{
  "data": {
    "a": {
      "slug": "lemonade",
      "name": "Lemonade",
      "vendor": "AMD and the Lemonade community",
      "vendorUrl": "https://lemonade-server.ai",
      "kind": "http-api",
      "category": "local-ai",
      "summary": "Open-source local AI server from AMD and community contributors. It runs text, speech and image models on the owner's CPU, GPU or NPU behind OpenAI-, Anthropic- and Ollama-compatible APIs and an MCP endpoint on port 13305.",
      "url": "https://www.anchorterminal.com/tools/lemonade",
      "markdownUrl": "https://www.anchorterminal.com/tools/lemonade.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/lemonade.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/lemonade.json",
      "repo": "https://github.com/lemonade-sdk/lemonade",
      "license": "Apache 2.0. Each backend (llama.cpp, whisper.cpp, stable-diffusion.cpp, FastFlowLM and others) is downloaded separately under its own licence",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "ghcr.io/lemonade-sdk/lemonade-server"
        }
      ],
      "auth": "api-key",
      "authNotes": "Off by default. With no key set, every endpoint answers without authentication, on a default bind of localhost. `LEMONADE_API_KEY` sets one bearer key for the regular API (`/api/*`, `/v0/*`, `/v1/*`, `/mcp` and `/metrics`). `LEMONADE_ADMIN_API_KEY` sets a second key for the internal control endpoints (`/internal/*`), and without it the regular key reaches those too. Both are environment variables, so there are no per-user keys. The docs tell WebSocket clients to pass `?api_key=KEY` in the URL.",
      "pricing": "free",
      "pricingNotes": "Free and Apache 2.0 with nothing to buy and no account. You run it on your own hardware. Cloud Offload, which is optional and experimental, bills through the owner's own keys at whichever cloud provider they add.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 6,
      "popularity": {
        "githubStars": 5800,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://lemonade-server.ai/docs/",
      "capabilities": [
        "inference.local",
        "inference.open-weights",
        "embed.text",
        "rerank",
        "speech.stt",
        "speech.tts",
        "image.generate"
      ],
      "tags": [
        "open-source",
        "local",
        "self-hosted",
        "free",
        "no-card",
        "openai-compatible",
        "mcp",
        "streaming",
        "open-weights",
        "amd",
        "npu",
        "docker"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.8,
        "grade": "B",
        "agentReady": false,
        "rank": 372,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 76,
          "payments": 60,
          "reliability": 75,
          "schema": 70,
          "security": 36,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Apache 2.0, with weekly releases, installers for Windows, macOS and five Linux routes, and a six-tool MCP endpoint whose descriptions steer a caller away from accidental multi-gigabyte downloads. Authentication is off by default, the repository has no security policy, and the docs tell WebSocket clients to pass the key in the URL.",
        "bestFor": "An owner with AMD hardware (Ryzen AI NPUs, Radeon or Strix Halo) who wants one local server for chat, speech and images that existing OpenAI, Anthropic or Ollama clients can call, and for MCP clients that want local models as tools.",
        "strengths": [
          "Apache 2.0, with OpenAI, Anthropic Messages, Ollama and llama.cpp-compatible routes on one port (13305)",
          "`POST /mcp` exposes six tools over Streamable HTTP, and omitting `model` reuses a loaded or downloaded model before any download",
          "Every running server returns its own Markdown API reference at `GET /v1/docs` and through the `lemonade_docs` tool, so it matches the installed version",
          "Stable release v2026.41.1 on 7 October 2026 on a weekly cadence, each with a Breaking Changes section in its notes",
          "Telemetry is off by default and exports OTLP traces only to an endpoint the operator sets, with switches to redact prompts and outputs"
        ],
        "weaknesses": [
          "No authentication by default. With no key set, every route answers, including `/internal/*` shutdown and configuration",
          "GitHub reports no `SECURITY.md`, and we found no security.txt, advisory or disclosure address",
          "The docs tell WebSocket clients to send the key as `?api_key=KEY` in the URL",
          "No OpenAPI file in the repository, and no `readOnlyHint` or `destructiveHint` on the MCP tools",
          "The main build and test workflow's badge read failing on main on 8 October 2026, with 411 issues open"
        ],
        "agentNotes": [
          "Call `lemonade_list_models` (or `GET /v1/models`) before naming a model. A wrong name with `allow_download: true` can start a multi-gigabyte download",
          "Send `Authorization: Bearer \u003ckey\u003e` when the operator has set `LEMONADE_API_KEY`. `/internal/*` needs the admin key when one is set",
          "Use `POST /v1/chat/completions` for streamed tokens, embeddings and speech. The MCP endpoint ignores `stream` and has no embeddings or text-to-speech tool",
          "Pass `output_dir` to `lemonade_generate_image` and `lemonade_omni` to get file paths in place of inline base64. Writes stay inside the MCP media sandbox",
          "Read `GET /v1/docs` on the running server for the reference that matches its version. Weekly releases change behaviour"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.8
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 76,
          "payments": 60,
          "reliability": 75,
          "schema": 70,
          "security": 36,
          "transparency": 70
        },
        "provenanceScore": 57
      },
      "connect": {
        "install": "winget install --id AMD.LemonadeServer -e",
        "http": "curl http://localhost:13305/api/v1/chat/completions -H \"Content-Type: application/json\" -d '{\"model\": \"your-model-name\", \"messages\": [{\"role\": \"user\", \"content\": \"Hello\"}]}'",
        "claudeCode": "lemonade launch claude"
      },
      "letme": {
        "capability": "https://letme.dev/inference.local",
        "tool": "https://letme.dev/lemonade"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "Advanced Micro Devices, Inc.",
        "domain": "lemonade-server.ai",
        "domainRegistered": "2025-05-12",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/lemonade-sdk/lemonade/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The website footer reads \"© 2026 AMD. Licensed under Apache 2.0\", and `contrib/debian/copyright` in the repository names Advanced Micro Devices, Inc. The code lives in the lemonade-sdk organisation on GitHub, and the README calls it a community project with optimisations by AMD engineers.",
          "We found no terms of service and no privacy policy for the software or the website. The home page and its footer link to neither, so both fields are empty.",
          "lemonade-server.ai/.well-known/security.txt, /security.txt and /llms.txt return 404.",
          "RDAP gives a registration date of 2025-05-12 for lemonade-server.ai, with Porkbun LLC as registrar and the registrant behind a privacy service.",
          "There's no hosted endpoint. Each instance answers on the owner's own machine, by default localhost port 13305."
        ],
        "score": 57
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/lemonade.json",
      "live": {
        "slug": "lemonade",
        "versions": [
          {
            "registry": "github",
            "name": "lemonade-sdk/lemonade",
            "version": "v2026.41.1",
            "released": "2026-10-07",
            "seenAt": "2026-10-09T17:01:56.36736009Z"
          }
        ],
        "githubStars": 5851,
        "securityTxt": {
          "url": "https://lemonade-server.ai/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:40:17.198212904Z"
        },
        "updatedAt": "2026-10-09T17:01:56.36736009Z"
      }
    },
    "answer": "Lemonade scores 63.8 (B) on agent readiness against vLLM's 57.7 (C), and leads in 3 of 7 scored categories. vLLM leads on security \u0026 auth and maintenance \u0026 community.",
    "b": {
      "slug": "vllm",
      "name": "vLLM",
      "vendor": "vLLM project (PyTorch Foundation)",
      "vendorUrl": "https://vllm.ai",
      "kind": "http-api",
      "category": "local-ai",
      "summary": "vLLM is an open-source inference and serving engine for open-weight language models. `vllm serve` runs an HTTP server with OpenAI-compatible, Anthropic Messages, embedding, reranking and transcription routes on the owner's own GPUs or CPUs.",
      "url": "https://www.anchorterminal.com/tools/vllm",
      "markdownUrl": "https://www.anchorterminal.com/tools/vllm.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/vllm.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/vllm.json",
      "repo": "https://github.com/vllm-project/vllm",
      "license": "Apache-2.0",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "vllm"
        },
        {
          "registry": "oci",
          "name": "vllm/vllm-openai"
        }
      ],
      "auth": "none",
      "authNotes": "No credential by default. `--api-key` (one or several keys) or `VLLM_API_KEY` turns on a Bearer check for paths under `/v1`, `/v2`, `/inference` and `/cohere` only, so `/invocations`, `/pooling`, `/classify`, `/score`, `/rerank` and control routes such as `/pause` stay open. Keys have no scopes and change with a restart. The key is read from the `Authorization` header, never the query string. gRPC has no authentication (https://github.com/vllm-project/vllm/blob/main/docs/usage/security.md).",
      "pricing": "free",
      "pricingNotes": "Free under Apache-2.0, with no account, key or card. Nothing is sold by the project. You pay for your own hardware and electricity.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 93444,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.vllm.ai/en/stable/",
      "capabilities": [
        "inference.local",
        "inference.open-weights",
        "embed.text",
        "rerank",
        "speech.stt",
        "inference.decision",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "local",
        "self-hosted",
        "free",
        "no-card",
        "openai-compatible",
        "docker",
        "pre-1.0",
        "telemetry-default-on"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.7,
        "grade": "C",
        "agentReady": false,
        "rank": 600,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 88,
          "payments": 60,
          "reliability": 62,
          "schema": 68,
          "security": 50,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -6,
        "negativeNotes": [
          "2026-06-02. GHSA-94f4-hr76-p5j6 (CVE-2026-48746, 9.1), a crafted Host header bypassed the API key check on the OpenAI routes, fixed in 0.22.0. With GHSA-4r2x-xpjr-7cvv (CVE-2026-22778, 9.8) of 2 February 2026, code execution through video decoding fixed in 0.14.1, these are the two critical advisories of the last 12 months. Both were fixed and published with CVEs, so they decay, -3. https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6; https://github.com/vllm-project/vllm/security/advisories/GHSA-4r2x-xpjr-7cvv",
          "2026-10-06. GHSA-h3rc-6mm3-gc2m (8.1), a request field could select the processor code a server started with `--trust-remote-code` imports, fixed in 0.31.0, one of 50 advisories published since 11 July 2026 (10 high, 36 medium, 4 low), most of them requests that crash or exhaust the engine. All name a fixed version, and eleven were published on 9 October 2026 months after their fixes, -3. https://github.com/vllm-project/vllm/security/advisories/GHSA-h3rc-6mm3-gc2m; https://github.com/vllm-project/vllm/security/advisories"
        ],
        "verdict": "Apache-2.0 software with a release about every two weeks, each with notes that list breaking changes and security fixes. The optional API key covers only some path prefixes, so `/invocations` and control routes such as `/pause` answer without it, and at least 81 security advisories were published in the 12 months to 9 October 2026.",
        "bestFor": "An owner with a GPU server who wants many concurrent requests against one open-weight model behind OpenAI or Anthropic compatible routes.",
        "strengths": [
          "OpenAI chat, completions, responses and embeddings, Anthropic `/v1/messages`, Cohere embed and rerank, transcription and `/v1/systemone` from one server",
          "Apache-2.0, with a written three-stage deprecation policy and release notes that carry a breaking changes section",
          "Eight stable releases between 12 July and 2 October 2026, and v0.31.0 lists 717 commits from 307 contributors",
          "A 650-line security guide names every route the API key does and does not protect, and the limits of multi-tenant use",
          "Usage statistics are documented field by field, with `VLLM_NO_USAGE_STATS`, `DO_NOT_TRACK` or a file as opt-outs"
        ],
        "weaknesses": [
          "`--api-key` guards only the `/v1`, `/v2`, `/inference` and `/cohere` prefixes. `/invocations`, `/pooling`, `/classify`, `/score`, `/rerank`, `/pause` and `/update_weights` answer without it",
          "No key by default, the server binds every interface when `--host` is unset, and CORS allows any origin",
          "At least 81 GitHub security advisories in 12 months, two critical, most of them remote crashes or resource exhaustion",
          "Pre-1.0 (0.31.0), with breaking changes in each fortnightly release and compatibility kept for a limited number of minor versions",
          "Usage statistics are sent to stats.vllm.ai by default, and no privacy policy or retention period for them was found"
        ],
        "agentNotes": [
          "Put a reverse proxy that allowlists routes in front of the server. `--api-key` leaves `/invocations` and the control routes open",
          "Pass `--host 127.0.0.1` for single-machine use. With no `--host` the server listens on every interface",
          "Set `VLLM_NO_USAGE_STATS=1` or `DO_NOT_TRACK=1` before starting if nothing should be sent to stats.vllm.ai",
          "Start with `--enable-auto-tool-choice` and the `--tool-call-parser` for the model before sending tools. Tool calling is off without them",
          "Send `max_tokens` on every request, and read the breaking changes section of the release notes before upgrading a minor version"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.7
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 88,
          "payments": 60,
          "reliability": 62,
          "schema": 68,
          "security": 50,
          "transparency": 80
        },
        "provenanceScore": 53
      },
      "connect": {
        "install": "uv pip install vllm --torch-backend=auto\nvllm serve Qwen/Qwen2.5-1.5B-Instruct   # listens on port 8000",
        "http": "curl http://localhost:8000/v1/chat/completions \\\n    -H \"Content-Type: application/json\" \\\n    -d '{\n        \"model\": \"Qwen/Qwen2.5-1.5B-Instruct\",\n        \"messages\": [\n            {\"role\": \"system\", \"content\": \"You are a helpful assistant.\"},\n            {\"role\": \"user\", \"content\": \"Who won the world series in 2020?\"}\n        ]\n    }'",
        "claudeCode": "ANTHROPIC_BASE_URL=http://localhost:8000 \\\nANTHROPIC_API_KEY=dummy \\\nANTHROPIC_AUTH_TOKEN=dummy \\\nANTHROPIC_DEFAULT_OPUS_MODEL=my-model \\\nANTHROPIC_DEFAULT_SONNET_MODEL=my-model \\\nANTHROPIC_DEFAULT_HAIKU_MODEL=my-model \\\nclaude"
      },
      "letme": {
        "capability": "https://letme.dev/inference.local",
        "tool": "https://letme.dev/vllm"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "The Linux Foundation (vLLM is a PyTorch Foundation project)",
        "domain": "vllm.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/vllm-project/vllm/releases",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "vllm.ai links no terms and no privacy policy, and its footer reads © 2026 vLLM. The project publishes none for the software or for stats.vllm.ai, so the Apache-2.0 licence stands in for terms.",
          "pytorch.org/projects/vllm/ lists vLLM among PyTorch Foundation projects and says UC Berkeley contributed it to the Linux Foundation in July 2024. The Linux Foundation's policies are linked from that page and are not specific to vLLM.",
          "vllm.ai/.well-known/security.txt and docs.vllm.ai/.well-known/security.txt return 404. SECURITY.md asks for private reports through GitHub.",
          "There's no shared hosted endpoint. The server runs on the owner's hardware. The software posts usage statistics to stats.vllm.ai unless turned off."
        ],
        "score": 53
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/vllm.json",
      "live": {
        "slug": "vllm",
        "versions": [
          {
            "registry": "github",
            "name": "vllm-project/vllm",
            "version": "v0.31.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-09T17:27:30.444059802Z"
          },
          {
            "registry": "pypi",
            "name": "vllm",
            "version": "0.31.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-09T17:27:30.259454009Z"
          }
        ],
        "githubStars": 93457,
        "pypiWeekly": 444466,
        "updatedAt": "2026-10-09T17:27:30.444059802Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "AMD and the Lemonade community",
        "b": "vLLM project (PyTorch Foundation)",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache 2.0. Each backend (llama.cpp, whisper.cpp, stable-diffusion.cpp, FastFlowLM and others) is downloaded separately under its own licence",
        "b": "Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "6",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-07",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "5.8k stars",
        "b": "93k stars",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Lemonade scores 63.8 (B) on agent readiness against vLLM's 57.7 (C), and leads in 3 of 7 scored categories. vLLM leads on security \u0026 auth and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Lemonade or vLLM?"
      },
      {
        "answer": "Lemonade needs an API key. vLLM needs no key.",
        "question": "Do Lemonade and vLLM need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Lemonade. No hosted endpoint is listed for vLLM.",
        "question": "Can an agent call Lemonade and vLLM without installing anything?"
      },
      {
        "answer": "Yes. Lemonade is open source (Apache 2.0. Each backend (llama.cpp, whisper.cpp, stable-diffusion.cpp, FastFlowLM and others) is downloaded separately under its own licence). vLLM is open source (Apache-2.0).",
        "question": "Are Lemonade and vLLM open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 75 against 62",
          "Agent ergonomics, 70 against 64"
        ],
        "also": [
          "No incidents deducted, where vLLM loses 6 points for them"
        ],
        "goodFor": "An owner with AMD hardware (Ryzen AI NPUs, Radeon or Strix Halo) who wants one local server for chat, speech and images that existing OpenAI, Anthropic or Ollama clients can call, and for MCP clients that want local models as tools.",
        "slug": "lemonade",
        "watchFor": "No authentication by default. With no key set, every route answers, including `/internal/*` shutdown and configuration"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 50 against 36",
          "Maintenance \u0026 community, 88 against 76"
        ],
        "also": [
          "No key needed to call it"
        ],
        "goodFor": "An owner with a GPU server who wants many concurrent requests against one open-weight model behind OpenAI or Anthropic compatible routes.",
        "slug": "vllm",
        "watchFor": "`--api-key` guards only the `/v1`, `/v2`, `/inference` and `/cohere` prefixes. `/invocations`, `/pooling`, `/classify`, `/score`, `/rerank`, `/pause` and `/update_weights` answer without it"
      }
    ],
    "job": {
      "capability": "inference.local",
      "name": "Local inference"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/anythingllm-vs-lemonade.json",
        "title": "AnythingLLM vs Lemonade",
        "url": "https://www.anchorterminal.com/compare/anythingllm-vs-lemonade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/anythingllm-vs-vllm.json",
        "title": "AnythingLLM vs vLLM",
        "url": "https://www.anchorterminal.com/compare/anythingllm-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/docker-model-runner-vs-lemonade.json",
        "title": "Docker Model Runner vs Lemonade",
        "url": "https://www.anchorterminal.com/compare/docker-model-runner-vs-lemonade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/docker-model-runner-vs-vllm.json",
        "title": "Docker Model Runner vs vLLM",
        "url": "https://www.anchorterminal.com/compare/docker-model-runner-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/foundry-local-vs-lemonade.json",
        "title": "Foundry Local vs Lemonade",
        "url": "https://www.anchorterminal.com/compare/foundry-local-vs-lemonade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/foundry-local-vs-vllm.json",
        "title": "Foundry Local vs vLLM",
        "url": "https://www.anchorterminal.com/compare/foundry-local-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-core-vs-lemonade.json",
        "title": "Core vs Lemonade",
        "url": "https://www.anchorterminal.com/compare/ghost-core-vs-lemonade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ghost-core-vs-vllm.json",
        "title": "Core vs vLLM",
        "url": "https://www.anchorterminal.com/compare/ghost-core-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gpt4all-vs-lemonade.json",
        "title": "GPT4All vs Lemonade",
        "url": "https://www.anchorterminal.com/compare/gpt4all-vs-lemonade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gpt4all-vs-vllm.json",
        "title": "GPT4All vs vLLM",
        "url": "https://www.anchorterminal.com/compare/gpt4all-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jan-vs-lemonade.json",
        "title": "Jan vs Lemonade",
        "url": "https://www.anchorterminal.com/compare/jan-vs-lemonade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/jan-vs-vllm.json",
        "title": "Jan vs vLLM",
        "url": "https://www.anchorterminal.com/compare/jan-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/khoj-vs-lemonade.json",
        "title": "Khoj vs Lemonade",
        "url": "https://www.anchorterminal.com/compare/khoj-vs-lemonade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/khoj-vs-vllm.json",
        "title": "Khoj vs vLLM",
        "url": "https://www.anchorterminal.com/compare/khoj-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/koboldcpp-vs-lemonade.json",
        "title": "KoboldCpp vs Lemonade",
        "url": "https://www.anchorterminal.com/compare/koboldcpp-vs-lemonade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/koboldcpp-vs-vllm.json",
        "title": "KoboldCpp vs vLLM",
        "url": "https://www.anchorterminal.com/compare/koboldcpp-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lemonade-vs-llama-cpp.json",
        "title": "Lemonade vs llama.cpp",
        "url": "https://www.anchorterminal.com/compare/lemonade-vs-llama-cpp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lemonade-vs-lm-studio.json",
        "title": "Lemonade vs LM Studio",
        "url": "https://www.anchorterminal.com/compare/lemonade-vs-lm-studio"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lemonade-vs-localai.json",
        "title": "Lemonade vs LocalAI",
        "url": "https://www.anchorterminal.com/compare/lemonade-vs-localai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lemonade-vs-mlx-lm.json",
        "title": "Lemonade vs MLX LM",
        "url": "https://www.anchorterminal.com/compare/lemonade-vs-mlx-lm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lemonade-vs-ollama.json",
        "title": "Lemonade vs Ollama",
        "url": "https://www.anchorterminal.com/compare/lemonade-vs-ollama"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lemonade-vs-open-webui.json",
        "title": "Lemonade vs Open WebUI",
        "url": "https://www.anchorterminal.com/compare/lemonade-vs-open-webui"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lemonade-vs-screenpipe.json",
        "title": "Lemonade vs screenpipe",
        "url": "https://www.anchorterminal.com/compare/lemonade-vs-screenpipe"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lemonade-vs-text-generation-webui.json",
        "title": "Lemonade vs TextGen",
        "url": "https://www.anchorterminal.com/compare/lemonade-vs-text-generation-webui"
      },
      {
        "json": "https://www.anchorterminal.com/compare/llama-cpp-vs-vllm.json",
        "title": "llama.cpp vs vLLM",
        "url": "https://www.anchorterminal.com/compare/llama-cpp-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lm-studio-vs-vllm.json",
        "title": "LM Studio vs vLLM",
        "url": "https://www.anchorterminal.com/compare/lm-studio-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/localai-vs-vllm.json",
        "title": "LocalAI vs vLLM",
        "url": "https://www.anchorterminal.com/compare/localai-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mlx-lm-vs-vllm.json",
        "title": "MLX LM vs vLLM",
        "url": "https://www.anchorterminal.com/compare/mlx-lm-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ollama-vs-vllm.json",
        "title": "Ollama vs vLLM",
        "url": "https://www.anchorterminal.com/compare/ollama-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/open-webui-vs-vllm.json",
        "title": "Open WebUI vs vLLM",
        "url": "https://www.anchorterminal.com/compare/open-webui-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/screenpipe-vs-vllm.json",
        "title": "screenpipe vs vLLM",
        "url": "https://www.anchorterminal.com/compare/screenpipe-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/text-generation-webui-vs-vllm.json",
        "title": "TextGen vs vLLM",
        "url": "https://www.anchorterminal.com/compare/text-generation-webui-vs-vllm"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lemonade-vs-underdog.json",
        "title": "Lemonade vs Underdog",
        "url": "https://www.anchorterminal.com/compare/lemonade-vs-underdog"
      },
      {
        "json": "https://www.anchorterminal.com/compare/underdog-vs-vllm.json",
        "title": "Underdog vs vLLM",
        "url": "https://www.anchorterminal.com/compare/underdog-vs-vllm"
      }
    ],
    "scores": [
      {
        "by": 13,
        "edge": "lemonade",
        "key": "reliability",
        "lemonade": 75,
        "name": "Reliability",
        "vllm": 62,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "lemonade",
        "key": "schema",
        "lemonade": 70,
        "name": "Schema \u0026 documentation",
        "vllm": 68,
        "weight": 13
      },
      {
        "by": 6,
        "edge": "lemonade",
        "key": "ergonomics",
        "lemonade": 70,
        "name": "Agent ergonomics",
        "vllm": 64,
        "weight": 13
      },
      {
        "by": 14,
        "edge": "vllm",
        "key": "security",
        "lemonade": 36,
        "name": "Security \u0026 auth",
        "vllm": 50,
        "weight": 14
      },
      {
        "by": 0,
        "edge": "",
        "key": "payments",
        "lemonade": 60,
        "name": "Payments \u0026 pricing",
        "vllm": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 12,
        "edge": "vllm",
        "key": "maintenance",
        "lemonade": 76,
        "name": "Maintenance \u0026 community",
        "vllm": 88,
        "weight": 7
      },
      {
        "by": 3,
        "edge": "vllm",
        "key": "transparency",
        "lemonade": 64,
        "name": "Transparency \u0026 trust",
        "vllm": 67,
        "weight": 7
      }
    ],
    "summary": "Lemonade scores 63.8 (B) on agent readiness against vLLM's 57.7 (C), and leads in 3 of 7 scored categories. vLLM leads on security \u0026 auth and maintenance \u0026 community. Both do local inference.",
    "verdicts": {
      "lemonade": "Apache 2.0, with weekly releases, installers for Windows, macOS and five Linux routes, and a six-tool MCP endpoint whose descriptions steer a caller away from accidental multi-gigabyte downloads. Authentication is off by default, the repository has no security policy, and the docs tell WebSocket clients to pass the key in the URL.",
      "vllm": "Apache-2.0 software with a release about every two weeks, each with notes that list breaking changes and security fixes. The optional API key covers only some path prefixes, so `/invocations` and control routes such as `/pause` answer without it, and at least 81 security advisories were published in the 12 months to 9 October 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/lemonade-vs-vllm",
    "json": "https://www.anchorterminal.com/compare/lemonade-vs-vllm.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/lemonade-vs-vllm.md",
    "slim": "https://www.anchorterminal.com/compare/lemonade-vs-vllm.min.md"
  },
  "markdown": "Lemonade scores 63.8 (B) on agent readiness against vLLM's 57.7 (C), and leads in 3 of 7 scored categories. vLLM leads on security \u0026 auth and maintenance \u0026 community. Both do local inference.\n\n- Lemonade: grade B, 63.8/100, rank #372 of 950. Markdown https://www.anchorterminal.com/tools/lemonade.md · JSON https://www.anchorterminal.com/api/v1/tools/lemonade.json\n- vLLM: grade C, 57.7/100, rank #600 of 950. Markdown https://www.anchorterminal.com/tools/vllm.md · JSON https://www.anchorterminal.com/api/v1/tools/vllm.json\n- Best local AI models and assistants: https://www.anchorterminal.com/best/local-ai/index.md\n- All 184 local ai comparisons: https://www.anchorterminal.com/compare/local-ai/index.md\n\n## Which one, for what\n\n### Lemonade (B)\n\nGood for: An owner with AMD hardware (Ryzen AI NPUs, Radeon or Strix Halo) who wants one local server for chat, speech and images that existing OpenAI, Anthropic or Ollama clients can call, and for MCP clients that want local models as tools.\n\nAhead on:\n- Reliability, 75 against 62\n- Agent ergonomics, 70 against 64\n\nAlso in its favour:\n- No incidents deducted, where vLLM loses 6 points for them\n\nWatch for: No authentication by default. With no key set, every route answers, including `/internal/*` shutdown and configuration\n\n### vLLM (C)\n\nGood for: An owner with a GPU server who wants many concurrent requests against one open-weight model behind OpenAI or Anthropic compatible routes.\n\nAhead on:\n- Security \u0026 auth, 50 against 36\n- Maintenance \u0026 community, 88 against 76\n\nAlso in its favour:\n- No key needed to call it\n\nWatch for: `--api-key` guards only the `/v1`, `/v2`, `/inference` and `/cohere` prefixes. `/invocations`, `/pooling`, `/classify`, `/score`, `/rerank`, `/pause` and `/update_weights` answer without it\n\n\n## Score by category\n\n| Category | Weight | Lemonade | vLLM | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 75 | 62 | Lemonade +13 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 70 | 68 | Lemonade +2 |\n| Agent ergonomics | 13% (16.2 this run) | 70 | 64 | Lemonade +6 |\n| Security \u0026 auth | 14% (17.5 this run) | 36 | 50 | vLLM +14 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 60 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 76 | 88 | vLLM +12 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 64 | 67 | vLLM +3 |\n| Negative events | ≤15 | 0 | -6 | |\n| **Total** | | **63.8 · B** | **57.7 · C** | |\n\n## Facts side by side\n\n| Fact | Lemonade | vLLM |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | AMD and the Lemonade community | vLLM project (PyTorch Foundation) |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP | HTTP |\n| Auth | API key | None |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | Apache 2.0. Each backend (llama.cpp, whisper.cpp, stable-diffusion.cpp, FastFlowLM and others) is downloaded separately under its own licence | Apache-2.0 |\n| Tools exposed | 6 | none |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| Last release | 2026-10-07 | 2026-10-02 |\n| Terms last updated | no document linked | no document linked |\n| Privacy policy last updated | no document linked | no document linked |\n| Customer content may train models |  |  |\n| Terms restrict automated access |  |  |\n| Terms restrict benchmarking |  |  |\n| Terms or service can change without notice |  |  |\n| Arbitration or class-action waiver |  |  |\n| Popularity | 5.8k stars | 93k stars |\n\n## Verdicts\n\n**Lemonade.** Apache 2.0, with weekly releases, installers for Windows, macOS and five Linux routes, and a six-tool MCP endpoint whose descriptions steer a caller away from accidental multi-gigabyte downloads. Authentication is off by default, the repository has no security policy, and the docs tell WebSocket clients to pass the key in the URL.\n\n**vLLM.** Apache-2.0 software with a release about every two weeks, each with notes that list breaking changes and security fixes. The optional API key covers only some path prefixes, so `/invocations` and control routes such as `/pause` answer without it, and at least 81 security advisories were published in the 12 months to 9 October 2026.\n\n## Before you call either\n\n### Lemonade\n\n1. Call `lemonade_list_models` (or `GET /v1/models`) before naming a model. A wrong name with `allow_download: true` can start a multi-gigabyte download\n2. Send `Authorization: Bearer \u003ckey\u003e` when the operator has set `LEMONADE_API_KEY`. `/internal/*` needs the admin key when one is set\n3. Use `POST /v1/chat/completions` for streamed tokens, embeddings and speech. The MCP endpoint ignores `stream` and has no embeddings or text-to-speech tool\n4. Pass `output_dir` to `lemonade_generate_image` and `lemonade_omni` to get file paths in place of inline base64. Writes stay inside the MCP media sandbox\n5. Read `GET /v1/docs` on the running server for the reference that matches its version. Weekly releases change behaviour\n\n### vLLM\n\n1. Put a reverse proxy that allowlists routes in front of the server. `--api-key` leaves `/invocations` and the control routes open\n2. Pass `--host 127.0.0.1` for single-machine use. With no `--host` the server listens on every interface\n3. Set `VLLM_NO_USAGE_STATS=1` or `DO_NOT_TRACK=1` before starting if nothing should be sent to stats.vllm.ai\n4. Start with `--enable-auto-tool-choice` and the `--tool-call-parser` for the model before sending tools. Tool calling is off without them\n5. Send `max_tokens` on every request, and read the breaking changes section of the release notes before upgrading a minor version\n\n## Questions\n\n### Which is better for AI agents, Lemonade or vLLM?\n\nLemonade scores 63.8 (B) on agent readiness against vLLM's 57.7 (C), and leads in 3 of 7 scored categories. vLLM leads on security \u0026 auth and maintenance \u0026 community.\n\n### Do Lemonade and vLLM need an API key?\n\nLemonade needs an API key. vLLM needs no key.\n\n### Can an agent call Lemonade and vLLM without installing anything?\n\nNo hosted endpoint is listed for Lemonade. No hosted endpoint is listed for vLLM.\n\n### Are Lemonade and vLLM open source?\n\nYes. Lemonade is open source (Apache 2.0. Each backend (llama.cpp, whisper.cpp, stable-diffusion.cpp, FastFlowLM and others) is downloaded separately under its own licence). vLLM is open source (Apache-2.0).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/lemonade-vs-vllm.json, and with the fewest tokens: https://www.anchorterminal.com/compare/lemonade-vs-vllm.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"lemonade\", \"b\": \"vllm\"}`. From a terminal: `anchor compare lemonade vllm`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/lemonade.json and https://www.anchorterminal.com/api/v1/tools/vllm.json\n\n## Other comparisons with Lemonade or vLLM\n\n- [AnythingLLM vs Lemonade](https://www.anchorterminal.com/compare/anythingllm-vs-lemonade.md)\n- [AnythingLLM vs vLLM](https://www.anchorterminal.com/compare/anythingllm-vs-vllm.md)\n- [Docker Model Runner vs Lemonade](https://www.anchorterminal.com/compare/docker-model-runner-vs-lemonade.md)\n- [Docker Model Runner vs vLLM](https://www.anchorterminal.com/compare/docker-model-runner-vs-vllm.md)\n- [Foundry Local vs Lemonade](https://www.anchorterminal.com/compare/foundry-local-vs-lemonade.md)\n- [Foundry Local vs vLLM](https://www.anchorterminal.com/compare/foundry-local-vs-vllm.md)\n- [Core vs Lemonade](https://www.anchorterminal.com/compare/ghost-core-vs-lemonade.md)\n- [Core vs vLLM](https://www.anchorterminal.com/compare/ghost-core-vs-vllm.md)\n- [GPT4All vs Lemonade](https://www.anchorterminal.com/compare/gpt4all-vs-lemonade.md)\n- [GPT4All vs vLLM](https://www.anchorterminal.com/compare/gpt4all-vs-vllm.md)\n- [Jan vs Lemonade](https://www.anchorterminal.com/compare/jan-vs-lemonade.md)\n- [Jan vs vLLM](https://www.anchorterminal.com/compare/jan-vs-vllm.md)\n- [Khoj vs Lemonade](https://www.anchorterminal.com/compare/khoj-vs-lemonade.md)\n- [Khoj vs vLLM](https://www.anchorterminal.com/compare/khoj-vs-vllm.md)\n- [KoboldCpp vs Lemonade](https://www.anchorterminal.com/compare/koboldcpp-vs-lemonade.md)\n- [KoboldCpp vs vLLM](https://www.anchorterminal.com/compare/koboldcpp-vs-vllm.md)\n- [Lemonade vs llama.cpp](https://www.anchorterminal.com/compare/lemonade-vs-llama-cpp.md)\n- [Lemonade vs LM Studio](https://www.anchorterminal.com/compare/lemonade-vs-lm-studio.md)\n- [Lemonade vs LocalAI](https://www.anchorterminal.com/compare/lemonade-vs-localai.md)\n- [Lemonade vs MLX LM](https://www.anchorterminal.com/compare/lemonade-vs-mlx-lm.md)\n- [Lemonade vs Ollama](https://www.anchorterminal.com/compare/lemonade-vs-ollama.md)\n- [Lemonade vs Open WebUI](https://www.anchorterminal.com/compare/lemonade-vs-open-webui.md)\n- [Lemonade vs screenpipe](https://www.anchorterminal.com/compare/lemonade-vs-screenpipe.md)\n- [Lemonade vs TextGen](https://www.anchorterminal.com/compare/lemonade-vs-text-generation-webui.md)\n- [llama.cpp vs vLLM](https://www.anchorterminal.com/compare/llama-cpp-vs-vllm.md)\n- [LM Studio vs vLLM](https://www.anchorterminal.com/compare/lm-studio-vs-vllm.md)\n- [LocalAI vs vLLM](https://www.anchorterminal.com/compare/localai-vs-vllm.md)\n- [MLX LM vs vLLM](https://www.anchorterminal.com/compare/mlx-lm-vs-vllm.md)\n- [Ollama vs vLLM](https://www.anchorterminal.com/compare/ollama-vs-vllm.md)\n- [Open WebUI vs vLLM](https://www.anchorterminal.com/compare/open-webui-vs-vllm.md)\n- [screenpipe vs vLLM](https://www.anchorterminal.com/compare/screenpipe-vs-vllm.md)\n- [TextGen vs vLLM](https://www.anchorterminal.com/compare/text-generation-webui-vs-vllm.md)\n- [Lemonade vs Underdog](https://www.anchorterminal.com/compare/lemonade-vs-underdog.md)\n- [Underdog vs vLLM](https://www.anchorterminal.com/compare/underdog-vs-vllm.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Lemonade vs vLLM",
        "url": ""
      }
    ],
    "description": "Lemonade scores 63.8 (B) to vLLM's 57.7 (C) for local inference. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Lemonade B 63.8",
      "vLLM C 57.7",
      "scores"
    ],
    "h1": "Lemonade vs vLLM",
    "image": "https://www.anchorterminal.com/assets/og/compare-lemonade-vs-vllm.png",
    "path": "/compare/lemonade-vs-vllm",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Lemonade vs vLLM for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/lemonade-vs-vllm"
  },
  "tokens": {
    "markdown": 2650,
    "slim": 580
  },
  "version": 1
}
