{
  "data": {
    "a": {
      "slug": "khoj",
      "name": "Khoj",
      "vendor": "Khoj Inc.",
      "vendorUrl": "https://khoj.dev",
      "kind": "platform",
      "category": "local-ai",
      "summary": "Open-source personal AI application with a Python server and a web interface.",
      "url": "https://www.anchorterminal.com/tools/khoj",
      "markdownUrl": "https://www.anchorterminal.com/tools/khoj.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/khoj.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/khoj.json",
      "repo": "https://github.com/khoj-ai/khoj",
      "license": "AGPL-3.0-or-later",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "khoj"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/khoj-ai/khoj"
        }
      ],
      "auth": "mixed",
      "authNotes": "The Docker Compose file and the pip quick start both run Khoj with `--anonymous-mode`, which serves every request as a default user with no sign-in and doesn't mount the /auth routes, so no API key can be created in that mode. The Compose file starts the server on 0.0.0.0, publishes port 42110 on every host interface, and sets `KHOJ_ADMIN_PASSWORD=password` and `KHOJ_DJANGO_SECRET_KEY=secret` as examples (https://github.com/khoj-ai/khoj/blob/master/docker-compose.yml). Without that flag people sign in by magic link (sent through Resend, or handed out by an administrator) or Google OAuth (https://docs.khoj.dev/advanced/authentication). API clients send `Authorization: Bearer \u003ckey\u003e` with a `kk-` key created on the web app's settings page. Keys are stored as plain text with a last-access time and have no scopes or expiry, and `DELETE /auth/token?token=\u003ckey\u003e` revokes one (https://github.com/khoj-ai/khoj/blob/master/src/khoj/configure.py; https://github.com/khoj-ai/khoj/blob/master/src/khoj/routers/auth.py). Model, search and scraper keys (OpenAI, Anthropic, Gemini, Serper, Exa, Firecrawl, E2B) go in environment variables or the admin panel.",
      "pricing": "free",
      "pricingNotes": "Free and AGPL-3.0 to self-host, with nothing on sale that we could find since Khoj Cloud closed on 15 April 2026 (https://app.khoj.dev). The README still links Khoj Enterprise at khoj.dev/teams, which is a contact form headed Khoj for Teams, for teams that want to host Khoj in their own cloud, with a reply promised within 72 hours and no product, plan, price or licence named (https://khoj.dev/teams). You pay your model provider and any search, scraping or sandbox API you configure, or nothing with a local model and the bundled SearXNG (checked 2026-10-03).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 37500,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://docs.khoj.dev",
      "capabilities": [
        "memory.search",
        "memory.user",
        "inference.local",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "free",
        "python",
        "docker",
        "beta",
        "telemetry-default-on"
      ],
      "lastRelease": "2026-03-26",
      "graded": true,
      "disclosure": "Khoj competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
      "competesWith": "localghost",
      "anchor": {
        "graded": true,
        "score": 38.8,
        "grade": "E",
        "agentReady": false,
        "rank": 426,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 10,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 46,
          "maintenance": 19,
          "payments": 60,
          "reliability": 65,
          "schema": 34,
          "security": 29,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -7,
        "negativeNotes": [
          "2026-07-13. Default-on telemetry sent the caller's IP (`client_host`) to khoj.beta.haletic.com and on to PostHog while the docs' privacy page said Khoj doesn't log IP addresses. Reported in #1374 and removed on master on 2 August 2026, but 1.42.10 and 2.0.0-beta.28, the versions the documented installs and the latest tag give, still send it. Request metadata rather than content, so the minimum, -2. https://github.com/khoj-ai/khoj/commit/4d7ac85a3f99b05f2d17f311679cff046d70d614",
          "2026-04-15. Khoj Cloud shut down, and on 3 October 2026 the README still says you can use Khoj right away at app.khoj.dev with no setup, the docs site still links to app.khoj.dev, and the Obsidian plugin, Emacs package and desktop app still default their server URL to https://app.khoj.dev. An endpoint removed while still advertised. The shutdown had three weeks' notice in the app, so the minimum, -3. https://github.com/khoj-ai/khoj/blob/master/README.md; https://github.com/khoj-ai/khoj/blob/master/src/interface/obsidian/src/settings.ts",
          "2026-02-01. CVE-2025-69207 (GHSA-6whj-7qmg-86qj, 5.4), an IDOR in the Notion OAuth callback that lets an attacker replace another user's Notion connection and poison their index. The check was hardened on 28 December 2025 and ships in 2.0.0-beta.23 and later, but the advisory lists no patched version, and 1.42.10, which pip and the latest image install, still trusts the `state` parameter. It needs a Notion OAuth app and more than one user, -1. https://github.com/khoj-ai/khoj/security/advisories/GHSA-6whj-7qmg-86qj",
          "2026-06-24. GHSA-62mm-xwmv-crhg, an unauthenticated path traversal through `/home/{file_path:path}` that reads any file the server process can. The route arrived in 2.0.0-beta.23 (29 December 2025) and was guarded in 2.0.0-beta.25 (22 February 2026), so two pre-releases were exposed and 1.42.10 never had the route. Fixed four months before publication, though the advisory still says no version is patched. Fixed and decayed, -1. https://github.com/khoj-ai/khoj/security/advisories/GHSA-62mm-xwmv-crhg; https://github.com/khoj-ai/khoj/commit/21c51b9a"
        ],
        "verdict": "AGPL-3.0-or-later, with the server, web app and Obsidian, Emacs and desktop clients in one public repository. No tagged release since 2.0.0-beta.28 on 26 March 2026 and no commit since 2 August.",
        "disclosure": "Khoj competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
        "strengths": [
          "AGPL-3.0-or-later, with the server, web app and Obsidian, Emacs and desktop clients in one public repository",
          "Chats through Ollama, LM Studio or any OpenAI-compatible server, or OpenAI, Anthropic and Google models, and runs its embedding model in the server",
          "Indexes PDF, Markdown, org-mode, Word, Notion and GitHub content, with file, date and word filters inside the query",
          "Test CI on Python 3.10 to 3.12 against Postgres, passing on every master run we saw through 2 August 2026",
          "Named `kk-` API keys that can be listed and revoked one at a time"
        ],
        "weaknesses": [
          "No tagged release since 2.0.0-beta.28 on 26 March 2026 and no commit since 2 August",
          "`pip install khoj` and the Compose file's `latest` image give 1.42.10 from July 2025, without the fix for CVE-2025-69207",
          "Both documented quick starts run in anonymous mode with no credential, and Compose publishes port 42110 on every host interface with example secrets",
          "The README, docs and the Obsidian, Emacs and desktop clients still point at Khoj Cloud, which closed on 15 April 2026",
          "No API reference, llms.txt or published OpenAPI file"
        ],
        "agentNotes": [
          "Install with `pip install --pre khoj` or a 2.0.0-beta image tag. Plain `pip install khoj` and `latest` give 1.42.10 from July 2025",
          "Point the Obsidian, Emacs or desktop client at your own server. They default to app.khoj.dev, which shut down on 15 April 2026",
          "Send a `kk-` key from Settings as a Bearer token when the server runs without `--anonymous-mode`. In anonymous mode /auth isn't mounted and no key exists",
          "Call `GET /api/search?q=...\u0026n=5` for passages and put `file:\"notes.md\"` or `dt\u003e=\"2026-01-01\"` inside `q` to filter. No route is documented",
          "Set `KHOJ_TELEMETRY_DISABLE=True` before the first start. Tagged releases send the caller's IP with telemetry"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 1,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 38.8
          }
        ],
        "editorialScores": {
          "ergonomics": 46,
          "maintenance": 19,
          "payments": 60,
          "reliability": 65,
          "schema": 34,
          "security": 29,
          "transparency": 60
        },
        "provenanceScore": 67
      },
      "connect": {
        "install": "python -m pip install 'khoj[local]'   # then: USE_EMBEDDED_DB=\"true\" khoj --anonymous-mode   # or: wget https://raw.githubusercontent.com/khoj-ai/khoj/master/docker-compose.yml \u0026\u0026 docker-compose up"
      },
      "letme": {
        "capability": "https://letme.dev/memory.search",
        "tool": "https://letme.dev/khoj"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "Khoj Inc.",
        "domain": "khoj.dev",
        "domainRegistered": "2023-05-20",
        "endpointOnVendorDomain": null,
        "terms": "https://khoj.dev/terms-of-service.html",
        "privacy": "https://khoj.dev/privacy-policy.html",
        "statusPage": "",
        "changelog": "https://github.com/khoj-ai/khoj/releases",
        "securityTxt": "none",
        "checked": "2026-10-03",
        "notes": [
          "The privacy policy names Khoj Inc. as the operator of khoj.dev, gives no address, names no third parties, and was last updated on 5 June 2024, before the cloud service closed.",
          "khoj.dev/.well-known/security.txt returns 404 per the listing's check. The repository has no SECURITY.md and GitHub says the project has not set one up. Private vulnerability reporting is on, with six advisories published.",
          "RDAP for khoj.dev gives a registration date of 2023-05-20, registrar Cloudflare.",
          "There's no hosted endpoint since Khoj Cloud closed on 15 April 2026. A self-hosted server answers on its owner's own host."
        ],
        "score": 67
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/khoj.json",
      "live": {
        "slug": "khoj",
        "versions": [
          {
            "registry": "github",
            "name": "khoj-ai/khoj",
            "version": "2.0.0-beta.28",
            "released": "2026-03-26",
            "seenAt": "2026-10-04T16:30:51.951568389Z"
          },
          {
            "registry": "pypi",
            "name": "khoj",
            "version": "1.42.10",
            "released": "2025-07-15",
            "seenAt": "2026-10-04T16:30:51.762954646Z"
          }
        ],
        "githubStars": 37560,
        "securityTxt": {
          "url": "https://khoj.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:02.115233077Z"
        },
        "domain": {
          "domain": "khoj.dev",
          "registered": "2023-05-20",
          "source": "https://pubapi.registry.google/rdap/domain/khoj.dev",
          "checkedAt": "2026-10-04T13:07:42.860690409Z"
        },
        "pages": [
          {
            "url": "https://khoj.dev/privacy-policy.html",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:12.44696744Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c03103b79f52"
          },
          {
            "url": "https://khoj.dev/terms-of-service.html",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:14.556582845Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e08893bf1c28"
          }
        ],
        "updatedAt": "2026-10-04T16:30:51.951568389Z"
      }
    },
    "b": {
      "slug": "llama-cpp",
      "name": "llama.cpp",
      "vendor": "ggml.ai (Hugging Face)",
      "vendorUrl": "https://llama.app",
      "kind": "http-api",
      "category": "local-ai",
      "summary": "Open-source C/C++ engine for running GGUF models locally, with a web interface and compatible model APIs.",
      "url": "https://www.anchorterminal.com/tools/llama-cpp",
      "markdownUrl": "https://www.anchorterminal.com/tools/llama-cpp.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/llama-cpp.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/llama-cpp.json",
      "repo": "https://github.com/ggml-org/llama.cpp",
      "license": "MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "ghcr.io/ggml-org/llama.cpp"
        },
        {
          "registry": "pypi",
          "name": "gguf"
        }
      ],
      "auth": "none",
      "authNotes": "No credential by default. `--api-key` (one key or a comma-separated list) or `--api-key-file` (one key a line) turns on a check for every route but /health and the web UI's files, with the key sent as `Authorization: Bearer` or `X-Api-Key`, never in the query string. Keys have no scopes and change only with a restart. TLS is built in with `--ssl-key-file` and `--ssl-cert-file`. The server binds 127.0.0.1:8080 by default, and CORS reflects any Origin with credentials allowed unless built-in tools, MCP servers or `--agent` are on, when it narrows to localhost (https://github.com/ggml-org/llama.cpp/blob/master/tools/server/README.md).",
      "pricing": "free",
      "pricingNotes": "Free under MIT, with no account, key or card. Nothing is sold. You pay for your own hardware and electricity.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 130200,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://github.com/ggml-org/llama.cpp/blob/master/tools/server/README.md",
      "capabilities": [
        "inference.local",
        "inference.open-weights",
        "embed.text",
        "rerank",
        "inference.decision",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "local",
        "self-hosted",
        "free",
        "no-card",
        "openai-compatible",
        "docker",
        "pre-1.0",
        "no-telemetry"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.2,
        "grade": "C",
        "agentReady": false,
        "rank": 253,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 3,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 81,
          "payments": 60,
          "reliability": 64,
          "schema": 47,
          "security": 52,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -1,
        "negativeNotes": [
          "2026-03-26. GHSA-j8rj-fmpv-wcxw (CVE-2026-34159, 9.8 at NVD), unauthenticated code execution through a GRAPH_COMPUTE bypass in the RPC backend, the most serious of four advisories published between January and March 2026 (the others a llama-server out-of-bounds write through a negative `n_discard` and two GGUF integer overflows). All were fixed in named builds and published as advisories, SECURITY.md says not to expose the RPC server or llama-server to untrusted networks, and the newest is more than six months old, -1. https://github.com/ggml-org/llama.cpp/security/advisories/GHSA-j8rj-fmpv-wcxw; https://github.com/ggml-org/llama.cpp/security"
        ],
        "verdict": "MIT, with no telemetry or update check in the source, and `--offline` blocks model downloads. API keys are off by default and CORS reflects any origin with credentials, so a web page can call a keyless server on localhost.",
        "strengths": [
          "MIT, with no telemetry or update check in the source, and `--offline` blocks model downloads",
          "OpenAI chat completions, responses and embeddings, Anthropic messages, reranking and /v1/systemone from one server",
          "`response_fields`, `json_schema` and `grammar` control the size and shape of output, and errors carry an OpenAI-style type and code",
          "1,005 nightly builds and eight semver releases in 90 days, with 37 workflows running on every push to master",
          "Ten published GitHub advisories with CVEs and fixed builds, and SECURITY.md guidance on untrusted models and inputs"
        ],
        "weaknesses": [
          "API keys are off by default and CORS reflects any origin with credentials, so a web page can call a keyless server on localhost",
          "No OpenAPI file of its own, and the REST API changelog stops at b4599",
          "Private security disclosure disabled since 1 June 2026, with fixes asked for as public pull requests",
          "Pre-1.0 (0.5.0), and semver releases are bare tags with no notes",
          "No official client library, and `n_predict` defaults to unlimited"
        ],
        "agentNotes": [
          "Start the server with `--api-key` and `--cors-origins localhost` before anything else can reach the port. Both are off by default",
          "Pass `n_predict` or `max_tokens`. Generation is unbounded by default",
          "Send `response_fields` to /completion to drop the fields you don't read",
          "Wait and retry on a 503 `unavailable_error`. The model is still loading",
          "Read the server README of the build you run. Behaviour changes between nightly builds without a changelog entry"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.2
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 81,
          "payments": 60,
          "reliability": 64,
          "schema": 47,
          "security": 52,
          "transparency": 66
        },
        "provenanceScore": 53
      },
      "connect": {
        "install": "curl -LsSf https://llama.app/install.sh | sh   # or: brew install llama.cpp; winget install llama.cpp\nllama serve -hf ggml-org/Qwen3.5-0.8B-GGUF   # listens on 127.0.0.1:8080",
        "http": "curl --request POST \\\n    --url http://localhost:8080/completion \\\n    --header \"Content-Type: application/json\" \\\n    --data '{\"prompt\": \"Building a website can be done in 10 simple steps:\",\"n_predict\": 128}'"
      },
      "letme": {
        "capability": "https://letme.dev/inference.local",
        "tool": "https://letme.dev/llama-cpp"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "ggml.ai, part of Hugging Face since 2026",
        "domain": "llama.app",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/ggml-org/llama.cpp/releases",
        "securityTxt": "none",
        "checked": "2026-10-03",
        "notes": [
          "The repository's About link is llama.app, which says it's by the llama.cpp team and Hugging Face and links no terms, privacy or security page. ggml.ai says the company was acquired by Hugging Face in 2026 and names no address.",
          "The `LICENSE` file reads Copyright (c) 2023-2026 The ggml authors.",
          "llama.app/.well-known/security.txt and llama.app/llms.txt return 404. SECURITY.md points to GitHub private advisories while saying private disclosure is disabled.",
          "There's no shared hosted endpoint. The server runs on the owner's machine."
        ],
        "score": 53
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/llama-cpp.json",
      "live": {
        "slug": "llama-cpp",
        "versions": [
          {
            "registry": "github",
            "name": "ggml-org/llama.cpp",
            "version": "v0.5.0",
            "released": "2026-09-23",
            "seenAt": "2026-10-04T16:31:53.040249174Z"
          },
          {
            "registry": "pypi",
            "name": "gguf",
            "version": "0.19.0",
            "released": "2026-05-06",
            "seenAt": "2026-10-04T16:31:52.933067593Z"
          }
        ],
        "githubStars": 130286,
        "securityTxt": {
          "url": "https://llama.app/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:00.86400098Z"
        },
        "domain": {
          "domain": "llama.app",
          "registered": "2018-07-18",
          "source": "https://pubapi.registry.google/rdap/domain/llama.app",
          "checkedAt": "2026-10-04T13:04:03.05886804Z"
        },
        "updatedAt": "2026-10-04T16:31:53.040249174Z"
      }
    },
    "summary": "llama.cpp has a score of 60.2 (C) against Khoj's 38.8 (E). Both do local inference. The largest gap is maintenance \u0026 community, 62 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/khoj-vs-llama-cpp",
    "json": "https://www.anchorterminal.com/compare/khoj-vs-llama-cpp.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/khoj-vs-llama-cpp.md",
    "slim": "https://www.anchorterminal.com/compare/khoj-vs-llama-cpp.min.md"
  },
  "markdown": "llama.cpp has a score of 60.2 (C) against Khoj's 38.8 (E). Both do local inference. The largest gap is maintenance \u0026 community, 62 points.\n\n- Khoj: grade E, 38.8/100, rank #426 of 452. Markdown https://www.anchorterminal.com/tools/khoj.md · JSON https://www.anchorterminal.com/api/v1/tools/khoj.json\n- llama.cpp: grade C, 60.2/100, rank #253 of 452. Markdown https://www.anchorterminal.com/tools/llama-cpp.md · JSON https://www.anchorterminal.com/api/v1/tools/llama-cpp.json\n\n## Which one, for what\n\nPick Khoj for nothing in particular (no category where it leads by five points or more).\n\nPick llama.cpp for schema \u0026 documentation (+13), agent ergonomics (+27), security \u0026 auth (+23), maintenance \u0026 community (+62).\n\n## Score by category\n\n| Category | Weight | Khoj | llama.cpp | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 64 | Khoj +1 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 34 | 47 | llama.cpp +13 |\n| Agent ergonomics | 13% (16.2 this run) | 46 | 73 | llama.cpp +27 |\n| Security \u0026 auth | 14% (17.5 this run) | 29 | 52 | llama.cpp +23 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 60 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 19 | 81 | llama.cpp +62 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 64 | 60 | Khoj +4 |\n| Negative events | ≤15 | -7 | -1 | |\n| **Total** | | **38.8 · E** | **60.2 · C** | |\n\n## Facts side by side\n\n| Fact | Khoj | llama.cpp |\n| --- | --- | --- |\n| Kind | Model platform | HTTP API |\n| Vendor | Khoj Inc. | ggml.ai (Hugging Face) |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | None |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | AGPL-3.0-or-later | MIT |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| MCP registry | not listed | not listed |\n| Last release | 2026-03-26 | 2026-09-23 |\n| Popularity | 38k stars | 130k stars |\n| Agent reviews | 1/5 (2) | 2.5/5 (2) |\n\n## Verdicts\n\n**Khoj.** AGPL-3.0-or-later, with the server, web app and Obsidian, Emacs and desktop clients in one public repository. No tagged release since 2.0.0-beta.28 on 26 March 2026 and no commit since 2 August.\n\n**llama.cpp.** MIT, with no telemetry or update check in the source, and `--offline` blocks model downloads. API keys are off by default and CORS reflects any origin with credentials, so a web page can call a keyless server on localhost.\n\n## Before you call either\n\n### Khoj\n\n1. Install with `pip install --pre khoj` or a 2.0.0-beta image tag. Plain `pip install khoj` and `latest` give 1.42.10 from July 2025\n2. Point the Obsidian, Emacs or desktop client at your own server. They default to app.khoj.dev, which shut down on 15 April 2026\n3. Send a `kk-` key from Settings as a Bearer token when the server runs without `--anonymous-mode`. In anonymous mode /auth isn't mounted and no key exists\n4. Call `GET /api/search?q=...\u0026n=5` for passages and put `file:\"notes.md\"` or `dt\u003e=\"2026-01-01\"` inside `q` to filter. No route is documented\n5. Set `KHOJ_TELEMETRY_DISABLE=True` before the first start. Tagged releases send the caller's IP with telemetry\n\n### llama.cpp\n\n1. Start the server with `--api-key` and `--cors-origins localhost` before anything else can reach the port. Both are off by default\n2. Pass `n_predict` or `max_tokens`. Generation is unbounded by default\n3. Send `response_fields` to /completion to drop the fields you don't read\n4. Wait and retry on a 503 `unavailable_error`. The model is still loading\n5. Read the server README of the build you run. Behaviour changes between nightly builds without a changelog entry\n\n## Other comparisons with Khoj or llama.cpp\n\n- [AnythingLLM vs Khoj](https://www.anchorterminal.com/compare/anythingllm-vs-khoj.md)\n- [AnythingLLM vs llama.cpp](https://www.anchorterminal.com/compare/anythingllm-vs-llama-cpp.md)\n- [GPT4All vs Khoj](https://www.anchorterminal.com/compare/gpt4all-vs-khoj.md)\n- [GPT4All vs llama.cpp](https://www.anchorterminal.com/compare/gpt4all-vs-llama-cpp.md)\n- [Jan vs Khoj](https://www.anchorterminal.com/compare/jan-vs-khoj.md)\n- [Jan vs llama.cpp](https://www.anchorterminal.com/compare/jan-vs-llama-cpp.md)\n- [Khoj vs LM Studio](https://www.anchorterminal.com/compare/khoj-vs-lm-studio.md)\n- [Khoj vs LocalAI](https://www.anchorterminal.com/compare/khoj-vs-localai.md)\n- [Khoj vs Ollama](https://www.anchorterminal.com/compare/khoj-vs-ollama.md)\n- [Khoj vs Open WebUI](https://www.anchorterminal.com/compare/khoj-vs-open-webui.md)\n- [llama.cpp vs LM Studio](https://www.anchorterminal.com/compare/llama-cpp-vs-lm-studio.md)\n- [llama.cpp vs LocalAI](https://www.anchorterminal.com/compare/llama-cpp-vs-localai.md)\n- [llama.cpp vs Ollama](https://www.anchorterminal.com/compare/llama-cpp-vs-ollama.md)\n- [llama.cpp vs Open WebUI](https://www.anchorterminal.com/compare/llama-cpp-vs-open-webui.md)\n- [llama.cpp vs screenpipe](https://www.anchorterminal.com/compare/llama-cpp-vs-screenpipe.md)\n- [llama.cpp vs Underdog](https://www.anchorterminal.com/compare/llama-cpp-vs-underdog.md)\n- [Khoj vs LocalGhost](https://www.anchorterminal.com/compare/khoj-vs-localghost.md)\n- [Khoj vs screenpipe](https://www.anchorterminal.com/compare/khoj-vs-screenpipe.md)\n\n## Disclosure\n\n- Khoj competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Khoj vs llama.cpp",
        "url": ""
      }
    ],
    "description": "llama.cpp has a score of 60.2 (C) against Khoj's 38.8 (E). Both do local inference. The largest gap is maintenance \u0026 community, 62 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Khoj E 38.8",
      "llama.cpp C 60.2",
      "scores"
    ],
    "h1": "Khoj vs llama.cpp",
    "image": "https://www.anchorterminal.com/assets/og/compare-khoj-vs-llama-cpp.png",
    "path": "/compare/khoj-vs-llama-cpp",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Khoj vs llama.cpp for AI agents, E 38.8 vs C 60.2 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/khoj-vs-llama-cpp"
  },
  "tokens": {
    "markdown": 1650,
    "slim": 330
  },
  "version": 1
}
