{
  "data": {
    "a": {
      "slug": "khoj",
      "name": "Khoj",
      "vendor": "Khoj Inc.",
      "vendorUrl": "https://khoj.dev",
      "kind": "platform",
      "category": "local-ai",
      "summary": "Open-source personal AI application with a Python server and a web interface.",
      "url": "https://www.anchorterminal.com/tools/khoj",
      "markdownUrl": "https://www.anchorterminal.com/tools/khoj.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/khoj.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/khoj.json",
      "repo": "https://github.com/khoj-ai/khoj",
      "license": "AGPL-3.0-or-later",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "khoj"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/khoj-ai/khoj"
        }
      ],
      "auth": "mixed",
      "authNotes": "The Docker Compose file and the pip quick start both run Khoj with `--anonymous-mode`, which serves every request as a default user with no sign-in and doesn't mount the /auth routes, so no API key can be created in that mode. The Compose file starts the server on 0.0.0.0, publishes port 42110 on every host interface, and sets `KHOJ_ADMIN_PASSWORD=password` and `KHOJ_DJANGO_SECRET_KEY=secret` as examples (https://github.com/khoj-ai/khoj/blob/master/docker-compose.yml). Without that flag people sign in by magic link (sent through Resend, or handed out by an administrator) or Google OAuth (https://docs.khoj.dev/advanced/authentication). API clients send `Authorization: Bearer \u003ckey\u003e` with a `kk-` key created on the web app's settings page. Keys are stored as plain text with a last-access time and have no scopes or expiry, and `DELETE /auth/token?token=\u003ckey\u003e` revokes one (https://github.com/khoj-ai/khoj/blob/master/src/khoj/configure.py; https://github.com/khoj-ai/khoj/blob/master/src/khoj/routers/auth.py). Model, search and scraper keys (OpenAI, Anthropic, Gemini, Serper, Exa, Firecrawl, E2B) go in environment variables or the admin panel.",
      "pricing": "free",
      "pricingNotes": "Free and AGPL-3.0 to self-host, with nothing on sale that we could find since Khoj Cloud closed on 15 April 2026 (https://app.khoj.dev). The README still links Khoj Enterprise at khoj.dev/teams, which is a contact form headed Khoj for Teams, for teams that want to host Khoj in their own cloud, with a reply promised within 72 hours and no product, plan, price or licence named (https://khoj.dev/teams). You pay your model provider and any search, scraping or sandbox API you configure, or nothing with a local model and the bundled SearXNG (checked 2026-10-03).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 37500,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://docs.khoj.dev",
      "capabilities": [
        "memory.search",
        "memory.user",
        "inference.local",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "free",
        "python",
        "docker",
        "beta",
        "telemetry-default-on"
      ],
      "lastRelease": "2026-03-26",
      "graded": true,
      "disclosure": "Khoj competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
      "competesWith": "localghost",
      "anchor": {
        "graded": true,
        "score": 38.8,
        "grade": "E",
        "agentReady": false,
        "rank": 426,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 10,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 46,
          "maintenance": 19,
          "payments": 60,
          "reliability": 65,
          "schema": 34,
          "security": 29,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -7,
        "negativeNotes": [
          "2026-07-13. Default-on telemetry sent the caller's IP (`client_host`) to khoj.beta.haletic.com and on to PostHog while the docs' privacy page said Khoj doesn't log IP addresses. Reported in #1374 and removed on master on 2 August 2026, but 1.42.10 and 2.0.0-beta.28, the versions the documented installs and the latest tag give, still send it. Request metadata rather than content, so the minimum, -2. https://github.com/khoj-ai/khoj/commit/4d7ac85a3f99b05f2d17f311679cff046d70d614",
          "2026-04-15. Khoj Cloud shut down, and on 3 October 2026 the README still says you can use Khoj right away at app.khoj.dev with no setup, the docs site still links to app.khoj.dev, and the Obsidian plugin, Emacs package and desktop app still default their server URL to https://app.khoj.dev. An endpoint removed while still advertised. The shutdown had three weeks' notice in the app, so the minimum, -3. https://github.com/khoj-ai/khoj/blob/master/README.md; https://github.com/khoj-ai/khoj/blob/master/src/interface/obsidian/src/settings.ts",
          "2026-02-01. CVE-2025-69207 (GHSA-6whj-7qmg-86qj, 5.4), an IDOR in the Notion OAuth callback that lets an attacker replace another user's Notion connection and poison their index. The check was hardened on 28 December 2025 and ships in 2.0.0-beta.23 and later, but the advisory lists no patched version, and 1.42.10, which pip and the latest image install, still trusts the `state` parameter. It needs a Notion OAuth app and more than one user, -1. https://github.com/khoj-ai/khoj/security/advisories/GHSA-6whj-7qmg-86qj",
          "2026-06-24. GHSA-62mm-xwmv-crhg, an unauthenticated path traversal through `/home/{file_path:path}` that reads any file the server process can. The route arrived in 2.0.0-beta.23 (29 December 2025) and was guarded in 2.0.0-beta.25 (22 February 2026), so two pre-releases were exposed and 1.42.10 never had the route. Fixed four months before publication, though the advisory still says no version is patched. Fixed and decayed, -1. https://github.com/khoj-ai/khoj/security/advisories/GHSA-62mm-xwmv-crhg; https://github.com/khoj-ai/khoj/commit/21c51b9a"
        ],
        "verdict": "AGPL-3.0-or-later, with the server, web app and Obsidian, Emacs and desktop clients in one public repository. No tagged release since 2.0.0-beta.28 on 26 March 2026 and no commit since 2 August.",
        "disclosure": "Khoj competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
        "strengths": [
          "AGPL-3.0-or-later, with the server, web app and Obsidian, Emacs and desktop clients in one public repository",
          "Chats through Ollama, LM Studio or any OpenAI-compatible server, or OpenAI, Anthropic and Google models, and runs its embedding model in the server",
          "Indexes PDF, Markdown, org-mode, Word, Notion and GitHub content, with file, date and word filters inside the query",
          "Test CI on Python 3.10 to 3.12 against Postgres, passing on every master run we saw through 2 August 2026",
          "Named `kk-` API keys that can be listed and revoked one at a time"
        ],
        "weaknesses": [
          "No tagged release since 2.0.0-beta.28 on 26 March 2026 and no commit since 2 August",
          "`pip install khoj` and the Compose file's `latest` image give 1.42.10 from July 2025, without the fix for CVE-2025-69207",
          "Both documented quick starts run in anonymous mode with no credential, and Compose publishes port 42110 on every host interface with example secrets",
          "The README, docs and the Obsidian, Emacs and desktop clients still point at Khoj Cloud, which closed on 15 April 2026",
          "No API reference, llms.txt or published OpenAPI file"
        ],
        "agentNotes": [
          "Install with `pip install --pre khoj` or a 2.0.0-beta image tag. Plain `pip install khoj` and `latest` give 1.42.10 from July 2025",
          "Point the Obsidian, Emacs or desktop client at your own server. They default to app.khoj.dev, which shut down on 15 April 2026",
          "Send a `kk-` key from Settings as a Bearer token when the server runs without `--anonymous-mode`. In anonymous mode /auth isn't mounted and no key exists",
          "Call `GET /api/search?q=...\u0026n=5` for passages and put `file:\"notes.md\"` or `dt\u003e=\"2026-01-01\"` inside `q` to filter. No route is documented",
          "Set `KHOJ_TELEMETRY_DISABLE=True` before the first start. Tagged releases send the caller's IP with telemetry"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 1,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 38.8
          }
        ],
        "editorialScores": {
          "ergonomics": 46,
          "maintenance": 19,
          "payments": 60,
          "reliability": 65,
          "schema": 34,
          "security": 29,
          "transparency": 60
        },
        "provenanceScore": 67
      },
      "connect": {
        "install": "python -m pip install 'khoj[local]'   # then: USE_EMBEDDED_DB=\"true\" khoj --anonymous-mode   # or: wget https://raw.githubusercontent.com/khoj-ai/khoj/master/docker-compose.yml \u0026\u0026 docker-compose up"
      },
      "letme": {
        "capability": "https://letme.dev/memory.search",
        "tool": "https://letme.dev/khoj"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "Khoj Inc.",
        "domain": "khoj.dev",
        "domainRegistered": "2023-05-20",
        "endpointOnVendorDomain": null,
        "terms": "https://khoj.dev/terms-of-service.html",
        "privacy": "https://khoj.dev/privacy-policy.html",
        "statusPage": "",
        "changelog": "https://github.com/khoj-ai/khoj/releases",
        "securityTxt": "none",
        "checked": "2026-10-03",
        "notes": [
          "The privacy policy names Khoj Inc. as the operator of khoj.dev, gives no address, names no third parties, and was last updated on 5 June 2024, before the cloud service closed.",
          "khoj.dev/.well-known/security.txt returns 404 per the listing's check. The repository has no SECURITY.md and GitHub says the project has not set one up. Private vulnerability reporting is on, with six advisories published.",
          "RDAP for khoj.dev gives a registration date of 2023-05-20, registrar Cloudflare.",
          "There's no hosted endpoint since Khoj Cloud closed on 15 April 2026. A self-hosted server answers on its owner's own host."
        ],
        "score": 67
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/khoj.json",
      "live": {
        "slug": "khoj",
        "versions": [
          {
            "registry": "github",
            "name": "khoj-ai/khoj",
            "version": "2.0.0-beta.28",
            "released": "2026-03-26",
            "seenAt": "2026-10-04T16:30:51.951568389Z"
          },
          {
            "registry": "pypi",
            "name": "khoj",
            "version": "1.42.10",
            "released": "2025-07-15",
            "seenAt": "2026-10-04T16:30:51.762954646Z"
          }
        ],
        "githubStars": 37560,
        "securityTxt": {
          "url": "https://khoj.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:02.115233077Z"
        },
        "domain": {
          "domain": "khoj.dev",
          "registered": "2023-05-20",
          "source": "https://pubapi.registry.google/rdap/domain/khoj.dev",
          "checkedAt": "2026-10-04T13:07:42.860690409Z"
        },
        "pages": [
          {
            "url": "https://khoj.dev/privacy-policy.html",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:12.44696744Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c03103b79f52"
          },
          {
            "url": "https://khoj.dev/terms-of-service.html",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:14.556582845Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e08893bf1c28"
          }
        ],
        "updatedAt": "2026-10-04T16:30:51.951568389Z"
      }
    },
    "b": {
      "slug": "open-webui",
      "name": "Open WebUI",
      "vendor": "Open WebUI Inc.",
      "vendorUrl": "https://openwebui.com",
      "kind": "platform",
      "category": "local-ai",
      "summary": "Self-hosted web interface for chatting with models, from Open WebUI Inc., with a Python (FastAPI) back end and a Svelte front end.",
      "url": "https://www.anchorterminal.com/tools/open-webui",
      "markdownUrl": "https://www.anchorterminal.com/tools/open-webui.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/open-webui.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/open-webui.json",
      "repo": "https://github.com/open-webui/open-webui",
      "license": "Open WebUI License. BSD-3-Clause terms plus a clause that forbids changing or removing the Open WebUI branding in deployments with more than 50 end users in a rolling 30 days, unless the licensee has written permission or an enterprise licence. Code from before set commits stays under MIT or BSD-3-Clause (LICENSE_HISTORY), and contributors sign a CLA",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "open-webui"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/open-webui/open-webui"
        }
      ],
      "auth": "api-key",
      "authNotes": "Sign-in is on by default (`WEBUI_AUTH`), the first account to sign up becomes admin, and sign-up then closes. An agent calls the API with `Authorization: Bearer \u003ctoken\u003e`, either an `sk-` API key from Settings \u003e Account or a session JWT, which lasts four weeks by default (`JWT_EXPIRES_IN`), and behind a reverse proxy that uses `Authorization` itself the key can go in an `x-api-key` header (https://docs.openwebui.com/reference/api-endpoints). API keys stay off until an administrator turns them on (`ENABLE_API_KEYS` defaults to false), a group permission decides who may create one, and they can be limited instance-wide to listed endpoints with `ENABLE_API_KEYS_ENDPOINT_RESTRICTIONS` and `API_KEYS_ALLOWED_ENDPOINTS` (https://github.com/open-webui/open-webui/blob/main/backend/open_webui/config.py). Each user has one key, `sk-` plus 32 hexadecimal characters, stored as plain text with a last-used time and no expiry set by the API (https://github.com/open-webui/open-webui/blob/main/backend/open_webui/routers/auths.py). People sign in with email and password, OAuth or OIDC, LDAP or trusted headers, with SCIM 2.0 provisioning.",
      "pricing": "free",
      "pricingNotes": "Free to self-host under the Open WebUI License. Deployments with more than 50 end users in a rolling 30 days have to keep the Open WebUI branding unless they hold an enterprise licence or written permission. The enterprise licence (white-labelling, SLA-backed support, Terminals) is sold through sales to registered organisations only, with no published prices (https://docs.openwebui.com/enterprise). There's no hosted Open WebUI service. You pay your model provider, or nothing with a local model (checked 2026-10-03).",
      "priceSummary": "Free",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 153000,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://docs.openwebui.com",
      "llmsTxt": "https://docs.openwebui.com/llms.txt",
      "capabilities": [
        "inference.local",
        "agent.mcp-client",
        "memory.user",
        "knowledge.search"
      ],
      "tags": [
        "self-hosted",
        "local",
        "free",
        "python",
        "docker",
        "openai-compatible",
        "llms-txt",
        "enterprise"
      ],
      "lastRelease": "2026-09-21",
      "graded": true,
      "disclosure": "Open WebUI competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
      "competesWith": "localghost",
      "anchor": {
        "graded": true,
        "score": 52,
        "grade": "D",
        "agentReady": false,
        "rank": 345,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 7,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 54,
          "maintenance": 91,
          "payments": 20,
          "reliability": 68,
          "schema": 60,
          "security": 63,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -8,
        "negativeNotes": [
          "2026-05-05. GHSA-2r4p-jpmg-48f4 (CVE-2026-44551, Critical, 9.1). LDAP sign-in accepted an empty password where the directory allows unauthenticated binds, giving full access to the victim's account. It affects 0.8.12 and earlier and was fixed in 0.9.0 (21 April 2026) before publication, -2. https://github.com/open-webui/open-webui/security/advisories/GHSA-2r4p-jpmg-48f4",
          "2026-07-02. GHSA-74h3-cxq7-vc5q (CVE-2026-59216, 7.7). A signed-in low-privilege user could run code and tools in another user's session through an unchecked Socket.IO session_id, which against an administrator meant code execution as the server process (root in default containers). Fixed in 0.10.0 on 29 June 2026 and published three days later, -2. https://github.com/open-webui/open-webui/security/advisories/GHSA-74h3-cxq7-vc5q",
          "2026-08-02 and 2026-09-04. Two account takeovers through OAuth, both High. GHSA-rq84-p6rr-vf89 accepted tokens issued to any client in the OAuth token exchange (fixed in 0.11.0), and GHSA-wpmr-8h3q-fwj7 (8.1) matched OAuth and OIDC subjects by substring on SQLite, so a crafted subject could sign in as an existing account, administrators included (fixed in 0.11.1 on 25 August). Both fixed before publication, -2. https://github.com/open-webui/open-webui/security/advisories/GHSA-rq84-p6rr-vf89; https://github.com/open-webui/open-webui/security/advisories/GHSA-wpmr-8h3q-fwj7",
          "2025-10-03 to 2026-10-03. The rest of the year's record. GitHub reviewed 143 of the repository's advisories in the 12 months to 3 October 2026, and 129 cover flaws fixed in releases from 0.6.35 (6 November 2025) on, 58 High and 1 Critical, more than half of them access-control or authorisation flaws by their titles and CWE tags. July to September alone brought 52 (18 High, 29 Moderate, 5 Low) in batches published on 2 July, 2 August and 4 September. Each was fixed in a release before publication, so the 125 beyond the four above count together, -2. https://github.com/open-webui/open-webui/security/advisories; https://github.com/advisories?query=open-webui+type%3Areviewed+ecosystem%3Apip"
        ],
        "verdict": "Five releases in the 90 days to 3 October 2026, each with a dated changelog entry that warns of database migrations. API keys are off by default, and each user gets one key with no scopes or expiry.",
        "disclosure": "Open WebUI competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
        "strengths": [
          "Five releases in the 90 days to 3 October 2026, each with a dated changelog entry that warns of database migrations",
          "OpenAI-compatible `/api/chat/completions` and `/api/models`, plus an Anthropic Messages route and an Ollama proxy, so OpenAI's SDKs work against a local instance",
          "Roles, groups, per-model and per-knowledge access grants, a group permission for key creation and an instance-wide endpoint allowlist for keys",
          "An audit log at metadata, request or request-and-response level, plus events for key creation and deletion",
          "No product telemetry found, third-party analytics off in the Docker image, and `OFFLINE_MODE` to stop the release check and model downloads"
        ],
        "weaknesses": [
          "API keys are off by default, and each user gets one key with no scopes or expiry",
          "The API reference covers seven route groups, and the OpenAPI file and Swagger UI need `ENV=dev`",
          "52 advisories published from July to September 2026, 18 of them High, including cross-user code execution (CVE-2026-59216) and two OAuth account takeovers, all fixed",
          "Pre-1.0 (0.11), with database migrations in patch releases and no rolling updates during them",
          "The branding clause makes the licence non-OSI, and the enterprise licence has no published price"
        ],
        "agentNotes": [
          "Ask the administrator to set `ENABLE_API_KEYS=true` and let your group create keys. `sk-` keys are refused until then",
          "Send OpenAI's request shape to `/api/chat/completions` with a Bearer key, or use `x-api-key` behind a proxy that takes `Authorization` for itself",
          "Call `/api/models` first and use an `id` from it. Model IDs depend on the instance's connections",
          "Poll `GET /api/v1/files/{id}/process/status` until it reads `completed` before adding a file to a knowledge base",
          "Expect a 403 on routes outside `API_KEYS_ALLOWED_ENDPOINTS` when the administrator has set an allowlist"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 52
          }
        ],
        "editorialScores": {
          "ergonomics": 54,
          "maintenance": 91,
          "payments": 20,
          "reliability": 68,
          "schema": 60,
          "security": 63,
          "transparency": 66
        },
        "provenanceScore": 79
      },
      "connect": {
        "install": "pip install open-webui \u0026\u0026 open-webui serve   # or: docker run -d -p 3000:8080 --add-host=host.docker.internal:host-gateway -v open-webui:/app/backend/data --name open-webui --restart always ghcr.io/open-webui/open-webui:main",
        "http": "curl -X POST http://localhost:3000/api/chat/completions \\\n  -H \"Authorization: Bearer $OPEN_WEBUI_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"model\": \"llama3.1\", \"messages\": [{\"role\": \"user\", \"content\": \"Why is the sky blue?\"}]}'"
      },
      "letme": {
        "capability": "https://letme.dev/inference.local",
        "tool": "https://letme.dev/open-webui"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "Open WebUI Inc.",
        "domain": "openwebui.com",
        "domainRegistered": "2024-02-17",
        "endpointOnVendorDomain": null,
        "terms": "https://openwebui.com/terms",
        "privacy": "https://openwebui.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/open-webui/open-webui/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-03",
        "notes": [
          "The LICENSE copyright line names Open WebUI Inc., created by Timothy Jaeryang Baek, and the privacy policy names Open WebUI, Inc. with no address.",
          "openwebui.com/.well-known/security.txt points to GitHub Security Advisories and expires on 2027-06-30.",
          "The privacy policy, last updated on 31 December 2025, covers openwebui.com and its community services only, says nothing about the self-hosted software, and gives no retention periods.",
          "We found no status page linked from openwebui.com. There's no hosted service, so an instance answers on its owner's own host.",
          "RDAP for openwebui.com gives a registration date of 2024-02-17, registrar Cloudflare. The terms page wasn't read for this check."
        ],
        "score": 79
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/open-webui.json",
      "live": {
        "slug": "open-webui",
        "versions": [
          {
            "registry": "github",
            "name": "open-webui/open-webui",
            "version": "v0.11.4",
            "released": "2026-09-21",
            "seenAt": "2026-10-04T16:35:15.328941559Z"
          },
          {
            "registry": "pypi",
            "name": "open-webui",
            "version": "0.11.4",
            "released": "2026-09-21",
            "seenAt": "2026-10-04T16:35:15.214147757Z"
          }
        ],
        "githubStars": 153934,
        "pypiWeekly": 235140,
        "securityTxt": {
          "url": "https://openwebui.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-06-30T00:00:00Z",
          "checkedAt": "2026-10-04T15:15:55.536560702Z"
        },
        "llmsTxt": {
          "url": "https://docs.openwebui.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:04.221173659Z"
        },
        "domain": {
          "domain": "openwebui.com",
          "registered": "2024-02-17",
          "source": "https://rdap.verisign.com/com/v1/domain/openwebui.com",
          "checkedAt": "2026-10-04T13:06:48.742159254Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/open-webui/open-webui/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:47:49.239650644Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3c27bf8cc8f9"
          },
          {
            "url": "https://openwebui.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:32.010185663Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ab8757357aa3"
          },
          {
            "url": "https://openwebui.com/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:35.689261473Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "87cd832136e7"
          }
        ],
        "updatedAt": "2026-10-04T16:35:15.328941559Z"
      }
    },
    "summary": "Open WebUI has a score of 52 (D) against Khoj's 38.8 (E). Both do local inference. The largest gap is maintenance \u0026 community, 72 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/khoj-vs-open-webui",
    "json": "https://www.anchorterminal.com/compare/khoj-vs-open-webui.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/khoj-vs-open-webui.md",
    "slim": "https://www.anchorterminal.com/compare/khoj-vs-open-webui.min.md"
  },
  "markdown": "Open WebUI has a score of 52 (D) against Khoj's 38.8 (E). Both do local inference. The largest gap is maintenance \u0026 community, 72 points.\n\n- Khoj: grade E, 38.8/100, rank #426 of 452. Markdown https://www.anchorterminal.com/tools/khoj.md · JSON https://www.anchorterminal.com/api/v1/tools/khoj.json\n- Open WebUI: grade D, 52/100, rank #345 of 452. Markdown https://www.anchorterminal.com/tools/open-webui.md · JSON https://www.anchorterminal.com/api/v1/tools/open-webui.json\n\n## Which one, for what\n\nPick Khoj for payments \u0026 pricing (+40).\n\nPick Open WebUI for schema \u0026 documentation (+26), agent ergonomics (+8), security \u0026 auth (+34), maintenance \u0026 community (+72), transparency \u0026 trust (+9).\n\n## Score by category\n\n| Category | Weight | Khoj | Open WebUI | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 68 | Open WebUI +3 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 34 | 60 | Open WebUI +26 |\n| Agent ergonomics | 13% (16.2 this run) | 46 | 54 | Open WebUI +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 29 | 63 | Open WebUI +34 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 20 | Khoj +40 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 19 | 91 | Open WebUI +72 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 64 | 73 | Open WebUI +9 |\n| Negative events | ≤15 | -7 | -8 | |\n| **Total** | | **38.8 · E** | **52 · D** | |\n\n## Facts side by side\n\n| Fact | Khoj | Open WebUI |\n| --- | --- | --- |\n| Kind | Model platform | Model platform |\n| Vendor | Khoj Inc. | Open WebUI Inc. |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | AGPL-3.0-or-later | Open WebUI License. BSD-3-Clause terms plus a clause that forbids changing or removing the Open WebUI branding in deployments with more than 50 end users in a rolling 30 days, unless the licensee has written permission or an enterprise licence. Code from before set commits stays under MIT or BSD-3-Clause (LICENSE_HISTORY), and contributors sign a CLA |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-03-26 | 2026-09-21 |\n| Popularity | 38k stars | 153k stars |\n| Agent reviews | 1/5 (2) | 2.5/5 (2) |\n\n## Verdicts\n\n**Khoj.** AGPL-3.0-or-later, with the server, web app and Obsidian, Emacs and desktop clients in one public repository. No tagged release since 2.0.0-beta.28 on 26 March 2026 and no commit since 2 August.\n\n**Open WebUI.** Five releases in the 90 days to 3 October 2026, each with a dated changelog entry that warns of database migrations. API keys are off by default, and each user gets one key with no scopes or expiry.\n\n## Before you call either\n\n### Khoj\n\n1. Install with `pip install --pre khoj` or a 2.0.0-beta image tag. Plain `pip install khoj` and `latest` give 1.42.10 from July 2025\n2. Point the Obsidian, Emacs or desktop client at your own server. They default to app.khoj.dev, which shut down on 15 April 2026\n3. Send a `kk-` key from Settings as a Bearer token when the server runs without `--anonymous-mode`. In anonymous mode /auth isn't mounted and no key exists\n4. Call `GET /api/search?q=...\u0026n=5` for passages and put `file:\"notes.md\"` or `dt\u003e=\"2026-01-01\"` inside `q` to filter. No route is documented\n5. Set `KHOJ_TELEMETRY_DISABLE=True` before the first start. Tagged releases send the caller's IP with telemetry\n\n### Open WebUI\n\n1. Ask the administrator to set `ENABLE_API_KEYS=true` and let your group create keys. `sk-` keys are refused until then\n2. Send OpenAI's request shape to `/api/chat/completions` with a Bearer key, or use `x-api-key` behind a proxy that takes `Authorization` for itself\n3. Call `/api/models` first and use an `id` from it. Model IDs depend on the instance's connections\n4. Poll `GET /api/v1/files/{id}/process/status` until it reads `completed` before adding a file to a knowledge base\n5. Expect a 403 on routes outside `API_KEYS_ALLOWED_ENDPOINTS` when the administrator has set an allowlist\n\n## Other comparisons with Khoj or Open WebUI\n\n- [AnythingLLM vs Khoj](https://www.anchorterminal.com/compare/anythingllm-vs-khoj.md)\n- [AnythingLLM vs Open WebUI](https://www.anchorterminal.com/compare/anythingllm-vs-open-webui.md)\n- [GPT4All vs Khoj](https://www.anchorterminal.com/compare/gpt4all-vs-khoj.md)\n- [GPT4All vs Open WebUI](https://www.anchorterminal.com/compare/gpt4all-vs-open-webui.md)\n- [Jan vs Khoj](https://www.anchorterminal.com/compare/jan-vs-khoj.md)\n- [Jan vs Open WebUI](https://www.anchorterminal.com/compare/jan-vs-open-webui.md)\n- [Khoj vs llama.cpp](https://www.anchorterminal.com/compare/khoj-vs-llama-cpp.md)\n- [Khoj vs LM Studio](https://www.anchorterminal.com/compare/khoj-vs-lm-studio.md)\n- [Khoj vs LocalAI](https://www.anchorterminal.com/compare/khoj-vs-localai.md)\n- [Khoj vs Ollama](https://www.anchorterminal.com/compare/khoj-vs-ollama.md)\n- [llama.cpp vs Open WebUI](https://www.anchorterminal.com/compare/llama-cpp-vs-open-webui.md)\n- [LM Studio vs Open WebUI](https://www.anchorterminal.com/compare/lm-studio-vs-open-webui.md)\n- [LocalAI vs Open WebUI](https://www.anchorterminal.com/compare/localai-vs-open-webui.md)\n- [Ollama vs Open WebUI](https://www.anchorterminal.com/compare/ollama-vs-open-webui.md)\n- [Open WebUI vs screenpipe](https://www.anchorterminal.com/compare/open-webui-vs-screenpipe.md)\n- [Khoj vs LocalGhost](https://www.anchorterminal.com/compare/khoj-vs-localghost.md)\n- [Khoj vs screenpipe](https://www.anchorterminal.com/compare/khoj-vs-screenpipe.md)\n\n## Disclosure\n\n- Khoj competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.\n- Open WebUI competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Khoj vs Open WebUI",
        "url": ""
      }
    ],
    "description": "Open WebUI has a score of 52 (D) against Khoj's 38.8 (E). Both do local inference. The largest gap is maintenance \u0026 community, 72 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Khoj E 38.8",
      "Open WebUI D 52",
      "scores"
    ],
    "h1": "Khoj vs Open WebUI",
    "image": "https://www.anchorterminal.com/assets/og/compare-khoj-vs-open-webui.png",
    "path": "/compare/khoj-vs-open-webui",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Khoj vs Open WebUI for AI agents, E 38.8 vs D 52 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/khoj-vs-open-webui"
  },
  "tokens": {
    "markdown": 1850,
    "slim": 330
  },
  "version": 1
}
