DevFlow vs OpenHands: 7 dimensions, sourced
DevFlow and OpenHands are compared on 7 dimensions below, each read from OpenHands's own documentation on 1 Oct 2026; 3 cases where OpenHands fits better are listed too.
OpenHands describes itself as a community focused on AI-driven development; its pieces include the open-source Agent Canvas client, a Software Agent SDK, a managed cloud service and an Enterprise offering for licensed self-hosting.↗
Each claim about the other product was read on 1 Oct 2026 from the page its ↗ link opens. Cells in the DevFlow column are written from files in DevFlow's own codebase, named next to each cell; that codebase is not public. A comparison left unchecked for 90 days is flagged for review.
| Dimension | DevFlow | OpenHands |
|---|---|---|
| Where it runs | On the hosted instance at devflow.fraway.io. A self-hosted install is not self-serve: it is arranged with Fraway on request.site/src/lib/site.tsENTITLEMENTS.mdweb/src/lib/components/billing/PlanCards.svelte | On your own machine with the open-source Agent Canvas, in the hosted OpenHands Cloud, or self-hosted with the commercial OpenHands Enterprise.↗ |
| Where your code goes | On the hosted instance at devflow.fraway.io, DevFlow clones repositories into worktrees on the servers that run it. Prompts, which include code, go to the model provider the workspace chooses.CLAUDE.mdsite/src/lib/site.ts | To work on a local repository, you mount it into the Docker sandbox workspace, for example with openhands serve --mount-cwd.↗ |
| Model choice | Each workspace stores its own key for OpenRouter, Anthropic, OpenAI or Google. On Pro and higher plans, managed OpenRouter inference can stand in when no OpenRouter key is stored.internal/relay/providers.gointernal/entitlement/entitlement.goCLAUDE.md | Any LLM supported by LiteLLM: a provider API key, a local model server such as Ollama, LM Studio, vLLM or SGLang, a LiteLLM proxy, or an OpenRouter key.↗ |
| Isolation | Each task gets its own git worktree. Agent CLIs run under a Landlock sandbox or, when enabled, in a per-invocation container; test and build commands run in non-root containers capped at 4 CPUs and 4 GB of memory by default.CLAUDE.mdinternal/agent/depcache.go | The Docker sandbox, the default and recommended option for most users, runs the agent server inside a Docker container to reduce risk when the agent runs commands. The comparison table lists isolated sandboxes for OpenHands Cloud and OpenHands Enterprise, as on the roadmap for an Agent Canvas VM backend, and not for a local backend.↗↗ |
| Verification | Runs the repository's configured test commands plus an AI code review and records both in a merge evidence report. A repository with no configured commands is not built or tested, and the report shows the skipped check.CLAUDE.mdinternal/agent/evidence.gointernal/agent/gate_command.go | An experimental critic, an LLM-based evaluator, scores predicted task success during a run and can prompt follow-up work; it is on automatically for OpenHands LLM Provider users.↗ |
| Human gates | A person approves, edits or rejects the plan before code is written, and a person marks the task done, which starts the squash, push and pull request when GitHub is connected. Opt-in autopilot keeps both gates.CLAUDE.mdinternal/agent/evidence.go | In the Software Agent SDK, a confirmation policy decides whether actions require user approval before execution, and a security analyzer rates action risk.↗ |
| Pricing model | The self-serve plans are Free, Pro and Team; an Enterprise plan is arranged with Fraway on request. Model usage is paid to the provider whose key the workspace stores, or through managed inference on Pro and above.internal/entitlement/entitlement.goENTITLEMENTS.mdweb/src/lib/components/billing/PlanCards.svelte | The pricing page lists Open Source as free and local, the Individual cloud plan as free with your own key or OpenHands models at cost, and Enterprise at custom pricing, as SaaS or self-hosted in your VPC.↗ |
How to read the table
- Where it runs compares hosted machines, machines you operate, and the options in between.
- Where your code goes compares where a checkout lives and which hosting services each product works with.
- Model choice compares fixed model sets, model pickers and keys you bring yourself.
- Isolation compares virtual machines, containers, sandboxes and network limits.
- Verification compares test runs, reviewing models and security scans.
- Human gates compares plan approval, pull request review and approval of individual actions.
- Pricing model compares plans, usage credits and the model spend you pay directly.
Where OpenHands fits better
- You want an MIT-licensed agent that runs locally on your own machine with your own LLM key.↗
- You want to run models on a local model server such as Ollama, LM Studio, vLLM or SGLang.↗
- You are building your own agent and want a composable Python library, the Software Agent SDK.↗
What OpenHands documents
The LLM overview says any model supported by LiteLLM can be connected, but that a powerful model is required for the agent to work well.↗
Without an LLM key of your own, the OpenHands LLM provider offers several models at cost, with no markup, on a pay-as-you-go basis.↗
Each public OpenHands repository includes its own license, and the introduction advises checking the one you use rather than assuming one license covers the whole ecosystem.↗
The critic feature is described as highly experimental and subject to change.↗
The Individual cloud plan adds hosted access from desktop and mobile, API support for automation and scripting, and Jira and Slack integrations.↗
How DevFlow runs the work
A DevFlow task moves from planning to a plan review, then to decomposition into at most 8 subtasks, implementation, verification and a written summary. Each task gets its own branch, named after its task ID, in a worktree under the repository's .devflow/worktrees directory.
By default, every agent invocation has a hard limit of 90 minutes and is stopped after 45 minutes without output. A workspace can also set a monthly spend cap, and a task over that cap fails with a reason before it starts.
On Pro and higher plans, finalization also runs dependency scanners for the languages DevFlow detects, such as govulncheck for Go modules and pnpm audit for Node packages, each stopped after 300 seconds by default. Scan results go into the evidence report and do not block the pipeline.
What DevFlow records along the way
A task that finishes implementation gets a merge evidence report listing the models that did the work, each subtask's verifier outcome, the build checks, the security scan summary, the final review and the people who approved the plan and clicked Mark Done. The report is added to the pull request body, and later rework refreshes it there.
Agent processes start with an allowlisted environment instead of inheriting the server's own. Provider keys and GitHub tokens are encrypted at rest with AES-256-GCM.
FAQ
Can I run OpenHands or DevFlow on my own servers?
OpenHands' pricing page describes an MIT-licensed open-source version that runs locally on your machine and an Enterprise plan offered as SaaS or self-hosted in your VPC. DevFlow runs at devflow.fraway.io; a self-hosted DevFlow install is not self-serve and is arranged with Fraway on request.
Does DevFlow support local model servers the way OpenHands does?
OpenHands documents local model servers such as Ollama, LM Studio, vLLM and SGLang. DevFlow calls OpenRouter, Anthropic, OpenAI or Google with a workspace key and rejects Ollama model ids.