{
  "data": {
    "a": {
      "slug": "khoj",
      "name": "Khoj",
      "vendor": "Khoj Inc.",
      "vendorUrl": "https://khoj.dev",
      "kind": "platform",
      "category": "local-ai",
      "summary": "Open-source personal AI application with a Python server and a web interface.",
      "url": "https://www.anchorterminal.com/tools/khoj",
      "markdownUrl": "https://www.anchorterminal.com/tools/khoj.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/khoj.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/khoj.json",
      "repo": "https://github.com/khoj-ai/khoj",
      "license": "AGPL-3.0-or-later",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "khoj"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/khoj-ai/khoj"
        }
      ],
      "auth": "mixed",
      "authNotes": "The Docker Compose file and the pip quick start both run Khoj with `--anonymous-mode`, which serves every request as a default user with no sign-in and doesn't mount the /auth routes, so no API key can be created in that mode. The Compose file starts the server on 0.0.0.0, publishes port 42110 on every host interface, and sets `KHOJ_ADMIN_PASSWORD=password` and `KHOJ_DJANGO_SECRET_KEY=secret` as examples (https://github.com/khoj-ai/khoj/blob/master/docker-compose.yml). Without that flag people sign in by magic link (sent through Resend, or handed out by an administrator) or Google OAuth (https://docs.khoj.dev/advanced/authentication). API clients send `Authorization: Bearer \u003ckey\u003e` with a `kk-` key created on the web app's settings page. Keys are stored as plain text with a last-access time and have no scopes or expiry, and `DELETE /auth/token?token=\u003ckey\u003e` revokes one (https://github.com/khoj-ai/khoj/blob/master/src/khoj/configure.py; https://github.com/khoj-ai/khoj/blob/master/src/khoj/routers/auth.py). Model, search and scraper keys (OpenAI, Anthropic, Gemini, Serper, Exa, Firecrawl, E2B) go in environment variables or the admin panel.",
      "pricing": "free",
      "pricingNotes": "Free and AGPL-3.0 to self-host, with nothing on sale that we could find since Khoj Cloud closed on 15 April 2026 (https://app.khoj.dev). The README still links Khoj Enterprise at khoj.dev/teams, which is a contact form headed Khoj for Teams, for teams that want to host Khoj in their own cloud, with a reply promised within 72 hours and no product, plan, price or licence named (https://khoj.dev/teams). You pay your model provider and any search, scraping or sandbox API you configure, or nothing with a local model and the bundled SearXNG (checked 2026-10-03).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 37500,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://docs.khoj.dev",
      "capabilities": [
        "memory.search",
        "memory.user",
        "inference.local",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "free",
        "python",
        "docker",
        "beta",
        "telemetry-default-on"
      ],
      "lastRelease": "2026-03-26",
      "graded": true,
      "disclosure": "Khoj competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
      "competesWith": "localghost",
      "anchor": {
        "graded": true,
        "score": 38.8,
        "grade": "E",
        "agentReady": false,
        "rank": 426,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 10,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 46,
          "maintenance": 19,
          "payments": 60,
          "reliability": 65,
          "schema": 34,
          "security": 29,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -7,
        "negativeNotes": [
          "2026-07-13. Default-on telemetry sent the caller's IP (`client_host`) to khoj.beta.haletic.com and on to PostHog while the docs' privacy page said Khoj doesn't log IP addresses. Reported in #1374 and removed on master on 2 August 2026, but 1.42.10 and 2.0.0-beta.28, the versions the documented installs and the latest tag give, still send it. Request metadata rather than content, so the minimum, -2. https://github.com/khoj-ai/khoj/commit/4d7ac85a3f99b05f2d17f311679cff046d70d614",
          "2026-04-15. Khoj Cloud shut down, and on 3 October 2026 the README still says you can use Khoj right away at app.khoj.dev with no setup, the docs site still links to app.khoj.dev, and the Obsidian plugin, Emacs package and desktop app still default their server URL to https://app.khoj.dev. An endpoint removed while still advertised. The shutdown had three weeks' notice in the app, so the minimum, -3. https://github.com/khoj-ai/khoj/blob/master/README.md; https://github.com/khoj-ai/khoj/blob/master/src/interface/obsidian/src/settings.ts",
          "2026-02-01. CVE-2025-69207 (GHSA-6whj-7qmg-86qj, 5.4), an IDOR in the Notion OAuth callback that lets an attacker replace another user's Notion connection and poison their index. The check was hardened on 28 December 2025 and ships in 2.0.0-beta.23 and later, but the advisory lists no patched version, and 1.42.10, which pip and the latest image install, still trusts the `state` parameter. It needs a Notion OAuth app and more than one user, -1. https://github.com/khoj-ai/khoj/security/advisories/GHSA-6whj-7qmg-86qj",
          "2026-06-24. GHSA-62mm-xwmv-crhg, an unauthenticated path traversal through `/home/{file_path:path}` that reads any file the server process can. The route arrived in 2.0.0-beta.23 (29 December 2025) and was guarded in 2.0.0-beta.25 (22 February 2026), so two pre-releases were exposed and 1.42.10 never had the route. Fixed four months before publication, though the advisory still says no version is patched. Fixed and decayed, -1. https://github.com/khoj-ai/khoj/security/advisories/GHSA-62mm-xwmv-crhg; https://github.com/khoj-ai/khoj/commit/21c51b9a"
        ],
        "verdict": "AGPL-3.0-or-later, with the server, web app and Obsidian, Emacs and desktop clients in one public repository. No tagged release since 2.0.0-beta.28 on 26 March 2026 and no commit since 2 August.",
        "disclosure": "Khoj competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
        "strengths": [
          "AGPL-3.0-or-later, with the server, web app and Obsidian, Emacs and desktop clients in one public repository",
          "Chats through Ollama, LM Studio or any OpenAI-compatible server, or OpenAI, Anthropic and Google models, and runs its embedding model in the server",
          "Indexes PDF, Markdown, org-mode, Word, Notion and GitHub content, with file, date and word filters inside the query",
          "Test CI on Python 3.10 to 3.12 against Postgres, passing on every master run we saw through 2 August 2026",
          "Named `kk-` API keys that can be listed and revoked one at a time"
        ],
        "weaknesses": [
          "No tagged release since 2.0.0-beta.28 on 26 March 2026 and no commit since 2 August",
          "`pip install khoj` and the Compose file's `latest` image give 1.42.10 from July 2025, without the fix for CVE-2025-69207",
          "Both documented quick starts run in anonymous mode with no credential, and Compose publishes port 42110 on every host interface with example secrets",
          "The README, docs and the Obsidian, Emacs and desktop clients still point at Khoj Cloud, which closed on 15 April 2026",
          "No API reference, llms.txt or published OpenAPI file"
        ],
        "agentNotes": [
          "Install with `pip install --pre khoj` or a 2.0.0-beta image tag. Plain `pip install khoj` and `latest` give 1.42.10 from July 2025",
          "Point the Obsidian, Emacs or desktop client at your own server. They default to app.khoj.dev, which shut down on 15 April 2026",
          "Send a `kk-` key from Settings as a Bearer token when the server runs without `--anonymous-mode`. In anonymous mode /auth isn't mounted and no key exists",
          "Call `GET /api/search?q=...\u0026n=5` for passages and put `file:\"notes.md\"` or `dt\u003e=\"2026-01-01\"` inside `q` to filter. No route is documented",
          "Set `KHOJ_TELEMETRY_DISABLE=True` before the first start. Tagged releases send the caller's IP with telemetry"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 1,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 38.8
          }
        ],
        "editorialScores": {
          "ergonomics": 46,
          "maintenance": 19,
          "payments": 60,
          "reliability": 65,
          "schema": 34,
          "security": 29,
          "transparency": 60
        },
        "provenanceScore": 67
      },
      "connect": {
        "install": "python -m pip install 'khoj[local]'   # then: USE_EMBEDDED_DB=\"true\" khoj --anonymous-mode   # or: wget https://raw.githubusercontent.com/khoj-ai/khoj/master/docker-compose.yml \u0026\u0026 docker-compose up"
      },
      "letme": {
        "capability": "https://letme.dev/memory.search",
        "tool": "https://letme.dev/khoj"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "Khoj Inc.",
        "domain": "khoj.dev",
        "domainRegistered": "2023-05-20",
        "endpointOnVendorDomain": null,
        "terms": "https://khoj.dev/terms-of-service.html",
        "privacy": "https://khoj.dev/privacy-policy.html",
        "statusPage": "",
        "changelog": "https://github.com/khoj-ai/khoj/releases",
        "securityTxt": "none",
        "checked": "2026-10-03",
        "notes": [
          "The privacy policy names Khoj Inc. as the operator of khoj.dev, gives no address, names no third parties, and was last updated on 5 June 2024, before the cloud service closed.",
          "khoj.dev/.well-known/security.txt returns 404 per the listing's check. The repository has no SECURITY.md and GitHub says the project has not set one up. Private vulnerability reporting is on, with six advisories published.",
          "RDAP for khoj.dev gives a registration date of 2023-05-20, registrar Cloudflare.",
          "There's no hosted endpoint since Khoj Cloud closed on 15 April 2026. A self-hosted server answers on its owner's own host."
        ],
        "score": 67
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/khoj.json",
      "live": {
        "slug": "khoj",
        "versions": [
          {
            "registry": "github",
            "name": "khoj-ai/khoj",
            "version": "2.0.0-beta.28",
            "released": "2026-03-26",
            "seenAt": "2026-10-04T16:30:51.951568389Z"
          },
          {
            "registry": "pypi",
            "name": "khoj",
            "version": "1.42.10",
            "released": "2025-07-15",
            "seenAt": "2026-10-04T16:30:51.762954646Z"
          }
        ],
        "githubStars": 37560,
        "securityTxt": {
          "url": "https://khoj.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:02.115233077Z"
        },
        "domain": {
          "domain": "khoj.dev",
          "registered": "2023-05-20",
          "source": "https://pubapi.registry.google/rdap/domain/khoj.dev",
          "checkedAt": "2026-10-04T13:07:42.860690409Z"
        },
        "pages": [
          {
            "url": "https://khoj.dev/privacy-policy.html",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:12.44696744Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c03103b79f52"
          },
          {
            "url": "https://khoj.dev/terms-of-service.html",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:14.556582845Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e08893bf1c28"
          }
        ],
        "updatedAt": "2026-10-04T16:30:51.951568389Z"
      }
    },
    "b": {
      "slug": "localghost",
      "name": "LocalGhost",
      "vendor": "LocalGhost",
      "vendorUrl": "https://www.localghost.ai",
      "kind": "platform",
      "category": "local-ai",
      "summary": "Pre-release, open-source personal AI server that runs on hardware its owner keeps, started in London in December 2025.",
      "url": "https://www.anchorterminal.com/tools/localghost",
      "markdownUrl": "https://www.anchorterminal.com/tools/localghost.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/localghost.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/localghost.json",
      "repo": "https://github.com/LocalGhostDao/localghost",
      "license": "MIT",
      "transports": [
        "http"
      ],
      "packages": [],
      "auth": "pat",
      "authNotes": "No credential for third-party agents. The companion app presents a client certificate issued by the box's own certificate authority (ECDSA P-256, valid ten years, no scopes) and a session token of at most 48 hours from a PIN unlock, sent in a header. Enrolment is one animated QR code carrying a `localghost://enroll` link whose query string holds the device's certificate and private key. Since 2 October 2026 the box draws that QR only on an interactive terminal and never prints the link as text, and after the first unlock the phone swaps the QR's key for one it makes in the Android Keystore and the box retires the QR's certificate (https://github.com/LocalGhostDao/localghost/blob/main/server/internal/secd/rekey.go). A request without a valid certificate, from a retired phone or to a locked box gets the same 503. Since wisp 0.0.2 (2 October 2026) one phone can be retired by its key with ghost-cli ghost.secd retire or from another phone (POST /v1/devices/retire), and the retire button in the app isn't built yet. On a fresh box nginx terminates the phone's TLS and passes the device certificate to ghost.secd as an X-Client-Cert header that any local process on the box can forge, until the operator runs ghost-ctl edge-passthrough and writes tls to /etc/ghost/edge, after which ghost.secd checks the certificate itself (https://github.com/LocalGhostDao/localghost/blob/main/server/internal/secd/edge.go).",
      "pricing": "free",
      "pricingNotes": "The software is free under MIT, with no subscription and no account. Nothing is on sale yet. Pre-built boxes are planned as a one-time purchase at the cost of parts and assembly plus a 30% margin, price not set, and optional future daemons may be sold as one-time packages. The June 2026 reference build is about £1,130 in parts (https://www.localghost.ai/about).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No payments of any kind. The software is free and nothing is sold yet (checked 2026-10-02).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 16,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-02"
      },
      "docsUrl": "https://github.com/LocalGhostDao/localghost/blob/main/server/tools/README.md",
      "llmsTxt": "https://www.localghost.ai/llms.txt",
      "capabilities": [
        "memory.store",
        "memory.search",
        "memory.user",
        "memory.delete"
      ],
      "tags": [
        "local",
        "self-hosted",
        "open-source",
        "free",
        "go",
        "llms-txt",
        "no-telemetry",
        "pre-1.0",
        "uk"
      ],
      "graded": true,
      "own": true,
      "disclosure": "LocalGhost is built by Anchor Terminal's founder. Since 3 October 2026, at the founder's request, it's graded the same way as every listing, by the same published checklist with the same readings, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed. The review panel doesn't review it, and letme never picks it.",
      "anchor": {
        "graded": true,
        "score": 45.8,
        "grade": "E",
        "agentReady": false,
        "rank": 396,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 9,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 2,
          "maintenance": 71,
          "payments": 60,
          "reliability": 59,
          "schema": 44,
          "security": 52,
          "transparency": 77
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-09-19 to 2026-10-03, unfixed at HEAD d4decab. The README ('One thing leaves the phone'), the privacy page ('The phone talks to your box and nothing else, apart from two things'), the setup page ('The phone sends one thing') and llms.txt ('no position leaves either device') describe less than the app sends. Since 19 September it passes each new location fix to Android's system Geocoder when the phone has moved 20 km or 12 hours have passed, a network call on some phones by its own code comment, and since 20 September it sends currency amounts to api.frankfurter.app and who-is subjects to Wikipedia's summary API, named only in the engineering journal, though the chat shows those two as sources when it uses them. Until 0.0.3 the same claim stood while the app sent the phone's position to Open-Meteo for a weather question naming no place. wisp 0.0.3 removed that call on 3 October and its notes, the privacy page, llms.txt and the changelog say so, so that part adds nothing. One misleading claim, still partly false, -3. https://github.com/LocalGhostDao/localghost/blob/main/app/android/app/src/main/java/com/localghost/app/sync/LocationLog.kt; https://github.com/LocalGhostDao/localghost/blob/main/app/android/app/src/main/java/com/localghost/app/net/WebSearch.kt; https://www.localghost.ai/privacy"
        ],
        "verdict": "The server and Android app are MIT-licensed, with no telemetry libraries found. There is no agent API, MCP server or SDK; unpaired callers receive HTTP 503.",
        "disclosure": "LocalGhost is built by Anchor Terminal's founder. Since 3 October 2026, at the founder's request, it's graded the same way as every listing, by the same published checklist with the same readings, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed. The review panel doesn't review it, and letme never picks it.",
        "strengths": [
          "MIT for the server and the Android app, with no telemetry, analytics or crash-reporting library in either",
          "The archive sits on a LUKS2 volume whose key is sealed to the TPM through go-tpm and opened by a PIN from the phone, with a wipe PIN that answers like a wrong one",
          "Per-device client certificates from the box's own CA, rekeyed into the Android Keystore at the first unlock since 2 October 2026, and one phone can be retired by its key since 0.0.2",
          "Server releases are built with CGO off, -trimpath and no build id, the v0.0.3 source archive matches the tag's 846 files, and SHA256SUMS.asc verifies against the key in the repository (DCE9 A3D1 4EB4 6197 1DD5 F393 706E 4194 F08A 09A0)",
          "A valid RFC 9116 security.txt to 2027-10-01 and a SECURITY.md with PGP, a 72-hour acknowledgement, 90-day disclosure and a commitment not to sue"
        ],
        "weaknesses": [
          "No API, MCP server or SDK for agents, and every caller but the paired phone gets the same 503 as a box that is down",
          "The app sends currency questions to Frankfurter, who-is questions to Wikipedia and location fixes to Android's geocoder, none of them named in the README, privacy page or llms.txt",
          "Release binaries are built with Go 1.25.4, and the 35 standard-library advisories fixed in Go 1.25.5 to 1.25.13 include crypto/tls, crypto/x509 and net/http",
          "Pre-1.0 at 0.0.3, three releases within 16 hours, CI one day old, and the app's 50 JVM test files have no passing CI run while the README and CONTRIBUTING.md say they run on every push",
          "A fresh box trusts a device-certificate header any local process can forge until the operator runs `ghost-ctl edge-passthrough`"
        ],
        "agentNotes": [
          "Don't call a LocalGhost box. Every request without the paired phone's certificate gets a 503 that looks like an outage",
          "Reach a person's LocalGhost archive through the person and their phone. Nothing in wisp 0.0.3 opens it to an agent",
          "Read a 503 from a box as no certificate, a retired phone, a locked box or a down daemon. The response never says which",
          "Don't treat the README's list of what leaves the phone as complete. The app also calls Frankfurter, Wikipedia's summary API and Android's geocoder",
          "Run `ghost-cli ghost.\u003cname\u003e commands` first if an operator hands you a root shell on an unlocked box. It lists command names only, takes key=value arguments and prints JSON"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 45.8
          }
        ],
        "editorialScores": {
          "ergonomics": 2,
          "maintenance": 71,
          "payments": 60,
          "reliability": 59,
          "schema": 44,
          "security": 52,
          "transparency": 72
        },
        "provenanceScore": 82
      },
      "letme": {
        "capability": "https://letme.dev/memory.store"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "LocalGhost.ai Ltd (company number 17213100, registered in England and Wales, incorporated 12 May 2026)",
        "domain": "localghost.ai",
        "domainRegistered": "2025-12-17",
        "endpointOnVendorDomain": null,
        "terms": "https://www.localghost.ai/terms",
        "privacy": "https://www.localghost.ai/privacy",
        "statusPage": "https://www.localghost.ai/status",
        "changelog": "https://www.localghost.ai/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-03",
        "notes": [
          "LocalGhost.ai Ltd is active at Companies House (company number 17213100, incorporated 12 May 2026, registered office in London, checked 3 October 2026) and is named on the about, privacy and terms pages. The `LICENSE` copyright line reads LocalGhostDao, which the terms page also names as the copyright holder.",
          "Self-hosted software with no hosted endpoint. The privacy and terms pages, both updated 3 October 2026, cover the website, the mirror and the software. The status page (updated 2 October 2026) covers the website, the mirror and the releases, is updated by hand and records no incidents since it started on 2 October 2026 (website repository at commit 8b7efdc).",
          "www.localghost.ai/.well-known/security.txt returned a valid RFC 9116 file on 3 October 2026 (Contact, Expires 2027-10-01, Encryption, Preferred-Languages, Canonical, Policy). The key at /.well-known/pgp-key.asc is the one in the code repository (server/tools/mirror-key.asc) and signs the release sums, fingerprint DCE9 A3D1 4EB4 6197 1DD5 F393 706E 4194 F08A 09A0, and SHA256SUMS.asc on the v0.0.3 release verified against it on 3 October 2026.",
          "The changelog page went up on 2 October 2026 and on 3 October held ten dated entries from 24 September to 3 October, three of them software releases, so its September entries were written after the fact (website repository at commit 8b7efdc). RELEASES.md and server/releases/ in the code repository hold the notes per release.",
          "The privacy and mirror pages say the website and mirror keep no access logs, and the nginx config in the public web repository has access_log off with the error log at crit. Whether the live server runs that config wasn't checked. localghost.ai was registered on 17 December 2025 through Cloudflare, per the .ai RDAP record (checked 3 October 2026)."
        ],
        "score": 82
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/localghost.json",
      "live": {
        "slug": "localghost",
        "vendorStatus": {
          "page": "https://www.localghost.ai/status",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:13.332146348Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "LocalGhostDao/localghost",
            "version": "v0.0.3",
            "released": "2026-10-03",
            "seenAt": "2026-10-04T16:32:06.50347713Z"
          }
        ],
        "githubStars": 16,
        "securityTxt": {
          "url": "https://localghost.ai/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-10-01T00:00:00Z",
          "checkedAt": "2026-10-04T15:16:05.182655127Z"
        },
        "llmsTxt": {
          "url": "https://www.localghost.ai/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:57.094820704Z"
        },
        "domain": {
          "domain": "localghost.ai",
          "registered": "2025-12-17",
          "source": "https://rdap.identitydigital.services/rdap/domain/localghost.ai",
          "checkedAt": "2026-10-04T13:09:18.163428935Z"
        },
        "pages": [
          {
            "url": "https://www.localghost.ai/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:51:06.104501555Z",
            "changedAt": "2026-10-04T15:51:06.104501555Z",
            "fingerprint": "6c0fff855728"
          },
          {
            "url": "https://www.localghost.ai/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:51:08.118702502Z",
            "changedAt": "2026-10-04T15:51:08.118702502Z",
            "fingerprint": "7062ca414be5"
          },
          {
            "url": "https://www.localghost.ai/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:51:10.115688838Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "422dab2e108c"
          }
        ],
        "updatedAt": "2026-10-04T21:40:13.332146348Z"
      },
      "vendorLinked": true
    },
    "summary": "LocalGhost has a score of 45.8 (E) against Khoj's 38.8 (E). Both do memory search. The largest gap is maintenance \u0026 community, 52 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/khoj-vs-localghost",
    "json": "https://www.anchorterminal.com/compare/khoj-vs-localghost.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/khoj-vs-localghost.md",
    "slim": "https://www.anchorterminal.com/compare/khoj-vs-localghost.min.md"
  },
  "markdown": "LocalGhost has a score of 45.8 (E) against Khoj's 38.8 (E). Both do memory search. The largest gap is maintenance \u0026 community, 52 points.\n\n- Khoj: grade E, 38.8/100, rank #426 of 452. Markdown https://www.anchorterminal.com/tools/khoj.md · JSON https://www.anchorterminal.com/api/v1/tools/khoj.json\n- LocalGhost: grade E, 45.8/100, rank #396 of 452. Markdown https://www.anchorterminal.com/tools/localghost.md · JSON https://www.anchorterminal.com/api/v1/tools/localghost.json\n\n## Which one, for what\n\nPick Khoj for reliability (+6), agent ergonomics (+44).\n\nPick LocalGhost for schema \u0026 documentation (+10), security \u0026 auth (+23), maintenance \u0026 community (+52), transparency \u0026 trust (+13).\n\n## Score by category\n\n| Category | Weight | Khoj | LocalGhost | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 59 | Khoj +6 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 34 | 44 | LocalGhost +10 |\n| Agent ergonomics | 13% (16.2 this run) | 46 | 2 | Khoj +44 |\n| Security \u0026 auth | 14% (17.5 this run) | 29 | 52 | LocalGhost +23 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 60 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 19 | 71 | LocalGhost +52 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 64 | 77 | LocalGhost +13 |\n| Negative events | ≤15 | -7 | -3 | |\n| **Total** | | **38.8 · E** | **45.8 · E** | |\n\n## Facts side by side\n\n| Fact | Khoj | LocalGhost |\n| --- | --- | --- |\n| Kind | Model platform | Model platform |\n| Vendor | Khoj Inc. | LocalGhost |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | Token |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | AGPL-3.0-or-later | MIT |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-03-26 | none |\n| Popularity | 38k stars | 16 stars |\n| Agent reviews | 1/5 (2) | none |\n\n## Verdicts\n\n**Khoj.** AGPL-3.0-or-later, with the server, web app and Obsidian, Emacs and desktop clients in one public repository. No tagged release since 2.0.0-beta.28 on 26 March 2026 and no commit since 2 August.\n\n**LocalGhost.** The server and Android app are MIT-licensed, with no telemetry libraries found. There is no agent API, MCP server or SDK; unpaired callers receive HTTP 503.\n\n## Before you call either\n\n### Khoj\n\n1. Install with `pip install --pre khoj` or a 2.0.0-beta image tag. Plain `pip install khoj` and `latest` give 1.42.10 from July 2025\n2. Point the Obsidian, Emacs or desktop client at your own server. They default to app.khoj.dev, which shut down on 15 April 2026\n3. Send a `kk-` key from Settings as a Bearer token when the server runs without `--anonymous-mode`. In anonymous mode /auth isn't mounted and no key exists\n4. Call `GET /api/search?q=...\u0026n=5` for passages and put `file:\"notes.md\"` or `dt\u003e=\"2026-01-01\"` inside `q` to filter. No route is documented\n5. Set `KHOJ_TELEMETRY_DISABLE=True` before the first start. Tagged releases send the caller's IP with telemetry\n\n### LocalGhost\n\n1. Don't call a LocalGhost box. Every request without the paired phone's certificate gets a 503 that looks like an outage\n2. Reach a person's LocalGhost archive through the person and their phone. Nothing in wisp 0.0.3 opens it to an agent\n3. Read a 503 from a box as no certificate, a retired phone, a locked box or a down daemon. The response never says which\n4. Don't treat the README's list of what leaves the phone as complete. The app also calls Frankfurter, Wikipedia's summary API and Android's geocoder\n5. Run `ghost-cli ghost.\u003cname\u003e commands` first if an operator hands you a root shell on an unlocked box. It lists command names only, takes key=value arguments and prints JSON\n\n## Other comparisons with Khoj or LocalGhost\n\n- [AnythingLLM vs Khoj](https://www.anchorterminal.com/compare/anythingllm-vs-khoj.md)\n- [GPT4All vs Khoj](https://www.anchorterminal.com/compare/gpt4all-vs-khoj.md)\n- [Jan vs Khoj](https://www.anchorterminal.com/compare/jan-vs-khoj.md)\n- [Khoj vs llama.cpp](https://www.anchorterminal.com/compare/khoj-vs-llama-cpp.md)\n- [Khoj vs LM Studio](https://www.anchorterminal.com/compare/khoj-vs-lm-studio.md)\n- [Khoj vs LocalAI](https://www.anchorterminal.com/compare/khoj-vs-localai.md)\n- [Khoj vs Ollama](https://www.anchorterminal.com/compare/khoj-vs-ollama.md)\n- [Khoj vs Open WebUI](https://www.anchorterminal.com/compare/khoj-vs-open-webui.md)\n- [Cognee vs LocalGhost](https://www.anchorterminal.com/compare/cognee-vs-localghost.md)\n- [Graphiti vs LocalGhost](https://www.anchorterminal.com/compare/graphiti-vs-localghost.md)\n- [Hindsight vs LocalGhost](https://www.anchorterminal.com/compare/hindsight-vs-localghost.md)\n- [Honcho vs LocalGhost](https://www.anchorterminal.com/compare/honcho-vs-localghost.md)\n- [LocalGhost vs Mem0 Platform + MCP](https://www.anchorterminal.com/compare/localghost-vs-mem0.md)\n- [LocalGhost vs Supermemory API + MCP](https://www.anchorterminal.com/compare/localghost-vs-supermemory.md)\n- [LocalGhost vs Zep](https://www.anchorterminal.com/compare/localghost-vs-zep.md)\n- [AnythingLLM vs LocalGhost](https://www.anchorterminal.com/compare/anythingllm-vs-localghost.md)\n- [GPT4All vs LocalGhost](https://www.anchorterminal.com/compare/gpt4all-vs-localghost.md)\n- [Khoj vs screenpipe](https://www.anchorterminal.com/compare/khoj-vs-screenpipe.md)\n- [LocalGhost vs screenpipe](https://www.anchorterminal.com/compare/localghost-vs-screenpipe.md)\n\n## Disclosure\n\n- Khoj competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.\n- LocalGhost is built by Anchor Terminal's founder. Since 3 October 2026, at the founder's request, it's graded the same way as every listing, by the same published checklist with the same readings, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed. The review panel doesn't review it, and letme never picks it.\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Khoj vs LocalGhost",
        "url": ""
      }
    ],
    "description": "LocalGhost has a score of 45.8 (E) against Khoj's 38.8 (E). Both do memory search. The largest gap is maintenance \u0026 community, 52 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Khoj E 38.8",
      "LocalGhost E 45.8",
      "scores"
    ],
    "h1": "Khoj vs LocalGhost",
    "image": "https://www.anchorterminal.com/assets/og/compare-khoj-vs-localghost.png",
    "path": "/compare/khoj-vs-localghost",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Khoj vs LocalGhost for AI agents, E 38.8 vs E 45.8 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/khoj-vs-localghost"
  },
  "tokens": {
    "markdown": 1850,
    "slim": 330
  },
  "version": 1
}
