{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "excalidraw",
    "name": "Excalidraw",
    "vendor": "Excalidraw s.r.o.",
    "vendorUrl": "https://plus.excalidraw.com",
    "kind": "http-api",
    "category": "diagramming",
    "summary": "Excalidraw is a hand-drawn style whiteboard and diagram editor from Excalidraw s.r.o. in Brno. Agents reach it through the Excalidraw+ REST API and MCP server (public beta), a free keyless MCP App, and the open-source editor on npm (MIT).",
    "url": "https://www.anchorterminal.com/tools/excalidraw",
    "markdownUrl": "https://www.anchorterminal.com/tools/excalidraw.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/excalidraw.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/excalidraw.json",
    "repo": "https://github.com/excalidraw/excalidraw",
    "license": "Excalidraw+ is a proprietary service under Excalidraw's terms of use. The editor and the MCP App on GitHub are MIT",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://api.excalidraw.com/api/v1/mcp",
    "packages": [
      {
        "registry": "npm",
        "name": "@excalidraw/excalidraw"
      }
    ],
    "auth": "api-key",
    "authNotes": "A person creates an API key in Excalidraw+ workspace settings, and the full key is shown once. Keys are sent as `Authorization: Bearer \u003cAPI_KEY\u003e`, belong to one workspace, take `read` or `full` permission or specific routes, and expire on a set date. Personal keys act as one member and need a workspace admin to enable them. Workspace keys act as the workspace. The free MCP App at https://mcp.excalidraw.com takes no credential.",
    "pricing": "freemium",
    "pricingNotes": "API and MCP access is listed under the Plus plan at $6 a user a month, 14 per cent less billed yearly, with a 14-day trial. The page does not say whether the trial takes a card. The Free plan, the free MCP App and the npm editor cost nothing, so an agent can draw without a contract but cannot reach a workspace (checked 2026-10-09).",
    "priceSummary": "$6 / seat-mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs dump, the pricing page or the MCP App source (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": 37,
    "popularity": {
      "githubStars": 133534,
      "npmWeekly": 675606,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://plus.excalidraw.com/docs",
    "llmsTxt": "https://plus.excalidraw.com/llms.txt",
    "capabilities": [
      "diagram.create",
      "diagram.edit",
      "diagram.export",
      "diagram.as-code"
    ],
    "tags": [
      "hosted",
      "mcp",
      "api-key",
      "llms-txt",
      "freemium",
      "beta",
      "status-page",
      "soc2",
      "open-source",
      "typescript",
      "eu"
    ],
    "lastRelease": "2026-09-01",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 54.5,
      "grade": "C",
      "agentReady": false,
      "rank": 683,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 9,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 58,
        "maintenance": 44,
        "payments": 35,
        "reliability": 50,
        "schema": 65,
        "security": 73,
        "transparency": 63
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 50,
          "points": 10,
          "reason": "Scored on the hosted lines for the Excalidraw+ API and MCP server. A status page exists at status.excalidraw.com (20). Its robots.txt disallows every path, so the incident history was not read (5). The rate limit is 600 requests a minute per IP, with `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset` headers (15). The docs ask for backoff on 429 and show a retry that waits for the reset time. No idempotency keys were found, `PUT` content replacement is repeatable and `PATCH` merges by element version (10). No SLA found (0). Both surfaces are in public beta (0)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 65,
          "points": 10.56,
          "reason": "The endpoint reference is generated from an OpenAPI schema, but no file is linked from the docs, and the MCP tool definitions could not be read without a key (10). `llms.txt` and `llms-full.txt` are published (10). The tools page says when to use `search_scene_content` over `get_scene_content`, `label` over `text` and `create_diagram` over `edit_scene_content` (16). Parameters carry ranges and enums in the reference, while `edit_scene_content` takes its elements as a JSON array string (9). Each endpoint has samples in six languages and error bodies for 400, 401 and 403 (12). The path is versioned as `/api/v1` and a monthly product changelog carries API and MCP items, with no API changelog of its own (8)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 58,
          "points": 9.43,
          "reason": "The docs list 37 MCP tools (5). The server shows a key only the tools its routes allow, so a read-only or route-restricted key cuts the list (7). Lists take `offset` and `limit` up to 100, logs take a cursor and filters, and `search_scene_content` returns only matching elements (18). Errors are JSON with `statusCode`, `error` and `message`, and seven status codes are documented (13). No idempotency keys. Deletes of scenes and collections move them to trash, and MCP annotations could not be read (8). `create_diagram` measures labels and routes arrows, but there is no SDK for the API (7)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 73,
          "points": 12.78,
          "reason": "API keys are workspace-bound, take `read` or `full` permission or specific routes, carry an expiry and can be rotated or soft-deleted. Personal and workspace keys differ in access to private collections (30). Read-only keys expose only read tools and deletes go to trash, with no confirmation step found (14). Scene text written by collaborators returns to the model and `add_image` fetches a public URL, with no injection guidance found (3). `GET /logs` returns the workspace audit log with filters by user, action and operation (13). Excalidraw states SOC 2 Type 1 and Type 2, yearly penetration tests and Vanta scanning, and publishes advisories on GitHub. No security.txt, bug bounty or SECURITY.md was found, and the trust centre report was not read (13)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 35,
          "points": 4.38,
          "reason": "No x402, MPP or L402 (0). Plan prices are public, Free at $0 and Plus at $6 a user a month, with no per-call price (10). The free editor and the keyless MCP App need no card, while the API needs the Plus plan, whose 14-day trial does not say whether a card is taken (15). An agent can call the free MCP App at https://mcp.excalidraw.com with no signup, but an API key is created by a person in workspace settings (10)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 44,
          "points": 3.85,
          "reason": "The newest changelog entry is dated 1 September 2026, 38 days before the check (20). Two dated entries fall in the last 90 days, 31 July and 1 September (0). A public changelog, a roadmap, a Discord server and support@excalidraw.com exist, and the editor repository had commits on 8 October 2026 with 3,251 open issues and pull requests (12). No vendor entry was found in the official MCP registry and there is no SDK for the API. The editor package `@excalidraw/excalidraw` 0.18.1 dates from 20 April 2026 (5). The editor repository runs test, lint and size workflows, and the MCP App repository has no CI and no commit since 24 March 2026 (7)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 63,
          "points": 5.51,
          "note": "editorial 45, provenance 80",
          "reason": "The graded service is closed under public terms of use, while the editor and the MCP App are MIT (20). The privacy policy of 29 April 2021 says servers are in the United States and data is kept at most one month after an account ends. The DPA of 13 January 2026 says cancelling a subscription does not delete data and retention follows internal policies. Neither names AI providers (14). No deprecation policy, only the beta warning that contracts may break (3). The DPA points to a sub-processor list at trust.excalidraw.com, which is script-drawn and was not read, and says some sub-processors are in the United States (8)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The docs list 37 MCP tools (5). The server shows a key only the tools its routes allow, so a read-only or route-restricted key cuts the list (7). Lists take `offset` and `limit` up to 100, logs take a cursor and filters, and `search_scene_content` returns only matching elements (18). Errors are JSON with `statusCode`, `error` and `message`, and seven status codes are documented (13). No idempotency keys. Deletes of scenes and collections move them to trash, and MCP annotations could not be read (8). `create_diagram` measures labels and routes arrows, but there is no SDK for the API (7).",
          "maintenance": "The newest changelog entry is dated 1 September 2026, 38 days before the check (20). Two dated entries fall in the last 90 days, 31 July and 1 September (0). A public changelog, a roadmap, a Discord server and support@excalidraw.com exist, and the editor repository had commits on 8 October 2026 with 3,251 open issues and pull requests (12). No vendor entry was found in the official MCP registry and there is no SDK for the API. The editor package `@excalidraw/excalidraw` 0.18.1 dates from 20 April 2026 (5). The editor repository runs test, lint and size workflows, and the MCP App repository has no CI and no commit since 24 March 2026 (7).",
          "payments": "No x402, MPP or L402 (0). Plan prices are public, Free at $0 and Plus at $6 a user a month, with no per-call price (10). The free editor and the keyless MCP App need no card, while the API needs the Plus plan, whose 14-day trial does not say whether a card is taken (15). An agent can call the free MCP App at https://mcp.excalidraw.com with no signup, but an API key is created by a person in workspace settings (10).",
          "reliability": "Scored on the hosted lines for the Excalidraw+ API and MCP server. A status page exists at status.excalidraw.com (20). Its robots.txt disallows every path, so the incident history was not read (5). The rate limit is 600 requests a minute per IP, with `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset` headers (15). The docs ask for backoff on 429 and show a retry that waits for the reset time. No idempotency keys were found, `PUT` content replacement is repeatable and `PATCH` merges by element version (10). No SLA found (0). Both surfaces are in public beta (0).",
          "schema": "The endpoint reference is generated from an OpenAPI schema, but no file is linked from the docs, and the MCP tool definitions could not be read without a key (10). `llms.txt` and `llms-full.txt` are published (10). The tools page says when to use `search_scene_content` over `get_scene_content`, `label` over `text` and `create_diagram` over `edit_scene_content` (16). Parameters carry ranges and enums in the reference, while `edit_scene_content` takes its elements as a JSON array string (9). Each endpoint has samples in six languages and error bodies for 400, 401 and 403 (12). The path is versioned as `/api/v1` and a monthly product changelog carries API and MCP items, with no API changelog of its own (8).",
          "security": "API keys are workspace-bound, take `read` or `full` permission or specific routes, carry an expiry and can be rotated or soft-deleted. Personal and workspace keys differ in access to private collections (30). Read-only keys expose only read tools and deletes go to trash, with no confirmation step found (14). Scene text written by collaborators returns to the model and `add_image` fetches a public URL, with no injection guidance found (3). `GET /logs` returns the workspace audit log with filters by user, action and operation (13). Excalidraw states SOC 2 Type 1 and Type 2, yearly penetration tests and Vanta scanning, and publishes advisories on GitHub. No security.txt, bug bounty or SECURITY.md was found, and the trust centre report was not read (13).",
          "transparency": "The graded service is closed under public terms of use, while the editor and the MCP App are MIT (20). The privacy policy of 29 April 2021 says servers are in the United States and data is kept at most one month after an account ends. The DPA of 13 January 2026 says cancelling a subscription does not delete data and retention follows internal policies. Neither names AI providers (14). No deprecation policy, only the beta warning that contracts may break (3). The DPA points to a sub-processor list at trust.excalidraw.com, which is script-drawn and was not read, and says some sub-processors are in the United States (8)."
        },
        "sources": [
          {
            "what": "docs index for agents",
            "url": "https://plus.excalidraw.com/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "full docs dump (API, MCP, scene schema, self-hosting)",
            "url": "https://plus.excalidraw.com/llms-full.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "one rendered endpoint reference page",
            "url": "https://plus.excalidraw.com/docs/api/logs/get",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing",
            "url": "https://plus.excalidraw.com/pricing",
            "seen": "2026-10-09"
          },
          {
            "what": "terms of use",
            "url": "https://plus.excalidraw.com/terms-of-service",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy",
            "url": "https://plus.excalidraw.com/privacy-policy",
            "seen": "2026-10-09"
          },
          {
            "what": "data processing agreement",
            "url": "https://plus.excalidraw.com/data-processing-agreement-dpa",
            "seen": "2026-10-09"
          },
          {
            "what": "security and compliance page",
            "url": "https://plus.excalidraw.com/security-and-compliance",
            "seen": "2026-10-09"
          },
          {
            "what": "changelog",
            "url": "https://plus.excalidraw.com/changelog",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP App source, shallow clone at v0.3.2 plus later commits",
            "url": "https://github.com/excalidraw/excalidraw-mcp",
            "seen": "2026-10-09"
          },
          {
            "what": "one `tools/list` request to the free MCP App",
            "url": "https://mcp.excalidraw.com/mcp",
            "seen": "2026-10-09"
          },
          {
            "what": "editor source, changelog, tags and workflows, shallow clone",
            "url": "https://github.com/excalidraw/excalidraw",
            "seen": "2026-10-09"
          },
          {
            "what": "repository advisories from the GitHub API",
            "url": "https://github.com/excalidraw/excalidraw/security/advisories",
            "seen": "2026-10-09"
          },
          {
            "what": "npm latest version and weekly downloads",
            "url": "https://registry.npmjs.org/@excalidraw/excalidraw/latest",
            "seen": "2026-10-09"
          },
          {
            "what": "official MCP registry search for excalidraw",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=excalidraw",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: the incident history on status.excalidraw.com. Its robots.txt disallows every path, so Reliability takes 5 of 30 for the record",
          "unchecked: the MCP tool definitions, annotations and their size on https://api.excalidraw.com/api/v1/mcp. They need a key, and the host's robots.txt disallows every path, so no request was sent",
          "unchecked: the sub-processor list and SOC 2 report in the trust centre at trust.excalidraw.com, which is script-drawn",
          "unchecked: any page of excalidraw.com beyond its robots.txt, which carries both `Allow: /` and `Disallow: /` for unnamed agents. Its security.txt was not requested",
          "Whether the 14-day Plus trial takes a card. The terms say the account is charged when the trial ends",
          "Whether the OpenAPI schema behind the reference pages is published at a public address. No link was found in the docs or `llms.txt`",
          "The terms of use forbid access through a bot or script, and the robots.txt files of api.excalidraw.com and status.excalidraw.com disallow every path. Both matter before any probe is run",
          "The lead named only the free MCP App and the npm package. The Excalidraw+ REST API and MCP server, in public beta since the May 2026 changelog entry, are the documented agent surface and are what the scores cover"
        ]
      },
      "negative": -2,
      "negativeNotes": [
        "Checked 2026-10-09. GHSA-39h7-pwv7-rc3x (CVE-2025-54881, medium), cross-site scripting in the Mermaid to Excalidraw conversion step, was published on 21 April 2026 and fixed in `@excalidraw/excalidraw` 0.18.1 and `@excalidraw/mermaid-to-excalidraw` 1.1.3. Fixed and published, so 2 points (https://github.com/excalidraw/excalidraw/security/advisories/GHSA-39h7-pwv7-rc3x)."
      ],
      "verdict": "Excalidraw+ keys carry read or full permission, route restrictions and an expiry, and the MCP server shows a key only the tools its routes allow. The API and MCP server are in public beta with breaking changes expected, sit behind the $6 Plus plan, and have no published OpenAPI file, SDK or idempotency keys.",
      "bestFor": "Teams already on Excalidraw+ that want agents to create and edit hand-drawn diagrams, slides and wireframes in a shared workspace, and one-off sketches through the free MCP App.",
      "strengths": [
        "API keys take `read` or `full` permission, route restrictions and an expiry, and can be rotated. The MCP server lists only the tools a key's routes allow",
        "`create_diagram` lays out nodes, edges and groups into editable shapes with bound arrows, and `take_screenshot` returns a PNG to check the result",
        "`search_scene_content` returns only matching elements, so an agent need not load a whole scene",
        "`llms.txt` and a 110 KB `llms-full.txt` carry the API and MCP docs, and `GET /logs` returns the workspace audit log",
        "A free MCP App at https://mcp.excalidraw.com needs no account or key, and the editor is MIT on npm with 675,606 downloads in the week to 7 October 2026"
      ],
      "weaknesses": [
        "The API and MCP server are in public beta. The docs say endpoints, tool names and schemas may change and to expect breaking changes",
        "API and MCP access needs the Plus plan at $6 a user a month. No per-call price, and no SDK for the API",
        "No OpenAPI file is linked from the docs, although the reference pages are generated from one. No idempotency keys and no SLA found",
        "The terms of use (in effect 1 June 2022) forbid access through a bot or script and do not mention the API. This matters before any probe is run",
        "The privacy policy is dated 29 April 2021 and names no AI providers. The sub-processor list sits in a script-drawn trust centre",
        "In the free MCP App, `create_view` is marked read-only yet stores a checkpoint for 30 days, and its reply names a `read_widget_context` tool the server does not register"
      ],
      "agentNotes": [
        "Send `Authorization: Bearer \u003cAPI_KEY\u003e` to https://api.excalidraw.com/api/v1. For MCP, use `POST /api/v1/mcp` only. The server is stateless and answers 405 to other methods",
        "Use a personal key to reach the owner's private collection with the collection ID `private`. A workspace admin must enable personal keys first",
        "Call `read_diagram_format`, `read_presentation_format` or `read_freeform_format` before the first scene write in a session",
        "Write with `edit_scene_content` and bind arrows through `startBinding` and `endBinding` with `tempId` references. `PUT /scenes/{sceneId}/content` removes every element left out of the request",
        "Stay under 600 requests a minute per IP and wait until `X-RateLimit-Reset` after a 429"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 54.5
        }
      ],
      "editorialScores": {
        "ergonomics": 58,
        "maintenance": 44,
        "payments": 35,
        "reliability": 50,
        "schema": 65,
        "security": 73,
        "transparency": 45
      },
      "provenanceScore": 80
    },
    "connect": {
      "install": "npm install react react-dom @excalidraw/excalidraw",
      "http": "curl https://api.excalidraw.com/api/v1/collections \\\n  -H \"Authorization: Bearer \u003cAPI_KEY\u003e\"",
      "config": {
        "mcpServers": {
          "excalidraw": {
            "headers": {
              "Authorization": "Bearer \u003cAPI_KEY\u003e"
            },
            "type": "http",
            "url": "https://api.excalidraw.com/api/v1/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/diagram.create",
      "tool": "https://letme.dev/excalidraw"
    },
    "notable": [
      "The Excalidraw+ API and MCP server are in public beta, and the docs say endpoints, payloads, tool names and schemas may change (https://plus.excalidraw.com/docs/api)",
      "The MCP server at https://api.excalidraw.com/api/v1/mcp is stateless Streamable HTTP, and its tools are filtered by the API key's route permissions (https://plus.excalidraw.com/docs/mcp/auth-and-permissions)",
      "The docs list 37 MCP tools across scenes, format guides, diagrams, presentations, images, collections, workspace, users, invites and logs (https://plus.excalidraw.com/docs/mcp/tools)",
      "The free MCP App at https://mcp.excalidraw.com answers `tools/list` with five tools and no authentication. Two face the model, `read_me` and `create_view`, and three are for the app (https://github.com/excalidraw/excalidraw-mcp)",
      "The pricing page lists REST API and MCP under the Plus plan at $6 a user a month, both marked public beta (https://plus.excalidraw.com/pricing)",
      "The terms of use, in effect since 1 June 2022, forbid access \"through automated or non-human means, whether through a bot, script or otherwise\" (https://plus.excalidraw.com/terms-of-service)",
      "Self-hosting of Excalidraw+ is in development and tied to an Enterprise licence. The open-source editor can be self-hosted today (https://plus.excalidraw.com/docs/self-hosting)"
    ],
    "area": "design-diagrams",
    "details": [
      {
        "label": "Surfaces",
        "value": "Excalidraw+ REST API at https://api.excalidraw.com/api/v1 and MCP server at `/api/v1/mcp` (both public beta, Plus plan). Free MCP App at https://mcp.excalidraw.com. Editor as the npm package `@excalidraw/excalidraw`"
      },
      {
        "label": "REST API",
        "value": "27 operations across collections, scenes, scene content, invites, users, workspace and logs. Scene content has `GET`, `PATCH` (merge by element version) and `PUT` (full replacement)"
      },
      {
        "label": "MCP tools",
        "value": "37 documented, among them `create_diagram`, `edit_scene_content`, `search_scene_content`, `get_scene_content`, `create_slide`, `add_image`, `take_screenshot` and three format guides. The low-level content write endpoints are not exposed as tools"
      },
      {
        "label": "Free MCP App",
        "value": "Open source (MIT per README and package.json, no licence file), v0.3.2 of 9 February 2026, last commit 24 March 2026. Five tools. Checkpoints are kept in Redis for 30 days and inputs are capped at 5 MB. Export uploads an encrypted copy to excalidraw.com"
      },
      {
        "label": "Credentials",
        "value": "Bearer API keys with `read` or `full` permission or specific routes, an expiry, rotation and soft delete. Personal keys (admin must enable) or workspace keys"
      },
      {
        "label": "Rate limits",
        "value": "600 requests a minute per IP, with `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset` headers"
      },
      {
        "label": "Pagination",
        "value": "`offset` and `limit` (default 10, up to 100) with `hasNextPage`. Logs also take a cursor"
      },
      {
        "label": "Errors",
        "value": "JSON with `statusCode`, `error` and `message`. Documented codes 400, 401, 403, 404, 429 and 500"
      },
      {
        "label": "Export formats",
        "value": "PNG through the MCP `take_screenshot` tool. The editor exports PNG, SVG and `.excalidraw` JSON, and Excalidraw+ adds PDF and PPTX"
      },
      {
        "label": "Audit",
        "value": "`GET /logs` returns workspace audit logs filtered by user, action, operation and date"
      },
      {
        "label": "Free tier",
        "value": "Free plan with one scene saved in the browser and 10 AI requests a day. Plus has a 14-day trial"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type 1 and Type 2 and yearly penetration tests, per the security page. Report in the Vanta trust centre"
      },
      {
        "label": "Editor package",
        "value": "`@excalidraw/excalidraw` 0.18.1 (20 April 2026), MIT, React 17 to 19, 133,534 GitHub stars"
      }
    ],
    "unitPrices": [
      {
        "item": "Plus plan",
        "unit": "seat-month",
        "usd": 6,
        "note": "billed monthly, 14 per cent less billed yearly. API and MCP access, 100 AI requests a day"
      }
    ],
    "provenance": {
      "legalEntity": "Excalidraw s.r.o.",
      "domain": "excalidraw.com",
      "domainRegistered": "2020-01-03",
      "endpointOnVendorDomain": true,
      "terms": "https://plus.excalidraw.com/terms-of-service",
      "privacy": "https://plus.excalidraw.com/privacy-policy",
      "statusPage": "https://status.excalidraw.com",
      "changelog": "https://plus.excalidraw.com/changelog",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The terms of use and the privacy policy name Excalidraw s.r.o., Pražákova 1008/69, Brno 639 00, Czech Republic. The terms are governed by Czech law.",
        "The terms of use (published 30 May 2022) are the only terms found. They cover the Site and the subscription and do not mention the API or MCP server.",
        "The privacy policy is dated 29 April 2021. A DPA dated 13 January 2026 is at https://plus.excalidraw.com/data-processing-agreement-dpa.",
        "plus.excalidraw.com/.well-known/security.txt returns 404. excalidraw.com was not asked, because its robots.txt is ambiguous for unnamed agents.",
        "RDAP for excalidraw.com gives a registration date of 2020-01-03.",
        "The robots.txt files of api.excalidraw.com and status.excalidraw.com disallow every path."
      ],
      "score": 80,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Excalidraw s.r.o.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "excalidraw.com, registered 2020-01-03 (6 years)",
          "points": 11,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.excalidraw.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 4.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.excalidraw.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://plus.excalidraw.com/terms-of-service",
          "state": "read",
          "readAt": "2026-10-09",
          "words": 6562,
          "points": 4.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "and yourself both agree to submit to the non-exclusive jurisdiction of the courts of Brno, which means that you may make a claim to defend your consumer protection rights in regards to these Conditions of Use in Czech Republic, or in the EU country in which you reside.",
              "says": "Disputes go to the courts of Brno"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "NOTWITHSTANDING ANYTHING TO THE CONTRARY CONTAINED HEREIN, OUR LIABILITY TO YOU FOR ANY CAUSE WHATSOEVER AND REGARDLESS OF THE FORM OF THE ACTION, WILL AT ALL TIMES BE LIMITED TO THE AMOUNT PAID, IF ANY, BY YOU TO US DURING THE ONE (1) MONTH PERIOD PRIOR TO ANY CAUSE OF ACTION ARISING.",
              "says": "Capped at the fees paid in the 1 month before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "WE MAY TERMINATE YOUR USE OR PARTICIPATION IN THE SITE OR DELETE YOUR ACCOUNT AND ANY CONTENT OR INFORMATION THAT YOU POSTED AT ANY TIME, WITHOUT WARNING, IN OUR SOLE DISCRETION."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We will alert you about any changes by updating the “Last updated” date of these Terms of Use, and you waive any right to receive specific notice of each such change.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "The Site is not tailored to comply with industry-specific regulations (Health Insurance Portability and Accountability Act (HIPAA), Federal Information Security Management Act (FISMA), etc.), so if your interactions would be subjected to such laws, you may not use this Site."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "(5) you will not access the Site through automated or non-human means, whether through a bot, script or otherwise;",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "We also reserve the right to modify or discontinue all or part of the Site without notice at any time.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "WE MAY TERMINATE YOUR USE OR PARTICIPATION IN THE SITE OR DELETE YOUR ACCOUNT AND ANY CONTENT OR INFORMATION THAT YOU POSTED AT ANY TIME, WITHOUT WARNING, IN OUR SOLE DISCRETION."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "The Parties agree that any arbitration shall be limited to the Dispute between the Parties individually."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Liability is limited to the amount paid in the one month before the cause of action arose.",
              "quote": "NOTWITHSTANDING ANYTHING TO THE CONTRARY CONTAINED HEREIN, OUR LIABILITY TO YOU FOR ANY CAUSE WHATSOEVER AND REGARDLESS OF THE FORM OF THE ACTION, WILL AT ALL TIMES BE LIMITED TO THE AMOUNT PAID, IF ANY, BY YOU TO US DURING THE ONE (1) MONTH PERIOD PRIOR TO ANY CAUSE OF ACTION ARISING."
            },
            {
              "date": "2026-10-08",
              "text": "Users agree not to use a buying agent or purchasing agent to make purchases on the site.",
              "quote": "Use a buying agent or purchasing agent to make purchases on the Site."
            },
            {
              "date": "2026-10-08",
              "text": "The licence over posted contributions extends to use of the customer's name, company name, trademarks and logos.",
              "quote": "This license will apply to any form, media, or technology now known or hereafter developed, and includes our use of your name, company name, and franchise name, as applicable, and any of the trademarks, service marks, trade names, logos, and personal and commercial images you provide."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://plus.excalidraw.com/privacy-policy",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2021-04-29",
          "words": 5779,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated April 29, 2021",
              "says": "Last updated 2021-04-29"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "In this privacy notice, we seek to explain to you in the clearest way possible what information we collect, how we use it and what rights you have in relation to it."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this privacy notice unless otherwise required by law.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We may share your data with third-party vendors, service providers, contractors or agents who perform services for us or on our behalf and require access to such information to do that work."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "will not sell personal information in the future belonging to website visitors, users and other consumers.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You can opt-out of our marketing emails at any time (see the \"WHAT ARE YOUR PRIVACY RIGHTS?\" below)."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have any questions or concerns about this privacy notice, or our practices with regards to your personal information, please contact us at support@excalidraw.com.",
              "says": "support@excalidraw.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "We have implemented measures to protect your personal information, including by using the European Commission's Standard Contractual Clauses for transfers of personal information between our group companies and between us and our third-party providers.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "Last updated April 29, 2021"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The notice says no purpose requires keeping personal information for longer than one month after the account is terminated.",
              "quote": "No purpose in this notice will require us keeping your personal information for longer than one (1) months past the termination of the user's account."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/excalidraw.json",
    "live": {
      "slug": "excalidraw",
      "probe": {
        "target": "https://api.excalidraw.com/api/v1/mcp",
        "method": "get",
        "lastAt": "2026-10-10T01:37:51.149256256Z",
        "lastOk": true,
        "lastStatus": 405,
        "lastMs": 409,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 338,
        "p95ms24h": 401,
        "samples24h": 102,
        "samples30d": 102,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 17,
            "ok": 17
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.excalidraw.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-10T00:50:32.425887728Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "excalidraw/excalidraw",
          "version": "v0.18.1",
          "released": "2026-04-21",
          "seenAt": "2026-10-09T16:52:20.443420866Z"
        },
        {
          "registry": "npm",
          "name": "@excalidraw/excalidraw",
          "version": "0.18.1",
          "seenAt": "2026-10-09T16:52:19.575748854Z"
        }
      ],
      "githubStars": 133551,
      "npmWeekly": 675606,
      "pages": [
        {
          "url": "https://plus.excalidraw.com/changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-09T18:43:35.623690787Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "7a9250424db5"
        },
        {
          "url": "https://plus.excalidraw.com/privacy-policy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:43:37.662006429Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "8328a24b3944"
        },
        {
          "url": "https://plus.excalidraw.com/terms-of-service",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:43:39.940578591Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "3dc978ec9eff"
        }
      ],
      "updatedAt": "2026-10-10T01:37:51.149256256Z"
    }
  }
}
