# Droid CLI (slim) > Droid CLI is Factory's closed-source coding agent for the terminal. It runs interactively or headless through droid exec, connects MCP servers, runs multi-agent Missions, and can be driven by TypeScript and Python SDKs. A paid Factory plan is required. - Full: https://www.anchorterminal.com/tools/droid-cli.md (~8,350 tokens) · this version ~1,580 tokens · JSON https://www.anchorterminal.com/tools/droid-cli.json · canonical https://www.anchorterminal.com/tools/droid-cli - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **C · 59.1/100 · rank #560 of 950 · #13 in Agent harnesses · not agent-ready · confidence medium** Assessment: `droid exec` is read-only unless `--auto` raises the autonomy level, with command rules, an optional kernel-enforced sandbox, JSON output and documented exit codes. No free tier, status page or security.txt was found, the source is closed, and usage metrics go to Factory by default. ## Facts - Kind: Agent harness · vendor: Factory · category: Agent harnesses · legal entity: The San Francisco AI Factory, Inc. · provenance 72/100 - Packages: npm `droid`, npm `@factory/droid-sdk`, pypi `droid-sdk` - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary, under Factory's Terms and Conditions. The `droid` npm package is marked `UNLICENSED` and the public repository holds documentation only. The Python SDK is Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - Interfaces: Interactive terminal UI (`droid`), headless `droid exec`, JSON-RPC over stdin and stdout, TypeScript and Python SDKs, and Agent Client Protocol for editors - Install: curl script for macOS and Linux with SHA-256 check, PowerShell for Windows, Homebrew cask, or the `droid` npm package (Node 20 or later) with prebuilt binaries for Linux, macOS and Windows on x64 and arm64 - Autonomy: Off, Low, Medium and High. `droid exec` is read-only without `--auto`. Missions need High or `--skip-permissions-unsafe` - Command policy: `permissionRules` with allow, ask and block decisions, checked with `droid rules check`. A block applies even under `--skip-permissions-unsafe` - Sandbox: Off by default. Seatbelt on macOS, bubblewrap with seccomp on Linux and WSL2, and a filtering proxy for network. Modes `per-command` (default) and `whole-process` - MCP client: `droid mcp add` for http, sse and stdio servers, OAuth with dynamic client registration, `disabledTools` per server, approvals bound to the server's command or URL, and an organisation allowlist - Headless: `droid exec` with text, json, stream-json and stream-jsonrpc output, `--session-id`, `--fork`, `--worktree`, `--restrict-tools` and `--disabled-tools`. Exit codes 0, 1 and 2 - Models: Factory-managed models chosen with `--model`, or custom models in `~/.factory/settings.json` with your own key and base URL - Telemetry: OpenTelemetry metrics to Factory's collector by default and to your own collector when configured. Message content goes only to your own collector and only when switched on - Updates: Standalone installs update themselves. The npm build has updates off. `droid update --version` selects or rolls back a version - Prices: Pro plan $20 per month (plan); Plus plan $100 per month (plan); Max plan $200 per month (plan); Teams seat $40 per seat per month - Scores: Reliability 49, Performance pending, Schema & documentation 79, Agent ergonomics 72, Security & auth 63, Payments & pricing 10, Task success pending, Maintenance & community 79, Transparency & trust 64 · total over the 7 assessed categories - Why: Reliability, Local-package reading, as for the other closed-source harnesses. · Schema & documentation, Framework reading. · Agent ergonomics, Harness reading of the framework line. · Security & auth, Harness reading of the framework checklist, as for the other harnesses. · Payments & pricing, Harness reading of the published rubric. · Maintenance & community, The changelog's newest entry is CLI v0.236.0 of 8 October 2026, and npm and the install script served 0.237.0 on 9 October 2026 (30). · Transparency & trust, Closed source under terms from The San Francisco AI Factory, Inc., last updated 14 July 2026. The npm package is marked `UNLICENSED` and the… - Sources: 29, open questions: 15, both in the full twin - Capabilities: agent.harness, agent.mcp-client, agent.multi-agent - JSON: https://www.anchorterminal.com/api/v1/tools/droid-cli.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/droid-cli.svg` or a link to https://www.anchorterminal.com/tools/droid-cli from a page on factory.com or one of its subdomains, or the README of github.com/Factory-AI/factory, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Set `FACTORY_API_KEY` (starts `fk-`) from the API keys page in Factory settings for headless runs. Interactive use signs in through a browser 2. Start with `droid exec` and no flags for analysis. Add `--auto low` for edits and `--auto medium` for installs, tests and local commits 3. Use `--output-format json` and read `is_error`, `num_turns` and `session_id`. Treat a non-zero exit code as failure 4. Set `sandbox.enabled` to true before running on untrusted code. In `droid exec` a sandbox violation is denied without a prompt 5. Pin the version in CI with `npm install -g droid@`, or set `FACTORY_DROID_AUTO_UPDATE_ENABLED=false` on standalone installs, which update themselves ## Connect ```bash curl -fsSL https://app.factory.ai/cli | sh # or: npm install -g droid ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Kilo Code CLI | BB | 75.4 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/kilo-code-cli.min.md | | goose | BB | 73.9 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/goose.min.md | | Qwen Code | BB | 72.4 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/qwen-code.min.md | | Gemini CLI | BB | 72 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/gemini-cli.min.md | | OpenHands | BB | 70.8 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/openhands.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)