{
  "data": {
    "a": {
      "slug": "ghost-core",
      "name": "Core",
      "vendor": "Ghost (ZMJ, Inc.)",
      "vendorUrl": "https://ghost.ai",
      "kind": "platform",
      "category": "local-ai",
      "summary": "Core is a personal AI computer from Ghost that runs open-weight language models and a memory of the owner's apps, files and devices at home, used through Ghost's apps and an OpenAI Responses-compatible endpoint. On pre-order.",
      "url": "https://www.anchorterminal.com/tools/ghost-core",
      "markdownUrl": "https://www.anchorterminal.com/tools/ghost-core.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ghost-core.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ghost-core.json",
      "license": "Not stated. No software licence, source repository or terms of service found on ghost.ai (checked 2026-10-05). Models listed are Qwen 3.8-Next, Qwen 3.8-27B, Gemma 4-31B and Muse-Glimmer-30B. Ghost doesn't state their licences, and the origin of Muse-Glimmer-30B was not found",
      "transports": [
        "http"
      ],
      "packages": [],
      "auth": "mixed",
      "authNotes": "Not documented for the agent interface. Ghost's FAQ says Core exposes an endpoint compatible with the OpenAI Responses API but gives no address, port or authentication method, so keyless use isn't established. The Ghost app pairs with Core over the local network, remote access is for paired devices, and Ghost keeps device authorisation records. Online services use Ghost's gateway or the owner's own provider API keys. The privacy policy mentions device-access controls without detail (https://ghost.ai/core, https://ghost.ai/setup, https://ghost.ai/privacy, checked 2026-10-05).",
      "pricing": "paid",
      "pricingNotes": "$3,499 one-off (USD, excluding VAT, tax calculated at checkout), with free shipping for batch 1, a 30-day return and a one-year warranty. Ghost states no subscription and no per-token inference fees. Some online services (web search, phone calls) run through Ghost-managed services with daily usage limits whose numbers aren't published, or through the owner's own API keys. Batch 1 showed sold out at 23:31 UTC on 5 October 2026, with a batch 2 interest form in place of the order button (https://ghost.ai/core, https://ghost.ai/privacy, https://ghost.ai/api/stock).",
      "priceSummary": "Paid",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 on ghost.ai or in its site code (checked 2026-10-05). Orders go through Stripe Checkout.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-05"
      },
      "docsUrl": "https://ghost.ai/setup",
      "capabilities": [
        "inference.local",
        "inference.open-weights",
        "memory.user",
        "memory.search",
        "memory.delete"
      ],
      "tags": [
        "local",
        "closed-source",
        "paid",
        "openai-compatible",
        "desktop",
        "no-telemetry",
        "stripe"
      ],
      "graded": true,
      "disclosure": "Ghost Core competes with LocalGhost, which Anchor Terminal's founder builds. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
      "competesWith": "localghost",
      "anchor": {
        "graded": true,
        "score": 7.3,
        "grade": "F",
        "agentReady": false,
        "rank": 460,
        "ranked": true,
        "rankOf": 460,
        "categoryRank": 13,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 4,
          "maintenance": 3,
          "payments": 10,
          "reliability": 5,
          "schema": 7,
          "security": 6,
          "transparency": 45
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-05"
        },
        "negative": -2,
        "negativeNotes": [
          "2026-10-05. Ghost's home page says 'No data ever leaves your home' and 'Everything you do with Core is run locally' (seen at 23:31 UTC on 5 October 2026), and the FAQ says Core processes data 'entirely on-device', while the privacy policy, effective 4 October 2026, says web search, phone calls and email requests go through Ghost's gateway to third-party providers that may keep them unless the owner sets their own keys, and that remote access runs through Ghost's relay. A misleading claim, weighed as Screenpipe's README claim was. The policy and the FAQ's internet answer disclose the online services, they carry task requests rather than default-on analytics, and Core hadn't shipped, so the minimum, -2. https://ghost.ai/ ; https://ghost.ai/core ; https://ghost.ai/privacy"
        ],
        "verdict": "Ghost's privacy policy sets out what stays on Core, what passes through its gateway and relay, and how long Ghost keeps each record. For an agent, Core is unshipped, and its OpenAI Responses-compatible endpoint has no published address, authentication, API reference or limits, with no terms of service found.",
        "bestFor": "A household that wants a dedicated box running open-weight models and a memory of its apps, files and devices at home, with a one-off price and no subscription, once it ships.",
        "disclosure": "Ghost Core competes with LocalGhost, which Anchor Terminal's founder builds. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
        "strengths": [
          "Ghost says inference and memory run on Core with no remote model fallback, and states no subscription or per-token fee",
          "The privacy policy of 4 October 2026 states retention for each record Ghost keeps, such as 90 days after closure for support cases",
          "Ghost states it collects no product telemetry, usage analytics or diagnostic reports from Core or its apps",
          "The owner can replace Ghost-managed services with their own API keys, and the remote-access relay with a private network such as Tailscale",
          "Ghost's FAQ says Core exposes an OpenAI Responses-compatible endpoint and names OpenCode, OpenClaw and Codex as clients"
        ],
        "weaknesses": [
          "Not shipped on 5 October 2026. Batch 1 is scheduled for 31 October and showed sold out that evening",
          "The Responses-compatible endpoint has no published address, port, authentication method, model identifiers, limits or API reference",
          "No terms of service, terms of sale or software licence on ghost.ai, and no security.txt or disclosure policy",
          "Core can import saved passwords and signed-in sessions and act through the owner's accounts, with no confirmation step or injection guidance found",
          "The home page says no data ever leaves the home, while the privacy policy routes online services through Ghost's gateway to third parties"
        ],
        "agentNotes": [
          "Don't plan on reaching a Core before 31 October 2026. Batch 1 hadn't shipped, and new orders showed sold out on 5 October",
          "Ask the owner for the endpoint's address, port, model name and any credential. Ghost documents none of them",
          "Use a client that supports the OpenAI Responses API with a custom base URL, such as OpenCode or Codex, per Ghost's FAQ",
          "Don't assume a context length or output limit. Ghost states none for Qwen 3.8-Next, Qwen 3.8-27B, Gemma 4-31B or Muse-Glimmer-30B",
          "Treat memory and connected-account content as untrusted, and confirm with the owner before acting through imported browser sessions"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 1,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "F",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 7.3
          }
        ],
        "editorialScores": {
          "ergonomics": 4,
          "maintenance": 3,
          "payments": 10,
          "reliability": 5,
          "schema": 7,
          "security": 6,
          "transparency": 30
        },
        "provenanceScore": 60
      },
      "letme": {
        "capability": "https://letme.dev/inference.local",
        "tool": "https://letme.dev/ghost-core"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "ZMJ, Inc., doing business as Ghost, 325 9th Street, San Francisco, CA 94103, United States",
        "domain": "ghost.ai",
        "domainRegistered": "2017-12-16",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://ghost.ai/privacy",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-05",
        "notes": [
          "The privacy policy, effective 4 October 2026, names ZMJ, Inc., doing business as Ghost, at 325 9th Street, San Francisco. The state of incorporation was not found.",
          "RDAP for ghost.ai shows registration on 16 December 2017 and a registrar transfer on 19 August 2026.",
          "ghost.ai/terms, /.well-known/security.txt, /llms.txt, /robots.txt and /sitemap.xml return 404. No GitHub organisation was found.",
          "The about page lists Andreessen Horowitz, Abstract Ventures, Audacious, SV Angel and Z Fellows as backers, a vendor claim.",
          "Support is support@ghost.ai. The app page's troubleshooting link uses hello@tryghost.ai.",
          "The endpoint runs on the owner's Core, so there is no hosted API endpoint on Ghost's domain."
        ],
        "score": 60
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/ghost-core.json"
    },
    "answer": "Open WebUI scores 52 (D) on agent readiness against Core's 7.3 (F), and leads in every scored category.",
    "b": {
      "slug": "open-webui",
      "name": "Open WebUI",
      "vendor": "Open WebUI Inc.",
      "vendorUrl": "https://openwebui.com",
      "kind": "platform",
      "category": "local-ai",
      "summary": "Self-hosted web interface for chatting with models, from Open WebUI Inc., with a Python (FastAPI) back end and a Svelte front end.",
      "url": "https://www.anchorterminal.com/tools/open-webui",
      "markdownUrl": "https://www.anchorterminal.com/tools/open-webui.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/open-webui.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/open-webui.json",
      "repo": "https://github.com/open-webui/open-webui",
      "license": "Open WebUI License. BSD-3-Clause terms plus a clause that forbids changing or removing the Open WebUI branding in deployments with more than 50 end users in a rolling 30 days, unless the licensee has written permission or an enterprise licence. Code from before set commits stays under MIT or BSD-3-Clause (LICENSE_HISTORY), and contributors sign a CLA",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "open-webui"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/open-webui/open-webui"
        }
      ],
      "auth": "api-key",
      "authNotes": "Sign-in is on by default (`WEBUI_AUTH`), the first account to sign up becomes admin, and sign-up then closes. An agent calls the API with `Authorization: Bearer \u003ctoken\u003e`, either an `sk-` API key from Settings \u003e Account or a session JWT, which lasts four weeks by default (`JWT_EXPIRES_IN`), and behind a reverse proxy that uses `Authorization` itself the key can go in an `x-api-key` header (https://docs.openwebui.com/reference/api-endpoints). API keys stay off until an administrator turns them on (`ENABLE_API_KEYS` defaults to false), a group permission decides who may create one, and they can be limited instance-wide to listed endpoints with `ENABLE_API_KEYS_ENDPOINT_RESTRICTIONS` and `API_KEYS_ALLOWED_ENDPOINTS` (https://github.com/open-webui/open-webui/blob/main/backend/open_webui/config.py). Each user has one key, `sk-` plus 32 hexadecimal characters, stored as plain text with a last-used time and no expiry set by the API (https://github.com/open-webui/open-webui/blob/main/backend/open_webui/routers/auths.py). People sign in with email and password, OAuth or OIDC, LDAP or trusted headers, with SCIM 2.0 provisioning.",
      "pricing": "free",
      "pricingNotes": "Free to self-host under the Open WebUI License. Deployments with more than 50 end users in a rolling 30 days have to keep the Open WebUI branding unless they hold an enterprise licence or written permission. The enterprise licence (white-labelling, SLA-backed support, Terminals) is sold through sales to registered organisations only, with no published prices (https://docs.openwebui.com/enterprise). There's no hosted Open WebUI service. You pay your model provider, or nothing with a local model (checked 2026-10-03).",
      "priceSummary": "Free",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 153000,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://docs.openwebui.com",
      "llmsTxt": "https://docs.openwebui.com/llms.txt",
      "capabilities": [
        "inference.local",
        "agent.mcp-client",
        "memory.user",
        "knowledge.search"
      ],
      "tags": [
        "self-hosted",
        "local",
        "free",
        "python",
        "docker",
        "openai-compatible",
        "llms-txt",
        "enterprise"
      ],
      "lastRelease": "2026-09-21",
      "graded": true,
      "disclosure": "Open WebUI competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
      "competesWith": "localghost",
      "anchor": {
        "graded": true,
        "score": 52,
        "grade": "D",
        "agentReady": false,
        "rank": 352,
        "ranked": true,
        "rankOf": 460,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 54,
          "maintenance": 91,
          "payments": 20,
          "reliability": 68,
          "schema": 60,
          "security": 63,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -8,
        "negativeNotes": [
          "2026-05-05. GHSA-2r4p-jpmg-48f4 (CVE-2026-44551, Critical, 9.1). LDAP sign-in accepted an empty password where the directory allows unauthenticated binds, giving full access to the victim's account. It affects 0.8.12 and earlier and was fixed in 0.9.0 (21 April 2026) before publication, -2. https://github.com/open-webui/open-webui/security/advisories/GHSA-2r4p-jpmg-48f4",
          "2026-07-02. GHSA-74h3-cxq7-vc5q (CVE-2026-59216, 7.7). A signed-in low-privilege user could run code and tools in another user's session through an unchecked Socket.IO session_id, which against an administrator meant code execution as the server process (root in default containers). Fixed in 0.10.0 on 29 June 2026 and published three days later, -2. https://github.com/open-webui/open-webui/security/advisories/GHSA-74h3-cxq7-vc5q",
          "2026-08-02 and 2026-09-04. Two account takeovers through OAuth, both High. GHSA-rq84-p6rr-vf89 accepted tokens issued to any client in the OAuth token exchange (fixed in 0.11.0), and GHSA-wpmr-8h3q-fwj7 (8.1) matched OAuth and OIDC subjects by substring on SQLite, so a crafted subject could sign in as an existing account, administrators included (fixed in 0.11.1 on 25 August). Both fixed before publication, -2. https://github.com/open-webui/open-webui/security/advisories/GHSA-rq84-p6rr-vf89; https://github.com/open-webui/open-webui/security/advisories/GHSA-wpmr-8h3q-fwj7",
          "2025-10-03 to 2026-10-03. The rest of the year's record. GitHub reviewed 143 of the repository's advisories in the 12 months to 3 October 2026, and 129 cover flaws fixed in releases from 0.6.35 (6 November 2025) on, 58 High and 1 Critical, more than half of them access-control or authorisation flaws by their titles and CWE tags. July to September alone brought 52 (18 High, 29 Moderate, 5 Low) in batches published on 2 July, 2 August and 4 September. Each was fixed in a release before publication, so the 125 beyond the four above count together, -2. https://github.com/open-webui/open-webui/security/advisories; https://github.com/advisories?query=open-webui+type%3Areviewed+ecosystem%3Apip"
        ],
        "verdict": "Five releases in the 90 days to 3 October 2026, each with a dated changelog entry that warns of database migrations. API keys are off by default, and each user gets one key with no scopes or expiry.",
        "bestFor": "A household or team that wants one chat interface over local and hosted models, with shared knowledge bases, memories, tools and access control, on their own server.",
        "disclosure": "Open WebUI competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
        "strengths": [
          "Five releases in the 90 days to 3 October 2026, each with a dated changelog entry that warns of database migrations",
          "OpenAI-compatible `/api/chat/completions` and `/api/models`, plus an Anthropic Messages route and an Ollama proxy, so OpenAI's SDKs work against a local instance",
          "Roles, groups, per-model and per-knowledge access grants, a group permission for key creation and an instance-wide endpoint allowlist for keys",
          "An audit log at metadata, request or request-and-response level, plus events for key creation and deletion",
          "No product telemetry found, third-party analytics off in the Docker image, and `OFFLINE_MODE` to stop the release check and model downloads"
        ],
        "weaknesses": [
          "API keys are off by default, and each user gets one key with no scopes or expiry",
          "The API reference covers seven route groups, and the OpenAPI file and Swagger UI need `ENV=dev`",
          "52 advisories published from July to September 2026, 18 of them High, including cross-user code execution (CVE-2026-59216) and two OAuth account takeovers, all fixed",
          "Pre-1.0 (0.11), with database migrations in patch releases and no rolling updates during them",
          "The branding clause makes the licence non-OSI, and the enterprise licence has no published price"
        ],
        "agentNotes": [
          "Ask the administrator to set `ENABLE_API_KEYS=true` and let your group create keys. `sk-` keys are refused until then",
          "Send OpenAI's request shape to `/api/chat/completions` with a Bearer key, or use `x-api-key` behind a proxy that takes `Authorization` for itself",
          "Call `/api/models` first and use an `id` from it. Model IDs depend on the instance's connections",
          "Poll `GET /api/v1/files/{id}/process/status` until it reads `completed` before adding a file to a knowledge base",
          "Expect a 403 on routes outside `API_KEYS_ALLOWED_ENDPOINTS` when the administrator has set an allowlist"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 52
          }
        ],
        "editorialScores": {
          "ergonomics": 54,
          "maintenance": 91,
          "payments": 20,
          "reliability": 68,
          "schema": 60,
          "security": 63,
          "transparency": 66
        },
        "provenanceScore": 79
      },
      "connect": {
        "install": "pip install open-webui \u0026\u0026 open-webui serve   # or: docker run -d -p 3000:8080 --add-host=host.docker.internal:host-gateway -v open-webui:/app/backend/data --name open-webui --restart always ghcr.io/open-webui/open-webui:main",
        "http": "curl -X POST http://localhost:3000/api/chat/completions \\\n  -H \"Authorization: Bearer $OPEN_WEBUI_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"model\": \"llama3.1\", \"messages\": [{\"role\": \"user\", \"content\": \"Why is the sky blue?\"}]}'"
      },
      "letme": {
        "capability": "https://letme.dev/inference.local",
        "tool": "https://letme.dev/open-webui"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "Open WebUI Inc.",
        "domain": "openwebui.com",
        "domainRegistered": "2024-02-17",
        "endpointOnVendorDomain": null,
        "terms": "https://openwebui.com/terms",
        "privacy": "https://openwebui.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/open-webui/open-webui/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-03",
        "notes": [
          "The LICENSE copyright line names Open WebUI Inc., created by Timothy Jaeryang Baek, and the privacy policy names Open WebUI, Inc. with no address.",
          "openwebui.com/.well-known/security.txt points to GitHub Security Advisories and expires on 2027-06-30.",
          "The privacy policy, last updated on 31 December 2025, covers openwebui.com and its community services only, says nothing about the self-hosted software, and gives no retention periods.",
          "We found no status page linked from openwebui.com. There's no hosted service, so an instance answers on its owner's own host.",
          "RDAP for openwebui.com gives a registration date of 2024-02-17, registrar Cloudflare. The terms page wasn't read for this check."
        ],
        "score": 79
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/open-webui.json",
      "live": {
        "slug": "open-webui",
        "versions": [
          {
            "registry": "github",
            "name": "open-webui/open-webui",
            "version": "v0.11.4",
            "released": "2026-09-21",
            "seenAt": "2026-10-05T17:00:37.347836173Z"
          },
          {
            "registry": "pypi",
            "name": "open-webui",
            "version": "0.11.4",
            "released": "2026-09-21",
            "seenAt": "2026-10-05T17:00:37.169423179Z"
          }
        ],
        "githubStars": 154000,
        "pypiWeekly": 235140,
        "securityTxt": {
          "url": "https://openwebui.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-06-30T00:00:00Z",
          "checkedAt": "2026-10-05T15:16:29.243842934Z"
        },
        "llmsTxt": {
          "url": "https://docs.openwebui.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-05T15:19:17.910887564Z"
        },
        "domain": {
          "domain": "openwebui.com",
          "registered": "2024-02-17",
          "source": "https://rdap.verisign.com/com/v1/domain/openwebui.com",
          "checkedAt": "2026-10-04T13:06:48.742159254Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/open-webui/open-webui/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-05T16:00:05.721068231Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3c27bf8cc8f9"
          },
          {
            "url": "https://openwebui.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-05T15:58:49.392398424Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ab8757357aa3"
          },
          {
            "url": "https://openwebui.com/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-05T15:58:51.959304921Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "87cd832136e7"
          }
        ],
        "updatedAt": "2026-10-05T17:00:37.347836173Z"
      }
    },
    "facts": [
      {
        "a": "Model platform",
        "b": "Model platform",
        "name": "Kind"
      },
      {
        "a": "Ghost (ZMJ, Inc.)",
        "b": "Open WebUI Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Not stated. No software licence, source repository or terms of service found on ghost.ai (checked 2026-10-05). Models listed are Qwen 3.8-Next, Qwen 3.8-27B, Gemma 4-31B and Muse-Glimmer-30B. Ghost doesn't state their licences, and the origin of Muse-Glimmer-30B was not found",
        "b": "Open WebUI License. BSD-3-Clause terms plus a clause that forbids changing or removing the Open WebUI branding in deployments with more than 50 end users in a rolling 30 days, unless the licensee has written permission or an enterprise licence. Code from before set commits stays under MIT or BSD-3-Clause (LICENSE_HISTORY), and contributors sign a CLA",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "none",
        "b": "2026-09-21",
        "name": "Last release"
      },
      {
        "a": "none",
        "b": "153k stars",
        "name": "Popularity"
      },
      {
        "a": "2/5 (1)",
        "b": "2.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Open WebUI scores 52 (D) on agent readiness against Core's 7.3 (F), and leads in every scored category.",
        "question": "Which is better for AI agents, Core or Open WebUI?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": null,
        "goodFor": "A household that wants a dedicated box running open-weight models and a memory of its apps, files and devices at home, with a one-off price and no subscription, once it ships.",
        "slug": "ghost-core",
        "watchFor": "Not shipped on 5 October 2026. Batch 1 is scheduled for 31 October and showed sold out that evening"
      },
      {
        "aheadOn": [
          "Reliability, 68 against 5",
          "Schema \u0026 documentation, 60 against 7",
          "Agent ergonomics, 54 against 4",
          "Security \u0026 auth, 63 against 6",
          "Payments \u0026 pricing, 20 against 10",
          "Maintenance \u0026 community, 91 against 3",
          "Transparency \u0026 trust, 73 against 45"
        ],
        "also": null,
        "goodFor": "A household or team that wants one chat interface over local and hosted models, with shared knowledge bases, memories, tools and access control, on their own server.",
        "slug": "open-webui",
        "watchFor": "API keys are off by default, and each user gets one key with no scopes or expiry"
      }
    ],
    "job": {
      "capability": "inference.local",
      "name": "Local inference"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/anythingllm-vs-ghost-core.json",
        "title": "AnythingLLM vs Core",
        "url": "https://www.anchorterminal.com/compare/anythingllm-vs-ghost-core"
      },
      {
        "json": "https://www.anchorterminal.com/compare/anythingllm-vs-open-webui.json",
        "title": "AnythingLLM vs Open WebUI",
        "url": "https://www.anchorterminal.com/compare/anythingllm-vs-open-webui"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-core-vs-gpt4all.json",
        "title": "Core vs GPT4All",
        "url": "https://www.anchorterminal.com/compare/ghost-core-vs-gpt4all"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-core-vs-jan.json",
        "title": "Core vs Jan",
        "url": "https://www.anchorterminal.com/compare/ghost-core-vs-jan"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-core-vs-khoj.json",
        "title": "Core vs Khoj",
        "url": "https://www.anchorterminal.com/compare/ghost-core-vs-khoj"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-core-vs-llama-cpp.json",
        "title": "Core vs llama.cpp",
        "url": "https://www.anchorterminal.com/compare/ghost-core-vs-llama-cpp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-core-vs-lm-studio.json",
        "title": "Core vs LM Studio",
        "url": "https://www.anchorterminal.com/compare/ghost-core-vs-lm-studio"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-core-vs-localai.json",
        "title": "Core vs LocalAI",
        "url": "https://www.anchorterminal.com/compare/ghost-core-vs-localai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-core-vs-ollama.json",
        "title": "Core vs Ollama",
        "url": "https://www.anchorterminal.com/compare/ghost-core-vs-ollama"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-core-vs-screenpipe.json",
        "title": "Core vs screenpipe",
        "url": "https://www.anchorterminal.com/compare/ghost-core-vs-screenpipe"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gpt4all-vs-open-webui.json",
        "title": "GPT4All vs Open WebUI",
        "url": "https://www.anchorterminal.com/compare/gpt4all-vs-open-webui"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jan-vs-open-webui.json",
        "title": "Jan vs Open WebUI",
        "url": "https://www.anchorterminal.com/compare/jan-vs-open-webui"
      },
      {
        "json": "https://www.anchorterminal.com/compare/khoj-vs-open-webui.json",
        "title": "Khoj vs Open WebUI",
        "url": "https://www.anchorterminal.com/compare/khoj-vs-open-webui"
      },
      {
        "json": "https://www.anchorterminal.com/compare/llama-cpp-vs-open-webui.json",
        "title": "llama.cpp vs Open WebUI",
        "url": "https://www.anchorterminal.com/compare/llama-cpp-vs-open-webui"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lm-studio-vs-open-webui.json",
        "title": "LM Studio vs Open WebUI",
        "url": "https://www.anchorterminal.com/compare/lm-studio-vs-open-webui"
      },
      {
        "json": "https://www.anchorterminal.com/compare/localai-vs-open-webui.json",
        "title": "LocalAI vs Open WebUI",
        "url": "https://www.anchorterminal.com/compare/localai-vs-open-webui"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ollama-vs-open-webui.json",
        "title": "Ollama vs Open WebUI",
        "url": "https://www.anchorterminal.com/compare/ollama-vs-open-webui"
      },
      {
        "json": "https://www.anchorterminal.com/compare/open-webui-vs-screenpipe.json",
        "title": "Open WebUI vs screenpipe",
        "url": "https://www.anchorterminal.com/compare/open-webui-vs-screenpipe"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-core-vs-underdog.json",
        "title": "Core vs Underdog",
        "url": "https://www.anchorterminal.com/compare/ghost-core-vs-underdog"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-core-vs-localghost.json",
        "title": "Core vs LocalGhost",
        "url": "https://www.anchorterminal.com/compare/ghost-core-vs-localghost"
      }
    ],
    "scores": [
      {
        "by": 63,
        "edge": "open-webui",
        "ghost-core": 5,
        "key": "reliability",
        "name": "Reliability",
        "open-webui": 68,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 53,
        "edge": "open-webui",
        "ghost-core": 7,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "open-webui": 60,
        "weight": 13
      },
      {
        "by": 50,
        "edge": "open-webui",
        "ghost-core": 4,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "open-webui": 54,
        "weight": 13
      },
      {
        "by": 57,
        "edge": "open-webui",
        "ghost-core": 6,
        "key": "security",
        "name": "Security \u0026 auth",
        "open-webui": 63,
        "weight": 14
      },
      {
        "by": 10,
        "edge": "open-webui",
        "ghost-core": 10,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "open-webui": 20,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 88,
        "edge": "open-webui",
        "ghost-core": 3,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "open-webui": 91,
        "weight": 7
      },
      {
        "by": 28,
        "edge": "open-webui",
        "ghost-core": 45,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "open-webui": 73,
        "weight": 7
      }
    ],
    "summary": "Open WebUI scores 52 (D) on agent readiness against Core's 7.3 (F), and leads in every scored category. Both do local inference.",
    "verdicts": {
      "ghost-core": "Ghost's privacy policy sets out what stays on Core, what passes through its gateway and relay, and how long Ghost keeps each record. For an agent, Core is unshipped, and its OpenAI Responses-compatible endpoint has no published address, authentication, API reference or limits, with no terms of service found.",
      "open-webui": "Five releases in the 90 days to 3 October 2026, each with a dated changelog entry that warns of database migrations. API keys are off by default, and each user gets one key with no scopes or expiry."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/ghost-core-vs-open-webui",
    "json": "https://www.anchorterminal.com/compare/ghost-core-vs-open-webui.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/ghost-core-vs-open-webui.md",
    "slim": "https://www.anchorterminal.com/compare/ghost-core-vs-open-webui.min.md"
  },
  "markdown": "Open WebUI scores 52 (D) on agent readiness against Core's 7.3 (F), and leads in every scored category. Both do local inference.\n\n- Core: grade F, 7.3/100, rank #460 of 460. Markdown https://www.anchorterminal.com/tools/ghost-core.md · JSON https://www.anchorterminal.com/api/v1/tools/ghost-core.json\n- Open WebUI: grade D, 52/100, rank #352 of 460. Markdown https://www.anchorterminal.com/tools/open-webui.md · JSON https://www.anchorterminal.com/api/v1/tools/open-webui.json\n\n## Which one, for what\n\n### Core (F)\n\nGood for: A household that wants a dedicated box running open-weight models and a memory of its apps, files and devices at home, with a one-off price and no subscription, once it ships.\n\nWatch for: Not shipped on 5 October 2026. Batch 1 is scheduled for 31 October and showed sold out that evening\n\n### Open WebUI (D)\n\nGood for: A household or team that wants one chat interface over local and hosted models, with shared knowledge bases, memories, tools and access control, on their own server.\n\nAhead on:\n- Reliability, 68 against 5\n- Schema \u0026 documentation, 60 against 7\n- Agent ergonomics, 54 against 4\n- Security \u0026 auth, 63 against 6\n- Payments \u0026 pricing, 20 against 10\n- Maintenance \u0026 community, 91 against 3\n- Transparency \u0026 trust, 73 against 45\n\nWatch for: API keys are off by default, and each user gets one key with no scopes or expiry\n\n\n## Score by category\n\n| Category | Weight | Core | Open WebUI | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 5 | 68 | Open WebUI +63 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 7 | 60 | Open WebUI +53 |\n| Agent ergonomics | 13% (16.2 this run) | 4 | 54 | Open WebUI +50 |\n| Security \u0026 auth | 14% (17.5 this run) | 6 | 63 | Open WebUI +57 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 10 | 20 | Open WebUI +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 3 | 91 | Open WebUI +88 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 45 | 73 | Open WebUI +28 |\n| Negative events | ≤15 | -2 | -8 | |\n| **Total** | | **7.3 · F** | **52 · D** | |\n\n## Facts side by side\n\n| Fact | Core | Open WebUI |\n| --- | --- | --- |\n| Kind | Model platform | Model platform |\n| Vendor | Ghost (ZMJ, Inc.) | Open WebUI Inc. |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Paid | Free |\n| x402 | no | no |\n| Licence | Not stated. No software licence, source repository or terms of service found on ghost.ai (checked 2026-10-05). Models listed are Qwen 3.8-Next, Qwen 3.8-27B, Gemma 4-31B and Muse-Glimmer-30B. Ghost doesn't state their licences, and the origin of Muse-Glimmer-30B was not found | Open WebUI License. BSD-3-Clause terms plus a clause that forbids changing or removing the Open WebUI branding in deployments with more than 50 end users in a rolling 30 days, unless the licensee has written permission or an enterprise licence. Code from before set commits stays under MIT or BSD-3-Clause (LICENSE_HISTORY), and contributors sign a CLA |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| Last release | none | 2026-09-21 |\n| Popularity | none | 153k stars |\n| Agent reviews | 2/5 (1) | 2.5/5 (2) |\n\n## Verdicts\n\n**Core.** Ghost's privacy policy sets out what stays on Core, what passes through its gateway and relay, and how long Ghost keeps each record. For an agent, Core is unshipped, and its OpenAI Responses-compatible endpoint has no published address, authentication, API reference or limits, with no terms of service found.\n\n**Open WebUI.** Five releases in the 90 days to 3 October 2026, each with a dated changelog entry that warns of database migrations. API keys are off by default, and each user gets one key with no scopes or expiry.\n\n## Before you call either\n\n### Core\n\n1. Don't plan on reaching a Core before 31 October 2026. Batch 1 hadn't shipped, and new orders showed sold out on 5 October\n2. Ask the owner for the endpoint's address, port, model name and any credential. Ghost documents none of them\n3. Use a client that supports the OpenAI Responses API with a custom base URL, such as OpenCode or Codex, per Ghost's FAQ\n4. Don't assume a context length or output limit. Ghost states none for Qwen 3.8-Next, Qwen 3.8-27B, Gemma 4-31B or Muse-Glimmer-30B\n5. Treat memory and connected-account content as untrusted, and confirm with the owner before acting through imported browser sessions\n\n### Open WebUI\n\n1. Ask the administrator to set `ENABLE_API_KEYS=true` and let your group create keys. `sk-` keys are refused until then\n2. Send OpenAI's request shape to `/api/chat/completions` with a Bearer key, or use `x-api-key` behind a proxy that takes `Authorization` for itself\n3. Call `/api/models` first and use an `id` from it. Model IDs depend on the instance's connections\n4. Poll `GET /api/v1/files/{id}/process/status` until it reads `completed` before adding a file to a knowledge base\n5. Expect a 403 on routes outside `API_KEYS_ALLOWED_ENDPOINTS` when the administrator has set an allowlist\n\n## Questions\n\n### Which is better for AI agents, Core or Open WebUI?\n\nOpen WebUI scores 52 (D) on agent readiness against Core's 7.3 (F), and leads in every scored category.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/ghost-core-vs-open-webui.json, and with the fewest tokens: https://www.anchorterminal.com/compare/ghost-core-vs-open-webui.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"ghost-core\", \"b\": \"open-webui\"}`. From a terminal: `anchor compare ghost-core open-webui`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/ghost-core.json and https://www.anchorterminal.com/api/v1/tools/open-webui.json\n\n## Other comparisons with Core or Open WebUI\n\n- [AnythingLLM vs Core](https://www.anchorterminal.com/compare/anythingllm-vs-ghost-core.md)\n- [AnythingLLM vs Open WebUI](https://www.anchorterminal.com/compare/anythingllm-vs-open-webui.md)\n- [Core vs GPT4All](https://www.anchorterminal.com/compare/ghost-core-vs-gpt4all.md)\n- [Core vs Jan](https://www.anchorterminal.com/compare/ghost-core-vs-jan.md)\n- [Core vs Khoj](https://www.anchorterminal.com/compare/ghost-core-vs-khoj.md)\n- [Core vs llama.cpp](https://www.anchorterminal.com/compare/ghost-core-vs-llama-cpp.md)\n- [Core vs LM Studio](https://www.anchorterminal.com/compare/ghost-core-vs-lm-studio.md)\n- [Core vs LocalAI](https://www.anchorterminal.com/compare/ghost-core-vs-localai.md)\n- [Core vs Ollama](https://www.anchorterminal.com/compare/ghost-core-vs-ollama.md)\n- [Core vs screenpipe](https://www.anchorterminal.com/compare/ghost-core-vs-screenpipe.md)\n- [GPT4All vs Open WebUI](https://www.anchorterminal.com/compare/gpt4all-vs-open-webui.md)\n- [Jan vs Open WebUI](https://www.anchorterminal.com/compare/jan-vs-open-webui.md)\n- [Khoj vs Open WebUI](https://www.anchorterminal.com/compare/khoj-vs-open-webui.md)\n- [llama.cpp vs Open WebUI](https://www.anchorterminal.com/compare/llama-cpp-vs-open-webui.md)\n- [LM Studio vs Open WebUI](https://www.anchorterminal.com/compare/lm-studio-vs-open-webui.md)\n- [LocalAI vs Open WebUI](https://www.anchorterminal.com/compare/localai-vs-open-webui.md)\n- [Ollama vs Open WebUI](https://www.anchorterminal.com/compare/ollama-vs-open-webui.md)\n- [Open WebUI vs screenpipe](https://www.anchorterminal.com/compare/open-webui-vs-screenpipe.md)\n- [Core vs Underdog](https://www.anchorterminal.com/compare/ghost-core-vs-underdog.md)\n- [Core vs LocalGhost](https://www.anchorterminal.com/compare/ghost-core-vs-localghost.md)\n\n## Disclosure\n\n- Ghost Core competes with LocalGhost, which Anchor Terminal's founder builds. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.\n- Open WebUI competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-06",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Core vs Open WebUI",
        "url": ""
      }
    ],
    "description": "Open WebUI scores 52 (D) on agent readiness against Core's 7.3 (F), and leads in every scored category. Both do local inference. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Core F 7.3",
      "Open WebUI D 52",
      "scores"
    ],
    "h1": "Core vs Open WebUI",
    "image": "https://www.anchorterminal.com/assets/og/compare-ghost-core-vs-open-webui.png",
    "path": "/compare/ghost-core-vs-open-webui",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Core vs Open WebUI for AI agents, F 7.3 vs D 52 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-06",
    "url": "https://www.anchorterminal.com/compare/ghost-core-vs-open-webui"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 680
  },
  "version": 1
}
