Head to head · Local inference · October 2026 research run

KoboldCpp vs vLLM

KoboldCpp scores 60.5 (C) on agent readiness against vLLM's 57.7 (C), and leads in 1 of 7 scored categories. vLLM leads on security & auth, maintenance & community and transparency & trust. Both do local inference.

Best local AI models and assistants · All 184 local ai comparisons

Which one, for what

KoboldCpp C

Good for An owner who wants text, image, speech and music models behind one executable with a writing and roleplay interface, and clients that speak the KoboldAI, OpenAI, Ollama or Anthropic formats.

Ahead on

  • Reliability, 68 against 62

Also in its favour

  • No incidents deducted, where vLLM loses 6 points for them

Watch for

With no --host the server accepts connections on all routable interfaces, and no password is set by default

vLLM C

Good for An owner with a GPU server who wants many concurrent requests against one open-weight model behind OpenAI or Anthropic compatible routes.

Ahead on

  • Security & auth, 50 against 38
  • Maintenance & community, 88 against 82
  • Transparency & trust, 67 against 49

Watch for

--api-key guards only the /v1, /v2, /inference and /cohere prefixes. /invocations, /pooling, /classify, /score, /rerank, /pause and /update_weights answer without it

Score by category

CategoryWeight this runKoboldCppvLLMEdge
Reliability16%206862KoboldCpp +6
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26868even
Agent ergonomics13%16.26364vLLM +1
Security & auth14%17.53850vLLM +12
Payments & pricing10%12.56060even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88288vLLM +6
Transparency & trust7%8.84967vLLM +18
Negative events≤150-6
Total60.5 · C57.7 · C

Facts side by side

FactKoboldCppvLLM
KindHTTP APIHTTP API
VendorLostRuins (Concedo)vLLM project (PyTorch Foundation)
Hosted endpointno (local only)no (local only)
TransportsHTTPHTTP
AuthNoneNone
PricingFreeFree
x402nono
LicenceAGPL-3.0 for KoboldCpp and KoboldAI Lite. The bundled GGML, llama.cpp and stable-diffusion.cpp code stays under MITApache-2.0
Read-only variant documentednono
llms.txtyesno
Last release2026-09-272026-10-02
Terms last updatedno document linkedno document linked
Privacy policy last updatedno document linkedno document linked
Customer content may train models
Terms restrict automated access
Terms restrict benchmarking
Terms or service can change without notice
Arbitration or class-action waiver
Popularity12k stars93k stars

Verdicts

KoboldCpp

One file runs text, image, speech and music models behind a published OpenAPI 3.0.3 document, with eight releases in 90 days. The server listens on every interface with no password by default, and --password leaves the image routes open.

vLLM

Apache-2.0 software with a release about every two weeks, each with notes that list breaking changes and security fixes. The optional API key covers only some path prefixes, so /invocations and control routes such as /pause answer without it, and at least 81 security advisories were published in the 12 months to 9 October 2026.

Before you call either

KoboldCpp

  1. Start with --host 127.0.0.1 and --password. The default listens on every interface with no key
  2. Send the password as Authorization: Bearer <password>. It is not read from the query string
  3. Treat 503 as both busy and rate limited. The server never sends 429 or Retry-After, and the wait in seconds is in detail.msg
  4. Pass max_length or max_tokens. The default is 2,048 tokens unless --defaultgenamt changes it
  5. Send a genkey with each generation so /api/extra/generate/check and /api/extra/abort act on your request and not another caller's

vLLM

  1. Put a reverse proxy that allowlists routes in front of the server. --api-key leaves /invocations and the control routes open
  2. Pass --host 127.0.0.1 for single-machine use. With no --host the server listens on every interface
  3. Set VLLM_NO_USAGE_STATS=1 or DO_NOT_TRACK=1 before starting if nothing should be sent to stats.vllm.ai
  4. Start with --enable-auto-tool-choice and the --tool-call-parser for the model before sending tools. Tool calling is off without them
  5. Send max_tokens on every request, and read the breaking changes section of the release notes before upgrading a minor version

Questions

Which is better for AI agents, KoboldCpp or vLLM?

KoboldCpp scores 60.5 (C) on agent readiness against vLLM's 57.7 (C), and leads in 1 of 7 scored categories. vLLM leads on security & auth, maintenance & community and transparency & trust.

Do KoboldCpp and vLLM need an API key?

Neither needs a key.

Can an agent call KoboldCpp and vLLM without installing anything?

No hosted endpoint is listed for KoboldCpp. No hosted endpoint is listed for vLLM.

Are KoboldCpp and vLLM open source?

Yes. KoboldCpp is open source (AGPL-3.0 for KoboldCpp and KoboldAI Lite. The bundled GGML, llama.cpp and stable-diffusion.cpp code stays under MIT). vLLM is open source (Apache-2.0).

Other comparisons with KoboldCpp or vLLM

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.