{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/localai.json",
        "name": "LocalAI",
        "score": 68,
        "shared": [
          "inference.local",
          "inference.open-weights",
          "embed.text",
          "speech.stt"
        ],
        "slug": "localai"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/lemonade.json",
        "name": "Lemonade",
        "score": 63.8,
        "shared": [
          "inference.local",
          "inference.open-weights",
          "embed.text",
          "speech.stt"
        ],
        "slug": "lemonade"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/koboldcpp.json",
        "name": "KoboldCpp",
        "score": 60.5,
        "shared": [
          "inference.local",
          "inference.open-weights",
          "embed.text",
          "speech.stt"
        ],
        "slug": "koboldcpp"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/deepinfra.json",
        "name": "DeepInfra",
        "score": 63,
        "shared": [
          "inference.open-weights",
          "embed.text",
          "speech.stt"
        ],
        "slug": "deepinfra"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/llama-cpp.json",
        "name": "llama.cpp",
        "score": 60.2,
        "shared": [
          "inference.local",
          "inference.open-weights",
          "embed.text"
        ],
        "slug": "llama-cpp"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/lm-studio.json",
        "name": "LM Studio",
        "score": 57.8,
        "shared": [
          "inference.local",
          "inference.open-weights",
          "embed.text"
        ],
        "slug": "lm-studio"
      }
    ],
    "tool": {
      "slug": "foundry-local",
      "name": "Foundry Local",
      "vendor": "Microsoft",
      "vendorUrl": "https://www.foundrylocal.ai",
      "kind": "sdk",
      "category": "local-ai",
      "summary": "Microsoft's on-device model runtime, built on ONNX Runtime. Applications embed it through SDKs for C#, JavaScript, Python and Rust, and it can start an optional OpenAI-compatible server on localhost. A preview CLI is also available.",
      "url": "https://www.anchorterminal.com/tools/foundry-local",
      "markdownUrl": "https://www.anchorterminal.com/tools/foundry-local.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/foundry-local.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/foundry-local.json",
      "repo": "https://github.com/microsoft/Foundry-Local",
      "license": "MIT for the SDKs and the v2 native runtime. The CLI is closed source under Microsoft Software Licence Terms. Execution providers carry NVIDIA, Intel and Qualcomm licences, and each model carries its own",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "foundry-local-sdk"
        },
        {
          "registry": "pypi",
          "name": "foundry-local-sdk"
        },
        {
          "registry": "nuget",
          "name": "Microsoft.AI.Foundry.Local"
        },
        {
          "registry": "cargo",
          "name": "foundry-local-sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No authentication. The SDK runs in the application's own process, and the optional local server takes no key or token. It binds to 127.0.0.1 on a dynamic port unless the owner configures `web.urls` or starts the CLI daemon with `--port`. No account or Azure subscription is needed.",
      "pricing": "free",
      "pricingNotes": "Free, with no account, card or Azure subscription. The SDK is MIT and the CLI is a free download under Microsoft's licence terms. Microsoft states there are no per-token costs. Foundry Local on Azure Local is a separate product for servers and is not covered here (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the README or the SDK source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 2600,
        "npmWeekly": 105372,
        "pypiWeekly": 47344,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/azure/foundry-local/",
      "capabilities": [
        "inference.local",
        "inference.open-weights",
        "embed.text",
        "speech.stt"
      ],
      "tags": [
        "local",
        "open-source",
        "free",
        "no-card",
        "account-free",
        "no-auth",
        "openai-compatible",
        "csharp",
        "typescript",
        "python",
        "rust",
        "npu",
        "telemetry-on-by-default"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.5,
        "grade": "C",
        "agentReady": false,
        "rank": 461,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 61,
          "maintenance": 88,
          "payments": 60,
          "reliability": 68,
          "schema": 53,
          "security": 39,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 68,
            "points": 13.6,
            "reason": "Read with the local-software lines, since Foundry Local runs in the owner's application or as a local daemon. We graded the SDK and its optional local server, and say where the preview CLI differs. Official packages on npm, PyPI, NuGet and crates.io, the CLI through winget and Homebrew, with Node.js 20, Python 3.11 to 3.14, .NET 8 and Rust 1.70 stated (20). The repository holds test suites for the C++ runtime and each SDK, but the only public GitHub Actions workflow is a build check for samples. Build and test run in Azure Pipelines whose results we couldn't see, and the pipeline file says its push trigger is switched off (12 of 25). 76 open issues against 362 closed. Open reports include a Linux ARM64 segmentation fault (#1182, 8 October), HTTP 500 on Qwen3.5 CUDA models (#1179), memory kept after unload (#1079) and several GPU and NPU detection failures from September with no reply (13 of 25). Versioned releases with notes on GitHub, and v2.0.1 has a breaking-changes section. There is no changelog file, and the CLI's REST reference warns of breaking changes without notice (10 of 15). SDK 2.1.0. The PyPI package still carries an Alpha classifier and the CLI is a public preview (13 of 15)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 53,
            "points": 8.61,
            "reason": "Read with the API lines, for the local server and the SDKs. No OpenAPI file in the repository or the docs. The server follows OpenAI's shapes and the SDKs are typed (8 of 25). Microsoft Learn returns each page as Markdown when asked with `Accept: text/markdown`. No llms.txt on learn.microsoft.com or foundrylocal.ai (6 of 10). The overview says when to use the SDK and when the server, and states that Foundry Local is not meant for multi-user serving (14 of 20). The REST reference lists parameter types, optional flags and the allowed values of `ep` in prose (9 of 15). 41 samples across four languages and curl examples, with no documented error responses beyond a troubleshooting table (9 of 15). Dated release notes on GitHub. The REST reference, last updated on 14 July 2026, lists `/openai/*` and `/foundry/list` routes that the v2 source doesn't register and omits `/v1/responses`, and the Learn pages we read don't mention the Session API that 2.0.1 made the main interface and still give install commands for the `-winml` packages that release removed (7 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 61,
            "points": 9.91,
            "reason": "Read with the API lines. Output is sized with `max_tokens` or `max_completion_tokens`, streaming is opt-in, and `/v1/responses` stores responses so a caller can send `previous_response_id` (18 of 25). `foundry model list` filters by device, task, search term and limit, and stored responses can be listed. Model lists over HTTP aren't paged (12 of 20). Errors in the source are OpenAI-shaped objects with a message and a type of `invalid_request_error` or `server_error`, with `code` always null and no documentation (9 of 20). Inference calls are stateless and safe to repeat. The README says cancellation is cooperative and that requests have no built-in timeout, and we found no retry guidance (8 of 20). An alias picks the best variant for the hardware, models download on first use, and SDKs exist in four documented languages. The server's port is dynamic by default, so a caller has to discover it (14 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 39,
            "points": 6.83,
            "reason": "Read with the tool checklist, for the local server. No credential exists. The server is off until the application or the CLI starts it, binds to 127.0.0.1 by default, and the docs tell clients to set auth to None (8 of 30). No read-only mode. Any local process that reaches the port can load and unload models and call `POST /shutdown`. Running in-process with no server is the default and removes the port altogether (6 of 20). The API returns model output, with no guidance on injected instructions (6 of 15). `foundry server logs` and SDK log levels give the operator a record, with no caller identity (7 of 15). SECURITY.md sends reports to MSRC and promises a reply within 24 hours, GitHub Actions are pinned to commit hashes, and no advisory or CVE was found. The security.txt on www.microsoft.com expired on 23 September 2026, and open issue #1123 says binaries downloaded at runtime rely on transport integrity alone (12 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 60,
            "points": 7.5,
            "reason": "Read with the self-hosted rule, since everything an agent calls runs on the owner's machine. No x402, MPP or L402 (0). The SDK is MIT, the CLI is a free download, and no account, card or Azure subscription is needed, so 20, 20 and 20 on the last three lines."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 88,
            "points": 7.7,
            "reason": "SDK 2.1.0 reached the registries on 29 September 2026 and CLI preview 0.11.0 followed on 7 October (30). Six releases in the 90 days to 8 October (20). 132 commits on main since 10 July, the newest on 7 October, and 362 issues closed against 76 open. Many of the newest open issues had no comment when we read them, and SUPPORT.md is still Microsoft's unedited template (15 of 25). Current SDKs at the same version on npm, PyPI, NuGet and crates.io (15). Dependabot is configured, native dependency versions are pinned in one file that the build validates, and actions are pinned. We couldn't see CI results (8 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 72,
            "points": 6.3,
            "note": "editorial 63, provenance 80",
            "reason": "The editorial half. The SDKs and the v2 native runtime are MIT in a public repository. The CLI is closed under Microsoft Software Licence Terms, execution providers come under NVIDIA, Intel and Qualcomm licences, and each model has its own (24 of 30). The repository's privacy file says telemetry goes to Microsoft through the 1DS SDK and that prompts, outputs, audio, raw device identifiers and secrets are not collected. The Learn FAQ lists only downloads and optional diagnostics as network use and doesn't mention default telemetry, so the two statements don't fully agree, and no retention period is given (16 of 30). The v2.0.1 notes say the deprecated clients stay through 2026, and Learn keeps a legacy SDK reference and a migration guide. There is no written deprecation policy (9 of 20). Telemetry is disclosed in the README and is on by default. A config option or `ORT_TELEMETRY_DISABLED=1` turns off non-essential telemetry, and what counts as essential isn't stated (14 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Read with the API lines. Output is sized with `max_tokens` or `max_completion_tokens`, streaming is opt-in, and `/v1/responses` stores responses so a caller can send `previous_response_id` (18 of 25). `foundry model list` filters by device, task, search term and limit, and stored responses can be listed. Model lists over HTTP aren't paged (12 of 20). Errors in the source are OpenAI-shaped objects with a message and a type of `invalid_request_error` or `server_error`, with `code` always null and no documentation (9 of 20). Inference calls are stateless and safe to repeat. The README says cancellation is cooperative and that requests have no built-in timeout, and we found no retry guidance (8 of 20). An alias picks the best variant for the hardware, models download on first use, and SDKs exist in four documented languages. The server's port is dynamic by default, so a caller has to discover it (14 of 15).",
            "maintenance": "SDK 2.1.0 reached the registries on 29 September 2026 and CLI preview 0.11.0 followed on 7 October (30). Six releases in the 90 days to 8 October (20). 132 commits on main since 10 July, the newest on 7 October, and 362 issues closed against 76 open. Many of the newest open issues had no comment when we read them, and SUPPORT.md is still Microsoft's unedited template (15 of 25). Current SDKs at the same version on npm, PyPI, NuGet and crates.io (15). Dependabot is configured, native dependency versions are pinned in one file that the build validates, and actions are pinned. We couldn't see CI results (8 of 10).",
            "payments": "Read with the self-hosted rule, since everything an agent calls runs on the owner's machine. No x402, MPP or L402 (0). The SDK is MIT, the CLI is a free download, and no account, card or Azure subscription is needed, so 20, 20 and 20 on the last three lines.",
            "reliability": "Read with the local-software lines, since Foundry Local runs in the owner's application or as a local daemon. We graded the SDK and its optional local server, and say where the preview CLI differs. Official packages on npm, PyPI, NuGet and crates.io, the CLI through winget and Homebrew, with Node.js 20, Python 3.11 to 3.14, .NET 8 and Rust 1.70 stated (20). The repository holds test suites for the C++ runtime and each SDK, but the only public GitHub Actions workflow is a build check for samples. Build and test run in Azure Pipelines whose results we couldn't see, and the pipeline file says its push trigger is switched off (12 of 25). 76 open issues against 362 closed. Open reports include a Linux ARM64 segmentation fault (#1182, 8 October), HTTP 500 on Qwen3.5 CUDA models (#1179), memory kept after unload (#1079) and several GPU and NPU detection failures from September with no reply (13 of 25). Versioned releases with notes on GitHub, and v2.0.1 has a breaking-changes section. There is no changelog file, and the CLI's REST reference warns of breaking changes without notice (10 of 15). SDK 2.1.0. The PyPI package still carries an Alpha classifier and the CLI is a public preview (13 of 15).",
            "schema": "Read with the API lines, for the local server and the SDKs. No OpenAPI file in the repository or the docs. The server follows OpenAI's shapes and the SDKs are typed (8 of 25). Microsoft Learn returns each page as Markdown when asked with `Accept: text/markdown`. No llms.txt on learn.microsoft.com or foundrylocal.ai (6 of 10). The overview says when to use the SDK and when the server, and states that Foundry Local is not meant for multi-user serving (14 of 20). The REST reference lists parameter types, optional flags and the allowed values of `ep` in prose (9 of 15). 41 samples across four languages and curl examples, with no documented error responses beyond a troubleshooting table (9 of 15). Dated release notes on GitHub. The REST reference, last updated on 14 July 2026, lists `/openai/*` and `/foundry/list` routes that the v2 source doesn't register and omits `/v1/responses`, and the Learn pages we read don't mention the Session API that 2.0.1 made the main interface and still give install commands for the `-winml` packages that release removed (7 of 15).",
            "security": "Read with the tool checklist, for the local server. No credential exists. The server is off until the application or the CLI starts it, binds to 127.0.0.1 by default, and the docs tell clients to set auth to None (8 of 30). No read-only mode. Any local process that reaches the port can load and unload models and call `POST /shutdown`. Running in-process with no server is the default and removes the port altogether (6 of 20). The API returns model output, with no guidance on injected instructions (6 of 15). `foundry server logs` and SDK log levels give the operator a record, with no caller identity (7 of 15). SECURITY.md sends reports to MSRC and promises a reply within 24 hours, GitHub Actions are pinned to commit hashes, and no advisory or CVE was found. The security.txt on www.microsoft.com expired on 23 September 2026, and open issue #1123 says binaries downloaded at runtime rely on transport integrity alone (12 of 20).",
            "transparency": "The editorial half. The SDKs and the v2 native runtime are MIT in a public repository. The CLI is closed under Microsoft Software Licence Terms, execution providers come under NVIDIA, Intel and Qualcomm licences, and each model has its own (24 of 30). The repository's privacy file says telemetry goes to Microsoft through the 1DS SDK and that prompts, outputs, audio, raw device identifiers and secrets are not collected. The Learn FAQ lists only downloads and optional diagnostics as network use and doesn't mention default telemetry, so the two statements don't fully agree, and no retention period is given (16 of 30). The v2.0.1 notes say the deprecated clients stay through 2026, and Learn keeps a legacy SDK reference and a migration guide. There is no written deprecation policy (9 of 20). Telemetry is disclosed in the README and is on by default. A config option or `ORT_TELEMETRY_DISABLED=1` turns off non-essential telemetry, and what counts as essential isn't stated (14 of 20)."
          },
          "sources": [
            {
              "what": "overview and FAQ",
              "url": "https://learn.microsoft.com/en-us/azure/foundry-local/what-is-foundry-local",
              "seen": "2026-10-08"
            },
            {
              "what": "architecture",
              "url": "https://learn.microsoft.com/en-us/azure/foundry-local/concepts/foundry-local-architecture",
              "seen": "2026-10-08"
            },
            {
              "what": "REST reference (CLI preview)",
              "url": "https://learn.microsoft.com/en-us/azure/foundry-local/reference/reference-rest",
              "seen": "2026-10-08"
            },
            {
              "what": "CLI reference",
              "url": "https://learn.microsoft.com/en-us/azure/foundry-local/reference/reference-cli",
              "seen": "2026-10-08"
            },
            {
              "what": "SDK reference",
              "url": "https://learn.microsoft.com/en-us/azure/foundry-local/reference/reference-sdk-current",
              "seen": "2026-10-08"
            },
            {
              "what": "REST server how-to",
              "url": "https://learn.microsoft.com/en-us/azure/foundry-local/how-to/how-to-integrate-with-inference-sdks",
              "seen": "2026-10-08"
            },
            {
              "what": "best practice and troubleshooting",
              "url": "https://learn.microsoft.com/en-us/azure/foundry-local/reference/reference-best-practice",
              "seen": "2026-10-08"
            },
            {
              "what": "get started",
              "url": "https://learn.microsoft.com/en-us/azure/foundry-local/get-started",
              "seen": "2026-10-08"
            },
            {
              "what": "repository (README, LICENSE, SECURITY.md, SUPPORT.md, workflows, tags), cloned at commit of 7 October 2026",
              "url": "https://github.com/microsoft/Foundry-Local",
              "seen": "2026-10-08"
            },
            {
              "what": "v2 web service source (routes, binding)",
              "url": "https://github.com/microsoft/Foundry-Local/blob/main/sdk_v2/cpp/src/service/web_service.cc",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy file",
              "url": "https://github.com/microsoft/Foundry-Local/blob/main/sdk_v2/cpp/docs/Privacy.md",
              "seen": "2026-10-08"
            },
            {
              "what": "licence file",
              "url": "https://github.com/microsoft/Foundry-Local/blob/main/LICENSE",
              "seen": "2026-10-08"
            },
            {
              "what": "releases",
              "url": "https://github.com/microsoft/Foundry-Local/releases",
              "seen": "2026-10-08"
            },
            {
              "what": "v2.0.1 release notes",
              "url": "https://github.com/microsoft/Foundry-Local/releases/tag/v2.0.1",
              "seen": "2026-10-08"
            },
            {
              "what": "v2.1.0 release notes",
              "url": "https://github.com/microsoft/Foundry-Local/releases/tag/v2.1.0",
              "seen": "2026-10-08"
            },
            {
              "what": "open issues",
              "url": "https://github.com/microsoft/Foundry-Local/issues",
              "seen": "2026-10-08"
            },
            {
              "what": "security advisories (none published)",
              "url": "https://github.com/microsoft/Foundry-Local/security/advisories",
              "seen": "2026-10-08"
            },
            {
              "what": "npm latest",
              "url": "https://registry.npmjs.org/foundry-local-sdk/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "npm weekly downloads",
              "url": "https://api.npmjs.org/downloads/point/last-week/foundry-local-sdk",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI release history",
              "url": "https://pypi.org/pypi/foundry-local-sdk/json",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI downloads",
              "url": "https://pypistats.org/api/packages/foundry-local-sdk/recent",
              "seen": "2026-10-08"
            },
            {
              "what": "crates.io",
              "url": "https://crates.io/api/v1/crates/foundry-local-sdk",
              "seen": "2026-10-08"
            },
            {
              "what": "NuGet versions",
              "url": "https://api.nuget.org/v3-flatcontainer/microsoft.ai.foundry.local/index.json",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt (expired 23 September 2026)",
              "url": "https://www.microsoft.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "product site",
              "url": "https://www.foundrylocal.ai/",
              "seen": "2026-10-08"
            },
            {
              "what": "NVD keyword search (no Foundry Local CVE)",
              "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?keywordSearch=Foundry%20Local",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP for microsoft.com",
              "url": "https://rdap.verisign.com/com/v1/domain/microsoft.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "Unchecked: whether the preview CLI's daemon adds the `/openai/*` and `/foundry/list` routes of the REST reference on top of the v2 runtime's routes. The CLI is closed source and we didn't run it",
            "Unchecked: CI results. Build and test run in Azure Pipelines, which we couldn't read, and api.github.com refused our requests for rate limiting",
            "Unchecked: the Microsoft Privacy Statement, which answered 403, so retention and sharing terms for the telemetry were not read",
            "Unchecked: how many models the catalogue holds. foundrylocal.ai/models is drawn by script",
            "What the telemetry events contain and which of them count as essential. The privacy file doesn't list them",
            "Whether the local server checks the Origin or Host header. We found no such check in the service source but did not test it",
            "The star count (2.6k) and issue counts come from GitHub's web pages as read through a summarising fetcher"
          ]
        },
        "negative": 0,
        "verdict": "The SDK and its native runtime are MIT, at 2.1.0 on four registries, and pick a CPU, GPU or NPU model variant automatically. The optional local server has no credential, its current routes aren't in the published REST reference, and telemetry is on by default with an opt-out.",
        "bestFor": "An application that ships a model to end users' Windows, macOS or Linux devices and wants NPU and GPU variants chosen automatically, especially on Windows.",
        "strengths": [
          "SDK 2.1.0 published on npm, PyPI, NuGet and crates.io on 29 September 2026, with the SDK and the v2 native runtime under MIT in a public repository",
          "A model alias selects the best variant for the machine's CPU, GPU or NPU, with CUDA, WebGPU, OpenVINO, QNN and Vitis AI execution providers",
          "The v2 server answers `/v1/chat/completions`, `/v1/responses`, `/v1/embeddings`, `/v1/audio/transcriptions` and `/v1/models` in OpenAI's shapes",
          "Six releases in the 90 days to 8 October 2026, and the v2.0.1 notes carry a breaking-changes section",
          "No account, key, card or Azure subscription is needed, and prompts and outputs are processed on the device per the docs"
        ],
        "weaknesses": [
          "The local server takes no credential, and its routes include model load and unload and `POST /shutdown`",
          "The REST reference on Microsoft Learn lists `/openai/*` and `/foundry/list` routes that the v2 runtime source doesn't register, and doesn't cover `/v1/responses`",
          "Telemetry is on by default through Microsoft's 1DS SDK. The opt-out covers non-essential telemetry only, and the Learn FAQ doesn't mention it",
          "The CLI is a closed-source public preview, and its REST reference warns of breaking changes without notice",
          "76 open issues on 8 October 2026, among them a Linux ARM64 segmentation fault (#1182) and several unanswered GPU and NPU detection reports"
        ],
        "agentNotes": [
          "Read the server URL from `manager.urls[0]` or `foundry server status`. The port is dynamic unless the owner sets `web.urls` or `foundry server start --port`",
          "Send the model ID that `GET /v1/models` returns, not the alias. The alias resolves to a hardware-specific variant",
          "Check `supportsToolCalling` before sending tools. Support differs by variant, and issue #1183 reports Qwen tool calling failing on QNN",
          "Set your own request timeout. Inference has no built-in one, and cancellation takes effect only after the current generation step",
          "Ask the owner to set `ORT_TELEMETRY_DISABLED=1` or `disableNonessentialTelemetry` before the manager is created if telemetry must be off"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.5
          }
        ],
        "editorialScores": {
          "ergonomics": 61,
          "maintenance": 88,
          "payments": 60,
          "reliability": 68,
          "schema": 53,
          "security": 39,
          "transparency": 63
        },
        "provenanceScore": 80
      },
      "connect": {
        "install": "pip install foundry-local-sdk   # or: npm install foundry-local-sdk\n# CLI (preview): winget install Microsoft.FoundryLocal   # macOS: brew tap microsoft/foundrylocal \u0026\u0026 brew install foundrylocal",
        "http": "foundry server start --port 39839 --idle-timeout 0\ncurl http://localhost:39839/v1/chat/completions \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"model\": \"\u003cMODEL_ID\u003e\", \"messages\": [{\"role\": \"user\", \"content\": \"What is the golden ratio?\"}]}'"
      },
      "letme": {
        "capability": "https://letme.dev/inference.local",
        "tool": "https://letme.dev/foundry-local"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-document-intelligence",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "azure-blob-storage",
        "onedrive-sharepoint",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "notable": [
        "Version 2.0.1 (GitHub release dated 1 September 2026) replaced the in-process OpenAI-style clients with `ChatSession`, `EmbeddingsSession` and `AudioSession`, merged the `-winml` packages into one per language, and keeps the old clients through 2026 (https://github.com/microsoft/Foundry-Local/releases/tag/v2.0.1)",
        "The v2 runtime registers `/v1/chat/completions`, `/v1/responses`, `/v1/embeddings`, `/v1/audio/transcriptions`, `/v1/models`, `/models/load/{name}`, `/models/unload/{name}`, `/models/loaded`, `/status` and `POST /shutdown`, with no credential check, and binds to 127.0.0.1 unless another host is configured (https://github.com/microsoft/Foundry-Local/blob/main/sdk_v2/cpp/src/service/web_service.cc)",
        "The REST reference (page updated 14 July 2026) describes `/openai/status`, `/foundry/list`, `/openai/download` and `/openai/load/{name}`, none of which appear in the repository source on 8 October 2026 (https://learn.microsoft.com/en-us/azure/foundry-local/reference/reference-rest)",
        "Telemetry is enabled by default through the 1DS SDK. The privacy file says prompts, model outputs, audio contents, raw device identifiers and secrets are not collected, and `ORT_TELEMETRY_DISABLED=1` turns off non-essential telemetry (https://github.com/microsoft/Foundry-Local/blob/main/sdk_v2/cpp/docs/Privacy.md)",
        "Microsoft's FAQ says Foundry Local targets one user on one device and is not a server inference stack, with no request queuing or batching for concurrent clients (https://learn.microsoft.com/en-us/azure/foundry-local/what-is-foundry-local)",
        "The SDK is MIT. The CLI is under Microsoft Software Licence Terms that forbid reverse engineering and sharing, and cap damages at US $5 (https://github.com/microsoft/Foundry-Local/blob/main/LICENSE)",
        "CLI preview 0.11.0 of 7 October 2026 moves the CLI to SDK 2.1.0, ONNX Runtime 1.30.0 and ONNX Runtime GenAI 0.17.1 (https://github.com/microsoft/Foundry-Local/releases)"
      ],
      "area": "models",
      "details": [
        {
          "label": "Interfaces",
          "value": "SDKs for C#, JavaScript, Python and Rust, with C++, a C ABI and Java in the v2 source. Optional OpenAI-compatible server started by `start_web_service()` or `foundry server start`. `foundry` CLI in public preview"
        },
        {
          "label": "Local server",
          "value": "http://127.0.0.1 on a dynamic port by default. `/v1/chat/completions`, `/v1/responses` (stored, with `previous_response_id`), `/v1/embeddings`, `/v1/audio/transcriptions`, `/v1/models`, `/models/load/{name}`, `/models/unload/{name}`, `/models/loaded`, `/status`, `POST /shutdown`, per the v2 source"
        },
        {
          "label": "Credentials",
          "value": "None. The docs tell OpenAI clients to send any placeholder key and set Open WebUI's auth to None"
        },
        {
          "label": "Engine",
          "value": "ONNX Runtime 1.30.0 and ONNX Runtime GenAI 0.17.1 in v2. Models are ONNX, from the Foundry catalogue or registered by the owner (bring your own model, 2.1.0)"
        },
        {
          "label": "Hardware",
          "value": "CPU everywhere. WebGPU through Dawn on Windows, Linux and macOS (Metal on Apple silicon). NVIDIA CUDA on Windows and Linux. Intel OpenVINO, Qualcomm QNN and AMD Vitis AI on Windows"
        },
        {
          "label": "Runs on",
          "value": "Windows, macOS on Apple silicon and Linux, x64 and ARM64. Node.js 20 or later, Python 3.11 to 3.14, .NET 8 or later, Rust 1.70 or later"
        },
        {
          "label": "Models",
          "value": "A curated catalogue. The docs name GPT OSS, Qwen, DeepSeek, Mistral and Phi for chat and Whisper for transcription, plus embedding models. Each model has its own licence"
        },
        {
          "label": "What leaves the machine",
          "value": "Model and execution provider downloads, and telemetry events through Microsoft's 1DS SDK, on by default. The privacy file says prompts, outputs and audio are not collected"
        },
        {
          "label": "Releases in 90 days",
          "value": "6 (CLI preview 0.10.2 on 14 July, v1.2.4, CLI preview 0.10.3, v2.0.1, v2.1.0, CLI preview 0.11.0 on 7 October 2026)"
        },
        {
          "label": "Packages",
          "value": "foundry-local-sdk 2.1.0 on npm (105,372 downloads in the week to 4 October 2026), PyPI (47,344 in the last week) and crates.io, and Microsoft.AI.Foundry.Local 2.1.0 on NuGet. CLI through winget and Homebrew"
        },
        {
          "label": "Issues",
          "value": "76 open and 362 closed on 8 October 2026, with 32 open pull requests. No published security advisory and no CVE found at NVD"
        }
      ],
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/microsoft/Foundry-Local/releases",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The repository is under GitHub's microsoft organisation, the licence file reads Copyright (c) Microsoft Corporation, and foundrylocal.ai names Microsoft Corporation as publisher.",
          "The terms link is the repository's LICENSE file, which holds the MIT licence for the SDK and the Microsoft Software Licence Terms for the CLI. Microsoft publishes no other agreement for Foundry Local that we found.",
          "The privacy link is the product's own privacy file in the repository, which the README links. It and the CLI licence both refer on to the Microsoft Privacy Statement, a company-wide notice, which answered 403 to our request.",
          "www.microsoft.com/.well-known/security.txt loads and points to the MSRC researcher portal, but its Expires field is 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026. learn.microsoft.com and foundrylocal.ai return 404.",
          "No status page is listed because the software runs on the owner's machine. The model catalogue is a cloud service with no status page that we found.",
          "RDAP gives microsoft.com a registration date of 1991-05-02 and foundrylocal.ai one of 2025-10-07."
        ],
        "score": 80,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Microsoft Corporation",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "microsoft.com, registered 1991-05-02 (35 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "no hosted endpoint",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Terms of service",
            "value": "nothing hosted, so the MIT for the SDKs and the v2 native runtime. The CLI is closed source under Microsoft Software Licence Terms. Execution providers carry NVIDIA, Intel and Qualcomm licences, and each model carries its own licence stands in",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Privacy policy",
            "value": "nothing hosted, not scored",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "published but past its Expires date",
            "points": 5,
            "max": 10,
            "state": "part"
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/foundry-local.json"
    },
    "verify": {
      "accepts": "a page on microsoft.com or foundrylocal.ai or one of their subdomains, or the README of github.com/microsoft/Foundry-Local",
      "badgeUrl": "https://www.anchorterminal.com/badges/foundry-local.svg",
      "body": {
        "slug": "foundry-local",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/foundry-local",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/foundry-local\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/foundry-local.svg\" alt=\"Foundry Local on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Foundry Local on Anchor Terminal](https://www.anchorterminal.com/badges/foundry-local.svg)](https://www.anchorterminal.com/tools/foundry-local)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/foundry-local\"\u003eFoundry Local on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/foundry-local",
    "json": "https://www.anchorterminal.com/tools/foundry-local.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/foundry-local.md",
    "slim": "https://www.anchorterminal.com/tools/foundry-local.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 60.5/100 · rank #461 of 842 · #4 in Local AI · not agent-ready · confidence medium**\n\n\nMore from Microsoft, listed separately because each is its own product: [Microsoft Foundry fine-tuning (Azure OpenAI)](https://www.anchorterminal.com/tools/azure-foundry-fine-tuning.md) (Fine-tuning), [Azure AI Content Safety (Prompt Shields)](https://www.anchorterminal.com/tools/azure-ai-content-safety.md) (Guardrails \u0026 safety filters), [Azure AI Speech speech-to-text](https://www.anchorterminal.com/tools/azure-speech-to-text.md) (Speech-to-text), [Azure AI Speech text-to-speech](https://www.anchorterminal.com/tools/azure-text-to-speech.md) (Text-to-speech), [Microsoft Agent Framework](https://www.anchorterminal.com/tools/microsoft-agent-framework.md) (Agent frameworks \u0026 SDKs), [Microsoft Execution Containers](https://www.anchorterminal.com/tools/microsoft-execution-containers.md) (Code execution sandboxes), [Microsoft Entra Agent ID](https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md) (Agent auth \u0026 delegated access), [Azure Key Vault](https://www.anchorterminal.com/tools/azure-key-vault.md) (Secrets \u0026 credential vaults), [Azure Document Intelligence](https://www.anchorterminal.com/tools/azure-document-intelligence.md) (Document parsing \u0026 extraction), [Azure DevOps MCP Server](https://www.anchorterminal.com/tools/azure-devops-mcp.md) (Code \u0026 developer platforms), [Microsoft Learn MCP Server](https://www.anchorterminal.com/tools/microsoft-learn-mcp.md) (Code \u0026 developer platforms), [Playwright MCP](https://www.anchorterminal.com/tools/playwright-mcp.md) (Browser automation), [Azure MCP Server](https://www.anchorterminal.com/tools/azure-mcp.md) (Cloud \u0026 infrastructure), [Azure Maps](https://www.anchorterminal.com/tools/azure-maps.md) (Maps, geocoding \u0026 places), [Azure Translator](https://www.anchorterminal.com/tools/azure-translator.md) (Translation), [Microsoft Graph Calendar API](https://www.anchorterminal.com/tools/microsoft-graph-calendar.md) (Calendars \u0026 scheduling), [Azure Blob Storage](https://www.anchorterminal.com/tools/azure-blob-storage.md) (File storage \u0026 sharing), [OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/tools/onedrive-sharepoint.md) (File storage \u0026 sharing), [Microsoft Teams (Microsoft Graph)](https://www.anchorterminal.com/tools/microsoft-teams.md) (Work \u0026 productivity), [Microsoft Dynamics 365 Sales](https://www.anchorterminal.com/tools/dynamics-365-sales.md) (CRM \u0026 customer platforms), [Microsoft Power Automate](https://www.anchorterminal.com/tools/power-automate.md) (Workflow automation), [Microsoft Advertising API](https://www.anchorterminal.com/tools/microsoft-advertising-api.md) (Advertising \u0026 campaign operations), [Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/tools/microsoft-excel-graph.md) (Spreadsheets \u0026 operational tables), [Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/tools/outlook-mail-graph.md) (Mailbox access).\n\n## Assessment\n\nThe SDK and its native runtime are MIT, at 2.1.0 on four registries, and pick a CPU, GPU or NPU model variant automatically. The optional local server has no credential, its current routes aren't in the published REST reference, and telemetry is on by default with an opt-out.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Microsoft (https://www.foundrylocal.ai) |\n| Kind | SDK + MCP |\n| Category | Local AI (https://www.anchorterminal.com/categories/local-ai) |\n| Transport | HTTP |\n| Auth | None · No authentication. The SDK runs in the application's own process, and the optional local server takes no key or token. It binds to 127.0.0.1 on a dynamic port unless the owner configures `web.urls` or starts the CLI daemon with `--port`. No account or Azure subscription is needed. |\n| Pricing | Free (Free · OSS) · Free, with no account, card or Azure subscription. The SDK is MIT and the CLI is a free download under Microsoft's licence terms. Microsoft states there are no per-token costs. Foundry Local on Azure Local is a separate product for servers and is not covered here (checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the docs, the README or the SDK source (checked 2026-10-08). |\n| Licence | MIT for the SDKs and the v2 native runtime. The CLI is closed source under Microsoft Software Licence Terms. Execution providers carry NVIDIA, Intel and Qualcomm licences, and each model carries its own |\n| Packages | npm: `foundry-local-sdk`; pypi: `foundry-local-sdk`; nuget: `Microsoft.AI.Foundry.Local`; cargo: `foundry-local-sdk` |\n| Source | https://github.com/microsoft/Foundry-Local |\n| Docs | https://learn.microsoft.com/en-us/azure/foundry-local/ |\n| llms.txt | not found |\n| Last release | 2026-09-29 |\n| GitHub stars | 2,600 (as of 2026-10-08) |\n| npm downloads / week | 105,372 |\n| PyPI downloads / week | 47,344 |\n| Interfaces | SDKs for C#, JavaScript, Python and Rust, with C++, a C ABI and Java in the v2 source. Optional OpenAI-compatible server started by `start_web_service()` or `foundry server start`. `foundry` CLI in public preview |\n| Local server | http://127.0.0.1 on a dynamic port by default. `/v1/chat/completions`, `/v1/responses` (stored, with `previous_response_id`), `/v1/embeddings`, `/v1/audio/transcriptions`, `/v1/models`, `/models/load/{name}`, `/models/unload/{name}`, `/models/loaded`, `/status`, `POST /shutdown`, per the v2 source |\n| Credentials | None. The docs tell OpenAI clients to send any placeholder key and set Open WebUI's auth to None |\n| Engine | ONNX Runtime 1.30.0 and ONNX Runtime GenAI 0.17.1 in v2. Models are ONNX, from the Foundry catalogue or registered by the owner (bring your own model, 2.1.0) |\n| Hardware | CPU everywhere. WebGPU through Dawn on Windows, Linux and macOS (Metal on Apple silicon). NVIDIA CUDA on Windows and Linux. Intel OpenVINO, Qualcomm QNN and AMD Vitis AI on Windows |\n| Runs on | Windows, macOS on Apple silicon and Linux, x64 and ARM64. Node.js 20 or later, Python 3.11 to 3.14, .NET 8 or later, Rust 1.70 or later |\n| Models | A curated catalogue. The docs name GPT OSS, Qwen, DeepSeek, Mistral and Phi for chat and Whisper for transcription, plus embedding models. Each model has its own licence |\n| What leaves the machine | Model and execution provider downloads, and telemetry events through Microsoft's 1DS SDK, on by default. The privacy file says prompts, outputs and audio are not collected |\n| Releases in 90 days | 6 (CLI preview 0.10.2 on 14 July, v1.2.4, CLI preview 0.10.3, v2.0.1, v2.1.0, CLI preview 0.11.0 on 7 October 2026) |\n| Packages | foundry-local-sdk 2.1.0 on npm (105,372 downloads in the week to 4 October 2026), PyPI (47,344 in the last week) and crates.io, and Microsoft.AI.Foundry.Local 2.1.0 on NuGet. CLI through winget and Homebrew |\n| Issues | 76 open and 362 closed on 8 October 2026, with 32 open pull requests. No published security advisory and no CVE found at NVD |\n| Capabilities | inference.local, inference.open-weights, embed.text, speech.stt |\n| Tags | local, open-source, free, no-card, account-free, no-auth, openai-compatible, csharp, typescript, python, rust, npu, telemetry-on-by-default |\n| JSON | https://www.anchorterminal.com/api/v1/tools/foundry-local.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 68 | 13.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 53 | 8.6 |\n| Agent ergonomics | 13% | 16.2 | 61 | 9.9 |\n| Security \u0026 auth | 14% | 17.5 | 39 | 6.8 |\n| Payments \u0026 pricing | 10% | 12.5 | 60 | 7.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 88 | 7.7 |\n| Transparency \u0026 trust (editorial 63, provenance 80) | 7% | 8.8 | 72 | 6.3 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **60.5 → C** |\n\n### Why each score\n\n- Reliability 68: Read with the local-software lines, since Foundry Local runs in the owner's application or as a local daemon. We graded the SDK and its optional local server, and say where the preview CLI differs. Official packages on npm, PyPI, NuGet and crates.io, the CLI through winget and Homebrew, with Node.js 20, Python 3.11 to 3.14, .NET 8 and Rust 1.70 stated (20). The repository holds test suites for the C++ runtime and each SDK, but the only public GitHub Actions workflow is a build check for samples. Build and test run in Azure Pipelines whose results we couldn't see, and the pipeline file says its push trigger is switched off (12 of 25). 76 open issues against 362 closed. Open reports include a Linux ARM64 segmentation fault (#1182, 8 October), HTTP 500 on Qwen3.5 CUDA models (#1179), memory kept after unload (#1079) and several GPU and NPU detection failures from September with no reply (13 of 25). Versioned releases with notes on GitHub, and v2.0.1 has a breaking-changes section. There is no changelog file, and the CLI's REST reference warns of breaking changes without notice (10 of 15). SDK 2.1.0. The PyPI package still carries an Alpha classifier and the CLI is a public preview (13 of 15).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 53: Read with the API lines, for the local server and the SDKs. No OpenAPI file in the repository or the docs. The server follows OpenAI's shapes and the SDKs are typed (8 of 25). Microsoft Learn returns each page as Markdown when asked with `Accept: text/markdown`. No llms.txt on learn.microsoft.com or foundrylocal.ai (6 of 10). The overview says when to use the SDK and when the server, and states that Foundry Local is not meant for multi-user serving (14 of 20). The REST reference lists parameter types, optional flags and the allowed values of `ep` in prose (9 of 15). 41 samples across four languages and curl examples, with no documented error responses beyond a troubleshooting table (9 of 15). Dated release notes on GitHub. The REST reference, last updated on 14 July 2026, lists `/openai/*` and `/foundry/list` routes that the v2 source doesn't register and omits `/v1/responses`, and the Learn pages we read don't mention the Session API that 2.0.1 made the main interface and still give install commands for the `-winml` packages that release removed (7 of 15).\n- Agent ergonomics 61: Read with the API lines. Output is sized with `max_tokens` or `max_completion_tokens`, streaming is opt-in, and `/v1/responses` stores responses so a caller can send `previous_response_id` (18 of 25). `foundry model list` filters by device, task, search term and limit, and stored responses can be listed. Model lists over HTTP aren't paged (12 of 20). Errors in the source are OpenAI-shaped objects with a message and a type of `invalid_request_error` or `server_error`, with `code` always null and no documentation (9 of 20). Inference calls are stateless and safe to repeat. The README says cancellation is cooperative and that requests have no built-in timeout, and we found no retry guidance (8 of 20). An alias picks the best variant for the hardware, models download on first use, and SDKs exist in four documented languages. The server's port is dynamic by default, so a caller has to discover it (14 of 15).\n- Security \u0026 auth 39: Read with the tool checklist, for the local server. No credential exists. The server is off until the application or the CLI starts it, binds to 127.0.0.1 by default, and the docs tell clients to set auth to None (8 of 30). No read-only mode. Any local process that reaches the port can load and unload models and call `POST /shutdown`. Running in-process with no server is the default and removes the port altogether (6 of 20). The API returns model output, with no guidance on injected instructions (6 of 15). `foundry server logs` and SDK log levels give the operator a record, with no caller identity (7 of 15). SECURITY.md sends reports to MSRC and promises a reply within 24 hours, GitHub Actions are pinned to commit hashes, and no advisory or CVE was found. The security.txt on www.microsoft.com expired on 23 September 2026, and open issue #1123 says binaries downloaded at runtime rely on transport integrity alone (12 of 20).\n- Payments \u0026 pricing 60: Read with the self-hosted rule, since everything an agent calls runs on the owner's machine. No x402, MPP or L402 (0). The SDK is MIT, the CLI is a free download, and no account, card or Azure subscription is needed, so 20, 20 and 20 on the last three lines.\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 88: SDK 2.1.0 reached the registries on 29 September 2026 and CLI preview 0.11.0 followed on 7 October (30). Six releases in the 90 days to 8 October (20). 132 commits on main since 10 July, the newest on 7 October, and 362 issues closed against 76 open. Many of the newest open issues had no comment when we read them, and SUPPORT.md is still Microsoft's unedited template (15 of 25). Current SDKs at the same version on npm, PyPI, NuGet and crates.io (15). Dependabot is configured, native dependency versions are pinned in one file that the build validates, and actions are pinned. We couldn't see CI results (8 of 10).\n- Transparency \u0026 trust 72: The editorial half. The SDKs and the v2 native runtime are MIT in a public repository. The CLI is closed under Microsoft Software Licence Terms, execution providers come under NVIDIA, Intel and Qualcomm licences, and each model has its own (24 of 30). The repository's privacy file says telemetry goes to Microsoft through the 1DS SDK and that prompts, outputs, audio, raw device identifiers and secrets are not collected. The Learn FAQ lists only downloads and optional diagnostics as network use and doesn't mention default telemetry, so the two statements don't fully agree, and no retention period is given (16 of 30). The v2.0.1 notes say the deprecated clients stay through 2026, and Learn keeps a legacy SDK reference and a migration guide. There is no written deprecation policy (9 of 20). Telemetry is disclosed in the README and is on by default. A config option or `ORT_TELEMETRY_DISABLED=1` turns off non-essential telemetry, and what counts as essential isn't stated (14 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (16 items): https://www.anchorterminal.com/fixes/foundry-local.md (JSON https://www.anchorterminal.com/fixes/foundry-local.json)\n\n### What we couldn't check\n\n- Unchecked: whether the preview CLI's daemon adds the `/openai/*` and `/foundry/list` routes of the REST reference on top of the v2 runtime's routes. The CLI is closed source and we didn't run it\n- Unchecked: CI results. Build and test run in Azure Pipelines, which we couldn't read, and api.github.com refused our requests for rate limiting\n- Unchecked: the Microsoft Privacy Statement, which answered 403, so retention and sharing terms for the telemetry were not read\n- Unchecked: how many models the catalogue holds. foundrylocal.ai/models is drawn by script\n- What the telemetry events contain and which of them count as essential. The privacy file doesn't list them\n- Whether the local server checks the Origin or Host header. We found no such check in the service source but did not test it\n- The star count (2.6k) and issue counts come from GitHub's web pages as read through a summarising fetcher\n\n### Sources\n\n- overview and FAQ: \u003chttps://learn.microsoft.com/en-us/azure/foundry-local/what-is-foundry-local\u003e (seen 2026-10-08)\n- architecture: \u003chttps://learn.microsoft.com/en-us/azure/foundry-local/concepts/foundry-local-architecture\u003e (seen 2026-10-08)\n- REST reference (CLI preview): \u003chttps://learn.microsoft.com/en-us/azure/foundry-local/reference/reference-rest\u003e (seen 2026-10-08)\n- CLI reference: \u003chttps://learn.microsoft.com/en-us/azure/foundry-local/reference/reference-cli\u003e (seen 2026-10-08)\n- SDK reference: \u003chttps://learn.microsoft.com/en-us/azure/foundry-local/reference/reference-sdk-current\u003e (seen 2026-10-08)\n- REST server how-to: \u003chttps://learn.microsoft.com/en-us/azure/foundry-local/how-to/how-to-integrate-with-inference-sdks\u003e (seen 2026-10-08)\n- best practice and troubleshooting: \u003chttps://learn.microsoft.com/en-us/azure/foundry-local/reference/reference-best-practice\u003e (seen 2026-10-08)\n- get started: \u003chttps://learn.microsoft.com/en-us/azure/foundry-local/get-started\u003e (seen 2026-10-08)\n- repository (README, LICENSE, SECURITY.md, SUPPORT.md, workflows, tags), cloned at commit of 7 October 2026: \u003chttps://github.com/microsoft/Foundry-Local\u003e (seen 2026-10-08)\n- v2 web service source (routes, binding): \u003chttps://github.com/microsoft/Foundry-Local/blob/main/sdk_v2/cpp/src/service/web_service.cc\u003e (seen 2026-10-08)\n- privacy file: \u003chttps://github.com/microsoft/Foundry-Local/blob/main/sdk_v2/cpp/docs/Privacy.md\u003e (seen 2026-10-08)\n- licence file: \u003chttps://github.com/microsoft/Foundry-Local/blob/main/LICENSE\u003e (seen 2026-10-08)\n- releases: \u003chttps://github.com/microsoft/Foundry-Local/releases\u003e (seen 2026-10-08)\n- v2.0.1 release notes: \u003chttps://github.com/microsoft/Foundry-Local/releases/tag/v2.0.1\u003e (seen 2026-10-08)\n- v2.1.0 release notes: \u003chttps://github.com/microsoft/Foundry-Local/releases/tag/v2.1.0\u003e (seen 2026-10-08)\n- open issues: \u003chttps://github.com/microsoft/Foundry-Local/issues\u003e (seen 2026-10-08)\n- security advisories (none published): \u003chttps://github.com/microsoft/Foundry-Local/security/advisories\u003e (seen 2026-10-08)\n- npm latest: \u003chttps://registry.npmjs.org/foundry-local-sdk/latest\u003e (seen 2026-10-08)\n- npm weekly downloads: \u003chttps://api.npmjs.org/downloads/point/last-week/foundry-local-sdk\u003e (seen 2026-10-08)\n- PyPI release history: \u003chttps://pypi.org/pypi/foundry-local-sdk/json\u003e (seen 2026-10-08)\n- PyPI downloads: \u003chttps://pypistats.org/api/packages/foundry-local-sdk/recent\u003e (seen 2026-10-08)\n- crates.io: \u003chttps://crates.io/api/v1/crates/foundry-local-sdk\u003e (seen 2026-10-08)\n- NuGet versions: \u003chttps://api.nuget.org/v3-flatcontainer/microsoft.ai.foundry.local/index.json\u003e (seen 2026-10-08)\n- security.txt (expired 23 September 2026): \u003chttps://www.microsoft.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- product site: \u003chttps://www.foundrylocal.ai/\u003e (seen 2026-10-08)\n- NVD keyword search (no Foundry Local CVE): \u003chttps://services.nvd.nist.gov/rest/json/cves/2.0?keywordSearch=Foundry%20Local\u003e (seen 2026-10-08)\n- RDAP for microsoft.com: \u003chttps://rdap.verisign.com/com/v1/domain/microsoft.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 80/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Microsoft Corporation | 20/20 |\n| Domain age | microsoft.com, registered 1991-05-02 (35 years) | 15/15 |\n| Endpoint on the vendor's domain | no hosted endpoint | n/a |\n| Terms of service | nothing hosted, so the MIT for the SDKs and the v2 native runtime. The CLI is closed source under Microsoft Software Licence Terms. Execution providers carry NVIDIA, Intel and Qualcomm licences, and each model carries its own licence stands in | 10/10 |\n| Privacy policy | nothing hosted, not scored | n/a |\n| Status page | not found | 0/10 |\n| Changelog | published | 10/10 |\n| security.txt | published but past its Expires date | 5/10 |\n\nThe repository is under GitHub's microsoft organisation, the licence file reads Copyright (c) Microsoft Corporation, and foundrylocal.ai names Microsoft Corporation as publisher.\n\nThe terms link is the repository's LICENSE file, which holds the MIT licence for the SDK and the Microsoft Software Licence Terms for the CLI. Microsoft publishes no other agreement for Foundry Local that we found.\n\nThe privacy link is the product's own privacy file in the repository, which the README links. It and the CLI licence both refer on to the Microsoft Privacy Statement, a company-wide notice, which answered 403 to our request.\n\nwww.microsoft.com/.well-known/security.txt loads and points to the MSRC researcher portal, but its Expires field is 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026. learn.microsoft.com and foundrylocal.ai return 404.\n\nNo status page is listed because the software runs on the owner's machine. The model catalogue is a cloud service with no status page that we found.\n\nRDAP gives microsoft.com a registration date of 1991-05-02 and foundrylocal.ai one of 2025-10-07.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service**. Nothing is hosted by the vendor, so there are no terms of service to read. The MIT for the SDKs and the v2 native runtime. The CLI is closed source under Microsoft Software Licence Terms. Execution providers carry NVIDIA, Intel and Qualcomm licences, and each model carries its own licence stands in and the check scores in full.\n\n\n**Privacy policy**. Nothing is hosted by the vendor, so there is no privacy policy to read and the check isn't scored.\n\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- SDK 2.1.0 published on npm, PyPI, NuGet and crates.io on 29 September 2026, with the SDK and the v2 native runtime under MIT in a public repository\n- A model alias selects the best variant for the machine's CPU, GPU or NPU, with CUDA, WebGPU, OpenVINO, QNN and Vitis AI execution providers\n- The v2 server answers `/v1/chat/completions`, `/v1/responses`, `/v1/embeddings`, `/v1/audio/transcriptions` and `/v1/models` in OpenAI's shapes\n- Six releases in the 90 days to 8 October 2026, and the v2.0.1 notes carry a breaking-changes section\n- No account, key, card or Azure subscription is needed, and prompts and outputs are processed on the device per the docs\n\n## Weaknesses\n\n- The local server takes no credential, and its routes include model load and unload and `POST /shutdown`\n- The REST reference on Microsoft Learn lists `/openai/*` and `/foundry/list` routes that the v2 runtime source doesn't register, and doesn't cover `/v1/responses`\n- Telemetry is on by default through Microsoft's 1DS SDK. The opt-out covers non-essential telemetry only, and the Learn FAQ doesn't mention it\n- The CLI is a closed-source public preview, and its REST reference warns of breaking changes without notice\n- 76 open issues on 8 October 2026, among them a Linux ARM64 segmentation fault (#1182) and several unanswered GPU and NPU detection reports\n\n## Before you call it (notes for agents)\n\n1. Read the server URL from `manager.urls[0]` or `foundry server status`. The port is dynamic unless the owner sets `web.urls` or `foundry server start --port`\n2. Send the model ID that `GET /v1/models` returns, not the alias. The alias resolves to a hardware-specific variant\n3. Check `supportsToolCalling` before sending tools. Support differs by variant, and issue #1183 reports Qwen tool calling failing on QNN\n4. Set your own request timeout. Inference has no built-in one, and cancellation takes effect only after the current generation step\n5. Ask the owner to set `ORT_TELEMETRY_DISABLED=1` or `disableNonessentialTelemetry` before the manager is created if telemetry must be off\n\n## Connect\n\nInstall:\n\n```bash\npip install foundry-local-sdk   # or: npm install foundry-local-sdk\n# CLI (preview): winget install Microsoft.FoundryLocal   # macOS: brew tap microsoft/foundrylocal \u0026\u0026 brew install foundrylocal\n```\n\nFirst request:\n\n```bash\nfoundry server start --port 39839 --idle-timeout 0\ncurl http://localhost:39839/v1/chat/completions \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"model\": \"\u003cMODEL_ID\u003e\", \"messages\": [{\"role\": \"user\", \"content\": \"What is the golden ratio?\"}]}'\n```\n\nThrough letme (picks today, calling later): https://letme.dev/foundry-local. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| LocalAI | B | 68 | 216 | inference.local, inference.open-weights, embed.text, speech.stt | no | https://www.anchorterminal.com/tools/localai.md |\n| Lemonade | B | 63.8 | 336 | inference.local, inference.open-weights, embed.text, speech.stt | no | https://www.anchorterminal.com/tools/lemonade.md |\n| KoboldCpp | C | 60.5 | 462 | inference.local, inference.open-weights, embed.text, speech.stt | no | https://www.anchorterminal.com/tools/koboldcpp.md |\n| DeepInfra | B | 63 | 371 | inference.open-weights, embed.text, speech.stt | no | https://www.anchorterminal.com/tools/deepinfra.md |\n| llama.cpp | C | 60.2 | 476 | inference.local, inference.open-weights, embed.text | no | https://www.anchorterminal.com/tools/llama-cpp.md |\n| LM Studio | C | 57.8 | 536 | inference.local, inference.open-weights, embed.text | no | https://www.anchorterminal.com/tools/lm-studio.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Version 2.0.1 (GitHub release dated 1 September 2026) replaced the in-process OpenAI-style clients with `ChatSession`, `EmbeddingsSession` and `AudioSession`, merged the `-winml` packages into one per language, and keeps the old clients through 2026 (source: \u003chttps://github.com/microsoft/Foundry-Local/releases/tag/v2.0.1\u003e)\n- The v2 runtime registers `/v1/chat/completions`, `/v1/responses`, `/v1/embeddings`, `/v1/audio/transcriptions`, `/v1/models`, `/models/load/{name}`, `/models/unload/{name}`, `/models/loaded`, `/status` and `POST /shutdown`, with no credential check, and binds to 127.0.0.1 unless another host is configured (source: \u003chttps://github.com/microsoft/Foundry-Local/blob/main/sdk_v2/cpp/src/service/web_service.cc\u003e)\n- The REST reference (page updated 14 July 2026) describes `/openai/status`, `/foundry/list`, `/openai/download` and `/openai/load/{name}`, none of which appear in the repository source on 8 October 2026 (source: \u003chttps://learn.microsoft.com/en-us/azure/foundry-local/reference/reference-rest\u003e)\n- Telemetry is enabled by default through the 1DS SDK. The privacy file says prompts, model outputs, audio contents, raw device identifiers and secrets are not collected, and `ORT_TELEMETRY_DISABLED=1` turns off non-essential telemetry (source: \u003chttps://github.com/microsoft/Foundry-Local/blob/main/sdk_v2/cpp/docs/Privacy.md\u003e)\n- Microsoft's FAQ says Foundry Local targets one user on one device and is not a server inference stack, with no request queuing or batching for concurrent clients (source: \u003chttps://learn.microsoft.com/en-us/azure/foundry-local/what-is-foundry-local\u003e)\n- The SDK is MIT. The CLI is under Microsoft Software Licence Terms that forbid reverse engineering and sharing, and cap damages at US $5 (source: \u003chttps://github.com/microsoft/Foundry-Local/blob/main/LICENSE\u003e)\n- CLI preview 0.11.0 of 7 October 2026 moves the CLI to SDK 2.1.0, ONNX Runtime 1.30.0 and ONNX Runtime GenAI 0.17.1 (source: \u003chttps://github.com/microsoft/Foundry-Local/releases\u003e)\n\n## Compare\n\n- [AnythingLLM vs Foundry Local](https://www.anchorterminal.com/compare/anythingllm-vs-foundry-local.md): D 53.3 vs C 60.5\n- [Docker Model Runner vs Foundry Local](https://www.anchorterminal.com/compare/docker-model-runner-vs-foundry-local.md): C 57.1 vs C 60.5\n- [Foundry Local vs Core](https://www.anchorterminal.com/compare/foundry-local-vs-ghost-core.md): C 60.5 vs F 7.3\n- [Foundry Local vs GPT4All](https://www.anchorterminal.com/compare/foundry-local-vs-gpt4all.md): C 60.5 vs F 36.2\n- [Foundry Local vs Jan](https://www.anchorterminal.com/compare/foundry-local-vs-jan.md): C 60.5 vs D 51.3\n- [Foundry Local vs Khoj](https://www.anchorterminal.com/compare/foundry-local-vs-khoj.md): C 60.5 vs E 38.5\n- [Foundry Local vs KoboldCpp](https://www.anchorterminal.com/compare/foundry-local-vs-koboldcpp.md): C 60.5 vs C 60.5\n- [Foundry Local vs Lemonade](https://www.anchorterminal.com/compare/foundry-local-vs-lemonade.md): C 60.5 vs B 63.8\n- [Foundry Local vs llama.cpp](https://www.anchorterminal.com/compare/foundry-local-vs-llama-cpp.md): C 60.5 vs C 60.2\n- [Foundry Local vs LM Studio](https://www.anchorterminal.com/compare/foundry-local-vs-lm-studio.md): C 60.5 vs C 57.8\n- [Foundry Local vs LocalAI](https://www.anchorterminal.com/compare/foundry-local-vs-localai.md): C 60.5 vs B 68\n- [Foundry Local vs MLX LM](https://www.anchorterminal.com/compare/foundry-local-vs-mlx-lm.md): C 60.5 vs D 52.2\n- [Foundry Local vs Ollama](https://www.anchorterminal.com/compare/foundry-local-vs-ollama.md): C 60.5 vs C 56.3\n- [Foundry Local vs Open WebUI](https://www.anchorterminal.com/compare/foundry-local-vs-open-webui.md): C 60.5 vs D 51.8\n- [Foundry Local vs screenpipe](https://www.anchorterminal.com/compare/foundry-local-vs-screenpipe.md): C 60.5 vs C 60.8\n- [Foundry Local vs TextGen](https://www.anchorterminal.com/compare/foundry-local-vs-text-generation-webui.md): C 60.5 vs E 45.1\n- [Foundry Local vs Underdog](https://www.anchorterminal.com/compare/foundry-local-vs-underdog.md): C 60.5 vs F 29.5\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on microsoft.com or foundrylocal.ai or one of their subdomains, or the README of github.com/microsoft/Foundry-Local. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"foundry-local\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/foundry-local\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/foundry-local.svg\" alt=\"Foundry Local on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Foundry Local on Anchor Terminal](https://www.anchorterminal.com/badges/foundry-local.svg)](https://www.anchorterminal.com/tools/foundry-local)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/foundry-local\"\u003eFoundry Local on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Foundry Local is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/foundry-local-dark.png\n- Light: https://www.anchorterminal.com/assets/share/foundry-local-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Local AI",
        "url": "https://www.anchorterminal.com/categories/local-ai"
      },
      {
        "name": "Foundry Local",
        "url": ""
      }
    ],
    "description": "Microsoft's on-device model runtime, built on ONNX Runtime. Applications embed it through SDKs for C#, JavaScript, Python and Rust, and it can start an optional OpenAI-compatible server on localhost. A preview CLI is also available.",
    "facts": [
      "rank #461 of 842",
      "None auth",
      "0 desk reviews"
    ],
    "h1": "Foundry Local",
    "image": "https://www.anchorterminal.com/assets/og/tools-foundry-local.png",
    "path": "/tools/foundry-local",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Foundry Local review for AI agents, grade C (60.5/100)",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/foundry-local"
  },
  "tokens": {
    "markdown": 8200,
    "slim": 1780
  },
  "version": 1
}
