{
  "data": {
    "a": {
      "slug": "ollama",
      "name": "Ollama",
      "vendor": "Ollama Inc.",
      "vendorUrl": "https://ollama.com",
      "kind": "http-api",
      "category": "local-ai",
      "summary": "Open-source model runner for macOS, Windows and Linux, with a local API and a library of downloadable models.",
      "url": "https://www.anchorterminal.com/tools/ollama",
      "markdownUrl": "https://www.anchorterminal.com/tools/ollama.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ollama.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ollama.json",
      "repo": "https://github.com/ollama/ollama",
      "license": "MIT (server, CLI and desktop app). Ollama Cloud is a closed service under the ollama.com terms, and each model carries its own licence",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "docker.io/ollama/ollama"
        },
        {
          "registry": "pypi",
          "name": "ollama"
        },
        {
          "registry": "npm",
          "name": "ollama"
        }
      ],
      "auth": "none",
      "authNotes": "The local API at http://localhost:11434 takes no credential. It binds 127.0.0.1, answers a foreign Host header with 403 while bound to loopback, and allows cross-origin calls from 127.0.0.1 and 0.0.0.0 unless `OLLAMA_ORIGINS` adds more. Anything that reaches the port can generate, pull, push, create, copy and delete models. Cloud models through the local server need `ollama signin`, which signs requests with the install's own key. Direct calls to https://ollama.com/api and /v1 need a Bearer API key from ollama.com/settings/keys, which doesn't expire and has no scopes, and is revoked from the same page (https://github.com/ollama/ollama/blob/main/docs/api/authentication.mdx).",
      "pricing": "freemium",
      "pricingNotes": "The server, CLI and desktop app are free under MIT with no account. Ollama Cloud has five plans on ollama.com/pricing. Free ($0, starter usage credits, starter models, 1 concurrent request), Pro ($20 a month or $200 a year, $60 of usage credits a month, 3 concurrent requests), Max ($100 a month, $300 of credits, 10 concurrent requests), Team ($500 a month, $1,000 of shared credits, unlimited users) and Enterprise (custom). Usage is priced per model by the token, and the page doesn't say whether the Free plan needs a card (checked 2026-10-03).",
      "priceSummary": "$20 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the source (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 181200,
        "npmWeekly": 871543,
        "pypiWeekly": null,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://docs.ollama.com",
      "llmsTxt": "https://docs.ollama.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/ollama/ollama/main/docs/openapi.yaml",
      "capabilities": [
        "inference.local",
        "inference.open-weights",
        "inference.llm",
        "embed.text",
        "inference.decision",
        "web.search",
        "web.fetch"
      ],
      "tags": [
        "open-source",
        "local",
        "self-hosted",
        "hosted",
        "freemium",
        "no-card",
        "openai-compatible",
        "openapi",
        "llms-txt",
        "docker",
        "go",
        "python",
        "typescript",
        "pre-1.0",
        "no-auth"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.6,
        "grade": "C",
        "agentReady": false,
        "rank": 302,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 5,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 75,
          "maintenance": 81,
          "payments": 60,
          "reliability": 53,
          "schema": 79,
          "security": 28,
          "transparency": 63
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-04-29. CERT Polska published CVE-2026-42248 and CVE-2026-42249 (9.8 each). The Windows app accepted downloaded updates without a signature check and took the file name from the server's response, and it installs updates silently, so whoever could answer the update request could run code on the machine. CERT Polska tested 0.12.10 to 0.17.5, and the Windows check stayed a stub returning success until v0.23.3 on 12 May 2026, whose notes list the fix only as `app: harden update flows`. CERT Polska says the maintainers didn't respond with details or the vulnerable range, and Ollama published no advisory. Fixed, but not disclosed by the vendor, -4. https://cert.pl/en/posts/2026/04/CVE-2026-42248/; https://github.com/ollama/ollama/releases/tag/v0.23.3"
        ],
        "verdict": "An OpenAPI 3.1 file for the 15 native operations and llms.txt with 68 links to Markdown pages. No credential on the local API, and any caller that reaches it can pull, push, create and delete models.",
        "strengths": [
          "An OpenAPI 3.1 file for the 15 native operations and llms.txt with 68 links to Markdown pages",
          "Native, OpenAI-compatible and Anthropic-compatible routes on one local port, with `ollama launch` for Claude Code, Codex and OpenCode",
          "28 releases in the 90 days to 3 October 2026, and official Python and JavaScript libraries released on 28 September",
          "Local prompts stay on the machine, and `OLLAMA_NO_CLOUD=1` turns off cloud models and web search",
          "Binds 127.0.0.1 by default and refuses foreign Host headers while bound to loopback"
        ],
        "weaknesses": [
          "No credential on the local API, and any caller that reaches it can pull, push, create and delete models",
          "No GitHub security advisory, against 12 CVEs on NVD since October 2025",
          "The Windows updater installed unsigned files until v0.23.3 on 12 May 2026, fixed under a release note that didn't mention security",
          "The desktop app checks ollama.com every hour with a signed request, even with automatic updates off, and no documented way to stop it",
          "A default context of 4k tokens below 24 GiB of VRAM, where the docs say agents need 64,000"
        ],
        "agentNotes": [
          "Send `\"stream\": false` for one JSON body. The native routes stream NDJSON by default",
          "Set `OLLAMA_CONTEXT_LENGTH=64000` or `options.num_ctx` before agent work. The default is 4k below 24 GiB of VRAM",
          "Back off on a 503. It means the queue (512 by default) is full",
          "Put an authenticating proxy in front before binding past 127.0.0.1. The server checks no credential",
          "Expect model names with a `cloud` tag to run on Ollama's servers. They need `ollama signin` and fail with `OLLAMA_NO_CLOUD=1`"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.6
          }
        ],
        "editorialScores": {
          "ergonomics": 75,
          "maintenance": 81,
          "payments": 60,
          "reliability": 53,
          "schema": 79,
          "security": 28,
          "transparency": 66
        },
        "provenanceScore": 59
      },
      "connect": {
        "install": "curl -fsSL https://ollama.com/install.sh | sh   # macOS and Linux; Windows: irm https://ollama.com/install.ps1 | iex\nollama pull gemma4:e2b",
        "http": "curl http://localhost:11434/api/chat \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"model\": \"gemma4:e2b\",\n    \"messages\": [{\"role\": \"user\", \"content\": \"Say hello in one sentence.\"}],\n    \"stream\": false\n  }'",
        "claudeCode": "ollama launch claude   # or: ANTHROPIC_AUTH_TOKEN=ollama ANTHROPIC_API_KEY=\"\" ANTHROPIC_BASE_URL=http://localhost:11434 claude --model qwen3.5"
      },
      "letme": {
        "capability": "https://letme.dev/inference.local",
        "tool": "https://letme.dev/ollama"
      },
      "area": "models",
      "unitPrices": [
        {
          "item": "Ollama Cloud Pro",
          "unit": "month",
          "usd": 20,
          "note": "$60 of usage credits a month, 3 concurrent requests. $200 a year"
        },
        {
          "item": "Ollama Cloud Max",
          "unit": "month",
          "usd": 100,
          "note": "$300 of usage credits a month, 10 concurrent requests"
        },
        {
          "item": "Ollama Cloud Team",
          "unit": "month",
          "usd": 500,
          "note": "$1,000 of shared usage credits a month, unlimited users, 10 concurrent requests"
        }
      ],
      "provenance": {
        "legalEntity": "Ollama Inc.",
        "domain": "ollama.com",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "https://ollama.com/terms",
        "privacy": "https://ollama.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/ollama/ollama/releases",
        "securityTxt": "none",
        "checked": "2026-10-03",
        "notes": [
          "The terms (last updated May 2026) name Ollama Inc., under California law with arbitration in San Francisco. The privacy policy was last updated in March 2026.",
          "ollama.com/.well-known/security.txt returns 404. SECURITY.md sends reports to hello@ollama.com.",
          "status.ollama.com doesn't resolve, and we found no other status page for Ollama Cloud.",
          "The API an agent calls runs on the owner's machine, so there's no shared endpoint to check. Ollama Cloud answers at https://ollama.com/api and /v1."
        ],
        "score": 59
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/ollama.json",
      "live": {
        "slug": "ollama",
        "versions": [
          {
            "registry": "github",
            "name": "ollama/ollama",
            "version": "v0.35.1",
            "released": "2026-09-29",
            "seenAt": "2026-10-04T16:34:54.976052119Z"
          },
          {
            "registry": "npm",
            "name": "ollama",
            "version": "0.6.4",
            "seenAt": "2026-10-04T16:34:54.718897973Z"
          },
          {
            "registry": "pypi",
            "name": "ollama",
            "version": "0.6.3",
            "released": "2026-09-29",
            "seenAt": "2026-10-04T16:34:54.611886134Z"
          }
        ],
        "githubStars": 182181,
        "npmWeekly": 899010,
        "pypiWeekly": 3792881,
        "securityTxt": {
          "url": "https://ollama.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:42.667557395Z"
        },
        "llmsTxt": {
          "url": "https://docs.ollama.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:03.78930424Z"
        },
        "domain": {
          "domain": "ollama.com",
          "registered": "2017-05-08",
          "source": "https://rdap.verisign.com/com/v1/domain/ollama.com",
          "checkedAt": "2026-10-04T13:05:52.948193398Z"
        },
        "pages": [
          {
            "url": "https://ollama.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:17.783383878Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "058925ed2fe9"
          },
          {
            "url": "https://ollama.com/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:19.909311869Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ef2c1d1a23eb"
          }
        ],
        "updatedAt": "2026-10-04T16:34:54.976052119Z"
      }
    },
    "b": {
      "slug": "open-webui",
      "name": "Open WebUI",
      "vendor": "Open WebUI Inc.",
      "vendorUrl": "https://openwebui.com",
      "kind": "platform",
      "category": "local-ai",
      "summary": "Self-hosted web interface for chatting with models, from Open WebUI Inc., with a Python (FastAPI) back end and a Svelte front end.",
      "url": "https://www.anchorterminal.com/tools/open-webui",
      "markdownUrl": "https://www.anchorterminal.com/tools/open-webui.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/open-webui.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/open-webui.json",
      "repo": "https://github.com/open-webui/open-webui",
      "license": "Open WebUI License. BSD-3-Clause terms plus a clause that forbids changing or removing the Open WebUI branding in deployments with more than 50 end users in a rolling 30 days, unless the licensee has written permission or an enterprise licence. Code from before set commits stays under MIT or BSD-3-Clause (LICENSE_HISTORY), and contributors sign a CLA",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "open-webui"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/open-webui/open-webui"
        }
      ],
      "auth": "api-key",
      "authNotes": "Sign-in is on by default (`WEBUI_AUTH`), the first account to sign up becomes admin, and sign-up then closes. An agent calls the API with `Authorization: Bearer \u003ctoken\u003e`, either an `sk-` API key from Settings \u003e Account or a session JWT, which lasts four weeks by default (`JWT_EXPIRES_IN`), and behind a reverse proxy that uses `Authorization` itself the key can go in an `x-api-key` header (https://docs.openwebui.com/reference/api-endpoints). API keys stay off until an administrator turns them on (`ENABLE_API_KEYS` defaults to false), a group permission decides who may create one, and they can be limited instance-wide to listed endpoints with `ENABLE_API_KEYS_ENDPOINT_RESTRICTIONS` and `API_KEYS_ALLOWED_ENDPOINTS` (https://github.com/open-webui/open-webui/blob/main/backend/open_webui/config.py). Each user has one key, `sk-` plus 32 hexadecimal characters, stored as plain text with a last-used time and no expiry set by the API (https://github.com/open-webui/open-webui/blob/main/backend/open_webui/routers/auths.py). People sign in with email and password, OAuth or OIDC, LDAP or trusted headers, with SCIM 2.0 provisioning.",
      "pricing": "free",
      "pricingNotes": "Free to self-host under the Open WebUI License. Deployments with more than 50 end users in a rolling 30 days have to keep the Open WebUI branding unless they hold an enterprise licence or written permission. The enterprise licence (white-labelling, SLA-backed support, Terminals) is sold through sales to registered organisations only, with no published prices (https://docs.openwebui.com/enterprise). There's no hosted Open WebUI service. You pay your model provider, or nothing with a local model (checked 2026-10-03).",
      "priceSummary": "Free",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-03).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 153000,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-03"
      },
      "docsUrl": "https://docs.openwebui.com",
      "llmsTxt": "https://docs.openwebui.com/llms.txt",
      "capabilities": [
        "inference.local",
        "agent.mcp-client",
        "memory.user",
        "knowledge.search"
      ],
      "tags": [
        "self-hosted",
        "local",
        "free",
        "python",
        "docker",
        "openai-compatible",
        "llms-txt",
        "enterprise"
      ],
      "lastRelease": "2026-09-21",
      "graded": true,
      "disclosure": "Open WebUI competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
      "competesWith": "localghost",
      "anchor": {
        "graded": true,
        "score": 52,
        "grade": "D",
        "agentReady": false,
        "rank": 345,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 7,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 54,
          "maintenance": 91,
          "payments": 20,
          "reliability": 68,
          "schema": 60,
          "security": 63,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-03"
        },
        "negative": -8,
        "negativeNotes": [
          "2026-05-05. GHSA-2r4p-jpmg-48f4 (CVE-2026-44551, Critical, 9.1). LDAP sign-in accepted an empty password where the directory allows unauthenticated binds, giving full access to the victim's account. It affects 0.8.12 and earlier and was fixed in 0.9.0 (21 April 2026) before publication, -2. https://github.com/open-webui/open-webui/security/advisories/GHSA-2r4p-jpmg-48f4",
          "2026-07-02. GHSA-74h3-cxq7-vc5q (CVE-2026-59216, 7.7). A signed-in low-privilege user could run code and tools in another user's session through an unchecked Socket.IO session_id, which against an administrator meant code execution as the server process (root in default containers). Fixed in 0.10.0 on 29 June 2026 and published three days later, -2. https://github.com/open-webui/open-webui/security/advisories/GHSA-74h3-cxq7-vc5q",
          "2026-08-02 and 2026-09-04. Two account takeovers through OAuth, both High. GHSA-rq84-p6rr-vf89 accepted tokens issued to any client in the OAuth token exchange (fixed in 0.11.0), and GHSA-wpmr-8h3q-fwj7 (8.1) matched OAuth and OIDC subjects by substring on SQLite, so a crafted subject could sign in as an existing account, administrators included (fixed in 0.11.1 on 25 August). Both fixed before publication, -2. https://github.com/open-webui/open-webui/security/advisories/GHSA-rq84-p6rr-vf89; https://github.com/open-webui/open-webui/security/advisories/GHSA-wpmr-8h3q-fwj7",
          "2025-10-03 to 2026-10-03. The rest of the year's record. GitHub reviewed 143 of the repository's advisories in the 12 months to 3 October 2026, and 129 cover flaws fixed in releases from 0.6.35 (6 November 2025) on, 58 High and 1 Critical, more than half of them access-control or authorisation flaws by their titles and CWE tags. July to September alone brought 52 (18 High, 29 Moderate, 5 Low) in batches published on 2 July, 2 August and 4 September. Each was fixed in a release before publication, so the 125 beyond the four above count together, -2. https://github.com/open-webui/open-webui/security/advisories; https://github.com/advisories?query=open-webui+type%3Areviewed+ecosystem%3Apip"
        ],
        "verdict": "Five releases in the 90 days to 3 October 2026, each with a dated changelog entry that warns of database migrations. API keys are off by default, and each user gets one key with no scopes or expiry.",
        "disclosure": "Open WebUI competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.",
        "strengths": [
          "Five releases in the 90 days to 3 October 2026, each with a dated changelog entry that warns of database migrations",
          "OpenAI-compatible `/api/chat/completions` and `/api/models`, plus an Anthropic Messages route and an Ollama proxy, so OpenAI's SDKs work against a local instance",
          "Roles, groups, per-model and per-knowledge access grants, a group permission for key creation and an instance-wide endpoint allowlist for keys",
          "An audit log at metadata, request or request-and-response level, plus events for key creation and deletion",
          "No product telemetry found, third-party analytics off in the Docker image, and `OFFLINE_MODE` to stop the release check and model downloads"
        ],
        "weaknesses": [
          "API keys are off by default, and each user gets one key with no scopes or expiry",
          "The API reference covers seven route groups, and the OpenAPI file and Swagger UI need `ENV=dev`",
          "52 advisories published from July to September 2026, 18 of them High, including cross-user code execution (CVE-2026-59216) and two OAuth account takeovers, all fixed",
          "Pre-1.0 (0.11), with database migrations in patch releases and no rolling updates during them",
          "The branding clause makes the licence non-OSI, and the enterprise licence has no published price"
        ],
        "agentNotes": [
          "Ask the administrator to set `ENABLE_API_KEYS=true` and let your group create keys. `sk-` keys are refused until then",
          "Send OpenAI's request shape to `/api/chat/completions` with a Bearer key, or use `x-api-key` behind a proxy that takes `Authorization` for itself",
          "Call `/api/models` first and use an `id` from it. Model IDs depend on the instance's connections",
          "Poll `GET /api/v1/files/{id}/process/status` until it reads `completed` before adding a file to a knowledge base",
          "Expect a 403 on routes outside `API_KEYS_ALLOWED_ENDPOINTS` when the administrator has set an allowlist"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 52
          }
        ],
        "editorialScores": {
          "ergonomics": 54,
          "maintenance": 91,
          "payments": 20,
          "reliability": 68,
          "schema": 60,
          "security": 63,
          "transparency": 66
        },
        "provenanceScore": 79
      },
      "connect": {
        "install": "pip install open-webui \u0026\u0026 open-webui serve   # or: docker run -d -p 3000:8080 --add-host=host.docker.internal:host-gateway -v open-webui:/app/backend/data --name open-webui --restart always ghcr.io/open-webui/open-webui:main",
        "http": "curl -X POST http://localhost:3000/api/chat/completions \\\n  -H \"Authorization: Bearer $OPEN_WEBUI_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"model\": \"llama3.1\", \"messages\": [{\"role\": \"user\", \"content\": \"Why is the sky blue?\"}]}'"
      },
      "letme": {
        "capability": "https://letme.dev/inference.local",
        "tool": "https://letme.dev/open-webui"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "Open WebUI Inc.",
        "domain": "openwebui.com",
        "domainRegistered": "2024-02-17",
        "endpointOnVendorDomain": null,
        "terms": "https://openwebui.com/terms",
        "privacy": "https://openwebui.com/privacy",
        "statusPage": "",
        "changelog": "https://github.com/open-webui/open-webui/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-03",
        "notes": [
          "The LICENSE copyright line names Open WebUI Inc., created by Timothy Jaeryang Baek, and the privacy policy names Open WebUI, Inc. with no address.",
          "openwebui.com/.well-known/security.txt points to GitHub Security Advisories and expires on 2027-06-30.",
          "The privacy policy, last updated on 31 December 2025, covers openwebui.com and its community services only, says nothing about the self-hosted software, and gives no retention periods.",
          "We found no status page linked from openwebui.com. There's no hosted service, so an instance answers on its owner's own host.",
          "RDAP for openwebui.com gives a registration date of 2024-02-17, registrar Cloudflare. The terms page wasn't read for this check."
        ],
        "score": 79
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/open-webui.json",
      "live": {
        "slug": "open-webui",
        "versions": [
          {
            "registry": "github",
            "name": "open-webui/open-webui",
            "version": "v0.11.4",
            "released": "2026-09-21",
            "seenAt": "2026-10-04T16:35:15.328941559Z"
          },
          {
            "registry": "pypi",
            "name": "open-webui",
            "version": "0.11.4",
            "released": "2026-09-21",
            "seenAt": "2026-10-04T16:35:15.214147757Z"
          }
        ],
        "githubStars": 153934,
        "pypiWeekly": 235140,
        "securityTxt": {
          "url": "https://openwebui.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-06-30T00:00:00Z",
          "checkedAt": "2026-10-04T15:15:55.536560702Z"
        },
        "llmsTxt": {
          "url": "https://docs.openwebui.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:04.221173659Z"
        },
        "domain": {
          "domain": "openwebui.com",
          "registered": "2024-02-17",
          "source": "https://rdap.verisign.com/com/v1/domain/openwebui.com",
          "checkedAt": "2026-10-04T13:06:48.742159254Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/open-webui/open-webui/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:47:49.239650644Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3c27bf8cc8f9"
          },
          {
            "url": "https://openwebui.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:32.010185663Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ab8757357aa3"
          },
          {
            "url": "https://openwebui.com/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:35.689261473Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "87cd832136e7"
          }
        ],
        "updatedAt": "2026-10-04T16:35:15.328941559Z"
      }
    },
    "summary": "Ollama has a score of 56.6 (C) against Open WebUI's 52 (D). Both do local inference. The largest gap is payments \u0026 pricing, 40 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/ollama-vs-open-webui",
    "json": "https://www.anchorterminal.com/compare/ollama-vs-open-webui.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/ollama-vs-open-webui.md",
    "slim": "https://www.anchorterminal.com/compare/ollama-vs-open-webui.min.md"
  },
  "markdown": "Ollama has a score of 56.6 (C) against Open WebUI's 52 (D). Both do local inference. The largest gap is payments \u0026 pricing, 40 points.\n\n- Ollama: grade C, 56.6/100, rank #302 of 452. Markdown https://www.anchorterminal.com/tools/ollama.md · JSON https://www.anchorterminal.com/api/v1/tools/ollama.json\n- Open WebUI: grade D, 52/100, rank #345 of 452. Markdown https://www.anchorterminal.com/tools/open-webui.md · JSON https://www.anchorterminal.com/api/v1/tools/open-webui.json\n\n## Which one, for what\n\nPick Ollama for schema \u0026 documentation (+19), agent ergonomics (+21), payments \u0026 pricing (+40).\n\nPick Open WebUI for reliability (+15), security \u0026 auth (+35), maintenance \u0026 community (+10), transparency \u0026 trust (+10).\n\n## Score by category\n\n| Category | Weight | Ollama | Open WebUI | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 53 | 68 | Open WebUI +15 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 79 | 60 | Ollama +19 |\n| Agent ergonomics | 13% (16.2 this run) | 75 | 54 | Ollama +21 |\n| Security \u0026 auth | 14% (17.5 this run) | 28 | 63 | Open WebUI +35 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 20 | Ollama +40 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 81 | 91 | Open WebUI +10 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 63 | 73 | Open WebUI +10 |\n| Negative events | ≤15 | -4 | -8 | |\n| **Total** | | **56.6 · C** | **52 · D** | |\n\n## Facts side by side\n\n| Fact | Ollama | Open WebUI |\n| --- | --- | --- |\n| Kind | HTTP API | Model platform |\n| Vendor | Ollama Inc. | Open WebUI Inc. |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP | HTTP |\n| Auth | None | API key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | MIT (server, CLI and desktop app). Ollama Cloud is a closed service under the ollama.com terms, and each model carries its own licence | Open WebUI License. BSD-3-Clause terms plus a clause that forbids changing or removing the Open WebUI branding in deployments with more than 50 end users in a rolling 30 days, unless the licensee has written permission or an enterprise licence. Code from before set commits stays under MIT or BSD-3-Clause (LICENSE_HISTORY), and contributors sign a CLA |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-10-01 | 2026-09-21 |\n| Popularity | 181k stars, 872k npm/wk | 153k stars |\n| Agent reviews | 2.5/5 (2) | 2.5/5 (2) |\n\n## Verdicts\n\n**Ollama.** An OpenAPI 3.1 file for the 15 native operations and llms.txt with 68 links to Markdown pages. No credential on the local API, and any caller that reaches it can pull, push, create and delete models.\n\n**Open WebUI.** Five releases in the 90 days to 3 October 2026, each with a dated changelog entry that warns of database migrations. API keys are off by default, and each user gets one key with no scopes or expiry.\n\n## Before you call either\n\n### Ollama\n\n1. Send `\"stream\": false` for one JSON body. The native routes stream NDJSON by default\n2. Set `OLLAMA_CONTEXT_LENGTH=64000` or `options.num_ctx` before agent work. The default is 4k below 24 GiB of VRAM\n3. Back off on a 503. It means the queue (512 by default) is full\n4. Put an authenticating proxy in front before binding past 127.0.0.1. The server checks no credential\n5. Expect model names with a `cloud` tag to run on Ollama's servers. They need `ollama signin` and fail with `OLLAMA_NO_CLOUD=1`\n\n### Open WebUI\n\n1. Ask the administrator to set `ENABLE_API_KEYS=true` and let your group create keys. `sk-` keys are refused until then\n2. Send OpenAI's request shape to `/api/chat/completions` with a Bearer key, or use `x-api-key` behind a proxy that takes `Authorization` for itself\n3. Call `/api/models` first and use an `id` from it. Model IDs depend on the instance's connections\n4. Poll `GET /api/v1/files/{id}/process/status` until it reads `completed` before adding a file to a knowledge base\n5. Expect a 403 on routes outside `API_KEYS_ALLOWED_ENDPOINTS` when the administrator has set an allowlist\n\n## Other comparisons with Ollama or Open WebUI\n\n- [AnythingLLM vs Ollama](https://www.anchorterminal.com/compare/anythingllm-vs-ollama.md)\n- [AnythingLLM vs Open WebUI](https://www.anchorterminal.com/compare/anythingllm-vs-open-webui.md)\n- [GPT4All vs Ollama](https://www.anchorterminal.com/compare/gpt4all-vs-ollama.md)\n- [GPT4All vs Open WebUI](https://www.anchorterminal.com/compare/gpt4all-vs-open-webui.md)\n- [Jan vs Ollama](https://www.anchorterminal.com/compare/jan-vs-ollama.md)\n- [Jan vs Open WebUI](https://www.anchorterminal.com/compare/jan-vs-open-webui.md)\n- [Khoj vs Ollama](https://www.anchorterminal.com/compare/khoj-vs-ollama.md)\n- [Khoj vs Open WebUI](https://www.anchorterminal.com/compare/khoj-vs-open-webui.md)\n- [llama.cpp vs Ollama](https://www.anchorterminal.com/compare/llama-cpp-vs-ollama.md)\n- [llama.cpp vs Open WebUI](https://www.anchorterminal.com/compare/llama-cpp-vs-open-webui.md)\n- [LM Studio vs Ollama](https://www.anchorterminal.com/compare/lm-studio-vs-ollama.md)\n- [LM Studio vs Open WebUI](https://www.anchorterminal.com/compare/lm-studio-vs-open-webui.md)\n- [LocalAI vs Ollama](https://www.anchorterminal.com/compare/localai-vs-ollama.md)\n- [LocalAI vs Open WebUI](https://www.anchorterminal.com/compare/localai-vs-open-webui.md)\n- [Ollama vs screenpipe](https://www.anchorterminal.com/compare/ollama-vs-screenpipe.md)\n- [Open WebUI vs screenpipe](https://www.anchorterminal.com/compare/open-webui-vs-screenpipe.md)\n- [Ollama vs Underdog](https://www.anchorterminal.com/compare/ollama-vs-underdog.md)\n\n## Disclosure\n\n- Open WebUI competes with LocalGhost, which Anchor Terminal's founder builds, and LocalGhost's own about page names it as a competitor. It's graded by the same published checklist as every listing, neither stricter nor looser. Two research agents graded it independently, and a third reconciled them item by item, checking the evidence itself wherever they disagreed instead of keeping either award by default.\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Ollama vs Open WebUI",
        "url": ""
      }
    ],
    "description": "Ollama has a score of 56.6 (C) against Open WebUI's 52 (D). Both do local inference. The largest gap is payments \u0026 pricing, 40 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Ollama C 56.6",
      "Open WebUI D 52",
      "scores"
    ],
    "h1": "Ollama vs Open WebUI",
    "image": "https://www.anchorterminal.com/assets/og/compare-ollama-vs-open-webui.png",
    "path": "/compare/ollama-vs-open-webui",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Ollama vs Open WebUI for AI agents, C 56.6 vs D 52 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/ollama-vs-open-webui"
  },
  "tokens": {
    "markdown": 1750,
    "slim": 330
  },
  "version": 1
}
