Hermes Agent vs Claude Code vs OpenCode is a choice between three ways to wrap a model in a working loop. Claude Code is Anthropic's proprietary agent for repositories and runs only Claude models. OpenCode is an MIT-licensed terminal agent that works with more than 75 providers and local servers. Hermes Agent is an MIT-licensed personal agent from Nous Research that lives in chat apps and learns reusable skills.
All three are agent harnesses: a control loop, tools, context management and permission rules around a language model. Our explainer on what an agent harness is covers the category. This comparison adds OpenClaw, because “OpenClaw vs Claude Code” is one of the most common searches in this space, and it leaves the two open-source personal agents’ head-to-head to our separate Hermes and OpenClaw comparison.
Every licence, default and price below comes from the projects’ own repositories, documentation and pricing pages, checked on 6 October 2026. These tools ship new releases weekly or faster, so re-check any default before you rely on it.
Quick picks
| If you need | Start with | Why |
|---|---|---|
| An agent that works inside a repository on Claude models | Claude Code | Terminal, IDE, desktop and web surfaces; Claude models only |
| The same style of workflow with any model, including local ones | OpenCode | MIT licence, 75+ providers, documented Ollama, LM Studio and llama.cpp setups |
| A personal assistant you message from Telegram, Slack or Signal | Hermes Agent | Messaging gateway, skills it writes from experience, seven places to run commands |
| The widest choice of chat channels and companion apps | OpenClaw | 20+ channels and native apps on five platforms |
| Administrator-enforced policy on developer machines | Claude Code | Managed settings that local configuration cannot override |
| No vendor subscription at all | OpenCode, Hermes Agent or OpenClaw | All three are free to self-host; you pay only for models and hardware |
The four harnesses at a glance
| Hermes Agent | Claude Code | OpenCode | OpenClaw | |
|---|---|---|---|---|
| Maker | Nous Research | Anthropic | Anomaly | OpenClaw Foundation |
| Licence | MIT | Proprietary; Anthropic’s commercial or consumer terms | MIT | MIT |
| Where you use it | CLI, plus one gateway process for Telegram, Discord, Slack, WhatsApp and Signal | Terminal, VS Code and JetBrains, desktop app, browser | Terminal UI, desktop app, IDE extension | 20+ chat channels, Control UI, native apps |
| Models | Any OpenAI-compatible endpoint, Anthropic, OpenRouter, Nous Portal | Claude models only | 75+ providers through the AI SDK and Models.dev | Hosted and local providers as plugins |
| Local inference | Ollama, vLLM, SGLang, llama-server, LM Studio | Not supported for non-Claude models | Ollama, LM Studio, llama.cpp | Ollama, vLLM, LM Studio, SGLang, llama.cpp |
| Approval default | smart: an auxiliary model screens risky commands on local and SSH backends | Manual mode asks before shell commands, edits and web fetches | Most actions allowed; asks only for outside directories and repeated identical calls | Trusted operator runs host commands without prompts |
| Isolation | Seven terminal backends, including hardened Docker | Built-in OS sandbox for shell commands, off by default | None built in; run it in a container or VM | Tool sandbox, off by default |
| MCP | Client | Client, and claude mcp serve makes it a server | Client, local and remote with OAuth | Client |
| GitHub stars, 6 Oct 2026 | About 252,000 | About 150,000 (public repository) | About 212,000 | About 391,000 |
Latest releases on the same date were Hermes Agent v0.21.5 (24 September) and OpenCode v1.18.34 (30 September).
Hermes Agent vs Claude Code
These two barely overlap. Claude Code’s own overview describes an agent that reads a codebase, edits files, runs commands and works with development tools. It is organised around a project: CLAUDE.md instructions, skills, hooks that run before or after actions, subagents that split a task, and integrations such as GitHub Actions and Slack. You reach it in the terminal, in VS Code or JetBrains, in Anthropic’s desktop app or at claude.ai/code.
Hermes Agent is organised around a person. Its README calls it a self-improving agent with a built-in learning loop that creates skills from experience and improves them during use. You talk to it from a terminal or through a single gateway process that serves Telegram, Discord, Slack, WhatsApp and Signal, and it can execute commands locally, in Docker, over SSH, under Singularity, or in Modal, Daytona or Vercel sandboxes.
Three differences decide most choices:
- Models. Hermes Agent works with any OpenAI-compatible API, Anthropic’s API, OpenRouter and Nous Portal. Claude Code serves Claude models through Anthropic, Amazon Bedrock, Claude Platform on AWS, Google Cloud’s Agent Platform or Microsoft Foundry.
- Who operates it. Hermes Agent is software you install, patch and expose. Claude Code is a product: updates arrive automatically on the native install, and an organisation can push managed settings to every machine.
- Licence. Hermes Agent is MIT. Claude Code is closed source and governed by Anthropic’s terms.
The overlap is growing at the edges. Claude Code’s Channels feature pushes events from Telegram, Discord, iMessage or your own webhooks into a session, and Hermes Agent can use Claude models with an Anthropic API key.
OpenCode vs Claude Code
This is the closest pairing. Both are terminal-first agents for software work with a planning mode, subagents, MCP and an editor integration. OpenCode ships a build agent with full access and a read-only plan agent. Under the hood, running opencode starts a server and a terminal client that talks to it, so IDE plugins and other clients can drive the same session; a standalone opencode serve listens on 127.0.0.1 port 4096, and a password is optional through OPENCODE_SERVER_PASSWORD.
Where they differ:
- Model choice. OpenCode’s provider docs list more than 75 providers plus local servers. Claude Code is the better-integrated choice if your organisation has already standardised on Claude.
- Defaults. OpenCode’s permission docs state that most permissions default to
allow, withdoom_loopandexternal_directoryset toaskand.envfiles denied. Claude Code’s Manual mode asks before shell commands outside a built-in read-only set, before file edits and before web fetches. - Isolation. Claude Code has a built-in sandbox for shell commands. OpenCode’s documentation has no equivalent, so the boundary has to come from a container, VM or remote development environment.
- Central control. Claude Code’s managed settings sit above user and project settings and can disable bypass and auto modes. OpenCode Enterprise offers one central config that can integrate with your SSO provider and restrict requests to an internal AI gateway, and its experimental policies can deny providers.
If the deciding question is where inference runs, our local model shortlist covers which open-weight models handle this kind of agent work and what hardware they need.
OpenClaw vs Claude Code
OpenClaw is a personal assistant first. Its gateway runs on your own device or server and connects WhatsApp, Telegram, Slack, Discord, iMessage, Teams and more than 20 other services to the model you configure, with companion apps for macOS, iOS, Android, Windows and Linux. Claude Code is a software agent first, centred on one repository at a time.
The two are not mutually exclusive. OpenClaw’s Agent Client Protocol (ACP) sessions run external harnesses, and its docs list Claude Code, Cursor, Copilot, OpenCode and Gemini CLI among them. A message in a chat thread can therefore start a session in which one of those tools does the repository work.
The security models differ sharply:
- OpenClaw’s trust model treats each gateway as one trust boundary for a single operator or a mutually trusting team, and recommends a separate gateway per tenant.
- For a trusted operator, host commands run without approval prompts by default (
security="full",ask="off"), and its docs call this intentional. Tool sandboxing with Docker, Podman, SSH or OpenShell is off until you configure it. - Claude Code starts from per-action approval in Manual mode, with an operating-system sandbox you can switch on.
On a regular host install the gateway binds to loopback, and most channels answer an unknown sender with a pairing code. Our OpenClaw security review covers its published advisories and a hardening baseline.
Models, local inference and subscription logins
Local inference is the clearest dividing line. Hermes Agent’s provider docs say it works with any OpenAI-compatible endpoint and name Ollama, vLLM, SGLang, llama-server and LM Studio; they also state that agent use with tools needs at least 64,000 tokens of context. OpenCode documents Ollama at localhost:11434/v1, LM Studio at port 1234 and llama.cpp at port 8080. Step-by-step configuration for the two open-source personal agents is in our local model setup guide.
Claude Code is different by design. Anthropic’s gateway documentation says it does not support routing Claude Code to non-Claude models through any gateway.
Subscription logins are the other trap. Anthropic’s legal and compliance page for Claude Code says OAuth authentication is intended for subscription purchasers using Claude Code and Anthropic’s native apps, and that third-party developers may not route requests through Free, Pro or Max plan credentials on their users’ behalf. The other harnesses reflect that rule:
- OpenCode says Anthropic prohibits it and that its bundled Claude subscription plugins were removed as of version 1.3.0. It supports ChatGPT Plus, GitHub Copilot and GitLab Duo subscriptions instead.
- Hermes Agent documents an OAuth path that only works on a Claude Max plan with purchased extra usage credits, and only those extra credits are consumed. Pro subscribers are directed to an API key.
- Any of them can use Claude through an Anthropic API key or a cloud provider, billed per token.
Permissions and sandboxing compared
| Control | Hermes Agent | Claude Code | OpenCode | OpenClaw |
|---|---|---|---|---|
| Modes | smart (default), manual, off | default (Manual), acceptEdits, plan, auto, dontAsk, bypassPermissions | allow, ask, deny per tool or pattern | Exec approvals and named operator roles |
| Hard floor | A blocklist that YOLO mode cannot override, such as rm -rf / and fork bombs | Protected paths and actions no mode auto-approves | .env reads denied by default | One trust boundary per gateway |
| Who decides in automatic mode | An auxiliary model rates each risky command | A background classifier in auto mode | Nobody: allowed actions just run | The operator’s configuration |
| Container or OS isolation | Docker with all capabilities dropped and selected ones re-added, no-new-privileges, 256-process limit | Seatbelt on macOS, bubblewrap on Linux and WSL2; network through a proxy whose allowed domains start empty | Bring your own | Docker, Podman, SSH or OpenShell sandbox |
| Known gap | Approval checks are skipped on container backends, because the container is treated as the boundary | The sandbox covers shell commands only; file tools, MCP servers and hooks run outside it | Permission rules are configuration, not isolation | Host execution is unprompted for the operator by default |
Two points from this table matter in practice. Claude Code’s sandbox is off by default, and on native Windows commands run unsandboxed unless you use WSL2. And in every harness, an MCP server or plugin runs with whatever access its own process has, so vetting what you install matters as much as the approval mode. Our guide to sandboxing agent code execution covers containers, gVisor and microVMs for teams that need a stronger boundary.
Pricing, verified October 2026
| Software | Paid options (list, verified October 2026) | |
|---|---|---|
| Hermes Agent | Free, MIT | Nous Portal: Plus $20, Super $100, Ultra $200 a month, each including model credits. Hermes Cloud: Medium instance $0.56 per running day, Large $1.09, with inference and tools billed on top. Business and Enterprise tiers, prices not published |
| Claude Code | Requires a paid Claude plan or API billing | Claude plans: Pro $20 a month, or $17 a month billed annually; Max from $100 a month; Team standard seat $25 monthly or $20 annually, premium seat $125 or $100; Enterprise $20 per seat a month billed annually, with usage cost on top. Or pay per token through the Claude Console or a cloud provider |
| OpenCode | Free, MIT | OpenCode Zen: pay-as-you-go per million tokens, card fees passed through at 4.4% + $0.30. OpenCode Go: $10 a month, Go Plus $40. Enterprise priced per seat, with no token charge when you use your own gateway |
| OpenClaw | Free, MIT | None; the Foundation describes OpenClaw as free and open source |
Hermes Business, a team tier with a shared credit balance and per-member spending caps, and Hermes Enterprise, a self-hosted edition for your own hardware or private cloud, were reported by AlphaSignal in September 2026 without prices. For every option, model usage, hardware and the time spent operating the agent are extra.
Before you run a harness on work systems
- Write down where inference runs. For Claude Code, that is always a Claude endpoint at Anthropic or a cloud provider. For the open-source harnesses, it is whatever endpoint you configure, local or hosted.
- Set approvals explicitly. Do not inherit defaults: set Claude Code’s
defaultMode, OpenCode’spermissionblock, Hermes Agent’sapprovals.modeand OpenClaw’s exec settings in files you review. - Put a boundary around execution. Turn on Claude Code’s sandbox, choose a container backend in Hermes Agent or OpenClaw, and run OpenCode in a container or VM.
- Keep credentials out of reach. Claude Code’s sandbox can still read most of the machine by default, including
~/.ssh, unless you deny those paths; give agents scoped tokens, not personal keys. - Vet MCP servers, plugins and skills. They run outside the approval system in most harnesses.
- Bind servers to localhost. OpenCode’s server and OpenClaw’s gateway both listen locally by default; keep it that way unless a reviewed proxy sits in front.
- Pin versions and patch on a schedule. All four projects ship fixes faster than most change processes expect.
How VDF AI fits
All four harnesses are built for an individual or a small trusted team. VDF AI is a governed enterprise alternative for organisations that need agents across many users and departments, deployed on their own servers, in a private cloud, air-gapped, or in VDF’s managed cloud. It does not run, host or integrate with Hermes Agent, Claude Code, OpenCode or OpenClaw.
For developers, VDF Code provides extensions for VS Code, JetBrains IDEs, Neovim and Visual Studio, deploys in your VPC or on Kubernetes, OpenShift or bare metal, and supports air-gapped installs with signed offline update bundles. Its policies can allow or block models, restrict tools by repository and require approval for privileged operations.
For business workflows, VDF AI Agents are built from versioned Agent Skills, with tools granted per role through the MCP gateway and an audit log covering each prompt, retrieval and tool call.
Sources
- Hermes Agent repository and releases
- Hermes Agent providers
- Hermes Agent security
- Hermes Agent and Nous Portal plans
- Hermes Cloud pricing
- AlphaSignal on Hermes Business and Enterprise
- Claude Code overview
- Claude Code permissions
- Claude Code sandboxing
- Claude Code MCP
- Claude Code enterprise deployment options
- Claude Code and LLM gateways
- Claude Code legal and compliance
- Claude Code licence
- Claude plans and pricing
- OpenCode repository and releases
- OpenCode providers
- OpenCode permissions
- OpenCode MCP servers
- OpenCode server
- OpenCode policies
- OpenCode Enterprise
- OpenCode Zen and OpenCode Go
- OpenClaw repository
- OpenClaw model providers
- OpenClaw gateway security
- OpenClaw trust model
- OpenClaw sandboxing
- OpenClaw ACP agents
- OpenClaw Foundation