{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/goose.json",
        "name": "goose",
        "score": 73.9,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "goose"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/qwen-code.json",
        "name": "Qwen Code",
        "score": 72.4,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "qwen-code"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/gemini-cli.json",
        "name": "Gemini CLI",
        "score": 72,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "gemini-cli"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/openhands.json",
        "name": "OpenHands",
        "score": 70.8,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "openhands"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/opencode.json",
        "name": "OpenCode",
        "score": 67.7,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "opencode"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/claude-code.json",
        "name": "Claude Code",
        "score": 61.9,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "claude-code"
      }
    ],
    "tool": {
      "slug": "kiro-cli",
      "name": "Kiro CLI",
      "vendor": "Amazon Web Services",
      "vendorUrl": "https://kiro.dev/cli/",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "AWS's coding agent for the terminal and the successor to the Amazon Q Developer CLI. It runs interactive chat, non-interactive runs for pipelines with an API key, MCP servers and an Agent Client Protocol server for editors.",
      "url": "https://www.anchorterminal.com/tools/kiro-cli",
      "markdownUrl": "https://www.anchorterminal.com/tools/kiro-cli.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kiro-cli.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kiro-cli.json",
      "repo": "https://github.com/kirodotdev/Kiro",
      "license": "Proprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the source",
      "transports": [],
      "packages": [],
      "auth": "mixed",
      "authNotes": "`kiro-cli login` with GitHub, Google, AWS Builder ID, AWS IAM Identity Centre or an external identity provider, in a browser or by device flow on a remote machine. Pipelines use an API key in `KIRO_API_KEY`, created at app.kiro.dev by Pro, Pro+, Pro Max and Power subscribers. Keys are long-lived, named and revocable, with no scopes, and API key generation is off by default for subscriptions an administrator manages. An active browser session takes precedence over the key.",
      "pricing": "freemium",
      "pricingNotes": "Kiro Free is $0 with 50 credits a month and a reduced model list. Pro is $20 a user a month with 1,000 credits, Pro+ $40 with 2,000, Pro Max $100 with 5,000 and Power $200 with 10,000, and extra credits cost $0.04 each. Models use credits at different rates (Auto is the 1.0x baseline). API keys for headless runs need a paid plan, and a paid plan needs a card. GovCloud prices are about 20 per cent higher with no free tier (checked 2026-10-08).",
      "priceSummary": "$20 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the CLI changelog (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4356,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://kiro.dev/docs/cli/",
      "llmsTxt": "https://kiro.dev/llms.txt",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "official",
        "harness",
        "coding-agent",
        "cli",
        "closed-source",
        "mcp",
        "acp",
        "llms-txt",
        "free-tier",
        "no-card",
        "telemetry-default-on"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.9,
        "grade": "C",
        "agentReady": false,
        "rank": 419,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 11,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 73,
          "payments": 40,
          "reliability": 57,
          "schema": 79,
          "security": 66,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 57,
            "points": 11.4,
            "reason": "Local-package reading, the same as the other closed-source harnesses. An install script that verifies SHA-256 checksums, a .deb, an AppImage and a PowerShell script, with macOS, Windows 11 and Linux (glibc 2.34 or newer, or musl) stated (20). No public CI or test suite, since the source isn't published and the GitHub repository is an issue tracker (0). 1,401 open issues in the shared Kiro tracker, 428 labelled cli, with 96 cli issues opened and 69 closed in the 30 days to 8 October, area labels, a triage label and stale-issue automation. Open reports from the last week include a `--no-interactive` run that never exits after a refusal (12). A dated changelog for every release and a breaking-change table with a migration guide for V3, which runs beside 2.x until the user opts in, though 2.24.0 stopped loading project `.env` files in a minor version (10). 2.28.0, with V3 still an early release (15)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 79,
            "points": 12.84,
            "reason": "Framework reading. A command reference, a settings reference, an exit-code page and a documented rule format for permissions, plus the Agent Client Protocol methods the CLI implements. No published schema for the stream-json events was found (14). kiro.dev/llms.txt indexes every docs page and each has a Markdown twin, though robots.txt disallows both for crawlers (10). The permissions page states the defaults, what each preset allows and when to pick it, and that headless runs treat ask as deny (16). Rules are validated, an unknown preset rejects the session request, and a malformed managed policy fails closed (12). CI examples, exit codes 0, 1, 3 and 4 and hook exit codes are documented, but code 1 covers every other failure (12). Versioned releases with a dated changelog and a 2.x reference kept beside V3 (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 67,
            "points": 10.89,
            "reason": "Framework reading, adapted to a harness driven by a pipeline. `--trust-tools` limits approved tools, `disabledTools` removes MCP tools per server, tool search loads MCP tools on demand, and custom agents carry their own tool set (20). Compaction and a workflow timeout (`KIRO_HEADLESS_WORKFLOW_TIMEOUT_SECS`, six hours by default) exist, but no cap on turns or run time for a plain headless run was found (10). Distinct exit codes for MCP startup failure and a missing agent, `--require-mcp-startup`, and a final interruption record in stream-json, with exit 1 for everything else (14). Sessions are saved every turn, with `--resume`, `--resume-id` and checkpoints with rewind (15). No SDK. The programmatic interfaces are the headless command and the ACP server, and a headless run needs a paid-plan API key and explicit trust flags (8)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 66,
            "points": 11.55,
            "reason": "Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. Telemetry and content collection are on by default for Free and individual accounts, each with a documented opt-out, and enterprise users are opted out. API keys are long-lived and revocable with no scopes, and administrators must switch key generation on (14). Deny over ask over allow across six scopes, hard-coded denies on Kiro's own settings paths, workspace trust and a managed policy that fails closed. There is no local sandbox in the CLI, and AWS says managed policies are client-enforced and can be circumvented (16). An untrusted workspace doesn't load its agents, steering, MCP configuration or skills, compound shell commands are split before matching, and the MCP page warns that servers run outside any sandbox (11). Enterprise prompt logging to the customer's S3 bucket covers the CLI, with daily activity reports and OpenTelemetry export, and individuals have local logs only (11). AWS vulnerability reporting with a HackerOne disclosure programme, CVEs published in security bulletins with credit to reporters, ISO/IEC 27001:2022 scope and HIPAA eligibility. kiro.dev has no security.txt and the one on aws.amazon.com expired on 24 September 2026 (14)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 40,
            "points": 5,
            "reason": "Harness reading of the published rubric, scored on the Kiro subscription the CLI needs. No payment protocol (0). Plan prices, the $0.04 credit price and per-model credit multipliers are public without a login (20). Kiro Free has 50 credits a month, and the pricing page asks for a card only on upgrade (20). A person signs in through a browser or device flow, and the API key for headless runs is created by hand at app.kiro.dev on a paid plan (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 73,
            "points": 6.39,
            "reason": "2.28.0 on 5 October 2026 (30). At least 11 minor versions and their patches between 26 August and 5 October (20). A public issue tracker with area labels and triage automation, 69 cli issues closed against 96 opened in 30 days, and a Discord server. We didn't establish how many replies come from staff (14). No SDK and no registry entry. The ACP server is kept current, with a migration guide for clients moving to V3 (6). Closed source, so no CI or dependency health to read. The installer verifies checksums (3)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 67,
            "points": 5.86,
            "note": "editorial 62, provenance 72",
            "reason": "Proprietary, with clear terms. The licence page puts the CLI under the AWS Customer Agreement and the AWS Intellectual Property Licence, where the Amazon Q Developer CLI it replaced was Apache 2.0 (15). The data protection page says what is stored for Free, individual and enterprise users, names US East (N. Virginia) for storage, lists inference regions, and gives 60 days for Free Tier abuse detection and 30 days for some models. It agrees with sections 50.3 and 50.14 of the AWS Service Terms. No general retention period for stored content was found (22). Classic sessions carry a deprecation notice and V3 has a breaking-change table and migration guides, but no deprecation policy or removal dates were found (10). Telemetry types are listed and `telemetry.enabled` turns them off, with collection on by default (15)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Framework reading, adapted to a harness driven by a pipeline. `--trust-tools` limits approved tools, `disabledTools` removes MCP tools per server, tool search loads MCP tools on demand, and custom agents carry their own tool set (20). Compaction and a workflow timeout (`KIRO_HEADLESS_WORKFLOW_TIMEOUT_SECS`, six hours by default) exist, but no cap on turns or run time for a plain headless run was found (10). Distinct exit codes for MCP startup failure and a missing agent, `--require-mcp-startup`, and a final interruption record in stream-json, with exit 1 for everything else (14). Sessions are saved every turn, with `--resume`, `--resume-id` and checkpoints with rewind (15). No SDK. The programmatic interfaces are the headless command and the ACP server, and a headless run needs a paid-plan API key and explicit trust flags (8).",
            "maintenance": "2.28.0 on 5 October 2026 (30). At least 11 minor versions and their patches between 26 August and 5 October (20). A public issue tracker with area labels and triage automation, 69 cli issues closed against 96 opened in 30 days, and a Discord server. We didn't establish how many replies come from staff (14). No SDK and no registry entry. The ACP server is kept current, with a migration guide for clients moving to V3 (6). Closed source, so no CI or dependency health to read. The installer verifies checksums (3).",
            "payments": "Harness reading of the published rubric, scored on the Kiro subscription the CLI needs. No payment protocol (0). Plan prices, the $0.04 credit price and per-model credit multipliers are public without a login (20). Kiro Free has 50 credits a month, and the pricing page asks for a card only on upgrade (20). A person signs in through a browser or device flow, and the API key for headless runs is created by hand at app.kiro.dev on a paid plan (0).",
            "reliability": "Local-package reading, the same as the other closed-source harnesses. An install script that verifies SHA-256 checksums, a .deb, an AppImage and a PowerShell script, with macOS, Windows 11 and Linux (glibc 2.34 or newer, or musl) stated (20). No public CI or test suite, since the source isn't published and the GitHub repository is an issue tracker (0). 1,401 open issues in the shared Kiro tracker, 428 labelled cli, with 96 cli issues opened and 69 closed in the 30 days to 8 October, area labels, a triage label and stale-issue automation. Open reports from the last week include a `--no-interactive` run that never exits after a refusal (12). A dated changelog for every release and a breaking-change table with a migration guide for V3, which runs beside 2.x until the user opts in, though 2.24.0 stopped loading project `.env` files in a minor version (10). 2.28.0, with V3 still an early release (15).",
            "schema": "Framework reading. A command reference, a settings reference, an exit-code page and a documented rule format for permissions, plus the Agent Client Protocol methods the CLI implements. No published schema for the stream-json events was found (14). kiro.dev/llms.txt indexes every docs page and each has a Markdown twin, though robots.txt disallows both for crawlers (10). The permissions page states the defaults, what each preset allows and when to pick it, and that headless runs treat ask as deny (16). Rules are validated, an unknown preset rejects the session request, and a malformed managed policy fails closed (12). CI examples, exit codes 0, 1, 3 and 4 and hook exit codes are documented, but code 1 covers every other failure (12). Versioned releases with a dated changelog and a 2.x reference kept beside V3 (15).",
            "security": "Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. Telemetry and content collection are on by default for Free and individual accounts, each with a documented opt-out, and enterprise users are opted out. API keys are long-lived and revocable with no scopes, and administrators must switch key generation on (14). Deny over ask over allow across six scopes, hard-coded denies on Kiro's own settings paths, workspace trust and a managed policy that fails closed. There is no local sandbox in the CLI, and AWS says managed policies are client-enforced and can be circumvented (16). An untrusted workspace doesn't load its agents, steering, MCP configuration or skills, compound shell commands are split before matching, and the MCP page warns that servers run outside any sandbox (11). Enterprise prompt logging to the customer's S3 bucket covers the CLI, with daily activity reports and OpenTelemetry export, and individuals have local logs only (11). AWS vulnerability reporting with a HackerOne disclosure programme, CVEs published in security bulletins with credit to reporters, ISO/IEC 27001:2022 scope and HIPAA eligibility. kiro.dev has no security.txt and the one on aws.amazon.com expired on 24 September 2026 (14).",
            "transparency": "Proprietary, with clear terms. The licence page puts the CLI under the AWS Customer Agreement and the AWS Intellectual Property Licence, where the Amazon Q Developer CLI it replaced was Apache 2.0 (15). The data protection page says what is stored for Free, individual and enterprise users, names US East (N. Virginia) for storage, lists inference regions, and gives 60 days for Free Tier abuse detection and 30 days for some models. It agrees with sections 50.3 and 50.14 of the AWS Service Terms. No general retention period for stored content was found (22). Classic sessions carry a deprecation notice and V3 has a breaking-change table and migration guides, but no deprecation policy or removal dates were found (10). Telemetry types are listed and `telemetry.enabled` turns them off, with collection on by default (15)."
          },
          "sources": [
            {
              "what": "CLI overview",
              "url": "https://kiro.dev/docs/cli/",
              "seen": "2026-10-08"
            },
            {
              "what": "headless mode",
              "url": "https://kiro.dev/docs/cli/headless/",
              "seen": "2026-10-08"
            },
            {
              "what": "authentication and API keys",
              "url": "https://kiro.dev/docs/getting-started/authentication/",
              "seen": "2026-10-08"
            },
            {
              "what": "permissions and workspace trust",
              "url": "https://kiro.dev/docs/permissions/",
              "seen": "2026-10-08"
            },
            {
              "what": "enterprise permission policies",
              "url": "https://kiro.dev/docs/enterprise/governance/permissions/",
              "seen": "2026-10-08"
            },
            {
              "what": "API key governance",
              "url": "https://kiro.dev/docs/enterprise/governance/api-keys/",
              "seen": "2026-10-08"
            },
            {
              "what": "exit codes",
              "url": "https://kiro.dev/docs/reference/exit-codes/",
              "seen": "2026-10-08"
            },
            {
              "what": "CLI command reference",
              "url": "https://kiro.dev/docs/reference/cli-commands/",
              "seen": "2026-10-08"
            },
            {
              "what": "settings reference",
              "url": "https://kiro.dev/docs/reference/settings/",
              "seen": "2026-10-08"
            },
            {
              "what": "ACP server",
              "url": "https://kiro.dev/docs/cli/acp/",
              "seen": "2026-10-08"
            },
            {
              "what": "CLI V3 and breaking changes",
              "url": "https://kiro.dev/docs/cli/v3/",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP configuration",
              "url": "https://kiro.dev/docs/mcp/configuration/",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP security",
              "url": "https://kiro.dev/docs/mcp/security/",
              "seen": "2026-10-08"
            },
            {
              "what": "data protection, service improvement and telemetry",
              "url": "https://kiro.dev/docs/privacy-and-security/data-protection/",
              "seen": "2026-10-08"
            },
            {
              "what": "compliance programmes",
              "url": "https://kiro.dev/docs/privacy-and-security/compliance-validation/",
              "seen": "2026-10-08"
            },
            {
              "what": "prompt logging",
              "url": "https://kiro.dev/docs/enterprise/monitor-and-track/prompt-logging/",
              "seen": "2026-10-08"
            },
            {
              "what": "installation and system requirements",
              "url": "https://kiro.dev/docs/getting-started/installation/",
              "seen": "2026-10-08"
            },
            {
              "what": "install script",
              "url": "https://cli.kiro.dev/install",
              "seen": "2026-10-08"
            },
            {
              "what": "migration from the Amazon Q Developer CLI",
              "url": "https://kiro.dev/docs/upgrade-guides/migrating-from-q/",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://kiro.dev/pricing/",
              "seen": "2026-10-08"
            },
            {
              "what": "billing tiers",
              "url": "https://kiro.dev/docs/billing/",
              "seen": "2026-10-08"
            },
            {
              "what": "models and credit multipliers",
              "url": "https://kiro.dev/docs/models/",
              "seen": "2026-10-08"
            },
            {
              "what": "CLI changelog",
              "url": "https://kiro.dev/changelog/cli/",
              "seen": "2026-10-08"
            },
            {
              "what": "licence",
              "url": "https://kiro.dev/license/",
              "seen": "2026-10-08"
            },
            {
              "what": "llms.txt",
              "url": "https://kiro.dev/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "robots.txt",
              "url": "https://kiro.dev/robots.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "issue tracker README and workflows (git clone)",
              "url": "https://github.com/kirodotdev/Kiro",
              "seen": "2026-10-08"
            },
            {
              "what": "issue counts (GitHub API)",
              "url": "https://api.github.com/search/issues?q=repo:kirodotdev/Kiro+is:issue+is:open+label:cli",
              "seen": "2026-10-08"
            },
            {
              "what": "security bulletin 2026-035-AWS, CVE-2026-9255",
              "url": "https://aws.amazon.com/security/security-bulletins/2026-035-aws/",
              "seen": "2026-10-08"
            },
            {
              "what": "security bulletin 2026-074-AWS, CVE-2026-18656 and CVE-2026-18657",
              "url": "https://aws.amazon.com/security/security-bulletins/2026-074-aws/",
              "seen": "2026-10-08"
            },
            {
              "what": "AWS security bulletins feed",
              "url": "https://aws.amazon.com/security/security-bulletins/rss/feed/",
              "seen": "2026-10-08"
            },
            {
              "what": "AWS Service Terms, sections 1.24, 50.3 and 50.14",
              "url": "https://aws.amazon.com/service-terms/",
              "seen": "2026-10-08"
            },
            {
              "what": "AWS Customer Agreement",
              "url": "https://aws.amazon.com/agreement/",
              "seen": "2026-10-08"
            },
            {
              "what": "AWS Privacy Notice",
              "url": "https://aws.amazon.com/privacy/",
              "seen": "2026-10-08"
            },
            {
              "what": "AWS security.txt",
              "url": "https://aws.amazon.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration (RDAP)",
              "url": "https://rdap.org/domain/kiro.dev",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: whether Kiro has a public status page or appears on the AWS Health Dashboard. None is linked from kiro.dev or its docs, and status.kiro.dev didn't answer",
            "unchecked: the event schema of `--output-format stream-json`. The headless page describes the format and no schema was found",
            "unchecked: how many replies in the GitHub issue tracker come from AWS staff, and the Discord server",
            "unchecked: releases before 26 August 2026. Only the first page of the CLI changelog was read, so the 90-day count is a lower bound",
            "unchecked: the AWS sub-processor list and the Data Privacy FAQ the data protection page links to",
            "Whether a paid bug bounty covers Kiro. The AWS security.txt points to a HackerOne vulnerability disclosure programme, and its Expires date of 24 September 2026 had passed",
            "robots.txt on kiro.dev disallows /llms.txt and the Markdown twins for crawlers, while llms.txt tells agents to fetch them. We read the HTML pages for the docs",
            "The headless page documents `--trust-tools` for V3 runs while the V3 page says permissions.yaml replaces the trust flags. We didn't run either engine",
            "The CLI overview page calls ACP the Agent Communication Protocol, and the ACP page calls it the Agent Client Protocol"
          ]
        },
        "negative": -4,
        "negativeNotes": [
          "2026-08-04. CVE-2026-18656 and CVE-2026-18657 (bulletin 2026-074-AWS), an uncontrolled search path on Windows let a planted executable in a crafted project directory run when a user opened it. Kiro CLI for Windows before 2.10.0 and Kiro IDE 1.0.0 to 1.0.212. Fixed and published with credit to the reporters, inside six months (https://aws.amazon.com/security/security-bulletins/2026-074-aws/). -2",
          "2026-05-22. CVE-2026-9255 (bulletin 2026-035-AWS), content piped to kiro-cli on stdin could answer the tool approval prompt, so a local actor could run tools and shell commands without the user's approval. kiro-cli before 1.28.0. Fixed and published, inside six months (https://aws.amazon.com/security/security-bulletins/2026-035-aws/). -2"
        ],
        "verdict": "Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.",
        "bestFor": "Teams on AWS that want one agent configuration across terminal, IDE and web, with central permission policy, prompt logging to their own S3 bucket and IAM Identity Centre sign-in.",
        "strengths": [
          "Capability permissions with deny over ask over allow, stored outside the repository so a clone can't add rules",
          "An untrusted workspace doesn't load its own agents, steering files, MCP configuration or skills, and asks before every shell command",
          "Headless runs with `--no-interactive`, JSON Lines output, and exit codes 3 and 4 for MCP startup and missing-agent failures",
          "Eleven minor releases between 26 August and 5 October 2026 in a dated changelog",
          "Plan prices, the $0.04 credit price and per-model credit multipliers are public, with a free tier of 50 credits a month"
        ],
        "weaknesses": [
          "Free and individual paid accounts have content used for service improvement, including model training, unless they opt out",
          "Closed source since it replaced the Apache 2.0 Amazon Q Developer CLI, with no public CI or test suite",
          "API keys for headless runs need a paid plan, are long-lived and carry no scopes",
          "No local sandbox in the CLI, and AWS says its managed permission policies are client-enforced and can be circumvented",
          "Two CVEs in 2026 (CVE-2026-9255 in May, CVE-2026-18656 and CVE-2026-18657 in August), both fixed"
        ],
        "agentNotes": [
          "Set `KIRO_API_KEY` and pass `--no-interactive` with `--trust-tools=\u003clist\u003e` in pipelines. Keep `--trust-all-tools` for disposable environments",
          "Pass `--require-mcp-startup` when a run depends on MCP tools. Without it a failed server is logged and the run continues",
          "Pass `--no-interactive` whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows",
          "Run `kiro-cli settings telemetry.enabled false` and turn off content collection on Free and individual plans. Both are on by default",
          "Export variables in the shell before starting. Since 2.24.0 a project `.env` file is no longer loaded into sessions, MCP servers or tools"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.9
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 73,
          "payments": 40,
          "reliability": 57,
          "schema": 79,
          "security": 66,
          "transparency": 62
        },
        "provenanceScore": 72
      },
      "connect": {
        "install": "curl -fsSL https://cli.kiro.dev/install | bash",
        "headless": {
          "run": "KIRO_API_KEY=ksk_... kiro-cli chat --no-interactive --trust-tools=read,grep \"Find all TODO comments in src/\""
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/kiro-cli"
      },
      "notable": [
        "Kiro CLI replaced the Amazon Q Developer CLI from 17 November 2025, and installs with auto-update moved across on 24 November 2025. The Q CLI was Apache 2.0 and Kiro CLI is licensed under the AWS Intellectual Property Licence (https://kiro.dev/docs/upgrade-guides/migrating-from-q/)",
        "Headless mode needs an API key in `KIRO_API_KEY`, which only Pro, Pro+, Pro Max and Power subscribers can create, and which an administrator has to switch on for managed subscriptions (https://kiro.dev/docs/cli/headless/)",
        "Content from Free Tier users and individual subscribers may be used for service improvement, including model training, unless they opt out. Enterprise content isn't used (https://kiro.dev/docs/privacy-and-security/data-protection/)",
        "Permission rules use deny over ask over allow across six scopes, workspace rules are stored outside the repository, and a headless session treats every ask as a deny (https://kiro.dev/docs/permissions/)",
        "CLI V3, built on the harness the Kiro IDE and Kiro Web use, is an early release beside 2.x. It replaces the trust flags with permissions.yaml, changes the session and hook formats and removes the built-in AWS tool (https://kiro.dev/docs/cli/v3/)",
        "AWS published two security bulletins that cover the CLI in 2026, CVE-2026-9255 on 22 May and CVE-2026-18656 with CVE-2026-18657 on 4 August (https://aws.amazon.com/security/security-bulletins/2026-035-aws/)",
        "Eleven minor versions from 2.20.0 on 26 August to 2.28.0 on 5 October 2026, with patch releases between them (https://kiro.dev/changelog/cli/)"
      ],
      "area": "frameworks",
      "details": [
        {
          "label": "Models",
          "value": "Models on the Kiro plan, with Auto as the default router and a choice of OpenAI GPT-5.6, Anthropic Claude and open-weight models, each with a credit multiplier. No bring-your-own-key option was found in the reviewed documentation"
        },
        {
          "label": "Install",
          "value": "Install script with SHA-256 checksum verification for macOS and Linux (glibc 2.34 or newer, or a musl build), a .deb and an AppImage, and a PowerShell script for Windows 11"
        },
        {
          "label": "Engines",
          "value": "2.x is the released line (2.28.0 on 5 October 2026). V3, the harness shared with the Kiro IDE and Kiro Web, is an early release chosen with `--v3` or `--agent-engine v3`. Classic sessions show a deprecation notice since 2.26.0"
        },
        {
          "label": "Approvals",
          "value": "Capabilities (fs_read, fs_write, shell, web_fetch, web_search, mcp, subagent and others) with deny, ask and allow rules in permissions.yaml. Deny wins in any scope. Defaults allow workspace reads and read-only git commands and ask for the rest. `--trust-tools` and `--trust-all-tools` for non-interactive runs"
        },
        {
          "label": "Workspace trust",
          "value": "An untrusted workspace doesn't load its custom agents, steering files, MCP configuration, skills or workflows, and asks before every shell command and MCP tool call. The trust decision is stored outside the repository"
        },
        {
          "label": "Sandbox",
          "value": "None in the CLI. The docs list sandboxed execution for Kiro Web only. Compound shell commands are split and each part is matched against the rules"
        },
        {
          "label": "Managed policy",
          "value": "A managed-settings.json at an OS-protected path adds deny and ask rules for the IDE and the CLI, and a malformed file fails closed. AWS says the policy is client-enforced and can be circumvented by a user with administrative access"
        },
        {
          "label": "MCP client",
          "value": "stdio and remote HTTP servers with headers, OAuth with dynamic client registration or supplied client credentials, `autoApprove` and `disabledTools` per server, on-demand tool search, and an enterprise MCP registry"
        },
        {
          "label": "Headless",
          "value": "`kiro-cli chat --no-interactive` with a prompt as an argument or on stdin, `--output-format stream-json`, `--agent`, `--model`, `--effort`, `--resume` and `--resume-id`. Exit codes 0, 1, 3 (MCP startup failure) and 4 (requested agent not found)"
        },
        {
          "label": "ACP",
          "value": "`kiro-cli acp` speaks the Agent Client Protocol as JSON-RPC 2.0 over stdio for JetBrains IDEs, Zed and other clients. A client can request policy presets such as read-workspace or edit-workspace for a session"
        },
        {
          "label": "Telemetry",
          "value": "Usage data and performance metrics on by default for Free and individual accounts, turned off with `kiro-cli settings telemetry.enabled false`. Content is used for service improvement, including model training, unless the user opts out. Enterprise users are opted out"
        },
        {
          "label": "Data handling",
          "value": "Content for Free and individual accounts is stored in US East (N. Virginia). Free Tier inputs may be kept up to 60 days for abuse detection, and traffic to some models is retained up to 30 days. Inference runs on Amazon Bedrock with cross-region routing"
        },
        {
          "label": "Releases in 90 days",
          "value": "At least 11 minor versions (2.20.0 on 26 August to 2.28.0 on 5 October 2026) plus patch releases. Earlier pages of the changelog weren't counted"
        }
      ],
      "unitPrices": [
        {
          "item": "Kiro Pro",
          "unit": "month",
          "usd": 20,
          "note": "per user, with 1,000 credits"
        },
        {
          "item": "Add-on credit",
          "unit": "credit",
          "usd": 0.04,
          "note": "paid plans, beyond the plan's credits"
        }
      ],
      "deprecations": [
        {
          "what": "Project `.env` files no longer load automatically into chat sessions, MCP servers or tools (2.24.0)",
          "date": "2026-09-23",
          "source": "https://kiro.dev/changelog/cli/",
          "kind": "breaking"
        },
        {
          "what": "Classic (non-TUI) sessions show a deprecation notice and don't support the V3 engine (2.26.0). No removal date was found",
          "date": "2026-09-30",
          "source": "https://kiro.dev/changelog/cli/",
          "kind": "notice"
        }
      ],
      "provenance": {
        "legalEntity": "Amazon Web Services, Inc.",
        "domain": "kiro.dev",
        "domainRegistered": "2019-03-01",
        "endpointOnVendorDomain": null,
        "terms": "https://aws.amazon.com/agreement/",
        "privacy": "https://aws.amazon.com/privacy/",
        "statusPage": "",
        "changelog": "https://kiro.dev/changelog/cli/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "Kiro's licence page says the Kiro IDE and CLI are licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence. Section 50.14 of the AWS Service Terms names Amazon Web Services, Inc. as the contracting party for subscriptions bought through the Stripe portal.",
          "The AWS Customer Agreement (last updated 14 August 2026) governs use, with the AWS Service Terms sections 50.3 and 50.14 for Kiro. The AWS Privacy Notice (last updated 18 May 2026) is the privacy link in Kiro's footer.",
          "kiro.dev/.well-known/security.txt answers 404. aws.amazon.com publishes a security.txt whose Expires line reads 24 September 2026, which had passed when we read it.",
          "No status page for Kiro was found on kiro.dev or in its docs.",
          "RDAP (Google Registry) gives kiro.dev a registration date of 1 March 2019, before the product."
        ],
        "score": 72,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Amazon Web Services, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "kiro.dev, registered 2019-03-01 (7 years)",
            "points": 11,
            "max": 15,
            "state": "part"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "no hosted endpoint",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Terms of service",
            "value": "read, states 7 of the 7 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://aws.amazon.com/agreement/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-08-14",
            "words": 10799,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: August 14, 2026",
                "says": "Last updated 2026-08-14"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "The laws of the Province of Ontario, Canada and federal laws of Canada applicable therein",
                "says": "The law of the Province of Ontario"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…UNDER THIS AGREEMENT OF EITHER AWS OR YOU, AND ANY OF OUR RESPECTIVE AFFILIATES OR LICENSORS, WILL NOT EXCEED THE AMOUNTS PAID BY YOU TO AWS UNDER THIS AGREEMENT FOR THE SERVICES THAT GAVE RISE TO THE LIABILITY DURING THE 12 MONTHS BEFORE THE LIABILITY AROSE;",
                "says": "Capped at the fees paid in the 12 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "If you become aware of any violation of your obligations under this Agreement caused by an End User, you will immediately suspend access to Your Content and the Services by such End User."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "We may change, discontinue or add Service Level Agreements, provided, however, that we will provide at least 90 days’ advance notice for adverse changes to any Service Level Agreement.",
                "says": "Gives 90 days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "AWS log-in credentials and private keys generated by the Services are for your internal use only and you will not sell, transfer or sublicense them to any other entity or person, except that you may disclose your private key to your agents and subcontractors performing work on your behalf."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "Service Level Agreements and Service Terms apply to certain Services."
              }
            ],
            "toKnow": [
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "We may terminate this Agreement for any reason by providing you at least 30 days’ advance notice."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "Disputes will be resolved by binding arbitration, rather than in court, except that either party may elect to proceed in small claims court if your claims qualify."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "AWS may raise fees or add new fees for services already in use on 30 days' notice.",
                "quote": "We may increase or add new fees and charges for any existing Services you are using by giving you at least 30 days’ prior notice."
              },
              {
                "date": "2026-10-08",
                "text": "For 30 days after termination the customer may retrieve its content only if all amounts due are paid. This period does not apply when AWS terminates under Section 5.2(b).",
                "quote": "(ii) we will allow you to retrieve Your Content from the Services only if you have paid all amounts due under this Agreement."
              },
              {
                "date": "2026-10-08",
                "text": "The customer may not issue a press release or other public communication about the agreement or its use of AWS services.",
                "quote": "You will not issue any press release or make any other public communication with respect to this Agreement or your use of the Services or AWS Content."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://aws.amazon.com/privacy/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-05-18",
            "words": 8790,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: May 18, 2026",
                "says": "Last updated 2026-05-18"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This Privacy Notice describes how we collect and use your personal information in relation to AWS websites, applications, products, services, events, and experiences that reference this Privacy Notice (together, “AWS Offerings”)."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We keep your personal information to enable your continued use of AWS Offerings, for as long as it is required in order to fulfill the relevant purposes described in this Privacy Notice, as may be required by law (including for tax and accounting purposes), or as otherwise communicated to you.",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Information from Other Sources: We might collect information about you from other sources, including service providers, partners, and publicly available sources."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "Information about our customers is an important part of our business and we are not in the business of selling our customers’ personal information to others."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "Additionally, you may have the right to opt out of the processing of your personal data for cross-context behavioral advertising (also referred to as targeted advertising under certain state privacy laws)."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "We provide additional information about our controllers and data protection officers (as applicable), the privacy, collection, and use of personal information of prospective and current customers of AWS Offerings located in certain jurisdictions.",
                "says": "Names a data protection officer"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework",
                "says": "Relies on the Data Privacy Framework"
              }
            ],
            "toKnow": [
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "To help you receive more useful and relevant ads on other sites and services and to measure their effectiveness, AWS shares limited personal information with our advertising partners."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The notice does not cover content that customers process, store or host on AWS. It refers to the customer agreement for how that content is handled.",
                "quote": "This Privacy Notice does not apply to the “content” processed, stored, or hosted by our customers using AWS Offerings in connection with an AWS account."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kiro-cli.json",
      "live": {
        "slug": "kiro-cli",
        "pages": [
          {
            "url": "https://kiro.dev/changelog/cli/",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-08T18:21:05.911888808Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f2b1951f0330"
          }
        ],
        "updatedAt": "2026-10-08T18:21:05.911888808Z"
      }
    },
    "verify": {
      "accepts": "a page on kiro.dev or one of its subdomains, or the README of github.com/kirodotdev/Kiro",
      "badgeUrl": "https://www.anchorterminal.com/badges/kiro-cli.svg",
      "body": {
        "slug": "kiro-cli",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/kiro-cli",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/kiro-cli\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/kiro-cli.svg\" alt=\"Kiro CLI on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Kiro CLI on Anchor Terminal](https://www.anchorterminal.com/badges/kiro-cli.svg)](https://www.anchorterminal.com/tools/kiro-cli)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/kiro-cli\"\u003eKiro CLI on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/kiro-cli",
    "json": "https://www.anchorterminal.com/tools/kiro-cli.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/kiro-cli.md",
    "slim": "https://www.anchorterminal.com/tools/kiro-cli.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 59.9/100 · rank #419 of 722 · #11 in Agent harnesses · not agent-ready · confidence medium**\n\n\n## Assessment\n\nPermission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Amazon Web Services (https://kiro.dev/cli/) |\n| Kind | Agent harness |\n| Category | Agent harnesses (https://www.anchorterminal.com/categories/agent-harnesses) |\n| Auth | OAuth or key · `kiro-cli login` with GitHub, Google, AWS Builder ID, AWS IAM Identity Centre or an external identity provider, in a browser or by device flow on a remote machine. Pipelines use an API key in `KIRO_API_KEY`, created at app.kiro.dev by Pro, Pro+, Pro Max and Power subscribers. Keys are long-lived, named and revocable, with no scopes, and API key generation is off by default for subscriptions an administrator manages. An active browser session takes precedence over the key. |\n| Pricing | Freemium ($20 / mo) · Kiro Free is $0 with 50 credits a month and a reduced model list. Pro is $20 a user a month with 1,000 credits, Pro+ $40 with 2,000, Pro Max $100 with 5,000 and Power $200 with 10,000, and extra credits cost $0.04 each. Models use credits at different rates (Auto is the 1.0x baseline). API keys for headless runs need a paid plan, and a paid plan needs a card. GovCloud prices are about 20 per cent higher with no free tier (checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the docs, the pricing page or the CLI changelog (checked 2026-10-08). |\n| Licence | Proprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the source |\n| Source | https://github.com/kirodotdev/Kiro |\n| Docs | https://kiro.dev/docs/cli/ |\n| llms.txt | https://kiro.dev/llms.txt |\n| Last release | 2026-10-05 |\n| GitHub stars | 4,356 (as of 2026-10-08) |\n| Models | Models on the Kiro plan, with Auto as the default router and a choice of OpenAI GPT-5.6, Anthropic Claude and open-weight models, each with a credit multiplier. No bring-your-own-key option was found in the reviewed documentation |\n| Install | Install script with SHA-256 checksum verification for macOS and Linux (glibc 2.34 or newer, or a musl build), a .deb and an AppImage, and a PowerShell script for Windows 11 |\n| Engines | 2.x is the released line (2.28.0 on 5 October 2026). V3, the harness shared with the Kiro IDE and Kiro Web, is an early release chosen with `--v3` or `--agent-engine v3`. Classic sessions show a deprecation notice since 2.26.0 |\n| Approvals | Capabilities (fs_read, fs_write, shell, web_fetch, web_search, mcp, subagent and others) with deny, ask and allow rules in permissions.yaml. Deny wins in any scope. Defaults allow workspace reads and read-only git commands and ask for the rest. `--trust-tools` and `--trust-all-tools` for non-interactive runs |\n| Workspace trust | An untrusted workspace doesn't load its custom agents, steering files, MCP configuration, skills or workflows, and asks before every shell command and MCP tool call. The trust decision is stored outside the repository |\n| Sandbox | None in the CLI. The docs list sandboxed execution for Kiro Web only. Compound shell commands are split and each part is matched against the rules |\n| Managed policy | A managed-settings.json at an OS-protected path adds deny and ask rules for the IDE and the CLI, and a malformed file fails closed. AWS says the policy is client-enforced and can be circumvented by a user with administrative access |\n| MCP client | stdio and remote HTTP servers with headers, OAuth with dynamic client registration or supplied client credentials, `autoApprove` and `disabledTools` per server, on-demand tool search, and an enterprise MCP registry |\n| Headless | `kiro-cli chat --no-interactive` with a prompt as an argument or on stdin, `--output-format stream-json`, `--agent`, `--model`, `--effort`, `--resume` and `--resume-id`. Exit codes 0, 1, 3 (MCP startup failure) and 4 (requested agent not found) |\n| ACP | `kiro-cli acp` speaks the Agent Client Protocol as JSON-RPC 2.0 over stdio for JetBrains IDEs, Zed and other clients. A client can request policy presets such as read-workspace or edit-workspace for a session |\n| Telemetry | Usage data and performance metrics on by default for Free and individual accounts, turned off with `kiro-cli settings telemetry.enabled false`. Content is used for service improvement, including model training, unless the user opts out. Enterprise users are opted out |\n| Data handling | Content for Free and individual accounts is stored in US East (N. Virginia). Free Tier inputs may be kept up to 60 days for abuse detection, and traffic to some models is retained up to 30 days. Inference runs on Amazon Bedrock with cross-region routing |\n| Releases in 90 days | At least 11 minor versions (2.20.0 on 26 August to 2.28.0 on 5 October 2026) plus patch releases. Earlier pages of the changelog weren't counted |\n| Capabilities | agent.harness, agent.mcp-client, agent.multi-agent |\n| Tags | official, harness, coding-agent, cli, closed-source, mcp, acp, llms-txt, free-tier, no-card, telemetry-default-on |\n| JSON | https://www.anchorterminal.com/api/v1/tools/kiro-cli.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 57 | 11.4 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 79 | 12.8 |\n| Agent ergonomics | 13% | 16.2 | 67 | 10.9 |\n| Security \u0026 auth | 14% | 17.5 | 66 | 11.6 |\n| Payments \u0026 pricing | 10% | 12.5 | 40 | 5.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 73 | 6.4 |\n| Transparency \u0026 trust (editorial 62, provenance 72) | 7% | 8.8 | 67 | 5.9 |\n| Negative events | up to −15 | up to −15 | 2026-08-04. CVE-2026-18656 and CVE-2026-18657 (bulletin 2026-074-AWS), an uncontrolled search path on Windows let a planted executable in a crafted project directory run when a user opened it. Kiro CLI for Windows before 2.10.0 and Kiro IDE 1.0.0 to 1.0.212. Fixed and published with credit to the reporters, inside six months (https://aws.amazon.com/security/security-bulletins/2026-074-aws/). -2 2026-05-22. CVE-2026-9255 (bulletin 2026-035-AWS), content piped to kiro-cli on stdin could answer the tool approval prompt, so a local actor could run tools and shell commands without the user's approval. kiro-cli before 1.28.0. Fixed and published, inside six months (https://aws.amazon.com/security/security-bulletins/2026-035-aws/). -2  | -4 |\n| **Total** | | | | **59.9 → C** |\n\n### Why each score\n\n- Reliability 57: Local-package reading, the same as the other closed-source harnesses. An install script that verifies SHA-256 checksums, a .deb, an AppImage and a PowerShell script, with macOS, Windows 11 and Linux (glibc 2.34 or newer, or musl) stated (20). No public CI or test suite, since the source isn't published and the GitHub repository is an issue tracker (0). 1,401 open issues in the shared Kiro tracker, 428 labelled cli, with 96 cli issues opened and 69 closed in the 30 days to 8 October, area labels, a triage label and stale-issue automation. Open reports from the last week include a `--no-interactive` run that never exits after a refusal (12). A dated changelog for every release and a breaking-change table with a migration guide for V3, which runs beside 2.x until the user opts in, though 2.24.0 stopped loading project `.env` files in a minor version (10). 2.28.0, with V3 still an early release (15).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 79: Framework reading. A command reference, a settings reference, an exit-code page and a documented rule format for permissions, plus the Agent Client Protocol methods the CLI implements. No published schema for the stream-json events was found (14). kiro.dev/llms.txt indexes every docs page and each has a Markdown twin, though robots.txt disallows both for crawlers (10). The permissions page states the defaults, what each preset allows and when to pick it, and that headless runs treat ask as deny (16). Rules are validated, an unknown preset rejects the session request, and a malformed managed policy fails closed (12). CI examples, exit codes 0, 1, 3 and 4 and hook exit codes are documented, but code 1 covers every other failure (12). Versioned releases with a dated changelog and a 2.x reference kept beside V3 (15).\n- Agent ergonomics 67: Framework reading, adapted to a harness driven by a pipeline. `--trust-tools` limits approved tools, `disabledTools` removes MCP tools per server, tool search loads MCP tools on demand, and custom agents carry their own tool set (20). Compaction and a workflow timeout (`KIRO_HEADLESS_WORKFLOW_TIMEOUT_SECS`, six hours by default) exist, but no cap on turns or run time for a plain headless run was found (10). Distinct exit codes for MCP startup failure and a missing agent, `--require-mcp-startup`, and a final interruption record in stream-json, with exit 1 for everything else (14). Sessions are saved every turn, with `--resume`, `--resume-id` and checkpoints with rewind (15). No SDK. The programmatic interfaces are the headless command and the ACP server, and a headless run needs a paid-plan API key and explicit trust flags (8).\n- Security \u0026 auth 66: Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. Telemetry and content collection are on by default for Free and individual accounts, each with a documented opt-out, and enterprise users are opted out. API keys are long-lived and revocable with no scopes, and administrators must switch key generation on (14). Deny over ask over allow across six scopes, hard-coded denies on Kiro's own settings paths, workspace trust and a managed policy that fails closed. There is no local sandbox in the CLI, and AWS says managed policies are client-enforced and can be circumvented (16). An untrusted workspace doesn't load its agents, steering, MCP configuration or skills, compound shell commands are split before matching, and the MCP page warns that servers run outside any sandbox (11). Enterprise prompt logging to the customer's S3 bucket covers the CLI, with daily activity reports and OpenTelemetry export, and individuals have local logs only (11). AWS vulnerability reporting with a HackerOne disclosure programme, CVEs published in security bulletins with credit to reporters, ISO/IEC 27001:2022 scope and HIPAA eligibility. kiro.dev has no security.txt and the one on aws.amazon.com expired on 24 September 2026 (14).\n- Payments \u0026 pricing 40: Harness reading of the published rubric, scored on the Kiro subscription the CLI needs. No payment protocol (0). Plan prices, the $0.04 credit price and per-model credit multipliers are public without a login (20). Kiro Free has 50 credits a month, and the pricing page asks for a card only on upgrade (20). A person signs in through a browser or device flow, and the API key for headless runs is created by hand at app.kiro.dev on a paid plan (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 73: 2.28.0 on 5 October 2026 (30). At least 11 minor versions and their patches between 26 August and 5 October (20). A public issue tracker with area labels and triage automation, 69 cli issues closed against 96 opened in 30 days, and a Discord server. We didn't establish how many replies come from staff (14). No SDK and no registry entry. The ACP server is kept current, with a migration guide for clients moving to V3 (6). Closed source, so no CI or dependency health to read. The installer verifies checksums (3).\n- Transparency \u0026 trust 67: Proprietary, with clear terms. The licence page puts the CLI under the AWS Customer Agreement and the AWS Intellectual Property Licence, where the Amazon Q Developer CLI it replaced was Apache 2.0 (15). The data protection page says what is stored for Free, individual and enterprise users, names US East (N. Virginia) for storage, lists inference regions, and gives 60 days for Free Tier abuse detection and 30 days for some models. It agrees with sections 50.3 and 50.14 of the AWS Service Terms. No general retention period for stored content was found (22). Classic sessions carry a deprecation notice and V3 has a breaking-change table and migration guides, but no deprecation policy or removal dates were found (10). Telemetry types are listed and `telemetry.enabled` turns them off, with collection on by default (15).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (21 items): https://www.anchorterminal.com/fixes/kiro-cli.md (JSON https://www.anchorterminal.com/fixes/kiro-cli.json)\n\n### What we couldn't check\n\n- unchecked: whether Kiro has a public status page or appears on the AWS Health Dashboard. None is linked from kiro.dev or its docs, and status.kiro.dev didn't answer\n- unchecked: the event schema of `--output-format stream-json`. The headless page describes the format and no schema was found\n- unchecked: how many replies in the GitHub issue tracker come from AWS staff, and the Discord server\n- unchecked: releases before 26 August 2026. Only the first page of the CLI changelog was read, so the 90-day count is a lower bound\n- unchecked: the AWS sub-processor list and the Data Privacy FAQ the data protection page links to\n- Whether a paid bug bounty covers Kiro. The AWS security.txt points to a HackerOne vulnerability disclosure programme, and its Expires date of 24 September 2026 had passed\n- robots.txt on kiro.dev disallows /llms.txt and the Markdown twins for crawlers, while llms.txt tells agents to fetch them. We read the HTML pages for the docs\n- The headless page documents `--trust-tools` for V3 runs while the V3 page says permissions.yaml replaces the trust flags. We didn't run either engine\n- The CLI overview page calls ACP the Agent Communication Protocol, and the ACP page calls it the Agent Client Protocol\n\n### Sources\n\n- CLI overview: \u003chttps://kiro.dev/docs/cli/\u003e (seen 2026-10-08)\n- headless mode: \u003chttps://kiro.dev/docs/cli/headless/\u003e (seen 2026-10-08)\n- authentication and API keys: \u003chttps://kiro.dev/docs/getting-started/authentication/\u003e (seen 2026-10-08)\n- permissions and workspace trust: \u003chttps://kiro.dev/docs/permissions/\u003e (seen 2026-10-08)\n- enterprise permission policies: \u003chttps://kiro.dev/docs/enterprise/governance/permissions/\u003e (seen 2026-10-08)\n- API key governance: \u003chttps://kiro.dev/docs/enterprise/governance/api-keys/\u003e (seen 2026-10-08)\n- exit codes: \u003chttps://kiro.dev/docs/reference/exit-codes/\u003e (seen 2026-10-08)\n- CLI command reference: \u003chttps://kiro.dev/docs/reference/cli-commands/\u003e (seen 2026-10-08)\n- settings reference: \u003chttps://kiro.dev/docs/reference/settings/\u003e (seen 2026-10-08)\n- ACP server: \u003chttps://kiro.dev/docs/cli/acp/\u003e (seen 2026-10-08)\n- CLI V3 and breaking changes: \u003chttps://kiro.dev/docs/cli/v3/\u003e (seen 2026-10-08)\n- MCP configuration: \u003chttps://kiro.dev/docs/mcp/configuration/\u003e (seen 2026-10-08)\n- MCP security: \u003chttps://kiro.dev/docs/mcp/security/\u003e (seen 2026-10-08)\n- data protection, service improvement and telemetry: \u003chttps://kiro.dev/docs/privacy-and-security/data-protection/\u003e (seen 2026-10-08)\n- compliance programmes: \u003chttps://kiro.dev/docs/privacy-and-security/compliance-validation/\u003e (seen 2026-10-08)\n- prompt logging: \u003chttps://kiro.dev/docs/enterprise/monitor-and-track/prompt-logging/\u003e (seen 2026-10-08)\n- installation and system requirements: \u003chttps://kiro.dev/docs/getting-started/installation/\u003e (seen 2026-10-08)\n- install script: \u003chttps://cli.kiro.dev/install\u003e (seen 2026-10-08)\n- migration from the Amazon Q Developer CLI: \u003chttps://kiro.dev/docs/upgrade-guides/migrating-from-q/\u003e (seen 2026-10-08)\n- pricing: \u003chttps://kiro.dev/pricing/\u003e (seen 2026-10-08)\n- billing tiers: \u003chttps://kiro.dev/docs/billing/\u003e (seen 2026-10-08)\n- models and credit multipliers: \u003chttps://kiro.dev/docs/models/\u003e (seen 2026-10-08)\n- CLI changelog: \u003chttps://kiro.dev/changelog/cli/\u003e (seen 2026-10-08)\n- licence: \u003chttps://kiro.dev/license/\u003e (seen 2026-10-08)\n- llms.txt: \u003chttps://kiro.dev/llms.txt\u003e (seen 2026-10-08)\n- robots.txt: \u003chttps://kiro.dev/robots.txt\u003e (seen 2026-10-08)\n- issue tracker README and workflows (git clone): \u003chttps://github.com/kirodotdev/Kiro\u003e (seen 2026-10-08)\n- issue counts (GitHub API): \u003chttps://api.github.com/search/issues?q=repo:kirodotdev/Kiro+is:issue+is:open+label:cli\u003e (seen 2026-10-08)\n- security bulletin 2026-035-AWS, CVE-2026-9255: \u003chttps://aws.amazon.com/security/security-bulletins/2026-035-aws/\u003e (seen 2026-10-08)\n- security bulletin 2026-074-AWS, CVE-2026-18656 and CVE-2026-18657: \u003chttps://aws.amazon.com/security/security-bulletins/2026-074-aws/\u003e (seen 2026-10-08)\n- AWS security bulletins feed: \u003chttps://aws.amazon.com/security/security-bulletins/rss/feed/\u003e (seen 2026-10-08)\n- AWS Service Terms, sections 1.24, 50.3 and 50.14: \u003chttps://aws.amazon.com/service-terms/\u003e (seen 2026-10-08)\n- AWS Customer Agreement: \u003chttps://aws.amazon.com/agreement/\u003e (seen 2026-10-08)\n- AWS Privacy Notice: \u003chttps://aws.amazon.com/privacy/\u003e (seen 2026-10-08)\n- AWS security.txt: \u003chttps://aws.amazon.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- domain registration (RDAP): \u003chttps://rdap.org/domain/kiro.dev\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 72/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Amazon Web Services, Inc. | 20/20 |\n| Domain age | kiro.dev, registered 2019-03-01 (7 years) | 11/15 |\n| Endpoint on the vendor's domain | no hosted endpoint | n/a |\n| Terms of service | read, states 7 of the 7 things a reader expects | 10/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | not found | 0/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nKiro's licence page says the Kiro IDE and CLI are licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence. Section 50.14 of the AWS Service Terms names Amazon Web Services, Inc. as the contracting party for subscriptions bought through the Stripe portal.\n\nThe AWS Customer Agreement (last updated 14 August 2026) governs use, with the AWS Service Terms sections 50.3 and 50.14 for Kiro. The AWS Privacy Notice (last updated 18 May 2026) is the privacy link in Kiro's footer.\n\nkiro.dev/.well-known/security.txt answers 404. aws.amazon.com publishes a security.txt whose Expires line reads 24 September 2026, which had passed when we read it.\n\nNo status page for Kiro was found on kiro.dev or in its docs.\n\nRDAP (Google Registry) gives kiro.dev a registration date of 1 March 2019, before the product.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://aws.amazon.com/agreement/), read 2026-10-08, dated 2026-08-14, states 7 of the 7 things a reader expects.\n\n- To know. Says access can be ended without notice or for any reason. \"We may terminate this Agreement for any reason by providing you at least 30 days’ advance notice.\"\n- To know. Requires arbitration or waives class actions. \"Disputes will be resolved by binding arbitration, rather than in court, except that either party may elect to proceed in small claims court if your claims qualify.\"\n- Gives the date it was last updated. Last updated 2026-08-14.\n- Names the governing law or courts. The law of the Province of Ontario.\n- States a limit on its liability. Capped at the fees paid in the 12 months before the claim.\n- Says how changes to the terms are announced. Gives 90 days of notice before a change.\n- Also in the text (2026-10-08). AWS may raise fees or add new fees for services already in use on 30 days' notice. \"We may increase or add new fees and charges for any existing Services you are using by giving you at least 30 days’ prior notice.\"\n- Also in the text (2026-10-08). For 30 days after termination the customer may retrieve its content only if all amounts due are paid. This period does not apply when AWS terminates under Section 5.2(b). \"(ii) we will allow you to retrieve Your Content from the Services only if you have paid all amounts due under this Agreement.\"\n- Also in the text (2026-10-08). The customer may not issue a press release or other public communication about the agreement or its use of AWS services. \"You will not issue any press release or make any other public communication with respect to this Agreement or your use of the Services or AWS Content.\"\n\n**Privacy policy** (https://aws.amazon.com/privacy/), read 2026-10-08, dated 2026-05-18, states 8 of the 8 things a reader expects.\n\n- To know. Says it sells personal data or shares it for advertising. \"To help you receive more useful and relevant ads on other sites and services and to measure their effectiveness, AWS shares limited personal information with our advertising partners.\"\n- Gives the date it was last updated. Last updated 2026-05-18.\n- Says how long data is kept. For as long as needed, with no period named.\n- Gives a privacy contact. Names a data protection officer.\n- Says where data is transferred or stored. Relies on the Data Privacy Framework.\n- Also in the text (2026-10-08). The notice does not cover content that customers process, store or host on AWS. It refers to the customer agreement for how that content is handled. \"This Privacy Notice does not apply to the “content” processed, stored, or hosted by our customers using AWS Offerings in connection with an AWS account.\"\n\n## Live (updated 2026-10-08 18:21 UTC)\n\n- Watching deprecations \u003chttps://kiro.dev/changelog/cli/\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/kiro-cli.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Kiro Pro | $20 | per month (plan) | per user, with 1,000 credits |\n| Add-on credit | $0.04 | per credit | paid plans, beyond the plan's credits |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Dated changes\n\n- 2026-09-23 · Breaking change · Project `.env` files no longer load automatically into chat sessions, MCP servers or tools (2.24.0) (source: \u003chttps://kiro.dev/changelog/cli/\u003e)\n- 2026-09-30 · Notice · Classic (non-TUI) sessions show a deprecation notice and don't support the V3 engine (2.26.0). No removal date was found (source: \u003chttps://kiro.dev/changelog/cli/\u003e)\n\nAll listings, as a calendar: https://www.anchorterminal.com/sunsets.ics\n\n## Strengths\n\n- Capability permissions with deny over ask over allow, stored outside the repository so a clone can't add rules\n- An untrusted workspace doesn't load its own agents, steering files, MCP configuration or skills, and asks before every shell command\n- Headless runs with `--no-interactive`, JSON Lines output, and exit codes 3 and 4 for MCP startup and missing-agent failures\n- Eleven minor releases between 26 August and 5 October 2026 in a dated changelog\n- Plan prices, the $0.04 credit price and per-model credit multipliers are public, with a free tier of 50 credits a month\n\n## Weaknesses\n\n- Free and individual paid accounts have content used for service improvement, including model training, unless they opt out\n- Closed source since it replaced the Apache 2.0 Amazon Q Developer CLI, with no public CI or test suite\n- API keys for headless runs need a paid plan, are long-lived and carry no scopes\n- No local sandbox in the CLI, and AWS says its managed permission policies are client-enforced and can be circumvented\n- Two CVEs in 2026 (CVE-2026-9255 in May, CVE-2026-18656 and CVE-2026-18657 in August), both fixed\n\n## Before you call it (notes for agents)\n\n1. Set `KIRO_API_KEY` and pass `--no-interactive` with `--trust-tools=\u003clist\u003e` in pipelines. Keep `--trust-all-tools` for disposable environments\n2. Pass `--require-mcp-startup` when a run depends on MCP tools. Without it a failed server is logged and the run continues\n3. Pass `--no-interactive` whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows\n4. Run `kiro-cli settings telemetry.enabled false` and turn off content collection on Free and individual plans. Both are on by default\n5. Export variables in the shell before starting. Since 2.24.0 a project `.env` file is no longer loaded into sessions, MCP servers or tools\n\n## Connect\n\nInstall:\n\n```bash\ncurl -fsSL https://cli.kiro.dev/install | bash\n```\n\nHeadless / CI:\n\n```json\n{\n  \"run\": \"KIRO_API_KEY=ksk_... kiro-cli chat --no-interactive --trust-tools=read,grep \\\"Find all TODO comments in src/\\\"\"\n}\n```\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| goose | BB | 73.9 | 72 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/goose.md |\n| Qwen Code | BB | 72.4 | 93 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/qwen-code.md |\n| Gemini CLI | BB | 72 | 99 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/gemini-cli.md |\n| OpenHands | BB | 70.8 | 126 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/openhands.md |\n| OpenCode | B | 67.7 | 200 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/opencode.md |\n| Claude Code | C | 61.9 | 354 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/claude-code.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Kiro CLI replaced the Amazon Q Developer CLI from 17 November 2025, and installs with auto-update moved across on 24 November 2025. The Q CLI was Apache 2.0 and Kiro CLI is licensed under the AWS Intellectual Property Licence (source: \u003chttps://kiro.dev/docs/upgrade-guides/migrating-from-q/\u003e)\n- Headless mode needs an API key in `KIRO_API_KEY`, which only Pro, Pro+, Pro Max and Power subscribers can create, and which an administrator has to switch on for managed subscriptions (source: \u003chttps://kiro.dev/docs/cli/headless/\u003e)\n- Content from Free Tier users and individual subscribers may be used for service improvement, including model training, unless they opt out. Enterprise content isn't used (source: \u003chttps://kiro.dev/docs/privacy-and-security/data-protection/\u003e)\n- Permission rules use deny over ask over allow across six scopes, workspace rules are stored outside the repository, and a headless session treats every ask as a deny (source: \u003chttps://kiro.dev/docs/permissions/\u003e)\n- CLI V3, built on the harness the Kiro IDE and Kiro Web use, is an early release beside 2.x. It replaces the trust flags with permissions.yaml, changes the session and hook formats and removes the built-in AWS tool (source: \u003chttps://kiro.dev/docs/cli/v3/\u003e)\n- AWS published two security bulletins that cover the CLI in 2026, CVE-2026-9255 on 22 May and CVE-2026-18656 with CVE-2026-18657 on 4 August (source: \u003chttps://aws.amazon.com/security/security-bulletins/2026-035-aws/\u003e)\n- Eleven minor versions from 2.20.0 on 26 August to 2.28.0 on 5 October 2026, with patch releases between them (source: \u003chttps://kiro.dev/changelog/cli/\u003e)\n\n## Compare\n\n- [Aider vs Kiro CLI](https://www.anchorterminal.com/compare/aider-vs-kiro-cli.md): D 46.9 vs C 59.9\n- [Amp vs Kiro CLI](https://www.anchorterminal.com/compare/amp-vs-kiro-cli.md): C 57.1 vs C 59.9\n- [Claude Code vs Kiro CLI](https://www.anchorterminal.com/compare/claude-code-vs-kiro-cli.md): C 61.9 vs C 59.9\n- [Cline vs Kiro CLI](https://www.anchorterminal.com/compare/cline-vs-kiro-cli.md): C 60.4 vs C 59.9\n- [Cursor CLI vs Kiro CLI](https://www.anchorterminal.com/compare/cursor-cli-vs-kiro-cli.md): F 35.3 vs C 59.9\n- [Devin vs Kiro CLI](https://www.anchorterminal.com/compare/devin-vs-kiro-cli.md): C 55.7 vs C 59.9\n- [Pi vs Kiro CLI](https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli.md): B 68.4 vs C 59.9\n- [Gemini CLI vs Kiro CLI](https://www.anchorterminal.com/compare/gemini-cli-vs-kiro-cli.md): BB 72 vs C 59.9\n- [GitHub Copilot CLI vs Kiro CLI](https://www.anchorterminal.com/compare/github-copilot-cli-vs-kiro-cli.md): C 57.6 vs C 59.9\n- [goose vs Kiro CLI](https://www.anchorterminal.com/compare/goose-vs-kiro-cli.md): BB 73.9 vs C 59.9\n- [Kiro CLI vs OpenAI Codex](https://www.anchorterminal.com/compare/kiro-cli-vs-openai-codex.md): C 59.9 vs BB 73\n- [Kiro CLI vs OpenCode](https://www.anchorterminal.com/compare/kiro-cli-vs-opencode.md): C 59.9 vs B 67.7\n- [Kiro CLI vs OpenHands](https://www.anchorterminal.com/compare/kiro-cli-vs-openhands.md): C 59.9 vs BB 70.8\n- [Kiro CLI vs Prime Agent](https://www.anchorterminal.com/compare/kiro-cli-vs-prime-agent.md): C 59.9 vs C 60.5\n- [Kiro CLI vs Qwen Code](https://www.anchorterminal.com/compare/kiro-cli-vs-qwen-code.md): C 59.9 vs BB 72.4\n- [Kiro CLI vs Paperclip](https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.md): C 59.9 vs C 59\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on kiro.dev or one of its subdomains, or the README of github.com/kirodotdev/Kiro. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"kiro-cli\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/kiro-cli\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/kiro-cli.svg\" alt=\"Kiro CLI on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Kiro CLI on Anchor Terminal](https://www.anchorterminal.com/badges/kiro-cli.svg)](https://www.anchorterminal.com/tools/kiro-cli)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/kiro-cli\"\u003eKiro CLI on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Kiro CLI is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/kiro-cli-dark.png\n- Light: https://www.anchorterminal.com/assets/share/kiro-cli-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Agent harnesses",
        "url": "https://www.anchorterminal.com/categories/agent-harnesses"
      },
      {
        "name": "Kiro CLI",
        "url": ""
      }
    ],
    "description": "AWS's coding agent for the terminal and the successor to the Amazon Q Developer CLI. It runs interactive chat, non-interactive runs for pipelines with an API key, MCP servers and an Agent Client Protocol server for editors.",
    "facts": [
      "rank #419 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Kiro CLI",
    "image": "https://www.anchorterminal.com/assets/og/tools-kiro-cli.png",
    "path": "/tools/kiro-cli",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Kiro CLI review for AI agents, grade C (59.9/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/kiro-cli"
  },
  "tokens": {
    "markdown": 8300,
    "slim": 1930
  },
  "version": 1
}
