Open WebUI vs LibreChat vs AnythingLLM: Open WebUI has the deepest admin controls (groups, LDAP, SCIM and an audit log) under a licence that limits rebranding above 50 users. LibreChat is MIT-licensed and strongest on multi-provider chat, agents and MCP. AnythingLLM is the quickest route to chatting with documents, as a desktop app or a Docker server for small teams.
All three projects give staff a browser-based assistant in front of models you choose, whether they run on your own GPUs or come from an approved provider. They overlap heavily, so the useful comparison is in the details an IT team inherits: licence terms, sign-in, roles, document handling, tool access and logging. Everything below comes from each project’s documentation, licence file and GitHub repository, checked on 2 October 2026. All three ship frequent releases, so re-check before you standardise.
If you are still deciding whether to assemble a chat stack at all, start with the three ways to build an internal ChatGPT. The chat interface also needs a model server behind it; the inference server comparison covers that layer.
The three projects at a glance
| Open WebUI | LibreChat | AnythingLLM | |
|---|---|---|---|
| Maintainer | Open WebUI Inc. | ClickHouse, which acquired it in November 2025 | Mintplex Labs |
| Licence | Open WebUI License: BSD-style terms plus a branding clause | MIT | MIT |
| Latest release (verified October 2026) | v0.11.4, 21 September 2026 | v0.8.8, 30 September 2026 | v1.17.0, 1 October 2026 |
| Strongest at | Administration and shared knowledge bases | Multi-provider chat, agents and MCP | Quick document chat for one person or a small team |
| Ways to run | Docker, pip, Helm chart, desktop app | Docker, npm, Helm chart | Desktop app, Docker, cloud templates; Kubernetes and Helm files in the repo |
| Multi-user | Yes | Yes | Docker version only |
The model layer rarely decides between them. Open WebUI describes itself as built to run entirely offline and supports Ollama and OpenAI-compatible APIs. LibreChat accepts any OpenAI-compatible API and lists Ollama among its local options, and AnythingLLM supports Ollama, LM Studio, LocalAI and generic OpenAI-compatible services.
Licences: what you may change and rebrand
Open WebUI moved from MIT to BSD-3-Clause in January 2025, then to its own licence in April 2025. Clause 4 of the current LICENSE prohibits altering, removing, obscuring or replacing any “Open WebUI” branding, with three exceptions:
- Deployments with no more than 50 end users, meaning people with direct access, in any rolling 30-day period.
- Specific prior written permission from the copyright holder.
- A signed enterprise licence that expressly permits the change.
The licence page dates the clause to version 0.6.6 (19 April 2025). The LICENSE file was reworded again on 14 April 2026, and the documentation page still describes an older exception for code contributors (verified October 2026). Read the file in the release you deploy rather than the summary. Code from before the change keeps its earlier licence, as listed in LICENSE_HISTORY.
LibreChat is MIT-licensed. When ClickHouse acquired it on 4 November 2025, it said LibreChat remains fully open source under its existing MIT licence. Two companion projects carry different terms: the standalone Admin Panel for managing users, groups and roles is AGPL-3.0, and the code interpreter service is Apache-2.0.
AnythingLLM is MIT-licensed. Its README notes anonymous telemetry, which you switch off by setting DISABLE_TELEMETRY to true.
Sign-in, SSO and roles
| Open WebUI | LibreChat | AnythingLLM | |
|---|---|---|---|
| OAuth and OpenID Connect | Google, Microsoft and GitHub built in, plus one generic OIDC provider at a time | OAuth2 social logins; OIDC providers including Microsoft Entra ID, Keycloak, Auth0 and AWS Cognito | None native; Simple SSO issues single-use login links through the API |
| SAML | – | Yes, switched off automatically when OIDC is on | – |
| LDAP | Yes | Yes | – |
| Header-based login behind a proxy | Yes | – | – |
| SCIM 2.0 provisioning | Yes | – | – |
| Roles | Admin, user and pending; additive permissions; groups synced from OAuth claims | ADMIN and USER plus custom roles; Viewer, Editor and Owner sharing per resource; Entra ID groups synced at login | Admin, manager and default |
A dash means we found no documentation for the feature in October 2026.
Three details matter in practice. Open WebUI’s permissions are additive: if any group grants a permission, the user has it, so you restrict access by leaving groups out rather than by denying. LibreChat’s access control lets owners share agents, prompts and other resources with users, groups or roles. AnythingLLM’s default role can only chat in workspaces it has been added to, which keeps permissions simple but coarse.
Documents and RAG
- Open WebUI has knowledge bases with 13 vector database options, of which ChromaDB and PGVector are officially maintained, and eight document extraction engines, including Apache Tika, Docling and several OCR services. Groups decide who can open a knowledge base. Web search runs through providers you configure, including self-hosted SearXNG.
- LibreChat indexes uploaded files through its RAG API, backed by PostgreSQL with pgvector, and agents can search those files.
- AnythingLLM organises everything into workspaces: a document embedded in a workspace is available to every thread in it. LanceDB and a built-in embedding model are the defaults, with PGVector, Chroma, Qdrant, Milvus, Pinecone and Weaviate among the alternatives.
In all three, access is granted per knowledge base, file or workspace inside the tool. We found no documented way to carry per-document permissions across from SharePoint, Confluence or a file share. That gap does not matter for a team sharing one handbook; it matters a great deal once several departments use one assistant. Our guide to retrieval that respects source permissions covers what that design involves.
Agents, tools and MCP
- Open WebUI has supported the Model Context Protocol natively since v0.6.31, over Streamable HTTP only; its
mcpoproxy turns stdio or SSE servers into OpenAPI endpoints (MCP docs). Its Tools, Functions, Pipes and Filters run arbitrary Python on your server, so treat installing one like deploying code. Pipelines are now marked as legacy. - LibreChat has no-code agents and the broadest MCP support of the three: stdio, SSE and Streamable HTTP, OAuth for MCP servers, and an isolated MCP connection for each user. Its code interpreter can be self-hosted, and Artifacts render React, HTML, SVG and Mermaid output.
- AnythingLLM starts agents with an
@agentdirective and has supported MCP tools since v1.8.0 (April 2025), over stdio, SSE and Streamable HTTP. It uses MCP tools only, not resources, prompts or sampling.
Tool access is also where the serious vulnerabilities have appeared. Each project has published at least one high or critical advisory in the past year:
| Project | Advisory | Severity | Fixed in |
|---|---|---|---|
| Open WebUI | CVE-2025-64496: code injection through SSE events from an external model server (Direct Connections) | High, 7.3 | 0.6.35 |
| LibreChat | CVE-2026-32625: server secrets exfiltrated through MCP server URL injection | Critical, 9.6 | v0.8.4-rc1 |
| AnythingLLM | CVE-2026-48116: remote code execution through argument injection in an agent file-search skill | High, 7.5 | No patched version listed on the advisory (verified October 2026) |
Whichever you choose, watch its GitHub security advisories and keep an upgrade path you can use within days.
Deployment, logging and audit
Open WebUI runs under Docker, Docker Compose, pip or an official Helm chart. Its audit logging is disabled by default; AUDIT_LOG_LEVEL can be set to METADATA, REQUEST or REQUEST_RESPONSE, and entries go to an audit.log file in the data directory. It can also export traces and metrics over OpenTelemetry.
LibreChat deploys with Docker Compose, npm or an official Helm chart. Its logging produces debug logs, enabled by default and rotated every 14 days, and the API server exposes Prometheus metrics at /metrics. Token usage is recorded per transaction by default, and administrators can set per-user token balances.
AnythingLLM ships Docker images and one-click templates for AWS, Google Cloud Run and other hosts, and its repository includes a Kubernetes manifest and a Helm chart. Its event logs record successful and failed logins, messages sent, settings changes and uploads. A developer API and an embeddable chat widget come with the Docker version.
None of the three records, per answer, which document passages the model was shown. For a team that is acceptable; for a regulated use case it is usually the first question an auditor asks.
Open WebUI vs LM Studio
LM Studio comes up in the same searches, but it is a desktop app rather than a shared web interface. One person downloads models, chats with them and attaches documents: short files go into the prompt whole, longer ones through retrieval. Since version 0.3.17 in June 2025 it can also act as an MCP host.
The app has been free for home and work use since July 2025, under terms that limit it to personal and internal business purposes. When LM Studio made it free, it pointed companies that need SSO, model and MCP gating and private collaboration to a separate Enterprise plan (announcement).
The two also combine. LM Studio can serve models on an OpenAI-style endpoint, and Open WebUI can sit in front of any such endpoint, as it can in front of Ollama. Use LM Studio to evaluate models on your own machine, and Open WebUI, LibreChat or AnythingLLM when a group needs accounts and shared knowledge.
When a DIY chat UI stops being enough for a company
Each of these projects can carry a department for a long time. The signs that a company has outgrown one are rarely about the chat window itself:
- Permissions have to follow the source system. When HR files, legal matters and engineering wikis feed one assistant, someone must copy every source’s access list into the tool’s groups by hand and keep it current. A security review will ask what happens on the day a document’s permissions change in SharePoint.
- Auditors want the whole chain. Request logs show that something happened. An auditor asks which person asked, which model version answered, which passages it saw and which tools it called, and rebuilding that from application logs is slow and incomplete.
- More than one team owns the models. When the assistant, agents and internal applications all call models, model choice, quotas and fallbacks need one control point instead of a setting in each front end.
- Tools start acting as well as answering. MCP servers that open tickets or query production databases need grants per role and a record of every call, reviewed by someone other than the person who installed them.
- The service becomes critical. Upgrades, backups, identity changes and incident response then need an owner and a runbook, whichever interface you run.
The private RAG overview explains the retrieval side of that shift in more depth.
How VDF AI fits
VDF AI Chat is a governed alternative to these interfaces that adds the controls from the list above. Connected sources such as SharePoint/OneDrive, Confluence, Jira and Google Drive bring their access lists into the index, and each query is filtered by the asking user’s identity before passages are ranked. Every turn writes an append-only record of the user, agent, model version, retrieved chunk IDs and tool calls, which can be exported to your SIEM.
On-premises, Microsoft Entra ID single sign-on is built in and maps Entra groups to roles. Okta, Keycloak, LDAP directories and other SAML or OIDC providers connect through an SSO-aware reverse proxy. Role-based access control is part of every plan, and the MCP gateway grants each tool to roles and logs every invocation. For licensing, see current pricing.
Sources
- Open WebUI LICENSE, licence page and releases
- Open WebUI documentation: SSO, permissions, knowledge, MCP and hardening and audit logging
- ClickHouse acquires LibreChat
- LibreChat documentation: access control, agents, MCP, RAG API, logging and Helm chart
- LibreChat repository and Admin Panel licence
- AnythingLLM repository and documentation: security and access, configuration and Simple SSO, workspaces, MCP and event logs
- LM Studio: chat with documents, MCP host and free for work
- Security advisories: GHSA-cm35-v4vp-5xvx, GHSA-4pcc-j6m6-wcwx and GHSA-6hrp-7mw6-8v59