The 7 best open source AI coding agents for the terminal
Seven open source AI coding agents that run in your terminal, compared on model choice, sandboxing, cost control and data handling. Updated for 2026.
- Comparison
- Open source
- CLI
What actually makes a coding agent different from a chat window
A chat window sends your text to a model and renders the reply. A coding agent has a tool loop: it reads files, runs commands, inspects the results, and iterates until the task is done. That loop is the product, and it is where the design decisions that matter live.
Four properties decide whether that loop is trustworthy in a real repository:
- Blast radius. What is the agent allowed to do without asking? Everything else is a prompt, and prompts are advisory.
- Reversibility. Can you get back to the state before a bad turn? Undo that spans turns is not a feature you need until the first time an agent rewrites four files you did not ask it to touch.
- Legibility. Can you read what it did and why, after the fact, without re-running it?
- Cost. Tokens spent on a solved bug and tokens spent on a spiral are billed identically unless the tool tells you otherwise.
We built Sentinel around exactly those four, which is why this list is weighted the way it is. It is not a neutral ranking, and we would rather say so than pretend otherwise.
The shortlist
Seven projects that are genuinely open source and genuinely useful in a terminal. Grouped by the job they are built for, because the categories rarely compete head to head.
| Project | Category | Where code runs | Model choice |
|---|---|---|---|
| Sentinel | Terminal agent + harness | Your machine, in-process | 12 providers, local models included |
| Aider | Git-native pair programmer | Your machine | Bring your own key, many providers |
| Goose | Extensible agent with toolkits | Your machine | Provider-based, local supported |
| OpenHands | Full autonomous software agent | Your machine or a container | Provider-based |
| Gemini CLI | Google's terminal assistant | Your machine | Gemini first, extensible |
| OpenCode | Terminal agent, TUI-first | Your machine | Provider-based |
| Crush | Terminal agent with LSP awareness | Your machine | Provider-based |
Categories and licence terms move over time, check each project's own README before you rely on this table for a procurement decision.
How to choose: four questions, in order
1. Where does my code go?
This is the first question because it is the only one you cannot undo. Even a fully open source agent is just a local client to a hosted model: your prompt, the file contents it read, and its tool output are sent to that provider.
If that is unacceptable, you are not shopping for a different agent, you are shopping for a different model. Run Ollama or LM Studio locally and the answer becomes “nowhere”. We wrote a guide to running a coding agent entirely offline.
2. What can it touch without asking?
A single “allow bash for this session” grant covers both git status and npm publish. One grant for both is either uselessly strict or uselessly loose, and most tools pick the second because it demos better.
Look for three specific things:
- Per-mode allowlists, not a global toggle. A read-only review mode that cannot write is worth more than a “sandbox” you cannot verify.
- Risk grading by command shape.
git commit -m "a"andgit commit -m "b"are one shape;git push --forceis a different one and must never be collapsed into a placeholder. - Higher friction on expensive paths: migrations, CI workflows, lockfiles, auth, billing, infrastructure. One extra prompt on those globs costs a second. Missing real billing code costs the incident.
3. Can I get back to where I was?
Every write should be checkpointed, and undo must work across turns, because the turn that breaks something is rarely the turn that looks like it did. An agent that only lets you revert the current turn is asking you to trust it in exactly the situation where you do not.
4. What did that turn cost?
If a tool cannot tell you what a turn spent, you cannot budget it, and if you cannot budget it you will not use it on the large tasks where an agent is most valuable. Print tokens and USD per turn, and make the free tier the default so the safe choice is also the cheap one.
A five-minute path to running one locally
Sentinel needs Node 20+, one API key (or a local model), and no build step. Groq's free tier is the default, so the cost floor is genuinely zero.
git clone https://github.com/KunjShah95/SENTINEL-CLI.git
cd SENTINEL-CLI
npm install
npm link
export GROQ_API_KEY=gsk_...
sentinelThen check the guard rails are real before you trust them with anything:
# what is approved in this repo?
sentinel risk
# how would this grade here?
sentinel risk "npm publish"Full setup, including every provider key and the local-model path, is in the installation guide.
What we chose, and what we left out
We left out every tool that needs a hosted account to be useful, because “runs on my machine” and “requires a vendor round trip to do anything” are not compatible claims. We also left out plugins and dashboards, which is a real limitation: if you want a managed platform with SSO and audit logs, Sentinel is the wrong product and we would rather you find that out in two minutes than in a procurement cycle.
What is left is one loop you can read in one sitting, under a thousand lines in src/agent/loop.js: plus the unglamorous controls around it: modes, checkpoints, budgets, a risk ledger, and a handoff document. The agent permission model is the deepest write-up we have.
Frequently asked questions
What is an open source AI coding agent?
An open source AI coding agent is a program, published under a licence that lets you read and modify its source, that can read and edit files in a real codebase on your own machine using an LLM. Open source matters for three concrete reasons: you can audit what the tool is allowed to do with your files, you are not locked to one vendor's pricing or model lineup, and if the project is abandoned you still own the code path it left behind.
Is a terminal coding agent better than an IDE extension?
It depends on where your attention already is. IDE extensions win when you want inline diffs and autocompletion inside the editor you live in. Terminal agents win for whole-repo work, scripted and headless runs, and any workflow you drive over SSH. Most senior engineers end up using both, which is why interoperability (MCP, plain-text session files) matters more than either side winning outright.
Do open source coding agents send my code to a third party?
The agent binary is local, but the model call is not. When you point an agent at a hosted model, your prompt, the files it read and its tool output are sent to that provider. Offline operation is only real when you run a local model such as Ollama or LM Studio. Check the provider's data-retention terms if your code cannot leave your infrastructure.
What should I look for in an open source coding agent?
Five things, in order: where the code runs, which model it can talk to, what the tool allowlist permits in each mode, whether writes are reversible, and whether you can see the token cost of every turn. A tool that cannot show you what a turn cost will quietly become the most expensive line item in your stack.
Written by Kunj Shah
Sentinel is an open source AI coding agent for the terminal, MIT licensed, no servers, no telemetry. Read the source or install it.