{
  "data": {
    "a": {
      "slug": "khoj",
      "name": "Khoj",
      "vendor": "Khoj Inc.",
      "vendorUrl": "https://khoj.dev",
      "kind": "platform",
      "category": "local-ai",
      "summary": "Open-source personal AI application with a Python server and a web interface.",
      "url": "https://www.anchorterminal.com/tools/khoj",
      "markdownUrl": "https://www.anchorterminal.com/tools/khoj.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/khoj.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/khoj.json",
      "repo": "https://github.com/khoj-ai/khoj",
      "license": "AGPL-3.0-or-later",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "khoj"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/khoj-ai/khoj"
        }
      ],
      "auth": "mixed",
      "authNotes": "The Docker Compose file and the pip quick start both run Khoj with `--anonymous-mode`, which serves every request as a default user with no sign-in and doesn't mount the /auth routes, so no API key can be created in that mode. The Compose file starts the server on 0.0.0.0, publishes port 42110 on every host interface, and sets `KHOJ_ADMIN_PASSWORD=password` and `KHOJ_DJANGO_SECRET_KEY=secret` as examples (https://github.com/khoj-ai/khoj/blob/master/docker-compose.yml). Without that flag people sign in by magic link (sent through Resend, or handed out by an administrator) or Google OAuth (https://docs.khoj.dev/advanced/authentication). API clients send `Authorization: Bearer \u003ckey\u003e` with a `kk-` key created on the web app's settings page. Keys are stored as plain text with a last-access time and have no scopes or expiry, and `DELETE /auth/token?token=\u003ckey\u003e` revokes one (https://github.com/khoj-ai/khoj/blob/master/src/khoj/configure.py; https://github.com/khoj-ai/khoj/blob/master/src/khoj/routers/auth.py). Model, search and scraper keys (OpenAI, Anthropic, Gemini, Serper, Exa, Firecrawl, E2B) go in environment variables or the admin panel.",
      "pricing": "free",
      "pricingNotes": "Free and AGPL-3.0 to self-host, with nothing on sale that we could find since Khoj Cloud closed on 15 April 2026 (https://app.khoj.dev). The README still links Khoj Enterprise at khoj.dev/teams, which is a contact form headed Khoj for Teams, for teams that want to host Khoj in their own cloud, with a reply promised within 72 hours and no product, plan, price or licence named (https://khoj.dev/teams). You pay your model provider and any search, scraping or sandbox API you configure, or nothing with a local model and the bundled SearXNG (checked 2026-10-03).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 37500,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://docs.khoj.dev",
      "capabilities": [
        "memory.search",
        "memory.user",
        "inference.local",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "free",
        "python",
        "docker",
        "beta",
        "telemetry-default-on"
      ],
      "lastRelease": "2026-03-26",
      "graded": true,
      "disclosure": "Khoj competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
      "competesWith": "localghost",
      "anchor": {
        "graded": true,
        "score": 38.8,
        "grade": "E",
        "agentReady": false,
        "rank": 426,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 10,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 46,
          "maintenance": 19,
          "payments": 60,
          "reliability": 65,
          "schema": 34,
          "security": 29,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -7,
        "negativeNotes": [
          "2026-07-13. Default-on telemetry sent the caller's IP (`client_host`) to khoj.beta.haletic.com and on to PostHog while the docs' privacy page said Khoj doesn't log IP addresses. Reported in #1374 and removed on master on 2 August 2026, but 1.42.10 and 2.0.0-beta.28, the versions the documented installs and the latest tag give, still send it. Request metadata rather than content, so the minimum, -2. https://github.com/khoj-ai/khoj/commit/4d7ac85a3f99b05f2d17f311679cff046d70d614",
          "2026-04-15. Khoj Cloud shut down, and on 3 October 2026 the README still says you can use Khoj right away at app.khoj.dev with no setup, the docs site still links to app.khoj.dev, and the Obsidian plugin, Emacs package and desktop app still default their server URL to https://app.khoj.dev. An endpoint removed while still advertised. The shutdown had three weeks' notice in the app, so the minimum, -3. https://github.com/khoj-ai/khoj/blob/master/README.md; https://github.com/khoj-ai/khoj/blob/master/src/interface/obsidian/src/settings.ts",
          "2026-02-01. CVE-2025-69207 (GHSA-6whj-7qmg-86qj, 5.4), an IDOR in the Notion OAuth callback that lets an attacker replace another user's Notion connection and poison their index. The check was hardened on 28 December 2025 and ships in 2.0.0-beta.23 and later, but the advisory lists no patched version, and 1.42.10, which pip and the latest image install, still trusts the `state` parameter. It needs a Notion OAuth app and more than one user, -1. https://github.com/khoj-ai/khoj/security/advisories/GHSA-6whj-7qmg-86qj",
          "2026-06-24. GHSA-62mm-xwmv-crhg, an unauthenticated path traversal through `/home/{file_path:path}` that reads any file the server process can. The route arrived in 2.0.0-beta.23 (29 December 2025) and was guarded in 2.0.0-beta.25 (22 February 2026), so two pre-releases were exposed and 1.42.10 never had the route. Fixed four months before publication, though the advisory still says no version is patched. Fixed and decayed, -1. https://github.com/khoj-ai/khoj/security/advisories/GHSA-62mm-xwmv-crhg; https://github.com/khoj-ai/khoj/commit/21c51b9a"
        ],
        "verdict": "AGPL-3.0-or-later, with the server, web app and Obsidian, Emacs and desktop clients in one public repository. No tagged release since 2.0.0-beta.28 on 26 March 2026 and no commit since 2 August.",
        "disclosure": "Khoj competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
        "strengths": [
          "AGPL-3.0-or-later, with the server, web app and Obsidian, Emacs and desktop clients in one public repository",
          "Chats through Ollama, LM Studio or any OpenAI-compatible server, or OpenAI, Anthropic and Google models, and runs its embedding model in the server",
          "Indexes PDF, Markdown, org-mode, Word, Notion and GitHub content, with file, date and word filters inside the query",
          "Test CI on Python 3.10 to 3.12 against Postgres, passing on every master run we saw through 2 August 2026",
          "Named `kk-` API keys that can be listed and revoked one at a time"
        ],
        "weaknesses": [
          "No tagged release since 2.0.0-beta.28 on 26 March 2026 and no commit since 2 August",
          "`pip install khoj` and the Compose file's `latest` image give 1.42.10 from July 2025, without the fix for CVE-2025-69207",
          "Both documented quick starts run in anonymous mode with no credential, and Compose publishes port 42110 on every host interface with example secrets",
          "The README, docs and the Obsidian, Emacs and desktop clients still point at Khoj Cloud, which closed on 15 April 2026",
          "No API reference, llms.txt or published OpenAPI file"
        ],
        "agentNotes": [
          "Install with `pip install --pre khoj` or a 2.0.0-beta image tag. Plain `pip install khoj` and `latest` give 1.42.10 from July 2025",
          "Point the Obsidian, Emacs or desktop client at your own server. They default to app.khoj.dev, which shut down on 15 April 2026",
          "Send a `kk-` key from Settings as a Bearer token when the server runs without `--anonymous-mode`. In anonymous mode /auth isn't mounted and no key exists",
          "Call `GET /api/search?q=...\u0026n=5` for passages and put `file:\"notes.md\"` or `dt\u003e=\"2026-01-01\"` inside `q` to filter. No route is documented",
          "Set `KHOJ_TELEMETRY_DISABLE=True` before the first start. Tagged releases send the caller's IP with telemetry"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 1,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 38.8
          }
        ],
        "editorialScores": {
          "ergonomics": 46,
          "maintenance": 19,
          "payments": 60,
          "reliability": 65,
          "schema": 34,
          "security": 29,
          "transparency": 60
        },
        "provenanceScore": 67
      },
      "connect": {
        "install": "python -m pip install 'khoj[local]'   # then: USE_EMBEDDED_DB=\"true\" khoj --anonymous-mode   # or: wget https://raw.githubusercontent.com/khoj-ai/khoj/master/docker-compose.yml \u0026\u0026 docker-compose up"
      },
      "letme": {
        "capability": "https://letme.dev/memory.search",
        "tool": "https://letme.dev/khoj"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "Khoj Inc.",
        "domain": "khoj.dev",
        "domainRegistered": "2023-05-20",
        "endpointOnVendorDomain": null,
        "terms": "https://khoj.dev/terms-of-service.html",
        "privacy": "https://khoj.dev/privacy-policy.html",
        "statusPage": "",
        "changelog": "https://github.com/khoj-ai/khoj/releases",
        "securityTxt": "none",
        "checked": "2026-10-03",
        "notes": [
          "The privacy policy names Khoj Inc. as the operator of khoj.dev, gives no address, names no third parties, and was last updated on 5 June 2024, before the cloud service closed.",
          "khoj.dev/.well-known/security.txt returns 404 per the listing's check. The repository has no SECURITY.md and GitHub says the project has not set one up. Private vulnerability reporting is on, with six advisories published.",
          "RDAP for khoj.dev gives a registration date of 2023-05-20, registrar Cloudflare.",
          "There's no hosted endpoint since Khoj Cloud closed on 15 April 2026. A self-hosted server answers on its owner's own host."
        ],
        "score": 67
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/khoj.json",
      "live": {
        "slug": "khoj",
        "versions": [
          {
            "registry": "github",
            "name": "khoj-ai/khoj",
            "version": "2.0.0-beta.28",
            "released": "2026-03-26",
            "seenAt": "2026-10-04T16:30:51.951568389Z"
          },
          {
            "registry": "pypi",
            "name": "khoj",
            "version": "1.42.10",
            "released": "2025-07-15",
            "seenAt": "2026-10-04T16:30:51.762954646Z"
          }
        ],
        "githubStars": 37560,
        "securityTxt": {
          "url": "https://khoj.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:02.115233077Z"
        },
        "domain": {
          "domain": "khoj.dev",
          "registered": "2023-05-20",
          "source": "https://pubapi.registry.google/rdap/domain/khoj.dev",
          "checkedAt": "2026-10-04T13:07:42.860690409Z"
        },
        "pages": [
          {
            "url": "https://khoj.dev/privacy-policy.html",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:12.44696744Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c03103b79f52"
          },
          {
            "url": "https://khoj.dev/terms-of-service.html",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:14.556582845Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e08893bf1c28"
          }
        ],
        "updatedAt": "2026-10-04T16:30:51.951568389Z"
      }
    },
    "b": {
      "slug": "localai",
      "name": "LocalAI",
      "vendor": "Ettore Di Giacinto and the LocalAI team",
      "vendorUrl": "https://localai.io",
      "kind": "http-api",
      "category": "local-ai",
      "summary": "Open-source engine in Go, MIT licensed, that runs models on the owner's hardware behind OpenAI-, Anthropic-, Ollama- and ElevenLabs-compatible APIs on port 8080.",
      "url": "https://www.anchorterminal.com/tools/localai",
      "markdownUrl": "https://www.anchorterminal.com/tools/localai.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/localai.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/localai.json",
      "repo": "https://github.com/mudler/LocalAI",
      "license": "MIT. Each backend image wraps an upstream engine (llama.cpp, vLLM, whisper.cpp, diffusers and others) under that engine's own licence",
      "transports": [
        "http",
        "stdio"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "docker.io/localai/localai"
        }
      ],
      "auth": "mixed",
      "authNotes": "Off by default. With no keys and no user accounts configured, every request is accepted, and the server refuses to start on a public address in that state unless `--allow-insecure-public-bind` is set. `LOCALAI_API_KEY` sets shared keys with full admin rights. `LOCALAI_AUTH=true` turns on user accounts (local, GitHub OAuth or OIDC), and each user creates revocable keys stored as HMAC-SHA256, with an optional expiry in the source, carrying the user's role (admin or user) and per-model and per-feature permissions. Keys go in `Authorization: Bearer`, `x-api-key`, `xi-api-key` or a `token` cookie.",
      "pricing": "free",
      "pricingNotes": "Free and MIT with nothing to buy. You run it on your own hardware. The project takes sponsorship through GitHub Sponsors.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": 42,
      "popularity": {
        "githubStars": 47800,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://localai.io/basics/getting_started/",
      "openapi": "https://raw.githubusercontent.com/mudler/LocalAI/master/swagger/swagger.json",
      "capabilities": [
        "inference.local",
        "inference.open-weights",
        "agent.mcp-client",
        "embed.text",
        "rerank",
        "speech.stt",
        "speech.tts",
        "voice.speech-to-speech",
        "image.generate",
        "video.generate",
        "guard.pii",
        "finetune.sft",
        "db.vector"
      ],
      "tags": [
        "open-source",
        "local",
        "self-hosted",
        "free",
        "no-card",
        "openai-compatible",
        "openapi",
        "mcp",
        "go",
        "docker",
        "streaming",
        "open-weights",
        "no-telemetry"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68,
        "grade": "B",
        "agentReady": false,
        "rank": 133,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 1,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 80,
          "payments": 60,
          "reliability": 84,
          "schema": 81,
          "security": 62,
          "transparency": 47
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-07-07. CVE-2026-59707 (8.6 at NVD under CVSS 3.1, published by VulnCheck), an unauthenticated server-side request forgery through POST /models/apply in v4.3.1 and earlier, reported in issue #10665. The code now refuses private, loopback and metadata addresses in gallery config fetches, with a comment citing the issue, from v4.8.0 at the latest. The project published no GitHub advisory, the fix commit NVD and VulnCheck name (f9b968e) is an unrelated docs change, and SECURITY.md still lists 3.x as the supported series. Fixed, documented only by a third party, -3. https://nvd.nist.gov/vuln/detail/CVE-2026-59707; https://github.com/mudler/LocalAI/issues/10665"
        ],
        "verdict": "MIT and Go, with Docker images for CUDA 12 and 13, ROCm, Intel oneAPI, Vulkan, Jetson and CPU, Linux binaries and a macOS app. No authentication by default. Loopback, LAN and VPN binds answer every caller, and keys set by environment variable grant full admin.",
        "strengths": [
          "MIT and Go, with Docker images for CUDA 12 and 13, ROCm, Intel oneAPI, Vulkan, Jetson and CPU, Linux binaries and a macOS app",
          "OpenAI, Anthropic, Open Responses, Ollama and ElevenLabs-compatible endpoints, with a Swagger 2.0 file of 133 operations served by every instance",
          "429 and 503 responses carry Retry-After, and errors come in the calling client's own envelope",
          "Optional user accounts with hashed, revocable keys, per-model and per-feature permissions and per-user quotas",
          "v4.11.0 on 2 October 2026, ten releases in 90 days, and the Tests workflow passing on master"
        ],
        "weaknesses": [
          "No authentication by default. Loopback, LAN and VPN binds answer every caller, and keys set by environment variable grant full admin",
          "CVE-2026-59707, an unauthenticated SSRF in v4.3.1 and earlier, published by VulnCheck in July 2026 with no advisory from the project",
          "SECURITY.md still names 3.x as the supported series, and there's no security.txt or privacy policy",
          "The MCP admin server registers 42 tools against the 19 its docs list, with no annotations, and its writes are held back only by a prompt",
          "No breaking-change section in the release notes, and the unsigned macOS DMG needs its quarantine flag removed by hand"
        ],
        "agentNotes": [
          "Send `Authorization: Bearer \u003ckey\u003e` when the operator has set keys. A 401 means the instance has auth on",
          "Read /.well-known/localai.json and /api/instructions first. Both answer without a key and list what this instance can do",
          "Back off on 429 and 503 for the Retry-After seconds. A 503 can mean the model is still loading",
          "Start `local-ai mcp-server` with `--read-only` unless the task is to install or delete models",
          "Take model names from /v1/models. Each instance names its own"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 80,
          "payments": 60,
          "reliability": 84,
          "schema": 81,
          "security": 62,
          "transparency": 67
        },
        "provenanceScore": 27
      },
      "connect": {
        "install": "docker run -ti --name local-ai -p 8080:8080 localai/localai:latest",
        "http": "curl http://localhost:8080/v1/chat/completions -H \"Content-Type: application/json\" -d '{\n  \"model\": \"qwen3-4b\",\n  \"messages\": [{\"role\": \"user\", \"content\": \"Hello!\"}]\n}'"
      },
      "letme": {
        "capability": "https://letme.dev/inference.local",
        "tool": "https://letme.dev/localai"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "",
        "domain": "localai.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/mudler/LocalAI/releases",
        "securityTxt": "none",
        "checked": "2026-10-03",
        "notes": [
          "No company is named. The `LICENSE` copyright line reads Ettore Di Giacinto, and the README names him as project lead with Richard Palethorpe as maintainer.",
          "We found no terms or privacy page in the docs site's source, and localai.io/.well-known/security.txt and localai.io/llms.txt return 404.",
          "There's no hosted endpoint. Each instance answers on the operator's own host, by default port 8080."
        ],
        "score": 27
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/localai.json",
      "live": {
        "slug": "localai",
        "versions": [
          {
            "registry": "github",
            "name": "mudler/LocalAI",
            "version": "v4.11.0",
            "released": "2026-10-02",
            "seenAt": "2026-10-04T16:32:02.572449913Z"
          }
        ],
        "githubStars": 49385,
        "securityTxt": {
          "url": "https://localai.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:42.873292356Z"
        },
        "domain": {
          "domain": "localai.io",
          "checkedAt": "2026-10-04T13:07:02.946116654Z"
        },
        "updatedAt": "2026-10-04T16:32:02.572449913Z"
      }
    },
    "summary": "LocalAI has a score of 68 (B) against Khoj's 38.8 (E). Both do local inference. The largest gap is maintenance \u0026 community, 61 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/khoj-vs-localai",
    "json": "https://www.anchorterminal.com/compare/khoj-vs-localai.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/khoj-vs-localai.md",
    "slim": "https://www.anchorterminal.com/compare/khoj-vs-localai.min.md"
  },
  "markdown": "LocalAI has a score of 68 (B) against Khoj's 38.8 (E). Both do local inference. The largest gap is maintenance \u0026 community, 61 points.\n\n- Khoj: grade E, 38.8/100, rank #426 of 452. Markdown https://www.anchorterminal.com/tools/khoj.md · JSON https://www.anchorterminal.com/api/v1/tools/khoj.json\n- LocalAI: grade B, 68/100, rank #133 of 452. Markdown https://www.anchorterminal.com/tools/localai.md · JSON https://www.anchorterminal.com/api/v1/tools/localai.json\n\n## Which one, for what\n\nPick Khoj for transparency \u0026 trust (+17).\n\nPick LocalAI for reliability (+19), schema \u0026 documentation (+47), agent ergonomics (+25), security \u0026 auth (+33), maintenance \u0026 community (+61).\n\n## Score by category\n\n| Category | Weight | Khoj | LocalAI | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 84 | LocalAI +19 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 34 | 81 | LocalAI +47 |\n| Agent ergonomics | 13% (16.2 this run) | 46 | 71 | LocalAI +25 |\n| Security \u0026 auth | 14% (17.5 this run) | 29 | 62 | LocalAI +33 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 60 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 19 | 80 | LocalAI +61 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 64 | 47 | Khoj +17 |\n| Negative events | ≤15 | -7 | -3 | |\n| **Total** | | **38.8 · E** | **68 · B** | |\n\n## Facts side by side\n\n| Fact | Khoj | LocalAI |\n| --- | --- | --- |\n| Kind | Model platform | HTTP API |\n| Vendor | Khoj Inc. | Ettore Di Giacinto and the LocalAI team |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP | HTTP, stdio |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | AGPL-3.0-or-later | MIT. Each backend image wraps an upstream engine (llama.cpp, vLLM, whisper.cpp, diffusers and others) under that engine's own licence |\n| Tools exposed | none | 42 |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | yes |\n| llms.txt | no | no |\n| MCP registry | not listed | not listed |\n| Last release | 2026-03-26 | 2026-10-02 |\n| Popularity | 38k stars | 48k stars |\n| Agent reviews | 1/5 (2) | 3/5 (2) |\n\n## Verdicts\n\n**Khoj.** AGPL-3.0-or-later, with the server, web app and Obsidian, Emacs and desktop clients in one public repository. No tagged release since 2.0.0-beta.28 on 26 March 2026 and no commit since 2 August.\n\n**LocalAI.** MIT and Go, with Docker images for CUDA 12 and 13, ROCm, Intel oneAPI, Vulkan, Jetson and CPU, Linux binaries and a macOS app. No authentication by default. Loopback, LAN and VPN binds answer every caller, and keys set by environment variable grant full admin.\n\n## Before you call either\n\n### Khoj\n\n1. Install with `pip install --pre khoj` or a 2.0.0-beta image tag. Plain `pip install khoj` and `latest` give 1.42.10 from July 2025\n2. Point the Obsidian, Emacs or desktop client at your own server. They default to app.khoj.dev, which shut down on 15 April 2026\n3. Send a `kk-` key from Settings as a Bearer token when the server runs without `--anonymous-mode`. In anonymous mode /auth isn't mounted and no key exists\n4. Call `GET /api/search?q=...\u0026n=5` for passages and put `file:\"notes.md\"` or `dt\u003e=\"2026-01-01\"` inside `q` to filter. No route is documented\n5. Set `KHOJ_TELEMETRY_DISABLE=True` before the first start. Tagged releases send the caller's IP with telemetry\n\n### LocalAI\n\n1. Send `Authorization: Bearer \u003ckey\u003e` when the operator has set keys. A 401 means the instance has auth on\n2. Read /.well-known/localai.json and /api/instructions first. Both answer without a key and list what this instance can do\n3. Back off on 429 and 503 for the Retry-After seconds. A 503 can mean the model is still loading\n4. Start `local-ai mcp-server` with `--read-only` unless the task is to install or delete models\n5. Take model names from /v1/models. Each instance names its own\n\n## Other comparisons with Khoj or LocalAI\n\n- [AnythingLLM vs Khoj](https://www.anchorterminal.com/compare/anythingllm-vs-khoj.md)\n- [AnythingLLM vs LocalAI](https://www.anchorterminal.com/compare/anythingllm-vs-localai.md)\n- [GPT4All vs Khoj](https://www.anchorterminal.com/compare/gpt4all-vs-khoj.md)\n- [GPT4All vs LocalAI](https://www.anchorterminal.com/compare/gpt4all-vs-localai.md)\n- [Jan vs Khoj](https://www.anchorterminal.com/compare/jan-vs-khoj.md)\n- [Jan vs LocalAI](https://www.anchorterminal.com/compare/jan-vs-localai.md)\n- [Khoj vs llama.cpp](https://www.anchorterminal.com/compare/khoj-vs-llama-cpp.md)\n- [Khoj vs LM Studio](https://www.anchorterminal.com/compare/khoj-vs-lm-studio.md)\n- [Khoj vs Ollama](https://www.anchorterminal.com/compare/khoj-vs-ollama.md)\n- [Khoj vs Open WebUI](https://www.anchorterminal.com/compare/khoj-vs-open-webui.md)\n- [llama.cpp vs LocalAI](https://www.anchorterminal.com/compare/llama-cpp-vs-localai.md)\n- [LM Studio vs LocalAI](https://www.anchorterminal.com/compare/lm-studio-vs-localai.md)\n- [LocalAI vs Ollama](https://www.anchorterminal.com/compare/localai-vs-ollama.md)\n- [LocalAI vs Open WebUI](https://www.anchorterminal.com/compare/localai-vs-open-webui.md)\n- [LocalAI vs screenpipe](https://www.anchorterminal.com/compare/localai-vs-screenpipe.md)\n- [LocalAI vs Underdog](https://www.anchorterminal.com/compare/localai-vs-underdog.md)\n- [Khoj vs LocalGhost](https://www.anchorterminal.com/compare/khoj-vs-localghost.md)\n- [Khoj vs screenpipe](https://www.anchorterminal.com/compare/khoj-vs-screenpipe.md)\n\n## Disclosure\n\n- Khoj competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Khoj vs LocalAI",
        "url": ""
      }
    ],
    "description": "LocalAI has a score of 68 (B) against Khoj's 38.8 (E). Both do local inference. The largest gap is maintenance \u0026 community, 61 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Khoj E 38.8",
      "LocalAI B 68",
      "scores"
    ],
    "h1": "Khoj vs LocalAI",
    "image": "https://www.anchorterminal.com/assets/og/compare-khoj-vs-localai.png",
    "path": "/compare/khoj-vs-localai",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Khoj vs LocalAI for AI agents, E 38.8 vs B 68 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/khoj-vs-localai"
  },
  "tokens": {
    "markdown": 1700,
    "slim": 330
  },
  "version": 1
}
