Dify
Dify is an open-source platform for building production AI applications: agentic workflows, autonomous agents and RAG knowledge pipelines on one visual canvas, deployable as managed cloud, inside your own VPC, or self-hosted with Docker.
What is Dify?
Dify is a development platform for large language model applications, published by LangGenius, Inc. and released as open source under the Dify Open Source License, a licence derived from Apache 2.0. It gathers four building blocks on a single collaborative canvas. Workflow Studio is a visual editor where teams assemble an application's logic from blocks and prompts: how it retrieves data, makes decisions, calls tools, asks for human input and completes a task. Because that logic stays visible, it can be tested, debugged and handed over instead of being buried in code. Agents reason through a task using approved tools, keep context in memory and stop within defined limits; they run standalone or as a node inside a larger workflow. The Knowledge Pipeline turns files, websites, online documents and drives into searchable knowledge bases, with extraction, cleaning, chunking, indexing and retrieval testing before anything is connected. The Marketplace supplies model providers, tools, data sources and MCP integrations that teams reuse across projects rather than wiring each one from scratch.
The platform is deliberately model-agnostic. It connects to OpenAI, Anthropic, Google Gemini, xAI, DeepSeek and Tongyi, and users may supply their own API keys, in which case interaction data goes directly to the chosen provider. Finished applications publish in one click as a hosted web app, a website embed, an API endpoint or an MCP-compatible tool, while logs, traces, annotations, latency and usage data feed the next iteration.
Three topologies share the same APIs and the same agent runtime. Dify Cloud is the managed service, with a permanently free Sandbox plan and paid tiers. Dify Enterprise runs inside a customer's VPC, on-premises or in an air-gapped network, adding SSO via SAML and OIDC, fine-grained RBAC, SCIM provisioning, tamper-evident audit logs streamed to a SIEM, Helm charts for Kubernetes and Terraform modules for AWS, GCP and Azure. The Community Edition is free and self-hosted through a single Docker command. LangGenius reports more than 280 enterprise customers, over 1.4 million machines running Dify and developers across 175 countries.
What it does
- Build agentic workflows in a visual editor where the execution path stays readable
- Create agents that reason through a task with approved tools, memory and stopping limits
- Turn files, websites, documents and drives into tested, searchable knowledge bases
- Connect any LLM provider, or bring your own API key, and swap models at will
- Publish the same logic as a web app, an embed, an API endpoint or an MCP-compatible tool
- Monitor logs, traces, annotations, latency, cost and errors after release
- Deploy on managed cloud, inside a private VPC, or self-hosted with a single Docker command
When to use Dify / When not to
A quick filter to help you decide if Dify is the right fit.
When to use Dify
- Software and platform engineering teams moving an AI prototype into production without rebuilding their stack
- AI, MLOps and LLMOps engineers who need one runtime across managed cloud, private VPC and air-gapped deployments
- Independent developers and small teams, explicitly targeted by the Professional plan
- Regulated enterprises in banking, pharma, the public sector or manufacturing that require SSO, RBAC, audit logs and data residency
- Business teams without a coding background, who can build their own agents from templates and prompts
When not to use Dify
- People looking for a ready-made consumer chatbot rather than a platform on which to build one
- Mobile-first users: there is no iOS or Android application and no browser extension
- Anyone wanting a model provider, since LangGenius states it does not train or supply its own AI models
- Teams needing published enterprise pricing, as the Enterprise tier is quoted only on request
- Users under 18, who are excluded from the service by the privacy policy
How to use Dify
A typical end-to-end flow, from setup to results.
- Choose a topology: a free Dify Cloud account, or a self-hosted install from the public GitHub repository
- For self-hosting, deploy the Community Edition with a single Docker command
- Create a workspace and invite the teammates who will build alongside you
- Install model providers, tools, data sources and MCP integrations from the Marketplace, or add your own API key
- Start from a template, then adjust the prompt, or assemble the logic block by block in Workflow Studio
- Add forms to collect inputs and variables to pass values between steps, dropping into a code node where business logic demands it
- Build a knowledge base from files, websites, documents or drives, then test retrieval before connecting it
- Give your agent its tools, its memory and the limits at which it must stop
- Test the execution path, then publish in one click as a web app, embed, API endpoint or MCP server
- Watch logs, annotations, latency, cost and errors, and iterate on what is actually running
Pros & Cons
Pros
- Genuinely open source and free to self-host, under a licence derived from Apache 2.0
- The same APIs and agent runtime across managed cloud, private VPC and air-gapped deployments
- Model-agnostic by design, with providers interchangeable and bring-your-own-key supported
- A written commitment not to train on customer data, extended contractually to model sub-processors
- Unusually complete GDPR paperwork, including a fully named Article 27 representative and a data request portal
- Verifiable adoption: 152.1k GitHub stars and named enterprise customers such as Maersk, Novartis and Volvo Cars
- A permanently free Sandbox plan and a 50% education discount on the Professional plan
Cons
- Enterprise pricing is never published; every quote goes through a sales form
- No contact page at all, only third-party forms and a handful of email addresses
- No mobile application and no browser extension
- The free Sandbox plan is tightly capped at 200 message credits, one member, five apps and 50 MB
- The sub-processor list for model providers is referenced three times in the privacy policy but published nowhere
- Website servers sit in the United States, with processing also possible in China through affiliates and providers
- Data retention is expressed as criteria only, with no stated duration
Pricing & Plans
Dify offers a permanently free plan rather than a time-limited trial: the Sandbox tier on Dify Cloud costs nothing and includes 200 message credits, one workspace, one member and five applications. The Community Edition is likewise free and self-hosted without any duration limit. The cheapest paid entry point is the Professional plan at USD 59.00 per workspace per month, or USD 590 per workspace per year, annual billing being advertised as a 17% saving. The Team plan follows at USD 159 per workspace per month, or USD 1,590 per year. Note that these prices are charged per workspace, not per seat. The Enterprise tier is priced on request.
- Sandbox — free — 200 message credits
- 1 workspace
- 1 member
- 5 apps
- 50 knowledge documents
- 50 MB storage
- 3
- 000 trigger events
- Professional — USD 59 per workspace/month or USD 590 per workspace/year — 5
- 000 message credits per month
- 3 members
- 50 apps
- 500 knowledge documents
- 5 GB storage
- priority document processing
- 20
- Team — USD 159 per workspace/month or USD 1
- 590 per workspace/year — 10
- 000 message credits per month
- 50 members
- 200 apps
- 1
- 000 knowledge documents
- 20 GB storage
- Enterprise — custom pricing — scalable private deployment
- commercial licence
- multiple workspaces
- SSO
- negotiated SLAs
- advanced security controls
- official maintenance and professional support
- Community — free — all core features from the public repository
- single workspace
- self-hosted under the Dify Open Source License
Data, GDPR & hosting
A consolidated view of how Dify handles your data.
GDPR overview
Dify never claims GDPR compliance outright. The only statement approaching one sits in the Dify for Education FAQ, which says the education programme is designed to be compliant with COPPA, FERPA and GDPR, an intention rather than an assertion, and limited to that programme. The underlying machinery is nonetheless substantial. The privacy policy, last updated 30 June 2026, devotes a section to the EEA, the UK and Switzerland that sets out a legal basis for each category of data. Transfers outside the EEA rely on the European Commission's Standard Contractual Clauses. An Article 27 representative is named in full, Instant EU GDPR Representative Ltd, with a contact person and a Dublin address, and a dedicated data request portal is published for EEA residents.
Who owns the data?
Under the Terms of Service, everything submitted through the platform is defined as Customer Data and stays with the customer. LangGenius, Inc. acts as data controller for the personal information it collects directly, and as a data processor when it handles personal data on behalf of enterprise customers, a relationship then governed by a separate Data Processing Agreement. The privacy policy names the service providers receiving each category of data, among them Amazon Web Services, Google Workspace, GitHub and Google. LangGenius states plainly that it does not train AI models itself and will not use interaction data for model training, and it contractually forbids the model providers acting as its sub-processors from doing so either.
Reuse rights
Customers keep the right to use what they build and generate: the Terms define Customer Data as content submitted by the customer or its authorised users, and nothing in the published terms requires permission from LangGenius to reuse an application's outputs. Two limits deserve attention. LangGenius reserves the right to use a customer's name and logo factually on its website and in commercial communications, with a written opt-out available at cloud@dify.ai; any broader marketing use, such as a press release or case study, needs prior consent. And when a user supplies their own model API key, interaction data travels straight to that provider, whose own agreement then decides whether it may be used for training, a point on which Dify explicitly declines responsibility.
Data retention & training
Hosting summary
The privacy policy states twice that the website servers are located in the United States, and the Dify for Education page repeats that Dify is hosted on US servers and that user data is stored on US-based servers. Beyond hosting itself, information may be stored and processed in any country where LangGenius, its affiliated companies or its service providers maintain facilities, and the policy names the United States, Australia, Canada, China, the European Economic Area and the United Kingdom. It adds that affiliates, partners, third parties and service providers operate in the United States, the European Economic Area and China. Transfers from the EEA, the UK and Switzerland rely on the European Commission's Standard Contractual Clauses. The named infrastructure providers are Amazon Web Services, Google Workspace, GitHub and Google. Dify Enterprise changes the picture entirely: data stays inside the customer's own VPC, region and perimeter, with bring-your-own-key encryption.
Things to keep in mind
Risks and trade-offs to weigh before adopting Dify.
- Agentic workflows act on their own; without the stopping limits and human-input steps Dify provides, an agent can take costly actions unsupervised
- Visible logic invites trust, but a readable workflow is not a correct one, and teams may skip evaluation because the diagram looks convincing
- Message credits run out and force a switch to your own provider API key, moving both cost and data exposure onto you
- With a bring-your-own-key setup, interaction data goes straight to the chosen model provider, and Dify explicitly declines responsibility for how that provider uses it
- Website servers are in the United States and processing may involve affiliates in China, a transfer chain worth checking against your own obligations
- The referenced sub-processor list is not published, so the model providers touching your data cannot be enumerated from public sources
- Delegating knowledge work to agents can erode the internal expertise needed to judge whether their output is right
Setup & Integrations
Technical difficulty
Two very different levels. On Dify Cloud, setup is minimal: create an account, and there is no infrastructure to manage. The visual builder is presented as drag-and-drop with no new concepts to learn, and three entry levels are offered, from no-code templates through low-code forms and variables to a full code node. Self-hosting the Community Edition needs one Docker command and basic server familiarity. Dify Enterprise is another matter: Helm charts for Kubernetes, Terraform modules for AWS, GCP or Azure, SSO federation and audit streaming to a SIEM all assume a competent infrastructure team.
Deployment
Integrations
Supported languages
Behind Dify
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Is Dify really open source?
Can I run Dify for free?
How much does the first paid plan cost?
Which AI models can I connect?
Will my data be used to train AI models?
Where is my data hosted?
Does Dify provide an API?
Is there a minimum age?
Is there a discount for students or teachers?
What security certifications does Dify hold?
Should you pick Dify?
Dify occupies a clear position: it is the orchestration layer between models, data, tools and the applications a team actually ships. Its strongest argument is continuity. The same product, the same APIs and the same agent runtime carry a project from a free cloud sandbox to an air-gapped deployment, which spares teams the rewrite that usually happens when a prototype meets a security review. Being open source under an Apache 2.0-derived licence, and agnostic about which model provider sits underneath, removes two of the dependencies that make AI projects fragile.
The evidence of adoption is unusually concrete for a young company: 152.1k GitHub stars, named enterprise customers including Maersk, Novartis, Anker, ETS and Volvo Cars, and a USD 30M round raised in 2026. On the governance side, the privacy documentation is more thorough than most, with a named Article 27 representative, Standard Contractual Clauses and an explicit written commitment never to train on customer data.
The reservations are mostly about what is not shown. Enterprise pricing is quoted only on request, there is no contact page anywhere on the site, and the sub-processor list covering model providers is referenced three times in the privacy policy without ever being published. SOC 2 Type II and ISO 27001 are announced on the homepage but no proof page backs them. Retention is described in criteria rather than durations, and processing may reach China through affiliates and providers, which some buyers will want to examine.
Dify suits a technical or business team that wants to industrialise LLM applications without locking itself to a single model vendor, and that can either accept a managed cloud or bring the infrastructure skills self-hosting requires.
- Choosing a selection results in a full page refresh.
- Opens in a new window.