Terminal coding agents compared
Claude Code, Codex CLI, Gemini CLI, GitHub Copilot CLI, OpenCode, Cline, goose and Aider compared on license, model access, instruction files, sandboxing, headless mode, MCP and Agent Skills support.
Comparison
| Entry | License | Models and access | Instruction files | Sandbox and approvals | Headless mode | MCP | Agent Skills | Latest release |
|---|---|---|---|---|---|---|---|---|
| Claude Code | Proprietary (Anthropic Commercial Terms) | Claude models; needs a Pro, Max, Team, Enterprise or Console account (not the free plan), or Bedrock, Google Cloud or Microsoft providers | CLAUDE.md; also reads AGENTS.md; auto memory | Permission modes plus an OS-enforced Bash sandbox (macOS, Linux, WSL2), off by default; sandboxed network goes through a domain allowlist proxy | claude -p, plus the Agent SDK for Python and TypeScript | Yes (stdio and HTTP; remote OAuth) | Yes | v2.1.287 (2026-10-01) |
| OpenAI Codex CLI | Apache-2.0 | OpenAI models; sign in with ChatGPT (Free, Go, Plus, Pro, Business, Edu, Enterprise) or use an API key | AGENTS.md | Sandbox on by default (Seatbelt on macOS, bubblewrap on Linux/WSL2); modes read-only, workspace-write (default), danger-full-access; approvals on-request or never, optional auto-review agent | codex exec | Yes, as a client. The codex mcp-server command was removed; integrations use the app server | Yes (custom prompts deprecated in favor of skills) | rust-v0.160.0 (2026-10-01) |
| Gemini CLI | Apache-2.0 | Gemini models; free tier with a personal Google account (60 requests/min, 1,000/day), API key or Vertex AI | GEMINI.md by default; context file name configurable (e.g. AGENTS.md) | Opt-in sandbox (-s or GEMINI_SANDBOX): macOS Seatbelt, Docker, Podman, gVisor (runsc) or LXC | gemini -p | Yes | Yes, enabled by default | v0.62.0 (2026-09-29) |
| GitHub Copilot CLI | Proprietary (GitHub Copilot CLI License; redistribution of unmodified copies allowed) | Several models selectable with /model; needs an active Copilot subscription; usage consumes AI credits by tokens | AGENTS.md, .github/copilot-instructions.md, CLAUDE.md, GEMINI.md and *.instructions.md, all combined | Tool approvals (--allow-tool); local sandbox via /sandbox enable and cloud sandboxes, both public preview | copilot -p | Yes; ships with GitHub's MCP server by default | Yes | v1.0.91 (2026-10-01) |
| OpenCode | MIT | 75+ providers via the AI SDK and Models.dev, plus local models; bring your own keys | AGENTS.md (project and global); falls back to CLAUDE.md and reads .claude/skills | Per-tool allow, ask or deny rules, with a read-only plan agent and an --auto mode; no OS sandbox documented in the sources used | opencode run, and opencode serve for a headless server | Yes | Yes | v1.18.34 (2026-09-30); site announces OpenCode v2 |
| Cline | Apache-2.0 (JetBrains plugin not open source) | Many providers (Anthropic, OpenAI, Bedrock, Gemini, OpenRouter, local), Claude Code or Codex subscriptions, or Cline's own usage billing | .clinerules/ or .cline/rules/, AGENTS.md, .cursorrules, .windsurfrules | Plan and Act modes; the CLI starts in act mode with auto-approve on by default; CLINE_SANDBOX env var enables a sandbox mode | cline "prompt" with --json output; also an SDK | Yes | Yes | Monorepo with per-app releases (desktop-v0.0.42 on 2026-10-02) |
| goose | Apache-2.0 per the GitHub repo (the docs' llms.txt says MIT) | 15+ providers (Anthropic, OpenAI, Google, Ollama, OpenRouter, Azure, Bedrock), or existing Claude, ChatGPT or Gemini subscriptions via ACP | .goosehints (docs also mention AGENT.md) | Not compared; check goose's permission docs | goose run (instructions file or recipe) | Yes; extensions are MCP servers | Yes (SKILL.md in ~/.agents/skills) | v1.52.0 (2026-09-23) |
| Aider | Apache-2.0 | Almost any LLM, cloud or local; bring your own keys | No fixed file; load e.g. CONVENTIONS.md with /read or read: in .aider.conf.yml | No sandbox; edits are auto-committed to git by default (--no-auto-commits to disable) | aider --message or --message-file | Not documented | Not documented | v0.86.0 (2025-08-09) |
Verdict: Pick by model access first: Claude Code for Claude, Codex CLI for a ChatGPT plan, Gemini CLI for a free tier, Copilot CLI if your org already pays for Copilot, and OpenCode, Cline or goose to bring your own provider. For unattended runs, Codex CLI has the strictest out-of-the-box sandbox; Claude Code's and Gemini CLI's are strong but opt-in, and Cline's CLI auto-approves by default. Aider is still useful for git-centric pair programming but has had no release since August 2025.
What actually differs
All eight read your repository, edit files, run shell commands and loop until the task is done. The differences that matter in practice are narrower than the feature lists suggest:
- How you pay for the model. Claude Code, Codex CLI, Gemini CLI and Copilot CLI are each tied to one vendor's account, which usually means a flat subscription instead of per-token bills. OpenCode, Cline, goose and Aider take any provider key, including local models, and several of them can also reuse a Claude, ChatGPT or Gemini subscription.
- What the sandbox does by default. This is the biggest difference for unattended use, and it's covered below.
- Which instruction file it reads. AGENTS.md has become the common denominator: Codex, OpenCode, Cline and Copilot read it directly, Claude Code reads it alongside CLAUDE.md, and Gemini CLI can be configured to. If you maintain one file for several agents, make it AGENTS.md.
- Extensibility. Every tool here except Aider documents MCP support, and all of them except Aider now load Agent Skills (folders with a
SKILL.md), so a skill written once works across most harnesses.
Sandboxing and approvals, read carefully
"Has a sandbox" means very different things:
- Codex CLI sandboxes by default. Commands run under Seatbelt on macOS or bubblewrap on Linux and WSL2 (you install
bubblewrapyourself), inworkspace-writemode: edits inside the workspace, routine commands, and approval when it needs to go further.danger-full-accesswith approval policyneverremoves all limits. - Claude Code combines permission modes with an OS-enforced Bash sandbox built on Anthropic's open-source
sandbox-runtime. It is off by default (/sandboxturns it on). When on, writes are limited to the working directory and network goes through a local proxy with an allowlist that starts empty. Note the documented defaults: sandboxed commands can still read most of the machine, including~/.sshand~/.aws/credentials, until you adddenyReador credential rules, and file tools, MCP servers and hooks run outside the sandbox. Native Windows runs commands unsandboxed; use WSL2. - Gemini CLI offers the widest choice of backends (Seatbelt, Docker, Podman, gVisor, LXC) but only when you pass
-sor setGEMINI_SANDBOX. - Copilot CLI relies on tool approvals (
--allow-tool='shell(git)') and added local and cloud sandboxes, both in public preview. - OpenCode uses allow, ask and deny rules per tool and per command pattern, plus a read-only
planagent. No OS-level sandbox was documented in the pages used here. - Cline's CLI starts a prompt in act mode with auto-approve on by default (
--auto-approve falseto change that). Fine inside a container; risky on your workstation. - Aider has no sandbox; its safety net is that every edit is a git commit you can undo.
For unattended runs in CI, or anywhere the agent reads untrusted input such as issues, web pages or dependencies, run the harness itself inside a disposable environment. The sandboxing guide and code sandboxes comparison cover the options.
Recent changes worth knowing
- Codex CLI removed
codex mcp-serverand the standalonecodex-mcp-serverbinary; integrations must move to the Codex app server's own JSON-RPC protocol. Theuntrustedapproval policy is retired, custom prompts are deprecated in favor of skills, and the docs moved to learn.chatgpt.com. - Claude Code's npm package is deprecated as an install method; use the native installer, Homebrew or WinGet. Claude Code now reads AGENTS.md.
- Copilot CLI bills by AI credits consumed per token rather than per request, and combines all instruction files instead of picking one by priority.
- goose moved from Block to the Agentic AI Foundation at the Linux Foundation; the repository is now
aaif-goose/goose. - OpenCode's repository is
anomalyco/opencode, and its site announces OpenCode v2. - Aider's last tagged release is v0.86.0 from 2025-08-09, and its README still recommends models from early 2025.
Not in this table
Cursor (an IDE with a CLI), Amp, Kiro, Qwen Code (a Gemini CLI fork for Qwen models) and OpenHands are also strong options, but they weren't re-verified for this page. To set up any of these harnesses with tools, see the coding agent starter stack and the guide to adding MCP servers to Claude Code.
Directory entries in this comparison
- Claude Code: Anthropic's agentic coding tool that reads your codebase, edits files, runs commands and integrates with dev tools; available in terminal, IDE, desktop and browser.
- OpenAI Codex CLI: OpenAI's lightweight open-source coding agent that runs in your terminal.
- Gemini CLI: Open-source AI agent from Google that brings Gemini models directly into your terminal.
- GitHub Copilot CLI: Brings GitHub Copilot's coding agent to your terminal to read, write and run code where you work.
- OpenCode: The open-source AI coding agent, built for the terminal.
- Cline: Open-source autonomous coding agent available as an SDK, IDE extension or CLI, with Plan/Act modes and MCP integration.
- goose: Open-source, extensible AI agent (desktop app, CLI and API) that can install, execute, edit and test with any LLM.
- Aider: Open-source AI pair programming in your terminal.
- AGENTS.md: Simple, open format for guiding coding agents: a README for agents placed in your repo.
- Agent Skills Specification: Open format for packaging agent capabilities as folders with a SKILL.md (YAML frontmatter + instructions) plus optional scripts and resources.
- Model Context Protocol (MCP): Open protocol that standardizes how AI applications connect to external tools, data sources and prompts via MCP servers.
- Cursor: AI code editor and coding agent with Agent mode, Rules, Skills, MCP servers and a CLI.
- Amp: Coding agent and development environment; run agents unsupervised in cloud orbs or locally with the CLI.
- Kiro: Agentic engineering environment that turns prompts into executable specs and builds across large codebases with parallel agents.
- Qwen Code: Open-source AI coding agent for the terminal from the Qwen team.
- OpenHands: Open-source, model-agnostic platform for cloud coding agents.
Related
- Coding agent starter stack (Stack)
- Add MCP servers to Claude Code (Guide)
- Connect an agent to a remote MCP server (Guide)
- Run agent-generated code safely in a sandbox (Guide)
Sources
- Claude Code docs, Set up Claude Code, accessed
- Claude Code docs, Configure the sandboxed Bash tool, accessed
- Claude Code docs, Memory (CLAUDE.md and AGENTS.md), accessed
- Claude Code docs, Run Claude Code programmatically, accessed
- anthropics/claude-code repository and LICENSE, accessed
- openai/codex repository, accessed
- Codex docs, Sandbox, accessed
- Codex docs, Codex MCP server removal, accessed
- Codex docs, Pricing, accessed
- Codex docs index (llms.txt), accessed
- google-gemini/gemini-cli repository, accessed
- Gemini CLI docs, Sandboxing, accessed
- GitHub Docs, About GitHub Copilot CLI, accessed
- GitHub Docs, Adding custom instructions for Copilot CLI, accessed
- github/copilot-cli repository, accessed
- OpenCode docs, Rules, accessed
- OpenCode docs, Providers, accessed
- OpenCode docs, Permissions, accessed
- OpenCode docs, CLI, accessed
- cline/cline repository, accessed
- Cline docs, Cline Rules, accessed
- Cline docs, CLI reference, accessed
- aaif-goose/goose repository, accessed
- goose docs, Using skills, accessed
- goose docs, CLI commands, accessed
- Aider-AI/aider repository, accessed
- Aider docs, Specifying coding conventions, accessed
- Aider docs, Options reference, accessed