# Kiro CLI (slim) > AWS's coding agent for the terminal and the successor to the Amazon Q Developer CLI. It runs interactive chat, non-interactive runs for pipelines with an API key, MCP servers and an Agent Client Protocol server for editors. - Full: https://www.anchorterminal.com/tools/kiro-cli.md (~8,300 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/kiro-cli.json · canonical https://www.anchorterminal.com/tools/kiro-cli - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 59.9/100 · rank #419 of 722 · #11 in Agent harnesses · not agent-ready · confidence medium** Assessment: Permission rules follow deny over ask over allow, cloned repositories can't add rules, and a headless session treats every ask as a deny. Content from Free and individual paid accounts is used for service improvement, including model training, unless the user opts out, and API keys for pipelines need a paid plan. ## Facts - Kind: Agent harness · vendor: Amazon Web Services · category: Agent harnesses · legal entity: Amazon Web Services, Inc. · provenance 72/100 - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary. Licensed as AWS Content under the AWS Customer Agreement and the AWS Intellectual Property Licence (https://kiro.dev/license/). The GitHub repository is the public issue tracker and doesn't hold the source - Probe metrics: not measured yet (probes haven't run) - Models: Models on the Kiro plan, with Auto as the default router and a choice of OpenAI GPT-5.6, Anthropic Claude and open-weight models, each with a credit multiplier. No bring-your-own-key option was found in the reviewed documentation - Install: Install script with SHA-256 checksum verification for macOS and Linux (glibc 2.34 or newer, or a musl build), a .deb and an AppImage, and a PowerShell script for Windows 11 - Engines: 2.x is the released line (2.28.0 on 5 October 2026). V3, the harness shared with the Kiro IDE and Kiro Web, is an early release chosen with `--v3` or `--agent-engine v3`. Classic sessions show a deprecation notice since 2.26.0 - Approvals: Capabilities (fs_read, fs_write, shell, web_fetch, web_search, mcp, subagent and others) with deny, ask and allow rules in permissions.yaml. Deny wins in any scope. Defaults allow workspace reads and read-only git commands and ask for the rest. `--trust-tools` and `--trust-all-tools` for non-interactive runs - Workspace trust: An untrusted workspace doesn't load its custom agents, steering files, MCP configuration, skills or workflows, and asks before every shell command and MCP tool call. The trust decision is stored outside the repository - Sandbox: None in the CLI. The docs list sandboxed execution for Kiro Web only. Compound shell commands are split and each part is matched against the rules - Managed policy: A managed-settings.json at an OS-protected path adds deny and ask rules for the IDE and the CLI, and a malformed file fails closed. AWS says the policy is client-enforced and can be circumvented by a user with administrative access - MCP client: stdio and remote HTTP servers with headers, OAuth with dynamic client registration or supplied client credentials, `autoApprove` and `disabledTools` per server, on-demand tool search, and an enterprise MCP registry - Headless: `kiro-cli chat --no-interactive` with a prompt as an argument or on stdin, `--output-format stream-json`, `--agent`, `--model`, `--effort`, `--resume` and `--resume-id`. Exit codes 0, 1, 3 (MCP startup failure) and 4 (requested agent not found) - ACP: `kiro-cli acp` speaks the Agent Client Protocol as JSON-RPC 2.0 over stdio for JetBrains IDEs, Zed and other clients. A client can request policy presets such as read-workspace or edit-workspace for a session - Telemetry: Usage data and performance metrics on by default for Free and individual accounts, turned off with `kiro-cli settings telemetry.enabled false`. Content is used for service improvement, including model training, unless the user opts out. Enterprise users are opted out - Data handling: Content for Free and individual accounts is stored in US East (N. Virginia). Free Tier inputs may be kept up to 60 days for abuse detection, and traffic to some models is retained up to 30 days. Inference runs on Amazon Bedrock with cross-region routing - Releases in 90 days: At least 11 minor versions (2.20.0 on 26 August to 2.28.0 on 5 October 2026) plus patch releases. Earlier pages of the changelog weren't counted - Prices: Kiro Pro $20 per month (plan); Add-on credit $0.04 per credit - 2026-09-23 Breaking change: Project `.env` files no longer load automatically into chat sessions, MCP servers or tools (2.24.0) - 2026-09-30 Notice: Classic (non-TUI) sessions show a deprecation notice and don't support the V3 engine (2.26.0). No removal date was found - Scores: Reliability 57, Performance pending, Schema & documentation 79, Agent ergonomics 67, Security & auth 66, Payments & pricing 40, Task success pending, Maintenance & community 73, Transparency & trust 67 · negative events -4 · total over the 7 assessed categories - Why: Reliability, Local-package reading, the same as the other closed-source harnesses. · Schema & documentation, Framework reading. · Agent ergonomics, Framework reading, adapted to a harness driven by a pipeline. · Security & auth, Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. · Payments & pricing, Harness reading of the published rubric, scored on the Kiro subscription the CLI needs. · Maintenance & community, 2.28.0 on 5 October 2026 (30). · Transparency & trust, Proprietary, with clear terms. - Sources: 36, open questions: 9, both in the full twin - Capabilities: agent.harness, agent.mcp-client, agent.multi-agent - JSON: https://www.anchorterminal.com/api/v1/tools/kiro-cli.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/kiro-cli.svg` or a link to https://www.anchorterminal.com/tools/kiro-cli from a page on kiro.dev or one of its subdomains, or the README of github.com/kirodotdev/Kiro, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Set `KIRO_API_KEY` and pass `--no-interactive` with `--trust-tools=` in pipelines. Keep `--trust-all-tools` for disposable environments 2. Pass `--require-mcp-startup` when a run depends on MCP tools. Without it a failed server is logged and the run continues 3. Pass `--no-interactive` whenever input is piped from a source you don't control, and run 2.10.0 or later on Windows 4. Run `kiro-cli settings telemetry.enabled false` and turn off content collection on Free and individual plans. Both are on by default 5. Export variables in the shell before starting. Since 2.24.0 a project `.env` file is no longer loaded into sessions, MCP servers or tools ## Connect ```bash curl -fsSL https://cli.kiro.dev/install | bash ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | goose | BB | 73.9 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/goose.min.md | | Qwen Code | BB | 72.4 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/qwen-code.min.md | | Gemini CLI | BB | 72 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/gemini-cli.min.md | | OpenHands | BB | 70.8 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/openhands.min.md | | OpenCode | B | 67.7 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/opencode.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)