# Docker Model Runner (slim) > Docker's open-source tool for pulling and running open models from Docker Hub, OCI registries or Hugging Face. It runs through Docker Desktop, Docker Engine or a standalone dmr binary, with local OpenAI-, Anthropic- and Ollama-compatible APIs. - Full: https://www.anchorterminal.com/tools/docker-model-runner.md (~8,450 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/docker-model-runner.json · canonical https://www.anchorterminal.com/tools/docker-model-runner - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 57.1/100 · rank #483 of 722 · #5 in Local AI · not agent-ready · confidence medium** Assessment: CI passes on the main branch, and Docker has published two security advisories with CVEs and fixed versions for the project. The API takes no credential, so any client or container that reaches it can pull, delete and run models, and the documentation has no OpenAPI file or error reference. ## Facts - Kind: HTTP API · vendor: Docker, Inc. · category: Local AI · legal entity: Docker, Inc. · provenance 84/100 - Local only (HTTP): oci `docker.io/docker/model-runner` - Auth: None · pricing: Free · x402: no · licence: Apache-2.0 (server, CLI plugin and `dmr` binary). Docker Desktop, which bundles it, is closed software under Docker's subscription agreement, and each model carries its own licence - Probe metrics: not measured yet (probes haven't run) - Interfaces: `docker model` CLI plugin (39 documented commands and subcommands), Docker Desktop Models tab, standalone `dmr` binary, local HTTP API on port 12434 or a Unix socket, Docker Compose `models` element - Routes: OpenAI-compatible /engines/v1 (chat completions, completions, embeddings, models), Anthropic-compatible /anthropic/v1/messages and count_tokens, Ollama-compatible /api (tags, show, chat, generate), image generation at /engines/diffusers/v1/images/generations, and native /models for pull, list, inspect and delete. The source also registers a Responses API, rerank and score routes. No OpenAPI file - Credentials: None. Host-side TCP off by default in Docker Desktop, on by default in Docker Engine. Cross-origin requests allowed from localhost, 127.0.0.1 and 0.0.0.0, widened with `DMR_ORIGINS` - Engines: llama.cpp for GGUF models on every platform (default), vLLM for Safetensors on Linux x86_64 and Windows with WSL2 with an NVIDIA GPU, Diffusers for image generation on Linux with an NVIDIA GPU - Hardware: macOS on Apple Silicon. Windows amd64 with NVIDIA drivers 576.57 or later, Windows arm64 with a Qualcomm Adreno 6xx or later GPU. Linux with CPU, NVIDIA CUDA (driver 575.57.08 or later), AMD ROCm or Vulkan - Models: Pulled as OCI artefacts from Docker Hub (the `ai/` namespace) or any OCI registry, or from Hugging Face with `hf.co/` names. `docker model package` and `push` publish GGUF and Safetensors files - Defaults: llama.cpp context of 4,096 tokens. Models load on first request and unload when idle. Requests above 10 MiB are refused - Isolation: Engines run in a container on Linux and in a sandbox on macOS (seatbelt) and Windows (Job Objects). Runtime flags are checked against an allowlist - What leaves the machine: Prompts and responses don't, per the docs. A HEAD request to the registry carries the model name and user agent, off with Docker Desktop's usage statistics setting or `DO_NOT_TRACK=1` in the source - Observability: `docker model logs`, `docker model requests` (the last 10 requests per model in the source) and a Prometheus `/metrics` route, off with `DISABLE_METRICS=1` - Releases in 90 days: 2 (v1.2.7 on 11 August and v1.2.8 on 12 August 2026) - Security record: CVE-2026-28400 (7.5, fixed in 1.0.16) and CVE-2026-33990 (7.1, fixed in 1.1.25), both published as GitHub advisories - Scores: Reliability 85, Performance pending, Schema & documentation 49, Agent ergonomics 58, Security & auth 40, Payments & pricing 60, Task success pending, Maintenance & community 55, Transparency & trust 73 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Read with the local-software lines, since the API runs on the owner's machine. · Schema & documentation, Read for an API. · Agent ergonomics, Read for an API. · Security & auth, Read with the tool checklist, for the local API. · Payments & pricing, Read with the self-hosted rule, since the API an agent calls is free software on the owner's machine. · Maintenance & community, v1.2.8 was released on 12 August 2026, 57 days before the check (20 of 30). · Transparency & trust, The editorial half. - Sources: 22, open questions: 7, both in the full twin - Capabilities: inference.local, inference.open-weights, inference.llm, embed.text, rerank, image.generate - JSON: https://www.anchorterminal.com/api/v1/tools/docker-model-runner.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/docker-model-runner.svg` or a link to https://www.anchorterminal.com/tools/docker-model-runner from a page on docker.com or one of its subdomains, or the README of github.com/docker/model-runner, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Use base URL `http://localhost:12434/engines/v1` for OpenAI clients and `http://localhost:12434` for Anthropic and Ollama clients. Any API key value is accepted 2. In Docker Desktop, run `docker desktop enable model-runner --tcp 12434` first. Host-side TCP is off by default 3. From a container, call `http://model-runner.docker.internal` on Docker Desktop or `http://172.17.0.1:12434` on Docker Engine 4. Raise the context before agent work with `docker model configure --context-size `. The llama.cpp default is 4,096 tokens 5. Name models with their namespace, such as `ai/smollm2`, and expect plain-text error bodies with a 400, 404, 500 or 503 status ## Connect ```bash sudo apt-get update && sudo apt-get install docker-model-plugin # Docker Engine on Ubuntu or Debian; Docker Desktop: docker desktop enable model-runner --tcp 12434 docker model pull ai/smollm2 ``` ```bash curl http://localhost:12434/engines/v1/chat/completions \ -H "Content-Type: application/json" \ -d '{ "model": "ai/smollm2", "messages": [{"role": "user", "content": "Say hello in one sentence."}] }' ``` ```bash docker model launch claude ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/docker-model-runner ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | LocalAI | B | 68 | inference.local, inference.open-weights, embed.text, rerank, image.generate | https://www.anchorterminal.com/tools/localai.min.md | | llama.cpp | C | 60.2 | inference.local, inference.open-weights, embed.text, rerank | https://www.anchorterminal.com/tools/llama-cpp.min.md | | Ollama | C | 56.3 | inference.local, inference.open-weights, inference.llm, embed.text | https://www.anchorterminal.com/tools/ollama.min.md | | LM Studio | C | 57.8 | inference.local, inference.open-weights, embed.text | https://www.anchorterminal.com/tools/lm-studio.min.md | | GPT4All | F | 36.2 | inference.local, inference.open-weights, embed.text | https://www.anchorterminal.com/tools/gpt4all.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)