{
  "data": {
    "a": {
      "slug": "cloudviz",
      "name": "Cloudviz API",
      "vendor": "Cloudviz",
      "vendorUrl": "https://cloudviz.io",
      "kind": "http-api",
      "category": "diagramming",
      "summary": "Generates AWS architecture diagrams from a live account.",
      "url": "https://www.anchorterminal.com/tools/cloudviz",
      "markdownUrl": "https://www.anchorterminal.com/tools/cloudviz.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cloudviz.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cloudviz.json",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.cloudviz.io",
      "packages": [],
      "auth": "api-key",
      "authNotes": "API key in the x-api-key header, created in the app under Manage API Keys. Each key is read or read and write, and can be changed at any time. Cloudviz reads your AWS account through a cross-account read-only IAM role.",
      "pricing": "paid",
      "pricingNotes": "10-day free trial. Base $9.95 per user a month with 3 AWS accounts and no API. Team $49 a month for 10 users with unlimited AWS accounts, API access, SSO and 20 automated diagrams. Enterprise (self-hosted, unlimited users) by quote. Annual billing is up to 30 per cent off, and AWS Marketplace billing is available (https://cloudviz.io/pricing).",
      "priceSummary": "$9.95 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://cloudviz.io/developers",
      "openapi": "https://cloudviz.io/assets/developers/openapi.json",
      "capabilities": [
        "diagram.create",
        "diagram.export",
        "diagram.architecture"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "openapi",
        "async-jobs",
        "enterprise"
      ],
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 37.7,
        "grade": "F",
        "agentReady": false,
        "rank": 925,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 13,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 50,
          "maintenance": 5,
          "payments": 20,
          "reliability": 20,
          "schema": 58,
          "security": 53,
          "transparency": 45
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Diagrams come from the live AWS account through a read-only cross-account role with a per-customer external ID. AWS only, and API access starts at the $49 a month Team plan.",
        "bestFor": "Documenting what already runs in AWS, for example regenerating a diagram after each deploy and posting it to Confluence or Slack.",
        "strengths": [
          "Diagrams come from the live AWS account through a read-only cross-account role with a per-customer external ID",
          "One GET returns svg, png, pdf, drawio, jsonDiagram or jsonSnapshot",
          "Public OpenAPI 3.0.3 file with 7 operations and documented status codes",
          "API keys can be read-only"
        ],
        "weaknesses": [
          "AWS only, and API access starts at the $49 a month Team plan",
          "Throttling on rate, burst and daily count with no published numbers",
          "No status page, changelog, SLA or security.txt",
          "No dated product update found since March 2025"
        ],
        "agentNotes": [
          "Call `GET /aws/accounts/` first to get the Cloudviz account ID, then request `/aws/accounts/{account-id}/{region}/{format}`",
          "On a 202, wait and repeat the same GET until the diagram is ready",
          "Ask for `jsonSnapshot` or `jsonDiagram` (there is no plain `json` format) when the agent has to reason over resources",
          "Use a read-only key unless the agent has to add, change or delete AWS accounts"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "F",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 37.7
          }
        ],
        "editorialScores": {
          "ergonomics": 50,
          "maintenance": 5,
          "payments": 20,
          "reliability": 20,
          "schema": 58,
          "security": 53,
          "transparency": 38
        },
        "provenanceScore": 51
      },
      "connect": {
        "http": "curl https://api.cloudviz.io/aws/accounts/ -H \"x-api-key: $CLOUDVIZ_API_KEY\""
      },
      "letme": {
        "capability": "https://letme.dev/diagram.create",
        "tool": "https://letme.dev/cloudviz"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Base plan",
          "unit": "seat-month",
          "usd": 9.95,
          "note": "billed monthly, no API access"
        },
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 49,
          "note": "10 users, first plan with API access, billed monthly"
        }
      ],
      "provenance": {
        "legalEntity": "SIA Cloudviz Solutions",
        "domain": "cloudviz.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://cloudviz.io/terms",
        "privacy": "https://cloudviz.io/privacy",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "SIA is a Latvian limited company, registration number 44103120286, legal address Rīgas iela 22A-53, Limbaži, LV-4001 (firmas.lv)",
          "Terms are governed by Latvian law and were last updated on 26 March 2019",
          "No RDAP service answers for .io, so the registration date is unknown",
          "/.well-known/security.txt returns 404. The security page names security@cloudviz.io"
        ],
        "score": 51
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/cloudviz.json",
      "live": {
        "slug": "cloudviz",
        "probe": {
          "target": "https://api.cloudviz.io",
          "method": "get",
          "lastAt": "2026-10-10T02:07:05.507824493Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 60,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 58,
          "p95ms24h": 100,
          "samples24h": 250,
          "samples30d": 2458,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 250,
              "ok": 250
            },
            {
              "date": "2026-10-10",
              "probes": 22,
              "ok": 22
            }
          ]
        },
        "securityTxt": {
          "url": "https://cloudviz.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:39:17.762891647Z"
        },
        "domain": {
          "domain": "cloudviz.io",
          "checkedAt": "2026-10-04T13:03:55.142223054Z"
        },
        "pages": [
          {
            "url": "https://cloudviz.io/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-09T18:34:00.11883612Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "65ac1cddb5ad"
          },
          {
            "url": "https://cloudviz.io/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-09T18:34:02.19941143Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b4c608710d46"
          },
          {
            "url": "https://cloudviz.io/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-09T18:34:04.18933796Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f319fbc0e66d"
          }
        ],
        "updatedAt": "2026-10-10T02:07:05.507824493Z"
      }
    },
    "answer": "Kroki scores 59.2 (C) on agent readiness against Cloudviz API's 37.7 (F), and leads in 6 of 7 scored categories. Cloudviz API leads on schema \u0026 documentation.",
    "b": {
      "slug": "kroki",
      "name": "Kroki",
      "vendor": "Yuzu tech",
      "vendorUrl": "https://kroki.io",
      "kind": "http-api",
      "category": "diagramming",
      "summary": "Kroki is an open-source HTTP server from Yuzu tech that converts diagram text in 29 formats, including PlantUML, Mermaid, GraphViz and D2, into SVG, PNG or PDF. Owners run it from Docker images, and kroki.io is a free public instance.",
      "url": "https://www.anchorterminal.com/tools/kroki",
      "markdownUrl": "https://www.anchorterminal.com/tools/kroki.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kroki.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kroki.json",
      "repo": "https://github.com/yuzutech/kroki",
      "license": "MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "yuzutech/kroki"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-mermaid"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-bpmn"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-excalidraw"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or login on the convert endpoints, on a self-hosted server or on the public instance at kroki.io. The server binds all interfaces on port 8000 unless `KROKI_LISTEN` says otherwise. An optional bearer token, `KROKI_COMPANION_REGISTRATION_TOKEN`, protects only the `/services` registration API, which is off by default.",
      "pricing": "free",
      "pricingNotes": "Free under the MIT licence, with nothing to buy. The public instance at kroki.io is free and paid for by sponsors, for reasonable, non-commercial use with no uptime guarantee. Third parties sell hosting, which the project says it does not operate.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4365,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.kroki.io/kroki/setup/usage/",
      "capabilities": [
        "diagram.as-code",
        "diagram.create",
        "diagram.export",
        "diagram.architecture"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "http-api",
        "docker",
        "diagram-as-code",
        "plantuml",
        "mermaid",
        "graphviz",
        "no-auth",
        "free"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.2,
        "grade": "C",
        "agentReady": false,
        "rank": 558,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -5,
        "negativeNotes": [
          "27 July to 12 August 2026. Four advisories on the repository. GHSA-wmpp-fj9c-w766 (critical, CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in 0.21.0 up to 0.32.0 whatever the safe mode. GHSA-r54f-fq6c-53vw (high, CVE-2026-102359), GHSA-px99-rjv4-49g8 (medium, CVE-2026-102356) and GHSA-9p7m-vrmg-qp4q (high) let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed, in 0.32.1 at the latest, and the maintainers published each with a changelog entry, so the deduction is five points (https://github.com/yuzutech/kroki/security/advisories)."
        ],
        "verdict": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
        "bestFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "strengths": [
          "`POST /` with `diagram_source`, `diagram_type` and `output_format`, or plain text to `/\u003ctype\u003e/\u003cformat\u003e`, returns the image. No account or key",
          "One API covers 29 diagram types, among them PlantUML, C4, Structurizr, Mermaid, GraphViz, D2, DBML, BPMN, Excalidraw and Vega",
          "`KROKI_SAFE_MODE` defaults to `SECURE`, which blocks file and network reads by diagram libraries, and the container runs as the non-root user `kroki`",
          "Five versions shipped between 15 July and 5 October 2026, and the `main.yaml` workflow passed on the last ten pushes to `main`",
          "MIT licence. The maintainers published four security advisories in 2026, each with a fixed version and a changelog entry"
        ],
        "weaknesses": [
          "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026",
          "Three more advisories in July and August 2026 let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed in 0.32.1",
          "No OpenAPI file, llms.txt or error catalogue. The JSON error shape is in the source and not in the documentation",
          "The public instance at kroki.io has no terms, privacy policy, status page or published rate limit. The CLI page limits the demonstration server to reasonable, non-commercial use",
          "The server has no authentication on its convert endpoints and binds all interfaces on port 8000 by default. The version is 0.33.0, with no 1.0"
        ],
        "agentNotes": [
          "Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs",
          "Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image",
          "Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers",
          "Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode",
          "Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.2
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 67
        },
        "provenanceScore": 56
      },
      "connect": {
        "install": "docker run -p8000:8000 yuzutech/kroki",
        "http": "curl https://kroki.io/graphviz/svg --data-raw 'digraph G {Hello-\u003eWorld}'"
      },
      "letme": {
        "capability": "https://letme.dev/diagram.as-code",
        "tool": "https://letme.dev/kroki"
      },
      "area": "design-diagrams",
      "provenance": {
        "legalEntity": "Yuzu tech, a French software firm. No registered legal form found",
        "domain": "kroki.io",
        "domainRegistered": "2019-01-06",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/yuzutech/kroki/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The kroki.io home page says Kroki is built and maintained by Yuzu tech, and links https://yuzutech.fr, whose pages name no legal form or registration number. `LICENSE` reads Copyright (c) 2020-present Kroki",
          "No terms or privacy document was found on kroki.io or docs.kroki.io, for the software or for the public instance. The MIT licence stands in for the software",
          "https://kroki.io/.well-known/security.txt answered 404 on 9 October 2026. `SECURITY.md` asks for reports through a private GitHub security advisory",
          "The lead wrote the vendor as Yuzutech. The site writes Yuzu tech, and the GitHub organisation is `yuzutech`",
          "The endpoint on the vendor's domain is the free public instance. The listing grades the server an owner runs"
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kroki.json",
      "live": {
        "slug": "kroki",
        "versions": [
          {
            "registry": "github",
            "name": "yuzutech/kroki",
            "version": "v0.33.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-09T17:00:57.82489933Z"
          }
        ],
        "githubStars": 4365,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/yuzutech/kroki/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:46:31.151891385Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3e34fa594488"
          }
        ],
        "updatedAt": "2026-10-09T18:46:31.151891385Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Cloudviz",
        "b": "Yuzu tech",
        "name": "Vendor"
      },
      {
        "a": "https://api.cloudviz.io",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "none",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "none",
        "b": "2026-10-05",
        "name": "Last release"
      },
      {
        "a": "2019-03-26",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "none",
        "b": "4.4k stars",
        "name": "Popularity"
      },
      {
        "a": "2.5/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Kroki scores 59.2 (C) on agent readiness against Cloudviz API's 37.7 (F), and leads in 6 of 7 scored categories. Cloudviz API leads on schema \u0026 documentation.",
        "question": "Which is better for AI agents, Cloudviz API or Kroki?"
      },
      {
        "answer": "Cloudviz API needs an API key. Kroki needs no key.",
        "question": "Do Cloudviz API and Kroki need an API key?"
      },
      {
        "answer": "Cloudviz API has a hosted endpoint at https://api.cloudviz.io. No hosted endpoint is listed for Kroki.",
        "question": "Can an agent call Cloudviz API and Kroki without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Cloudviz API. Kroki is open source (MIT).",
        "question": "Are Cloudviz API and Kroki open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 58 against 48"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "No incidents deducted, where Kroki loses 5 points for them"
        ],
        "goodFor": "Documenting what already runs in AWS, for example regenerating a diagram after each deploy and posting it to Confluence or Slack.",
        "slug": "cloudviz",
        "watchFor": "AWS only, and API access starts at the $49 a month Team plan"
      },
      {
        "aheadOn": [
          "Reliability, 74 against 20",
          "Agent ergonomics, 70 against 50",
          "Payments \u0026 pricing, 60 against 20",
          "Maintenance \u0026 community, 86 against 5",
          "Transparency \u0026 trust, 62 against 45"
        ],
        "also": [
          "No key needed to call it",
          "Open source"
        ],
        "goodFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "slug": "kroki",
        "watchFor": "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026"
      }
    ],
    "job": {
      "capability": "diagram.create",
      "name": "Diagram creation"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-d2.json",
        "title": "Cloudviz API vs D2",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-d2"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-diagrams-so.json",
        "title": "Cloudviz API vs Diagrams.so API + MCP",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-diagrams-so"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-drawio.json",
        "title": "Cloudviz API vs draw.io + MCP",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-drawio"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-eraser.json",
        "title": "Cloudviz API vs Eraser API + MCP",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-eraser"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-excalidraw.json",
        "title": "Cloudviz API vs Excalidraw",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-excalidraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-lucid.json",
        "title": "Cloudviz API vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-mermaid-chart.json",
        "title": "Cloudviz API vs Mermaid Chart MCP",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-mermaid-chart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-mural-mcp.json",
        "title": "Cloudviz API vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-plantuml.json",
        "title": "Cloudviz API vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-structurizr.json",
        "title": "Cloudviz API vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-tldraw.json",
        "title": "Cloudviz API vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-whimsical.json",
        "title": "Cloudviz API vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.json",
        "title": "Diagrams.so API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-kroki.json",
        "title": "draw.io + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-kroki.json",
        "title": "Eraser API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki.json",
        "title": "Excalidraw vs Kroki",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.json",
        "title": "Kroki vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-whimsical.json",
        "title": "Kroki vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-kroki.json",
        "title": "D2 vs Kroki",
        "url": "https://www.anchorterminal.com/compare/d2-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-lucid.json",
        "title": "Kroki vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.json",
        "title": "Kroki vs Mermaid Chart MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-plantuml.json",
        "title": "Kroki vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-structurizr.json",
        "title": "Kroki vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-tldraw.json",
        "title": "Kroki vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-tldraw"
      }
    ],
    "scores": [
      {
        "by": 54,
        "cloudviz": 20,
        "edge": "kroki",
        "key": "reliability",
        "kroki": 74,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 10,
        "cloudviz": 58,
        "edge": "cloudviz",
        "key": "schema",
        "kroki": 48,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 20,
        "cloudviz": 50,
        "edge": "kroki",
        "key": "ergonomics",
        "kroki": 70,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 3,
        "cloudviz": 53,
        "edge": "kroki",
        "key": "security",
        "kroki": 56,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 40,
        "cloudviz": 20,
        "edge": "kroki",
        "key": "payments",
        "kroki": 60,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 81,
        "cloudviz": 5,
        "edge": "kroki",
        "key": "maintenance",
        "kroki": 86,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 17,
        "cloudviz": 45,
        "edge": "kroki",
        "key": "transparency",
        "kroki": 62,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Kroki scores 59.2 (C) on agent readiness against Cloudviz API's 37.7 (F), and leads in 6 of 7 scored categories. Cloudviz API leads on schema \u0026 documentation. Both do diagram creation.",
    "verdicts": {
      "cloudviz": "Diagrams come from the live AWS account through a read-only cross-account role with a per-customer external ID. AWS only, and API access starts at the $49 a month Team plan.",
      "kroki": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki",
    "json": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md",
    "slim": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki.min.md"
  },
  "markdown": "Kroki scores 59.2 (C) on agent readiness against Cloudviz API's 37.7 (F), and leads in 6 of 7 scored categories. Cloudviz API leads on schema \u0026 documentation. Both do diagram creation.\n\n- Cloudviz API: grade F, 37.7/100, rank #925 of 950. Markdown https://www.anchorterminal.com/tools/cloudviz.md · JSON https://www.anchorterminal.com/api/v1/tools/cloudviz.json\n- Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json\n- Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md\n- All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md\n\n## Which one, for what\n\n### Cloudviz API (F)\n\nGood for: Documenting what already runs in AWS, for example regenerating a diagram after each deploy and posting it to Confluence or Slack.\n\nAhead on:\n- Schema \u0026 documentation, 58 against 48\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- No incidents deducted, where Kroki loses 5 points for them\n\nWatch for: AWS only, and API access starts at the $49 a month Team plan\n\n### Kroki (C)\n\nGood for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.\n\nAhead on:\n- Reliability, 74 against 20\n- Agent ergonomics, 70 against 50\n- Payments \u0026 pricing, 60 against 20\n- Maintenance \u0026 community, 86 against 5\n- Transparency \u0026 trust, 62 against 45\n\nAlso in its favour:\n- No key needed to call it\n- Open source\n\nWatch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026\n\n\n## Score by category\n\n| Category | Weight | Cloudviz API | Kroki | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 20 | 74 | Kroki +54 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 58 | 48 | Cloudviz API +10 |\n| Agent ergonomics | 13% (16.2 this run) | 50 | 70 | Kroki +20 |\n| Security \u0026 auth | 14% (17.5 this run) | 53 | 56 | Kroki +3 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 60 | Kroki +40 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 5 | 86 | Kroki +81 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 45 | 62 | Kroki +17 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **37.7 · F** | **59.2 · C** | |\n\n## Facts side by side\n\n| Fact | Cloudviz API | Kroki |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Cloudviz | Yuzu tech |\n| Hosted endpoint | `https://api.cloudviz.io` | no (local only) |\n| Transports | HTTP | HTTP |\n| Auth | API key | None |\n| Pricing | Paid | Free |\n| x402 | no | no |\n| Licence | none | MIT |\n| Read-only variant documented | yes | no |\n| llms.txt | no | no |\n| Last release | none | 2026-10-05 |\n| Terms last updated | 2019-03-26 | no document linked |\n| Privacy policy last updated | couldn't be read | no document linked |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | not found in the text |  |\n| Terms or service can change without notice | not found in the text |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | none | 4.4k stars |\n| Agent reviews | 2.5/5 (2) | none |\n\n## Verdicts\n\n**Cloudviz API.** Diagrams come from the live AWS account through a read-only cross-account role with a per-customer external ID. AWS only, and API access starts at the $49 a month Team plan.\n\n**Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.\n\n## Before you call either\n\n### Cloudviz API\n\n1. Call `GET /aws/accounts/` first to get the Cloudviz account ID, then request `/aws/accounts/{account-id}/{region}/{format}`\n2. On a 202, wait and repeat the same GET until the diagram is ready\n3. Ask for `jsonSnapshot` or `jsonDiagram` (there is no plain `json` format) when the agent has to reason over resources\n4. Use a read-only key unless the agent has to add, change or delete AWS accounts\n\n### Kroki\n\n1. Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs\n2. Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image\n3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers\n4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode\n5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication\n\n## Questions\n\n### Which is better for AI agents, Cloudviz API or Kroki?\n\nKroki scores 59.2 (C) on agent readiness against Cloudviz API's 37.7 (F), and leads in 6 of 7 scored categories. Cloudviz API leads on schema \u0026 documentation.\n\n### Do Cloudviz API and Kroki need an API key?\n\nCloudviz API needs an API key. Kroki needs no key.\n\n### Can an agent call Cloudviz API and Kroki without installing anything?\n\nCloudviz API has a hosted endpoint at https://api.cloudviz.io. No hosted endpoint is listed for Kroki.\n\n### Are Cloudviz API and Kroki open source?\n\nNo open-source release is listed for Cloudviz API. Kroki is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/cloudviz-vs-kroki.json, and with the fewest tokens: https://www.anchorterminal.com/compare/cloudviz-vs-kroki.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"cloudviz\", \"b\": \"kroki\"}`. From a terminal: `anchor compare cloudviz kroki`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/cloudviz.json and https://www.anchorterminal.com/api/v1/tools/kroki.json\n\n## Other comparisons with Cloudviz API or Kroki\n\n- [Cloudviz API vs D2](https://www.anchorterminal.com/compare/cloudviz-vs-d2.md)\n- [Cloudviz API vs Diagrams.so API + MCP](https://www.anchorterminal.com/compare/cloudviz-vs-diagrams-so.md)\n- [Cloudviz API vs draw.io + MCP](https://www.anchorterminal.com/compare/cloudviz-vs-drawio.md)\n- [Cloudviz API vs Eraser API + MCP](https://www.anchorterminal.com/compare/cloudviz-vs-eraser.md)\n- [Cloudviz API vs Excalidraw](https://www.anchorterminal.com/compare/cloudviz-vs-excalidraw.md)\n- [Cloudviz API vs Lucid API + MCP](https://www.anchorterminal.com/compare/cloudviz-vs-lucid.md)\n- [Cloudviz API vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/cloudviz-vs-mermaid-chart.md)\n- [Cloudviz API vs Mural MCP](https://www.anchorterminal.com/compare/cloudviz-vs-mural-mcp.md)\n- [Cloudviz API vs PlantUML](https://www.anchorterminal.com/compare/cloudviz-vs-plantuml.md)\n- [Cloudviz API vs Structurizr + MCP](https://www.anchorterminal.com/compare/cloudviz-vs-structurizr.md)\n- [Cloudviz API vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/cloudviz-vs-tldraw.md)\n- [Cloudviz API vs Whimsical MCP](https://www.anchorterminal.com/compare/cloudviz-vs-whimsical.md)\n- [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md)\n- [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md)\n- [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md)\n- [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md)\n- [Kroki vs Mural MCP](https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md)\n- [Kroki vs Whimsical MCP](https://www.anchorterminal.com/compare/kroki-vs-whimsical.md)\n- [D2 vs Kroki](https://www.anchorterminal.com/compare/d2-vs-kroki.md)\n- [Kroki vs Lucid API + MCP](https://www.anchorterminal.com/compare/kroki-vs-lucid.md)\n- [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md)\n- [Kroki vs PlantUML](https://www.anchorterminal.com/compare/kroki-vs-plantuml.md)\n- [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md)\n- [Kroki vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/kroki-vs-tldraw.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Cloudviz API vs Kroki",
        "url": ""
      }
    ],
    "description": "Kroki scores 59.2 (C) to Cloudviz's 37.7 (F) for diagram creation. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Cloudviz API F 37.7",
      "Kroki C 59.2",
      "scores"
    ],
    "h1": "Cloudviz API vs Kroki",
    "image": "https://www.anchorterminal.com/assets/og/compare-cloudviz-vs-kroki.png",
    "path": "/compare/cloudviz-vs-kroki",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Cloudviz vs Kroki for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki"
  },
  "tokens": {
    "markdown": 2400,
    "slim": 680
  },
  "version": 1
}
