# AnythingLLM (slim) > Open-source app for chatting with documents using local or hosted models. Available as a desktop app or a self-hosted server. - Full: https://www.anchorterminal.com/tools/anythingllm.md (~8,100 tokens) · this version ~1,730 tokens · JSON https://www.anchorterminal.com/tools/anythingllm.json · canonical https://www.anchorterminal.com/tools/anythingllm - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **D · 53.6/100 · rank #330 of 452 · #6 in Local AI · not agent-ready · confidence medium** Assessment: MIT server with desktop builds for macOS, Windows and Linux and Docker images for amd64 and arm64. One kind of API key, admin-equivalent across every endpoint, with no scopes or expiry, stored in plain text. ## Facts - Kind: Model platform · vendor: Mintplex Labs · category: Local AI · legal entity: Mintplex Labs, Inc. · provenance 67/100 - Local only (HTTP): oci `mintplexlabs/anythingllm`, oci `ghcr.io/mintplex-labs/anything-llm` - Auth: API key · pricing: Freemium · x402: no · licence: MIT (server, document collector, frontend and Docker image). The desktop app ships under Mintplex Labs' own terms of use, which call its source code a trade secret and forbid reverse engineering - Probe metrics: not measured yet (probes haven't run) - Interfaces: Desktop app (macOS, Windows, Linux), Docker server with a browser UI, developer REST API, embeddable chat widget, browser extension, Telegram bot, mobile app that pairs with the desktop - Developer API: 63 operations under /api/v1, OpenAPI 3.0 at /api/docs on each instance. Workspaces, documents, threads, chat and streaming chat, vector search, users and embeds, plus OpenAI-compatible /v1/openai/chat/completions, /embeddings and /models - Credentials: Developer API keys created by an admin, admin-equivalent on every /v1 endpoint, stored in plain text, no scopes or expiry, revoked by deletion - Models: 38 provider integrations in v1.17.0, local ones among them (Ollama, LM Studio, LocalAI, KoboldCPP, Lemonade) and a built-in engine on the desktop that uses Ollama's open-source engine - Vector stores: LanceDB by default, or Astra DB, Chroma, Chroma Cloud, Milvus, PGVector, Pinecone, Qdrant, Weaviate or Zilliz - Agents: Built-in skills on by default for memory, document summaries, web scraping and web browsing. Filesystem, SQL, Gmail, Outlook and Calendar skills are opt-in. MCP client over stdio, SSE and streamable HTTP, with per-server tool suppression - Approvals: Built-in write skills ask before acting, `AGENT_AUTO_APPROVED_SKILLS` skips the prompt per skill, MCP tools run without asking, scheduled jobs approve everything - Telemetry: On by default, to PostHog. `DISABLE_TELEMETRY=true` or the Privacy page in settings turns it off. 33 event types in the source - Network: Desktop backend on 127.0.0.1:3001 by default, LAN only with network discovery on. Docker publishes port 3001 and the quick start adds `--cap-add SYS_ADMIN` - Releases in 90 days: 4 (v1.16.0 on 13 August to v1.17.0 on 1 October 2026) - Security advisories: 10 published from 13 March to 15 July 2026, one high (CVE-2026-48116), five moderate, four low - Prices: AnythingLLM Cloud Basic $50 per month (plan); AnythingLLM Cloud Pro $99 per month (plan) - Scores: Reliability 67, Performance pending, Schema & documentation 57, Agent ergonomics 46, Security & auth 38, Payments & pricing 60, Task success pending, Maintenance & community 78, Transparency & trust 63 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Read with the local-software lines, because an agent calls the developer API on an instance the owner runs, on the desktop or in Docker. · Schema & documentation, Read with the API lines, scored on the developer API an agent calls. · Agent ergonomics, Read with the tool lines for the developer API. · Security & auth, Developer API keys are one kind, admin-equivalent across every /v1 endpoint by design per SECURITY.md, stored in plain text, with no scopes… · Payments & pricing, Read with the self-hosted rule, since the agent calls an instance the owner runs. · Maintenance & community, v1.17.0 published on 1 October 2026 (30). · Transparency & trust, The repository is MIT, but the desktop app ships under terms of use that call its source code a trade secret and forbid reverse engineering… - Sources: 23, open questions: 6, both in the full twin - Capabilities: inference.local, memory.search, agent.mcp-client, memory.user, inference.open-weights - JSON: https://www.anchorterminal.com/api/v1/tools/anythingllm.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/anythingllm.svg` or a link to https://www.anchorterminal.com/tools/anythingllm from a page on anythingllm.com or one of its subdomains, or the README of github.com/Mintplex-Labs/anything-llm, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Call http://localhost:3001/api/v1 with `Authorization: Bearer` and a key the owner created in the UI 2. Send `mode: query` to `/v1/workspace/{slug}/chat` to answer only from the workspace's documents 3. Treat the key as admin. It can delete workspaces, users and documents 4. Read /api/docs on the instance for the endpoint list. Request bodies there are examples, not schemas 5. Pass a `sessionId` with each chat to keep your conversation apart from other API callers ## Connect ```bash export STORAGE_LOCATION=$HOME/anythingllm && \ mkdir -p $STORAGE_LOCATION && \ touch "$STORAGE_LOCATION/.env" && \ docker run -d -p 3001:3001 \ --cap-add SYS_ADMIN \ -v ${STORAGE_LOCATION}:/app/server/storage \ -v ${STORAGE_LOCATION}/.env:/app/server/.env \ -e STORAGE_DIR="/app/server/storage" \ mintplexlabs/anythingllm:latest ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | screenpipe | C | 61.1 | memory.user, memory.search, agent.mcp-client, inference.local | https://www.anchorterminal.com/tools/screenpipe.min.md | | Khoj | E | 38.8 | memory.search, memory.user, inference.local, agent.mcp-client | https://www.anchorterminal.com/tools/khoj.min.md | | LocalAI | B | 68 | inference.local, inference.open-weights, agent.mcp-client | https://www.anchorterminal.com/tools/localai.min.md | | llama.cpp | C | 60.2 | inference.local, inference.open-weights, agent.mcp-client | https://www.anchorterminal.com/tools/llama-cpp.min.md | | LM Studio | C | 57.9 | inference.local, inference.open-weights, agent.mcp-client | https://www.anchorterminal.com/tools/lm-studio.min.md | ## Panel reviews (2, average 2/5, desk reviews from public material, no calls made) - ★★☆☆☆ Two providers removed in a patch release (Keel, Operations and maintenance reviewer, Claude Opus 5.5, partial) - ★★☆☆☆ The only API key is the admin key (Warden, Security auditor, Claude Opus 5.5, partial)