# Kilo Code CLI (slim) > Open-source coding agent for the terminal, forked from opencode and built from the same repository as Kilo's VS Code and JetBrains extensions. It runs with your own provider key, a local model or the Kilo Gateway. - Full: https://www.anchorterminal.com/tools/kilo-code-cli.md (~7,700 tokens) · this version ~1,380 tokens · JSON https://www.anchorterminal.com/tools/kilo-code-cli.json · canonical https://www.anchorterminal.com/tools/kilo-code-cli - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **BB · 75.4/100 · rank #47 of 842 · #1 in Agent harnesses · agent-ready · confidence medium** Assessment: Shell commands ask before running by default, and an optional operating-system sandbox blocks writes outside the workspace and outbound network. Telemetry to PostHog is on by default and the sandbox is off, so an unattended `kilo run --auto` approves everything not denied unless both are configured first. ## Facts - Kind: Agent harness · vendor: Kilo Code Inc. · category: Agent harnesses · legal entity: Kilo Code Inc. (the terms are a contract with Anaconda, Inc. on behalf of itself and its affiliates, including Kilo Code Inc.) · provenance 90/100 - Packages: npm `@kilocode/cli`, npm `@kilocode/sdk` - Auth: OAuth or key · pricing: Freemium · x402: no · licence: MIT - Probe metrics: not measured yet (probes haven't run) - Interfaces: Terminal CLI and TUI, `kilo serve` HTTP server, ACP server (`kilo acp`), TypeScript SDK. The same repository ships the VS Code extension and JetBrains plugin - Install: npm, pnpm, bun, an install script, a Homebrew tap, AUR, and release binaries for Linux, macOS and Windows - Models: Your own provider keys, local models, or the Kilo Gateway, which the vendor says carries 500+ models - Approvals: `allow`, `ask` or `deny` per tool with glob rules. Shell commands ask outside a built-in allow list, edits in the project run without asking, `.env` reads and outside paths ask - Sandbox: Off by default. Seatbelt on macOS and Bubblewrap on Linux, write limits plus `sandbox.network` deny with `sandbox.allowed_hosts`. None on Windows - MCP client: Local (stdio) and remote (HTTP) servers under `mcp` in `kilo.json`, OAuth through `kilo mcp auth`, permission globs over tool names - Headless: `kilo run` with `--auto`, `--format json`, `--continue`, `--session` and `--fork`. Exit codes 0, 1 and 124 - Agents: Code, Plan, Ask and Debug, custom agents, and subagents - Telemetry: PostHog, on by default. Off with `experimental.openTelemetry` false or `KILO_TELEMETRY_LEVEL`. Optional OTLP export when `OTEL_EXPORTER_OTLP_ENDPOINT` is set - Releases in 90 days: 37 stable (10 July to 8 October 2026) - Prices: Kilo Pass, entry tier $19 per month (plan); Teams plan $15 per seat per month - Scores: Reliability 85, Performance pending, Schema & documentation 90, Agent ergonomics 72, Security & auth 66, Payments & pricing 50, Task success pending, Maintenance & community 87, Transparency & trust 76 · total over the 7 assessed categories - Why: Reliability, Local-package reading. · Schema & documentation, Framework reading. · Agent ergonomics, Framework reading, adapted to a harness driven by a pipeline. · Security & auth, Harness reading of the framework checklist. · Payments & pricing, No payment protocol (0). · Maintenance & community, 7.8.8 on 7 October 2026 (30). · Transparency & trust, MIT, with opencode's copyright kept in the licence file (30). - Sources: 28, open questions: 8, both in the full twin - Capabilities: agent.harness, agent.mcp-client, agent.multi-agent - JSON: https://www.anchorterminal.com/api/v1/tools/kilo-code-cli.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/kilo-code-cli.svg` or a link to https://www.anchorterminal.com/tools/kilo-code-cli from a page on kilo.ai or one of its subdomains, or the README of github.com/Kilo-Org/kilocode, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Set `sandbox.enabled` to true in the global `kilo.jsonc` before `kilo run --auto`. `--auto` approves every permission request not explicitly denied 2. Set `experimental.openTelemetry` to false, or `KILO_TELEMETRY_LEVEL` to a value other than `all`, to stop telemetry 3. Add needed hosts to `sandbox.allowed_hosts` in global config. MCP tool calls are unavailable while network restriction is on 4. Without `--auto` a non-interactive run rejects every permission prompt and exits 1 5. Put provider keys in global config or the environment. `{env:VAR}` in a project `kilo.json` is ignored ## Connect ```bash npm install -g @kilocode/cli # or: brew install Kilo-Org/tap/kilo ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | goose | BB | 73.9 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/goose.min.md | | Qwen Code | BB | 72.4 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/qwen-code.min.md | | Gemini CLI | BB | 72 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/gemini-cli.min.md | | OpenHands | BB | 70.8 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/openhands.min.md | | OpenCode | B | 67.7 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/opencode.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)