Harness · spec sheet
OpenHands
- Category
- Coding agent
- Interface
- Terminal and web UI; ACP client
- License
- MIT
- Languages
- Python (1.0 rebuilt on its own Software Agent SDK)
- Models
- Any
- Isolation
- Optional Docker sandbox on a host you control
- Best for
- Self-hosted automation with a sandbox you control
Formerly OpenDevin. Self-hosted, sandboxed, model-agnostic — the sandbox protects the filesystem, not the bill, so watch it on ambiguous tasks.
What it is
OpenHands is the project that started life as OpenDevin, built by All Hands AI with a large open-source contributor base. It sits at roughly 85,000 GitHub stars, which makes it one of the better-established options on this board rather than a 2026 arrival.
The 1.0 release was a rebuild: the agent now runs on the project's own Software Agent SDK, so the harness and the library underneath it are separable. If you want the loop without the interface, that is now a supported shape rather than an act of archaeology.
How the loop works
Python throughout. You give it a task, it plans, edits files, runs commands and iterates against the results. Two front ends are provided — a terminal interface and a web UI — and they drive the same agent, which is useful when you want to kick a job off from a browser and watch it from a shell.
It is model-agnostic: point it at whichever provider you are paying for. It also works as an ACP client, so it can slot into editors and tooling that speak the Agent Client Protocol instead of being a closed world.
Isolation and permissions
This is the reason most people choose OpenHands. The agent can run inside a Docker sandbox on a host you control, so its file writes and command execution land in a container rather than on your working machine. Nothing is shipped off to someone else's infrastructure, and the sandbox boundary is one you configured and can inspect.
Be clear about what that boundary does and does not cover. It stops the agent from damaging your filesystem. It does not stop the agent from spending money. The known failure mode is an ambiguous task where the agent loops — retrying, re-reading, re-planning — and the container happily contains every one of those API calls while the provider bill climbs. Set spend limits at the provider and check on long runs.
The other operational wrinkle: if your own workflow already runs in a container, the Docker-in-Docker setup is awkward. It can be made to work, but budget time for it.
Who it is for
Teams and individuals who want automation on infrastructure they own, and who care that the sandbox is theirs rather than a vendor's. It is also a reasonable pick when data residency or policy makes hosted agents a non-starter, because there is nothing in the design that requires calling out to anyone except your chosen model provider.
Limits
Cost control is the weak spot, as above. Self-hosting is real work — you own the container images, the upgrades and the debugging. And the 1.0 SDK rebuild means older guides and blog posts written against the OpenDevin-era codebase may not apply; check the date on anything you find.
Alternatives on this board
- Managed agents — the opposite trade: someone else runs the sandbox and the infrastructure.
- OpenCode — lighter, terminal-only, also provider-agnostic.
- Codex CLI — open source and sandboxed by default, without the self-hosting overhead.
Sources
Hand-maintained editorial spec, not vendor copy — the read on each tool is judgement. Last checked 26 Sep 2026 · back to harnesses.