Docker Model Runner
by Docker, Inc. HTTP API in Local AI
Docker, Inc. · docker.com since 1995 · who's behind it
Docker's open-source tool for pulling and running open models from Docker Hub, OCI registries or Hugging Face. It runs through Docker Desktop, Docker Engine or a standalone dmr binary, with local OpenAI-, Anthropic- and Ollama-compatible APIs.
Good for A team that already runs Docker and wants local models served to containers and Compose services through OpenAI-, Anthropic- or Ollama-compatible routes, with models stored as OCI artefacts.
Is this your product? Claim this listing or verify it
More from Docker, Inc. Docker Agent (Frameworks)
Assessment. CI passes on the main branch, and Docker has published two security advisories with CVEs and fixed versions for the project. The API takes no credential, so any client or container that reaches it can pull, delete and run models, and the documentation has no OpenAPI file or error reference.
Facts
- Transport
- HTTP
- Auth
- None
- Pricing
- Free · Free · OSS
- x402
- No
- Licence
- Apache-2.0 (server, CLI plugin and `dmr` binary). Docker Desktop, which bundles it, is closed software under Docker's subscription agreement, and each model carries its own licence
- Packages
ocidocker.io/docker/model-runner- llms.txt
- published
- Last release
- GitHub stars
- 656
- Interfaces
docker modelCLI plugin (39 documented commands and subcommands), Docker Desktop Models tab, standalonedmrbinary, local HTTP API on port 12434 or a Unix socket, Docker Composemodelselement- Routes
- OpenAI-compatible /engines/v1 (chat completions, completions, embeddings, models), Anthropic-compatible /anthropic/v1/messages and count_tokens, Ollama-compatible /api (tags, show, chat, generate), image generation at /engines/diffusers/v1/images/generations, and native /models for pull, list, inspect and delete. The source also registers a Responses API, rerank and score routes. No OpenAPI file
- Credentials
- None. Host-side TCP off by default in Docker Desktop, on by default in Docker Engine. Cross-origin requests allowed from localhost, 127.0.0.1 and 0.0.0.0, widened with
DMR_ORIGINS - Engines
- llama.cpp for GGUF models on every platform (default), vLLM for Safetensors on Linux x86_64 and Windows with WSL2 with an NVIDIA GPU, Diffusers for image generation on Linux with an NVIDIA GPU
- Hardware
- macOS on Apple Silicon. Windows amd64 with NVIDIA drivers 576.57 or later, Windows arm64 with a Qualcomm Adreno 6xx or later GPU. Linux with CPU, NVIDIA CUDA (driver 575.57.08 or later), AMD ROCm or Vulkan
- Models
- Pulled as OCI artefacts from Docker Hub (the
ai/namespace) or any OCI registry, or from Hugging Face withhf.co/names.docker model packageandpushpublish GGUF and Safetensors files - Defaults
- llama.cpp context of 4,096 tokens. Models load on first request and unload when idle. Requests above 10 MiB are refused
- Isolation
- Engines run in a container on Linux and in a sandbox on macOS (seatbelt) and Windows (Job Objects). Runtime flags are checked against an allowlist
- What leaves the machine
- Prompts and responses don't, per the docs. A HEAD request to the registry carries the model name and user agent, off with Docker Desktop's usage statistics setting or
DO_NOT_TRACK=1in the source - Observability
docker model logs,docker model requests(the last 10 requests per model in the source) and a Prometheus/metricsroute, off withDISABLE_METRICS=1- Releases in 90 days
- 2 (v1.2.7 on 11 August and v1.2.8 on 12 August 2026)
- Security record
- CVE-2026-28400 (7.5, fixed in 1.0.16) and CVE-2026-33990 (7.1, fixed in 1.1.25), both published as GitHub advisories
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- OpenAI-, Anthropic- and Ollama-compatible routes on one local port, so existing clients for those three APIs work with a changed base URL
- CI runs lint, race-detector tests and end-to-end tests on every push to main, and the ten most recent runs on main passed on 8 October 2026
- Two GitHub security advisories with CVE numbers, fixed versions and workarounds, and a SECURITY.md that promises an acknowledgement within 72 hours
- Apache-2.0 source, and the docs list what usage data is collected with a link to the code that sends it
- Host-side TCP is off by default in Docker Desktop, and inference engines run sandboxed on macOS and Windows or in a container on Linux
Weaknesses
- No credential on the API. The docs say any client that can reach it, including other containers, can pull, load and run models
- No OpenAPI file, no error reference and no rate-limit or retry guidance in the reviewed documentation
- Two releases in the 90 days to 8 October 2026 (v1.2.7 and v1.2.8), the latest on 12 August
- CVE-2026-28400 let an unauthenticated caller overwrite files, including the Docker Desktop VM disk, until 1.0.16 in February 2026
- On Docker Engine the docs say model-name requests go to Docker Hub regardless of settings, and the
DO_NOT_TRACKswitch in the source is undocumented
Before you call it notes for agents
- Use base URL
http://localhost:12434/engines/v1for OpenAI clients andhttp://localhost:12434for Anthropic and Ollama clients. Any API key value is accepted - In Docker Desktop, run
docker desktop enable model-runner --tcp 12434first. Host-side TCP is off by default - From a container, call
http://model-runner.docker.internalon Docker Desktop orhttp://172.17.0.1:12434on Docker Engine - Raise the context before agent work with
docker model configure --context-size <n> <model>. The llama.cpp default is 4,096 tokens - Name models with their namespace, such as
ai/smollm2, and expect plain-text error bodies with a 400, 404, 500 or 503 status
Who's behind it provenance 84/100
- Legal entity namedDocker, Inc.20/20
- Domain agedocker.com, registered 1995-01-25 (31 years)15/15
- Endpoint on the vendor's domainno hosted endpointn/a
- Terms of serviceread, states 7 of the 7 things a reader expects, and has 2 clauses that cost points6/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagenot found0/10
- Changelogpublished10/10
- security.txtvalid10/10
Terms and privacy, as read
Terms of service dated 2026-08-26, states 7 of 7, 4 to know
TL;DR Dated 2026-08-26. States all 7 things a reader expects. To know before relying on it, limits on automated access, limits on benchmarking, cut-off without notice or for any reason and arbitration or a class action waiver.
Restricts automated accesscosts points
Use any robot, spider, site search/retrieval application, or other device to retrieve or index any portion of the Services or the content posted thereon or to collect information about its users for any unauthorized purpose;
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Restricts benchmarking or competitive usecosts points
access the Services for the purpose of developing or operating products or services intended to be offered to third parties in competition with the Services or exploit the Services for any unauthorized commercial purpose
A clause against publishing test results or using the service to build something that competes.
Says access can be ended without notice or for any reason
Users with an account that is inactive for more than six (6) months may be terminated at Docker’s discretion and without further notice.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
Any dispute, controversy or claim arising under, out of or relating to this Agreement, will be finally determined by arbitration conducted by JAMS
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2026-08-26
Last updated on August 26, 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of California
The laws of the State of California and controlling United States federal law.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at $100
NOTWITHSTANDING ANYTHING ELSE IN THE AGREEMENT, DOCKER’S MAXIMUM AGGREGATE LIABILITY TO CUSTOMER FOR SUCH SERVICES SHALL NOT EXCEED THE GREATER OF (A) ONE-HUNDRED DOLLARS ($100) OR (B) THE FEES PAID BY CUSTOMER FOR SUCH TRIAL SERVICES.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Docker may modify or terminate Customer’s right to use Trial Services at any time and for any reason in its sole discretion.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
Docker may modify these terms from time to time, with notice to Customer in accordance with Section 18.2 (Legal Notices) or by posting the modified terms on our website.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
The Services are not designed, and Customer shall not use the Services as a basis, to deploy systems that must be hardened or highly secure except to the extent supported by DHI, or involve mission-critical business operations, the operation of nuclear facilities, aircraft navigation, important communication systems,…
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
During the Subscription Term, Docker will provide support for the Services in accordance with the Service Level Agreement & Terms available at https://www.docker.com/support/ as applicable to the products and support purchased via an Order Form.
Says whether availability is promised and where the promise is written.
Docker accepts no liability for the customer's use of Output or for any autonomous or semi-autonomous action taken by an AI Feature.
NOTWITHSTANDING ANYTHING TO THE CONTRARY IN THIS AGREEMENT, DOCKER WILL HAVE NO LIABILITY OR RESPONSIBILITY FOR CUSTOMER’S OR ITS USERS’ USE OF OUTPUT OR ANY AUTONOMOUS OR SEMI-AUTONOMOUS ACTION.
Noted by a second reader on 2026-10-08.
The customer indemnifies Docker against third-party claims arising from any action, Output, omission or decision of an AI Agent or AI Feature working on its behalf.
any claim by a third party arising from or relating to any action, Output, omission, or decision by an AI Agent or AI Feature operating on behalf of, or initiated by, Customer or its Users
Noted by a second reader on 2026-10-08.
The initial term renews automatically for 12-month periods unless a party gives at least 30 days' written notice before the current term ends.
The Initial Term will automatically renew for additional 12-month periods unless a party provides at least 30 days’ written notice prior to the end of the then-current term that such party does not wish to renew for the upcoming term
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 9,421 words
Privacy policy dated 2026-08-26, states 8 of 8
TL;DR Dated 2026-08-26. States all 8 things a reader expects. The rules found no clause to flag.
Gives the date it was last updated Last updated 2026-08-26
Last Update: August 26, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
Where you subscribe to Docker’s self-service AI services as an individual, this Privacy Policy applies to the personal data we collect from you as described below;
The basic statement a privacy policy exists to make.
Says how long data is kept Names a period of 7 days
earlier snapshots and images are deleted within 7 days.
Says when data sent to the service is deleted.
Says who else receives the data
(iv) credentials you choose to store — API keys and access tokens for third-party AI model providers and MCP-connected tools, which we store securely on your behalf in order to provide the Services;
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
In the preceding 12 months we did not sell or share for cross context behavioral advertising, the personal information of California residents.
A plain statement either way.
Says what rights people have over their data
This includes the right to object to our processing of your personal data for direct marketing and the right to object to our processing of your personal data where we are performing a task in the public interest or pursuing our legitimate interests or those of a third party.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@docker.com
You may also contact Docker by emailing privacy@docker.com or by sending postal mail to: Docker, Inc., 3790 El Camino Real # 1052, Palo Alto, CA 94306, (415) 941-0376
An address or officer to send a request to.
Says where data is transferred or stored Relies on the Data Privacy Framework
Data Privacy Framework, Docker is responsible for the processing of personal data received from Customers from the EU, the UK, and Switzerland and onward transfers to a third party acting as an agent on our behalf.
The countries data goes to and the safeguard used.
A saved sandbox image or snapshot may contain the prompts and responses from the session.
If you save a sandbox image or snapshot, it may contain prompts and responses from your session.
Noted by a second reader on 2026-10-08.
Docker stores the API keys and access tokens for third-party AI model providers and MCP-connected tools that a user chooses to store.
API keys and access tokens for third-party AI model providers and MCP-connected tools, which we store securely on your behalf in order to provide the Services
Noted by a second reader on 2026-10-08.
Docker gives its customers information on how particular domains access and use the Website, Services and particular functions or uploads.
Docker also provides information on how particular domains (e.g., www.companyx.com ) access and use our Website, Services, and particular features or uploads to customers for their business purposes, for example, so they can improve or target their software and other offerings.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 7,523 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The repository is under GitHub's docker organisation and SECURITY.md sends reports to security@docker.com. The subscription agreement and privacy policy both name Docker, Inc.
Docker publishes no terms written for Model Runner. The Docker Subscription Service Agreement (last updated 26 August 2026) governs Docker Desktop, which bundles it, and the privacy policy carries the same date. The Engine plugin and the dmr binary are under Apache-2.0 only.
www.docker.com/.well-known/security.txt gives security@docker.com, a policy URL and an expiry of 1 January 2030.
No status page is listed because the software runs on the owner's machine.
RDAP for docker.com gives a registration date of 1995-01-25.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 18:27 UTC
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| www.docker.com/pricing | pricing | 43 minutes ago · 200 | no change seen |
| www.docker.com/legal/docker-subscription-service-agreement | terms | 43 minutes ago · 200 | no change seen |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/docker-model-runner.json
Notable
- The docs state that the API is not authenticated and that any client that can reach it, including other containers on the same Docker network, can pull, load and run models source
- CVE-2026-28400 (7.5), published on 27 February 2026. The unauthenticated
/engines/_configureroute accepted arbitrary runtime flags and could overwrite files, fixed in 1.0.16 and Docker Desktop 4.61.0 source - CVE-2026-33990 (7.1), published on 30 March 2026. A malicious OCI registry could make the runner send GET requests to host-local services, fixed in 1.1.25 and Docker Desktop 4.67.0 source
- Usage tracking is a HEAD request to the registry with the model name and user agent. Docker Desktop's usage statistics setting turns it off, and the docs say Docker Engine sends it regardless of settings source source 2
- The llama.cpp engine defaults to a 4,096-token context, changed per model with
docker model configure --context-sizesource - A standalone
dmrbinary (dmr 0.1.0, 7 July 2026) runs the daemon and CLI without Docker Desktop or Docker Engine, on TCP port 12434 by default source docker model launchstarts AnythingLLM, Claude Code, Codex, OpenClaw, OpenCode or Open WebUI configured to use the local runner source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 17.0 | |
Read with the local-software lines, since the API runs on the owner's machine. Bundled with Docker Desktop, installed as docker-model-plugin from Docker's apt and dnf repositories, and shipped as a standalone dmr binary through Homebrew and winget, with platform, GPU and driver requirements stated in the docs (20). The CI workflow runs lint, race-detector tests and builds on pushes and pull requests to main, with separate end-to-end, integration and daily check workflows, and the ten most recent CI runs on main passed on 8 October 2026 (25). 41 open issues and 25 open pull requests. Each of the 20 newest open issues had at least one comment, but several are regressions or failures still open, including HTTP 500 on sequential tool calls (#1063), a Windows GPU regression after Docker Desktop 4.82.0 (#1054) and a context-size setting applied nondeterministically (#1025) (17 of 25). Semver tags with notes on each GitHub release, but no changelog file and no breaking-change section in the notes we read (8 of 15). Version 1.2.8 (15). The docs make no stability statement for the REST API, and the Unix-socket path still carries an /exp/ prefix. | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 8.0 | |
| Read for an API. No OpenAPI or similar file was found in the repository or the docs. The compatible routes point to OpenAI's and Anthropic's own references, and the CLI has a generated reference for 39 commands and subcommands (5 of 25). docs.docker.com has llms.txt and serves each page as Markdown, such as /ai/model-runner/api-reference.md (10). The API reference names a use case for each of its five API families and gives base URLs for containers, host TCP and the Unix socket (12 of 20). Parameters are listed in tables with types and ranges for the OpenAI, Anthropic and image routes, in prose only (7 of 15). curl examples for every family, but no error responses documented (7 of 15). Dated GitHub releases with notes. The API has no version of its own, and the reference omits routes present in the source, including the Responses API, rerank and the Ollama pull and delete routes (8 of 15). | |||
| Agent ergonomics | 13%16.2 | 9.4 | |
Read for an API. Output can be sized with max_tokens, stop sequences and JSON mode, and streaming is opt-in on the OpenAI and Anthropic routes (17 of 25). Output-size controls on the generation routes, with unpaged model lists, which are small on most machines (12 of 20). Errors in the source are plain-text bodies with status 400, 404, 500 or 503, and the docs don't describe them (7 of 20). Inference is stateless and safe to retry, but no retry or backoff guidance and no idempotency keys for pull or delete were found (10 of 20). model is the only required field beyond the messages or prompt. There is no SDK of its own, though OpenAI, Anthropic and Ollama clients work against it, and the docs link Testcontainers modules for Java and Go (12 of 15). | |||
| Security & auth | 14%17.5 | 7.0 | |
Read with the tool checklist, for the local API. No credential, by design. The docs say the API is not authenticated and that any client that can reach it, including other containers on the same Docker network, can pull, load and run models. Host-side TCP is off by default in Docker Desktop and on by default on port 12434 in Docker Engine, and cross-origin requests are refused with 403 unless the origin is localhost, 127.0.0.1, 0.0.0.0 or listed in DMR_ORIGINS (7 of 30). No read-only mode or per-caller limit. Runtime flags pass an allowlist, engines run sandboxed on macOS and Windows and in a container on Linux, and Enhanced Container Isolation, a Docker Business control, blocks container access (6 of 20). The API returns model output, with no injection guidance in the docs (6 of 15). docker model requests and the Requests tab show recent requests and responses, the source keeps the last 10 per model, and /metrics exposes Prometheus counters. No caller identity (8 of 15). www.docker.com has a valid security.txt with a disclosure policy, SECURITY.md promises an acknowledgement within 72 hours, and two advisories were published with CVEs in 2026. No monetary bounty for this project (13 of 20). | |||
| Payments & pricing | 10%12.5 | 7.5 | |
Read with the self-hosted rule, since the API an agent calls is free software on the owner's machine. No x402, MPP or L402 in the docs or the source (0). Model Runner is Apache-2.0 with nothing to buy and no account needed for the Docker Engine plugin or the dmr binary, so 20, 20 and 20 on the last three lines. One qualification applies to the Docker Desktop route. Docker's subscription agreement limits free Desktop use to non-commercial open-source projects and businesses with fewer than 250 employees and under US $10,000,000 in annual revenue, and paid plans run from $11 to $24 per user a month. | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 4.8 | |
v1.2.8 was released on 12 August 2026, 57 days before the check (20 of 30). Two releases in the 90 days to 8 October 2026, v1.2.7 on 11 August and v1.2.8, against 30 or so between March and June (0 of 20). 45 commits on main since 10 July, the newest on 8 October, and each of the 20 newest open issues had at least one comment, with 41 issues and 25 pull requests open (17 of 25). No SDK of its own. The docker model CLI plugin is the official client, and Testcontainers has modules for Java and Go (8 of 15). Dependabot runs weekly on Go modules and GitHub Actions, actions are pinned by commit, a script bumps llama.cpp, and CI passes on main (10). | |||
| Transparency & trusteditorial 62, provenance 84 | 7%8.8 | 6.4 | |
The editorial half. Apache-2.0 for the server, the CLI and the dmr binary in a public repository. Docker Desktop, which bundles it on macOS and Windows, is closed software under Docker's subscription agreement (27 of 30). The docs' privacy section says no prompt content, responses or personal data is collected, and Docker's privacy policy and subscription agreement, both updated on 26 August 2026, cover the Desktop product. No retention period specific to Model Runner was found (18 of 30). No deprecation policy for the API was found, and the reference doesn't mark any route as stable or experimental (4 of 20). Telemetry is disclosed with a link to the source. It is a HEAD request to the registry carrying the model name and user agent, and Docker Desktop's usage statistics setting turns it off. For Docker Engine the docs say the requests are made regardless of settings, while the source skips them when DO_NOT_TRACK=1, which the docs don't mention (13 of 20). | |||
| Negative events | ≤15 |
| -3 |
| Total | 57.1 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 18 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Docker Model Runner, or have the agent fetch /fixes/docker-model-runner.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Docker Model Runner From Anchor Terminal's listing at https://www.anchorterminal.com/tools/docker-model-runner, the October 2026 research run, assessed 8 October 2026. Grade C, 57.1 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Docker Model Runner: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Security & auth, 40 out of 100, up to 10.5 more on the total Why it scored 40: Read with the tool checklist, for the local API. No credential, by design. The docs say the API is not authenticated and that any client that can reach it, including other containers on the same Docker network, can pull, load and run models. Host-side TCP is off by default in Docker Desktop and on by default on port 12434 in Docker Engine, and cross-origin requests are refused with 403 unless the origin is localhost, 127.0.0.1, 0.0.0.0 or listed in `DMR_ORIGINS` (7 of 30). No read-only mode or per-caller limit. Runtime flags pass an allowlist, engines run sandboxed on macOS and Windows and in a container on Linux, and Enhanced Container Isolation, a Docker Business control, blocks container access (6 of 20). The API returns model output, with no injection guidance in the docs (6 of 15). `docker model requests` and the Requests tab show recent requests and responses, the source keeps the last 10 per model, and `/metrics` exposes Prometheus counters. No caller identity (8 of 15). www.docker.com has a valid security.txt with a disclosure policy, SECURITY.md promises an acknowledgement within 72 hours, and two advisories were published with CVEs in 2026. No monetary bounty for this project (13 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 2. Schema & documentation, 49 out of 100, up to 8.3 more on the total Why it scored 49: Read for an API. No OpenAPI or similar file was found in the repository or the docs. The compatible routes point to OpenAI's and Anthropic's own references, and the CLI has a generated reference for 39 commands and subcommands (5 of 25). docs.docker.com has llms.txt and serves each page as Markdown, such as /ai/model-runner/api-reference.md (10). The API reference names a use case for each of its five API families and gives base URLs for containers, host TCP and the Unix socket (12 of 20). Parameters are listed in tables with types and ranges for the OpenAI, Anthropic and image routes, in prose only (7 of 15). curl examples for every family, but no error responses documented (7 of 15). Dated GitHub releases with notes. The API has no version of its own, and the reference omits routes present in the source, including the Responses API, rerank and the Ollama pull and delete routes (8 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 3. Agent ergonomics, 58 out of 100, up to 6.8 more on the total Why it scored 58: Read for an API. Output can be sized with `max_tokens`, stop sequences and JSON mode, and streaming is opt-in on the OpenAI and Anthropic routes (17 of 25). Output-size controls on the generation routes, with unpaged model lists, which are small on most machines (12 of 20). Errors in the source are plain-text bodies with status 400, 404, 500 or 503, and the docs don't describe them (7 of 20). Inference is stateless and safe to retry, but no retry or backoff guidance and no idempotency keys for pull or delete were found (10 of 20). `model` is the only required field beyond the messages or prompt. There is no SDK of its own, though OpenAI, Anthropic and Ollama clients work against it, and the docs link Testcontainers modules for Java and Go (12 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 4. Payments & pricing, 60 out of 100, up to 5 more on the total Why it scored 60: Read with the self-hosted rule, since the API an agent calls is free software on the owner's machine. No x402, MPP or L402 in the docs or the source (0). Model Runner is Apache-2.0 with nothing to buy and no account needed for the Docker Engine plugin or the `dmr` binary, so 20, 20 and 20 on the last three lines. One qualification applies to the Docker Desktop route. Docker's subscription agreement limits free Desktop use to non-commercial open-source projects and businesses with fewer than 250 employees and under US $10,000,000 in annual revenue, and paid plans run from $11 to $24 per user a month. The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 5. Maintenance & community, 55 out of 100, up to 3.9 more on the total Why it scored 55: v1.2.8 was released on 12 August 2026, 57 days before the check (20 of 30). Two releases in the 90 days to 8 October 2026, v1.2.7 on 11 August and v1.2.8, against 30 or so between March and June (0 of 20). 45 commits on main since 10 July, the newest on 8 October, and each of the 20 newest open issues had at least one comment, with 41 issues and 25 pull requests open (17 of 25). No SDK of its own. The `docker model` CLI plugin is the official client, and Testcontainers has modules for Java and Go (8 of 15). Dependabot runs weekly on Go modules and GitHub Actions, actions are pinned by commit, a script bumps llama.cpp, and CI passes on main (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 6. Reliability, 85 out of 100, up to 3 more on the total Why it scored 85: Read with the local-software lines, since the API runs on the owner's machine. Bundled with Docker Desktop, installed as `docker-model-plugin` from Docker's apt and dnf repositories, and shipped as a standalone `dmr` binary through Homebrew and winget, with platform, GPU and driver requirements stated in the docs (20). The CI workflow runs lint, race-detector tests and builds on pushes and pull requests to main, with separate end-to-end, integration and daily check workflows, and the ten most recent CI runs on main passed on 8 October 2026 (25). 41 open issues and 25 open pull requests. Each of the 20 newest open issues had at least one comment, but several are regressions or failures still open, including HTTP 500 on sequential tool calls (#1063), a Windows GPU regression after Docker Desktop 4.82.0 (#1054) and a context-size setting applied nondeterministically (#1025) (17 of 25). Semver tags with notes on each GitHub release, but no changelog file and no breaking-change section in the notes we read (8 of 15). Version 1.2.8 (15). The docs make no stability statement for the REST API, and the Unix-socket path still carries an `/exp/` prefix. The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 7. Transparency & trust, 73 out of 100, up to 2.4 more on the total Made of editorial 62, provenance 84. Why it scored 73: The editorial half. Apache-2.0 for the server, the CLI and the `dmr` binary in a public repository. Docker Desktop, which bundles it on macOS and Windows, is closed software under Docker's subscription agreement (27 of 30). The docs' privacy section says no prompt content, responses or personal data is collected, and Docker's privacy policy and subscription agreement, both updated on 26 August 2026, cover the Desktop product. No retention period specific to Model Runner was found (18 of 30). No deprecation policy for the API was found, and the reference doesn't mark any route as stable or experimental (4 of 20). Telemetry is disclosed with a link to the source. It is a HEAD request to the registry carrying the model name and user agent, and Docker Desktop's usage statistics setting turns it off. For Docker Engine the docs say the requests are made regardless of settings, while the source skips them when `DO_NOT_TRACK=1`, which the docs don't mention (13 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points (6 of 10) - Status page: not found (0 of 10) ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - 2026-02-27. GHSA-m456-c56c-hh5c (CVE-2026-28400, 7.5). The unauthenticated `/engines/_configure` route accepted arbitrary runtime flags, so a caller, including a container on Docker Desktop, could overwrite files the runner could reach, the Desktop VM disk among them. Fixed in Model Runner 1.0.16 and Docker Desktop 4.61.0 and published by Docker, more than six months ago, -2. https://github.com/docker/model-runner/security/advisories/GHSA-m456-c56c-hh5c - 2026-03-30. GHSA-x2f5-332j-9xwq (CVE-2026-33990, 7.1). A malicious OCI registry could point the token exchange at an internal URL and make the runner send GET requests to host-local services. Fixed in 1.1.25 and Docker Desktop 4.67.0 and published by Docker, more than six months ago, -1. https://github.com/docker/model-runner/security/advisories/GHSA-x2f5-332j-9xwq ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: Docker Desktop release notes, which may carry Model Runner changes between the tagged releases, so the release count covers GitHub tags only - unchecked: whether the Docker Engine install publishes port 12434 on loopback only. The server source listens on every interface when `MODEL_RUNNER_PORT` is set - unchecked: reply times on issues. We saw comment counts on the issue list, not who replied or when - unchecked: Docker's SOC 2 or ISO 27001 status, which we didn't look up for this listing - unchecked: the first release date, and pull counts for the docker/model-runner image - Docker publishes no terms written for Model Runner itself. The subscription agreement and privacy policy listed are the ones that govern Docker Desktop, and the Engine plugin and `dmr` binary are under Apache-2.0 only - The API reference shows the Anthropic route as /anthropic/v1/messages in its table and /v1/messages in its examples. The source registers both ## Weaknesses - No credential on the API. The docs say any client that can reach it, including other containers, can pull, load and run models - No OpenAPI file, no error reference and no rate-limit or retry guidance in the reviewed documentation - Two releases in the 90 days to 8 October 2026 (v1.2.7 and v1.2.8), the latest on 12 August - CVE-2026-28400 let an unauthenticated caller overwrite files, including the Docker Desktop VM disk, until 1.0.16 in February 2026 - On Docker Engine the docs say model-name requests go to Docker Hub regardless of settings, and the `DO_NOT_TRACK` switch in the source is undocumented ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Use base URL `http://localhost:12434/engines/v1` for OpenAI clients and `http://localhost:12434` for Anthropic and Ollama clients. Any API key value is accepted - In Docker Desktop, run `docker desktop enable model-runner --tcp 12434` first. Host-side TCP is off by default - From a container, call `http://model-runner.docker.internal` on Docker Desktop or `http://172.17.0.1:12434` on Docker Engine - Raise the context before agent work with `docker model configure --context-size <n> <model>`. The llama.cpp default is 4,096 tokens - Name models with their namespace, such as `ai/smollm2`, and expect plain-text error bodies with a 400, 404, 500 or 503 status ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: Docker Desktop release notes, which may carry Model Runner changes between the tagged releases, so the release count covers GitHub tags only
- unchecked: whether the Docker Engine install publishes port 12434 on loopback only. The server source listens on every interface when
MODEL_RUNNER_PORTis set - unchecked: reply times on issues. We saw comment counts on the issue list, not who replied or when
- unchecked: Docker's SOC 2 or ISO 27001 status, which we didn't look up for this listing
- unchecked: the first release date, and pull counts for the docker/model-runner image
- Docker publishes no terms written for Model Runner itself. The subscription agreement and privacy policy listed are the ones that govern Docker Desktop, and the Engine plugin and
dmrbinary are under Apache-2.0 only - The API reference shows the Anthropic route as /anthropic/v1/messages in its table and /v1/messages in its examples. The source registers both
Sources 22
- overview, requirements, isolation, networking and data collection docs.docker.com · seen 2026-10-08
- API reference docs.docker.com · seen 2026-10-08
- get started docs.docker.com · seen 2026-10-08
- configuration options docs.docker.com · seen 2026-10-08
- llms.txt docs.docker.com · seen 2026-10-08
- repository README, licence and header counts github.com · seen 2026-10-08
- releases github.com · seen 2026-10-08
- open issues github.com · seen 2026-10-08
- CI workflow runs on main github.com · seen 2026-10-08
- security advisories github.com · seen 2026-10-08
- advisory GHSA-m456-c56c-hh5c github.com · seen 2026-10-08
- advisory GHSA-x2f5-332j-9xwq github.com · seen 2026-10-08
- security policy github.com · seen 2026-10-08
- route registrations github.com · seen 2026-10-08
- CORS middleware and default origins github.com · seen 2026-10-08
- model-name tracker github.com · seen 2026-10-08
- server listen code github.com · seen 2026-10-08
- pricing docker.com · seen 2026-10-08
- subscription service agreement docker.com · seen 2026-10-08
- privacy policy docker.com · seen 2026-10-08
- security.txt docker.com · seen 2026-10-08
- RDAP for docker.com rdap.verisign.com · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Free Free · OSS Free under Apache-2.0, with no account needed for the Docker Engine plugin or the standalone `dmr` binary. On macOS and Windows it also ships inside Docker Desktop, which is free for personal use, non-commercial open-source projects and businesses with fewer than 250 employees and under US $10,000,000 in annual revenue. Larger organisations need a paid Docker plan for Desktop (https://www.docker.com/legal/docker-subscription-service-agreement/; https://www.docker.com/pricing/, checked 2026-10-08).
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/docker-model-runner.xml, or this listing's score history at history.json.
Connect
Install
sudo apt-get update && sudo apt-get install docker-model-plugin # Docker Engine on Ubuntu or Debian; Docker Desktop: docker desktop enable model-runner --tcp 12434
docker model pull ai/smollm2
First request
curl http://localhost:12434/engines/v1/chat/completions \
-H "Content-Type: application/json" \
-d '{
"model": "ai/smollm2",
"messages": [{"role": "user", "content": "Say hello in one sentence."}]
}'
Claude Code
docker model launch claude
Through letme picks today, calling later
GET https://letme.dev/docker-model-runner
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
LocalAI Bllama.cpp COllama CLM Studio CGPT4All FGroqCloud BB
Head to head AnythingLLM vs Docker Model Runner · Docker Model Runner vs Core · Docker Model Runner vs GPT4All · Docker Model Runner vs Jan · Docker Model Runner vs Khoj · Docker Model Runner vs llama.cpp · Docker Model Runner vs LM Studio · Docker Model Runner vs LocalAI · Docker Model Runner vs Ollama · Docker Model Runner vs Open WebUI · Docker Model Runner vs screenpipe · Docker Model Runner vs Underdog
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| LocalAI Ettore Di Giacinto and the LocalAI team | B | 68 | inference.local inference.open-weights embed.text rerank image.generate | no |
| llama.cpp ggml.ai (Hugging Face) | C | 60.2 | inference.local inference.open-weights embed.text rerank | no |
| Ollama Ollama Inc. | C | 56.3 | inference.local inference.open-weights inference.llm embed.text | no |
| LM Studio Element Labs, Inc. | C | 57.8 | inference.local inference.open-weights embed.text | no |
| GPT4All Nomic, Inc. | F | 36.2 | inference.local inference.open-weights embed.text | no |
| GroqCloud Groq | BB | 75.6 | inference.llm inference.open-weights | no |
Machine-readable
- JSON
/api/v1/tools/docker-model-runner.json· historyhistory.json· badge/badges/docker-model-runner.svg· changes feed/feeds/tools/docker-model-runner.xml - Markdown
/tools/docker-model-runner.md· slim/tools/docker-model-runner.min.md(or sendAccept: text/markdown) - Fix list
/fixes/docker-model-runner.md·/fixes/docker-model-runner.json - From a terminal
anchor tool docker-model-runner --md(the CLI) · over MCPget_tool {"slug": "docker-model-runner"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/docker-model-runner"><img src="https://www.anchorterminal.com/badges/docker-model-runner.svg" alt="Docker Model Runner on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/docker-model-runner)<a href="https://www.anchorterminal.com/tools/docker-model-runner">Docker Model Runner on Anchor Terminal</a>It counts on a page on docker.com or one of its subdomains, or the README of github.com/docker/model-runner.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "docker-model-runner", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


