Kiro Review 2026: AWS's Spec-Driven IDE Just Became the Official Replacement for Amazon Q Developer
Kiro is Amazon Web Services' own agentic IDE, and it insists on something almost no rival does: before it writes a line of code, it turns your prompt into three plain files -- requirements.md, design.md, tasks.md -- runs automated reasoning to catch contradictions in that plan, and generates property-based tests before implementation starts. What's changed since most people last looked: on April 30, 2026, AWS confirmed Kiro isn't a side experiment anymore -- it's the named, official successor to Amazon Q Developer, which stopped taking new signups on May 15, 2026 and reaches full end-of-support April 30, 2027. This review covers what's verified true today: live pricing with a credit-rollover rule most people get backwards, three real security vulnerabilities AWS has patched, and an autocomplete complaint pattern documented straight from Kiro's own public GitHub issue tracker.
| Core tech (specs + reasoning) | Genuinely differentiated |
| Free tier | Real -- 50 credits/mo, open models + Sonnet 4.5 |
| Cheapest paid plan | $20/mo (Pro, 1,000 credits) |
| Official status | Named successor to Amazon Q Developer (Apr 30, 2026) |
| G2 record | 4.6/5, but only ~5 reviews -- too thin to trust yet |
Kiro's planning-first idea is genuinely the most interesting thing an AI IDE has shipped this year. Its autocomplete is the part that still annoys real users.
"Spec-driven development isn't a gimmick bolted onto a chatbox -- it's Kiro's entire premise. You describe a feature, Kiro writes a requirements document, a design document, and a sequenced task list, an automated-reasoning pass checks that plan for contradictions and gaps, and only then does an agent start writing code, with property-based tests generated to catch what 'all tests passed' would otherwise miss. That's a real, defensible answer to the 'AI wrote 400 lines and I have no idea what it did' problem every vibe-coding tool eventually runs into -- and it's why AWS was confident enough to name Kiro, not a Q Developer update, as the official replacement for its previous coding assistant. But sit next to that genuine strength a much more ordinary one: Kiro's own public GitHub issue tracker has multiple, independent, still-open reports about slow or non-functional inline autocomplete, the credit-based pricing model is opaque enough that several independent reviewers flagged it as harder to budget than a flat-rate tool, and three real security vulnerabilities -- all patched, all responsibly disclosed -- show up in 2026 security research. Both things are true about the same product."
None of that erases what Kiro does well: forcing a written, reviewable plan before code gets touched is a real discipline that pays off on production and regulated work, AWS's own enterprise case studies back that up with real numbers, and the free tier is genuinely usable to evaluate fit. It does mean I'd budget for a slower typing experience than Cursor, read the credit-rollover rule before assuming unused credits carry over (they mostly don't), and treat the spec workflow as overkill for a five-minute tweak.
One IDE, five surfaces, one non-negotiable idea: write the plan before the code.
Kiro is AWS's agentic IDE, built as a fork of VS Code (Code OSS), that turns a plain-English request into a structured spec -- requirements, architectural design, and a sequenced task list -- before an agent writes any code. As of this check, that same workflow is available across five surfaces: the IDE, a CLI (successor to the old Amazon Q Developer CLI), a web app (app.kiro.dev), a mobile app, and Kiro Crew, a separately open-sourced persistent workspace. Automated reasoning checks specs for contradictions, property-based testing generates test cases from stated rules rather than specific examples, and Hooks/Steering let the agent follow your team's own conventions automatically.
The one thing worth flagging up front: Kiro is not a rename of Amazon Q Developer, and it's not a community fork of anything -- it's a ground-up product AWS built in parallel, powered by Anthropic's Claude models served through Amazon Bedrock alongside several other model families. If you used Amazon Q Developer's IDE plugin, AWS's own migration guidance says everything you relied on (inline suggestions, chat, code generation) is available in Kiro, plus the spec workflow Q Developer never had.
AWS didn't just launch a product -- it's retiring its previous one to force the migration.
Jul 2025 launch; doubled to 200K+ by Oct 2025 (AWS-reported).
CLI, property-based testing, checkpointing, team plans shipped.
Plus 100+ curated partner Powers, as of the Jul 14, 2026 anniversary post.
New signups already blocked since May 15, 2026.
| Date | Event | Result |
|---|---|---|
| Jul 14-15, 2025 | Kiro launches in preview at AWS NY Summit | 100K+ developers try it in 5 days; waitlist forms within weeks |
| Nov 17, 2025 | General availability | Kiro CLI, property-based testing, checkpointing, team (Pro/Pro+/Power) plans |
| Dec 1-5, 2025 | AWS re:Invent 2025 | Claude Opus 4.5 added; autonomous agent shown in preview |
| Feb 5, 2026 | Kiro 0.9 | Custom subagents, agent skills, enterprise controls, smart refactoring |
| Apr 30, 2026 | AWS announces Amazon Q Developer end-of-support | Kiro named the official successor |
| May 18, 2026 | Kiro Web launches (app.kiro.dev) | Cloud-based sessions against GitHub repos |
| Jun 2026 | Kiro Pro Max tier; IDE 1.0 | Agent Focus mode, capability-based permissions |
| Aug 4, 2026 | Kiro Crew open-sourced (Apache 2.0) | A fifth platform surface, run outside the IDE |
| Sep 1, 2026 | Kiro Web reaches GA | Cloud config sync; Kiro added to AWS's ISO/IEC 27001:2022 scope |
| Sep 14, 2026 | IDE 1.1 | Agent Artifacts, native ARM64 builds, "Kiro for students" |
kirodotdev/Kiro (4,335 GitHub stars, 1,343 open issues, live API) is only Kiro's public issue tracker -- the IDE itself is a closed-source, proprietary AWS product, not something you can read or fork. The genuinely open-source part is a separate product, kirodotdev/KiroCrew (Apache 2.0, 4,183 stars, 698 forks, actively pushed as of Sep 28, 2026) -- a persistent companion workspace, not the IDE. Stars on either repo measure developer awareness, not paying Kiro subscribers -- worth keeping the two repos and the two meanings separate.| Netsmart (healthcare EHR), one of AWS's first Kiro customers | Result |
|---|---|
| Engineering-org adoption | 86% of identified developer roles use Kiro in daily workflow |
| Software development tasks | Up to 80% faster |
| Root-cause time on production incidents | 66% faster |
| MCP deployment time | 98% reduction |
The praise is about discipline. The complaint is about typing -- and it's documented on Kiro's own issue tracker.
Multiple independent authors describe the spec workflow the same way: it "did not invent good engineering practices, it made them unavoidable," forcing acceptance criteria to become "constraints the system enforced" rather than guidance an agent could quietly skip -- praise that shows up consistently across separate, unaffiliated posts rather than one outlier.
At least five separate, independently filed issues describe the same problem: inline autocomplete suggestions taking 5-10 seconds to appear, sometimes not appearing at all, with weak context-awareness -- several reports explicitly benchmark this against Cursor's roughly one-second response time. As close to a primary source as a closed-source product's complaint pattern gets.
"For small tweaks, the full spec workflow can feel like overkill -- especially with re-generating tasks," and keeping specs synchronized with an evolving codebase "requires ongoing discipline." The same piece also flags that Kiro's model selection lagged Cursor's breadth at the time of writing.
Six tiers, one credit system -- and a rollover rule that's easy to get backwards.
Free
50 credits/month.
- Open-weight models + Claude Sonnet 4.5
- For teams up to 500 (self-serve ceiling)
Pro
1,000 credits/month, premium models.
- Add-on credits at $0.04/credit
- Monthly credits do not roll over
Pro+
2,000 credits/month, premium models.
- Same add-on and rollover rules as Pro
- Access to Claude Haiku 4.5 at a lower multiplier
Pro Max
5,000 credits/month.
- Added Jun 2026 alongside IDE 1.0
- Same $0.04/credit add-on pricing
Power
10,000 credits/month.
- Top self-serve tier before Enterprise
- Access to every published model
Enterprise
Centralized billing, SSO, governance.
- Content excluded from service improvement
- Own AWS region / own S3 bucket for logs
Sign-up bonus: $20 credited toward your first paid upgrade via social login or AWS Builder ID. AWS also offers a full year of Kiro Pro+ free to qualifying startups (through Series B, while credits last) and 1,000 free credits/month for a year to students. Exact wording pulled from the live pricing page, Sep 28, 2026.
Your answer depends on whether you want a plan reviewed before code, or code as fast as typing allows.
Free tier -- 50 credits/month is enough to run one real spec end-to-end; watch the monthly reset.
Pro, $20/mo, 1,000 credits -- budget by model multiplier, not just credit count.
Enterprise, custom -- SSO, your own AWS region/S3 for logs, content excluded from training.
Plan the move now -- new Q Developer signups stopped May 15, 2026; full end-of-support is April 30, 2027.
Kiro isn't optimized for that -- see the GitHub-sourced complaint pattern in Reviews and consider Cursor instead.
Kiro supports 15+ languages broadly (Python, Java, Go, Rust, etc.) -- check Alternatives if you specifically need deep non-AWS cloud tooling.
The thing that actually differentiates Kiro: it argues with your plan before it writes any code.
Every Kiro spec produces three plain Markdown files: requirements.md, design.md, and tasks.md. That alone isn't new -- plenty of tools generate a plan. What is genuinely different is what happens next: automated reasoning checks the requirements for internal contradictions and gaps before a single task is created, and property-based testing extracts testable "properties" from the spec (for example, "for any sequence of operations, all generated IDs should be unique") and generates hundreds of randomized test cases against that rule, rather than relying only on the specific examples a developer happened to write. AWS's own framing: this catches issues that "all tests passed" would otherwise miss, because example-based tests only prove the cases you thought to write.
| Spec artifact | What it is | Why it matters |
|---|---|---|
| requirements.md | Formal, reviewable requirements generated from your prompt | The thing you (or a reviewer) actually approve before code starts |
| design.md | Architectural design derived from the requirements | Catches structural problems before implementation, not after |
| tasks.md | Sequenced, checkable task list tied back to requirements | Agents implement in bounded chunks, not one giant diff |
| Automated reasoning | Checks requirements for contradictions/gaps | Finds plan-level bugs before any code exists |
| Property-based tests | Rule-based tests generated from spec properties | Catches edge cases specific unit tests miss |
Two features layer on top of specs. Hooks are event-driven automations (JSON files in .kiro/hooks/) that fire on triggers like a file save or a tool call -- lint on every save, or gate a risky tool call behind a precondition. Steering is persistent project knowledge in Markdown (.kiro/steering/ for one project, ~/.kiro/steering/ globally) so Kiro stops needing to be reminded of your conventions every session -- with four inclusion modes (Always, conditional on file match, manual reference, or auto-triggered by request).
"AWS Tech Tales | Catching Up with Kiro" -- a May 2026 update on what changed since launch, straight from AWS's own events channel.
Published by the official "AWS Events" YouTube channel (youtube.com/@AWSEventsChannel). A separate candidate video ("Hands-on with Kiro, the agentic code generation IDE") was checked the same way and rejected: YouTube lists the author as "InfoWorld", a third-party publication, not AWS's own channel.
Prompt in, reviewable plan out, code only after the plan survives review.
The review step moves earlier than most competitors put it -- you're approving a written plan, not just diffing generated code after the fact. The trade-off, per the user-sentiment pattern above, is real: for a five-minute fix, generating and re-generating a full requirements/design/tasks cycle can feel like process for its own sake.
The same spec workflow now runs in five different places, not just one editor window.
Kiro shipped as an IDE first (a VS Code / Code-OSS fork that imports your existing settings, themes, and Open VSX-compatible extensions), but by this check it's genuinely multi-surface. Kiro CLI succeeded the old Amazon Q Developer CLI in the terminal -- legacy q commands still work, and configs auto-migrated to ~/.kiro/. Kiro Web (app.kiro.dev) launched May 18, 2026 and reached GA Sep 1, 2026, for cloud-based sessions against a GitHub repo without a local checkout. A mobile app covers on-the-go review. And Kiro Crew, open-sourced under Apache 2.0 on Aug 4, 2026, is a separate, persistent workspace product -- described by its own repo as something that "self-improves and continues beyond one session" -- with its own session manager, memory, and GitHub PR integration.
Powers bundle MCP, steering, and hooks into one installable unit -- and 15,000+ of them already exist.
Kiro speaks the Model Context Protocol directly: you can add any MCP server via a JSON config at the workspace or user level, though unlike some rivals, Kiro ships with no default MCP servers pre-installed -- you add what you need. On top of raw MCP, Kiro has its own packaging concept, Powers: a bundle of MCP server configuration, a steering file (POWER.md), hooks, and contextual knowledge, installable as one unit. By the one-year mark (Jul 14, 2026), AWS reported 15,000+ community-created Powers plus 100+ curated partner Powers spanning categories like Stripe, Supabase, Figma, Postman, Datadog, and Terraform.
There's no separate API bill -- your real variable cost is which model you pick, multiplied by how much you use it.
| Model | Credit multiplier | Where it fits |
|---|---|---|
| Auto (default router) | 1x (baseline) | Frontier models with automatic fallback -- the recommended default |
| Qwen3 Coder Next | 0.05x | Cheapest option; open-weight, strong error recovery |
| DeepSeek 3.2 / MiniMax M2.5 | 0.25x each | Open-weight, long tool-calling chains, high-volume drafting |
| GLM-5 | 0.5x | 200K context, repository-scale work at a fraction of frontier cost |
| Claude Haiku 4.5 | 0.4x | Fastest near-frontier option for quick iterations |
| Claude Sonnet 5 / GPT-5.6 Terra | 1.3x / 2.2x | Balanced agentic performance for everyday building |
| Claude Opus 5 / GPT-5.6 Sol | 2.2x / 4.4x | State-of-the-art reasoning for complex, high-stakes tasks |
Real certifications, a genuine enterprise-grade data policy, and three patched vulnerabilities worth knowing about.
| Control | What's actually in place |
|---|---|
| Compliance | HIPAA eligible (IDE and CLI); Kiro is in-scope for AWS's ISO/IEC 27001:2022 certification, assessed by EY CertifyPoint |
| Free / individual tier data use | Content may be used for service improvement; inputs stored up to 60 days for abuse detection; opt-out available in Settings |
| Enterprise data use | Content explicitly excluded from service improvement; logs stored in a customer-selected AWS region or the customer's own S3 bucket |
| Encryption | TLS 1.2+ in transit; AWS KMS at rest (customer-managed keys available on Enterprise) |
| Permissions | Capability-based permissions and Agent Focus mode, added with IDE 1.0 (Jun 2026) |
It's worth separating two different kinds of "trust" here: the certification and data-handling posture (ISO 27001 scope, HIPAA eligibility, enterprise no-training policy) is real and independently verifiable. The vulnerability pattern is also real -- three distinct, CVE-or-researcher-documented issues in a single year is not nothing -- but every one of them was fixed, in two cases before public disclosure even happened, which is the responsible-disclosure process working as intended rather than a red flag on its own.
Best for teams that need a paper trail before code ships, not people who want the fastest possible autocomplete.
| Situation | Why Kiro fits | Likely plan |
|---|---|---|
| Team on AWS building regulated software (healthcare, finance) | HIPAA eligibility, ISO 27001 scope, enterprise no-training data policy | Enterprise |
| Existing Amazon Q Developer user | Named official successor; migration path is real, not optional forever | Pro or Pro+, then Enterprise |
| Solo developer who wants fewer "AI wrote something wrong" surprises | Specs + automated reasoning + property-based tests catch plan-level bugs early | Free, then Pro |
| Developer who wants the fastest raw typing/autocomplete feel | Not Kiro's strength -- see the documented GitHub complaint pattern above | Consider Cursor instead |
| Non-AWS shop that just wants a cheap, flexible model router | Credit multipliers reward using cheap open-weight models deliberately | Pro, using Auto or Qwen3 Coder Next |
Four real gaps, not manufactured ones.
At least five separate, independently filed issues on Kiro's own GitHub tracker describe 5-10 second delays or missing suggestions, with several reports explicitly benchmarking this as slower than Cursor's roughly one-second response.
The sticker price ($20 for 1,000 credits) means little until you know your model mix -- multipliers range from 0.05x to 4.4x, monthly credits reset unused rather than roll over, and only purchased add-on credits carry a 12-month rollover.
Independent reviewers consistently note that regenerating a full requirements/design/tasks cycle for a five-minute fix feels like process for its own sake, and keeping specs synced with a fast-moving codebase takes ongoing discipline.
CVE-2026-4295, CVE-2026-10591, and an August-disclosed Powers prompt-injection flaw were all real, all patched -- but the pattern (crafted project files, poisoned web content, malicious repo content) is the same class of risk every agentic IDE is now dealing with, and worth factoring into how much you let Kiro auto-approve.
Kiro isn't the only agentic IDE, and it isn't optimized for everyone's trade-off.
| If you mostly need... | Compare Kiro with... |
|---|---|
| The fastest, most polished autocomplete/typing experience | Cursor -- read our Cursor review |
| A fully autonomous agent you delegate whole tickets to, minimal supervision | Devin -- read our Devin review |
| The largest installed base, tightest GitHub/VS Code integration | GitHub Copilot -- read our GitHub Copilot review |
| A free, open-source, fully auditable agent you run yourself | Cline -- read our Cline review |
| A terminal-first agent from the same model family Kiro uses under the hood | Claude Code -- see our Claude Code setup guide |
| Another spec-first framework outside AWS's ecosystem | BMAD-Method or GSD (open frameworks independent reviewers group alongside Kiro's category) |
No affiliate relationship shapes this review.
JAVIS has not established a publisher affiliate program with AWS/Kiro. Every CTA in this article points to the official product.
Go to the official page.
Open KiroRead the alternative that matches your real question.
Choose the next articleKiro makes the most sense next to the agentic editors people actually shortlist against it.
Kiro's closest comparisons are the tools most developers already have an opinion about -- here's what I'd read next depending on which trade-off matters most to you.
Questions people are actually searching right now
Is Kiro free to use?
Yes. The Free plan gives you 50 credits per month, with access to open-weight models and Claude Sonnet 4.5, self-serve for teams up to 500. Paid plans start at Pro, $20/user/month for 1,000 credits.
What is spec-driven development in Kiro?
Instead of jumping straight from a prompt to code, Kiro first generates requirements.md, design.md, and tasks.md, runs automated reasoning to check that plan for contradictions, and creates property-based tests -- and only after you review that plan does an agent implement the tasks.
What happened to Amazon Q Developer?
AWS announced on April 30, 2026 that Kiro is the official successor to Amazon Q Developer. New Q Developer signups were blocked May 15, 2026; Opus 4.6 and later Claude models became Kiro-exclusive from May 29, 2026; full end-of-support for Q Developer IDE plugins and subscriptions is April 30, 2027.
Is Kiro built on VS Code?
Yes. Kiro is based on Code OSS (the open-source base of VS Code), so it imports your existing VS Code settings, themes, and Open VSX-compatible extensions during onboarding -- though some VS Code-exclusive extensions won't work.
Do unused Kiro credits roll over?
Not by default. Monthly plan credits reset at the start of each billing cycle and do not carry over. Purchased add-on credits behave differently: they do roll over and expire 12 months after purchase.
Is Kiro open source?
The IDE itself is not -- it's a closed-source, proprietary AWS product; kirodotdev/Kiro on GitHub is only the public issue tracker. A separate, related product, Kiro Crew, was open-sourced under the Apache 2.0 license on Aug 4, 2026.
Is Kiro secure enough for regulated industries?
Kiro is HIPAA eligible (IDE and CLI) and is included in AWS's ISO/IEC 27001:2022 certification scope. Separately, three real vulnerabilities were found and patched by outside researchers in 2026 (CVE-2026-4295, CVE-2026-10591, and an August-disclosed Powers prompt-injection issue) -- all fixed, and worth reading about before deciding how much autonomy to grant the agent.
How does Kiro compare to Cursor?
Independent comparisons consistently describe Kiro as planning-first (specs are "a first-class artifact," no code until the plan is reviewed) versus Cursor's editor-first, no-enforced-planning approach with widely-praised autocomplete. Many developers who've tried both report using Cursor for daily coding and Kiro for planned, documented, higher-stakes work.
Where this came from, and when it was checked.
Pricing (Free/Pro/Pro+/Pro Max/Power/Enterprise, credit rollover rule): kiro.dev/pricing, Sep 28, 2026.
Homepage claims, Powers, multi-surface support: kiro.dev, official, checked Sep 28, 2026.
Specs, automated reasoning, property-based testing: kiro.dev/docs/specs, kiro.dev/blog/general-availability, official, cross-checked Sep 28, 2026.
Hooks and Steering: kiro.dev/docs/hooks, kiro.dev/docs/steering, official documentation, checked Sep 28, 2026.
GA date and shipped features (Nov 17, 2025): kiro.dev/blog/general-availability, official, corroborated by AWS News Blog weekly roundup (Nov 24, 2025) and independent 2025 re:Invent coverage.
One-year milestones (preview adoption, community Powers, enterprise examples): kiro.dev/blog/one-year, official, published Jul 14, 2026.
Amazon Q Developer retirement/timeline: aws.amazon.com/blogs/devops/amazon-q-developer-end-of-support-announcement, official AWS blog, published Apr 30, 2026.
Model list and credit multipliers: kiro.dev/docs/models/available-models (official docs) cross-checked directly against the live model-picker screenshot captured from kiro.dev, Sep 28, 2026.
Data protection / compliance (HIPAA eligibility, ISO 27001:2022 scope, encryption, enterprise no-training): kiro.dev/docs/privacy-and-security/data-protection and /compliance-validation, official, checked Sep 28, 2026; ISO 27001 scope corroborated via kiro.dev/changelog/general/kiro-covered-by-aws-iso-27001-certification.
CVE-2026-4295: AWS Security Bulletin 2026-009-AWS; OpenCVE and Strix.ai CVE detail pages, published Mar 17, 2026, fixed in Kiro IDE 0.8.0.
CVE-2026-10591: The Hacker News coverage of Intezer/Kodem Security's disclosure, reported Feb 11, 2026, fix confirmed in v0.11.130 by Apr 3, 2026.
Kiro Powers prompt-injection finding: The Hacker News coverage of Mindgard's research, disclosed Aug 27, 2026; AWS confirmed the fix shipped in the Jan 15, 2026 (v0.8.140) update.
Netsmart case study: Businesswire press release (May 28, 2026) and aws.amazon.com/solutions/case-studies/netsmart-case-study -- company-disclosed, not independently audited by JAVIS.
G2 rating: g2.com/products/kiro (the page could not be read directly) -- sourced via search-result aggregation; explicitly disclosed as a very small sample (~5 reviews).
User sentiment (praise and autocomplete-latency pattern): DEV Community posts (multiple independent authors), Peter McAree's "Kiro's Agentic IDE: Hype, Hope and Hard Truths," and the public issue tracker at github.com/kirodotdev/Kiro (issues #2397, #3483, #3988, #7992, #11279), all checked Sep 2026.
GitHub repo stats (kirodotdev/Kiro and kirodotdev/KiroCrew): GitHub data for github.com/kirodotdev/Kiro and api.github.com/repos/kirodotdev/KiroCrew, Sep 28, 2026.
AWS ownership (not a spinout/acquisition): cross-checked via AWS's own product documentation and a confirmed AWS-team Hacker News comment (news.ycombinator.com/item?id=44561873), Sep 2026.
Official video: youtube.com/watch?v=w-fn-vELIEs, authorship confirmed on YouTube (author "AWS Events", channel @AWSEventsChannel); one other candidate video was checked the same way and rejected as non-official (InfoWorld).
