# Docker Model Runner > Docker's open-source tool for pulling and running open models from Docker Hub, OCI registries or Hugging Face. It runs through Docker Desktop, Docker Engine or a standalone dmr binary, with local OpenAI-, Anthropic- and Ollama-compatible APIs. - Canonical: https://www.anchorterminal.com/tools/docker-model-runner - Markdown: https://www.anchorterminal.com/tools/docker-model-runner.md (~8,450 tokens) - Slim: https://www.anchorterminal.com/tools/docker-model-runner.min.md (~1,830 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/docker-model-runner.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade C · 57.1/100 · rank #483 of 722 · #5 in Local AI · not agent-ready · confidence medium** More from Docker, Inc., listed separately because each is its own product: [Docker Agent](https://www.anchorterminal.com/tools/docker-agent.md) (Agent frameworks & SDKs). ## Assessment CI passes on the main branch, and Docker has published two security advisories with CVEs and fixed versions for the project. The API takes no credential, so any client or container that reaches it can pull, delete and run models, and the documentation has no OpenAPI file or error reference. ## Facts | Field | Value | | --- | --- | | Vendor | Docker, Inc. (https://www.docker.com) | | Kind | HTTP API | | Category | Local AI (https://www.anchorterminal.com/categories/local-ai) | | Transport | HTTP | | Auth | None · The API takes no credential, and the docs say it ignores any key sent. Per the docs, any client that can reach it, including other containers on the same Docker network, can pull, load and run models. In Docker Desktop, host-side TCP is off until enabled in settings or with `docker desktop enable model-runner --tcp `, and containers reach the API at model-runner.docker.internal. In Docker Engine, TCP is on by default on port 12434. Cross-origin requests get 403 unless the origin is localhost, 127.0.0.1, 0.0.0.0 or listed in `DMR_ORIGINS` (https://docs.docker.com/ai/model-runner/; https://github.com/docker/model-runner/blob/main/pkg/envconfig/envconfig.go). | | Pricing | Free (Free · OSS) · Free under Apache-2.0, with no account needed for the Docker Engine plugin or the standalone `dmr` binary. On macOS and Windows it also ships inside Docker Desktop, which is free for personal use, non-commercial open-source projects and businesses with fewer than 250 employees and under US $10,000,000 in annual revenue. Larger organisations need a paid Docker plan for Desktop (https://www.docker.com/legal/docker-subscription-service-agreement/; https://www.docker.com/pricing/, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the docs or the source (checked 2026-10-08). | | Licence | Apache-2.0 (server, CLI plugin and `dmr` binary). Docker Desktop, which bundles it, is closed software under Docker's subscription agreement, and each model carries its own licence | | Packages | oci: `docker.io/docker/model-runner` | | Source | https://github.com/docker/model-runner | | Docs | https://docs.docker.com/ai/model-runner/ | | llms.txt | https://docs.docker.com/llms.txt | | Last release | 2026-08-12 | | GitHub stars | 656 (as of 2026-10-08) | | Interfaces | `docker model` CLI plugin (39 documented commands and subcommands), Docker Desktop Models tab, standalone `dmr` binary, local HTTP API on port 12434 or a Unix socket, Docker Compose `models` element | | Routes | OpenAI-compatible /engines/v1 (chat completions, completions, embeddings, models), Anthropic-compatible /anthropic/v1/messages and count_tokens, Ollama-compatible /api (tags, show, chat, generate), image generation at /engines/diffusers/v1/images/generations, and native /models for pull, list, inspect and delete. The source also registers a Responses API, rerank and score routes. No OpenAPI file | | Credentials | None. Host-side TCP off by default in Docker Desktop, on by default in Docker Engine. Cross-origin requests allowed from localhost, 127.0.0.1 and 0.0.0.0, widened with `DMR_ORIGINS` | | Engines | llama.cpp for GGUF models on every platform (default), vLLM for Safetensors on Linux x86_64 and Windows with WSL2 with an NVIDIA GPU, Diffusers for image generation on Linux with an NVIDIA GPU | | Hardware | macOS on Apple Silicon. Windows amd64 with NVIDIA drivers 576.57 or later, Windows arm64 with a Qualcomm Adreno 6xx or later GPU. Linux with CPU, NVIDIA CUDA (driver 575.57.08 or later), AMD ROCm or Vulkan | | Models | Pulled as OCI artefacts from Docker Hub (the `ai/` namespace) or any OCI registry, or from Hugging Face with `hf.co/` names. `docker model package` and `push` publish GGUF and Safetensors files | | Defaults | llama.cpp context of 4,096 tokens. Models load on first request and unload when idle. Requests above 10 MiB are refused | | Isolation | Engines run in a container on Linux and in a sandbox on macOS (seatbelt) and Windows (Job Objects). Runtime flags are checked against an allowlist | | What leaves the machine | Prompts and responses don't, per the docs. A HEAD request to the registry carries the model name and user agent, off with Docker Desktop's usage statistics setting or `DO_NOT_TRACK=1` in the source | | Observability | `docker model logs`, `docker model requests` (the last 10 requests per model in the source) and a Prometheus `/metrics` route, off with `DISABLE_METRICS=1` | | Releases in 90 days | 2 (v1.2.7 on 11 August and v1.2.8 on 12 August 2026) | | Security record | CVE-2026-28400 (7.5, fixed in 1.0.16) and CVE-2026-33990 (7.1, fixed in 1.1.25), both published as GitHub advisories | | Capabilities | inference.local, inference.open-weights, inference.llm, embed.text, rerank, image.generate | | Tags | open-source, local, self-hosted, free, no-card, openai-compatible, llms-txt, docker, go, no-auth | | JSON | https://www.anchorterminal.com/api/v1/tools/docker-model-runner.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 85 | 17.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 49 | 8.0 | | Agent ergonomics | 13% | 16.2 | 58 | 9.4 | | Security & auth | 14% | 17.5 | 40 | 7.0 | | Payments & pricing | 10% | 12.5 | 60 | 7.5 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 55 | 4.8 | | Transparency & trust (editorial 62, provenance 84) | 7% | 8.8 | 73 | 6.4 | | Negative events | up to −15 | up to −15 | 2026-02-27. GHSA-m456-c56c-hh5c (CVE-2026-28400, 7.5). The unauthenticated `/engines/_configure` route accepted arbitrary runtime flags, so a caller, including a container on Docker Desktop, could overwrite files the runner could reach, the Desktop VM disk among them. Fixed in Model Runner 1.0.16 and Docker Desktop 4.61.0 and published by Docker, more than six months ago, -2. https://github.com/docker/model-runner/security/advisories/GHSA-m456-c56c-hh5c 2026-03-30. GHSA-x2f5-332j-9xwq (CVE-2026-33990, 7.1). A malicious OCI registry could point the token exchange at an internal URL and make the runner send GET requests to host-local services. Fixed in 1.1.25 and Docker Desktop 4.67.0 and published by Docker, more than six months ago, -1. https://github.com/docker/model-runner/security/advisories/GHSA-x2f5-332j-9xwq | -3 | | **Total** | | | | **57.1 → C** | ### Why each score - Reliability 85: Read with the local-software lines, since the API runs on the owner's machine. Bundled with Docker Desktop, installed as `docker-model-plugin` from Docker's apt and dnf repositories, and shipped as a standalone `dmr` binary through Homebrew and winget, with platform, GPU and driver requirements stated in the docs (20). The CI workflow runs lint, race-detector tests and builds on pushes and pull requests to main, with separate end-to-end, integration and daily check workflows, and the ten most recent CI runs on main passed on 8 October 2026 (25). 41 open issues and 25 open pull requests. Each of the 20 newest open issues had at least one comment, but several are regressions or failures still open, including HTTP 500 on sequential tool calls (#1063), a Windows GPU regression after Docker Desktop 4.82.0 (#1054) and a context-size setting applied nondeterministically (#1025) (17 of 25). Semver tags with notes on each GitHub release, but no changelog file and no breaking-change section in the notes we read (8 of 15). Version 1.2.8 (15). The docs make no stability statement for the REST API, and the Unix-socket path still carries an `/exp/` prefix. - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 49: Read for an API. No OpenAPI or similar file was found in the repository or the docs. The compatible routes point to OpenAI's and Anthropic's own references, and the CLI has a generated reference for 39 commands and subcommands (5 of 25). docs.docker.com has llms.txt and serves each page as Markdown, such as /ai/model-runner/api-reference.md (10). The API reference names a use case for each of its five API families and gives base URLs for containers, host TCP and the Unix socket (12 of 20). Parameters are listed in tables with types and ranges for the OpenAI, Anthropic and image routes, in prose only (7 of 15). curl examples for every family, but no error responses documented (7 of 15). Dated GitHub releases with notes. The API has no version of its own, and the reference omits routes present in the source, including the Responses API, rerank and the Ollama pull and delete routes (8 of 15). - Agent ergonomics 58: Read for an API. Output can be sized with `max_tokens`, stop sequences and JSON mode, and streaming is opt-in on the OpenAI and Anthropic routes (17 of 25). Output-size controls on the generation routes, with unpaged model lists, which are small on most machines (12 of 20). Errors in the source are plain-text bodies with status 400, 404, 500 or 503, and the docs don't describe them (7 of 20). Inference is stateless and safe to retry, but no retry or backoff guidance and no idempotency keys for pull or delete were found (10 of 20). `model` is the only required field beyond the messages or prompt. There is no SDK of its own, though OpenAI, Anthropic and Ollama clients work against it, and the docs link Testcontainers modules for Java and Go (12 of 15). - Security & auth 40: Read with the tool checklist, for the local API. No credential, by design. The docs say the API is not authenticated and that any client that can reach it, including other containers on the same Docker network, can pull, load and run models. Host-side TCP is off by default in Docker Desktop and on by default on port 12434 in Docker Engine, and cross-origin requests are refused with 403 unless the origin is localhost, 127.0.0.1, 0.0.0.0 or listed in `DMR_ORIGINS` (7 of 30). No read-only mode or per-caller limit. Runtime flags pass an allowlist, engines run sandboxed on macOS and Windows and in a container on Linux, and Enhanced Container Isolation, a Docker Business control, blocks container access (6 of 20). The API returns model output, with no injection guidance in the docs (6 of 15). `docker model requests` and the Requests tab show recent requests and responses, the source keeps the last 10 per model, and `/metrics` exposes Prometheus counters. No caller identity (8 of 15). www.docker.com has a valid security.txt with a disclosure policy, SECURITY.md promises an acknowledgement within 72 hours, and two advisories were published with CVEs in 2026. No monetary bounty for this project (13 of 20). - Payments & pricing 60: Read with the self-hosted rule, since the API an agent calls is free software on the owner's machine. No x402, MPP or L402 in the docs or the source (0). Model Runner is Apache-2.0 with nothing to buy and no account needed for the Docker Engine plugin or the `dmr` binary, so 20, 20 and 20 on the last three lines. One qualification applies to the Docker Desktop route. Docker's subscription agreement limits free Desktop use to non-commercial open-source projects and businesses with fewer than 250 employees and under US $10,000,000 in annual revenue, and paid plans run from $11 to $24 per user a month. - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 55: v1.2.8 was released on 12 August 2026, 57 days before the check (20 of 30). Two releases in the 90 days to 8 October 2026, v1.2.7 on 11 August and v1.2.8, against 30 or so between March and June (0 of 20). 45 commits on main since 10 July, the newest on 8 October, and each of the 20 newest open issues had at least one comment, with 41 issues and 25 pull requests open (17 of 25). No SDK of its own. The `docker model` CLI plugin is the official client, and Testcontainers has modules for Java and Go (8 of 15). Dependabot runs weekly on Go modules and GitHub Actions, actions are pinned by commit, a script bumps llama.cpp, and CI passes on main (10). - Transparency & trust 73: The editorial half. Apache-2.0 for the server, the CLI and the `dmr` binary in a public repository. Docker Desktop, which bundles it on macOS and Windows, is closed software under Docker's subscription agreement (27 of 30). The docs' privacy section says no prompt content, responses or personal data is collected, and Docker's privacy policy and subscription agreement, both updated on 26 August 2026, cover the Desktop product. No retention period specific to Model Runner was found (18 of 30). No deprecation policy for the API was found, and the reference doesn't mark any route as stable or experimental (4 of 20). Telemetry is disclosed with a link to the source. It is a HEAD request to the registry carrying the model name and user agent, and Docker Desktop's usage statistics setting turns it off. For Docker Engine the docs say the requests are made regardless of settings, while the source skips them when `DO_NOT_TRACK=1`, which the docs don't mention (13 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/docker-model-runner.md (JSON https://www.anchorterminal.com/fixes/docker-model-runner.json) ### What we couldn't check - unchecked: Docker Desktop release notes, which may carry Model Runner changes between the tagged releases, so the release count covers GitHub tags only - unchecked: whether the Docker Engine install publishes port 12434 on loopback only. The server source listens on every interface when `MODEL_RUNNER_PORT` is set - unchecked: reply times on issues. We saw comment counts on the issue list, not who replied or when - unchecked: Docker's SOC 2 or ISO 27001 status, which we didn't look up for this listing - unchecked: the first release date, and pull counts for the docker/model-runner image - Docker publishes no terms written for Model Runner itself. The subscription agreement and privacy policy listed are the ones that govern Docker Desktop, and the Engine plugin and `dmr` binary are under Apache-2.0 only - The API reference shows the Anthropic route as /anthropic/v1/messages in its table and /v1/messages in its examples. The source registers both ### Sources - overview, requirements, isolation, networking and data collection: (seen 2026-10-08) - API reference: (seen 2026-10-08) - get started: (seen 2026-10-08) - configuration options: (seen 2026-10-08) - llms.txt: (seen 2026-10-08) - repository README, licence and header counts: (seen 2026-10-08) - releases: (seen 2026-10-08) - open issues: (seen 2026-10-08) - CI workflow runs on main: (seen 2026-10-08) - security advisories: (seen 2026-10-08) - advisory GHSA-m456-c56c-hh5c: (seen 2026-10-08) - advisory GHSA-x2f5-332j-9xwq: (seen 2026-10-08) - security policy: (seen 2026-10-08) - route registrations: (seen 2026-10-08) - CORS middleware and default origins: (seen 2026-10-08) - model-name tracker: (seen 2026-10-08) - server listen code: (seen 2026-10-08) - pricing: (seen 2026-10-08) - subscription service agreement: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - RDAP for docker.com: (seen 2026-10-08) ## Who's behind it (provenance 84/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Docker, Inc. | 20/20 | | Domain age | docker.com, registered 1995-01-25 (31 years) | 15/15 | | Endpoint on the vendor's domain | no hosted endpoint | n/a | | Terms of service | read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points | 6/10 | | Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 | | Status page | not found | 0/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The repository is under GitHub's docker organisation and SECURITY.md sends reports to security@docker.com. The subscription agreement and privacy policy both name Docker, Inc. Docker publishes no terms written for Model Runner. The Docker Subscription Service Agreement (last updated 26 August 2026) governs Docker Desktop, which bundles it, and the privacy policy carries the same date. The Engine plugin and the `dmr` binary are under Apache-2.0 only. www.docker.com/.well-known/security.txt gives security@docker.com, a policy URL and an expiry of 1 January 2030. No status page is listed because the software runs on the owner's machine. RDAP for docker.com gives a registration date of 1995-01-25. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.docker.com/legal/docker-subscription-service-agreement/), read 2026-10-08, dated 2026-08-26, states 7 of the 7 things a reader expects. - To know. Restricts automated access (costs points). "Use any robot, spider, site search/retrieval application, or other device to retrieve or index any portion of the Services or the content posted thereon or to collect information about its users for any unauthorized purpose;" - To know. Restricts benchmarking or competitive use (costs points). "access the Services for the purpose of developing or operating products or services intended to be offered to third parties in competition with the Services or exploit the Services for any unauthorized commercial purpose" - To know. Says access can be ended without notice or for any reason. "Users with an account that is inactive for more than six (6) months may be terminated at Docker’s discretion and without further notice." - To know. Requires arbitration or waives class actions. "Any dispute, controversy or claim arising under, out of or relating to this Agreement, will be finally determined by arbitration conducted by JAMS" - Gives the date it was last updated. Last updated 2026-08-26. - Names the governing law or courts. The law of the State of California. - States a limit on its liability. Capped at $100. - Says how changes to the terms are announced. Says it gives notice of a change. - Also in the text (2026-10-08). Docker accepts no liability for the customer's use of Output or for any autonomous or semi-autonomous action taken by an AI Feature. "NOTWITHSTANDING ANYTHING TO THE CONTRARY IN THIS AGREEMENT, DOCKER WILL HAVE NO LIABILITY OR RESPONSIBILITY FOR CUSTOMER’S OR ITS USERS’ USE OF OUTPUT OR ANY AUTONOMOUS OR SEMI-AUTONOMOUS ACTION." - Also in the text (2026-10-08). The customer indemnifies Docker against third-party claims arising from any action, Output, omission or decision of an AI Agent or AI Feature working on its behalf. "any claim by a third party arising from or relating to any action, Output, omission, or decision by an AI Agent or AI Feature operating on behalf of, or initiated by, Customer or its Users" - Also in the text (2026-10-08). The initial term renews automatically for 12-month periods unless a party gives at least 30 days' written notice before the current term ends. "The Initial Term will automatically renew for additional 12-month periods unless a party provides at least 30 days’ written notice prior to the end of the then-current term that such party does not wish to renew for the upcoming term" **Privacy policy** (https://www.docker.com/legal/privacy/), read 2026-10-08, dated 2026-08-26, states 8 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2026-08-26. - Says how long data is kept. Names a period of 7 days. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Gives a privacy contact. privacy@docker.com. - Says where data is transferred or stored. Relies on the Data Privacy Framework. - Also in the text (2026-10-08). A saved sandbox image or snapshot may contain the prompts and responses from the session. "If you save a sandbox image or snapshot, it may contain prompts and responses from your session." - Also in the text (2026-10-08). Docker stores the API keys and access tokens for third-party AI model providers and MCP-connected tools that a user chooses to store. "API keys and access tokens for third-party AI model providers and MCP-connected tools, which we store securely on your behalf in order to provide the Services" - Also in the text (2026-10-08). Docker gives its customers information on how particular domains access and use the Website, Services and particular functions or uploads. "Docker also provides information on how particular domains (e.g., www.companyx.com ) access and use our Website, Services, and particular features or uploads to customers for their business purposes, for example, so they can improve or target their software and other offerings." ## Live (updated 2026-10-08 18:27 UTC) - Watching pricing - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/docker-model-runner.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - OpenAI-, Anthropic- and Ollama-compatible routes on one local port, so existing clients for those three APIs work with a changed base URL - CI runs lint, race-detector tests and end-to-end tests on every push to main, and the ten most recent runs on main passed on 8 October 2026 - Two GitHub security advisories with CVE numbers, fixed versions and workarounds, and a SECURITY.md that promises an acknowledgement within 72 hours - Apache-2.0 source, and the docs list what usage data is collected with a link to the code that sends it - Host-side TCP is off by default in Docker Desktop, and inference engines run sandboxed on macOS and Windows or in a container on Linux ## Weaknesses - No credential on the API. The docs say any client that can reach it, including other containers, can pull, load and run models - No OpenAPI file, no error reference and no rate-limit or retry guidance in the reviewed documentation - Two releases in the 90 days to 8 October 2026 (v1.2.7 and v1.2.8), the latest on 12 August - CVE-2026-28400 let an unauthenticated caller overwrite files, including the Docker Desktop VM disk, until 1.0.16 in February 2026 - On Docker Engine the docs say model-name requests go to Docker Hub regardless of settings, and the `DO_NOT_TRACK` switch in the source is undocumented ## Before you call it (notes for agents) 1. Use base URL `http://localhost:12434/engines/v1` for OpenAI clients and `http://localhost:12434` for Anthropic and Ollama clients. Any API key value is accepted 2. In Docker Desktop, run `docker desktop enable model-runner --tcp 12434` first. Host-side TCP is off by default 3. From a container, call `http://model-runner.docker.internal` on Docker Desktop or `http://172.17.0.1:12434` on Docker Engine 4. Raise the context before agent work with `docker model configure --context-size `. The llama.cpp default is 4,096 tokens 5. Name models with their namespace, such as `ai/smollm2`, and expect plain-text error bodies with a 400, 404, 500 or 503 status ## Connect Install: ```bash sudo apt-get update && sudo apt-get install docker-model-plugin # Docker Engine on Ubuntu or Debian; Docker Desktop: docker desktop enable model-runner --tcp 12434 docker model pull ai/smollm2 ``` First request: ```bash curl http://localhost:12434/engines/v1/chat/completions \ -H "Content-Type: application/json" \ -d '{ "model": "ai/smollm2", "messages": [{"role": "user", "content": "Say hello in one sentence."}] }' ``` Claude Code: ```bash docker model launch claude ``` Through letme (picks today, calling later): https://letme.dev/docker-model-runner. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | LocalAI | B | 68 | 193 | inference.local, inference.open-weights, embed.text, rerank, image.generate | no | https://www.anchorterminal.com/tools/localai.md | | llama.cpp | C | 60.2 | 410 | inference.local, inference.open-weights, embed.text, rerank | no | https://www.anchorterminal.com/tools/llama-cpp.md | | Ollama | C | 56.3 | 491 | inference.local, inference.open-weights, inference.llm, embed.text | no | https://www.anchorterminal.com/tools/ollama.md | | LM Studio | C | 57.8 | 463 | inference.local, inference.open-weights, embed.text | no | https://www.anchorterminal.com/tools/lm-studio.md | | GPT4All | F | 36.2 | 706 | inference.local, inference.open-weights, embed.text | no | https://www.anchorterminal.com/tools/gpt4all.md | | GroqCloud | BB | 75.6 | 39 | inference.llm, inference.open-weights | no | https://www.anchorterminal.com/tools/groq.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The docs state that the API is not authenticated and that any client that can reach it, including other containers on the same Docker network, can pull, load and run models (source: ) - CVE-2026-28400 (7.5), published on 27 February 2026. The unauthenticated `/engines/_configure` route accepted arbitrary runtime flags and could overwrite files, fixed in 1.0.16 and Docker Desktop 4.61.0 (source: ) - CVE-2026-33990 (7.1), published on 30 March 2026. A malicious OCI registry could make the runner send GET requests to host-local services, fixed in 1.1.25 and Docker Desktop 4.67.0 (source: ) - Usage tracking is a HEAD request to the registry with the model name and user agent. Docker Desktop's usage statistics setting turns it off, and the docs say Docker Engine sends it regardless of settings (source: , ) - The llama.cpp engine defaults to a 4,096-token context, changed per model with `docker model configure --context-size` (source: ) - A standalone `dmr` binary (dmr 0.1.0, 7 July 2026) runs the daemon and CLI without Docker Desktop or Docker Engine, on TCP port 12434 by default (source: ) - `docker model launch` starts AnythingLLM, Claude Code, Codex, OpenClaw, OpenCode or Open WebUI configured to use the local runner (source: ) ## Compare - [AnythingLLM vs Docker Model Runner](https://www.anchorterminal.com/compare/anythingllm-vs-docker-model-runner.md): D 53.3 vs C 57.1 - [Docker Model Runner vs Core](https://www.anchorterminal.com/compare/docker-model-runner-vs-ghost-core.md): C 57.1 vs F 7.3 - [Docker Model Runner vs GPT4All](https://www.anchorterminal.com/compare/docker-model-runner-vs-gpt4all.md): C 57.1 vs F 36.2 - [Docker Model Runner vs Jan](https://www.anchorterminal.com/compare/docker-model-runner-vs-jan.md): C 57.1 vs D 51.3 - [Docker Model Runner vs Khoj](https://www.anchorterminal.com/compare/docker-model-runner-vs-khoj.md): C 57.1 vs E 38.5 - [Docker Model Runner vs llama.cpp](https://www.anchorterminal.com/compare/docker-model-runner-vs-llama-cpp.md): C 57.1 vs C 60.2 - [Docker Model Runner vs LM Studio](https://www.anchorterminal.com/compare/docker-model-runner-vs-lm-studio.md): C 57.1 vs C 57.8 - [Docker Model Runner vs LocalAI](https://www.anchorterminal.com/compare/docker-model-runner-vs-localai.md): C 57.1 vs B 68 - [Docker Model Runner vs Ollama](https://www.anchorterminal.com/compare/docker-model-runner-vs-ollama.md): C 57.1 vs C 56.3 - [Docker Model Runner vs Open WebUI](https://www.anchorterminal.com/compare/docker-model-runner-vs-open-webui.md): C 57.1 vs D 51.8 - [Docker Model Runner vs screenpipe](https://www.anchorterminal.com/compare/docker-model-runner-vs-screenpipe.md): C 57.1 vs C 60.8 - [Docker Model Runner vs Underdog](https://www.anchorterminal.com/compare/docker-model-runner-vs-underdog.md): C 57.1 vs F 29.5 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on docker.com or one of its subdomains, or the README of github.com/docker/model-runner. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "docker-model-runner", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Docker Model Runner on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Docker Model Runner on Anchor Terminal](https://www.anchorterminal.com/badges/docker-model-runner.svg)](https://www.anchorterminal.com/tools/docker-model-runner) ``` Plain link: ```html Docker Model Runner on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Docker Model Runner is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/docker-model-runner-dark.png - Light: https://www.anchorterminal.com/assets/share/docker-model-runner-light.png