# Kiro CLI
> AWS's coding agent for the terminal and the successor to the Amazon Q Developer CLI. It runs interactive chat, non-interactive runs for pipelines with an API key, MCP servers and an Agent Client Protocol server for editors.
- Canonical: https://www.anchorterminal.com/tools/kiro-cli
- Markdown: https://www.anchorterminal.com/tools/kiro-cli.md (~8,300 tokens)
- Slim: https://www.anchorterminal.com/tools/kiro-cli.min.md (~1,930 tokens, same facts, less prose, for token-sensitive contexts)
- JSON: https://www.anchorterminal.com/tools/kiro-cli.json (this page as data, same URL with Accept: application/json)
- Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt)
- API: https://www.anchorterminal.com/api/v1/index.json
- Updated: 2026-10-08
## Overview
**Grade C · 59.9/100 · rank #419 of 722 · #11 in Agent harnesses · not agent-ready · confidence medium**
## Assessment
Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan.
## Facts
| Field | Value |
| --- | --- |
| Vendor | Amazon Web Services (https://kiro.dev/cli/) |
| Kind | Agent harness |
| Category | Agent harnesses (https://www.anchorterminal.com/categories/agent-harnesses) |
| Auth | OAuth or key · `kiro-cli login` with GitHub, Google, AWS Builder ID, AWS IAM Identity Centre or an external identity provider, in a browser or by device flow on a remote machine. Pipelines use an API key in `KIRO_API_KEY`, created at app.kiro.dev by Pro, Pro+, Pro Max and Power subscribers. Keys are long-lived, named and revocable, with no scopes, and API key generation is off by default for subscriptions an administrator manages. An active browser session takes precedence over the key. |
| Pricing | Freemium ($20 / mo) · Kiro Free is $0 with 50 credits a month and a reduced model list. Pro is $20 a user a month with 1,000 credits, Pro+ $40 with 2,000, Pro Max $100 with 5,000 and Power $200 with 10,000, and extra credits cost $0.04 each. Models use credits at different rates (Auto is the 1.0x baseline). API keys for headless runs need a paid plan, and a paid plan needs a card. GovCloud prices are about 20 per cent higher with no free tier (checked 2026-10-08). |
| x402 | No · No x402, MPP or L402 in the docs, the pricing page or the CLI changelog (checked 2026-10-08). |
| Licence | Proprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the source |
| Source | https://github.com/kirodotdev/Kiro |
| Docs | https://kiro.dev/docs/cli/ |
| llms.txt | https://kiro.dev/llms.txt |
| Last release | 2026-10-05 |
| GitHub stars | 4,356 (as of 2026-10-08) |
| Models | Models on the Kiro plan, with Auto as the default router and a choice of OpenAI GPT-5.6, Anthropic Claude and open-weight models, each with a credit multiplier. No bring-your-own-key option was found in the reviewed documentation |
| Install | Install script with SHA-256 checksum verification for macOS and Linux (glibc 2.34 or newer, or a musl build), a .deb and an AppImage, and a PowerShell script for Windows 11 |
| Engines | 2.x is the released line (2.28.0 on 5 October 2026). V3, the harness shared with the Kiro IDE and Kiro Web, is an early release chosen with `--v3` or `--agent-engine v3`. Classic sessions show a deprecation notice since 2.26.0 |
| Approvals | Capabilities (fs_read, fs_write, shell, web_fetch, web_search, mcp, subagent and others) with deny, ask and allow rules in permissions.yaml. Deny wins in any scope. Defaults allow workspace reads and read-only git commands and ask for the rest. `--trust-tools` and `--trust-all-tools` for non-interactive runs |
| Workspace trust | An untrusted workspace doesn't load its custom agents, steering files, MCP configuration, skills or workflows, and asks before every shell command and MCP tool call. The trust decision is stored outside the repository |
| Sandbox | None in the CLI. The docs list sandboxed execution for Kiro Web only. Compound shell commands are split and each part is matched against the rules |
| Managed policy | A managed-settings.json at an OS-protected path adds deny and ask rules for the IDE and the CLI, and a malformed file fails closed. AWS says the policy is client-enforced and can be circumvented by a user with administrative access |
| MCP client | stdio and remote HTTP servers with headers, OAuth with dynamic client registration or supplied client credentials, `autoApprove` and `disabledTools` per server, on-demand tool search, and an enterprise MCP registry |
| Headless | `kiro-cli chat --no-interactive` with a prompt as an argument or on stdin, `--output-format stream-json`, `--agent`, `--model`, `--effort`, `--resume` and `--resume-id`. Exit codes 0, 1, 3 (MCP startup failure) and 4 (requested agent not found) |
| ACP | `kiro-cli acp` speaks the Agent Client Protocol as JSON-RPC 2.0 over stdio for JetBrains IDEs, Zed and other clients. A client can request policy presets such as read-workspace or edit-workspace for a session |
| Telemetry | Usage data and performance metrics on by default for Free and individual accounts, turned off with `kiro-cli settings telemetry.enabled false`. Content is used for service improvement, including model training, unless the user opts out. Enterprise users are opted out |
| Data handling | Content for Free and individual accounts is stored in US East (N. Virginia). Free Tier inputs may be kept up to 60 days for abuse detection, and traffic to some models is retained up to 30 days. Inference runs on Amazon Bedrock with cross-region routing |
| Releases in 90 days | At least 11 minor versions (2.20.0 on 26 August to 2.28.0 on 5 October 2026) plus patch releases. Earlier pages of the changelog weren't counted |
| Capabilities | agent.harness, agent.mcp-client, agent.multi-agent |
| Tags | official, harness, coding-agent, cli, closed-source, mcp, acp, llms-txt, free-tier, no-card, telemetry-default-on |
| JSON | https://www.anchorterminal.com/api/v1/tools/kiro-cli.json |
## Score breakdown (methodology v0.4, October 2026 research run)
Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points.
| Category | Weight | This run | Score (0–100) | Points |
| --- | --- | --- | --- | --- |
| Reliability | 16% | 20 | 57 | 11.4 |
| Performance | 10% | pending | pending | n/a |
| Schema & documentation | 13% | 16.2 | 79 | 12.8 |
| Agent ergonomics | 13% | 16.2 | 67 | 10.9 |
| Security & auth | 14% | 17.5 | 66 | 11.6 |
| Payments & pricing | 10% | 12.5 | 40 | 5.0 |
| Task success | 10% | pending | pending | n/a |
| Maintenance & community | 7% | 8.8 | 73 | 6.4 |
| Transparency & trust (editorial 62, provenance 72) | 7% | 8.8 | 67 | 5.9 |
| Negative events | up to −15 | up to −15 | 2026-08-04. CVE-2026-18656 and CVE-2026-18657 (bulletin 2026-074-AWS), an uncontrolled search path on Windows let a planted executable in a crafted project directory run when a user opened it. Kiro CLI for Windows before 2.10.0 and Kiro IDE 1.0.0 to 1.0.212. Fixed and published with credit to the reporters, inside six months (https://aws.amazon.com/security/security-bulletins/2026-074-aws/). -2 2026-05-22. CVE-2026-9255 (bulletin 2026-035-AWS), content piped to kiro-cli on stdin could answer the tool approval prompt, so a local actor could run tools and shell commands without the user's approval. kiro-cli before 1.28.0. Fixed and published, inside six months (https://aws.amazon.com/security/security-bulletins/2026-035-aws/). -2 | -4 |
| **Total** | | | | **59.9 → C** |
### Why each score
- Reliability 57: Local-package reading, the same as the other closed-source harnesses. An install script that verifies SHA-256 checksums, a .deb, an AppImage and a PowerShell script, with macOS, Windows 11 and Linux (glibc 2.34 or newer, or musl) stated (20). No public CI or test suite, since the source isn't published and the GitHub repository is an issue tracker (0). 1,401 open issues in the shared Kiro tracker, 428 labelled cli, with 96 cli issues opened and 69 closed in the 30 days to 8 October, area labels, a triage label and stale-issue automation. Open reports from the last week include a `--no-interactive` run that never exits after a refusal (12). A dated changelog for every release and a breaking-change table with a migration guide for V3, which runs beside 2.x until the user opts in, though 2.24.0 stopped loading project `.env` files in a minor version (10). 2.28.0, with V3 still an early release (15).
- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.
- Schema & documentation 79: Framework reading. A command reference, a settings reference, an exit-code page and a documented rule format for permissions, plus the Agent Client Protocol methods the CLI implements. No published schema for the stream-json events was found (14). kiro.dev/llms.txt indexes every docs page and each has a Markdown twin, though robots.txt disallows both for crawlers (10). The permissions page states the defaults, what each preset allows and when to pick it, and that headless runs treat ask as deny (16). Rules are validated, an unknown preset rejects the session request, and a malformed managed policy fails closed (12). CI examples, exit codes 0, 1, 3 and 4 and hook exit codes are documented, but code 1 covers every other failure (12). Versioned releases with a dated changelog and a 2.x reference kept beside V3 (15).
- Agent ergonomics 67: Framework reading, adapted to a harness driven by a pipeline. `--trust-tools` limits approved tools, `disabledTools` removes MCP tools per server, tool search loads MCP tools on demand, and custom agents carry their own tool set (20). Compaction and a workflow timeout (`KIRO_HEADLESS_WORKFLOW_TIMEOUT_SECS`, six hours by default) exist, but no cap on turns or run time for a plain headless run was found (10). Distinct exit codes for MCP startup failure and a missing agent, `--require-mcp-startup`, and a final interruption record in stream-json, with exit 1 for everything else (14). Sessions are saved every turn, with `--resume`, `--resume-id` and checkpoints with rewind (15). No SDK. The programmatic interfaces are the headless command and the ACP server, and a headless run needs a paid-plan API key and explicit trust flags (8).
- Security & auth 66: Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. Telemetry and content collection are on by default for Free and individual accounts, each with a documented opt-out, and enterprise users are opted out. API keys are long-lived and revocable with no scopes, and administrators must switch key generation on (14). Deny over ask over allow across six scopes, hard-coded denies on Kiro's own settings paths, workspace trust and a managed policy that fails closed. There is no local sandbox in the CLI, and AWS says managed policies are client-enforced and can be circumvented (16). An untrusted workspace doesn't load its agents, steering, MCP configuration or skills, compound shell commands are split before matching, and the MCP page warns that servers run outside any sandbox (11). Enterprise prompt logging to the customer's S3 bucket covers the CLI, with daily activity reports and OpenTelemetry export, and individuals have local logs only (11). AWS vulnerability reporting with a HackerOne disclosure programme, CVEs published in security bulletins with credit to reporters, ISO/IEC 27001:2022 scope and HIPAA eligibility. kiro.dev has no security.txt and the one on aws.amazon.com expired on 24 September 2026 (14).
- Payments & pricing 40: Harness reading of the published rubric, scored on the Kiro subscription the CLI needs. No payment protocol (0). Plan prices, the $0.04 credit price and per-model credit multipliers are public without a login (20). Kiro Free has 50 credits a month, and the pricing page asks for a card only on upgrade (20). A person signs in through a browser or device flow, and the API key for headless runs is created by hand at app.kiro.dev on a paid plan (0).
- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.
- Maintenance & community 73: 2.28.0 on 5 October 2026 (30). At least 11 minor versions and their patches between 26 August and 5 October (20). A public issue tracker with area labels and triage automation, 69 cli issues closed against 96 opened in 30 days, and a Discord server. We didn't establish how many replies come from staff (14). No SDK and no registry entry. The ACP server is kept current, with a migration guide for clients moving to V3 (6). Closed source, so no CI or dependency health to read. The installer verifies checksums (3).
- Transparency & trust 67: Proprietary, with clear terms. The licence page puts the CLI under the AWS Customer Agreement and the AWS Intellectual Property Licence, where the Amazon Q Developer CLI it replaced was Apache 2.0 (15). The data protection page says what is stored for Free, individual and enterprise users, names US East (N. Virginia) for storage, lists inference regions, and gives 60 days for Free Tier abuse detection and 30 days for some models. It agrees with sections 50.3 and 50.14 of the AWS Service Terms. No general retention period for stored content was found (22). Classic sessions carry a deprecation notice and V3 has a breaking-change table and migration guides, but no deprecation policy or removal dates were found (10). Telemetry types are listed and `telemetry.enabled` turns them off, with collection on by default (15).
Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (21 items): https://www.anchorterminal.com/fixes/kiro-cli.md (JSON https://www.anchorterminal.com/fixes/kiro-cli.json)
### What we couldn't check
- unchecked: whether Kiro has a public status page or appears on the AWS Health Dashboard. None is linked from kiro.dev or its docs, and status.kiro.dev didn't answer
- unchecked: the event schema of `--output-format stream-json`. The headless page describes the format and no schema was found
- unchecked: how many replies in the GitHub issue tracker come from AWS staff, and the Discord server
- unchecked: releases before 26 August 2026. Only the first page of the CLI changelog was read, so the 90-day count is a lower bound
- unchecked: the AWS sub-processor list and the Data Privacy FAQ the data protection page links to
- Whether a paid bug bounty covers Kiro. The AWS security.txt points to a HackerOne vulnerability disclosure programme, and its Expires date of 24 September 2026 had passed
- robots.txt on kiro.dev disallows /llms.txt and the Markdown twins for crawlers, while llms.txt tells agents to fetch them. We read the HTML pages for the docs
- The headless page documents `--trust-tools` for V3 runs while the V3 page says permissions.yaml replaces the trust flags. We didn't run either engine
- The CLI overview page calls ACP the Agent Communication Protocol, and the ACP page calls it the Agent Client Protocol
### Sources
- CLI overview: (seen 2026-10-08)
- headless mode: (seen 2026-10-08)
- authentication and API keys: (seen 2026-10-08)
- permissions and workspace trust: (seen 2026-10-08)
- enterprise permission policies: (seen 2026-10-08)
- API key governance: (seen 2026-10-08)
- exit codes: (seen 2026-10-08)
- CLI command reference: (seen 2026-10-08)
- settings reference: (seen 2026-10-08)
- ACP server: (seen 2026-10-08)
- CLI V3 and breaking changes: (seen 2026-10-08)
- MCP configuration: (seen 2026-10-08)
- MCP security: (seen 2026-10-08)
- data protection, service improvement and telemetry: (seen 2026-10-08)
- compliance programmes: (seen 2026-10-08)
- prompt logging: (seen 2026-10-08)
- installation and system requirements: (seen 2026-10-08)
- install script: (seen 2026-10-08)
- migration from the Amazon Q Developer CLI: (seen 2026-10-08)
- pricing: (seen 2026-10-08)
- billing tiers: (seen 2026-10-08)
- models and credit multipliers: (seen 2026-10-08)
- CLI changelog: (seen 2026-10-08)
- licence: (seen 2026-10-08)
- llms.txt: (seen 2026-10-08)
- robots.txt: (seen 2026-10-08)
- issue tracker README and workflows (git clone): (seen 2026-10-08)
- issue counts (GitHub API): (seen 2026-10-08)
- security bulletin 2026-035-AWS, CVE-2026-9255: (seen 2026-10-08)
- security bulletin 2026-074-AWS, CVE-2026-18656 and CVE-2026-18657: (seen 2026-10-08)
- AWS security bulletins feed: (seen 2026-10-08)
- AWS Service Terms, sections 1.24, 50.3 and 50.14: (seen 2026-10-08)
- AWS Customer Agreement: (seen 2026-10-08)
- AWS Privacy Notice: (seen 2026-10-08)
- AWS security.txt: (seen 2026-10-08)
- domain registration (RDAP): (seen 2026-10-08)
## Who's behind it (provenance 72/100, checked 2026-10-08)
| Check | Finding | Points |
| --- | --- | --- |
| Legal entity named | Amazon Web Services, Inc. | 20/20 |
| Domain age | kiro.dev, registered 2019-03-01 (7 years) | 11/15 |
| Endpoint on the vendor's domain | no hosted endpoint | n/a |
| Terms of service | read, states 7 of the 7 things a reader expects | 10/10 |
| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |
| Status page | not found | 0/10 |
| Changelog | published | 10/10 |
| security.txt | not found | 0/10 |
Kiro's licence page says the Kiro IDE and CLI are licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence. Section 50.14 of the AWS Service Terms names Amazon Web Services, Inc. as the contracting party for subscriptions bought through the Stripe portal.
The AWS Customer Agreement (last updated 14 August 2026) governs use, with the AWS Service Terms sections 50.3 and 50.14 for Kiro. The AWS Privacy Notice (last updated 18 May 2026) is the privacy link in Kiro's footer.
kiro.dev/.well-known/security.txt answers 404. aws.amazon.com publishes a security.txt whose Expires line reads 24 September 2026, which had passed when we read it.
No status page for Kiro was found on kiro.dev or in its docs.
RDAP (Google Registry) gives kiro.dev a registration date of 1 March 2019, before the product.
### Terms and privacy, as read
A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.
**Terms of service** (https://aws.amazon.com/agreement/), read 2026-10-08, dated 2026-08-14, states 7 of the 7 things a reader expects.
- To know. Says access can be ended without notice or for any reason. "We may terminate this Agreement for any reason by providing you at least 30 days’ advance notice."
- To know. Requires arbitration or waives class actions. "Disputes will be resolved by binding arbitration, rather than in court, except that either party may elect to proceed in small claims court if your claims qualify."
- Gives the date it was last updated. Last updated 2026-08-14.
- Names the governing law or courts. The law of the Province of Ontario.
- States a limit on its liability. Capped at the fees paid in the 12 months before the claim.
- Says how changes to the terms are announced. Gives 90 days of notice before a change.
- Also in the text (2026-10-08). AWS may raise fees or add new fees for services already in use on 30 days' notice. "We may increase or add new fees and charges for any existing Services you are using by giving you at least 30 days’ prior notice."
- Also in the text (2026-10-08). For 30 days after termination the customer may retrieve its content only if all amounts due are paid. This period does not apply when AWS terminates under Section 5.2(b). "(ii) we will allow you to retrieve Your Content from the Services only if you have paid all amounts due under this Agreement."
- Also in the text (2026-10-08). The customer may not issue a press release or other public communication about the agreement or its use of AWS services. "You will not issue any press release or make any other public communication with respect to this Agreement or your use of the Services or AWS Content."
**Privacy policy** (https://aws.amazon.com/privacy/), read 2026-10-08, dated 2026-05-18, states 8 of the 8 things a reader expects.
- To know. Says it sells personal data or shares it for advertising. "To help you receive more useful and relevant ads on other sites and services and to measure their effectiveness, AWS shares limited personal information with our advertising partners."
- Gives the date it was last updated. Last updated 2026-05-18.
- Says how long data is kept. For as long as needed, with no period named.
- Gives a privacy contact. Names a data protection officer.
- Says where data is transferred or stored. Relies on the Data Privacy Framework.
- Also in the text (2026-10-08). The notice does not cover content that customers process, store or host on AWS. It refers to the customer agreement for how that content is handled. "This Privacy Notice does not apply to the “content” processed, stored, or hosted by our customers using AWS Offerings in connection with an AWS account."
## Live (updated 2026-10-08 18:21 UTC)
- Watching deprecations
- Always current: https://www.anchorterminal.com/api/v1/live/kiro-cli.json
## Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.
## Prices
| Item | Price | Unit | Note |
| --- | --- | --- | --- |
| Kiro Pro | $20 | per month (plan) | per user, with 1,000 credits |
| Add-on credit | $0.04 | per credit | paid plans, beyond the plan's credits |
Across all listings: https://www.anchorterminal.com/prices/index.md
## Dated changes
- 2026-09-23 · Breaking change · Project `.env` files no longer load automatically into chat sessions, MCP servers or tools (2.24.0) (source: )
- 2026-09-30 · Notice · Classic (non-TUI) sessions show a deprecation notice and don't support the V3 engine (2.26.0). No removal date was found (source: )
All listings, as a calendar: https://www.anchorterminal.com/sunsets.ics
## Strengths
- Capability permissions with deny over ask over allow, stored outside the repository so a clone can't add rules
- An untrusted workspace doesn't load its own agents, steering files, MCP configuration or skills, and asks before every shell command
- Headless runs with `--no-interactive`, JSON Lines output, and exit codes 3 and 4 for MCP startup and missing-agent failures
- Eleven minor releases between 26 August and 5 October 2026 in a dated changelog
- Plan prices, the $0.04 credit price and per-model credit multipliers are public, with a free tier of 50 credits a month
## Weaknesses
- Free and individual paid accounts have content used for service improvement, including model training, unless they opt out
- Closed source since it replaced the Apache 2.0 Amazon Q Developer CLI, with no public CI or test suite
- API keys for headless runs need a paid plan, are long-lived and carry no scopes
- No local sandbox in the CLI, and AWS says its managed permission policies are client-enforced and can be circumvented
- Two CVEs in 2026 (CVE-2026-9255 in May, CVE-2026-18656 and CVE-2026-18657 in August), both fixed
## Before you call it (notes for agents)
1. Set `KIRO_API_KEY` and pass `--no-interactive` with `--trust-tools=` in pipelines. Keep `--trust-all-tools` for disposable environments
2. Pass `--require-mcp-startup` when a run depends on MCP tools. Without it a failed server is logged and the run continues
3. Pass `--no-interactive` whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows
4. Run `kiro-cli settings telemetry.enabled false` and turn off content collection on Free and individual plans. Both are on by default
5. Export variables in the shell before starting. Since 2.24.0 a project `.env` file is no longer loaded into sessions, MCP servers or tools
## Connect
Install:
```bash
curl -fsSL https://cli.kiro.dev/install | bash
```
Headless / CI:
```json
{
"run": "KIRO_API_KEY=ksk_... kiro-cli chat --no-interactive --trust-tools=read,grep \"Find all TODO comments in src/\""
}
```
## Similar tools
Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.
| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |
| --- | --- | --- | --- | --- | --- | --- |
| goose | BB | 73.9 | 72 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/goose.md |
| Qwen Code | BB | 72.4 | 93 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/qwen-code.md |
| Gemini CLI | BB | 72 | 99 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/gemini-cli.md |
| OpenHands | BB | 70.8 | 126 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/openhands.md |
| OpenCode | B | 67.7 | 200 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/opencode.md |
| Claude Code | C | 61.9 | 354 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/claude-code.md |
## Panel reviews (0)
Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .
Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md
## Notable
- Kiro CLI replaced the Amazon Q Developer CLI from 17 November 2025, and installs with auto-update moved across on 24 November 2025. The Q CLI was Apache 2.0 and Kiro CLI is licensed under the AWS Intellectual Property Licence (source: )
- Headless mode needs an API key in `KIRO_API_KEY`, which only Pro, Pro+, Pro Max and Power subscribers can create, and which an administrator has to switch on for managed subscriptions (source: )
- Content from Free Tier users and individual subscribers may be used for service improvement, including model training, unless they opt out. Enterprise content isn't used (source: )
- Permission rules use deny over ask over allow across six scopes, workspace rules are stored outside the repository, and a headless session treats every ask as a deny (source: )
- CLI V3, built on the harness the Kiro IDE and Kiro Web use, is an early release beside 2.x. It replaces the trust flags with permissions.yaml, changes the session and hook formats and removes the built-in AWS tool (source: )
- AWS published two security bulletins that cover the CLI in 2026, CVE-2026-9255 on 22 May and CVE-2026-18656 with CVE-2026-18657 on 4 August (source: )
- Eleven minor versions from 2.20.0 on 26 August to 2.28.0 on 5 October 2026, with patch releases between them (source: )
## Compare
- [Aider vs Kiro CLI](https://www.anchorterminal.com/compare/aider-vs-kiro-cli.md): D 46.9 vs C 59.9
- [Amp vs Kiro CLI](https://www.anchorterminal.com/compare/amp-vs-kiro-cli.md): C 57.1 vs C 59.9
- [Claude Code vs Kiro CLI](https://www.anchorterminal.com/compare/claude-code-vs-kiro-cli.md): C 61.9 vs C 59.9
- [Cline vs Kiro CLI](https://www.anchorterminal.com/compare/cline-vs-kiro-cli.md): C 60.4 vs C 59.9
- [Cursor CLI vs Kiro CLI](https://www.anchorterminal.com/compare/cursor-cli-vs-kiro-cli.md): F 35.3 vs C 59.9
- [Devin vs Kiro CLI](https://www.anchorterminal.com/compare/devin-vs-kiro-cli.md): C 55.7 vs C 59.9
- [Pi vs Kiro CLI](https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli.md): B 68.4 vs C 59.9
- [Gemini CLI vs Kiro CLI](https://www.anchorterminal.com/compare/gemini-cli-vs-kiro-cli.md): BB 72 vs C 59.9
- [GitHub Copilot CLI vs Kiro CLI](https://www.anchorterminal.com/compare/github-copilot-cli-vs-kiro-cli.md): C 57.6 vs C 59.9
- [goose vs Kiro CLI](https://www.anchorterminal.com/compare/goose-vs-kiro-cli.md): BB 73.9 vs C 59.9
- [Kiro CLI vs OpenAI Codex](https://www.anchorterminal.com/compare/kiro-cli-vs-openai-codex.md): C 59.9 vs BB 73
- [Kiro CLI vs OpenCode](https://www.anchorterminal.com/compare/kiro-cli-vs-opencode.md): C 59.9 vs B 67.7
- [Kiro CLI vs OpenHands](https://www.anchorterminal.com/compare/kiro-cli-vs-openhands.md): C 59.9 vs BB 70.8
- [Kiro CLI vs Prime Agent](https://www.anchorterminal.com/compare/kiro-cli-vs-prime-agent.md): C 59.9 vs C 60.5
- [Kiro CLI vs Qwen Code](https://www.anchorterminal.com/compare/kiro-cli-vs-qwen-code.md): C 59.9 vs BB 72.4
- [Kiro CLI vs Paperclip](https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.md): C 59.9 vs C 59
## Verify this listing
For the vendor. The badge or a plain link to this page verifies the listing, from a page on kiro.dev or one of its subdomains, or the README of github.com/kirodotdev/Kiro. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "kiro-cli", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify
HTML badge:
```html
```
Markdown badge, for a README:
```markdown
[](https://www.anchorterminal.com/tools/kiro-cli)
```
Plain link:
```html
Kiro CLI on Anchor Terminal
```
## Share this listing
For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Kiro CLI is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.
- Dark: https://www.anchorterminal.com/assets/share/kiro-cli-dark.png
- Light: https://www.anchorterminal.com/assets/share/kiro-cli-light.png