OpenCode
Open-source terminal-first AI coding agent — #1 by GitHub stars (~178K+) and the fastest-adopted developer tool in history, now ~8M monthly active users (up from 7.5M). ~$25M ARR projection disclosed.
Dimension breakdown
Score · confidenceOpen-source terminal-first AI coding agent — #1 by GitHub stars (~178K+) and the fastest-adopted developer tool in history, now ~8M monthly active users (up from 7.5M). ~$25M ARR projection disclosed. Model-agnostic (75+ providers); "infrastructure, not a model" — reliability tracks the chosen model.
Native background subagents matured; Build/Plan modes and autonomous GitHub Actions / GitLab CI PR review. MIT licensed, local-first, zero-retention default (provider 30-day retention applies for OpenAI/Anthropic).
Enterprise tier offers SSO + internal AI gateway + new Black ($200) gateway; SSO/audit available via central config or third-party gateways (LiteLLM), not native.
Anthropic legally forced removal of Claude OAuth auth (Feb-Mar 2026) — provider-dependency risk despite BYOK; OpenAI's official Codex-subscription partnership offsets.
Two prior RCE CVEs (CVE-2026-22812 CVSS 8.8, CVE-2026-22813 CVSS 9.4) both patched early 2026 — historical. No SOC 2/ISO/RBAC/SCIM/admin console/native audit trail; ongoing auto-compaction context-loss issues.
Enterprise governance gap persists.
Use cases
Not yet assessed — this section fills in as ACES research covers the tool.
Risk flags
No enterprise features
enterpriseConditionalNo enterprise customers/features
Caps all dimensions at 70
Removed when — Enterprise tier launched with SSO, audit logs, or compliance certification
Status rationale
Assessed — OpenCode demonstrates world-class community traction (160K+ stars, 900 contributors, 7.5M+ monthly developers, 13K+ commits, #1 AI coding agent by stars) with mature native background subagents and hourly release cadence. Enterprise tier improving (SSO + AI gateway + Black gateway confirmed) but SSO/audit are central-config/third-party-gateway dependent, not native; no SOC 2/ISO, no RBAC/SCIM/admin console, no native audit trail — no-enterprise-features cap continues to apply.
Two prior RCE CVEs patched (early 2026); security history weighs on enterprise readiness. Anthropic legal action remains a provider-dependency risk (OpenAI Codex-subscription partnership partially offsets).
Ongoing auto-compaction context-loss issues bound the Context dimension.
Movement triggers
Upgrade if: SOC 2 certification achieved, self-hosted enterprise deployment ships, RBAC and centralized admin added, F500 customer publicly confirmed with case study, background subagents exit experimental status with independent reliability data. Downgrade if: new critical security vulnerability disclosed, Anthropic legal escalation disrupts Claude model access, development stalls, enterprise features stagnant 6+ months, funding crunch signal emerges.
Risks & limitations
No Enterprise Features
ModerateRadar cap: no-enterprise-features
Integration surface
Not yet assessed — this section fills in as ACES research covers the tool.
Adoption & benchmarks
Not yet assessed — this section fills in as ACES research covers the tool.
Spotted something wrong or missing here? Suggest a change →
Per-source contributions
Click any dimension to see the underlying sources and citations.
More in this category