{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/localai.json",
        "name": "LocalAI",
        "score": 68,
        "shared": [
          "inference.local",
          "inference.open-weights",
          "agent.mcp-client",
          "embed.text",
          "speech.stt",
          "speech.tts",
          "image.generate"
        ],
        "slug": "localai"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/lemonade.json",
        "name": "Lemonade",
        "score": 63.8,
        "shared": [
          "inference.local",
          "inference.open-weights",
          "embed.text",
          "speech.stt",
          "speech.tts",
          "image.generate"
        ],
        "slug": "lemonade"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/deepinfra.json",
        "name": "DeepInfra",
        "score": 63,
        "shared": [
          "inference.open-weights",
          "embed.text",
          "image.generate",
          "speech.stt",
          "speech.tts"
        ],
        "slug": "deepinfra"
      },
      {
        "grade": "E",
        "json": "https://www.anchorterminal.com/tools/text-generation-webui.json",
        "name": "TextGen",
        "score": 45.1,
        "shared": [
          "inference.local",
          "inference.open-weights",
          "agent.mcp-client",
          "embed.text",
          "image.generate"
        ],
        "slug": "text-generation-webui"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/foundry-local.json",
        "name": "Foundry Local",
        "score": 60.5,
        "shared": [
          "inference.local",
          "inference.open-weights",
          "embed.text",
          "speech.stt"
        ],
        "slug": "foundry-local"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/llama-cpp.json",
        "name": "llama.cpp",
        "score": 60.2,
        "shared": [
          "inference.local",
          "inference.open-weights",
          "embed.text",
          "agent.mcp-client"
        ],
        "slug": "llama-cpp"
      }
    ],
    "tool": {
      "slug": "koboldcpp",
      "name": "KoboldCpp",
      "vendor": "LostRuins (Concedo)",
      "vendorUrl": "https://koboldcpp.net",
      "kind": "http-api",
      "category": "local-ai",
      "summary": "Open-source program for running GGUF models on the owner's own computer, built on llama.cpp. One executable serves a web interface and KoboldAI, OpenAI, Ollama and Anthropic compatible APIs on port 5001.",
      "url": "https://www.anchorterminal.com/tools/koboldcpp",
      "markdownUrl": "https://www.anchorterminal.com/tools/koboldcpp.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/koboldcpp.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/koboldcpp.json",
      "repo": "https://github.com/LostRuins/koboldcpp",
      "license": "AGPL-3.0 for KoboldCpp and KoboldAI Lite. The bundled GGML, llama.cpp and stable-diffusion.cpp code stays under MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "koboldai/koboldcpp"
        }
      ],
      "auth": "none",
      "authNotes": "No credential by default. `--password` (or the `KCPP_PASSWORD` environment variable) sets one shared key, sent as `Authorization: Bearer`, and the server reads it from the header only. The key guards text routes. Image generation, upscaling, `/sdapi/v1/interrogate` and `/tts_to_audio` skip the check, and the `--help` text says image endpoints are not secured. Admin routes need `--admin`, an `--admindir` and, when set, a separate `--adminpassword`. Keys have no scopes and change only with a restart. With no `--host` the server listens on all routable interfaces, and CORS reflects any Origin with credentials allowed (https://github.com/LostRuins/koboldcpp/blob/concedo/koboldcpp.py).",
      "pricing": "free",
      "pricingNotes": "Free under AGPL-3.0, with no account, key or card. Nothing is sold by the project. The owner pays for hardware and electricity, and the README links third-party GPU rental (RunPod, SimplePod) and Google Colab as other places to run it.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the wiki, the API document or `koboldcpp.py` (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 11972,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://github.com/LostRuins/koboldcpp/wiki",
      "llmsTxt": "https://koboldcpp.net/llms.txt",
      "openapi": "https://lite.koboldai.net/koboldcpp_api.json",
      "capabilities": [
        "inference.local",
        "inference.open-weights",
        "agent.mcp-client",
        "embed.text",
        "image.generate",
        "speech.stt",
        "speech.tts",
        "audio.music"
      ],
      "tags": [
        "open-source",
        "local",
        "self-hosted",
        "free",
        "no-card",
        "openai-compatible",
        "openapi",
        "llms-txt",
        "docker",
        "agpl",
        "no-telemetry"
      ],
      "lastRelease": "2026-09-27",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.5,
        "grade": "C",
        "agentReady": false,
        "rank": 462,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 82,
          "payments": 60,
          "reliability": 68,
          "schema": 68,
          "security": 38,
          "transparency": 49
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 68,
            "points": 13.6,
            "reason": "Read with the local-software lines, since KoboldCpp runs on the owner's machine with no hosted service. Single-file binaries on GitHub releases for Windows x64, Linux x64 and Apple Silicon macOS, with `nocuda` and `oldpc` variants and the hardware each suits stated in the README and release notes, plus the `koboldai/koboldcpp` Docker image. No package-manager release of the project's own, since the Nix and AUR packages are third-party (18 of 20). Twelve workflows, eleven of them builds started by hand (1,490 runs listed), and the one automatic test runs only on pull requests that touch `kcpp_adapters/AutoGuess.json`. The `tests` folder holds 460 lines of Python that no workflow runs on a push. We didn't check the outcome of individual runs (10 of 25). 524 open issues and 5 open pull requests with no stale bot. The 24 newest open issues, from 9 September to 8 October 2026, each have at least one comment, and they include hangs and GPU regressions between 1.119 and 1.121 (16 of 25). Sequential 1.x version numbers with notes on every release, and 1.122 calls out a breaking change to `koboldcpp.sh` for package maintainers and the removal of the pipeline-parallel flag. No changelog file and no stated semver rule (9 of 15). Version 1.122.1 (15)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 68,
            "points": 11.05,
            "reason": "An OpenAPI 3.0.3 document is served by the program at `/api?json=1` and published at lite.koboldai.net, with 53 paths and 54 operations. Its `info.version` still reads 2025.06.03, it declares no security scheme, and the Ollama, ComfyUI, XTTS and `/mcp` routes are missing from it (20 of 25). koboldcpp.net/llms.txt links abridged and full documentation sets for the community site, and the wiki is one Markdown page of 1,261 lines. Neither is an API reference (8 of 10). 52 of 54 operations carry a description, some with limits such as abort and polling not working when several requests are queued. The OpenAI and Anthropic routes point to those vendors' own documentation (13 of 20). The generate input lists 42 typed properties with minimums and only `prompt` required, but the whole document has two enums and several response schemas are empty objects (9 of 15). 52 of 54 operations have an example. Only 503 is documented as an error, on two operations, and the 401 and `bad_input` shapes the source returns are absent (8 of 15). Release notes on GitHub for every version and `/api/extra/version` reports the running version, with no separate API changelog and a stale version label in the document (10 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 63,
            "points": 10.24,
            "reason": "Read for an API. `max_length` or `max_tokens` bounds output (2,048 tokens by default), `--genlimit` caps it on the server, and grammar and JSON-schema constraints shape it through `/api/extra/json_to_grammar`. There's no field selection on responses (17 of 25). `/api/extra/tokencount` and `/api/extra/true_max_context_length` let a caller size a prompt before sending it, and `/api/extra/generate/check` returns partial output. The model lists aren't paged (14 of 20). Errors come as `detail.msg` and `detail.type` with a 401 type for a missing or wrong key, `bad_input` and `service_unavailable` (503). The optional per-IP rate limit answers 503 with the wait in the message text, with no 429 and no `Retry-After` header, and most of this is undocumented (11 of 20). Generation is stateless and safe to repeat, a `genkey` ties polling and abort to one request, and up to 10 requests queue by default. No retry guidance was found (12 of 20). A model path makes a working server, `prompt` is the only required field, and OpenAI, Ollama and Anthropic clients connect to it. There's no official client library, only a Python example script (9 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 38,
            "points": 6.65,
            "reason": "Read with the tool checklist, credential model first. No credential by default. `--password` sets one shared key, sent as a Bearer token and never read from the query string, with a separate `--adminpassword` for admin routes. Keys have no scopes and change only with a restart, and the key doesn't cover image generation, upscaling, `/sdapi/v1/interrogate` or `/tts_to_audio`, as the `--help` text says (11 of 30). Admin mode, web search, MCP servers and the agent are off by default, the agent asks for confirmation of tool calls unless set to auto or off, and `/api/extra/shutdown` answers only local callers with `--singleinstance`. But with no `--host` the server listens on all routable interfaces, CORS reflects any Origin with credentials and allows private-network requests, so a web page or another machine on the network can call a server with no password (7 of 20). The server returns model output unless web search or MCP tools are on. The wiki lists flags for a public instance and the 1.122 notes tell users to take care when approving tool calls, with no guidance on untrusted content (7 of 15). Prompts and outputs print to the terminal unless `--quiet` is set and `/api/extra/perf` gives timing counters. No per-key record or log file was found (6 of 15). No `SECURITY.md`, security.txt or bug bounty. GitHub private vulnerability reporting is open, and one advisory was published on 29 August 2026 (GHSA-qhvp-gj7g-rw26, Low) with the fix committed on 18 August, though the advisory still lists no patched version (7 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 60,
            "points": 7.5,
            "reason": "Read with the self-hosted rule. No x402, MPP or L402 in the README, the wiki, the API document or the source (0). Free under AGPL-3.0 with no account, key or card, and nothing to buy from the project, so 20, 20 and 20 on the last three lines."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 82,
            "points": 7.18,
            "reason": "Release 1.122.1 on 27 September 2026, 11 days before the check (30). Eight releases since 10 July 2026 (1.117.1, 1.118, 1.118.1, 1.119, 1.120, 1.121, 1.122 and 1.122.1) (20). 524 open issues and 5 open pull requests. All 24 of the newest open issues have a reply, and the README points to GitHub Discussions and a Discord server. One person, Concedo, is the main author of the project's own commits, and reply times on older issues are unchecked (20 of 25). No client library. The official Docker image was last updated on 14 September 2026, before the two newest releases, and has 155,052 pulls (6 of 15). Upstream llama.cpp and stable-diffusion.cpp were merged on 24 September 2026 and builds run on GitHub Actions for five targets, but they are started by hand, `requirements.txt` pins only minimum versions and there's no Dependabot (6 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 49,
            "points": 4.29,
            "note": "editorial 70, provenance 27",
            "reason": "The editorial half. AGPL-3.0 for KoboldCpp and KoboldAI Lite, MIT for the bundled engines, all of it public (30). No privacy policy. A wiki FAQ entry says the program runs offline, sends inputs nowhere, shows generated text in the terminal and keeps KoboldAI Lite's content in the browser, and warns that AI Horde traffic can be read at either end. That agrees with `koboldcpp.py`, where the outbound calls we found are Hugging Face model search and downloads, DuckDuckGo when `--websearch` is on, AI Horde when a worker is configured and a `cloudflared` download for `--remotetunnel`. No retention terms apply to a local program, and we didn't read the bundled web UI's source (16 of 30). Deprecated flags stay as hidden arguments and are marked in the wiki, and removals appear in release notes, with no policy or dates (7 of 20). No telemetry, analytics or update check in `koboldcpp.py`, so nothing to opt out of. The launcher's update button opens the releases page in a browser (17 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Read for an API. `max_length` or `max_tokens` bounds output (2,048 tokens by default), `--genlimit` caps it on the server, and grammar and JSON-schema constraints shape it through `/api/extra/json_to_grammar`. There's no field selection on responses (17 of 25). `/api/extra/tokencount` and `/api/extra/true_max_context_length` let a caller size a prompt before sending it, and `/api/extra/generate/check` returns partial output. The model lists aren't paged (14 of 20). Errors come as `detail.msg` and `detail.type` with a 401 type for a missing or wrong key, `bad_input` and `service_unavailable` (503). The optional per-IP rate limit answers 503 with the wait in the message text, with no 429 and no `Retry-After` header, and most of this is undocumented (11 of 20). Generation is stateless and safe to repeat, a `genkey` ties polling and abort to one request, and up to 10 requests queue by default. No retry guidance was found (12 of 20). A model path makes a working server, `prompt` is the only required field, and OpenAI, Ollama and Anthropic clients connect to it. There's no official client library, only a Python example script (9 of 15).",
            "maintenance": "Release 1.122.1 on 27 September 2026, 11 days before the check (30). Eight releases since 10 July 2026 (1.117.1, 1.118, 1.118.1, 1.119, 1.120, 1.121, 1.122 and 1.122.1) (20). 524 open issues and 5 open pull requests. All 24 of the newest open issues have a reply, and the README points to GitHub Discussions and a Discord server. One person, Concedo, is the main author of the project's own commits, and reply times on older issues are unchecked (20 of 25). No client library. The official Docker image was last updated on 14 September 2026, before the two newest releases, and has 155,052 pulls (6 of 15). Upstream llama.cpp and stable-diffusion.cpp were merged on 24 September 2026 and builds run on GitHub Actions for five targets, but they are started by hand, `requirements.txt` pins only minimum versions and there's no Dependabot (6 of 10).",
            "payments": "Read with the self-hosted rule. No x402, MPP or L402 in the README, the wiki, the API document or the source (0). Free under AGPL-3.0 with no account, key or card, and nothing to buy from the project, so 20, 20 and 20 on the last three lines.",
            "reliability": "Read with the local-software lines, since KoboldCpp runs on the owner's machine with no hosted service. Single-file binaries on GitHub releases for Windows x64, Linux x64 and Apple Silicon macOS, with `nocuda` and `oldpc` variants and the hardware each suits stated in the README and release notes, plus the `koboldai/koboldcpp` Docker image. No package-manager release of the project's own, since the Nix and AUR packages are third-party (18 of 20). Twelve workflows, eleven of them builds started by hand (1,490 runs listed), and the one automatic test runs only on pull requests that touch `kcpp_adapters/AutoGuess.json`. The `tests` folder holds 460 lines of Python that no workflow runs on a push. We didn't check the outcome of individual runs (10 of 25). 524 open issues and 5 open pull requests with no stale bot. The 24 newest open issues, from 9 September to 8 October 2026, each have at least one comment, and they include hangs and GPU regressions between 1.119 and 1.121 (16 of 25). Sequential 1.x version numbers with notes on every release, and 1.122 calls out a breaking change to `koboldcpp.sh` for package maintainers and the removal of the pipeline-parallel flag. No changelog file and no stated semver rule (9 of 15). Version 1.122.1 (15).",
            "schema": "An OpenAPI 3.0.3 document is served by the program at `/api?json=1` and published at lite.koboldai.net, with 53 paths and 54 operations. Its `info.version` still reads 2025.06.03, it declares no security scheme, and the Ollama, ComfyUI, XTTS and `/mcp` routes are missing from it (20 of 25). koboldcpp.net/llms.txt links abridged and full documentation sets for the community site, and the wiki is one Markdown page of 1,261 lines. Neither is an API reference (8 of 10). 52 of 54 operations carry a description, some with limits such as abort and polling not working when several requests are queued. The OpenAI and Anthropic routes point to those vendors' own documentation (13 of 20). The generate input lists 42 typed properties with minimums and only `prompt` required, but the whole document has two enums and several response schemas are empty objects (9 of 15). 52 of 54 operations have an example. Only 503 is documented as an error, on two operations, and the 401 and `bad_input` shapes the source returns are absent (8 of 15). Release notes on GitHub for every version and `/api/extra/version` reports the running version, with no separate API changelog and a stale version label in the document (10 of 15).",
            "security": "Read with the tool checklist, credential model first. No credential by default. `--password` sets one shared key, sent as a Bearer token and never read from the query string, with a separate `--adminpassword` for admin routes. Keys have no scopes and change only with a restart, and the key doesn't cover image generation, upscaling, `/sdapi/v1/interrogate` or `/tts_to_audio`, as the `--help` text says (11 of 30). Admin mode, web search, MCP servers and the agent are off by default, the agent asks for confirmation of tool calls unless set to auto or off, and `/api/extra/shutdown` answers only local callers with `--singleinstance`. But with no `--host` the server listens on all routable interfaces, CORS reflects any Origin with credentials and allows private-network requests, so a web page or another machine on the network can call a server with no password (7 of 20). The server returns model output unless web search or MCP tools are on. The wiki lists flags for a public instance and the 1.122 notes tell users to take care when approving tool calls, with no guidance on untrusted content (7 of 15). Prompts and outputs print to the terminal unless `--quiet` is set and `/api/extra/perf` gives timing counters. No per-key record or log file was found (6 of 15). No `SECURITY.md`, security.txt or bug bounty. GitHub private vulnerability reporting is open, and one advisory was published on 29 August 2026 (GHSA-qhvp-gj7g-rw26, Low) with the fix committed on 18 August, though the advisory still lists no patched version (7 of 20).",
            "transparency": "The editorial half. AGPL-3.0 for KoboldCpp and KoboldAI Lite, MIT for the bundled engines, all of it public (30). No privacy policy. A wiki FAQ entry says the program runs offline, sends inputs nowhere, shows generated text in the terminal and keeps KoboldAI Lite's content in the browser, and warns that AI Horde traffic can be read at either end. That agrees with `koboldcpp.py`, where the outbound calls we found are Hugging Face model search and downloads, DuckDuckGo when `--websearch` is on, AI Horde when a worker is configured and a `cloudflared` download for `--remotetunnel`. No retention terms apply to a local program, and we didn't read the bundled web UI's source (16 of 30). Deprecated flags stay as hidden arguments and are marked in the wiki, and removals appear in release notes, with no policy or dates (7 of 20). No telemetry, analytics or update check in `koboldcpp.py`, so nothing to opt out of. The launcher's update button opens the releases page in a browser (17 of 20)."
          },
          "sources": [
            {
              "what": "repository README and header counts",
              "url": "https://github.com/LostRuins/koboldcpp",
              "seen": "2026-10-08"
            },
            {
              "what": "release feed and release notes",
              "url": "https://github.com/LostRuins/koboldcpp/releases",
              "seen": "2026-10-08"
            },
            {
              "what": "server source (flags, password check, CORS, rate limit, routes)",
              "url": "https://github.com/LostRuins/koboldcpp/blob/concedo/koboldcpp.py",
              "seen": "2026-10-08"
            },
            {
              "what": "agent source (tools and confirmation modes)",
              "url": "https://github.com/LostRuins/koboldcpp/blob/concedo/kcpp_agent.py",
              "seen": "2026-10-08"
            },
            {
              "what": "wiki (API, authentication, public instances, privacy, MCP)",
              "url": "https://github.com/LostRuins/koboldcpp/wiki",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI document",
              "url": "https://lite.koboldai.net/koboldcpp_api.json",
              "seen": "2026-10-08"
            },
            {
              "what": "online API reference",
              "url": "https://lite.koboldai.net/koboldcpp_api",
              "seen": "2026-10-08"
            },
            {
              "what": "security overview",
              "url": "https://github.com/LostRuins/koboldcpp/security",
              "seen": "2026-10-08"
            },
            {
              "what": "advisory GHSA-qhvp-gj7g-rw26",
              "url": "https://github.com/LostRuins/koboldcpp/security/advisories/GHSA-qhvp-gj7g-rw26",
              "seen": "2026-10-08"
            },
            {
              "what": "open issues",
              "url": "https://github.com/LostRuins/koboldcpp/issues",
              "seen": "2026-10-08"
            },
            {
              "what": "workflow runs",
              "url": "https://github.com/LostRuins/koboldcpp/actions",
              "seen": "2026-10-08"
            },
            {
              "what": "workflow definitions",
              "url": "https://github.com/LostRuins/koboldcpp/tree/concedo/.github/workflows",
              "seen": "2026-10-08"
            },
            {
              "what": "licence",
              "url": "https://github.com/LostRuins/koboldcpp/blob/concedo/LICENSE.md",
              "seen": "2026-10-08"
            },
            {
              "what": "community site",
              "url": "https://koboldcpp.net/",
              "seen": "2026-10-08"
            },
            {
              "what": "community site llms.txt",
              "url": "https://koboldcpp.net/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "community site links page",
              "url": "https://koboldcpp.net/links/",
              "seen": "2026-10-08"
            },
            {
              "what": "Docker image",
              "url": "https://hub.docker.com/r/koboldai/koboldcpp",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP record for koboldcpp.net",
              "url": "https://rdap.org/domain/koboldcpp.net",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the GitHub REST API refused us for a rate limit, so the repository's creation date and first release date are absent and counts come from the repository's web pages",
            "unchecked: pass or fail state of individual workflow runs",
            "unchecked: reply times on older issues. Only the 24 newest open issues were read",
            "unchecked: what the bundled KoboldAI Lite web UI sends from the browser. Only `koboldcpp.py` and `kcpp_agent.py` were read for outbound calls",
            "unchecked: the contents of koboldcpp.net/llms-small.txt and llms-full.txt, and which version the Docker image of 14 September 2026 contains",
            "No legal entity, terms of service or privacy policy is published, so `provenance.terms` and `provenance.privacy` are empty",
            "The advisory GHSA-qhvp-gj7g-rw26 lists no patched version although the bounds check was committed on 18 August 2026. Which release first carried it was not confirmed (1.120 of 29 August is the first after the commit)",
            "Video generation (WAN 2.2 and others) is claimed in the README and wasn't traced to an API route, so `video.generate` is not in the capabilities"
          ]
        },
        "negative": 0,
        "verdict": "One file runs text, image, speech and music models behind a published OpenAPI 3.0.3 document, with eight releases in 90 days. The server listens on every interface with no password by default, and `--password` leaves the image routes open.",
        "bestFor": "An owner who wants text, image, speech and music models behind one executable with a writing and roleplay interface, and clients that speak the KoboldAI, OpenAI, Ollama or Anthropic formats.",
        "strengths": [
          "OpenAPI 3.0.3 document with 54 operations, served by the program at `/api?json=1` and published at lite.koboldai.net",
          "KoboldAI, OpenAI, Ollama, Anthropic, AUTOMATIC1111 and ComfyUI style routes from one server on port 5001",
          "Eight releases between 10 July and 27 September 2026, each with written notes, and replies on all 24 of the newest open issues",
          "AGPL-3.0, with no telemetry or update check found in `koboldcpp.py` and a wiki statement that inputs are sent nowhere",
          "Admin functions are off by default and take their own `--adminpassword`"
        ],
        "weaknesses": [
          "With no `--host` the server accepts connections on all routable interfaces, and no password is set by default",
          "`--password` covers text routes only. The `--help` text says image endpoints are not secured",
          "CORS reflects any Origin with credentials allowed and permits private-network requests",
          "No `SECURITY.md` or security.txt, and the one advisory (GHSA-qhvp-gj7g-rw26) still lists no patched version",
          "No continuous test run on pushes. Build workflows are started by hand and the only automatic test covers `AutoGuess.json`"
        ],
        "agentNotes": [
          "Start with `--host 127.0.0.1` and `--password`. The default listens on every interface with no key",
          "Send the password as `Authorization: Bearer \u003cpassword\u003e`. It is not read from the query string",
          "Treat 503 as both busy and rate limited. The server never sends 429 or `Retry-After`, and the wait in seconds is in `detail.msg`",
          "Pass `max_length` or `max_tokens`. The default is 2,048 tokens unless `--defaultgenamt` changes it",
          "Send a `genkey` with each generation so `/api/extra/generate/check` and `/api/extra/abort` act on your request and not another caller's"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.5
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 82,
          "payments": 60,
          "reliability": 68,
          "schema": 68,
          "security": 38,
          "transparency": 70
        },
        "provenanceScore": 27
      },
      "connect": {
        "install": "curl -fLo koboldcpp-linux-x64 https://github.com/LostRuins/koboldcpp/releases/latest/download/koboldcpp-linux-x64 \u0026\u0026 chmod +x koboldcpp-linux-x64 \u0026\u0026 ./koboldcpp-linux-x64\n./koboldcpp-linux-x64 --model /path/to/model.gguf   # listens on port 5001",
        "http": "curl --request POST \\\n    --url http://localhost:5001/api/v1/generate \\\n    --header \"Content-Type: application/json\" \\\n    --data '{\"prompt\": \"Niko the kobold stalked carefully down the alley,\", \"max_context_length\": 2048, \"max_length\": 100}'"
      },
      "letme": {
        "capability": "https://letme.dev/inference.local",
        "tool": "https://letme.dev/koboldcpp"
      },
      "notable": [
        "The program serves its own OpenAPI 3.0.3 document at `/api?json=1` and the same file is published online with 53 paths and 54 operations. Its `info.version` reads 2025.06.03 and it has no security scheme (https://lite.koboldai.net/koboldcpp_api.json)",
        "`--host` defaults to empty, which the help text describes as accepting all routable interfaces, and `--password` is unset by default (https://github.com/LostRuins/koboldcpp/blob/concedo/koboldcpp.py)",
        "The `--password` help text says the key is required for all text endpoints and that image endpoints are not secured. The source skips the check for image generation, upscaling, `/sdapi/v1/interrogate` and `/tts_to_audio` (https://github.com/LostRuins/koboldcpp/blob/concedo/koboldcpp.py)",
        "Every response reflects the request's Origin with `access-control-allow-credentials: true` and sends `access-control-allow-private-network: true` (https://github.com/LostRuins/koboldcpp/blob/concedo/koboldcpp.py)",
        "One GitHub security advisory, GHSA-qhvp-gj7g-rw26, published 29 August 2026 and rated Low, a stack buffer overflow in six legacy GPT-J and GPT-2 loaders reached through a crafted model file. A commit of 18 August 2026 adds the bounds check (https://github.com/LostRuins/koboldcpp/security/advisories/GHSA-qhvp-gj7g-rw26)",
        "Release 1.122 of 24 September 2026 added an integrated terminal agent with nine tools (`read`, `write`, `edit`, `shell`, `glob`, `grep`, `web_fetch`, `view_image`, `ask_user`) and three confirmation modes (https://github.com/LostRuins/koboldcpp/releases)",
        "`--mcpfile` loads a Claude Desktop style `mcp.json`, starts stdio or HTTP MCP servers and exposes their tools through a `/mcp` proxy route behind the password (https://github.com/LostRuins/koboldcpp/wiki)",
        "The README warns that `koboldcpp.com` is a fake site unconnected to the project and names GitHub releases as the only official download (https://github.com/LostRuins/koboldcpp)",
        "The wiki says KoboldCpp runs offline and does not send inputs anywhere, and that AI Horde traffic can be read at either end (https://github.com/LostRuins/koboldcpp/wiki)"
      ],
      "area": "models",
      "details": [
        {
          "label": "Interfaces",
          "value": "HTTP server on port 5001 with the KoboldAI Lite web UI at `/`, the llama.cpp web UI at `/lcpp`, StableUI at `/sdui`, a music UI at `/musicui`, interactive API docs at `/api`, a desktop launcher, `--cli` terminal chat and `--agent`"
        },
        {
          "label": "Routes",
          "value": "KoboldAI `/api/v1/generate` and `/api/extra/*` (stream, tokencount, abort, embeddings, transcribe, tts, music, websearch), OpenAI `/v1/chat/completions`, `/v1/completions`, `/v1/responses`, `/v1/embeddings`, `/v1/images/generations`, `/v1/audio/speech`, `/v1/audio/transcriptions` and `/v1/models`, Anthropic `/v1/messages`, Ollama `/api/chat` and `/api/generate`, AUTOMATIC1111 `/sdapi/v1/*`, ComfyUI `/prompt`, and `/mcp`"
        },
        {
          "label": "API contract",
          "value": "OpenAPI 3.0.3 at `/api?json=1` and https://lite.koboldai.net/koboldcpp_api.json, 53 paths and 54 operations. The Ollama, ComfyUI, XTTS and `/mcp` routes are not in it"
        },
        {
          "label": "Credentials",
          "value": "None by default. `--password` or `KCPP_PASSWORD` sets one shared key sent as a Bearer token, for text routes only. `--adminpassword` or `KCPP_ADMINPASSWORD` guards admin routes. No scopes"
        },
        {
          "label": "Network defaults",
          "value": "Listens on all routable interfaces, port 5001. CORS reflects any Origin with credentials. `--ssl` takes a certificate and key. `--remotetunnel` opens a Cloudflare tunnel when asked"
        },
        {
          "label": "Limits",
          "value": "Up to 10 queued requests by default (`--multiuser`), `--ratelimit` seconds between requests per IP (off by default), `--maxrequestsize` 32 MB, `--genlimit` caps output. Busy and rate-limited requests get 503"
        },
        {
          "label": "Models",
          "value": "GGUF text models, legacy GGML `.bin`, vision projectors, Stable Diffusion, SDXL, SD3, Flux and other image models, Whisper, several TTS models, ACE Step music models and embedding models, per the README. No model is bundled"
        },
        {
          "label": "Backends",
          "value": "CPU, CUDA, Vulkan and Metal in the release binaries. ROCm in a rolling Linux build"
        },
        {
          "label": "Install",
          "value": "Single-file binaries on GitHub releases for Windows x64, Linux x64 and Apple Silicon macOS, each with `nocuda` and `oldpc` variants where relevant, the `koboldai/koboldcpp` Docker image, a Colab notebook, and source builds for Android (Termux), OpenBSD and Raspberry Pi"
        },
        {
          "label": "Agent and tools",
          "value": "`--agent` starts a terminal agent with nine tools and confirmation modes on, auto and off. `--mcpfile` connects stdio and HTTP MCP servers. `--websearch` turns on a DuckDuckGo proxy. All off by default"
        },
        {
          "label": "Releases in 90 days",
          "value": "Eight, from 1.117.1 on 10 July to 1.122.1 on 27 September 2026, each with notes on GitHub"
        },
        {
          "label": "Governance",
          "value": "Maintained by LostRuins (Concedo), the main author of the commits on the `concedo` branch that are not upstream llama.cpp work. The Windows binary names KoboldAI as the company. No legal entity is stated"
        },
        {
          "label": "Security record",
          "value": "One GitHub advisory, GHSA-qhvp-gj7g-rw26 (Low, 29 August 2026). No `SECURITY.md`. Private vulnerability reporting is open on GitHub"
        }
      ],
      "provenance": {
        "legalEntity": "",
        "domain": "koboldcpp.net",
        "domainRegistered": "2026-03-18",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/LostRuins/koboldcpp/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No legal entity is named in the repository, the wiki or koboldcpp.net. The maintainer publishes as LostRuins on GitHub and Concedo on Discord, and the Windows binary's version resource gives KoboldAI as the company name.",
          "The project publishes no terms of service and no privacy policy, so both fields are empty. The licence is AGPL-3.0 and the only privacy statement is an FAQ entry in the wiki.",
          "The README calls koboldcpp.net the official community website. RDAP gives its registration date as 2026-03-18 and Cloudflare, Inc. as registrar. The README warns that koboldcpp.com is a fake site.",
          "koboldcpp.net/.well-known/security.txt and koboldai.org/.well-known/security.txt return 404. koboldcpp.net/llms.txt returns a short index that links llms-small.txt and llms-full.txt.",
          "There's no shared hosted endpoint. The server runs on the owner's machine. The online API reference is on lite.koboldai.net."
        ],
        "score": 27,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "not found",
            "points": 0,
            "max": 20,
            "state": "no"
          },
          {
            "check": "Domain age",
            "value": "koboldcpp.net, registered 2026-03-18 (under a year)",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "no hosted endpoint",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Terms of service",
            "value": "nothing hosted, so the AGPL-3.0 for KoboldCpp and KoboldAI Lite. The bundled GGML, llama.cpp and stable-diffusion.cpp code stays under MIT licence stands in",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Privacy policy",
            "value": "nothing hosted, not scored",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/koboldcpp.json"
    },
    "verify": {
      "accepts": "a page on koboldcpp.net or one of its subdomains, or the README of github.com/LostRuins/koboldcpp",
      "badgeUrl": "https://www.anchorterminal.com/badges/koboldcpp.svg",
      "body": {
        "slug": "koboldcpp",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/koboldcpp",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/koboldcpp\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/koboldcpp.svg\" alt=\"KoboldCpp on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![KoboldCpp on Anchor Terminal](https://www.anchorterminal.com/badges/koboldcpp.svg)](https://www.anchorterminal.com/tools/koboldcpp)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/koboldcpp\"\u003eKoboldCpp on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/koboldcpp",
    "json": "https://www.anchorterminal.com/tools/koboldcpp.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/koboldcpp.md",
    "slim": "https://www.anchorterminal.com/tools/koboldcpp.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 60.5/100 · rank #462 of 842 · #5 in Local AI · not agent-ready · confidence medium**\n\n\n## Assessment\n\nOne file runs text, image, speech and music models behind a published OpenAPI 3.0.3 document, with eight releases in 90 days. The server listens on every interface with no password by default, and `--password` leaves the image routes open.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | LostRuins (Concedo) (https://koboldcpp.net) |\n| Kind | HTTP API |\n| Category | Local AI (https://www.anchorterminal.com/categories/local-ai) |\n| Transport | HTTP |\n| Auth | None · No credential by default. `--password` (or the `KCPP_PASSWORD` environment variable) sets one shared key, sent as `Authorization: Bearer`, and the server reads it from the header only. The key guards text routes. Image generation, upscaling, `/sdapi/v1/interrogate` and `/tts_to_audio` skip the check, and the `--help` text says image endpoints are not secured. Admin routes need `--admin`, an `--admindir` and, when set, a separate `--adminpassword`. Keys have no scopes and change only with a restart. With no `--host` the server listens on all routable interfaces, and CORS reflects any Origin with credentials allowed (https://github.com/LostRuins/koboldcpp/blob/concedo/koboldcpp.py). |\n| Pricing | Free (Free · OSS) · Free under AGPL-3.0, with no account, key or card. Nothing is sold by the project. The owner pays for hardware and electricity, and the README links third-party GPU rental (RunPod, SimplePod) and Google Colab as other places to run it. |\n| x402 | No · No x402, MPP or L402 in the README, the wiki, the API document or `koboldcpp.py` (checked 2026-10-08). |\n| Licence | AGPL-3.0 for KoboldCpp and KoboldAI Lite. The bundled GGML, llama.cpp and stable-diffusion.cpp code stays under MIT |\n| Packages | oci: `koboldai/koboldcpp` |\n| Source | https://github.com/LostRuins/koboldcpp |\n| Docs | https://github.com/LostRuins/koboldcpp/wiki |\n| llms.txt | https://koboldcpp.net/llms.txt |\n| Last release | 2026-09-27 |\n| GitHub stars | 11,972 (as of 2026-10-08) |\n| Interfaces | HTTP server on port 5001 with the KoboldAI Lite web UI at `/`, the llama.cpp web UI at `/lcpp`, StableUI at `/sdui`, a music UI at `/musicui`, interactive API docs at `/api`, a desktop launcher, `--cli` terminal chat and `--agent` |\n| Routes | KoboldAI `/api/v1/generate` and `/api/extra/*` (stream, tokencount, abort, embeddings, transcribe, tts, music, websearch), OpenAI `/v1/chat/completions`, `/v1/completions`, `/v1/responses`, `/v1/embeddings`, `/v1/images/generations`, `/v1/audio/speech`, `/v1/audio/transcriptions` and `/v1/models`, Anthropic `/v1/messages`, Ollama `/api/chat` and `/api/generate`, AUTOMATIC1111 `/sdapi/v1/*`, ComfyUI `/prompt`, and `/mcp` |\n| API contract | OpenAPI 3.0.3 at `/api?json=1` and https://lite.koboldai.net/koboldcpp_api.json, 53 paths and 54 operations. The Ollama, ComfyUI, XTTS and `/mcp` routes are not in it |\n| Credentials | None by default. `--password` or `KCPP_PASSWORD` sets one shared key sent as a Bearer token, for text routes only. `--adminpassword` or `KCPP_ADMINPASSWORD` guards admin routes. No scopes |\n| Network defaults | Listens on all routable interfaces, port 5001. CORS reflects any Origin with credentials. `--ssl` takes a certificate and key. `--remotetunnel` opens a Cloudflare tunnel when asked |\n| Limits | Up to 10 queued requests by default (`--multiuser`), `--ratelimit` seconds between requests per IP (off by default), `--maxrequestsize` 32 MB, `--genlimit` caps output. Busy and rate-limited requests get 503 |\n| Models | GGUF text models, legacy GGML `.bin`, vision projectors, Stable Diffusion, SDXL, SD3, Flux and other image models, Whisper, several TTS models, ACE Step music models and embedding models, per the README. No model is bundled |\n| Backends | CPU, CUDA, Vulkan and Metal in the release binaries. ROCm in a rolling Linux build |\n| Install | Single-file binaries on GitHub releases for Windows x64, Linux x64 and Apple Silicon macOS, each with `nocuda` and `oldpc` variants where relevant, the `koboldai/koboldcpp` Docker image, a Colab notebook, and source builds for Android (Termux), OpenBSD and Raspberry Pi |\n| Agent and tools | `--agent` starts a terminal agent with nine tools and confirmation modes on, auto and off. `--mcpfile` connects stdio and HTTP MCP servers. `--websearch` turns on a DuckDuckGo proxy. All off by default |\n| Releases in 90 days | Eight, from 1.117.1 on 10 July to 1.122.1 on 27 September 2026, each with notes on GitHub |\n| Governance | Maintained by LostRuins (Concedo), the main author of the commits on the `concedo` branch that are not upstream llama.cpp work. The Windows binary names KoboldAI as the company. No legal entity is stated |\n| Security record | One GitHub advisory, GHSA-qhvp-gj7g-rw26 (Low, 29 August 2026). No `SECURITY.md`. Private vulnerability reporting is open on GitHub |\n| Capabilities | inference.local, inference.open-weights, agent.mcp-client, embed.text, image.generate, speech.stt, speech.tts, audio.music |\n| Tags | open-source, local, self-hosted, free, no-card, openai-compatible, openapi, llms-txt, docker, agpl, no-telemetry |\n| JSON | https://www.anchorterminal.com/api/v1/tools/koboldcpp.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 68 | 13.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 68 | 11.1 |\n| Agent ergonomics | 13% | 16.2 | 63 | 10.2 |\n| Security \u0026 auth | 14% | 17.5 | 38 | 6.7 |\n| Payments \u0026 pricing | 10% | 12.5 | 60 | 7.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 82 | 7.2 |\n| Transparency \u0026 trust (editorial 70, provenance 27) | 7% | 8.8 | 49 | 4.3 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **60.5 → C** |\n\n### Why each score\n\n- Reliability 68: Read with the local-software lines, since KoboldCpp runs on the owner's machine with no hosted service. Single-file binaries on GitHub releases for Windows x64, Linux x64 and Apple Silicon macOS, with `nocuda` and `oldpc` variants and the hardware each suits stated in the README and release notes, plus the `koboldai/koboldcpp` Docker image. No package-manager release of the project's own, since the Nix and AUR packages are third-party (18 of 20). Twelve workflows, eleven of them builds started by hand (1,490 runs listed), and the one automatic test runs only on pull requests that touch `kcpp_adapters/AutoGuess.json`. The `tests` folder holds 460 lines of Python that no workflow runs on a push. We didn't check the outcome of individual runs (10 of 25). 524 open issues and 5 open pull requests with no stale bot. The 24 newest open issues, from 9 September to 8 October 2026, each have at least one comment, and they include hangs and GPU regressions between 1.119 and 1.121 (16 of 25). Sequential 1.x version numbers with notes on every release, and 1.122 calls out a breaking change to `koboldcpp.sh` for package maintainers and the removal of the pipeline-parallel flag. No changelog file and no stated semver rule (9 of 15). Version 1.122.1 (15).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 68: An OpenAPI 3.0.3 document is served by the program at `/api?json=1` and published at lite.koboldai.net, with 53 paths and 54 operations. Its `info.version` still reads 2025.06.03, it declares no security scheme, and the Ollama, ComfyUI, XTTS and `/mcp` routes are missing from it (20 of 25). koboldcpp.net/llms.txt links abridged and full documentation sets for the community site, and the wiki is one Markdown page of 1,261 lines. Neither is an API reference (8 of 10). 52 of 54 operations carry a description, some with limits such as abort and polling not working when several requests are queued. The OpenAI and Anthropic routes point to those vendors' own documentation (13 of 20). The generate input lists 42 typed properties with minimums and only `prompt` required, but the whole document has two enums and several response schemas are empty objects (9 of 15). 52 of 54 operations have an example. Only 503 is documented as an error, on two operations, and the 401 and `bad_input` shapes the source returns are absent (8 of 15). Release notes on GitHub for every version and `/api/extra/version` reports the running version, with no separate API changelog and a stale version label in the document (10 of 15).\n- Agent ergonomics 63: Read for an API. `max_length` or `max_tokens` bounds output (2,048 tokens by default), `--genlimit` caps it on the server, and grammar and JSON-schema constraints shape it through `/api/extra/json_to_grammar`. There's no field selection on responses (17 of 25). `/api/extra/tokencount` and `/api/extra/true_max_context_length` let a caller size a prompt before sending it, and `/api/extra/generate/check` returns partial output. The model lists aren't paged (14 of 20). Errors come as `detail.msg` and `detail.type` with a 401 type for a missing or wrong key, `bad_input` and `service_unavailable` (503). The optional per-IP rate limit answers 503 with the wait in the message text, with no 429 and no `Retry-After` header, and most of this is undocumented (11 of 20). Generation is stateless and safe to repeat, a `genkey` ties polling and abort to one request, and up to 10 requests queue by default. No retry guidance was found (12 of 20). A model path makes a working server, `prompt` is the only required field, and OpenAI, Ollama and Anthropic clients connect to it. There's no official client library, only a Python example script (9 of 15).\n- Security \u0026 auth 38: Read with the tool checklist, credential model first. No credential by default. `--password` sets one shared key, sent as a Bearer token and never read from the query string, with a separate `--adminpassword` for admin routes. Keys have no scopes and change only with a restart, and the key doesn't cover image generation, upscaling, `/sdapi/v1/interrogate` or `/tts_to_audio`, as the `--help` text says (11 of 30). Admin mode, web search, MCP servers and the agent are off by default, the agent asks for confirmation of tool calls unless set to auto or off, and `/api/extra/shutdown` answers only local callers with `--singleinstance`. But with no `--host` the server listens on all routable interfaces, CORS reflects any Origin with credentials and allows private-network requests, so a web page or another machine on the network can call a server with no password (7 of 20). The server returns model output unless web search or MCP tools are on. The wiki lists flags for a public instance and the 1.122 notes tell users to take care when approving tool calls, with no guidance on untrusted content (7 of 15). Prompts and outputs print to the terminal unless `--quiet` is set and `/api/extra/perf` gives timing counters. No per-key record or log file was found (6 of 15). No `SECURITY.md`, security.txt or bug bounty. GitHub private vulnerability reporting is open, and one advisory was published on 29 August 2026 (GHSA-qhvp-gj7g-rw26, Low) with the fix committed on 18 August, though the advisory still lists no patched version (7 of 20).\n- Payments \u0026 pricing 60: Read with the self-hosted rule. No x402, MPP or L402 in the README, the wiki, the API document or the source (0). Free under AGPL-3.0 with no account, key or card, and nothing to buy from the project, so 20, 20 and 20 on the last three lines.\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 82: Release 1.122.1 on 27 September 2026, 11 days before the check (30). Eight releases since 10 July 2026 (1.117.1, 1.118, 1.118.1, 1.119, 1.120, 1.121, 1.122 and 1.122.1) (20). 524 open issues and 5 open pull requests. All 24 of the newest open issues have a reply, and the README points to GitHub Discussions and a Discord server. One person, Concedo, is the main author of the project's own commits, and reply times on older issues are unchecked (20 of 25). No client library. The official Docker image was last updated on 14 September 2026, before the two newest releases, and has 155,052 pulls (6 of 15). Upstream llama.cpp and stable-diffusion.cpp were merged on 24 September 2026 and builds run on GitHub Actions for five targets, but they are started by hand, `requirements.txt` pins only minimum versions and there's no Dependabot (6 of 10).\n- Transparency \u0026 trust 49: The editorial half. AGPL-3.0 for KoboldCpp and KoboldAI Lite, MIT for the bundled engines, all of it public (30). No privacy policy. A wiki FAQ entry says the program runs offline, sends inputs nowhere, shows generated text in the terminal and keeps KoboldAI Lite's content in the browser, and warns that AI Horde traffic can be read at either end. That agrees with `koboldcpp.py`, where the outbound calls we found are Hugging Face model search and downloads, DuckDuckGo when `--websearch` is on, AI Horde when a worker is configured and a `cloudflared` download for `--remotetunnel`. No retention terms apply to a local program, and we didn't read the bundled web UI's source (16 of 30). Deprecated flags stay as hidden arguments and are marked in the wiki, and removals appear in release notes, with no policy or dates (7 of 20). No telemetry, analytics or update check in `koboldcpp.py`, so nothing to opt out of. The launcher's update button opens the releases page in a browser (17 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/koboldcpp.md (JSON https://www.anchorterminal.com/fixes/koboldcpp.json)\n\n### What we couldn't check\n\n- unchecked: the GitHub REST API refused us for a rate limit, so the repository's creation date and first release date are absent and counts come from the repository's web pages\n- unchecked: pass or fail state of individual workflow runs\n- unchecked: reply times on older issues. Only the 24 newest open issues were read\n- unchecked: what the bundled KoboldAI Lite web UI sends from the browser. Only `koboldcpp.py` and `kcpp_agent.py` were read for outbound calls\n- unchecked: the contents of koboldcpp.net/llms-small.txt and llms-full.txt, and which version the Docker image of 14 September 2026 contains\n- No legal entity, terms of service or privacy policy is published, so `provenance.terms` and `provenance.privacy` are empty\n- The advisory GHSA-qhvp-gj7g-rw26 lists no patched version although the bounds check was committed on 18 August 2026. Which release first carried it was not confirmed (1.120 of 29 August is the first after the commit)\n- Video generation (WAN 2.2 and others) is claimed in the README and wasn't traced to an API route, so `video.generate` is not in the capabilities\n\n### Sources\n\n- repository README and header counts: \u003chttps://github.com/LostRuins/koboldcpp\u003e (seen 2026-10-08)\n- release feed and release notes: \u003chttps://github.com/LostRuins/koboldcpp/releases\u003e (seen 2026-10-08)\n- server source (flags, password check, CORS, rate limit, routes): \u003chttps://github.com/LostRuins/koboldcpp/blob/concedo/koboldcpp.py\u003e (seen 2026-10-08)\n- agent source (tools and confirmation modes): \u003chttps://github.com/LostRuins/koboldcpp/blob/concedo/kcpp_agent.py\u003e (seen 2026-10-08)\n- wiki (API, authentication, public instances, privacy, MCP): \u003chttps://github.com/LostRuins/koboldcpp/wiki\u003e (seen 2026-10-08)\n- OpenAPI document: \u003chttps://lite.koboldai.net/koboldcpp_api.json\u003e (seen 2026-10-08)\n- online API reference: \u003chttps://lite.koboldai.net/koboldcpp_api\u003e (seen 2026-10-08)\n- security overview: \u003chttps://github.com/LostRuins/koboldcpp/security\u003e (seen 2026-10-08)\n- advisory GHSA-qhvp-gj7g-rw26: \u003chttps://github.com/LostRuins/koboldcpp/security/advisories/GHSA-qhvp-gj7g-rw26\u003e (seen 2026-10-08)\n- open issues: \u003chttps://github.com/LostRuins/koboldcpp/issues\u003e (seen 2026-10-08)\n- workflow runs: \u003chttps://github.com/LostRuins/koboldcpp/actions\u003e (seen 2026-10-08)\n- workflow definitions: \u003chttps://github.com/LostRuins/koboldcpp/tree/concedo/.github/workflows\u003e (seen 2026-10-08)\n- licence: \u003chttps://github.com/LostRuins/koboldcpp/blob/concedo/LICENSE.md\u003e (seen 2026-10-08)\n- community site: \u003chttps://koboldcpp.net/\u003e (seen 2026-10-08)\n- community site llms.txt: \u003chttps://koboldcpp.net/llms.txt\u003e (seen 2026-10-08)\n- community site links page: \u003chttps://koboldcpp.net/links/\u003e (seen 2026-10-08)\n- Docker image: \u003chttps://hub.docker.com/r/koboldai/koboldcpp\u003e (seen 2026-10-08)\n- RDAP record for koboldcpp.net: \u003chttps://rdap.org/domain/koboldcpp.net\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 27/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | not found | 0/20 |\n| Domain age | koboldcpp.net, registered 2026-03-18 (under a year) | 0/15 |\n| Endpoint on the vendor's domain | no hosted endpoint | n/a |\n| Terms of service | nothing hosted, so the AGPL-3.0 for KoboldCpp and KoboldAI Lite. The bundled GGML, llama.cpp and stable-diffusion.cpp code stays under MIT licence stands in | 10/10 |\n| Privacy policy | nothing hosted, not scored | n/a |\n| Status page | not found | 0/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nNo legal entity is named in the repository, the wiki or koboldcpp.net. The maintainer publishes as LostRuins on GitHub and Concedo on Discord, and the Windows binary's version resource gives KoboldAI as the company name.\n\nThe project publishes no terms of service and no privacy policy, so both fields are empty. The licence is AGPL-3.0 and the only privacy statement is an FAQ entry in the wiki.\n\nThe README calls koboldcpp.net the official community website. RDAP gives its registration date as 2026-03-18 and Cloudflare, Inc. as registrar. The README warns that koboldcpp.com is a fake site.\n\nkoboldcpp.net/.well-known/security.txt and koboldai.org/.well-known/security.txt return 404. koboldcpp.net/llms.txt returns a short index that links llms-small.txt and llms-full.txt.\n\nThere's no shared hosted endpoint. The server runs on the owner's machine. The online API reference is on lite.koboldai.net.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service**. Nothing is hosted by the vendor, so there are no terms of service to read. The AGPL-3.0 for KoboldCpp and KoboldAI Lite. The bundled GGML, llama.cpp and stable-diffusion.cpp code stays under MIT licence stands in and the check scores in full.\n\n\n**Privacy policy**. Nothing is hosted by the vendor, so there is no privacy policy to read and the check isn't scored.\n\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- OpenAPI 3.0.3 document with 54 operations, served by the program at `/api?json=1` and published at lite.koboldai.net\n- KoboldAI, OpenAI, Ollama, Anthropic, AUTOMATIC1111 and ComfyUI style routes from one server on port 5001\n- Eight releases between 10 July and 27 September 2026, each with written notes, and replies on all 24 of the newest open issues\n- AGPL-3.0, with no telemetry or update check found in `koboldcpp.py` and a wiki statement that inputs are sent nowhere\n- Admin functions are off by default and take their own `--adminpassword`\n\n## Weaknesses\n\n- With no `--host` the server accepts connections on all routable interfaces, and no password is set by default\n- `--password` covers text routes only. The `--help` text says image endpoints are not secured\n- CORS reflects any Origin with credentials allowed and permits private-network requests\n- No `SECURITY.md` or security.txt, and the one advisory (GHSA-qhvp-gj7g-rw26) still lists no patched version\n- No continuous test run on pushes. Build workflows are started by hand and the only automatic test covers `AutoGuess.json`\n\n## Before you call it (notes for agents)\n\n1. Start with `--host 127.0.0.1` and `--password`. The default listens on every interface with no key\n2. Send the password as `Authorization: Bearer \u003cpassword\u003e`. It is not read from the query string\n3. Treat 503 as both busy and rate limited. The server never sends 429 or `Retry-After`, and the wait in seconds is in `detail.msg`\n4. Pass `max_length` or `max_tokens`. The default is 2,048 tokens unless `--defaultgenamt` changes it\n5. Send a `genkey` with each generation so `/api/extra/generate/check` and `/api/extra/abort` act on your request and not another caller's\n\n## Connect\n\nInstall:\n\n```bash\ncurl -fLo koboldcpp-linux-x64 https://github.com/LostRuins/koboldcpp/releases/latest/download/koboldcpp-linux-x64 \u0026\u0026 chmod +x koboldcpp-linux-x64 \u0026\u0026 ./koboldcpp-linux-x64\n./koboldcpp-linux-x64 --model /path/to/model.gguf   # listens on port 5001\n```\n\nFirst request:\n\n```bash\ncurl --request POST \\\n    --url http://localhost:5001/api/v1/generate \\\n    --header \"Content-Type: application/json\" \\\n    --data '{\"prompt\": \"Niko the kobold stalked carefully down the alley,\", \"max_context_length\": 2048, \"max_length\": 100}'\n```\n\nThrough letme (picks today, calling later): https://letme.dev/koboldcpp. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| LocalAI | B | 68 | 216 | inference.local, inference.open-weights, agent.mcp-client, embed.text, speech.stt, speech.tts, image.generate | no | https://www.anchorterminal.com/tools/localai.md |\n| Lemonade | B | 63.8 | 336 | inference.local, inference.open-weights, embed.text, speech.stt, speech.tts, image.generate | no | https://www.anchorterminal.com/tools/lemonade.md |\n| DeepInfra | B | 63 | 371 | inference.open-weights, embed.text, image.generate, speech.stt, speech.tts | no | https://www.anchorterminal.com/tools/deepinfra.md |\n| TextGen | E | 45.1 | 775 | inference.local, inference.open-weights, agent.mcp-client, embed.text, image.generate | no | https://www.anchorterminal.com/tools/text-generation-webui.md |\n| Foundry Local | C | 60.5 | 461 | inference.local, inference.open-weights, embed.text, speech.stt | no | https://www.anchorterminal.com/tools/foundry-local.md |\n| llama.cpp | C | 60.2 | 476 | inference.local, inference.open-weights, embed.text, agent.mcp-client | no | https://www.anchorterminal.com/tools/llama-cpp.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The program serves its own OpenAPI 3.0.3 document at `/api?json=1` and the same file is published online with 53 paths and 54 operations. Its `info.version` reads 2025.06.03 and it has no security scheme (source: \u003chttps://lite.koboldai.net/koboldcpp_api.json\u003e)\n- `--host` defaults to empty, which the help text describes as accepting all routable interfaces, and `--password` is unset by default (source: \u003chttps://github.com/LostRuins/koboldcpp/blob/concedo/koboldcpp.py\u003e)\n- The `--password` help text says the key is required for all text endpoints and that image endpoints are not secured. The source skips the check for image generation, upscaling, `/sdapi/v1/interrogate` and `/tts_to_audio` (source: \u003chttps://github.com/LostRuins/koboldcpp/blob/concedo/koboldcpp.py\u003e)\n- Every response reflects the request's Origin with `access-control-allow-credentials: true` and sends `access-control-allow-private-network: true` (source: \u003chttps://github.com/LostRuins/koboldcpp/blob/concedo/koboldcpp.py\u003e)\n- One GitHub security advisory, GHSA-qhvp-gj7g-rw26, published 29 August 2026 and rated Low, a stack buffer overflow in six legacy GPT-J and GPT-2 loaders reached through a crafted model file. A commit of 18 August 2026 adds the bounds check (source: \u003chttps://github.com/LostRuins/koboldcpp/security/advisories/GHSA-qhvp-gj7g-rw26\u003e)\n- Release 1.122 of 24 September 2026 added an integrated terminal agent with nine tools (`read`, `write`, `edit`, `shell`, `glob`, `grep`, `web_fetch`, `view_image`, `ask_user`) and three confirmation modes (source: \u003chttps://github.com/LostRuins/koboldcpp/releases\u003e)\n- `--mcpfile` loads a Claude Desktop style `mcp.json`, starts stdio or HTTP MCP servers and exposes their tools through a `/mcp` proxy route behind the password (source: \u003chttps://github.com/LostRuins/koboldcpp/wiki\u003e)\n- The README warns that `koboldcpp.com` is a fake site unconnected to the project and names GitHub releases as the only official download (source: \u003chttps://github.com/LostRuins/koboldcpp\u003e)\n- The wiki says KoboldCpp runs offline and does not send inputs anywhere, and that AI Horde traffic can be read at either end (source: \u003chttps://github.com/LostRuins/koboldcpp/wiki\u003e)\n\n## Compare\n\n- [AnythingLLM vs KoboldCpp](https://www.anchorterminal.com/compare/anythingllm-vs-koboldcpp.md): D 53.3 vs C 60.5\n- [Docker Model Runner vs KoboldCpp](https://www.anchorterminal.com/compare/docker-model-runner-vs-koboldcpp.md): C 57.1 vs C 60.5\n- [Foundry Local vs KoboldCpp](https://www.anchorterminal.com/compare/foundry-local-vs-koboldcpp.md): C 60.5 vs C 60.5\n- [Core vs KoboldCpp](https://www.anchorterminal.com/compare/ghost-core-vs-koboldcpp.md): F 7.3 vs C 60.5\n- [GPT4All vs KoboldCpp](https://www.anchorterminal.com/compare/gpt4all-vs-koboldcpp.md): F 36.2 vs C 60.5\n- [Jan vs KoboldCpp](https://www.anchorterminal.com/compare/jan-vs-koboldcpp.md): D 51.3 vs C 60.5\n- [Khoj vs KoboldCpp](https://www.anchorterminal.com/compare/khoj-vs-koboldcpp.md): E 38.5 vs C 60.5\n- [KoboldCpp vs Lemonade](https://www.anchorterminal.com/compare/koboldcpp-vs-lemonade.md): C 60.5 vs B 63.8\n- [KoboldCpp vs llama.cpp](https://www.anchorterminal.com/compare/koboldcpp-vs-llama-cpp.md): C 60.5 vs C 60.2\n- [KoboldCpp vs LM Studio](https://www.anchorterminal.com/compare/koboldcpp-vs-lm-studio.md): C 60.5 vs C 57.8\n- [KoboldCpp vs LocalAI](https://www.anchorterminal.com/compare/koboldcpp-vs-localai.md): C 60.5 vs B 68\n- [KoboldCpp vs MLX LM](https://www.anchorterminal.com/compare/koboldcpp-vs-mlx-lm.md): C 60.5 vs D 52.2\n- [KoboldCpp vs Ollama](https://www.anchorterminal.com/compare/koboldcpp-vs-ollama.md): C 60.5 vs C 56.3\n- [KoboldCpp vs Open WebUI](https://www.anchorterminal.com/compare/koboldcpp-vs-open-webui.md): C 60.5 vs D 51.8\n- [KoboldCpp vs screenpipe](https://www.anchorterminal.com/compare/koboldcpp-vs-screenpipe.md): C 60.5 vs C 60.8\n- [KoboldCpp vs TextGen](https://www.anchorterminal.com/compare/koboldcpp-vs-text-generation-webui.md): C 60.5 vs E 45.1\n- [KoboldCpp vs Underdog](https://www.anchorterminal.com/compare/koboldcpp-vs-underdog.md): C 60.5 vs F 29.5\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on koboldcpp.net or one of its subdomains, or the README of github.com/LostRuins/koboldcpp. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"koboldcpp\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/koboldcpp\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/koboldcpp.svg\" alt=\"KoboldCpp on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![KoboldCpp on Anchor Terminal](https://www.anchorterminal.com/badges/koboldcpp.svg)](https://www.anchorterminal.com/tools/koboldcpp)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/koboldcpp\"\u003eKoboldCpp on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say KoboldCpp is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/koboldcpp-dark.png\n- Light: https://www.anchorterminal.com/assets/share/koboldcpp-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Local AI",
        "url": "https://www.anchorterminal.com/categories/local-ai"
      },
      {
        "name": "KoboldCpp",
        "url": ""
      }
    ],
    "description": "Open-source program for running GGUF models on the owner's own computer, built on llama.cpp. One executable serves a web interface and KoboldAI, OpenAI, Ollama and Anthropic compatible APIs on port 5001.",
    "facts": [
      "rank #462 of 842",
      "None auth",
      "0 desk reviews"
    ],
    "h1": "KoboldCpp",
    "image": "https://www.anchorterminal.com/assets/og/tools-koboldcpp.png",
    "path": "/tools/koboldcpp",
    "published": "2026-10-01",
    "section": "tools",
    "title": "KoboldCpp review for AI agents, grade C (60.5/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/koboldcpp"
  },
  "tokens": {
    "markdown": 7600,
    "slim": 1930
  },
  "version": 1
}
