995, long before Anthropic bought it. Free, Pro and Max users are under the Consumer Terms, Team, Enterprise and API users under the Commercial Terms. The security.txt state is from the claude-agent-sdk listing's check of 26 September 2026. ## Live (updated 2026-10-04 21:39 UTC) - Vendor status page: none, All Systems Operational - github `anthropics/claude-code` v2.1.289, released 2026-10-03 - npm `@anthropic-ai/claude-code` 2.1.289 - security.txt: none - Watching deprecations , last changed 2026-10-04 15:47 UTC - Always current: https://www.anchorterminal.com/api/v1/live/claude-code.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Pro plan | $20 | per month (plan) | $17 a month billed annually | | Max plan | $100 | per month (plan) | lowest Max tier | Across all listings: https://www.anchorterminal.com/prices/index.md ## Dated changes - 2026-09-28 · Breaking change · Interactive terminal and VS Code sessions start in auto mode when no permission mode is configured, on every plan and provider (2.1.284) (source: ) - 2026-09-29 · Breaking change · `claude -p` and Python Agent SDK sessions on third-party providers or with telemetry off start in auto mode when no permission mode is configured (2.1.285) (source: ) All listings, as a calendar: https://www.anchorterminal.com/sunsets.ics ## Strengths - Six permission modes, allow, ask and deny rules down to command arguments, PreToolUse hooks, and managed settings that can disable bypass and auto mode - An OS sandbox (Seatbelt, bubblewrap) whose network proxy denies every host outside an allowlist that starts empty - `claude -p` with json and stream-json output, `--max-turns`, `--max-budget-usd`, resume and fork, and Python and TypeScript SDKs for the same loop - Signed apt, dnf and apk repositories, a GPG-signed checksum manifest and a stable channel that skips releases with major regressions - Telemetry documented per provider and per service, each with its own opt-out ## Weaknesses - The sandbox is off by default and native Windows has none - Auto mode, a classifier rather than a person, has been the starting mode for interactive sessions on every plan since 28 September 2026 - 22 security advisories in the year to 25 June 2026, 16 rated high - Usage metrics on by default on the Claude API, and error reports on Pro and Max sign-ins - Closed source, Claude models only, and no free plan includes it ## Before you call it (notes for agents) 1. Pass `--permission-mode` on every `claude -p` run. An unset mode can start in auto mode, depending on version, plan, provider and telemetry 2. Turn on the sandbox with `sandbox.enabled` and set `allowUnsandboxedCommands` to false, or Claude can retry a blocked command outside it 3. Set `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1` on a Claude login to stop metrics and error reports in one go 4. Set `autoUpdatesChannel` to stable or `DISABLE_AUTOUPDATER=1` in CI. Native installs update themselves about once a day 5. Cap pipeline runs with `--max-turns` and `--max-budget-usd` ## Connect Install: ```bash curl -fsSL https://claude.ai/install.sh | bash # or: brew install --cask claude-code ``` Headless / CI: ```json { "run": "claude -p \"fix the failing test\" --output-format json --permission-mode acceptEdits --max-turns 20" } ``` ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | goose | BB | 73.9 | 52 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/goose.md | | Gemini CLI | BB | 72.3 | 72 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/gemini-cli.md | | OpenHands | BB | 70.9 | 92 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/openhands.md | | OpenCode | B | 68 | 134 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/opencode.md | | Cline | C | 60.8 | 239 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/cline.md | | GitHub Copilot CLI | C | 57.9 | 286 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/github-copilot-cli.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Auto mode, where a classifier model reviews actions instead of the person, became the built-in starting mode for interactive sessions on Pro, Max and Team in v2.1.228 (11 August 2026) and on every plan and provider in v2.1.283 and v2.1.284 (25 and 28 September). An explicit `defaultMode` or `--permission-mode` still wins (source: ) - Usage metrics go to Anthropic by default on the Claude API, and error reports on Pro and Max sign-ins since v2.1.198. `DISABLE_TELEMETRY=1` and `DISABLE_ERROR_REPORTING=1` turn them off, and both are off by default on Bedrock, Google Cloud, Foundry and Claude Platform on AWS (source: ) - The Bash sandbox (Seatbelt on macOS, bubblewrap and socat on Linux and WSL2) is off by default, and native Windows has none (source: ) - 22 security advisories published between 3 October 2025 and 25 June 2026, 16 rated high, all fixed. None since (source: ) - 76 tagged releases between 3 July and 1 October 2026, with a stable channel about a week behind that skips releases with major regressions (source: ) ## Compare - [Aider vs Claude Code](https://www.anchorterminal.com/compare/aider-vs-claude-code.md): D 47.1 vs B 62.2 - [Claude Code vs Cline](https://www.anchorterminal.com/compare/claude-code-vs-cline.md): B 62.2 vs C 60.8 - [Claude Code vs Cursor CLI](https://www.anchorterminal.com/compare/claude-code-vs-cursor-cli.md): B 62.2 vs F 35.8 - [Claude Code vs Gemini CLI](https://www.anchorterminal.com/compare/claude-code-vs-gemini-cli.md): B 62.2 vs BB 72.3 - [Claude Code vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/claude-code-vs-github-copilot-cli.md): B 62.2 vs C 57.9 - [Claude Code vs goose](https://www.anchorterminal.com/compare/claude-code-vs-goose.md): B 62.2 vs BB 73.9 - [Claude Code vs OpenAI Codex](https://www.anchorterminal.com/compare/claude-code-vs-openai-codex.md): B 62.2 vs BB 73.4 - [Claude Code vs OpenCode](https://www.anchorterminal.com/compare/claude-code-vs-opencode.md): B 62.2 vs B 68 - [Claude Code vs OpenHands](https://www.anchorterminal.com/compare/claude-code-vs-openhands.md): B 62.2 vs BB 70.9 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on claude.com or anthropic.com or one of their subdomains, or the README of github.com/anthropics/claude-code. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "claude-code", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Claude Code on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Claude Code on Anchor Terminal](https://www.anchorterminal.com/badges/claude-code.svg)](https://www.anchorterminal.com/tools/claude-code) ``` Plain link: ```html Claude Code on Anchor Terminal ```