Head to head · Diagrams as code · October 2026 research run
D2 vs Kroki
D2 scores 65.3 (B) on agent readiness against Kroki's 59.2 (C), and leads in 3 of 7 scored categories. Kroki leads on reliability, security & auth and maintenance & community. Both do diagrams as code.
Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons
Which one, for what
D2 B
Good for Agents that need to produce or edit architecture, sequence, grid, SQL table or class diagrams as reviewable text and render them locally.
Ahead on
- Schema & documentation, 65 against 48
- Agent ergonomics, 78 against 70
- Transparency & trust, 69 against 62
Also in its favour
- No incidents deducted, where Kroki loses 5 points for them
Watch for
No 1.0 release. The maintainer lists a stable 1.0 with a formal grammar as a goal, and 0.8.2 changed Dagre and ELK layout output
Kroki C
Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.
Ahead on
- Reliability, 74 against 68
- Security & auth, 56 against 48
- Maintenance & community, 86 against 74
Watch for
GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026
Score by category
| Category | Weight this run | D2 | Kroki | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 68 | 74 | Kroki +6 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 65 | 48 | D2 +17 |
| Agent ergonomics | 13%16.2 | 78 | 70 | D2 +8 |
| Security & auth | 14%17.5 | 48 | 56 | Kroki +8 |
| Payments & pricing | 10%12.5 | 60 | 60 | even |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 74 | 86 | Kroki +12 |
| Transparency & trust | 7%8.8 | 69 | 62 | D2 +7 |
| Negative events | ≤15 | 0 | -5 | |
| Total | 65.3 · B | 59.2 · C |
Facts side by side
| Fact | D2 | Kroki |
|---|---|---|
| Kind | SDK + MCP | HTTP API |
| Vendor | D2 project (The Hack Foundation) | Yuzu tech |
| Hosted endpoint | no (local only) | no (local only) |
| Transports | HTTP | |
| Auth | None | None |
| Pricing | Free | Free |
| x402 | no | no |
| Licence | MPL-2.0 | MIT |
| Read-only variant documented | no | no |
| llms.txt | no | no |
| Last release | 2026-09-07 | 2026-10-05 |
| Terms last updated | no document linked | no document linked |
| Privacy policy last updated | no document linked | no document linked |
| Customer content may train models | ||
| Terms restrict automated access | ||
| Terms restrict benchmarking | ||
| Terms or service can change without notice | ||
| Arbitration or class-action waiver | ||
| Popularity | 26k stars, 22k npm/wk | 4.4k stars |
Verdicts
D2
A single local command turns text into a diagram in six formats with no account, key or network call, and CI passes on the default branch. The language is at 0.9.0 with no stable release, its company sponsor has shut down, and one maintainer with limited time wrote every commit since July.
Kroki
One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.
Before you call either
D2
- Check the exit status of
d2, never the output file. The man page says a partial render can be written when an error occurs - Run
d2 validate file.d2before rendering, andd2 fmtto normalise the source - Pass
-for input and output and set--stdout-format(svg, png, ascii, txt, pdf, pptx or gif) to work without files - Use
--stdout-format asciiwhen the reader is a text-only model - Pass
--bundle=falseor review image URLs and imports before rendering D2 text from an untrusted source. Release 0.9.0 fetches remote images when bundling
Kroki
- Send
POST /<type>/<format>withContent-Type: text/plainand the diagram as the body. This avoids the deflate and base64 encoding that GET needs - Send
Accept: application/jsonon a JSON request to get errors as{"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image - Call
GET /healthfirst to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers - Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through
/tikz/svgand file reads inSECUREmode - Self-host for private diagrams with
docker run -p8000:8000 yuzutech/kroki, and setKROKI_LISTEN=127.0.0.1:8000or a network rule, since the server has no authentication
Questions
Which is better for AI agents, D2 or Kroki?
D2 scores 65.3 (B) on agent readiness against Kroki's 59.2 (C), and leads in 3 of 7 scored categories. Kroki leads on reliability, security & auth and maintenance & community.
Can an agent call D2 and Kroki without installing anything?
No hosted endpoint is listed for D2. No hosted endpoint is listed for Kroki.
Are D2 and Kroki open source?
Yes. D2 is open source (MPL-2.0). Kroki is open source (MIT).
Other comparisons with D2 or Kroki
- Cloudviz API vs D2
- Cloudviz API vs Kroki
- D2 vs Diagrams.so API + MCP
- D2 vs Mural MCP
- D2 vs Whimsical MCP
- Diagrams.so API + MCP vs Kroki
- draw.io + MCP vs Kroki
- Eraser API + MCP vs Kroki
- Excalidraw vs Kroki
- Kroki vs Mural MCP
- Kroki vs Whimsical MCP
- D2 vs draw.io + MCP
- D2 vs Eraser API + MCP
- D2 vs Excalidraw
- D2 vs Lucid API + MCP
- D2 vs Mermaid Chart MCP
- D2 vs PlantUML
- D2 vs Structurizr + MCP
- D2 vs tldraw SDK + MCP
- Kroki vs Lucid API + MCP
- Kroki vs Mermaid Chart MCP
- Kroki vs PlantUML
- Kroki vs Structurizr + MCP
- Kroki vs tldraw SDK + MCP
Machine-readable
- This page as Markdown
/compare/d2-vs-kroki.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/d2.json·/api/v1/tools/kroki.json - From a terminal
anchor compare d2 kroki(the CLI) - Over MCP
compare_tools {"a": "d2", "b": "kroki"}at/mcp, no key