chromadb
Chroma.
Decision gist · record as of 2026-08-14
Yes, with conditions. Chroma is worth installing for vector search applications where you need a managed embedding store with a simple API. Active maintenance, permissive license, and top-5000 popularity are strong signals. However, 28 runtime dependencies create medium install friction, and two known vulnerabilities (GHSA-f4j7-r4q5-qw2c, PYSEC-2026-311) require review before production use. For prototyping, install freely; for production, verify vulnerability impact and assess dependency footprint.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later; onnxruntime and grpcio dependencies may require system libraries on some platforms.
- Medium install friction due to 28 runtime dependencies including onnxruntime, grpcio, and opentelemetry packages.
- Active maintenance with recent commits and regular Monday releases; last release was 101 days ago.
License · maintenance · safety
permissive license (permissive) — Apache 2.0 permissive license allows commercial use, modification, and distribution with minimal restrictions—suitable for most production and proprietary projects.
last release 2026-05-05 (101 days) · last repo commit 2026-08-14 · 29,058 stars
2 known vulnerabilities (OSV.dev, 2026-08-14) · 13,265,337 downloads/mo, #1,290 on PyPI
Alternatives
Verify before relying
pip install chromadb
import chromadb
client = chromadb.Client()
collection = client.create_collection("my-docs")
collection.add(documents=["doc1", "doc2"], ids=["id1", "id2"])
results = collection.query(query_texts=["search query"], n_results=2)- Whether the 28 runtime dependencies create significant bloat or startup-time overhead in typical usage patterns.
- Performance characteristics and scalability limits for in-memory versus persistent/server modes.
- Details on the two known security vulnerabilities (GHSA-f4j7-r4q5-qw2c, PYSEC-2026-311) and their impact.
What it is and what it does
Chroma is a vector database designed to store and search document embeddings with built-in support for metadata filtering and full-text search. It provides a simple four-function API for creating collections, adding documents with automatic tokenization and embedding, and querying by semantic similarity. The package handles the infrastructure layer for AI applications that need to retrieve contextually relevant documents.
The library supports both in-memory prototyping and persistent storage modes, with a client-server architecture available via the command line. It depends on 28 runtime packages including pydantic, onnxruntime, grpcio, and opentelemetry. The project is actively maintained with regular releases and 29058 GitHub stars, though the substantial dependency footprint and two known vulnerabilities warrant attention before production deployment.
Use it for
- Build retrieval-augmented generation systems that fetch relevant documents to augment prompts.
- Implement semantic search over document collections with metadata-based filtering.
- Prototype vector search applications locally before scaling to a hosted service.
- Store and query embeddings from custom embedding models with optional full-text search.
- Add similarity-based recommendation or deduplication logic to data pipelines.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, with conditions.
Chroma is worth installing for vector search applications where you need a managed embedding store with a simple API. Active maintenance, permissive license, and top-5000 popularity are strong signals. However, 28 runtime dependencies create medium install friction, and two known vulnerabilities (GHSA-f4j7-r4q5-qw2c, PYSEC-2026-311) require review before production use. For prototyping, install freely; for production, verify vulnerability impact and assess dependency footprint.
Install
chromadb on PyPI
Before you install
Medium install friction due to 28 runtime dependencies including onnxruntime, grpcio, and opentelemetry packages. Active maintenance with recent commits and regular Monday releases; last release was 101 days ago. Requires Python 3.9 or later.
Requires Python 3.9 or later; onnxruntime and grpcio dependencies may require system libraries on some platforms.
License in practice
Apache 2.0 permissive license allows commercial use, modification, and distribution with minimal restrictions—suitable for most production and proprietary projects.
Quickstart
pip install chromadb
import chromadb
client = chromadb.Client()
collection = client.create_collection("my-docs")
collection.add(documents=["doc1", "doc2"], ids=["id1", "id2"])
results = collection.query(query_texts=["search query"], n_results=2)
Verify before relying
- Whether the 28 runtime dependencies create significant bloat or startup-time overhead in typical usage patterns.
- Performance characteristics and scalability limits for in-memory versus persistent/server modes.
- Details on the two known security vulnerabilities (GHSA-f4j7-r4q5-qw2c, PYSEC-2026-311) and their impact.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | 28 packagesbuildpydanticpydantic-settingspybase64uvicornnumpytyping-extensionsonnxruntimeopentelemetry-apiopentelemetry-exporter-otlp-proto-grpcopentelemetry-sdktokenizerspypikatqdmoverridesimportlib-resourcesgraphlib-backportgrpciobcrypttyperkubernetestenacitypyyamlmmh3orjsonhttpxrichjsonschema |
| Maintenance | Actively maintained 101 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 13,265,337 / month, #1,290 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | 2 GHSA-f4j7-r4q5-qw2c, PYSEC-2026-311 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3 |
Evidence: chromadb-1.5.9-cp39-abi3-macosx_10_12_x86_64.whl; chromadb-1.5.9-cp39-abi3-macosx_11_0_arm64.whl; chromadb-1.5.9-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; chromadb-1.5.9-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; chromadb-1.5.9-cp39-abi3-win_amd64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “AI data infrastructure”
- chromadbChroma is a vector database and search infrastructure that stores,…
- langchain-ociIntegrates LangChain with Oracle Cloud Infrastructure (OCI) services,…
- torchtitantorchtitan is a PyTorch-native platform for training large generative…
Give your agent the search over MCP, or paste the wish link into any chat.
More Database packages
psycopg2-binary is a PostgreSQL database adapter for Python that implements the DB API 2.0 specification, enabling Python applications to connect to and query PostgreSQL databases with thread-safe concurrent operations.
Python client library for connecting to and executing commands against Redis key-value stores, supporting both synchronous and asynchronous operations.
Install it if your application needs to interact with Redis; the only prerequisite is a running Redis server instance.
YDB Python SDK is the official client library for connecting to and querying YDB databases from Python applications.
Install it if you need to connect Python applications to YDB databases.
Connects Python applications to Snowflake data warehouses using the DB API 2.0 specification, enabling SQL queries, data transfers, and warehouse operations.
sqlparse tokenizes SQL text into a tree of statements, clauses, and expressions, and provides functions to split scripts, format queries, and inspect parsed tokens without validating dialect or syntax.
Install it if you need to manipulate, format, or analyze SQL text programmatically.
Provides base adapter protocols and shared functionality that database adapters use to integrate with dbt-core, handling connections, dialect translation, relation caching, and core interface management.
See also chroma-mcp · chromadb-client · langchain-chroma · llama-index-vector-stores-chroma · opentelemetry-instrumentation-chromadb · deeplake · llama-index-vector-stores-qdrant · redisvl · sqlite-vec · nucliadb-utils