{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/goose.json",
        "name": "goose",
        "score": 73.9,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "goose"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/gemini-cli.json",
        "name": "Gemini CLI",
        "score": 72,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "gemini-cli"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/openhands.json",
        "name": "OpenHands",
        "score": 70.8,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "openhands"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/opencode.json",
        "name": "OpenCode",
        "score": 67.7,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "opencode"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/claude-code.json",
        "name": "Claude Code",
        "score": 61.9,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "claude-code"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/prime-agent.json",
        "name": "Prime Agent",
        "score": 60.5,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "prime-agent"
      }
    ],
    "tool": {
      "slug": "qwen-code",
      "name": "Qwen Code",
      "vendor": "Alibaba (Qwen team)",
      "vendorUrl": "https://qwenlm.github.io/qwen-code-docs/en/users/overview/",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Open-source coding agent from Alibaba's Qwen team for the terminal, with desktop, browser and editor interfaces. It runs Qwen, OpenAI, Anthropic and Gemini-compatible models or a local one, and runs headless with `qwen -p`.",
      "url": "https://www.anchorterminal.com/tools/qwen-code",
      "markdownUrl": "https://www.anchorterminal.com/tools/qwen-code.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/qwen-code.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/qwen-code.json",
      "repo": "https://github.com/QwenLM/qwen-code",
      "license": "Apache-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@qwen-code/qwen-code"
        },
        {
          "registry": "npm",
          "name": "@qwen-code/sdk"
        },
        {
          "registry": "pypi",
          "name": "qwen-code-sdk"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/qwenlm/qwen-code"
        }
      ],
      "auth": "api-key",
      "authNotes": "No account of its own. A model key goes in an environment variable or `~/.qwen/settings.json`, for Alibaba Cloud Model Studio (Coding Plan, Token Plan or a standard key), a listed third-party provider, or any OpenAI, Anthropic or Gemini-compatible endpoint including a local server. Vertex AI credentials also work. The Qwen OAuth sign-in was discontinued on 15 April 2026.",
      "pricing": "free",
      "pricingNotes": "Free and Apache-2.0, with nothing to buy for the CLI. The owner pays the model provider, or nothing with a local model. The Qwen OAuth free tier ended on 15 April 2026. Alibaba Cloud sells a fixed-fee Coding Plan and a usage-billed Token Plan for it, and we couldn't load their price pages on 8 October 2026.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 28362,
        "npmWeekly": 104819,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://qwenlm.github.io/qwen-code-docs/en/users/overview/",
      "llmsTxt": "https://qwenlm.github.io/qwen-code-docs/llms.txt",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "official",
        "harness",
        "coding-agent",
        "cli",
        "open-source",
        "typescript",
        "mcp",
        "llms-txt",
        "telemetry-default-on",
        "pre-1.0",
        "free",
        "no-card",
        "local",
        "docker"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 72.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 93,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 85,
          "maintenance": 88,
          "payments": 60,
          "reliability": 69,
          "schema": 91,
          "security": 53,
          "transparency": 63
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 69,
            "points": 13.8,
            "reason": "Local-package reading. npm with engines node 22 or newer, Homebrew at 0.25.0 and a standalone installer, with stable, preview and nightly channels (20). Public CI, and of the 15 most recent completed CI runs on main on 8 October, 12 passed, 3 were cancelled and none failed, though two issues opened by automation the same day report a failed end-to-end test and a failed Java SDK job on main (22). 1,402 open issues and 334 open pull requests. The ten newest issues each had labels and one to five comments within the day, much of it from the project's own triage automation (15). The changelog states Keep a Changelog and semver and every release has a Breaking Changes heading, but breaking changes shipped in patch releases 0.23.4 and 0.24.1 (12). 0.25.0, pre-1.0 (0)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 91,
            "points": 14.79,
            "reason": "Framework reading. A settings.schema.json in the repository, a settings reference with the type and default of each key, and an OpenAPI file for the daemon's REST API (25). llms.txt on the docs site lists the pages with a line each, though it links to HTML and the Markdown path we tried returned 404 (8). The approval-mode page says when to use each mode and the sandbox page what each method and Seatbelt profile allows (15). Approval modes, sandbox backends, filesystem and network policies are enums (13). The headless page documents json and stream-json output, and exit codes 41, 42, 44, 52, 53, 55 and 130 are documented (15). A dated changelog generated from releases (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 85,
            "points": 13.81,
            "reason": "Framework reading, adapted to a harness driven by a pipeline. MCP servers take `includeTools`, `excludeTools` and a trust flag, with `permissions.allow`, `ask` and `deny` rules and `--exclude-tools` (20). Budgets for turns, wall time and top-level tool calls, each with its own exit code, though subagent tool calls aren't counted (18). Documented exit codes (18). `--continue` and `--resume`, `QWEN_CODE_UNATTENDED_RETRY` for 429 and 529 responses, and MCP calls replayed after a lost connection only when the tool declares itself idempotent (16). A TypeScript SDK on npm at 0.1.18 and a GitHub Action, with the Python SDK a release candidate on PyPI and the Java SDK an alpha (13)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 53,
            "points": 9.28,
            "reason": "Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. Usage statistics are on by default, documented as tool names, model names, timings and configuration without prompts, responses, file contents or personal information, with a setting and an environment variable to turn them off. Credentials are API keys in environment variables or settings.json (15). Five approval modes with a read-only plan mode and allow, ask and deny rules, but the settings default is Auto, where an LLM classifier approves tool calls, folder trust is disabled by default and sandboxing is opt-in (10). A Linux tool sandbox with `network: closed`, `--safe-mode` and a stderr warning for yolo without a sandbox, but the default macOS Seatbelt profile allows network and we found no guidance on prompt injection in the pages read (7). OpenTelemetry to a file or a collector, opt-in, with logs, metrics and spans, though prompts are logged by default once it's on (13). SECURITY.md gives only an Alibaba Cloud console portal with no response time, the repository has no published advisories, no security.txt was found, and CodeQL and scorecard workflows run in CI (8)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 60,
            "points": 7.5,
            "reason": "Self-hosted rule. No payment protocol (0). The CLI is free under Apache-2.0 with nothing to buy (20). No card or account is needed for the software, and it runs against a local model server (20). An agent can install and run it with no sign-up, given a model endpoint (20). Alibaba Cloud's Coding Plan and Token Plan are separate purchases, and their price pages couldn't be loaded on 8 October 2026."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 88,
            "points": 7.7,
            "reason": "0.25.0 on 5 October 2026 (30). 39 stable releases since 10 July, plus previews and nightlies (20). Issues are labelled and commented on within a day, largely by automation, against 1,402 open issues and 334 open pull requests (17). A TypeScript SDK released on 5 October, with the Python SDK last published to PyPI as a release candidate on 9 May 2026 and the Java SDK an alpha (11). CI, CodeQL, a monthly scorecard and Dependabot (10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 63,
            "points": 5.51,
            "note": "editorial 77, provenance 48",
            "reason": "Apache-2.0 (30). One terms and privacy page maps each sign-in method to the model provider's terms, says the project doesn't train on prompts or code, and lists what usage statistics hold, but gives no retention period, doesn't name the Alibaba Cloud endpoint the statistics go to, and names no legal entity (18). The end of the Qwen OAuth free tier is dated 15 April 2026 and `tools.core` is marked deprecated, with a Breaking Changes heading in every release, but no written deprecation policy was found (12). Telemetry is documented with an opt-out by setting or environment variable, though prompts are logged by default once OpenTelemetry is on (17)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Framework reading, adapted to a harness driven by a pipeline. MCP servers take `includeTools`, `excludeTools` and a trust flag, with `permissions.allow`, `ask` and `deny` rules and `--exclude-tools` (20). Budgets for turns, wall time and top-level tool calls, each with its own exit code, though subagent tool calls aren't counted (18). Documented exit codes (18). `--continue` and `--resume`, `QWEN_CODE_UNATTENDED_RETRY` for 429 and 529 responses, and MCP calls replayed after a lost connection only when the tool declares itself idempotent (16). A TypeScript SDK on npm at 0.1.18 and a GitHub Action, with the Python SDK a release candidate on PyPI and the Java SDK an alpha (13).",
            "maintenance": "0.25.0 on 5 October 2026 (30). 39 stable releases since 10 July, plus previews and nightlies (20). Issues are labelled and commented on within a day, largely by automation, against 1,402 open issues and 334 open pull requests (17). A TypeScript SDK released on 5 October, with the Python SDK last published to PyPI as a release candidate on 9 May 2026 and the Java SDK an alpha (11). CI, CodeQL, a monthly scorecard and Dependabot (10).",
            "payments": "Self-hosted rule. No payment protocol (0). The CLI is free under Apache-2.0 with nothing to buy (20). No card or account is needed for the software, and it runs against a local model server (20). An agent can install and run it with no sign-up, given a model endpoint (20). Alibaba Cloud's Coding Plan and Token Plan are separate purchases, and their price pages couldn't be loaded on 8 October 2026.",
            "reliability": "Local-package reading. npm with engines node 22 or newer, Homebrew at 0.25.0 and a standalone installer, with stable, preview and nightly channels (20). Public CI, and of the 15 most recent completed CI runs on main on 8 October, 12 passed, 3 were cancelled and none failed, though two issues opened by automation the same day report a failed end-to-end test and a failed Java SDK job on main (22). 1,402 open issues and 334 open pull requests. The ten newest issues each had labels and one to five comments within the day, much of it from the project's own triage automation (15). The changelog states Keep a Changelog and semver and every release has a Breaking Changes heading, but breaking changes shipped in patch releases 0.23.4 and 0.24.1 (12). 0.25.0, pre-1.0 (0).",
            "schema": "Framework reading. A settings.schema.json in the repository, a settings reference with the type and default of each key, and an OpenAPI file for the daemon's REST API (25). llms.txt on the docs site lists the pages with a line each, though it links to HTML and the Markdown path we tried returned 404 (8). The approval-mode page says when to use each mode and the sandbox page what each method and Seatbelt profile allows (15). Approval modes, sandbox backends, filesystem and network policies are enums (13). The headless page documents json and stream-json output, and exit codes 41, 42, 44, 52, 53, 55 and 130 are documented (15). A dated changelog generated from releases (15).",
            "security": "Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. Usage statistics are on by default, documented as tool names, model names, timings and configuration without prompts, responses, file contents or personal information, with a setting and an environment variable to turn them off. Credentials are API keys in environment variables or settings.json (15). Five approval modes with a read-only plan mode and allow, ask and deny rules, but the settings default is Auto, where an LLM classifier approves tool calls, folder trust is disabled by default and sandboxing is opt-in (10). A Linux tool sandbox with `network: closed`, `--safe-mode` and a stderr warning for yolo without a sandbox, but the default macOS Seatbelt profile allows network and we found no guidance on prompt injection in the pages read (7). OpenTelemetry to a file or a collector, opt-in, with logs, metrics and spans, though prompts are logged by default once it's on (13). SECURITY.md gives only an Alibaba Cloud console portal with no response time, the repository has no published advisories, no security.txt was found, and CodeQL and scorecard workflows run in CI (8).",
            "transparency": "Apache-2.0 (30). One terms and privacy page maps each sign-in method to the model provider's terms, says the project doesn't train on prompts or code, and lists what usage statistics hold, but gives no retention period, doesn't name the Alibaba Cloud endpoint the statistics go to, and names no legal entity (18). The end of the Qwen OAuth free tier is dated 15 April 2026 and `tools.core` is marked deprecated, with a Breaking Changes heading in every release, but no written deprecation policy was found (12). Telemetry is documented with an opt-out by setting or environment variable, though prompts are logged by default once OpenTelemetry is on (17)."
          },
          "sources": [
            {
              "what": "repository, README, SECURITY.md, CHANGELOG.md, docs and workflows (git clone at 29aef7d)",
              "url": "https://github.com/QwenLM/qwen-code",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog with release dates and Breaking Changes headings",
              "url": "https://github.com/QwenLM/qwen-code/blob/main/CHANGELOG.md",
              "seen": "2026-10-08"
            },
            {
              "what": "npm registry, versions and dates, engines",
              "url": "https://registry.npmjs.org/@qwen-code/qwen-code",
              "seen": "2026-10-08"
            },
            {
              "what": "npm weekly downloads",
              "url": "https://api.npmjs.org/downloads/point/last-week/@qwen-code/qwen-code",
              "seen": "2026-10-08"
            },
            {
              "what": "stars, licence and CI runs on main (GitHub API)",
              "url": "https://api.github.com/repos/QwenLM/qwen-code/actions/workflows/ci.yml/runs?branch=main",
              "seen": "2026-10-08"
            },
            {
              "what": "open issues and pull requests",
              "url": "https://github.com/QwenLM/qwen-code/issues",
              "seen": "2026-10-08"
            },
            {
              "what": "repository advisories (none published)",
              "url": "https://github.com/QwenLM/qwen-code/security/advisories",
              "seen": "2026-10-08"
            },
            {
              "what": "settings reference (approval mode default, usage statistics, MCP keys)",
              "url": "https://qwenlm.github.io/qwen-code-docs/en/users/configuration/settings/",
              "seen": "2026-10-08"
            },
            {
              "what": "headless mode, output formats and run budgets",
              "url": "https://qwenlm.github.io/qwen-code-docs/en/users/features/headless/",
              "seen": "2026-10-08"
            },
            {
              "what": "approval modes",
              "url": "https://qwenlm.github.io/qwen-code-docs/en/users/features/approval-mode/",
              "seen": "2026-10-08"
            },
            {
              "what": "sandboxing",
              "url": "https://qwenlm.github.io/qwen-code-docs/en/users/features/sandbox/",
              "seen": "2026-10-08"
            },
            {
              "what": "trusted folders",
              "url": "https://qwenlm.github.io/qwen-code-docs/en/users/configuration/trusted-folders/",
              "seen": "2026-10-08"
            },
            {
              "what": "authentication and the end of the Qwen OAuth free tier",
              "url": "https://qwenlm.github.io/qwen-code-docs/en/users/configuration/auth/",
              "seen": "2026-10-08"
            },
            {
              "what": "terms of service and privacy notice",
              "url": "https://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/",
              "seen": "2026-10-08"
            },
            {
              "what": "exit codes",
              "url": "https://qwenlm.github.io/qwen-code-docs/en/users/support/troubleshooting/",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenTelemetry settings",
              "url": "https://github.com/QwenLM/qwen-code/blob/main/docs/developers/development/telemetry.md",
              "seen": "2026-10-08"
            },
            {
              "what": "usage statistics endpoint in source",
              "url": "https://github.com/QwenLM/qwen-code/blob/main/packages/core/src/telemetry/qwen-logger/qwen-logger.ts",
              "seen": "2026-10-08"
            },
            {
              "what": "llms.txt",
              "url": "https://qwenlm.github.io/qwen-code-docs/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "Homebrew formula at 0.25.0",
              "url": "https://formulae.brew.sh/api/formula/qwen-code.json",
              "seen": "2026-10-08"
            },
            {
              "what": "Python SDK on PyPI (0.1.0rc0)",
              "url": "https://pypi.org/pypi/qwen-code-sdk/json",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: Alibaba Cloud Coding Plan and Token Plan prices and quotas. alibabacloud.com and help.aliyun.com couldn't be reached from our network on 8 October 2026",
            "unchecked: the Qwen terms of service and privacy policy at qwen.ai, which render only with JavaScript",
            "unchecked: security.txt on alibabacloud.com, and the registration date of any vendor domain",
            "unchecked: how many of the 1,402 open issues are bugs, and how old the oldest are. GitHub's search API refused us for its rate limit",
            "The settings reference gives `auto` as the default approval mode, while the approval-mode page says headless runs default to Ask Permissions. We didn't run it to see which holds",
            "The docs don't name where usage statistics go. The source sends them to gb4w8c3ygj-default-sea.rum.aliyuncs.com",
            "Whether the Java SDK is published to Maven Central wasn't checked",
            "The lead was right on licence, stars (28,362), headless `qwen -p` and MCP. Its docs link was the repository, and the docs site is qwenlm.github.io/qwen-code-docs"
          ]
        },
        "negative": 0,
        "verdict": "Apache-2.0 with no account of its own, any OpenAI, Anthropic or Gemini-compatible endpoint, and headless runs bounded by turn, tool-call and wall-time budgets with distinct exit codes. Out of the box, Auto mode lets an LLM classifier approve tool calls, with the sandbox and folder trust both off. Usage statistics are on by default.",
        "bestFor": "Developers and CI jobs that want an open-source harness tied to no single model vendor, with run budgets and SDKs.",
        "strengths": [
          "Apache-2.0, with CI on main showing 12 passes and 3 cancelled runs in the last 15, none failed",
          "Headless `qwen -p` with json and stream-json output, and exit codes 53 for the turn limit and 55 for a wall-time or tool-call budget",
          "Works with any OpenAI, Anthropic or Gemini-compatible endpoint, including a local server, with keys set by environment variable",
          "39 stable releases in the 90 days to 8 October 2026, each with a Breaking Changes heading in a generated changelog",
          "A Linux tool sandbox (Bubblewrap or Landlock) with `network: closed`, plus Seatbelt, Docker and Podman"
        ],
        "weaknesses": [
          "The default approval mode is Auto, where an LLM classifier approves tool calls, and sandboxing and folder trust are both off by default",
          "Usage statistics are on by default and go to an Alibaba Cloud endpoint that the docs don't name",
          "SECURITY.md points only to an Alibaba Cloud console portal, with no response time, and the repository has no published advisories",
          "Pre-1.0 at 0.25.0, with breaking changes shipped in patch releases such as 0.23.4 and 0.24.1",
          "1,402 open issues and 334 open pull requests on 8 October 2026",
          "The Qwen OAuth free tier ended on 15 April 2026, so every run needs a paid key or a local model"
        ],
        "agentNotes": [
          "Pass `--approval-mode` on every run. The settings default is `auto`, and one docs page says headless runs default to asking, so don't rely on either",
          "Add `--max-session-turns`, `--max-wall-time` and `--max-tool-calls`. All three are unlimited by default. Exit 53 is the turn limit and 55 a budget",
          "`--yolo` doesn't turn on a sandbox. Add `--sandbox`, or on Linux set `tools.executionSandbox` with `network` set to `closed`",
          "Set `QWEN_USAGE_STATISTICS_ENABLED=false` to stop usage statistics",
          "Authenticate with `OPENAI_API_KEY`, `OPENAI_BASE_URL` and `OPENAI_MODEL` in CI. The browser sign-in is discontinued"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 72.4
          }
        ],
        "editorialScores": {
          "ergonomics": 85,
          "maintenance": 88,
          "payments": 60,
          "reliability": 69,
          "schema": 91,
          "security": 53,
          "transparency": 77
        },
        "provenanceScore": 48
      },
      "connect": {
        "install": "npm install -g @qwen-code/qwen-code@latest   # or: brew install qwen-code",
        "headless": {
          "command": "qwen -p \"$TASK\" --output-format json --approval-mode auto-edit --max-session-turns 30 --max-wall-time 10m",
          "env": {
            "OPENAI_API_KEY": "\u003ckey\u003e",
            "OPENAI_BASE_URL": "\u003cendpoint\u003e",
            "OPENAI_MODEL": "\u003cmodel\u003e",
            "QWEN_USAGE_STATISTICS_ENABLED": "false"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/qwen-code"
      },
      "notable": [
        "The default approval mode is `auto`, where an LLM classifier approves or blocks each tool call (https://qwenlm.github.io/qwen-code-docs/en/users/configuration/settings/)",
        "Usage statistics are on by default (`privacy.usageStatisticsEnabled`). The docs say they hold tool names, model names and timings, never prompts, responses or file contents (https://qwenlm.github.io/qwen-code-docs/en/users/configuration/settings/)",
        "The Qwen OAuth free tier was discontinued on 15 April 2026 (https://qwenlm.github.io/qwen-code-docs/en/users/configuration/auth/)",
        "Forked from Google Gemini CLI 0.8.2, and developed independently since Qwen Code 0.1 (https://github.com/QwenLM/qwen-code#acknowledgments)",
        "Folder trust is disabled by default, and sandboxing is opt-in (https://qwenlm.github.io/qwen-code-docs/en/users/configuration/trusted-folders/)"
      ],
      "area": "frameworks",
      "details": [
        {
          "label": "Interfaces",
          "value": "Terminal CLI, desktop app (macOS, Windows, Linux), `qwen serve` daemon and web UI (experimental), VS Code, Zed and JetBrains, chat channels, SDKs for TypeScript, Python and Java"
        },
        {
          "label": "Install",
          "value": "npm (Node 22 or newer), Homebrew, a standalone install script. Stable, preview and nightly channels"
        },
        {
          "label": "Models",
          "value": "Qwen, OpenAI, Anthropic and Gemini protocols. Alibaba Cloud Model Studio, DeepSeek, OpenRouter and other listed providers, Vertex AI, or a custom or local endpoint"
        },
        {
          "label": "Approval modes",
          "value": "plan (read-only), default (ask), auto-edit, auto (LLM classifier, the settings default) and yolo. `permissions.allow`, `ask` and `deny` rules"
        },
        {
          "label": "Sandbox",
          "value": "Off unless enabled. Linux tool sandbox with Bubblewrap or Landlock and `network` open or closed, macOS Seatbelt (default profile permissive-open allows network), Docker or Podman"
        },
        {
          "label": "Folder trust",
          "value": "Disabled by default (`security.folderTrust.enabled`)"
        },
        {
          "label": "MCP client",
          "value": "stdio, SSE and streamable HTTP, OAuth 2.0, per-server `trust`, `includeTools` and `excludeTools`"
        },
        {
          "label": "Headless",
          "value": "`qwen -p` with text, json or stream-json output, `--continue` and `--resume`, `--json-schema`. Exit codes 41, 42, 44, 52, 53 (turn limit), 55 (budget) and 130"
        },
        {
          "label": "Run budgets",
          "value": "`--max-session-turns`, `--max-wall-time` and `--max-tool-calls`, each unlimited by default"
        },
        {
          "label": "Telemetry",
          "value": "Usage statistics on by default, off with `privacy.usageStatisticsEnabled` or `QWEN_USAGE_STATISTICS_ENABLED`. OpenTelemetry off by default, with prompts logged by default once on"
        },
        {
          "label": "CI",
          "value": "GitHub Action qwen-code-action"
        },
        {
          "label": "Releases in 90 days",
          "value": "39 stable (10 July to 8 October 2026)"
        }
      ],
      "provenance": {
        "legalEntity": "Qwen team, Alibaba Group (no legal entity is named in the repository or the docs)",
        "domain": "qwenlm.github.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "https://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/",
        "privacy": "https://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/",
        "statusPage": "",
        "changelog": "https://github.com/QwenLM/qwen-code/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The project's own Terms of Service and Privacy Notice is one page. It covers usage statistics and the Chrome extension, and maps each sign-in method to the model provider's terms and privacy policy. The project publishes no separate privacy policy for the CLI, so both fields point at that page.",
          "The LICENSE file carries Copyright 2025 Google LLC and Copyright 2025 Qwen. The docs describe the project as Alibaba's, and SECURITY.md sends reports to an Alibaba Cloud console portal.",
          "The docs are on GitHub Pages. qwen.ai returned its application page for /.well-known/security.txt, so no security.txt was found. alibabacloud.com couldn't be reached from our network on 8 October 2026.",
          "The qwen.ai terms and privacy pages render only with JavaScript and weren't read."
        ],
        "score": 48,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Qwen team, Alibaba Group (no legal entity is named in the repository or the docs)",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "qwenlm.github.io, no registry record we could read",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "no hosted endpoint",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Terms of service",
            "value": "read, states 1 of the 7 things a reader expects",
            "points": 4.9,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 2 of the 8 things a reader expects",
            "points": 5.5,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-10-01",
            "words": 2452,
            "points": 4.9,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated on October 1, 2026",
                "says": "Last updated 2026-10-01"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": false
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": false
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": false
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": false
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": false
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "A user who signs in with their own API key is subject to the terms and privacy policy of the chosen API provider and not to terms of Qwen Code.",
                "quote": "When using your own API key, you are subject to the terms and privacy policies of your chosen API provider, not Qwen Code’s terms."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-10-01",
            "words": 2452,
            "points": 5.5,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated on October 1, 2026",
                "says": "Last updated 2026-10-01"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": false
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": false
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "For each authentication method, different Terms of Service and Privacy Notices may apply depending on the underlying service provider."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": false
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": false
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": false
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": false
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Results from the browser tools may be added to the conversation context and sent to the AI provider configured for the session.",
                "quote": "Qwen Code may include those results in conversation context and transmit them to the AI provider configured for that session."
              },
              {
                "date": "2026-10-08",
                "text": "Any use of data for model training is governed by the policy of the AI provider the user authenticates with.",
                "quote": "Any data usage for training purposes would be governed by the policies of the AI service provider you authenticate with."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/qwen-code.json",
      "live": {
        "slug": "qwen-code",
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/QwenLM/qwen-code/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:23:49.8394153Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0782fd2dec4a"
          },
          {
            "url": "https://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:23:34.139570921Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "11f3bc6ce7da"
          }
        ],
        "updatedAt": "2026-10-08T18:23:49.8394153Z"
      }
    },
    "verify": {
      "accepts": "a page on qwenlm.github.io or one of its subdomains, or the README of github.com/QwenLM/qwen-code",
      "badgeUrl": "https://www.anchorterminal.com/badges/qwen-code.svg",
      "body": {
        "slug": "qwen-code",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/qwen-code",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/qwen-code\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/qwen-code.svg\" alt=\"Qwen Code on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Qwen Code on Anchor Terminal](https://www.anchorterminal.com/badges/qwen-code.svg)](https://www.anchorterminal.com/tools/qwen-code)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/qwen-code\"\u003eQwen Code on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/qwen-code",
    "json": "https://www.anchorterminal.com/tools/qwen-code.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/qwen-code.md",
    "slim": "https://www.anchorterminal.com/tools/qwen-code.min.md"
  },
  "markdown": "## Overview\n\n**Grade BB · 72.4/100 · rank #93 of 722 · #3 in Agent harnesses · agent-ready · confidence medium**\n\n\n## Assessment\n\nApache-2.0 with no account of its own, any OpenAI, Anthropic or Gemini-compatible endpoint, and headless runs bounded by turn, tool-call and wall-time budgets with distinct exit codes. Out of the box, Auto mode lets an LLM classifier approve tool calls, with the sandbox and folder trust both off. Usage statistics are on by default.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Alibaba (Qwen team) (https://qwenlm.github.io/qwen-code-docs/en/users/overview/) |\n| Kind | Agent harness |\n| Category | Agent harnesses (https://www.anchorterminal.com/categories/agent-harnesses) |\n| Auth | API key · No account of its own. A model key goes in an environment variable or `~/.qwen/settings.json`, for Alibaba Cloud Model Studio (Coding Plan, Token Plan or a standard key), a listed third-party provider, or any OpenAI, Anthropic or Gemini-compatible endpoint including a local server. Vertex AI credentials also work. The Qwen OAuth sign-in was discontinued on 15 April 2026. |\n| Pricing | Free (Free · OSS) · Free and Apache-2.0, with nothing to buy for the CLI. The owner pays the model provider, or nothing with a local model. The Qwen OAuth free tier ended on 15 April 2026. Alibaba Cloud sells a fixed-fee Coding Plan and a usage-billed Token Plan for it, and we couldn't load their price pages on 8 October 2026. |\n| x402 | No · No x402, MPP or L402 in the docs or the source (checked 2026-10-08). |\n| Licence | Apache-2.0 |\n| Packages | npm: `@qwen-code/qwen-code`; npm: `@qwen-code/sdk`; pypi: `qwen-code-sdk`; oci: `ghcr.io/qwenlm/qwen-code` |\n| Source | https://github.com/QwenLM/qwen-code |\n| Docs | https://qwenlm.github.io/qwen-code-docs/en/users/overview/ |\n| llms.txt | https://qwenlm.github.io/qwen-code-docs/llms.txt |\n| Last release | 2026-10-05 |\n| GitHub stars | 28,362 (as of 2026-10-08) |\n| npm downloads / week | 104,819 |\n| Interfaces | Terminal CLI, desktop app (macOS, Windows, Linux), `qwen serve` daemon and web UI (experimental), VS Code, Zed and JetBrains, chat channels, SDKs for TypeScript, Python and Java |\n| Install | npm (Node 22 or newer), Homebrew, a standalone install script. Stable, preview and nightly channels |\n| Models | Qwen, OpenAI, Anthropic and Gemini protocols. Alibaba Cloud Model Studio, DeepSeek, OpenRouter and other listed providers, Vertex AI, or a custom or local endpoint |\n| Approval modes | plan (read-only), default (ask), auto-edit, auto (LLM classifier, the settings default) and yolo. `permissions.allow`, `ask` and `deny` rules |\n| Sandbox | Off unless enabled. Linux tool sandbox with Bubblewrap or Landlock and `network` open or closed, macOS Seatbelt (default profile permissive-open allows network), Docker or Podman |\n| Folder trust | Disabled by default (`security.folderTrust.enabled`) |\n| MCP client | stdio, SSE and streamable HTTP, OAuth 2.0, per-server `trust`, `includeTools` and `excludeTools` |\n| Headless | `qwen -p` with text, json or stream-json output, `--continue` and `--resume`, `--json-schema`. Exit codes 41, 42, 44, 52, 53 (turn limit), 55 (budget) and 130 |\n| Run budgets | `--max-session-turns`, `--max-wall-time` and `--max-tool-calls`, each unlimited by default |\n| Telemetry | Usage statistics on by default, off with `privacy.usageStatisticsEnabled` or `QWEN_USAGE_STATISTICS_ENABLED`. OpenTelemetry off by default, with prompts logged by default once on |\n| CI | GitHub Action qwen-code-action |\n| Releases in 90 days | 39 stable (10 July to 8 October 2026) |\n| Capabilities | agent.harness, agent.mcp-client, agent.multi-agent |\n| Tags | official, harness, coding-agent, cli, open-source, typescript, mcp, llms-txt, telemetry-default-on, pre-1.0, free, no-card, local, docker |\n| JSON | https://www.anchorterminal.com/api/v1/tools/qwen-code.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 69 | 13.8 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 91 | 14.8 |\n| Agent ergonomics | 13% | 16.2 | 85 | 13.8 |\n| Security \u0026 auth | 14% | 17.5 | 53 | 9.3 |\n| Payments \u0026 pricing | 10% | 12.5 | 60 | 7.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 88 | 7.7 |\n| Transparency \u0026 trust (editorial 77, provenance 48) | 7% | 8.8 | 63 | 5.5 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **72.4 → BB** |\n\n### Why each score\n\n- Reliability 69: Local-package reading. npm with engines node 22 or newer, Homebrew at 0.25.0 and a standalone installer, with stable, preview and nightly channels (20). Public CI, and of the 15 most recent completed CI runs on main on 8 October, 12 passed, 3 were cancelled and none failed, though two issues opened by automation the same day report a failed end-to-end test and a failed Java SDK job on main (22). 1,402 open issues and 334 open pull requests. The ten newest issues each had labels and one to five comments within the day, much of it from the project's own triage automation (15). The changelog states Keep a Changelog and semver and every release has a Breaking Changes heading, but breaking changes shipped in patch releases 0.23.4 and 0.24.1 (12). 0.25.0, pre-1.0 (0).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 91: Framework reading. A settings.schema.json in the repository, a settings reference with the type and default of each key, and an OpenAPI file for the daemon's REST API (25). llms.txt on the docs site lists the pages with a line each, though it links to HTML and the Markdown path we tried returned 404 (8). The approval-mode page says when to use each mode and the sandbox page what each method and Seatbelt profile allows (15). Approval modes, sandbox backends, filesystem and network policies are enums (13). The headless page documents json and stream-json output, and exit codes 41, 42, 44, 52, 53, 55 and 130 are documented (15). A dated changelog generated from releases (15).\n- Agent ergonomics 85: Framework reading, adapted to a harness driven by a pipeline. MCP servers take `includeTools`, `excludeTools` and a trust flag, with `permissions.allow`, `ask` and `deny` rules and `--exclude-tools` (20). Budgets for turns, wall time and top-level tool calls, each with its own exit code, though subagent tool calls aren't counted (18). Documented exit codes (18). `--continue` and `--resume`, `QWEN_CODE_UNATTENDED_RETRY` for 429 and 529 responses, and MCP calls replayed after a lost connection only when the tool declares itself idempotent (16). A TypeScript SDK on npm at 0.1.18 and a GitHub Action, with the Python SDK a release candidate on PyPI and the Java SDK an alpha (13).\n- Security \u0026 auth 53: Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. Usage statistics are on by default, documented as tool names, model names, timings and configuration without prompts, responses, file contents or personal information, with a setting and an environment variable to turn them off. Credentials are API keys in environment variables or settings.json (15). Five approval modes with a read-only plan mode and allow, ask and deny rules, but the settings default is Auto, where an LLM classifier approves tool calls, folder trust is disabled by default and sandboxing is opt-in (10). A Linux tool sandbox with `network: closed`, `--safe-mode` and a stderr warning for yolo without a sandbox, but the default macOS Seatbelt profile allows network and we found no guidance on prompt injection in the pages read (7). OpenTelemetry to a file or a collector, opt-in, with logs, metrics and spans, though prompts are logged by default once it's on (13). SECURITY.md gives only an Alibaba Cloud console portal with no response time, the repository has no published advisories, no security.txt was found, and CodeQL and scorecard workflows run in CI (8).\n- Payments \u0026 pricing 60: Self-hosted rule. No payment protocol (0). The CLI is free under Apache-2.0 with nothing to buy (20). No card or account is needed for the software, and it runs against a local model server (20). An agent can install and run it with no sign-up, given a model endpoint (20). Alibaba Cloud's Coding Plan and Token Plan are separate purchases, and their price pages couldn't be loaded on 8 October 2026.\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 88: 0.25.0 on 5 October 2026 (30). 39 stable releases since 10 July, plus previews and nightlies (20). Issues are labelled and commented on within a day, largely by automation, against 1,402 open issues and 334 open pull requests (17). A TypeScript SDK released on 5 October, with the Python SDK last published to PyPI as a release candidate on 9 May 2026 and the Java SDK an alpha (11). CI, CodeQL, a monthly scorecard and Dependabot (10).\n- Transparency \u0026 trust 63: Apache-2.0 (30). One terms and privacy page maps each sign-in method to the model provider's terms, says the project doesn't train on prompts or code, and lists what usage statistics hold, but gives no retention period, doesn't name the Alibaba Cloud endpoint the statistics go to, and names no legal entity (18). The end of the Qwen OAuth free tier is dated 15 April 2026 and `tools.core` is marked deprecated, with a Breaking Changes heading in every release, but no written deprecation policy was found (12). Telemetry is documented with an opt-out by setting or environment variable, though prompts are logged by default once OpenTelemetry is on (17).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/qwen-code.md (JSON https://www.anchorterminal.com/fixes/qwen-code.json)\n\n### What we couldn't check\n\n- unchecked: Alibaba Cloud Coding Plan and Token Plan prices and quotas. alibabacloud.com and help.aliyun.com couldn't be reached from our network on 8 October 2026\n- unchecked: the Qwen terms of service and privacy policy at qwen.ai, which render only with JavaScript\n- unchecked: security.txt on alibabacloud.com, and the registration date of any vendor domain\n- unchecked: how many of the 1,402 open issues are bugs, and how old the oldest are. GitHub's search API refused us for its rate limit\n- The settings reference gives `auto` as the default approval mode, while the approval-mode page says headless runs default to Ask Permissions. We didn't run it to see which holds\n- The docs don't name where usage statistics go. The source sends them to gb4w8c3ygj-default-sea.rum.aliyuncs.com\n- Whether the Java SDK is published to Maven Central wasn't checked\n- The lead was right on licence, stars (28,362), headless `qwen -p` and MCP. Its docs link was the repository, and the docs site is qwenlm.github.io/qwen-code-docs\n\n### Sources\n\n- repository, README, SECURITY.md, CHANGELOG.md, docs and workflows (git clone at 29aef7d): \u003chttps://github.com/QwenLM/qwen-code\u003e (seen 2026-10-08)\n- changelog with release dates and Breaking Changes headings: \u003chttps://github.com/QwenLM/qwen-code/blob/main/CHANGELOG.md\u003e (seen 2026-10-08)\n- npm registry, versions and dates, engines: \u003chttps://registry.npmjs.org/@qwen-code/qwen-code\u003e (seen 2026-10-08)\n- npm weekly downloads: \u003chttps://api.npmjs.org/downloads/point/last-week/@qwen-code/qwen-code\u003e (seen 2026-10-08)\n- stars, licence and CI runs on main (GitHub API): \u003chttps://api.github.com/repos/QwenLM/qwen-code/actions/workflows/ci.yml/runs?branch=main\u003e (seen 2026-10-08)\n- open issues and pull requests: \u003chttps://github.com/QwenLM/qwen-code/issues\u003e (seen 2026-10-08)\n- repository advisories (none published): \u003chttps://github.com/QwenLM/qwen-code/security/advisories\u003e (seen 2026-10-08)\n- settings reference (approval mode default, usage statistics, MCP keys): \u003chttps://qwenlm.github.io/qwen-code-docs/en/users/configuration/settings/\u003e (seen 2026-10-08)\n- headless mode, output formats and run budgets: \u003chttps://qwenlm.github.io/qwen-code-docs/en/users/features/headless/\u003e (seen 2026-10-08)\n- approval modes: \u003chttps://qwenlm.github.io/qwen-code-docs/en/users/features/approval-mode/\u003e (seen 2026-10-08)\n- sandboxing: \u003chttps://qwenlm.github.io/qwen-code-docs/en/users/features/sandbox/\u003e (seen 2026-10-08)\n- trusted folders: \u003chttps://qwenlm.github.io/qwen-code-docs/en/users/configuration/trusted-folders/\u003e (seen 2026-10-08)\n- authentication and the end of the Qwen OAuth free tier: \u003chttps://qwenlm.github.io/qwen-code-docs/en/users/configuration/auth/\u003e (seen 2026-10-08)\n- terms of service and privacy notice: \u003chttps://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/\u003e (seen 2026-10-08)\n- exit codes: \u003chttps://qwenlm.github.io/qwen-code-docs/en/users/support/troubleshooting/\u003e (seen 2026-10-08)\n- OpenTelemetry settings: \u003chttps://github.com/QwenLM/qwen-code/blob/main/docs/developers/development/telemetry.md\u003e (seen 2026-10-08)\n- usage statistics endpoint in source: \u003chttps://github.com/QwenLM/qwen-code/blob/main/packages/core/src/telemetry/qwen-logger/qwen-logger.ts\u003e (seen 2026-10-08)\n- llms.txt: \u003chttps://qwenlm.github.io/qwen-code-docs/llms.txt\u003e (seen 2026-10-08)\n- Homebrew formula at 0.25.0: \u003chttps://formulae.brew.sh/api/formula/qwen-code.json\u003e (seen 2026-10-08)\n- Python SDK on PyPI (0.1.0rc0): \u003chttps://pypi.org/pypi/qwen-code-sdk/json\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 48/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Qwen team, Alibaba Group (no legal entity is named in the repository or the docs) | 20/20 |\n| Domain age | qwenlm.github.io, no registry record we could read | 0/15 |\n| Endpoint on the vendor's domain | no hosted endpoint | n/a |\n| Terms of service | read, states 1 of the 7 things a reader expects | 4.9/10 |\n| Privacy policy | read, states 2 of the 8 things a reader expects | 5.5/10 |\n| Status page | not found | 0/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe project's own Terms of Service and Privacy Notice is one page. It covers usage statistics and the Chrome extension, and maps each sign-in method to the model provider's terms and privacy policy. The project publishes no separate privacy policy for the CLI, so both fields point at that page.\n\nThe LICENSE file carries Copyright 2025 Google LLC and Copyright 2025 Qwen. The docs describe the project as Alibaba's, and SECURITY.md sends reports to an Alibaba Cloud console portal.\n\nThe docs are on GitHub Pages. qwen.ai returned its application page for /.well-known/security.txt, so no security.txt was found. alibabacloud.com couldn't be reached from our network on 8 October 2026.\n\nThe qwen.ai terms and privacy pages render only with JavaScript and weren't read.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/), read 2026-10-08, dated 2026-10-01, states 1 of the 7 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2026-10-01.\n- Not found in the text. Names the governing law or courts.\n- Not found in the text. States a limit on its liability.\n- Not found in the text. Says how the agreement or account can be ended.\n- Not found in the text. Says how changes to the terms are announced.\n- Not found in the text. Lists what users may not do.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). A user who signs in with their own API key is subject to the terms and privacy policy of the chosen API provider and not to terms of Qwen Code. \"When using your own API key, you are subject to the terms and privacy policies of your chosen API provider, not Qwen Code’s terms.\"\n\n**Privacy policy** (https://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/), read 2026-10-08, dated 2026-10-01, states 2 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2026-10-01.\n- Not found in the text. Says what personal data is collected.\n- Not found in the text. Says how long data is kept.\n- Not found in the text. Says whether personal data is sold or shared for advertising.\n- Not found in the text. Says what rights people have over their data.\n- Not found in the text. Gives a privacy contact.\n- Not found in the text. Says where data is transferred or stored.\n- Also in the text (2026-10-08). Results from the browser tools may be added to the conversation context and sent to the AI provider configured for the session. \"Qwen Code may include those results in conversation context and transmit them to the AI provider configured for that session.\"\n- Also in the text (2026-10-08). Any use of data for model training is governed by the policy of the AI provider the user authenticates with. \"Any data usage for training purposes would be governed by the policies of the AI service provider you authenticate with.\"\n\n## Live (updated 2026-10-08 18:23 UTC)\n\n- Watching changelog \u003chttps://raw.githubusercontent.com/QwenLM/qwen-code/main/CHANGELOG.md\u003e\n- Watching terms \u003chttps://qwenlm.github.io/qwen-code-docs/en/users/support/tos-privacy/\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/qwen-code.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Apache-2.0, with CI on main showing 12 passes and 3 cancelled runs in the last 15, none failed\n- Headless `qwen -p` with json and stream-json output, and exit codes 53 for the turn limit and 55 for a wall-time or tool-call budget\n- Works with any OpenAI, Anthropic or Gemini-compatible endpoint, including a local server, with keys set by environment variable\n- 39 stable releases in the 90 days to 8 October 2026, each with a Breaking Changes heading in a generated changelog\n- A Linux tool sandbox (Bubblewrap or Landlock) with `network: closed`, plus Seatbelt, Docker and Podman\n\n## Weaknesses\n\n- The default approval mode is Auto, where an LLM classifier approves tool calls, and sandboxing and folder trust are both off by default\n- Usage statistics are on by default and go to an Alibaba Cloud endpoint that the docs don't name\n- SECURITY.md points only to an Alibaba Cloud console portal, with no response time, and the repository has no published advisories\n- Pre-1.0 at 0.25.0, with breaking changes shipped in patch releases such as 0.23.4 and 0.24.1\n- 1,402 open issues and 334 open pull requests on 8 October 2026\n- The Qwen OAuth free tier ended on 15 April 2026, so every run needs a paid key or a local model\n\n## Before you call it (notes for agents)\n\n1. Pass `--approval-mode` on every run. The settings default is `auto`, and one docs page says headless runs default to asking, so don't rely on either\n2. Add `--max-session-turns`, `--max-wall-time` and `--max-tool-calls`. All three are unlimited by default. Exit 53 is the turn limit and 55 a budget\n3. `--yolo` doesn't turn on a sandbox. Add `--sandbox`, or on Linux set `tools.executionSandbox` with `network` set to `closed`\n4. Set `QWEN_USAGE_STATISTICS_ENABLED=false` to stop usage statistics\n5. Authenticate with `OPENAI_API_KEY`, `OPENAI_BASE_URL` and `OPENAI_MODEL` in CI. The browser sign-in is discontinued\n\n## Connect\n\nInstall:\n\n```bash\nnpm install -g @qwen-code/qwen-code@latest   # or: brew install qwen-code\n```\n\nHeadless / CI:\n\n```json\n{\n  \"command\": \"qwen -p \\\"$TASK\\\" --output-format json --approval-mode auto-edit --max-session-turns 30 --max-wall-time 10m\",\n  \"env\": {\n    \"OPENAI_API_KEY\": \"\\u003ckey\\u003e\",\n    \"OPENAI_BASE_URL\": \"\\u003cendpoint\\u003e\",\n    \"OPENAI_MODEL\": \"\\u003cmodel\\u003e\",\n    \"QWEN_USAGE_STATISTICS_ENABLED\": \"false\"\n  }\n}\n```\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| goose | BB | 73.9 | 72 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/goose.md |\n| Gemini CLI | BB | 72 | 99 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/gemini-cli.md |\n| OpenHands | BB | 70.8 | 126 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/openhands.md |\n| OpenCode | B | 67.7 | 200 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/opencode.md |\n| Claude Code | C | 61.9 | 354 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/claude-code.md |\n| Prime Agent | C | 60.5 | 399 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/prime-agent.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The default approval mode is `auto`, where an LLM classifier approves or blocks each tool call (source: \u003chttps://qwenlm.github.io/qwen-code-docs/en/users/configuration/settings/\u003e)\n- Usage statistics are on by default (`privacy.usageStatisticsEnabled`). The docs say they hold tool names, model names and timings, never prompts, responses or file contents (source: \u003chttps://qwenlm.github.io/qwen-code-docs/en/users/configuration/settings/\u003e)\n- The Qwen OAuth free tier was discontinued on 15 April 2026 (source: \u003chttps://qwenlm.github.io/qwen-code-docs/en/users/configuration/auth/\u003e)\n- Forked from Google Gemini CLI 0.8.2, and developed independently since Qwen Code 0.1 (source: \u003chttps://github.com/QwenLM/qwen-code#acknowledgments\u003e)\n- Folder trust is disabled by default, and sandboxing is opt-in (source: \u003chttps://qwenlm.github.io/qwen-code-docs/en/users/configuration/trusted-folders/\u003e)\n\n## Compare\n\n- [Aider vs Qwen Code](https://www.anchorterminal.com/compare/aider-vs-qwen-code.md): D 46.9 vs BB 72.4\n- [Amp vs Qwen Code](https://www.anchorterminal.com/compare/amp-vs-qwen-code.md): C 57.1 vs BB 72.4\n- [Claude Code vs Qwen Code](https://www.anchorterminal.com/compare/claude-code-vs-qwen-code.md): C 61.9 vs BB 72.4\n- [Cline vs Qwen Code](https://www.anchorterminal.com/compare/cline-vs-qwen-code.md): C 60.4 vs BB 72.4\n- [Cursor CLI vs Qwen Code](https://www.anchorterminal.com/compare/cursor-cli-vs-qwen-code.md): F 35.3 vs BB 72.4\n- [Devin vs Qwen Code](https://www.anchorterminal.com/compare/devin-vs-qwen-code.md): C 55.7 vs BB 72.4\n- [Pi vs Qwen Code](https://www.anchorterminal.com/compare/earendil-pi-vs-qwen-code.md): B 68.4 vs BB 72.4\n- [Gemini CLI vs Qwen Code](https://www.anchorterminal.com/compare/gemini-cli-vs-qwen-code.md): BB 72 vs BB 72.4\n- [GitHub Copilot CLI vs Qwen Code](https://www.anchorterminal.com/compare/github-copilot-cli-vs-qwen-code.md): C 57.6 vs BB 72.4\n- [goose vs Qwen Code](https://www.anchorterminal.com/compare/goose-vs-qwen-code.md): BB 73.9 vs BB 72.4\n- [Kiro CLI vs Qwen Code](https://www.anchorterminal.com/compare/kiro-cli-vs-qwen-code.md): C 59.9 vs BB 72.4\n- [OpenAI Codex vs Qwen Code](https://www.anchorterminal.com/compare/openai-codex-vs-qwen-code.md): BB 73 vs BB 72.4\n- [OpenCode vs Qwen Code](https://www.anchorterminal.com/compare/opencode-vs-qwen-code.md): B 67.7 vs BB 72.4\n- [OpenHands vs Qwen Code](https://www.anchorterminal.com/compare/openhands-vs-qwen-code.md): BB 70.8 vs BB 72.4\n- [Prime Agent vs Qwen Code](https://www.anchorterminal.com/compare/prime-agent-vs-qwen-code.md): C 60.5 vs BB 72.4\n- [Paperclip vs Qwen Code](https://www.anchorterminal.com/compare/paperclip-vs-qwen-code.md): C 59 vs BB 72.4\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on qwenlm.github.io or one of its subdomains, or the README of github.com/QwenLM/qwen-code. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"qwen-code\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/qwen-code\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/qwen-code.svg\" alt=\"Qwen Code on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Qwen Code on Anchor Terminal](https://www.anchorterminal.com/badges/qwen-code.svg)](https://www.anchorterminal.com/tools/qwen-code)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/qwen-code\"\u003eQwen Code on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Qwen Code is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/qwen-code-dark.png\n- Light: https://www.anchorterminal.com/assets/share/qwen-code-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Agent harnesses",
        "url": "https://www.anchorterminal.com/categories/agent-harnesses"
      },
      {
        "name": "Qwen Code",
        "url": ""
      }
    ],
    "description": "Open-source coding agent from Alibaba's Qwen team for the terminal, with desktop, browser and editor interfaces. It runs Qwen, OpenAI, Anthropic and Gemini-compatible models or a local one, and runs headless with qwen -p.",
    "facts": [
      "rank #93 of 722",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "Qwen Code",
    "image": "https://www.anchorterminal.com/assets/og/tools-qwen-code.png",
    "path": "/tools/qwen-code",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Qwen Code review for AI agents, grade BB (72.4/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/qwen-code"
  },
  "tokens": {
    "markdown": 6850,
    "slim": 1430
  },
  "version": 1
}
