{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "docker-model-runner",
    "name": "Docker Model Runner",
    "vendor": "Docker, Inc.",
    "vendorUrl": "https://www.docker.com",
    "kind": "http-api",
    "category": "local-ai",
    "summary": "Docker's open-source tool for pulling and running open models from Docker Hub, OCI registries or Hugging Face. It runs through Docker Desktop, Docker Engine or a standalone `dmr` binary, with local OpenAI-, Anthropic- and Ollama-compatible APIs.",
    "url": "https://www.anchorterminal.com/tools/docker-model-runner",
    "markdownUrl": "https://www.anchorterminal.com/tools/docker-model-runner.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/docker-model-runner.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/docker-model-runner.json",
    "repo": "https://github.com/docker/model-runner",
    "license": "Apache-2.0 (server, CLI plugin and `dmr` binary). Docker Desktop, which bundles it, is closed software under Docker's subscription agreement, and each model carries its own licence",
    "transports": [
      "http"
    ],
    "packages": [
      {
        "registry": "oci",
        "name": "docker.io/docker/model-runner"
      }
    ],
    "auth": "none",
    "authNotes": "The API takes no credential, and the docs say it ignores any key sent. Per the docs, any client that can reach it, including other containers on the same Docker network, can pull, load and run models. In Docker Desktop, host-side TCP is off until enabled in settings or with `docker desktop enable model-runner --tcp \u003cport\u003e`, and containers reach the API at model-runner.docker.internal. In Docker Engine, TCP is on by default on port 12434. Cross-origin requests get 403 unless the origin is localhost, 127.0.0.1, 0.0.0.0 or listed in `DMR_ORIGINS` (https://docs.docker.com/ai/model-runner/; https://github.com/docker/model-runner/blob/main/pkg/envconfig/envconfig.go).",
    "pricing": "free",
    "pricingNotes": "Free under Apache-2.0, with no account needed for the Docker Engine plugin or the standalone `dmr` binary. On macOS and Windows it also ships inside Docker Desktop, which is free for personal use, non-commercial open-source projects and businesses with fewer than 250 employees and under US $10,000,000 in annual revenue. Larger organisations need a paid Docker plan for Desktop (https://www.docker.com/legal/docker-subscription-service-agreement/; https://www.docker.com/pricing/, checked 2026-10-08).",
    "priceSummary": "Free · OSS",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 656,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.docker.com/ai/model-runner/",
    "llmsTxt": "https://docs.docker.com/llms.txt",
    "capabilities": [
      "inference.local",
      "inference.open-weights",
      "inference.llm",
      "embed.text",
      "rerank",
      "image.generate"
    ],
    "tags": [
      "open-source",
      "local",
      "self-hosted",
      "free",
      "no-card",
      "openai-compatible",
      "llms-txt",
      "docker",
      "go",
      "no-auth"
    ],
    "lastRelease": "2026-08-12",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 57.1,
      "grade": "C",
      "agentReady": false,
      "rank": 428,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 5,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 58,
        "maintenance": 55,
        "payments": 60,
        "reliability": 85,
        "schema": 49,
        "security": 40,
        "transparency": 73
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 85,
          "points": 17,
          "reason": "Read with the local-software lines, since the API runs on the owner's machine. Bundled with Docker Desktop, installed as `docker-model-plugin` from Docker's apt and dnf repositories, and shipped as a standalone `dmr` binary through Homebrew and winget, with platform, GPU and driver requirements stated in the docs (20). The CI workflow runs lint, race-detector tests and builds on pushes and pull requests to main, with separate end-to-end, integration and daily check workflows, and the ten most recent CI runs on main passed on 8 October 2026 (25). 41 open issues and 25 open pull requests. Each of the 20 newest open issues had at least one comment, but several are regressions or failures still open, including HTTP 500 on sequential tool calls (#1063), a Windows GPU regression after Docker Desktop 4.82.0 (#1054) and a context-size setting applied nondeterministically (#1025) (17 of 25). Semver tags with notes on each GitHub release, but no changelog file and no breaking-change section in the notes we read (8 of 15). Version 1.2.8 (15). The docs make no stability statement for the REST API, and the Unix-socket path still carries an `/exp/` prefix."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 49,
          "points": 7.96,
          "reason": "Read for an API. No OpenAPI or similar file was found in the repository or the docs. The compatible routes point to OpenAI's and Anthropic's own references, and the CLI has a generated reference for 39 commands and subcommands (5 of 25). docs.docker.com has llms.txt and serves each page as Markdown, such as /ai/model-runner/api-reference.md (10). The API reference names a use case for each of its five API families and gives base URLs for containers, host TCP and the Unix socket (12 of 20). Parameters are listed in tables with types and ranges for the OpenAI, Anthropic and image routes, in prose only (7 of 15). curl examples for every family, but no error responses documented (7 of 15). Dated GitHub releases with notes. The API has no version of its own, and the reference omits routes present in the source, including the Responses API, rerank and the Ollama pull and delete routes (8 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 58,
          "points": 9.43,
          "reason": "Read for an API. Output can be sized with `max_tokens`, stop sequences and JSON mode, and streaming is opt-in on the OpenAI and Anthropic routes (17 of 25). Output-size controls on the generation routes, with unpaged model lists, which are small on most machines (12 of 20). Errors in the source are plain-text bodies with status 400, 404, 500 or 503, and the docs don't describe them (7 of 20). Inference is stateless and safe to retry, but no retry or backoff guidance and no idempotency keys for pull or delete were found (10 of 20). `model` is the only required field beyond the messages or prompt. There is no SDK of its own, though OpenAI, Anthropic and Ollama clients work against it, and the docs link Testcontainers modules for Java and Go (12 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 40,
          "points": 7,
          "reason": "Read with the tool checklist, for the local API. No credential, by design. The docs say the API is not authenticated and that any client that can reach it, including other containers on the same Docker network, can pull, load and run models. Host-side TCP is off by default in Docker Desktop and on by default on port 12434 in Docker Engine, and cross-origin requests are refused with 403 unless the origin is localhost, 127.0.0.1, 0.0.0.0 or listed in `DMR_ORIGINS` (7 of 30). No read-only mode or per-caller limit. Runtime flags pass an allowlist, engines run sandboxed on macOS and Windows and in a container on Linux, and Enhanced Container Isolation, a Docker Business control, blocks container access (6 of 20). The API returns model output, with no injection guidance in the docs (6 of 15). `docker model requests` and the Requests tab show recent requests and responses, the source keeps the last 10 per model, and `/metrics` exposes Prometheus counters. No caller identity (8 of 15). www.docker.com has a valid security.txt with a disclosure policy, SECURITY.md promises an acknowledgement within 72 hours, and two advisories were published with CVEs in 2026. No monetary bounty for this project (13 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 60,
          "points": 7.5,
          "reason": "Read with the self-hosted rule, since the API an agent calls is free software on the owner's machine. No x402, MPP or L402 in the docs or the source (0). Model Runner is Apache-2.0 with nothing to buy and no account needed for the Docker Engine plugin or the `dmr` binary, so 20, 20 and 20 on the last three lines. One qualification applies to the Docker Desktop route. Docker's subscription agreement limits free Desktop use to non-commercial open-source projects and businesses with fewer than 250 employees and under US $10,000,000 in annual revenue, and paid plans run from $11 to $24 per user a month."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 55,
          "points": 4.81,
          "reason": "v1.2.8 was released on 12 August 2026, 57 days before the check (20 of 30). Two releases in the 90 days to 8 October 2026, v1.2.7 on 11 August and v1.2.8, against 30 or so between March and June (0 of 20). 45 commits on main since 10 July, the newest on 8 October, and each of the 20 newest open issues had at least one comment, with 41 issues and 25 pull requests open (17 of 25). No SDK of its own. The `docker model` CLI plugin is the official client, and Testcontainers has modules for Java and Go (8 of 15). Dependabot runs weekly on Go modules and GitHub Actions, actions are pinned by commit, a script bumps llama.cpp, and CI passes on main (10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 73,
          "points": 6.39,
          "note": "editorial 62, provenance 84",
          "reason": "The editorial half. Apache-2.0 for the server, the CLI and the `dmr` binary in a public repository. Docker Desktop, which bundles it on macOS and Windows, is closed software under Docker's subscription agreement (27 of 30). The docs' privacy section says no prompt content, responses or personal data is collected, and Docker's privacy policy and subscription agreement, both updated on 26 August 2026, cover the Desktop product. No retention period specific to Model Runner was found (18 of 30). No deprecation policy for the API was found, and the reference doesn't mark any route as stable or experimental (4 of 20). Telemetry is disclosed with a link to the source. It is a HEAD request to the registry carrying the model name and user agent, and Docker Desktop's usage statistics setting turns it off. For Docker Engine the docs say the requests are made regardless of settings, while the source skips them when `DO_NOT_TRACK=1`, which the docs don't mention (13 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Read for an API. Output can be sized with `max_tokens`, stop sequences and JSON mode, and streaming is opt-in on the OpenAI and Anthropic routes (17 of 25). Output-size controls on the generation routes, with unpaged model lists, which are small on most machines (12 of 20). Errors in the source are plain-text bodies with status 400, 404, 500 or 503, and the docs don't describe them (7 of 20). Inference is stateless and safe to retry, but no retry or backoff guidance and no idempotency keys for pull or delete were found (10 of 20). `model` is the only required field beyond the messages or prompt. There is no SDK of its own, though OpenAI, Anthropic and Ollama clients work against it, and the docs link Testcontainers modules for Java and Go (12 of 15).",
          "maintenance": "v1.2.8 was released on 12 August 2026, 57 days before the check (20 of 30). Two releases in the 90 days to 8 October 2026, v1.2.7 on 11 August and v1.2.8, against 30 or so between March and June (0 of 20). 45 commits on main since 10 July, the newest on 8 October, and each of the 20 newest open issues had at least one comment, with 41 issues and 25 pull requests open (17 of 25). No SDK of its own. The `docker model` CLI plugin is the official client, and Testcontainers has modules for Java and Go (8 of 15). Dependabot runs weekly on Go modules and GitHub Actions, actions are pinned by commit, a script bumps llama.cpp, and CI passes on main (10).",
          "payments": "Read with the self-hosted rule, since the API an agent calls is free software on the owner's machine. No x402, MPP or L402 in the docs or the source (0). Model Runner is Apache-2.0 with nothing to buy and no account needed for the Docker Engine plugin or the `dmr` binary, so 20, 20 and 20 on the last three lines. One qualification applies to the Docker Desktop route. Docker's subscription agreement limits free Desktop use to non-commercial open-source projects and businesses with fewer than 250 employees and under US $10,000,000 in annual revenue, and paid plans run from $11 to $24 per user a month.",
          "reliability": "Read with the local-software lines, since the API runs on the owner's machine. Bundled with Docker Desktop, installed as `docker-model-plugin` from Docker's apt and dnf repositories, and shipped as a standalone `dmr` binary through Homebrew and winget, with platform, GPU and driver requirements stated in the docs (20). The CI workflow runs lint, race-detector tests and builds on pushes and pull requests to main, with separate end-to-end, integration and daily check workflows, and the ten most recent CI runs on main passed on 8 October 2026 (25). 41 open issues and 25 open pull requests. Each of the 20 newest open issues had at least one comment, but several are regressions or failures still open, including HTTP 500 on sequential tool calls (#1063), a Windows GPU regression after Docker Desktop 4.82.0 (#1054) and a context-size setting applied nondeterministically (#1025) (17 of 25). Semver tags with notes on each GitHub release, but no changelog file and no breaking-change section in the notes we read (8 of 15). Version 1.2.8 (15). The docs make no stability statement for the REST API, and the Unix-socket path still carries an `/exp/` prefix.",
          "schema": "Read for an API. No OpenAPI or similar file was found in the repository or the docs. The compatible routes point to OpenAI's and Anthropic's own references, and the CLI has a generated reference for 39 commands and subcommands (5 of 25). docs.docker.com has llms.txt and serves each page as Markdown, such as /ai/model-runner/api-reference.md (10). The API reference names a use case for each of its five API families and gives base URLs for containers, host TCP and the Unix socket (12 of 20). Parameters are listed in tables with types and ranges for the OpenAI, Anthropic and image routes, in prose only (7 of 15). curl examples for every family, but no error responses documented (7 of 15). Dated GitHub releases with notes. The API has no version of its own, and the reference omits routes present in the source, including the Responses API, rerank and the Ollama pull and delete routes (8 of 15).",
          "security": "Read with the tool checklist, for the local API. No credential, by design. The docs say the API is not authenticated and that any client that can reach it, including other containers on the same Docker network, can pull, load and run models. Host-side TCP is off by default in Docker Desktop and on by default on port 12434 in Docker Engine, and cross-origin requests are refused with 403 unless the origin is localhost, 127.0.0.1, 0.0.0.0 or listed in `DMR_ORIGINS` (7 of 30). No read-only mode or per-caller limit. Runtime flags pass an allowlist, engines run sandboxed on macOS and Windows and in a container on Linux, and Enhanced Container Isolation, a Docker Business control, blocks container access (6 of 20). The API returns model output, with no injection guidance in the docs (6 of 15). `docker model requests` and the Requests tab show recent requests and responses, the source keeps the last 10 per model, and `/metrics` exposes Prometheus counters. No caller identity (8 of 15). www.docker.com has a valid security.txt with a disclosure policy, SECURITY.md promises an acknowledgement within 72 hours, and two advisories were published with CVEs in 2026. No monetary bounty for this project (13 of 20).",
          "transparency": "The editorial half. Apache-2.0 for the server, the CLI and the `dmr` binary in a public repository. Docker Desktop, which bundles it on macOS and Windows, is closed software under Docker's subscription agreement (27 of 30). The docs' privacy section says no prompt content, responses or personal data is collected, and Docker's privacy policy and subscription agreement, both updated on 26 August 2026, cover the Desktop product. No retention period specific to Model Runner was found (18 of 30). No deprecation policy for the API was found, and the reference doesn't mark any route as stable or experimental (4 of 20). Telemetry is disclosed with a link to the source. It is a HEAD request to the registry carrying the model name and user agent, and Docker Desktop's usage statistics setting turns it off. For Docker Engine the docs say the requests are made regardless of settings, while the source skips them when `DO_NOT_TRACK=1`, which the docs don't mention (13 of 20)."
        },
        "sources": [
          {
            "what": "overview, requirements, isolation, networking and data collection",
            "url": "https://docs.docker.com/ai/model-runner/",
            "seen": "2026-10-08"
          },
          {
            "what": "API reference",
            "url": "https://docs.docker.com/ai/model-runner/api-reference/",
            "seen": "2026-10-08"
          },
          {
            "what": "get started",
            "url": "https://docs.docker.com/ai/model-runner/get-started/",
            "seen": "2026-10-08"
          },
          {
            "what": "configuration options",
            "url": "https://docs.docker.com/ai/model-runner/configuration/",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt",
            "url": "https://docs.docker.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "repository README, licence and header counts",
            "url": "https://github.com/docker/model-runner",
            "seen": "2026-10-08"
          },
          {
            "what": "releases",
            "url": "https://github.com/docker/model-runner/releases",
            "seen": "2026-10-08"
          },
          {
            "what": "open issues",
            "url": "https://github.com/docker/model-runner/issues",
            "seen": "2026-10-08"
          },
          {
            "what": "CI workflow runs on main",
            "url": "https://github.com/docker/model-runner/actions/workflows/ci.yml",
            "seen": "2026-10-08"
          },
          {
            "what": "security advisories",
            "url": "https://github.com/docker/model-runner/security/advisories",
            "seen": "2026-10-08"
          },
          {
            "what": "advisory GHSA-m456-c56c-hh5c",
            "url": "https://github.com/docker/model-runner/security/advisories/GHSA-m456-c56c-hh5c",
            "seen": "2026-10-08"
          },
          {
            "what": "advisory GHSA-x2f5-332j-9xwq",
            "url": "https://github.com/docker/model-runner/security/advisories/GHSA-x2f5-332j-9xwq",
            "seen": "2026-10-08"
          },
          {
            "what": "security policy",
            "url": "https://github.com/docker/model-runner/security/policy",
            "seen": "2026-10-08"
          },
          {
            "what": "route registrations",
            "url": "https://github.com/docker/model-runner/blob/main/pkg/routing/router.go",
            "seen": "2026-10-08"
          },
          {
            "what": "CORS middleware and default origins",
            "url": "https://github.com/docker/model-runner/blob/main/pkg/envconfig/envconfig.go",
            "seen": "2026-10-08"
          },
          {
            "what": "model-name tracker",
            "url": "https://github.com/docker/model-runner/blob/main/pkg/metrics/metrics.go",
            "seen": "2026-10-08"
          },
          {
            "what": "server listen code",
            "url": "https://github.com/docker/model-runner/blob/main/pkg/server/server.go",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.docker.com/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "subscription service agreement",
            "url": "https://www.docker.com/legal/docker-subscription-service-agreement/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.docker.com/legal/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.docker.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for docker.com",
            "url": "https://rdap.verisign.com/com/v1/domain/docker.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: Docker Desktop release notes, which may carry Model Runner changes between the tagged releases, so the release count covers GitHub tags only",
          "unchecked: whether the Docker Engine install publishes port 12434 on loopback only. The server source listens on every interface when `MODEL_RUNNER_PORT` is set",
          "unchecked: reply times on issues. We saw comment counts on the issue list, not who replied or when",
          "unchecked: Docker's SOC 2 or ISO 27001 status, which we didn't look up for this listing",
          "unchecked: the first release date, and pull counts for the docker/model-runner image",
          "Docker publishes no terms written for Model Runner itself. The subscription agreement and privacy policy listed are the ones that govern Docker Desktop, and the Engine plugin and `dmr` binary are under Apache-2.0 only",
          "The API reference shows the Anthropic route as /anthropic/v1/messages in its table and /v1/messages in its examples. The source registers both"
        ]
      },
      "negative": -3,
      "negativeNotes": [
        "2026-02-27. GHSA-m456-c56c-hh5c (CVE-2026-28400, 7.5). The unauthenticated `/engines/_configure` route accepted arbitrary runtime flags, so a caller, including a container on Docker Desktop, could overwrite files the runner could reach, the Desktop VM disk among them. Fixed in Model Runner 1.0.16 and Docker Desktop 4.61.0 and published by Docker, more than six months ago, -2. https://github.com/docker/model-runner/security/advisories/GHSA-m456-c56c-hh5c",
        "2026-03-30. GHSA-x2f5-332j-9xwq (CVE-2026-33990, 7.1). A malicious OCI registry could point the token exchange at an internal URL and make the runner send GET requests to host-local services. Fixed in 1.1.25 and Docker Desktop 4.67.0 and published by Docker, more than six months ago, -1. https://github.com/docker/model-runner/security/advisories/GHSA-x2f5-332j-9xwq"
      ],
      "verdict": "CI passes on the main branch, and Docker has published two security advisories with CVEs and fixed versions for the project. The API takes no credential, so any client or container that reaches it can pull, delete and run models, and the documentation has no OpenAPI file or error reference.",
      "bestFor": "A team that already runs Docker and wants local models served to containers and Compose services through OpenAI-, Anthropic- or Ollama-compatible routes, with models stored as OCI artefacts.",
      "strengths": [
        "OpenAI-, Anthropic- and Ollama-compatible routes on one local port, so existing clients for those three APIs work with a changed base URL",
        "CI runs lint, race-detector tests and end-to-end tests on every push to main, and the ten most recent runs on main passed on 8 October 2026",
        "Two GitHub security advisories with CVE numbers, fixed versions and workarounds, and a SECURITY.md that promises an acknowledgement within 72 hours",
        "Apache-2.0 source, and the docs list what usage data is collected with a link to the code that sends it",
        "Host-side TCP is off by default in Docker Desktop, and inference engines run sandboxed on macOS and Windows or in a container on Linux"
      ],
      "weaknesses": [
        "No credential on the API. The docs say any client that can reach it, including other containers, can pull, load and run models",
        "No OpenAPI file, no error reference and no rate-limit or retry guidance in the reviewed documentation",
        "Two releases in the 90 days to 8 October 2026 (v1.2.7 and v1.2.8), the latest on 12 August",
        "CVE-2026-28400 let an unauthenticated caller overwrite files, including the Docker Desktop VM disk, until 1.0.16 in February 2026",
        "On Docker Engine the docs say model-name requests go to Docker Hub regardless of settings, and the `DO_NOT_TRACK` switch in the source is undocumented"
      ],
      "agentNotes": [
        "Use base URL `http://localhost:12434/engines/v1` for OpenAI clients and `http://localhost:12434` for Anthropic and Ollama clients. Any API key value is accepted",
        "In Docker Desktop, run `docker desktop enable model-runner --tcp 12434` first. Host-side TCP is off by default",
        "From a container, call `http://model-runner.docker.internal` on Docker Desktop or `http://172.17.0.1:12434` on Docker Engine",
        "Raise the context before agent work with `docker model configure --context-size \u003cn\u003e \u003cmodel\u003e`. The llama.cpp default is 4,096 tokens",
        "Name models with their namespace, such as `ai/smollm2`, and expect plain-text error bodies with a 400, 404, 500 or 503 status"
      ],
      "metrics": {
        "kind": "local",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 57.1
        }
      ],
      "editorialScores": {
        "ergonomics": 58,
        "maintenance": 55,
        "payments": 60,
        "reliability": 85,
        "schema": 49,
        "security": 40,
        "transparency": 62
      },
      "provenanceScore": 84
    },
    "connect": {
      "install": "sudo apt-get update \u0026\u0026 sudo apt-get install docker-model-plugin   # Docker Engine on Ubuntu or Debian; Docker Desktop: docker desktop enable model-runner --tcp 12434\ndocker model pull ai/smollm2",
      "http": "curl http://localhost:12434/engines/v1/chat/completions \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"model\": \"ai/smollm2\",\n    \"messages\": [{\"role\": \"user\", \"content\": \"Say hello in one sentence.\"}]\n  }'",
      "claudeCode": "docker model launch claude"
    },
    "letme": {
      "capability": "https://letme.dev/inference.local",
      "tool": "https://letme.dev/docker-model-runner"
    },
    "sameCompany": [
      "docker-agent"
    ],
    "notable": [
      "The docs state that the API is not authenticated and that any client that can reach it, including other containers on the same Docker network, can pull, load and run models (https://docs.docker.com/ai/model-runner/)",
      "CVE-2026-28400 (7.5), published on 27 February 2026. The unauthenticated `/engines/_configure` route accepted arbitrary runtime flags and could overwrite files, fixed in 1.0.16 and Docker Desktop 4.61.0 (https://github.com/docker/model-runner/security/advisories/GHSA-m456-c56c-hh5c)",
      "CVE-2026-33990 (7.1), published on 30 March 2026. A malicious OCI registry could make the runner send GET requests to host-local services, fixed in 1.1.25 and Docker Desktop 4.67.0 (https://github.com/docker/model-runner/security/advisories/GHSA-x2f5-332j-9xwq)",
      "Usage tracking is a HEAD request to the registry with the model name and user agent. Docker Desktop's usage statistics setting turns it off, and the docs say Docker Engine sends it regardless of settings (https://docs.docker.com/ai/model-runner/; https://github.com/docker/model-runner/blob/main/pkg/metrics/metrics.go)",
      "The llama.cpp engine defaults to a 4,096-token context, changed per model with `docker model configure --context-size` (https://docs.docker.com/ai/model-runner/configuration/)",
      "A standalone `dmr` binary (dmr 0.1.0, 7 July 2026) runs the daemon and CLI without Docker Desktop or Docker Engine, on TCP port 12434 by default (https://github.com/docker/model-runner)",
      "`docker model launch` starts AnythingLLM, Claude Code, Codex, OpenClaw, OpenCode or Open WebUI configured to use the local runner (https://github.com/docker/model-runner/blob/main/cmd/cli/docs/reference/model_launch.md)"
    ],
    "area": "models",
    "details": [
      {
        "label": "Interfaces",
        "value": "`docker model` CLI plugin (39 documented commands and subcommands), Docker Desktop Models tab, standalone `dmr` binary, local HTTP API on port 12434 or a Unix socket, Docker Compose `models` element"
      },
      {
        "label": "Routes",
        "value": "OpenAI-compatible /engines/v1 (chat completions, completions, embeddings, models), Anthropic-compatible /anthropic/v1/messages and count_tokens, Ollama-compatible /api (tags, show, chat, generate), image generation at /engines/diffusers/v1/images/generations, and native /models for pull, list, inspect and delete. The source also registers a Responses API, rerank and score routes. No OpenAPI file"
      },
      {
        "label": "Credentials",
        "value": "None. Host-side TCP off by default in Docker Desktop, on by default in Docker Engine. Cross-origin requests allowed from localhost, 127.0.0.1 and 0.0.0.0, widened with `DMR_ORIGINS`"
      },
      {
        "label": "Engines",
        "value": "llama.cpp for GGUF models on every platform (default), vLLM for Safetensors on Linux x86_64 and Windows with WSL2 with an NVIDIA GPU, Diffusers for image generation on Linux with an NVIDIA GPU"
      },
      {
        "label": "Hardware",
        "value": "macOS on Apple Silicon. Windows amd64 with NVIDIA drivers 576.57 or later, Windows arm64 with a Qualcomm Adreno 6xx or later GPU. Linux with CPU, NVIDIA CUDA (driver 575.57.08 or later), AMD ROCm or Vulkan"
      },
      {
        "label": "Models",
        "value": "Pulled as OCI artefacts from Docker Hub (the `ai/` namespace) or any OCI registry, or from Hugging Face with `hf.co/` names. `docker model package` and `push` publish GGUF and Safetensors files"
      },
      {
        "label": "Defaults",
        "value": "llama.cpp context of 4,096 tokens. Models load on first request and unload when idle. Requests above 10 MiB are refused"
      },
      {
        "label": "Isolation",
        "value": "Engines run in a container on Linux and in a sandbox on macOS (seatbelt) and Windows (Job Objects). Runtime flags are checked against an allowlist"
      },
      {
        "label": "What leaves the machine",
        "value": "Prompts and responses don't, per the docs. A HEAD request to the registry carries the model name and user agent, off with Docker Desktop's usage statistics setting or `DO_NOT_TRACK=1` in the source"
      },
      {
        "label": "Observability",
        "value": "`docker model logs`, `docker model requests` (the last 10 requests per model in the source) and a Prometheus `/metrics` route, off with `DISABLE_METRICS=1`"
      },
      {
        "label": "Releases in 90 days",
        "value": "2 (v1.2.7 on 11 August and v1.2.8 on 12 August 2026)"
      },
      {
        "label": "Security record",
        "value": "CVE-2026-28400 (7.5, fixed in 1.0.16) and CVE-2026-33990 (7.1, fixed in 1.1.25), both published as GitHub advisories"
      }
    ],
    "provenance": {
      "legalEntity": "Docker, Inc.",
      "domain": "docker.com",
      "domainRegistered": "1995-01-25",
      "endpointOnVendorDomain": null,
      "terms": "https://www.docker.com/legal/docker-subscription-service-agreement/",
      "privacy": "https://www.docker.com/legal/privacy/",
      "statusPage": "",
      "changelog": "https://github.com/docker/model-runner/releases",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The repository is under GitHub's docker organisation and SECURITY.md sends reports to security@docker.com. The subscription agreement and privacy policy both name Docker, Inc.",
        "Docker publishes no terms written for Model Runner. The Docker Subscription Service Agreement (last updated 26 August 2026) governs Docker Desktop, which bundles it, and the privacy policy carries the same date. The Engine plugin and the `dmr` binary are under Apache-2.0 only.",
        "www.docker.com/.well-known/security.txt gives security@docker.com, a policy URL and an expiry of 1 January 2030.",
        "No status page is listed because the software runs on the owner's machine.",
        "RDAP for docker.com gives a registration date of 1995-01-25."
      ],
      "score": 84,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Docker, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "docker.com, registered 1995-01-25 (31 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "no hosted endpoint",
          "points": 0,
          "max": 0,
          "state": "na"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 6,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.docker.com/legal/docker-subscription-service-agreement/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-08-26",
          "words": 9421,
          "points": 6,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated on August 26, 2026",
              "says": "Last updated 2026-08-26"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "The laws of the State of California and controlling United States federal law.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "NOTWITHSTANDING ANYTHING ELSE IN THE AGREEMENT, DOCKER’S MAXIMUM AGGREGATE LIABILITY TO CUSTOMER FOR SUCH SERVICES SHALL NOT EXCEED THE GREATER OF (A) ONE-HUNDRED DOLLARS ($100) OR (B) THE FEES PAID BY CUSTOMER FOR SUCH TRIAL SERVICES.",
              "says": "Capped at $100"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Docker may modify or terminate Customer’s right to use Trial Services at any time and for any reason in its sole discretion."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Docker may modify these terms from time to time, with notice to Customer in accordance with Section 18.2 (Legal Notices) or by posting the modified terms on our website.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "The Services are not designed, and Customer shall not use the Services as a basis, to deploy systems that must be hardened or highly secure except to the extent supported by DHI, or involve mission-critical business operations, the operation of nuclear facilities, aircraft navigation, important communication systems,…"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "During the Subscription Term, Docker will provide support for the Services in accordance with the Service Level Agreement \u0026 Terms available at https://www.docker.com/support/ as applicable to the products and support purchased via an Order Form."
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "Use any robot, spider, site search/retrieval application, or other device to retrieve or index any portion of the Services or the content posted thereon or to collect information about its users for any unauthorized purpose;",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "access the Services for the purpose of developing or operating products or services intended to be offered to third parties in competition with the Services or exploit the Services for any unauthorized commercial purpose",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Users with an account that is inactive for more than six (6) months may be terminated at Docker’s discretion and without further notice."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "Any dispute, controversy or claim arising under, out of or relating to this Agreement, will be finally determined by arbitration conducted by JAMS"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Docker accepts no liability for the customer's use of Output or for any autonomous or semi-autonomous action taken by an AI Feature.",
              "quote": "NOTWITHSTANDING ANYTHING TO THE CONTRARY IN THIS AGREEMENT, DOCKER WILL HAVE NO LIABILITY OR RESPONSIBILITY FOR CUSTOMER’S OR ITS USERS’ USE OF OUTPUT OR ANY AUTONOMOUS OR SEMI-AUTONOMOUS ACTION."
            },
            {
              "date": "2026-10-08",
              "text": "The customer indemnifies Docker against third-party claims arising from any action, Output, omission or decision of an AI Agent or AI Feature working on its behalf.",
              "quote": "any claim by a third party arising from or relating to any action, Output, omission, or decision by an AI Agent or AI Feature operating on behalf of, or initiated by, Customer or its Users"
            },
            {
              "date": "2026-10-08",
              "text": "The initial term renews automatically for 12-month periods unless a party gives at least 30 days' written notice before the current term ends.",
              "quote": "The Initial Term will automatically renew for additional 12-month periods unless a party provides at least 30 days’ written notice prior to the end of the then-current term that such party does not wish to renew for the upcoming term"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.docker.com/legal/privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-08-26",
          "words": 7523,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Update: August 26, 2026",
              "says": "Last updated 2026-08-26"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Where you subscribe to Docker’s self-service AI services as an individual, this Privacy Policy applies to the personal data we collect from you as described below;"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "earlier snapshots and images are deleted within 7 days.",
              "says": "Names a period of 7 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "(iv) credentials you choose to store — API keys and access tokens for third-party AI model providers and MCP-connected tools, which we store securely on your behalf in order to provide the Services;"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "In the preceding 12 months we did not sell or share for cross context behavioral advertising, the personal information of California residents.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "This includes the right to object to our processing of your personal data for direct marketing and the right to object to our processing of your personal data where we are performing a task in the public interest or pursuing our legitimate interests or those of a third party."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "You may also contact Docker by emailing privacy@docker.com or by sending postal mail to: Docker, Inc., 3790 El Camino Real # 1052, Palo Alto, CA 94306, (415) 941-0376",
              "says": "privacy@docker.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Data Privacy Framework, Docker is responsible for the processing of personal data received from Customers from the EU, the UK, and Switzerland and onward transfers to a third party acting as an agent on our behalf.",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "A saved sandbox image or snapshot may contain the prompts and responses from the session.",
              "quote": "If you save a sandbox image or snapshot, it may contain prompts and responses from your session."
            },
            {
              "date": "2026-10-08",
              "text": "Docker stores the API keys and access tokens for third-party AI model providers and MCP-connected tools that a user chooses to store.",
              "quote": "API keys and access tokens for third-party AI model providers and MCP-connected tools, which we store securely on your behalf in order to provide the Services"
            },
            {
              "date": "2026-10-08",
              "text": "Docker gives its customers information on how particular domains access and use the Website, Services and particular functions or uploads.",
              "quote": "Docker also provides information on how particular domains (e.g., www.companyx.com ) access and use our Website, Services, and particular features or uploads to customers for their business purposes, for example, so they can improve or target their software and other offerings."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/docker-model-runner.json",
    "live": {
      "slug": "docker-model-runner",
      "pages": [
        {
          "url": "https://www.docker.com/pricing/",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-08T18:27:30.95553924Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "308829465f88"
        },
        {
          "url": "https://www.docker.com/legal/docker-subscription-service-agreement/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:27:24.912652297Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "f8cfdf3308dd"
        }
      ],
      "updatedAt": "2026-10-08T18:27:30.95553924Z"
    }
  }
}
