ComfyUI: installation and getting started locally (2026)
ComfyUI is an open-source interface (GPL-3.0) that generates images and video locally using a node graph. The simplest option is the Desktop application; the portable Windows archive and manual installation are also available. It opens at http://127.0.0.1:8188. Plan on an NVIDIA 8 GB card for SDXL, 12 to 16 GB for Flux in FP8, and install only known extensions: malicious nodes have stolen data, and exposed instances have been hijacked.
ComfyUI is an open-source interface that generates images, and now video, on your own machine by connecting blocks called nodes. As of September 28, 2026, its README announces native support for Stable Diffusion 1.5 and SDXL, as well as Flux.1, Flux.2, Qwen Image, Z-Image, and, for video, Wan 2.2. It has a reputation for being intimidating, especially when you start with a forty-node workflow found on a forum. This guide takes you from installation to your first image on Windows, Mac, or Linux, with only the strictly necessary nodes.
#What is ComfyUI?
ComfyUI is free software (GPL-3.0 license). Its repository was created in January 2023, and it is now maintained by the Comfy Org organization; it has more than 130,000 stars on GitHub. It installs on your computer and opens in the browser at http://127.0.0.1:8188. Computation runs on your graphics card, and the README states that the software core downloads nothing unless you ask it to.
Its distinguishing feature is that it shows the pipeline instead of hiding it. Where a traditional interface offers a text field and a button, ComfyUI displays each step as a node: load the model, encode the prompt, denoise, decode the image, save it. You connect the nodes with wires. Together, they form a workflow that you can save, share, and replay identically.
The README announces a major stable release approximately every two weeks. This detail matters for installation: the Desktop application follows the stable version by default, while the portable version and Git installation follow the latest commits, which, the README warns, can break many extensions.
#The hardware you need
AI images and videos on your own machine, no subscription and no credits: ComfyUI, Flux, Z-Image and Wan 2.2 with ready-to-load workflows, VRAM tiers, LoRA training and the legal frame.
- Lifetime online access
- PDF + files
- Lifetime updates
As with an LLM, graphics card memory determines everything. ComfyUI qualifies the rule, however: its README states that even the largest open models run “relatively fast” with 4 GB of VRAM and 8 GB of RAM, thanks to asynchronous weight loading. That's a claim, not a measurement: the more the weights spill beyond VRAM, the more time the back-and-forth costs. The table therefore starts with what can be verified: the size of the files published on Hugging Face.
| Model family | File sizes | Comfortable VRAM | Cards in our database that are suitable |
|---|---|---|---|
| Stable Diffusion 1.5 | 4.27 GB (v1-5-pruned-emaonly) | 4 to 6 GB | GTX 1660, RTX 2060, RTX 3050 6 GB and above |
| SDXL and its derivatives | 6.94 GB (sd_xl_base_1.0) | 8 GB | RTX 3060, RTX 4060, RTX 5060, RX 7700 XT |
| Z-Image Turbo | 12.3 GB in bf16, plus the Qwen 3 4B encoder (8.04 GB); variants from 4.51 to 6.2 GB | 12 to 16 GB: the model card says it fits in 16 GB | RTX 3060 12 GB, RTX 4070, RTX 5070 Ti, RX 9070 XT |
| Flux.1 dev in FP8 | 17.2 GB (Comfy-Org checkpoint, text encoders included) | 12 to 16 GB | RTX 3060 12 GB, RTX 4070, RTX 5070 Ti, RX 9070 XT |
| Flux.1 dev at full precision | 23.8 GB, plus the text encoders | 24 GB | RTX 3090, RTX 4090, RTX 5090, RX 7900 XTX |
| Video (Wan 2.2 and equivalents) | Depending on the version | 16 to 24 GB and more; below that, quantized and slow versions | RTX 4090, RTX 5090 |
| Mac Apple Silicon (M1 to M4) | Same files as above | Unified memory serves as VRAM: the weights must fit there, along with system headroom | Any M chip; slower than a comparable NVIDIA-class card |
On the hardware side, NVIDIA remains the frictionless path. AMD cards work well on Linux with ROCm, and since January 2026, the ComfyUI team itself has announced that official ROCm support “is now available on the Windows ComfyUI Desktop app, starting with version v0.7.0,” for compatible Radeon cards and Ryzen AI processors. Finally, plan for disk space: a single model weighs 2 to 25 GB, and you quickly accumulate ten or so.
#Three ways to install it
| Method | Who it's for | What you need to know |
|---|---|---|
| ComfyUI Desktop | Almost everyone: the README recommends it to new users | An installer for Windows (an NVIDIA or AMD card recommended), macOS (Apple Silicon), and Linux (AppImage or .deb), downloaded from comfy.org. It follows the stable version by default. |
| Portable Windows version | Those who want to keep everything in one folder or the latest features | The README considers it unsuitable for regular users. Separate archives are available for NVIDIA, AMD, and Intel: extract them with 7-Zip, then double-click run_nvidia_gpu.bat (or run_amd_gpu.bat, run_intel_gpu.bat). It tracks the latest commits. |
| Manual installation | Linux, AMD or Intel cards, Macs with custom configurations, and anyone who wants to control the environment | A Git clone, a Python environment (3.13 is recommended; 3.12 is the fallback), PyTorch suited to your card, and then the project dependencies. |
At launch, the terminal displays the local address to open in the browser. If the terminal reports « Torch not compiled with CUDA enabled », the README says to uninstall torch (pip uninstall torch) and then reinstall it with the command above.
#Managing memory: the options that matter in 2026
VRAM management has changed. In the ComfyUI code, “dynamic VRAM” is enabled by default unless you specify --highvram, --novram, or --cpu, or disable it with --disable-dynamic-vram; the --enable-dynamic-vram help text suggests that some systems don't have it enabled by default. The --lowvram help is explicit: the option does nothing while dynamic VRAM is active. So the old advice to add --lowvram on a 6 GB card no longer applies as written.
- --reserve-vram X
- Reserve X GB of VRAM for the system and other software: useful if the machine is also used for display or an LLM.
- --disable-dynamic-vram
- Falls back to classic loading based on estimates: try this if you experience a memory-related crash.
- --novram and --cpu
- Last resorts: the help describes --novram as the option “when lowvram is not enough” and --cpu as “slow.” Expect a significantly slower generation.
- --listen
- By default, ComfyUI listens only on 127.0.0.1. Without an argument, --listen opens all network interfaces: reserve it for a trusted network; see the security section.
#Where to store models
ComfyUI doesn't include any models. This is the first common stumbling block: the interface opens, you click Run, and an error reports a missing file. Each file type has its own subfolder in the models folder.
- models/checkpoints
- “All-in-one” models such as SDXL: a single .safetensors file contains the diffusion model, text encoder, and VAE. This is the simplest option for getting started.
- models/diffusion_models
- The diffusion model alone, for recent families distributed in separate components (Flux, Z-Image, Wan).
- models/text_encoders
- The encoder that turns your prompt into vectors. Often the largest file after the model itself.
- models/vae
- The decoder that transforms the computation result into a visible image.
- models/loras
- LoRAs: small files that add a style, character, or concept to a base model.
#Reuse models from another interface
If you already have checkpoints with AUTOMATIC1111 or Fooocus, there’s no need to copy them. The README provides an extra_model_paths.yaml.example file at the root of ComfyUI: rename it to extra_model_paths.yaml, specify the paths to the existing folders, and ComfyUI will read them without duplicating them. In the portable Windows archive, this file is in the ComfyUI folder.
#Your first image
- 01Load an official workflowIn the workflow model menu, choose the base image-generation model that matches your VRAM: SDXL from 8 GB, or a recent FP8 model from 12 GB.
- 02Download the proposed filesAllow the downloads. Verify in the terminal that they finish without errors: a network interruption leaves a truncated file that will cause an obscure error later.
- 03Write the promptThe text-encoding node connected to the “positive” input contains the image description. The one connected to “negative” lists what you do not want to see. Most models understand English better.
- 04RunClick Run. The nodes light up one after another. The first generation is slow because the model has to load into VRAM; subsequent generations are much faster.
- 05Retrieve the imageIt appears in the recording node and is located in the output folder. The PNG file contains the complete workflow that produced it.
Three sampling-node settings are enough to get started. The seed determines the image: the same seed and settings produce the same image. The number of steps controls computation time: 20 to 30 for a standard model, 4 to 8 for a “turbo” model. CFG controls prompt fidelity: set it too high, and the image becomes oversaturated and distorted.
#Understand and retrieve workflows
A workflow is a simple JSON file, and ComfyUI embeds it in every image it saves. Drag a PNG produced by ComfyUI into the window, and the complete graph that generated it reloads, along with the prompt, seed, and all settings. The official documentation presents this as one of the two methods for loading its first tutorial. It is the best way to learn.
When a retrieved workflow shows red nodes, it uses extensions you do not have. ComfyUI-Manager lists and installs them. It is now integrated into the main repository, but remains optional: enable it with the --enable-manager option, after installing manager_requirements.txt. Keep it lean: fifty extensions eventually break an installation during the first update.
#Malicious nodes and exposed instances: the real risk
The warning about code execution is not theoretical. On January 10, 2026, an issue in the official repository documented a series of nodes published on the Comfy Registry under the guise of an “Upscaler_4K,” titled “Malicious Distribution of Akira Stealer via 'Upscaler_4K' Custom Nodes in Comfy Registry.” The malicious logic, buried in a scripts folder to evade registry scanners, targeted browser data, cryptocurrency wallets, and Discord tokens on Windows. The issue lists 779 possible installations.
A second risk, independent of registry extensions: exposure to the Internet. In April 2026, The Hacker News reported, based on a Censys report, a campaign targeting publicly accessible ComfyUI instances: more than 1,000 were identified. The scanner exploits custom nodes that execute code without authentication and, if ComfyUI-Manager is present, installs a vulnerable node itself before trying again. The compromised machines mined Monero and Conflux and powered a botnet.
- Before installing an extension
- Use ComfyUI-Manager instead of a link found on a forum, check the installation count and the date of the last update, and avoid any node that promises a shortcut that sounds too good to be true (“magic upscaler,” “unlocking” a commercial model).
- If you use --listen
- Never expose ComfyUI to the Internet without authentication in front of it: a password-protected reverse proxy, or preferably, a VPN. Without this, your machine joins the list of automatically scanned targets.
- To disable online services
- The --disable-api-nodes option disables Comfy's paid API nodes and prevents the interface from communicating with the Internet, according to the command-line help.
- Source: the official report on the Akira Stealer campaign
- Source: The Hacker News on hijacked ComfyUI instances
- Source: the announcement of official ROCm support on Windows
#The mistakes people make in the early days
- Memory error (CUDA out of memory)
- The model or resolution exceeds your VRAM. Reduce the image size, use an FP8 or quantized version, reserve headroom with --reserve-vram, or try --disable-dynamic-vram.
- Black image or colored noise
- Almost always a VAE or text encoder that does not match the model. Start from the official workflow for the relevant family.
- Endless generation
- Check in the terminal that the GPU is detected at startup. If ComfyUI reports running on the CPU, the installed PyTorch version does not match your card.
- Torch not compiled with CUDA enabled
- Uninstall torch (pip uninstall torch), then reinstall it using the command from the README for your card.
- Red nodes when opening a workflow
- Some extensions are missing. Use the manager to install them, then restart ComfyUI.
#Licenses: what you’re allowed to do
ComfyUI is free, but each model has its own license, and one confusion comes up often: the model's license is not the same as the license for the images it produces. Before using an image for a client, product, or advertisement, read the model card for the model that generated it.
| Model | License | What the model card says |
|---|---|---|
| Z-Image Turbo | Apache 2.0 | Permissive license |
| Flux.1 schnell | Apache 2.0 | Personal, scientific, and commercial use permitted |
| Flux.1 dev | Black Forest Labs non-commercial license | The model is non-commercial, but generated images may be used for personal, scientific, and commercial purposes “as described” in the license: read it |
| SDXL | OpenRAIL++ | Allowed, with usage restrictions listed in the license |
- The AI image kit: ready-to-use workflows and settings by graphics card
- Official ComfyUI documentation
- The ComfyUI repository on GitHub
#FAQ
Is ComfyUI free?+
Does ComfyUI work without a graphics card?+
Do you need to know how to code to use ComfyUI?+
ComfyUI or a simpler interface such as AUTOMATIC1111?+
Do my images and prompts remain private with ComfyUI?+
How can you recognize a dangerous custom node?+
Does ComfyUI work properly on an AMD card under Windows?+
Feedback, an error, or a clarification? Let us know—it improves the guide for everyone.