{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "text-generation-webui",
    "name": "TextGen",
    "vendor": "oobabooga",
    "vendorUrl": "https://github.com/oobabooga",
    "kind": "platform",
    "category": "local-ai",
    "summary": "Open-source desktop and browser app for running language models on the owner's hardware, formerly text-generation-webui. With `--api` it serves an OpenAI and Anthropic-compatible local API with tool calling, vision, embeddings and image generation.",
    "url": "https://www.anchorterminal.com/tools/text-generation-webui",
    "markdownUrl": "https://www.anchorterminal.com/tools/text-generation-webui.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/text-generation-webui.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/text-generation-webui.json",
    "repo": "https://github.com/oobabooga/textgen",
    "license": "AGPL-3.0",
    "transports": [
      "http"
    ],
    "packages": [],
    "auth": "api-key",
    "authNotes": "The API takes one optional key from `--api-key`, off by default, sent as `Authorization: Bearer` on the OpenAI routes and as `x-api-key` on `/v1/messages`. A second key from `--admin-key` guards model and LoRA loading, unloading and listing, and equals the API key when unset. Keys are set at launch, have no scopes and change only with a restart. Without `--listen` or `--public-api` the server binds 127.0.0.1, rejects other Host headers and limits CORS to localhost. The web UI has no login unless `--gradio-auth` is set.",
    "pricing": "free",
    "pricingNotes": "Free and AGPL-3.0, with no account, card or paid edition. Portable builds and source are on GitHub (checked 2026-10-08).",
    "priceSummary": "Free · OSS",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the README, the docs folder or the API source (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 47700,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://github.com/oobabooga/textgen/wiki",
    "capabilities": [
      "inference.local",
      "inference.open-weights",
      "agent.mcp-client",
      "embed.text",
      "image.generate"
    ],
    "tags": [
      "open-source",
      "local",
      "self-hosted",
      "free",
      "no-card",
      "account-free",
      "openai-compatible",
      "open-weights",
      "streaming",
      "mcp",
      "docker",
      "no-telemetry"
    ],
    "lastRelease": "2026-05-20",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 45.1,
      "grade": "E",
      "agentReady": false,
      "rank": 775,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 15,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 50,
        "maintenance": 24,
        "payments": 60,
        "reliability": 51,
        "schema": 61,
        "security": 40,
        "transparency": 49
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 51,
          "points": 10.2,
          "reason": "Read with the local-software lines, since TextGen runs on the owner's machine with no hosted service. Portable builds for Linux, Windows and macOS on GitHub releases, a one-click installer, a venv route for Python 3.9 or later, a Conda route on Python 3.13 and Docker files, but no package on a registry (18 of 20). No test suite was found in the repository, and the seven workflows only build release packages on manual dispatch (3 of 25). 807 open issues and 40 open pull requests, no code commit on `main` or `dev` since 31 May 2026, and the newest open issues we saw (July to October 2026) carry between none and two comments (6 of 25). Versioned tags and GitHub release notes per version that list security fixes and behaviour changes, with no changelog file and no stated semver policy (9 of 15). v4.9 (15)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 61,
          "points": 9.91,
          "reason": "Read with the API lines. The server is a FastAPI app with default settings, so a running instance serves `/docs` and `/openapi.json` generated from 33 Pydantic classes in `modules/api/typing.py`, and the docs point callers there. No OpenAPI file is published, and we read the source without running the server (17 of 25). No llms.txt. The docs are Markdown files in the repository's docs folder, mirrored to the wiki (4 of 10). The API page is mostly examples with a compatibility table, and 36 fields in `typing.py` carry descriptions (10 of 20). Typed request models with defaults and a few range limits, while `tools` is a list of free-form objects (10 of 15). curl, Python and Node examples for chat, completions, streaming, tool calling, vision, images and model loading, with no error responses documented (9 of 15). A `/v1` prefix and release notes per version, with no changelog file (11 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 50,
          "points": 8.13,
          "reason": "Read with the API lines. `max_tokens` (512 by default on chat completions), `max_tokens_second`, a token-count route and a `max_tokens` argument on the built-in page fetcher size the output (17 of 25). `/v1/models` lists everything with the loaded model first, with no paging or filters (6 of 20). Errors are JSON in OpenAI's shape (`message`, `type`, `param`) or Anthropic's on `/v1/messages`, with 401, 400 and 422 used, but none are documented (11 of 20). Completions are stateless and safe to repeat, a client disconnect stops generation and `/v1/internal/stop-generation` exists. No retry guidance (7 of 20). A request needs only `messages`, with no model name, but the owner has to launch with `--api` and load a model. No SDK of its own, with OpenAI's Python and Node clients shown in the docs (9 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 40,
          "points": 7,
          "reason": "Read with the tool checklist. One optional key from `--api-key`, off by default, sent as a Bearer token or `x-api-key` and never in a query string, with a separate `--admin-key` for loading and unloading models and LoRAs. No scopes or per-client keys, and a key changes only with a restart (14 of 30). Without `--listen` or `--public-api` the API binds 127.0.0.1, rejects other Host headers and limits CORS to localhost (since v4.9). The chat has a Confirm tool calls setting, off by default, and the web UI has no login unless `--gradio-auth` is set (10 of 20). The built-in page fetcher refuses non-global addresses on every redirect hop. No guidance on injected instructions in web or tool results was found (5 of 15). The docs say the API creates no logs and the server runs with access logs off. `--verbose` prints prompts to the terminal (3 of 15). No SECURITY.md, security.txt or bounty. Ten advisories are published on GitHub with patched versions, one with a CVE (8 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 60,
          "points": 7.5,
          "reason": "Self-hosted rule. No x402, MPP or L402 (0). Free and AGPL-3.0 with no account, card or paid edition, so 20, 20 and 20 on the last three lines."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 24,
          "points": 2.1,
          "reason": "v4.9 on 20 May 2026, 141 days before this check (10). No release in the last 90 days (0). No code commit on `main` since 31 May 2026 (one README edit on 17 August) and none on `dev` since 16 May. 807 open issues and 40 open pull requests, and the newest open issues show few or no comments. Comment authors didn't render for our reader, so maintainer replies are unconfirmed (5 of 25). No SDK and no MCP registry entry. Portable builds shipped with each release up to May (5 of 15). A weekly Dependabot config with its update branches unmerged, no test CI, and the bundled llama.cpp last updated on 31 May (4 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 49,
          "points": 4.29,
          "note": "editorial 70, provenance 27",
          "reason": "AGPL-3.0 for the whole repository (30). No privacy policy or terms exist, and there's no hosted service. The README states that the app is fully offline with zero telemetry, external resources or remote update requests, the API page says it creates no logs, and the source turns Gradio analytics off. A Check for updates button calls api.github.com when clicked, which the README's wording doesn't mention (18 of 30). No deprecation policy. Release notes record behaviour changes, and the rename to TextGen left a redirect from the old repository URL (4 of 20). No telemetry to opt out of, and analytics are disabled in `server.py` (18 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Read with the API lines. `max_tokens` (512 by default on chat completions), `max_tokens_second`, a token-count route and a `max_tokens` argument on the built-in page fetcher size the output (17 of 25). `/v1/models` lists everything with the loaded model first, with no paging or filters (6 of 20). Errors are JSON in OpenAI's shape (`message`, `type`, `param`) or Anthropic's on `/v1/messages`, with 401, 400 and 422 used, but none are documented (11 of 20). Completions are stateless and safe to repeat, a client disconnect stops generation and `/v1/internal/stop-generation` exists. No retry guidance (7 of 20). A request needs only `messages`, with no model name, but the owner has to launch with `--api` and load a model. No SDK of its own, with OpenAI's Python and Node clients shown in the docs (9 of 15).",
          "maintenance": "v4.9 on 20 May 2026, 141 days before this check (10). No release in the last 90 days (0). No code commit on `main` since 31 May 2026 (one README edit on 17 August) and none on `dev` since 16 May. 807 open issues and 40 open pull requests, and the newest open issues show few or no comments. Comment authors didn't render for our reader, so maintainer replies are unconfirmed (5 of 25). No SDK and no MCP registry entry. Portable builds shipped with each release up to May (5 of 15). A weekly Dependabot config with its update branches unmerged, no test CI, and the bundled llama.cpp last updated on 31 May (4 of 10).",
          "payments": "Self-hosted rule. No x402, MPP or L402 (0). Free and AGPL-3.0 with no account, card or paid edition, so 20, 20 and 20 on the last three lines.",
          "reliability": "Read with the local-software lines, since TextGen runs on the owner's machine with no hosted service. Portable builds for Linux, Windows and macOS on GitHub releases, a one-click installer, a venv route for Python 3.9 or later, a Conda route on Python 3.13 and Docker files, but no package on a registry (18 of 20). No test suite was found in the repository, and the seven workflows only build release packages on manual dispatch (3 of 25). 807 open issues and 40 open pull requests, no code commit on `main` or `dev` since 31 May 2026, and the newest open issues we saw (July to October 2026) carry between none and two comments (6 of 25). Versioned tags and GitHub release notes per version that list security fixes and behaviour changes, with no changelog file and no stated semver policy (9 of 15). v4.9 (15).",
          "schema": "Read with the API lines. The server is a FastAPI app with default settings, so a running instance serves `/docs` and `/openapi.json` generated from 33 Pydantic classes in `modules/api/typing.py`, and the docs point callers there. No OpenAPI file is published, and we read the source without running the server (17 of 25). No llms.txt. The docs are Markdown files in the repository's docs folder, mirrored to the wiki (4 of 10). The API page is mostly examples with a compatibility table, and 36 fields in `typing.py` carry descriptions (10 of 20). Typed request models with defaults and a few range limits, while `tools` is a list of free-form objects (10 of 15). curl, Python and Node examples for chat, completions, streaming, tool calling, vision, images and model loading, with no error responses documented (9 of 15). A `/v1` prefix and release notes per version, with no changelog file (11 of 15).",
          "security": "Read with the tool checklist. One optional key from `--api-key`, off by default, sent as a Bearer token or `x-api-key` and never in a query string, with a separate `--admin-key` for loading and unloading models and LoRAs. No scopes or per-client keys, and a key changes only with a restart (14 of 30). Without `--listen` or `--public-api` the API binds 127.0.0.1, rejects other Host headers and limits CORS to localhost (since v4.9). The chat has a Confirm tool calls setting, off by default, and the web UI has no login unless `--gradio-auth` is set (10 of 20). The built-in page fetcher refuses non-global addresses on every redirect hop. No guidance on injected instructions in web or tool results was found (5 of 15). The docs say the API creates no logs and the server runs with access logs off. `--verbose` prints prompts to the terminal (3 of 15). No SECURITY.md, security.txt or bounty. Ten advisories are published on GitHub with patched versions, one with a CVE (8 of 20).",
          "transparency": "AGPL-3.0 for the whole repository (30). No privacy policy or terms exist, and there's no hosted service. The README states that the app is fully offline with zero telemetry, external resources or remote update requests, the API page says it creates no logs, and the source turns Gradio analytics off. A Check for updates button calls api.github.com when clicked, which the README's wording doesn't mention (18 of 30). No deprecation policy. Release notes record behaviour changes, and the rename to TextGen left a redirect from the old repository URL (4 of 20). No telemetry to opt out of, and analytics are disabled in `server.py` (18 of 20)."
        },
        "sources": [
          {
            "what": "repository and README",
            "url": "https://github.com/oobabooga/textgen",
            "seen": "2026-10-08"
          },
          {
            "what": "releases",
            "url": "https://github.com/oobabooga/textgen/releases",
            "seen": "2026-10-08"
          },
          {
            "what": "security tab and advisories",
            "url": "https://github.com/oobabooga/textgen/security",
            "seen": "2026-10-08"
          },
          {
            "what": "advisory GHSA-jg96-p5p6-q3cv",
            "url": "https://github.com/oobabooga/textgen/security/advisories/GHSA-jg96-p5p6-q3cv",
            "seen": "2026-10-08"
          },
          {
            "what": "advisory GHSA-4p45-76cc-7p62",
            "url": "https://github.com/oobabooga/textgen/security/advisories/GHSA-4p45-76cc-7p62",
            "seen": "2026-10-08"
          },
          {
            "what": "advisory GHSA-fpwc-4mvr-7jpr",
            "url": "https://github.com/oobabooga/textgen/security/advisories/GHSA-fpwc-4mvr-7jpr",
            "seen": "2026-10-08"
          },
          {
            "what": "advisory GHSA-r2qq-p5wg-gf5g",
            "url": "https://github.com/oobabooga/textgen/security/advisories/GHSA-r2qq-p5wg-gf5g",
            "seen": "2026-10-08"
          },
          {
            "what": "open issues",
            "url": "https://github.com/oobabooga/textgen/issues",
            "seen": "2026-10-08"
          },
          {
            "what": "API docs (wiki)",
            "url": "https://github.com/oobabooga/textgen/wiki/12-%E2%80%90-OpenAI-API",
            "seen": "2026-10-08"
          },
          {
            "what": "API docs (source)",
            "url": "https://github.com/oobabooga/textgen/blob/main/docs/12%20-%20OpenAI%20API.md",
            "seen": "2026-10-08"
          },
          {
            "what": "tool calling and MCP tutorial",
            "url": "https://github.com/oobabooga/textgen/blob/main/docs/Tool%20Calling%20Tutorial.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API server source",
            "url": "https://github.com/oobabooga/textgen/blob/main/modules/api/script.py",
            "seen": "2026-10-08"
          },
          {
            "what": "request models",
            "url": "https://github.com/oobabooga/textgen/blob/main/modules/api/typing.py",
            "seen": "2026-10-08"
          },
          {
            "what": "web fetch validation",
            "url": "https://github.com/oobabooga/textgen/blob/main/modules/web_search.py",
            "seen": "2026-10-08"
          },
          {
            "what": "update check source",
            "url": "https://github.com/oobabooga/textgen/blob/main/modules/ui_session.py",
            "seen": "2026-10-08"
          },
          {
            "what": "workflows",
            "url": "https://github.com/oobabooga/textgen/tree/main/.github/workflows",
            "seen": "2026-10-08"
          },
          {
            "what": "dev branch",
            "url": "https://github.com/oobabooga/textgen/tree/dev",
            "seen": "2026-10-08"
          },
          {
            "what": "licence",
            "url": "https://github.com/oobabooga/textgen/blob/main/LICENSE",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "Whether development has paused. No release since 20 May 2026 and no code commit since 31 May, with no notice in the README",
          "unchecked: maintainer replies on recent issues. Comment threads didn't render for our reader",
          "unchecked: `/docs` and `/openapi.json` on a running server. We read the FastAPI source and the docs and didn't run it",
          "unchecked: star, issue and pull request counts come from the repository page as our reader saw it. GitHub's API refused us for a shared rate limit",
          "No terms of use or privacy policy exist for the project, so `provenance.terms` and `provenance.privacy` are left out",
          "The developer publishes under a pseudonym and no legal entity is named",
          "The first release date wasn't established, since the clone was shallow"
        ]
      },
      "negative": -4,
      "negativeNotes": [
        "2026-03-18. Two Critical advisories at 9.1. GHSA-jg96-p5p6-q3cv (CVE-2026-35050) let a user of the web UI write Python files through a path traversal in extension settings and run them, in 4.1 and earlier, fixed in 4.1.1. GHSA-4p45-76cc-7p62 let a caller write or delete files through a character name on instances started with `--listen`, fixed in 4.0. Both fixed and published, -2. https://github.com/oobabooga/textgen/security/advisories/GHSA-jg96-p5p6-q3cv",
        "2026-03-18. GHSA-fpwc-4mvr-7jpr (High, 7.1). `/v1/chat/completions` and `/v1/completions` fetched any `image_url` from the server side, so a caller could reach internal addresses, in 4.1 and earlier. Fixed in 4.1.1 and published, -1. https://github.com/oobabooga/textgen/security/advisories/GHSA-fpwc-4mvr-7jpr",
        "2025-10-13 to 2026-04-03. Seven more advisories in the year, four High and three Moderate, among them a file read through an uploaded symbolic link, four path traversals in preset, grammar, template and prompt loading, an SSRF in the superbooga extensions and a Gradio path-check bypass fixed in 4.3. All published with fixes, -1. https://github.com/oobabooga/textgen/security"
      ],
      "verdict": "AGPL-3.0 with no telemetry, and a local API on 127.0.0.1:5000 that checks the Host header, limits CORS to localhost and separates an admin key from the caller's key. No release since v4.9 on 20 May 2026, no code commits since 31 May, no test suite, and ten security advisories in the year, all fixed.",
      "bestFor": "A person who wants one app for several backends (llama.cpp, ExLlamaV3, Transformers) with an OpenAI and Anthropic-compatible endpoint, LoRA training and image generation.",
      "strengths": [
        "AGPL-3.0, with analytics switched off in the source and a README that states zero telemetry",
        "One server answers `/v1/chat/completions`, `/v1/completions` and Anthropic's `/v1/messages`, with tool calling and streaming",
        "Since v4.9 the API rejects Host headers other than localhost and 127.0.0.1 and limits CORS to localhost unless `--listen` or `--public-api` is set",
        "A separate `--admin-key` guards model and LoRA loading, apart from the `--api-key` callers use",
        "Ten security advisories published on GitHub with patched versions named, the newest on 3 April 2026"
      ],
      "weaknesses": [
        "No release since v4.9 on 20 May 2026 and no code commit on `main` or `dev` since 31 May 2026",
        "No test suite. The seven GitHub workflows only build release packages on manual dispatch",
        "807 open issues and 40 open pull requests, with no SECURITY.md or disclosure address",
        "Two Critical advisories (9.1) published on 18 March 2026, both path traversals in the web UI, fixed in 4.0 and 4.1.1",
        "The API key is off by default, set only at launch, and has no scopes or per-client keys",
        "No rate limits, error list or published OpenAPI file in the docs. The schema is served only by a running server at `/docs`"
      ],
      "agentNotes": [
        "Ask the owner to launch with `--api`. Nothing listens on port 5000 without it, and a model must be loaded first",
        "Call `http://127.0.0.1:5000/v1`. Any Host header other than localhost or 127.0.0.1 gets 400 `Invalid host header` unless `--listen` is set",
        "Send the key as `Authorization: Bearer` on OpenAI routes and as `x-api-key` on `/v1/messages`. Model loading needs the admin key",
        "Read `http://127.0.0.1:5000/docs` or `modules/api/typing.py` for parameters. `max_tokens` defaults to 512 on chat completions",
        "Run tool calls yourself. The API returns `finish_reason: \"tool_calls\"` and executes nothing on the server",
        "Use the repository name `oobabooga/textgen`. The old `text-generation-webui` URL redirects"
      ],
      "metrics": {
        "kind": "local",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "E",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 45.1
        }
      ],
      "editorialScores": {
        "ergonomics": 50,
        "maintenance": 24,
        "payments": 60,
        "reliability": 51,
        "schema": 61,
        "security": 40,
        "transparency": 70
      },
      "provenanceScore": 27
    },
    "connect": {
      "install": "git clone https://github.com/oobabooga/textgen\ncd textgen\npython -m venv venv\nsource venv/bin/activate\npip install -r requirements/portable/requirements.txt --upgrade\npython server.py --portable --api --auto-launch",
      "http": "curl http://127.0.0.1:5000/v1/chat/completions \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"messages\": [{\"role\": \"user\", \"content\": \"Hello!\"}], \"temperature\": 0.6, \"top_p\": 0.95, \"top_k\": 20}'"
    },
    "letme": {
      "capability": "https://letme.dev/inference.local",
      "tool": "https://letme.dev/text-generation-webui"
    },
    "notable": [
      "The repository was renamed from oobabooga/text-generation-webui to oobabooga/textgen and the product is now called TextGen. The old URL redirects (https://github.com/oobabooga/textgen)",
      "v4.9 of 20 May 2026 is the latest release. `main` has had one commit since 31 May 2026, a README edit on 17 August, and `dev` stops on 16 May (https://github.com/oobabooga/textgen/releases)",
      "Ten security advisories are published, from 13 October 2025 to 3 April 2026, two of them Critical at 9.1 (GHSA-jg96-p5p6-q3cv, CVE-2026-35050, and GHSA-4p45-76cc-7p62), all with patched versions (https://github.com/oobabooga/textgen/security)",
      "v4.9 restricted the API's CORS to localhost by default, and the server rejects Host headers other than localhost and 127.0.0.1 unless `--listen` or `--public-api` is set (https://github.com/oobabooga/textgen/blob/main/modules/api/script.py)",
      "The app is an MCP client for HTTP servers (typed into the chat sidebar) and stdio servers (`user_data/mcp.json`). A Confirm tool calls setting exists and is off by default (https://github.com/oobabooga/textgen/blob/main/docs/Tool%20Calling%20Tutorial.md)",
      "Gradio analytics are disabled in `server.py`, and the only request to the developer's side found in the source is a Check for updates button that calls api.github.com when clicked (https://github.com/oobabooga/textgen/blob/main/modules/ui_session.py)"
    ],
    "area": "models",
    "details": [
      {
        "label": "Interfaces",
        "value": "Electron desktop window in the portable builds (Linux, Windows, macOS, with CUDA, Vulkan, ROCm and CPU-only options), a Gradio web UI at 127.0.0.1:7860, and a local HTTP API on port 5000 when `--api` is set"
      },
      {
        "label": "API routes",
        "value": "`/v1/chat/completions`, `/v1/completions`, `/v1/messages`, `/v1/models`, `/v1/embeddings`, `/v1/images/generations`, `/v1/moderations`, `/v1/audio/transcriptions`, plus `/v1/internal/*` for token counts, logits, stopping generation and loading models and LoRAs"
      },
      {
        "label": "Auth",
        "value": "Optional `--api-key` and `--admin-key`, off by default, as Bearer or `x-api-key`. Host-header check and localhost-only CORS unless `--listen` or `--public-api`"
      },
      {
        "label": "Backends",
        "value": "llama.cpp, ik_llama.cpp, Transformers, ExLlamaV3 and TensorRT-LLM. The portable builds run GGUF models only"
      },
      {
        "label": "Tools and MCP",
        "value": "Five built-in tools in `user_data/tools` (web_search, fetch_webpage, calculate, get_datetime, roll_dice), custom tools as single `.py` files, and MCP servers over HTTP or stdio. Over the API the caller runs the tools"
      },
      {
        "label": "Telemetry",
        "value": "None, per the README. Gradio analytics are off in the source. A manual Check for updates button calls api.github.com"
      },
      {
        "label": "Embeddings",
        "value": "`/v1/embeddings` is marked alpha and needs `sentence-transformers`, with all-mpnet-base-v2 by default"
      },
      {
        "label": "Releases in 90 days",
        "value": "None. v4.0 on 7 March 2026 to v4.9 on 20 May 2026, then nothing"
      },
      {
        "label": "Former name",
        "value": "text-generation-webui, also known as oobabooga. The repository is now oobabooga/textgen"
      }
    ],
    "provenance": {
      "legalEntity": "",
      "domain": "github.com/oobabooga",
      "domainRegistered": "",
      "endpointOnVendorDomain": null,
      "terms": "",
      "privacy": "",
      "statusPage": "",
      "changelog": "https://github.com/oobabooga/textgen/releases",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The project belongs to a developer who publishes as oobabooga. The LICENSE is the AGPL-3.0 text and names no legal entity, and the README acknowledges a grant from Andreessen Horowitz in August 2023.",
        "No vendor domain. The README links only the GitHub repository, its wiki, a subreddit, a Substack and a Hugging Face space.",
        "No terms of use and no privacy policy were found in the repository, the README or the wiki, so both fields are left out. The README states zero telemetry.",
        "No SECURITY.md (the Security tab says none is set up) and no security.txt of the project's own.",
        "There's no hosted endpoint. The API answers on the owner's machine, at 127.0.0.1:5000 by default."
      ],
      "score": 27,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "not found",
          "points": 0,
          "max": 20,
          "state": "no"
        },
        {
          "check": "Domain age",
          "value": "github.com/oobabooga, no registry record we could read",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "no hosted endpoint",
          "points": 0,
          "max": 0,
          "state": "na"
        },
        {
          "check": "Terms of service",
          "value": "nothing hosted, so the AGPL-3.0 licence stands in",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "nothing hosted, not scored",
          "points": 0,
          "max": 0,
          "state": "na"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/text-generation-webui.json"
  }
}
