Kiro CLI
by Amazon Web Services Agent harness in Agent harnesses
Amazon Web Services, Inc. · kiro.dev since 2019 · who's behind it
AWS's coding agent for the terminal and the successor to the Amazon Q Developer CLI. It runs interactive chat, non-interactive runs for pipelines with an API key, MCP servers and an Agent Client Protocol server for editors.
Good for Teams on AWS that want one agent configuration across terminal, IDE and web, with central permission policy, prompt logging to their own S3 bucket and IAM Identity Centre sign-in.
Is this your product? Claim this listing or verify it
Assessment. Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.
Facts
- Auth
- OAuth or key
- Pricing
- Freemium · $20 / mo
- x402
- No
- Licence
- Proprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the source
- llms.txt
- published
- Last release
- GitHub stars
- 4.4k
- Models
- Models on the Kiro plan, with Auto as the default router and a choice of OpenAI GPT-5.6, Anthropic Claude and open-weight models, each with a credit multiplier. No bring-your-own-key option was found in the reviewed documentation
- Install
- Install script with SHA-256 checksum verification for macOS and Linux (glibc 2.34 or newer, or a musl build), a .deb and an AppImage, and a PowerShell script for Windows 11
- Engines
- 2.x is the released line (2.28.0 on 5 October 2026). V3, the harness shared with the Kiro IDE and Kiro Web, is an early release chosen with
--v3or--agent-engine v3. Classic sessions show a deprecation notice since 2.26.0 - Approvals
- Capabilities (fs_read, fs_write, shell, web_fetch, web_search, mcp, subagent and others) with deny, ask and allow rules in permissions.yaml. Deny wins in any scope. Defaults allow workspace reads and read-only git commands and ask for the rest.
--trust-toolsand--trust-all-toolsfor non-interactive runs - Workspace trust
- An untrusted workspace doesn't load its custom agents, steering files, MCP configuration, skills or workflows, and asks before every shell command and MCP tool call. The trust decision is stored outside the repository
- Sandbox
- None in the CLI. The docs list sandboxed execution for Kiro Web only. Compound shell commands are split and each part is matched against the rules
- Managed policy
- A managed-settings.json at an OS-protected path adds deny and ask rules for the IDE and the CLI, and a malformed file fails closed. AWS says the policy is client-enforced and can be circumvented by a user with administrative access
- MCP client
- stdio and remote HTTP servers with headers, OAuth with dynamic client registration or supplied client credentials,
autoApproveanddisabledToolsper server, on-demand tool search, and an enterprise MCP registry - Headless
kiro-cli chat --no-interactivewith a prompt as an argument or on stdin,--output-format stream-json,--agent,--model,--effort,--resumeand--resume-id. Exit codes 0, 1, 3 (MCP startup failure) and 4 (requested agent not found)- ACP
kiro-cli acpspeaks the Agent Client Protocol as JSON-RPC 2.0 over stdio for JetBrains IDEs, Zed and other clients. A client can request policy presets such as read-workspace or edit-workspace for a session- Telemetry
- Usage data and performance metrics on by default for Free and individual accounts, turned off with
kiro-cli settings telemetry.enabled false. Content is used for service improvement, including model training, unless the user opts out. Enterprise users are opted out - Data handling
- Content for Free and individual accounts is stored in US East (N. Virginia). Free Tier inputs may be kept up to 60 days for abuse detection, and traffic to some models is retained up to 30 days. Inference runs on Amazon Bedrock with cross-region routing
- Releases in 90 days
- At least 11 minor versions (2.20.0 on 26 August to 2.28.0 on 5 October 2026) plus patch releases. Earlier pages of the changelog weren't counted
- Capabilities
- agent.harness agent.mcp-client agent.multi-agent
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Capability permissions with deny over ask over allow, stored outside the repository so a clone can't add rules
- An untrusted workspace doesn't load its own agents, steering files, MCP configuration or skills, and asks before every shell command
- Headless runs with
--no-interactive, JSON Lines output, and exit codes 3 and 4 for MCP startup and missing-agent failures - Eleven minor releases between 26 August and 5 October 2026 in a dated changelog
- Plan prices, the $0.04 credit price and per-model credit multipliers are public, with a free tier of 50 credits a month
Weaknesses
- Free and individual paid accounts have content used for service improvement, including model training, unless they opt out
- Closed source since it replaced the Apache 2.0 Amazon Q Developer CLI, with no public CI or test suite
- API keys for headless runs need a paid plan, are long-lived and carry no scopes
- No local sandbox in the CLI, and AWS says its managed permission policies are client-enforced and can be circumvented
- Two CVEs in 2026 (CVE-2026-9255 in May, CVE-2026-18656 and CVE-2026-18657 in August), both fixed
Before you call it notes for agents
- Set
KIRO_API_KEYand pass--no-interactivewith--trust-tools=<list>in pipelines. Keep--trust-all-toolsfor disposable environments - Pass
--require-mcp-startupwhen a run depends on MCP tools. Without it a failed server is logged and the run continues - Pass
--no-interactivewhenever input is piped from a source you don't control, and run 2.10.0 or later on Windows - Run
kiro-cli settings telemetry.enabled falseand turn off content collection on Free and individual plans. Both are on by default - Export variables in the shell before starting. Since 2.24.0 a project
.envfile is no longer loaded into sessions, MCP servers or tools
Who's behind it provenance 72/100
- Legal entity namedAmazon Web Services, Inc.20/20
- Domain agekiro.dev, registered 2019-03-01 (7 years)11/15
- Endpoint on the vendor's domainno hosted endpointn/a
- Terms of serviceread, states 7 of the 7 things a reader expects10/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagenot found0/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2026-08-14, states 7 of 7, 2 to know
TL;DR Dated 2026-08-14. States all 7 things a reader expects. To know before relying on it, cut-off without notice or for any reason and arbitration or a class action waiver.
Says access can be ended without notice or for any reason
We may terminate this Agreement for any reason by providing you at least 30 days’ advance notice.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
Disputes will be resolved by binding arbitration, rather than in court, except that either party may elect to proceed in small claims court if your claims qualify.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2026-08-14
Last Updated: August 14, 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the Province of Ontario
The laws of the Province of Ontario, Canada and federal laws of Canada applicable therein
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the fees paid in the 12 months before the claim
…UNDER THIS AGREEMENT OF EITHER AWS OR YOU, AND ANY OF OUR RESPECTIVE AFFILIATES OR LICENSORS, WILL NOT EXCEED THE AMOUNTS PAID BY YOU TO AWS UNDER THIS AGREEMENT FOR THE SERVICES THAT GAVE RISE TO THE LIABILITY DURING THE 12 MONTHS BEFORE THE LIABILITY AROSE;
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
If you become aware of any violation of your obligations under this Agreement caused by an End User, you will immediately suspend access to Your Content and the Services by such End User.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives 90 days of notice before a change
We may change, discontinue or add Service Level Agreements, provided, however, that we will provide at least 90 days’ advance notice for adverse changes to any Service Level Agreement.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
AWS log-in credentials and private keys generated by the Services are for your internal use only and you will not sell, transfer or sublicense them to any other entity or person, except that you may disclose your private key to your agents and subcontractors performing work on your behalf.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Service Level Agreements and Service Terms apply to certain Services.
Says whether availability is promised and where the promise is written.
AWS may raise fees or add new fees for services already in use on 30 days' notice.
We may increase or add new fees and charges for any existing Services you are using by giving you at least 30 days’ prior notice.
Noted by a second reader on 2026-10-08.
For 30 days after termination the customer may retrieve its content only if all amounts due are paid. This period does not apply when AWS terminates under Section 5.2(b).
(ii) we will allow you to retrieve Your Content from the Services only if you have paid all amounts due under this Agreement.
Noted by a second reader on 2026-10-08.
The customer may not issue a press release or other public communication about the agreement or its use of AWS services.
You will not issue any press release or make any other public communication with respect to this Agreement or your use of the Services or AWS Content.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 10,799 words
Privacy policy dated 2026-05-18, states 8 of 8, 1 to know
TL;DR Dated 2026-05-18. States all 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.
Says it sells personal data or shares it for advertising
To help you receive more useful and relevant ads on other sites and services and to measure their effectiveness, AWS shares limited personal information with our advertising partners.
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated Last updated 2026-05-18
Last Updated: May 18, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
This Privacy Notice describes how we collect and use your personal information in relation to AWS websites, applications, products, services, events, and experiences that reference this Privacy Notice (together, “AWS Offerings”).
The basic statement a privacy policy exists to make.
Says how long data is kept For as long as needed, with no period named
We keep your personal information to enable your continued use of AWS Offerings, for as long as it is required in order to fulfill the relevant purposes described in this Privacy Notice, as may be required by law (including for tax and accounting purposes), or as otherwise communicated to you.
Says when data sent to the service is deleted.
Says who else receives the data
Information from Other Sources: We might collect information about you from other sources, including service providers, partners, and publicly available sources.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
Information about our customers is an important part of our business and we are not in the business of selling our customers’ personal information to others.
A plain statement either way.
Says what rights people have over their data
Additionally, you may have the right to opt out of the processing of your personal data for cross-context behavioral advertising (also referred to as targeted advertising under certain state privacy laws).
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact Names a data protection officer
We provide additional information about our controllers and data protection officers (as applicable), the privacy, collection, and use of personal information of prospective and current customers of AWS Offerings located in certain jurisdictions.
An address or officer to send a request to.
Says where data is transferred or stored Relies on the Data Privacy Framework
EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework
The countries data goes to and the safeguard used.
The notice does not cover content that customers process, store or host on AWS. It refers to the customer agreement for how that content is handled.
This Privacy Notice does not apply to the “content” processed, stored, or hosted by our customers using AWS Offerings in connection with an AWS account.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 8,790 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
Kiro's licence page says the Kiro IDE and CLI are licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence. Section 50.14 of the AWS Service Terms names Amazon Web Services, Inc. as the contracting party for subscriptions bought through the Stripe portal.
The AWS Customer Agreement (last updated 14 August 2026) governs use, with the AWS Service Terms sections 50.3 and 50.14 for Kiro. The AWS Privacy Notice (last updated 18 May 2026) is the privacy link in Kiro's footer.
kiro.dev/.well-known/security.txt answers 404. aws.amazon.com publishes a security.txt whose Expires line reads 24 September 2026, which had passed when we read it.
No status page for Kiro was found on kiro.dev or in its docs.
RDAP (Google Registry) gives kiro.dev a registration date of 1 March 2019, before the product.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 18:21 UTC
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| kiro.dev/changelog/cli | deprecations | 50 minutes ago · 200 | no change seen |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/kiro-cli.json
Notable
- Kiro CLI replaced the Amazon Q Developer CLI from 17 November 2025, and installs with auto-update moved across on 24 November 2025. The Q CLI was Apache 2.0 and Kiro CLI is licensed under the AWS Intellectual Property Licence source
- Headless mode needs an API key in
KIRO_API_KEY, which only Pro, Pro+, Pro Max and Power subscribers can create, and which an administrator has to switch on for managed subscriptions source - Content from Free Tier users and individual subscribers may be used for service improvement, including model training, unless they opt out. Enterprise content isn't used source
- Permission rules use deny over ask over allow across six scopes, workspace rules are stored outside the repository, and a headless session treats every ask as a deny source
- CLI V3, built on the harness the Kiro IDE and Kiro Web use, is an early release beside 2.x. It replaces the trust flags with permissions.yaml, changes the session and hook formats and removes the built-in AWS tool source
- AWS published two security bulletins that cover the CLI in 2026, CVE-2026-9255 on 22 May and CVE-2026-18656 with CVE-2026-18657 on 4 August source
- Eleven minor versions from 2.20.0 on 26 August to 2.28.0 on 5 October 2026, with patch releases between them source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 11.4 | |
Local-package reading, the same as the other closed-source harnesses. An install script that verifies SHA-256 checksums, a .deb, an AppImage and a PowerShell script, with macOS, Windows 11 and Linux (glibc 2.34 or newer, or musl) stated (20). No public CI or test suite, since the source isn't published and the GitHub repository is an issue tracker (0). 1,401 open issues in the shared Kiro tracker, 428 labelled cli, with 96 cli issues opened and 69 closed in the 30 days to 8 October, area labels, a triage label and stale-issue automation. Open reports from the last week include a --no-interactive run that never exits after a refusal (12). A dated changelog for every release and a breaking-change table with a migration guide for V3, which runs beside 2.x until the user opts in, though 2.24.0 stopped loading project .env files in a minor version (10). 2.28.0, with V3 still an early release (15). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 12.8 | |
| Framework reading. A command reference, a settings reference, an exit-code page and a documented rule format for permissions, plus the Agent Client Protocol methods the CLI implements. No published schema for the stream-json events was found (14). kiro.dev/llms.txt indexes every docs page and each has a Markdown twin, though robots.txt disallows both for crawlers (10). The permissions page states the defaults, what each preset allows and when to pick it, and that headless runs treat ask as deny (16). Rules are validated, an unknown preset rejects the session request, and a malformed managed policy fails closed (12). CI examples, exit codes 0, 1, 3 and 4 and hook exit codes are documented, but code 1 covers every other failure (12). Versioned releases with a dated changelog and a 2.x reference kept beside V3 (15). | |||
| Agent ergonomics | 13%16.2 | 10.9 | |
Framework reading, adapted to a harness driven by a pipeline. --trust-tools limits approved tools, disabledTools removes MCP tools per server, tool search loads MCP tools on demand, and custom agents carry their own tool set (20). Compaction and a workflow timeout (KIRO_HEADLESS_WORKFLOW_TIMEOUT_SECS, six hours by default) exist, but no cap on turns or run time for a plain headless run was found (10). Distinct exit codes for MCP startup failure and a missing agent, --require-mcp-startup, and a final interruption record in stream-json, with exit 1 for everything else (14). Sessions are saved every turn, with --resume, --resume-id and checkpoints with rewind (15). No SDK. The programmatic interfaces are the headless command and the ACP server, and a headless run needs a paid-plan API key and explicit trust flags (8). | |||
| Security & auth | 14%17.5 | 11.6 | |
| Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. Telemetry and content collection are on by default for Free and individual accounts, each with a documented opt-out, and enterprise users are opted out. API keys are long-lived and revocable with no scopes, and administrators must switch key generation on (14). Deny over ask over allow across six scopes, hard-coded denies on Kiro's own settings paths, workspace trust and a managed policy that fails closed. There is no local sandbox in the CLI, and AWS says managed policies are client-enforced and can be circumvented (16). An untrusted workspace doesn't load its agents, steering, MCP configuration or skills, compound shell commands are split before matching, and the MCP page warns that servers run outside any sandbox (11). Enterprise prompt logging to the customer's S3 bucket covers the CLI, with daily activity reports and OpenTelemetry export, and individuals have local logs only (11). AWS vulnerability reporting with a HackerOne disclosure programme, CVEs published in security bulletins with credit to reporters, ISO/IEC 27001:2022 scope and HIPAA eligibility. kiro.dev has no security.txt and the one on aws.amazon.com expired on 24 September 2026 (14). | |||
| Payments & pricing | 10%12.5 | 5.0 | |
| Harness reading of the published rubric, scored on the Kiro subscription the CLI needs. No payment protocol (0). Plan prices, the $0.04 credit price and per-model credit multipliers are public without a login (20). Kiro Free has 50 credits a month, and the pricing page asks for a card only on upgrade (20). A person signs in through a browser or device flow, and the API key for headless runs is created by hand at app.kiro.dev on a paid plan (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.4 | |
| 2.28.0 on 5 October 2026 (30). At least 11 minor versions and their patches between 26 August and 5 October (20). A public issue tracker with area labels and triage automation, 69 cli issues closed against 96 opened in 30 days, and a Discord server. We didn't establish how many replies come from staff (14). No SDK and no registry entry. The ACP server is kept current, with a migration guide for clients moving to V3 (6). Closed source, so no CI or dependency health to read. The installer verifies checksums (3). | |||
| Transparency & trusteditorial 62, provenance 72 | 7%8.8 | 5.9 | |
Proprietary, with clear terms. The licence page puts the CLI under the AWS Customer Agreement and the AWS Intellectual Property Licence, where the Amazon Q Developer CLI it replaced was Apache 2.0 (15). The data protection page says what is stored for Free, individual and enterprise users, names US East (N. Virginia) for storage, lists inference regions, and gives 60 days for Free Tier abuse detection and 30 days for some models. It agrees with sections 50.3 and 50.14 of the AWS Service Terms. No general retention period for stored content was found (22). Classic sessions carry a deprecation notice and V3 has a breaking-change table and migration guides, but no deprecation policy or removal dates were found (10). Telemetry types are listed and telemetry.enabled turns them off, with collection on by default (15). | |||
| Negative events | ≤15 |
| -4 |
| Total | 59.9 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 21 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Kiro CLI, or have the agent fetch /fixes/kiro-cli.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Kiro CLI From Anchor Terminal's listing at https://www.anchorterminal.com/tools/kiro-cli, the October 2026 research run, assessed 8 October 2026. Grade C, 59.9 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Kiro CLI: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Reliability, 57 out of 100, up to 8.6 more on the total Why it scored 57: Local-package reading, the same as the other closed-source harnesses. An install script that verifies SHA-256 checksums, a .deb, an AppImage and a PowerShell script, with macOS, Windows 11 and Linux (glibc 2.34 or newer, or musl) stated (20). No public CI or test suite, since the source isn't published and the GitHub repository is an issue tracker (0). 1,401 open issues in the shared Kiro tracker, 428 labelled cli, with 96 cli issues opened and 69 closed in the 30 days to 8 October, area labels, a triage label and stale-issue automation. Open reports from the last week include a `--no-interactive` run that never exits after a refusal (12). A dated changelog for every release and a breaking-change table with a migration guide for V3, which runs beside 2.x until the user opts in, though 2.24.0 stopped loading project `.env` files in a minor version (10). 2.28.0, with V3 still an early release (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 2. Payments & pricing, 40 out of 100, up to 7.5 more on the total Why it scored 40: Harness reading of the published rubric, scored on the Kiro subscription the CLI needs. No payment protocol (0). Plan prices, the $0.04 credit price and per-model credit multipliers are public without a login (20). Kiro Free has 50 credits a month, and the pricing page asks for a card only on upgrade (20). A person signs in through a browser or device flow, and the API key for headless runs is created by hand at app.kiro.dev on a paid plan (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Security & auth, 66 out of 100, up to 6 more on the total Why it scored 66: Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. Telemetry and content collection are on by default for Free and individual accounts, each with a documented opt-out, and enterprise users are opted out. API keys are long-lived and revocable with no scopes, and administrators must switch key generation on (14). Deny over ask over allow across six scopes, hard-coded denies on Kiro's own settings paths, workspace trust and a managed policy that fails closed. There is no local sandbox in the CLI, and AWS says managed policies are client-enforced and can be circumvented (16). An untrusted workspace doesn't load its agents, steering, MCP configuration or skills, compound shell commands are split before matching, and the MCP page warns that servers run outside any sandbox (11). Enterprise prompt logging to the customer's S3 bucket covers the CLI, with daily activity reports and OpenTelemetry export, and individuals have local logs only (11). AWS vulnerability reporting with a HackerOne disclosure programme, CVEs published in security bulletins with credit to reporters, ISO/IEC 27001:2022 scope and HIPAA eligibility. kiro.dev has no security.txt and the one on aws.amazon.com expired on 24 September 2026 (14). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 4. Agent ergonomics, 67 out of 100, up to 5.4 more on the total Why it scored 67: Framework reading, adapted to a harness driven by a pipeline. `--trust-tools` limits approved tools, `disabledTools` removes MCP tools per server, tool search loads MCP tools on demand, and custom agents carry their own tool set (20). Compaction and a workflow timeout (`KIRO_HEADLESS_WORKFLOW_TIMEOUT_SECS`, six hours by default) exist, but no cap on turns or run time for a plain headless run was found (10). Distinct exit codes for MCP startup failure and a missing agent, `--require-mcp-startup`, and a final interruption record in stream-json, with exit 1 for everything else (14). Sessions are saved every turn, with `--resume`, `--resume-id` and checkpoints with rewind (15). No SDK. The programmatic interfaces are the headless command and the ACP server, and a headless run needs a paid-plan API key and explicit trust flags (8). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 5. Schema & documentation, 79 out of 100, up to 3.4 more on the total Why it scored 79: Framework reading. A command reference, a settings reference, an exit-code page and a documented rule format for permissions, plus the Agent Client Protocol methods the CLI implements. No published schema for the stream-json events was found (14). kiro.dev/llms.txt indexes every docs page and each has a Markdown twin, though robots.txt disallows both for crawlers (10). The permissions page states the defaults, what each preset allows and when to pick it, and that headless runs treat ask as deny (16). Rules are validated, an unknown preset rejects the session request, and a malformed managed policy fails closed (12). CI examples, exit codes 0, 1, 3 and 4 and hook exit codes are documented, but code 1 covers every other failure (12). Versioned releases with a dated changelog and a 2.x reference kept beside V3 (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 6. Transparency & trust, 67 out of 100, up to 2.9 more on the total Made of editorial 62, provenance 72. Why it scored 67: Proprietary, with clear terms. The licence page puts the CLI under the AWS Customer Agreement and the AWS Intellectual Property Licence, where the Amazon Q Developer CLI it replaced was Apache 2.0 (15). The data protection page says what is stored for Free, individual and enterprise users, names US East (N. Virginia) for storage, lists inference regions, and gives 60 days for Free Tier abuse detection and 30 days for some models. It agrees with sections 50.3 and 50.14 of the AWS Service Terms. No general retention period for stored content was found (22). Classic sessions carry a deprecation notice and V3 has a breaking-change table and migration guides, but no deprecation policy or removal dates were found (10). Telemetry types are listed and `telemetry.enabled` turns them off, with collection on by default (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: kiro.dev, registered 2019-03-01 (7 years) (11 of 15) - Status page: not found (0 of 10) - security.txt: not found (0 of 10) ## 7. Maintenance & community, 73 out of 100, up to 2.4 more on the total Why it scored 73: 2.28.0 on 5 October 2026 (30). At least 11 minor versions and their patches between 26 August and 5 October (20). A public issue tracker with area labels and triage automation, 69 cli issues closed against 96 opened in 30 days, and a Discord server. We didn't establish how many replies come from staff (14). No SDK and no registry entry. The ACP server is kept current, with a migration guide for clients moving to V3 (6). Closed source, so no CI or dependency health to read. The installer verifies checksums (3). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - 2026-08-04. CVE-2026-18656 and CVE-2026-18657 (bulletin 2026-074-AWS), an uncontrolled search path on Windows let a planted executable in a crafted project directory run when a user opened it. Kiro CLI for Windows before 2.10.0 and Kiro IDE 1.0.0 to 1.0.212. Fixed and published with credit to the reporters, inside six months (https://aws.amazon.com/security/security-bulletins/2026-074-aws/). -2 - 2026-05-22. CVE-2026-9255 (bulletin 2026-035-AWS), content piped to kiro-cli on stdin could answer the tool approval prompt, so a local actor could run tools and shell commands without the user's approval. kiro-cli before 1.28.0. Fixed and published, inside six months (https://aws.amazon.com/security/security-bulletins/2026-035-aws/). -2 ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: whether Kiro has a public status page or appears on the AWS Health Dashboard. None is linked from kiro.dev or its docs, and status.kiro.dev didn't answer - unchecked: the event schema of `--output-format stream-json`. The headless page describes the format and no schema was found - unchecked: how many replies in the GitHub issue tracker come from AWS staff, and the Discord server - unchecked: releases before 26 August 2026. Only the first page of the CLI changelog was read, so the 90-day count is a lower bound - unchecked: the AWS sub-processor list and the Data Privacy FAQ the data protection page links to - Whether a paid bug bounty covers Kiro. The AWS security.txt points to a HackerOne vulnerability disclosure programme, and its Expires date of 24 September 2026 had passed - robots.txt on kiro.dev disallows /llms.txt and the Markdown twins for crawlers, while llms.txt tells agents to fetch them. We read the HTML pages for the docs - The headless page documents `--trust-tools` for V3 runs while the V3 page says permissions.yaml replaces the trust flags. We didn't run either engine - The CLI overview page calls ACP the Agent Communication Protocol, and the ACP page calls it the Agent Client Protocol ## Weaknesses - Free and individual paid accounts have content used for service improvement, including model training, unless they opt out - Closed source since it replaced the Apache 2.0 Amazon Q Developer CLI, with no public CI or test suite - API keys for headless runs need a paid plan, are long-lived and carry no scopes - No local sandbox in the CLI, and AWS says its managed permission policies are client-enforced and can be circumvented - Two CVEs in 2026 (CVE-2026-9255 in May, CVE-2026-18656 and CVE-2026-18657 in August), both fixed ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Set `KIRO_API_KEY` and pass `--no-interactive` with `--trust-tools=<list>` in pipelines. Keep `--trust-all-tools` for disposable environments - Pass `--require-mcp-startup` when a run depends on MCP tools. Without it a failed server is logged and the run continues - Pass `--no-interactive` whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows - Run `kiro-cli settings telemetry.enabled false` and turn off content collection on Free and individual plans. Both are on by default - Export variables in the shell before starting. Since 2.24.0 a project `.env` file is no longer loaded into sessions, MCP servers or tools ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: whether Kiro has a public status page or appears on the AWS Health Dashboard. None is linked from kiro.dev or its docs, and status.kiro.dev didn't answer
- unchecked: the event schema of
--output-format stream-json. The headless page describes the format and no schema was found - unchecked: how many replies in the GitHub issue tracker come from AWS staff, and the Discord server
- unchecked: releases before 26 August 2026. Only the first page of the CLI changelog was read, so the 90-day count is a lower bound
- unchecked: the AWS sub-processor list and the Data Privacy FAQ the data protection page links to
- Whether a paid bug bounty covers Kiro. The AWS security.txt points to a HackerOne vulnerability disclosure programme, and its Expires date of 24 September 2026 had passed
- robots.txt on kiro.dev disallows /llms.txt and the Markdown twins for crawlers, while llms.txt tells agents to fetch them. We read the HTML pages for the docs
- The headless page documents
--trust-toolsfor V3 runs while the V3 page says permissions.yaml replaces the trust flags. We didn't run either engine - The CLI overview page calls ACP the Agent Communication Protocol, and the ACP page calls it the Agent Client Protocol
Sources 36
- CLI overview kiro.dev · seen 2026-10-08
- headless mode kiro.dev · seen 2026-10-08
- authentication and API keys kiro.dev · seen 2026-10-08
- permissions and workspace trust kiro.dev · seen 2026-10-08
- enterprise permission policies kiro.dev · seen 2026-10-08
- API key governance kiro.dev · seen 2026-10-08
- exit codes kiro.dev · seen 2026-10-08
- CLI command reference kiro.dev · seen 2026-10-08
- settings reference kiro.dev · seen 2026-10-08
- ACP server kiro.dev · seen 2026-10-08
- CLI V3 and breaking changes kiro.dev · seen 2026-10-08
- MCP configuration kiro.dev · seen 2026-10-08
- MCP security kiro.dev · seen 2026-10-08
- data protection, service improvement and telemetry kiro.dev · seen 2026-10-08
- compliance programmes kiro.dev · seen 2026-10-08
- prompt logging kiro.dev · seen 2026-10-08
- installation and system requirements kiro.dev · seen 2026-10-08
- install script cli.kiro.dev · seen 2026-10-08
- migration from the Amazon Q Developer CLI kiro.dev · seen 2026-10-08
- pricing kiro.dev · seen 2026-10-08
- billing tiers kiro.dev · seen 2026-10-08
- models and credit multipliers kiro.dev · seen 2026-10-08
- CLI changelog kiro.dev · seen 2026-10-08
- licence kiro.dev · seen 2026-10-08
- llms.txt kiro.dev · seen 2026-10-08
- robots.txt kiro.dev · seen 2026-10-08
- issue tracker README and workflows (git clone) github.com · seen 2026-10-08
- issue counts (GitHub API) api.github.com · seen 2026-10-08
- security bulletin 2026-035-AWS, CVE-2026-9255 aws.amazon.com · seen 2026-10-08
- security bulletin 2026-074-AWS, CVE-2026-18656 and CVE-2026-18657 aws.amazon.com · seen 2026-10-08
- AWS security bulletins feed aws.amazon.com · seen 2026-10-08
- AWS Service Terms, sections 1.24, 50.3 and 50.14 aws.amazon.com · seen 2026-10-08
- AWS Customer Agreement aws.amazon.com · seen 2026-10-08
- AWS Privacy Notice aws.amazon.com · seen 2026-10-08
- AWS security.txt aws.amazon.com · seen 2026-10-08
- domain registration (RDAP) rdap.org · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $20 / mo Kiro Free is $0 with 50 credits a month and a reduced model list. Pro is $20 a user a month with 1,000 credits, Pro+ $40 with 2,000, Pro Max $100 with 5,000 and Power $200 with 10,000, and extra credits cost $0.04 each. Models use credits at different rates (Auto is the 1.0x baseline). API keys for headless runs need a paid plan, and a paid plan needs a card. GovCloud prices are about 20 per cent higher with no free tier (checked 2026-10-08).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Kiro Pro | $20 | per month (plan) | per user, with 1,000 credits |
| Add-on credit | $0.04 | per credit | paid plans, beyond the plan's credits |
Compared across listings on the price index.
Dated changes shutdowns, breaking changes, price changes
- Breaking change Project
.envfiles no longer load automatically into chat sessions, MCP servers or tools (2.24.0) source - Notice Classic (non-TUI) sessions show a deprecation notice and don't support the V3 engine (2.26.0). No removal date was found source
All of these, for every listing, are on Sunsets and in the calendar feed.
Recent changes
- Latest release
- Classic (non-TUI) sessions show a deprecation notice and don't support the V3 engine (2.26.0). No removal date was found source
- Project
.envfiles no longer load automatically into chat sessions, MCP servers or tools (2.24.0) source
Follow them as a feed at /feeds/tools/kiro-cli.xml, or this listing's score history at history.json.
Connect
Install
curl -fsSL https://cli.kiro.dev/install | bash
Headless / CI
{
"run": "KIRO_API_KEY=ksk_... kiro-cli chat --no-interactive --trust-tools=read,grep \"Find all TODO comments in src/\""
}
Compare with
goose BBQwen Code BBGemini CLI BBOpenHands BBOpenCode BClaude Code C
Head to head Aider vs Kiro CLI · Amp vs Kiro CLI · Claude Code vs Kiro CLI · Cline vs Kiro CLI · Cursor CLI vs Kiro CLI · Devin vs Kiro CLI · Pi vs Kiro CLI · Gemini CLI vs Kiro CLI · GitHub Copilot CLI vs Kiro CLI · goose vs Kiro CLI · Kiro CLI vs OpenAI Codex · Kiro CLI vs OpenCode · Kiro CLI vs OpenHands · Kiro CLI vs Prime Agent · Kiro CLI vs Qwen Code · Kiro CLI vs Paperclip
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| goose Agentic AI Foundation (originally Block) | BB | 73.9 | agent.harness agent.mcp-client agent.multi-agent | no |
| Qwen Code Alibaba (Qwen team) | BB | 72.4 | agent.harness agent.mcp-client agent.multi-agent | no |
| Gemini CLI Google | BB | 72 | agent.harness agent.mcp-client agent.multi-agent | no |
| OpenHands All Hands AI | BB | 70.8 | agent.harness agent.mcp-client agent.multi-agent | no |
| OpenCode Anomaly | B | 67.7 | agent.harness agent.mcp-client agent.multi-agent | no |
| Claude Code Anthropic | C | 61.9 | agent.harness agent.mcp-client agent.multi-agent | no |
Machine-readable
- JSON
/api/v1/tools/kiro-cli.json· historyhistory.json· badge/badges/kiro-cli.svg· changes feed/feeds/tools/kiro-cli.xml - Markdown
/tools/kiro-cli.md· slim/tools/kiro-cli.min.md(or sendAccept: text/markdown) - Fix list
/fixes/kiro-cli.md·/fixes/kiro-cli.json - From a terminal
anchor tool kiro-cli --md(the CLI) · over MCPget_tool {"slug": "kiro-cli"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/kiro-cli"><img src="https://www.anchorterminal.com/badges/kiro-cli.svg" alt="Kiro CLI on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/kiro-cli)<a href="https://www.anchorterminal.com/tools/kiro-cli">Kiro CLI on Anchor Terminal</a>It counts on a page on kiro.dev or one of its subdomains, or the README of github.com/kirodotdev/Kiro.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "kiro-cli", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


