Head to head · Diagrams as code · October 2026 research run

D2 vs Kroki

D2 scores 65.3 (B) on agent readiness against Kroki's 59.2 (C), and leads in 3 of 7 scored categories. Kroki leads on reliability, security & auth and maintenance & community. Both do diagrams as code.

Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons

Which one, for what

D2 B

Good for Agents that need to produce or edit architecture, sequence, grid, SQL table or class diagrams as reviewable text and render them locally.

Ahead on

  • Schema & documentation, 65 against 48
  • Agent ergonomics, 78 against 70
  • Transparency & trust, 69 against 62

Also in its favour

  • No incidents deducted, where Kroki loses 5 points for them

Watch for

No 1.0 release. The maintainer lists a stable 1.0 with a formal grammar as a goal, and 0.8.2 changed Dagre and ELK layout output

Kroki C

Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.

Ahead on

  • Reliability, 74 against 68
  • Security & auth, 56 against 48
  • Maintenance & community, 86 against 74

Watch for

GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026

Score by category

CategoryWeight this runD2KrokiEdge
Reliability16%206874Kroki +6
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26548D2 +17
Agent ergonomics13%16.27870D2 +8
Security & auth14%17.54856Kroki +8
Payments & pricing10%12.56060even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87486Kroki +12
Transparency & trust7%8.86962D2 +7
Negative events≤150-5
Total65.3 · B59.2 · C

Facts side by side

FactD2Kroki
KindSDK + MCPHTTP API
VendorD2 project (The Hack Foundation)Yuzu tech
Hosted endpointno (local only)no (local only)
TransportsHTTP
AuthNoneNone
PricingFreeFree
x402nono
LicenceMPL-2.0MIT
Read-only variant documentednono
llms.txtnono
Last release2026-09-072026-10-05
Terms last updatedno document linkedno document linked
Privacy policy last updatedno document linkedno document linked
Customer content may train models
Terms restrict automated access
Terms restrict benchmarking
Terms or service can change without notice
Arbitration or class-action waiver
Popularity26k stars, 22k npm/wk4.4k stars

Verdicts

D2

A single local command turns text into a diagram in six formats with no account, key or network call, and CI passes on the default branch. The language is at 0.9.0 with no stable release, its company sponsor has shut down, and one maintainer with limited time wrote every commit since July.

Kroki

One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.

Before you call either

D2

  1. Check the exit status of d2, never the output file. The man page says a partial render can be written when an error occurs
  2. Run d2 validate file.d2 before rendering, and d2 fmt to normalise the source
  3. Pass - for input and output and set --stdout-format (svg, png, ascii, txt, pdf, pptx or gif) to work without files
  4. Use --stdout-format ascii when the reader is a text-only model
  5. Pass --bundle=false or review image URLs and imports before rendering D2 text from an untrusted source. Release 0.9.0 fetches remote images when bundling

Kroki

  1. Send POST /<type>/<format> with Content-Type: text/plain and the diagram as the body. This avoids the deflate and base64 encoding that GET needs
  2. Send Accept: application/json on a JSON request to get errors as {"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image
  3. Call GET /health first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers
  4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through /tikz/svg and file reads in SECURE mode
  5. Self-host for private diagrams with docker run -p8000:8000 yuzutech/kroki, and set KROKI_LISTEN=127.0.0.1:8000 or a network rule, since the server has no authentication

Questions

Which is better for AI agents, D2 or Kroki?

D2 scores 65.3 (B) on agent readiness against Kroki's 59.2 (C), and leads in 3 of 7 scored categories. Kroki leads on reliability, security & auth and maintenance & community.

Can an agent call D2 and Kroki without installing anything?

No hosted endpoint is listed for D2. No hosted endpoint is listed for Kroki.

Are D2 and Kroki open source?

Yes. D2 is open source (MPL-2.0). Kroki is open source (MIT).

Other comparisons with D2 or Kroki

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.