# TextGen > Open-source desktop and browser app for running language models on the owner's hardware, formerly text-generation-webui. With --api it serves an OpenAI and Anthropic-compatible local API with tool calling, vision, embeddings and image generation. - Canonical: https://www.anchorterminal.com/tools/text-generation-webui - Markdown: https://www.anchorterminal.com/tools/text-generation-webui.md (~6,550 tokens) - Slim: https://www.anchorterminal.com/tools/text-generation-webui.min.md (~1,530 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/text-generation-webui.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade E · 45.1/100 · rank #775 of 842 · #15 in Local AI · not agent-ready · confidence medium** ## Assessment AGPL-3.0 with no telemetry, and a local API on 127.0.0.1:5000 that checks the Host header, limits CORS to localhost and separates an admin key from the caller's key. No release since v4.9 on 20 May 2026, no code commits since 31 May, no test suite, and ten security advisories in the year, all fixed. ## Facts | Field | Value | | --- | --- | | Vendor | oobabooga (https://github.com/oobabooga) | | Kind | Model platform | | Category | Local AI (https://www.anchorterminal.com/categories/local-ai) | | Transport | HTTP | | Auth | API key · The API takes one optional key from `--api-key`, off by default, sent as `Authorization: Bearer` on the OpenAI routes and as `x-api-key` on `/v1/messages`. A second key from `--admin-key` guards model and LoRA loading, unloading and listing, and equals the API key when unset. Keys are set at launch, have no scopes and change only with a restart. Without `--listen` or `--public-api` the server binds 127.0.0.1, rejects other Host headers and limits CORS to localhost. The web UI has no login unless `--gradio-auth` is set. | | Pricing | Free (Free · OSS) · Free and AGPL-3.0, with no account, card or paid edition. Portable builds and source are on GitHub (checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the README, the docs folder or the API source (checked 2026-10-08). | | Licence | AGPL-3.0 | | Source | https://github.com/oobabooga/textgen | | Docs | https://github.com/oobabooga/textgen/wiki | | llms.txt | not found | | Last release | 2026-05-20 | | GitHub stars | 47,700 (as of 2026-10-08) | | Interfaces | Electron desktop window in the portable builds (Linux, Windows, macOS, with CUDA, Vulkan, ROCm and CPU-only options), a Gradio web UI at 127.0.0.1:7860, and a local HTTP API on port 5000 when `--api` is set | | API routes | `/v1/chat/completions`, `/v1/completions`, `/v1/messages`, `/v1/models`, `/v1/embeddings`, `/v1/images/generations`, `/v1/moderations`, `/v1/audio/transcriptions`, plus `/v1/internal/*` for token counts, logits, stopping generation and loading models and LoRAs | | Auth | Optional `--api-key` and `--admin-key`, off by default, as Bearer or `x-api-key`. Host-header check and localhost-only CORS unless `--listen` or `--public-api` | | Backends | llama.cpp, ik_llama.cpp, Transformers, ExLlamaV3 and TensorRT-LLM. The portable builds run GGUF models only | | Tools and MCP | Five built-in tools in `user_data/tools` (web_search, fetch_webpage, calculate, get_datetime, roll_dice), custom tools as single `.py` files, and MCP servers over HTTP or stdio. Over the API the caller runs the tools | | Telemetry | None, per the README. Gradio analytics are off in the source. A manual Check for updates button calls api.github.com | | Embeddings | `/v1/embeddings` is marked alpha and needs `sentence-transformers`, with all-mpnet-base-v2 by default | | Releases in 90 days | None. v4.0 on 7 March 2026 to v4.9 on 20 May 2026, then nothing | | Former name | text-generation-webui, also known as oobabooga. The repository is now oobabooga/textgen | | Capabilities | inference.local, inference.open-weights, agent.mcp-client, embed.text, image.generate | | Tags | open-source, local, self-hosted, free, no-card, account-free, openai-compatible, open-weights, streaming, mcp, docker, no-telemetry | | JSON | https://www.anchorterminal.com/api/v1/tools/text-generation-webui.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 51 | 10.2 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 61 | 9.9 | | Agent ergonomics | 13% | 16.2 | 50 | 8.1 | | Security & auth | 14% | 17.5 | 40 | 7.0 | | Payments & pricing | 10% | 12.5 | 60 | 7.5 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 24 | 2.1 | | Transparency & trust (editorial 70, provenance 27) | 7% | 8.8 | 49 | 4.3 | | Negative events | up to −15 | up to −15 | 2026-03-18. Two Critical advisories at 9.1. GHSA-jg96-p5p6-q3cv (CVE-2026-35050) let a user of the web UI write Python files through a path traversal in extension settings and run them, in 4.1 and earlier, fixed in 4.1.1. GHSA-4p45-76cc-7p62 let a caller write or delete files through a character name on instances started with `--listen`, fixed in 4.0. Both fixed and published, -2. https://github.com/oobabooga/textgen/security/advisories/GHSA-jg96-p5p6-q3cv 2026-03-18. GHSA-fpwc-4mvr-7jpr (High, 7.1). `/v1/chat/completions` and `/v1/completions` fetched any `image_url` from the server side, so a caller could reach internal addresses, in 4.1 and earlier. Fixed in 4.1.1 and published, -1. https://github.com/oobabooga/textgen/security/advisories/GHSA-fpwc-4mvr-7jpr 2025-10-13 to 2026-04-03. Seven more advisories in the year, four High and three Moderate, among them a file read through an uploaded symbolic link, four path traversals in preset, grammar, template and prompt loading, an SSRF in the superbooga extensions and a Gradio path-check bypass fixed in 4.3. All published with fixes, -1. https://github.com/oobabooga/textgen/security | -4 | | **Total** | | | | **45.1 → E** | ### Why each score - Reliability 51: Read with the local-software lines, since TextGen runs on the owner's machine with no hosted service. Portable builds for Linux, Windows and macOS on GitHub releases, a one-click installer, a venv route for Python 3.9 or later, a Conda route on Python 3.13 and Docker files, but no package on a registry (18 of 20). No test suite was found in the repository, and the seven workflows only build release packages on manual dispatch (3 of 25). 807 open issues and 40 open pull requests, no code commit on `main` or `dev` since 31 May 2026, and the newest open issues we saw (July to October 2026) carry between none and two comments (6 of 25). Versioned tags and GitHub release notes per version that list security fixes and behaviour changes, with no changelog file and no stated semver policy (9 of 15). v4.9 (15). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 61: Read with the API lines. The server is a FastAPI app with default settings, so a running instance serves `/docs` and `/openapi.json` generated from 33 Pydantic classes in `modules/api/typing.py`, and the docs point callers there. No OpenAPI file is published, and we read the source without running the server (17 of 25). No llms.txt. The docs are Markdown files in the repository's docs folder, mirrored to the wiki (4 of 10). The API page is mostly examples with a compatibility table, and 36 fields in `typing.py` carry descriptions (10 of 20). Typed request models with defaults and a few range limits, while `tools` is a list of free-form objects (10 of 15). curl, Python and Node examples for chat, completions, streaming, tool calling, vision, images and model loading, with no error responses documented (9 of 15). A `/v1` prefix and release notes per version, with no changelog file (11 of 15). - Agent ergonomics 50: Read with the API lines. `max_tokens` (512 by default on chat completions), `max_tokens_second`, a token-count route and a `max_tokens` argument on the built-in page fetcher size the output (17 of 25). `/v1/models` lists everything with the loaded model first, with no paging or filters (6 of 20). Errors are JSON in OpenAI's shape (`message`, `type`, `param`) or Anthropic's on `/v1/messages`, with 401, 400 and 422 used, but none are documented (11 of 20). Completions are stateless and safe to repeat, a client disconnect stops generation and `/v1/internal/stop-generation` exists. No retry guidance (7 of 20). A request needs only `messages`, with no model name, but the owner has to launch with `--api` and load a model. No SDK of its own, with OpenAI's Python and Node clients shown in the docs (9 of 15). - Security & auth 40: Read with the tool checklist. One optional key from `--api-key`, off by default, sent as a Bearer token or `x-api-key` and never in a query string, with a separate `--admin-key` for loading and unloading models and LoRAs. No scopes or per-client keys, and a key changes only with a restart (14 of 30). Without `--listen` or `--public-api` the API binds 127.0.0.1, rejects other Host headers and limits CORS to localhost (since v4.9). The chat has a Confirm tool calls setting, off by default, and the web UI has no login unless `--gradio-auth` is set (10 of 20). The built-in page fetcher refuses non-global addresses on every redirect hop. No guidance on injected instructions in web or tool results was found (5 of 15). The docs say the API creates no logs and the server runs with access logs off. `--verbose` prints prompts to the terminal (3 of 15). No SECURITY.md, security.txt or bounty. Ten advisories are published on GitHub with patched versions, one with a CVE (8 of 20). - Payments & pricing 60: Self-hosted rule. No x402, MPP or L402 (0). Free and AGPL-3.0 with no account, card or paid edition, so 20, 20 and 20 on the last three lines. - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 24: v4.9 on 20 May 2026, 141 days before this check (10). No release in the last 90 days (0). No code commit on `main` since 31 May 2026 (one README edit on 17 August) and none on `dev` since 16 May. 807 open issues and 40 open pull requests, and the newest open issues show few or no comments. Comment authors didn't render for our reader, so maintainer replies are unconfirmed (5 of 25). No SDK and no MCP registry entry. Portable builds shipped with each release up to May (5 of 15). A weekly Dependabot config with its update branches unmerged, no test CI, and the bundled llama.cpp last updated on 31 May (4 of 10). - Transparency & trust 49: AGPL-3.0 for the whole repository (30). No privacy policy or terms exist, and there's no hosted service. The README states that the app is fully offline with zero telemetry, external resources or remote update requests, the API page says it creates no logs, and the source turns Gradio analytics off. A Check for updates button calls api.github.com when clicked, which the README's wording doesn't mention (18 of 30). No deprecation policy. Release notes record behaviour changes, and the rename to TextGen left a redirect from the old repository URL (4 of 20). No telemetry to opt out of, and analytics are disabled in `server.py` (18 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (21 items): https://www.anchorterminal.com/fixes/text-generation-webui.md (JSON https://www.anchorterminal.com/fixes/text-generation-webui.json) ### What we couldn't check - Whether development has paused. No release since 20 May 2026 and no code commit since 31 May, with no notice in the README - unchecked: maintainer replies on recent issues. Comment threads didn't render for our reader - unchecked: `/docs` and `/openapi.json` on a running server. We read the FastAPI source and the docs and didn't run it - unchecked: star, issue and pull request counts come from the repository page as our reader saw it. GitHub's API refused us for a shared rate limit - No terms of use or privacy policy exist for the project, so `provenance.terms` and `provenance.privacy` are left out - The developer publishes under a pseudonym and no legal entity is named - The first release date wasn't established, since the clone was shallow ### Sources - repository and README: (seen 2026-10-08) - releases: (seen 2026-10-08) - security tab and advisories: (seen 2026-10-08) - advisory GHSA-jg96-p5p6-q3cv: (seen 2026-10-08) - advisory GHSA-4p45-76cc-7p62: (seen 2026-10-08) - advisory GHSA-fpwc-4mvr-7jpr: (seen 2026-10-08) - advisory GHSA-r2qq-p5wg-gf5g: (seen 2026-10-08) - open issues: (seen 2026-10-08) - API docs (wiki): (seen 2026-10-08) - API docs (source): (seen 2026-10-08) - tool calling and MCP tutorial: (seen 2026-10-08) - API server source: (seen 2026-10-08) - request models: (seen 2026-10-08) - web fetch validation: (seen 2026-10-08) - update check source: (seen 2026-10-08) - workflows: (seen 2026-10-08) - dev branch: (seen 2026-10-08) - licence: (seen 2026-10-08) ## Who's behind it (provenance 27/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | not found | 0/20 | | Domain age | github.com/oobabooga, no registry record we could read | 0/15 | | Endpoint on the vendor's domain | no hosted endpoint | n/a | | Terms of service | nothing hosted, so the AGPL-3.0 licence stands in | 10/10 | | Privacy policy | nothing hosted, not scored | n/a | | Status page | not found | 0/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The project belongs to a developer who publishes as oobabooga. The LICENSE is the AGPL-3.0 text and names no legal entity, and the README acknowledges a grant from Andreessen Horowitz in August 2023. No vendor domain. The README links only the GitHub repository, its wiki, a subreddit, a Substack and a Hugging Face space. No terms of use and no privacy policy were found in the repository, the README or the wiki, so both fields are left out. The README states zero telemetry. No SECURITY.md (the Security tab says none is set up) and no security.txt of the project's own. There's no hosted endpoint. The API answers on the owner's machine, at 127.0.0.1:5000 by default. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service**. Nothing is hosted by the vendor, so there are no terms of service to read. The AGPL-3.0 licence stands in and the check scores in full. **Privacy policy**. Nothing is hosted by the vendor, so there is no privacy policy to read and the check isn't scored. ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - AGPL-3.0, with analytics switched off in the source and a README that states zero telemetry - One server answers `/v1/chat/completions`, `/v1/completions` and Anthropic's `/v1/messages`, with tool calling and streaming - Since v4.9 the API rejects Host headers other than localhost and 127.0.0.1 and limits CORS to localhost unless `--listen` or `--public-api` is set - A separate `--admin-key` guards model and LoRA loading, apart from the `--api-key` callers use - Ten security advisories published on GitHub with patched versions named, the newest on 3 April 2026 ## Weaknesses - No release since v4.9 on 20 May 2026 and no code commit on `main` or `dev` since 31 May 2026 - No test suite. The seven GitHub workflows only build release packages on manual dispatch - 807 open issues and 40 open pull requests, with no SECURITY.md or disclosure address - Two Critical advisories (9.1) published on 18 March 2026, both path traversals in the web UI, fixed in 4.0 and 4.1.1 - The API key is off by default, set only at launch, and has no scopes or per-client keys - No rate limits, error list or published OpenAPI file in the docs. The schema is served only by a running server at `/docs` ## Before you call it (notes for agents) 1. Ask the owner to launch with `--api`. Nothing listens on port 5000 without it, and a model must be loaded first 2. Call `http://127.0.0.1:5000/v1`. Any Host header other than localhost or 127.0.0.1 gets 400 `Invalid host header` unless `--listen` is set 3. Send the key as `Authorization: Bearer` on OpenAI routes and as `x-api-key` on `/v1/messages`. Model loading needs the admin key 4. Read `http://127.0.0.1:5000/docs` or `modules/api/typing.py` for parameters. `max_tokens` defaults to 512 on chat completions 5. Run tool calls yourself. The API returns `finish_reason: "tool_calls"` and executes nothing on the server 6. Use the repository name `oobabooga/textgen`. The old `text-generation-webui` URL redirects ## Connect Install: ```bash git clone https://github.com/oobabooga/textgen cd textgen python -m venv venv source venv/bin/activate pip install -r requirements/portable/requirements.txt --upgrade python server.py --portable --api --auto-launch ``` First request: ```bash curl http://127.0.0.1:5000/v1/chat/completions \ -H "Content-Type: application/json" \ -d '{"messages": [{"role": "user", "content": "Hello!"}], "temperature": 0.6, "top_p": 0.95, "top_k": 20}' ``` ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | LocalAI | B | 68 | 216 | inference.local, inference.open-weights, agent.mcp-client, embed.text, image.generate | no | https://www.anchorterminal.com/tools/localai.md | | KoboldCpp | C | 60.5 | 462 | inference.local, inference.open-weights, agent.mcp-client, embed.text, image.generate | no | https://www.anchorterminal.com/tools/koboldcpp.md | | Lemonade | B | 63.8 | 336 | inference.local, inference.open-weights, embed.text, image.generate | no | https://www.anchorterminal.com/tools/lemonade.md | | llama.cpp | C | 60.2 | 476 | inference.local, inference.open-weights, embed.text, agent.mcp-client | no | https://www.anchorterminal.com/tools/llama-cpp.md | | LM Studio | C | 57.8 | 536 | inference.local, inference.open-weights, agent.mcp-client, embed.text | no | https://www.anchorterminal.com/tools/lm-studio.md | | Docker Model Runner | C | 57.1 | 559 | inference.local, inference.open-weights, embed.text, image.generate | no | https://www.anchorterminal.com/tools/docker-model-runner.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The repository was renamed from oobabooga/text-generation-webui to oobabooga/textgen and the product is now called TextGen. The old URL redirects (source: ) - v4.9 of 20 May 2026 is the latest release. `main` has had one commit since 31 May 2026, a README edit on 17 August, and `dev` stops on 16 May (source: ) - Ten security advisories are published, from 13 October 2025 to 3 April 2026, two of them Critical at 9.1 (GHSA-jg96-p5p6-q3cv, CVE-2026-35050, and GHSA-4p45-76cc-7p62), all with patched versions (source: ) - v4.9 restricted the API's CORS to localhost by default, and the server rejects Host headers other than localhost and 127.0.0.1 unless `--listen` or `--public-api` is set (source: ) - The app is an MCP client for HTTP servers (typed into the chat sidebar) and stdio servers (`user_data/mcp.json`). A Confirm tool calls setting exists and is off by default (source: ) - Gradio analytics are disabled in `server.py`, and the only request to the developer's side found in the source is a Check for updates button that calls api.github.com when clicked (source: ) ## Compare - [AnythingLLM vs TextGen](https://www.anchorterminal.com/compare/anythingllm-vs-text-generation-webui.md): D 53.3 vs E 45.1 - [Docker Model Runner vs TextGen](https://www.anchorterminal.com/compare/docker-model-runner-vs-text-generation-webui.md): C 57.1 vs E 45.1 - [Foundry Local vs TextGen](https://www.anchorterminal.com/compare/foundry-local-vs-text-generation-webui.md): C 60.5 vs E 45.1 - [Core vs TextGen](https://www.anchorterminal.com/compare/ghost-core-vs-text-generation-webui.md): F 7.3 vs E 45.1 - [GPT4All vs TextGen](https://www.anchorterminal.com/compare/gpt4all-vs-text-generation-webui.md): F 36.2 vs E 45.1 - [Jan vs TextGen](https://www.anchorterminal.com/compare/jan-vs-text-generation-webui.md): D 51.3 vs E 45.1 - [Khoj vs TextGen](https://www.anchorterminal.com/compare/khoj-vs-text-generation-webui.md): E 38.5 vs E 45.1 - [KoboldCpp vs TextGen](https://www.anchorterminal.com/compare/koboldcpp-vs-text-generation-webui.md): C 60.5 vs E 45.1 - [Lemonade vs TextGen](https://www.anchorterminal.com/compare/lemonade-vs-text-generation-webui.md): B 63.8 vs E 45.1 - [llama.cpp vs TextGen](https://www.anchorterminal.com/compare/llama-cpp-vs-text-generation-webui.md): C 60.2 vs E 45.1 - [LM Studio vs TextGen](https://www.anchorterminal.com/compare/lm-studio-vs-text-generation-webui.md): C 57.8 vs E 45.1 - [LocalAI vs TextGen](https://www.anchorterminal.com/compare/localai-vs-text-generation-webui.md): B 68 vs E 45.1 - [MLX LM vs TextGen](https://www.anchorterminal.com/compare/mlx-lm-vs-text-generation-webui.md): D 52.2 vs E 45.1 - [Ollama vs TextGen](https://www.anchorterminal.com/compare/ollama-vs-text-generation-webui.md): C 56.3 vs E 45.1 - [Open WebUI vs TextGen](https://www.anchorterminal.com/compare/open-webui-vs-text-generation-webui.md): D 51.8 vs E 45.1 - [screenpipe vs TextGen](https://www.anchorterminal.com/compare/screenpipe-vs-text-generation-webui.md): C 60.8 vs E 45.1 - [TextGen vs Underdog](https://www.anchorterminal.com/compare/text-generation-webui-vs-underdog.md): E 45.1 vs F 29.5 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page under github.com/oobabooga, or the README of github.com/oobabooga/textgen. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "text-generation-webui", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html TextGen on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![TextGen on Anchor Terminal](https://www.anchorterminal.com/badges/text-generation-webui.svg)](https://www.anchorterminal.com/tools/text-generation-webui) ``` Plain link: ```html TextGen on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say TextGen is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/text-generation-webui-dark.png - Light: https://www.anchorterminal.com/assets/share/text-generation-webui-light.png