{
  "data": {
    "a": {
      "slug": "d2",
      "name": "D2",
      "vendor": "D2 project (The Hack Foundation)",
      "vendorUrl": "https://d2lang.com",
      "kind": "sdk",
      "category": "diagramming",
      "summary": "D2 is an open-source diagram scripting language that turns text into SVG, PNG, PDF, PPTX, GIF or ASCII diagrams. Agents run it as a local CLI, a Go library or the `@d2lang/d2` WebAssembly package.",
      "url": "https://www.anchorterminal.com/tools/d2",
      "markdownUrl": "https://www.anchorterminal.com/tools/d2.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/d2.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/d2.json",
      "repo": "https://github.com/d2lang/d2",
      "license": "MPL-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@d2lang/d2"
        },
        {
          "registry": "go",
          "name": "github.com/d2lang/d2"
        },
        {
          "registry": "oci",
          "name": "d2lang/d2"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or login. The CLI, the Go library and the WebAssembly package run on the owner's machine with the owner's file and network rights. `d2 --watch` serves a preview on localhost.",
      "pricing": "free",
      "pricingNotes": "Free under MPL-2.0 with nothing to buy. The TALA layout engine, once a paid plugin with a licence key, has been bundled and open source since 0.9.0. The project takes donations through a public Hack Club fund (https://d2lang.com/sponsor/).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source. The maintainer's 5 September 2026 post rules out any server-side service (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 25581,
        "npmWeekly": 21627,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://d2lang.com/tour/intro/",
      "capabilities": [
        "diagram.as-code",
        "diagram.create",
        "diagram.export",
        "diagram.edit",
        "diagram.architecture"
      ],
      "tags": [
        "open-source",
        "local",
        "cli",
        "go",
        "wasm",
        "diagram-as-code",
        "no-auth",
        "free",
        "non-profit",
        "docker"
      ],
      "lastRelease": "2026-09-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.3,
        "grade": "B",
        "agentReady": false,
        "rank": 322,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 74,
          "payments": 60,
          "reliability": 68,
          "schema": 65,
          "security": 48,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "A single local command turns text into a diagram in six formats with no account, key or network call, and CI passes on the default branch. The language is at 0.9.0 with no stable release, its company sponsor has shut down, and one maintainer with limited time wrote every commit since July.",
        "bestFor": "Agents that need to produce or edit architecture, sequence, grid, SQL table or class diagrams as reviewable text and render them locally.",
        "strengths": [
          "One command reads D2 from stdin and writes SVG, PNG, PDF, PPTX, GIF or ASCII to stdout, with no account or key",
          "MPL-2.0 throughout, and the TALA layout engine has been open source and bundled since 0.9.0 on 7 September 2026",
          "`d2 validate` and `d2 fmt --check` let an agent test a diagram before rendering it",
          "The `d2oracle` Go package creates, sets, moves, renames and deletes shapes without mutating the input graph",
          "Release archives carry SHA-256 sums, signed provenance and SBOM attestations since 0.8.2"
        ],
        "weaknesses": [
          "No 1.0 release. The maintainer lists a stable 1.0 with a formal grammar as a goal, and 0.8.2 changed Dagre and ELK layout output",
          "Terrastruct, the company that built D2, is shutting down. The project is now donation-funded under The Hack Foundation",
          "All 317 commits since 8 July 2026 are by one maintainer, who says his time on D2 is limited",
          "A security hardening pass merged on 11 and 12 September 2026 is not in a release yet, and the repository has no security policy",
          "No llms.txt, no machine-readable grammar and no MCP server. The maintainer rules out an MCP server and a hosted API"
        ],
        "agentNotes": [
          "Check the exit status of `d2`, never the output file. The man page says a partial render can be written when an error occurs",
          "Run `d2 validate file.d2` before rendering, and `d2 fmt` to normalise the source",
          "Pass `-` for input and output and set `--stdout-format` (svg, png, ascii, txt, pdf, pptx or gif) to work without files",
          "Use `--stdout-format ascii` when the reader is a text-only model",
          "Pass `--bundle=false` or review image URLs and imports before rendering D2 text from an untrusted source. Release 0.9.0 fetches remote images when bundling"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.3
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 74,
          "payments": 60,
          "reliability": 68,
          "schema": 65,
          "security": 48,
          "transparency": 74
        },
        "provenanceScore": 63
      },
      "connect": {
        "install": "curl -fsSL https://d2lang.com/install.sh | sh -s --   # or: brew install d2, go install github.com/d2lang/d2@latest, npm install @d2lang/d2"
      },
      "letme": {
        "capability": "https://letme.dev/diagram.as-code",
        "tool": "https://letme.dev/d2"
      },
      "area": "design-diagrams",
      "provenance": {
        "legalEntity": "The Hack Foundation (Hack Club), fiscal sponsor of the D2 project",
        "domain": "d2lang.com",
        "domainRegistered": "2022-10-24",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://d2lang.com/releases/intro/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The sponsor page says D2 is fiscally sponsored by The Hack Foundation, the 501(c)(3) nonprofit behind Hack Club, after the lead maintainer donated the project in August 2026 (https://d2lang.com/sponsor/)",
          "LICENSE.txt still reads Copyright 2022 Terrastruct Inc. The 5 September 2026 post says that company is shutting down, and terrastruct.com now redirects to d2lang.com",
          "No terms or privacy document governs the software. The MPL-2.0 licence stands in",
          "https://d2lang.com/.well-known/security.txt answered 404 on 8 October 2026, and the repository has no SECURITY.md",
          "The repository moved from github.com/terrastruct/d2, which redirects, to github.com/d2lang/d2"
        ],
        "score": 63
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/d2.json",
      "live": {
        "slug": "d2",
        "versions": [
          {
            "registry": "github",
            "name": "d2lang/d2",
            "version": "v0.9.0",
            "released": "2026-09-07",
            "seenAt": "2026-10-09T16:48:21.247085679Z"
          },
          {
            "registry": "npm",
            "name": "@d2lang/d2",
            "version": "0.1.34",
            "seenAt": "2026-10-09T16:48:20.267156647Z"
          }
        ],
        "githubStars": 25589,
        "npmWeekly": 14992,
        "securityTxt": {
          "url": "https://d2lang.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:39:21.206946684Z"
        },
        "pages": [
          {
            "url": "https://d2lang.com/releases/intro/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:34:34.851222156Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9eb891f2acbe"
          }
        ],
        "updatedAt": "2026-10-09T18:34:34.851222156Z"
      }
    },
    "answer": "D2 scores 65.3 (B) on agent readiness against Kroki's 59.2 (C), and leads in 3 of 7 scored categories. Kroki leads on reliability, security \u0026 auth and maintenance \u0026 community.",
    "b": {
      "slug": "kroki",
      "name": "Kroki",
      "vendor": "Yuzu tech",
      "vendorUrl": "https://kroki.io",
      "kind": "http-api",
      "category": "diagramming",
      "summary": "Kroki is an open-source HTTP server from Yuzu tech that converts diagram text in 29 formats, including PlantUML, Mermaid, GraphViz and D2, into SVG, PNG or PDF. Owners run it from Docker images, and kroki.io is a free public instance.",
      "url": "https://www.anchorterminal.com/tools/kroki",
      "markdownUrl": "https://www.anchorterminal.com/tools/kroki.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kroki.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kroki.json",
      "repo": "https://github.com/yuzutech/kroki",
      "license": "MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "yuzutech/kroki"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-mermaid"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-bpmn"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-excalidraw"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or login on the convert endpoints, on a self-hosted server or on the public instance at kroki.io. The server binds all interfaces on port 8000 unless `KROKI_LISTEN` says otherwise. An optional bearer token, `KROKI_COMPANION_REGISTRATION_TOKEN`, protects only the `/services` registration API, which is off by default.",
      "pricing": "free",
      "pricingNotes": "Free under the MIT licence, with nothing to buy. The public instance at kroki.io is free and paid for by sponsors, for reasonable, non-commercial use with no uptime guarantee. Third parties sell hosting, which the project says it does not operate.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4365,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.kroki.io/kroki/setup/usage/",
      "capabilities": [
        "diagram.as-code",
        "diagram.create",
        "diagram.export",
        "diagram.architecture"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "http-api",
        "docker",
        "diagram-as-code",
        "plantuml",
        "mermaid",
        "graphviz",
        "no-auth",
        "free"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.2,
        "grade": "C",
        "agentReady": false,
        "rank": 558,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -5,
        "negativeNotes": [
          "27 July to 12 August 2026. Four advisories on the repository. GHSA-wmpp-fj9c-w766 (critical, CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in 0.21.0 up to 0.32.0 whatever the safe mode. GHSA-r54f-fq6c-53vw (high, CVE-2026-102359), GHSA-px99-rjv4-49g8 (medium, CVE-2026-102356) and GHSA-9p7m-vrmg-qp4q (high) let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed, in 0.32.1 at the latest, and the maintainers published each with a changelog entry, so the deduction is five points (https://github.com/yuzutech/kroki/security/advisories)."
        ],
        "verdict": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
        "bestFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "strengths": [
          "`POST /` with `diagram_source`, `diagram_type` and `output_format`, or plain text to `/\u003ctype\u003e/\u003cformat\u003e`, returns the image. No account or key",
          "One API covers 29 diagram types, among them PlantUML, C4, Structurizr, Mermaid, GraphViz, D2, DBML, BPMN, Excalidraw and Vega",
          "`KROKI_SAFE_MODE` defaults to `SECURE`, which blocks file and network reads by diagram libraries, and the container runs as the non-root user `kroki`",
          "Five versions shipped between 15 July and 5 October 2026, and the `main.yaml` workflow passed on the last ten pushes to `main`",
          "MIT licence. The maintainers published four security advisories in 2026, each with a fixed version and a changelog entry"
        ],
        "weaknesses": [
          "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026",
          "Three more advisories in July and August 2026 let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed in 0.32.1",
          "No OpenAPI file, llms.txt or error catalogue. The JSON error shape is in the source and not in the documentation",
          "The public instance at kroki.io has no terms, privacy policy, status page or published rate limit. The CLI page limits the demonstration server to reasonable, non-commercial use",
          "The server has no authentication on its convert endpoints and binds all interfaces on port 8000 by default. The version is 0.33.0, with no 1.0"
        ],
        "agentNotes": [
          "Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs",
          "Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image",
          "Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers",
          "Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode",
          "Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.2
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 67
        },
        "provenanceScore": 56
      },
      "connect": {
        "install": "docker run -p8000:8000 yuzutech/kroki",
        "http": "curl https://kroki.io/graphviz/svg --data-raw 'digraph G {Hello-\u003eWorld}'"
      },
      "letme": {
        "capability": "https://letme.dev/diagram.as-code",
        "tool": "https://letme.dev/kroki"
      },
      "area": "design-diagrams",
      "provenance": {
        "legalEntity": "Yuzu tech, a French software firm. No registered legal form found",
        "domain": "kroki.io",
        "domainRegistered": "2019-01-06",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/yuzutech/kroki/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The kroki.io home page says Kroki is built and maintained by Yuzu tech, and links https://yuzutech.fr, whose pages name no legal form or registration number. `LICENSE` reads Copyright (c) 2020-present Kroki",
          "No terms or privacy document was found on kroki.io or docs.kroki.io, for the software or for the public instance. The MIT licence stands in for the software",
          "https://kroki.io/.well-known/security.txt answered 404 on 9 October 2026. `SECURITY.md` asks for reports through a private GitHub security advisory",
          "The lead wrote the vendor as Yuzutech. The site writes Yuzu tech, and the GitHub organisation is `yuzutech`",
          "The endpoint on the vendor's domain is the free public instance. The listing grades the server an owner runs"
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kroki.json",
      "live": {
        "slug": "kroki",
        "versions": [
          {
            "registry": "github",
            "name": "yuzutech/kroki",
            "version": "v0.33.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-09T17:00:57.82489933Z"
          }
        ],
        "githubStars": 4365,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/yuzutech/kroki/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:46:31.151891385Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3e34fa594488"
          }
        ],
        "updatedAt": "2026-10-09T18:46:31.151891385Z"
      }
    },
    "facts": [
      {
        "a": "SDK + MCP",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "D2 project (The Hack Foundation)",
        "b": "Yuzu tech",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MPL-2.0",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-07",
        "b": "2026-10-05",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "26k stars, 22k npm/wk",
        "b": "4.4k stars",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "D2 scores 65.3 (B) on agent readiness against Kroki's 59.2 (C), and leads in 3 of 7 scored categories. Kroki leads on reliability, security \u0026 auth and maintenance \u0026 community.",
        "question": "Which is better for AI agents, D2 or Kroki?"
      },
      {
        "answer": "No hosted endpoint is listed for D2. No hosted endpoint is listed for Kroki.",
        "question": "Can an agent call D2 and Kroki without installing anything?"
      },
      {
        "answer": "Yes. D2 is open source (MPL-2.0). Kroki is open source (MIT).",
        "question": "Are D2 and Kroki open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 65 against 48",
          "Agent ergonomics, 78 against 70",
          "Transparency \u0026 trust, 69 against 62"
        ],
        "also": [
          "No incidents deducted, where Kroki loses 5 points for them"
        ],
        "goodFor": "Agents that need to produce or edit architecture, sequence, grid, SQL table or class diagrams as reviewable text and render them locally.",
        "slug": "d2",
        "watchFor": "No 1.0 release. The maintainer lists a stable 1.0 with a formal grammar as a goal, and 0.8.2 changed Dagre and ELK layout output"
      },
      {
        "aheadOn": [
          "Reliability, 74 against 68",
          "Security \u0026 auth, 56 against 48",
          "Maintenance \u0026 community, 86 against 74"
        ],
        "also": null,
        "goodFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "slug": "kroki",
        "watchFor": "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026"
      }
    ],
    "job": {
      "capability": "diagram.as-code",
      "name": "Diagrams as code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-d2.json",
        "title": "Cloudviz API vs D2",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-d2"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki.json",
        "title": "Cloudviz API vs Kroki",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-diagrams-so.json",
        "title": "D2 vs Diagrams.so API + MCP",
        "url": "https://www.anchorterminal.com/compare/d2-vs-diagrams-so"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-mural-mcp.json",
        "title": "D2 vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/d2-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-whimsical.json",
        "title": "D2 vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/d2-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.json",
        "title": "Diagrams.so API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-kroki.json",
        "title": "draw.io + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-kroki.json",
        "title": "Eraser API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki.json",
        "title": "Excalidraw vs Kroki",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.json",
        "title": "Kroki vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-whimsical.json",
        "title": "Kroki vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-drawio.json",
        "title": "D2 vs draw.io + MCP",
        "url": "https://www.anchorterminal.com/compare/d2-vs-drawio"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-eraser.json",
        "title": "D2 vs Eraser API + MCP",
        "url": "https://www.anchorterminal.com/compare/d2-vs-eraser"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-excalidraw.json",
        "title": "D2 vs Excalidraw",
        "url": "https://www.anchorterminal.com/compare/d2-vs-excalidraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-lucid.json",
        "title": "D2 vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/d2-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-mermaid-chart.json",
        "title": "D2 vs Mermaid Chart MCP",
        "url": "https://www.anchorterminal.com/compare/d2-vs-mermaid-chart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-plantuml.json",
        "title": "D2 vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/d2-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-structurizr.json",
        "title": "D2 vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/d2-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-tldraw.json",
        "title": "D2 vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/d2-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-lucid.json",
        "title": "Kroki vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.json",
        "title": "Kroki vs Mermaid Chart MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-plantuml.json",
        "title": "Kroki vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-structurizr.json",
        "title": "Kroki vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-tldraw.json",
        "title": "Kroki vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-tldraw"
      }
    ],
    "scores": [
      {
        "by": 6,
        "d2": 68,
        "edge": "kroki",
        "key": "reliability",
        "kroki": 74,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 17,
        "d2": 65,
        "edge": "d2",
        "key": "schema",
        "kroki": 48,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 8,
        "d2": 78,
        "edge": "d2",
        "key": "ergonomics",
        "kroki": 70,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 8,
        "d2": 48,
        "edge": "kroki",
        "key": "security",
        "kroki": 56,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 0,
        "d2": 60,
        "edge": "",
        "key": "payments",
        "kroki": 60,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 12,
        "d2": 74,
        "edge": "kroki",
        "key": "maintenance",
        "kroki": 86,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 7,
        "d2": 69,
        "edge": "d2",
        "key": "transparency",
        "kroki": 62,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "D2 scores 65.3 (B) on agent readiness against Kroki's 59.2 (C), and leads in 3 of 7 scored categories. Kroki leads on reliability, security \u0026 auth and maintenance \u0026 community. Both do diagrams as code.",
    "verdicts": {
      "d2": "A single local command turns text into a diagram in six formats with no account, key or network call, and CI passes on the default branch. The language is at 0.9.0 with no stable release, its company sponsor has shut down, and one maintainer with limited time wrote every commit since July.",
      "kroki": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/d2-vs-kroki",
    "json": "https://www.anchorterminal.com/compare/d2-vs-kroki.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/d2-vs-kroki.md",
    "slim": "https://www.anchorterminal.com/compare/d2-vs-kroki.min.md"
  },
  "markdown": "D2 scores 65.3 (B) on agent readiness against Kroki's 59.2 (C), and leads in 3 of 7 scored categories. Kroki leads on reliability, security \u0026 auth and maintenance \u0026 community. Both do diagrams as code.\n\n- D2: grade B, 65.3/100, rank #322 of 950. Markdown https://www.anchorterminal.com/tools/d2.md · JSON https://www.anchorterminal.com/api/v1/tools/d2.json\n- Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json\n- Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md\n- All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md\n\n## Which one, for what\n\n### D2 (B)\n\nGood for: Agents that need to produce or edit architecture, sequence, grid, SQL table or class diagrams as reviewable text and render them locally.\n\nAhead on:\n- Schema \u0026 documentation, 65 against 48\n- Agent ergonomics, 78 against 70\n- Transparency \u0026 trust, 69 against 62\n\nAlso in its favour:\n- No incidents deducted, where Kroki loses 5 points for them\n\nWatch for: No 1.0 release. The maintainer lists a stable 1.0 with a formal grammar as a goal, and 0.8.2 changed Dagre and ELK layout output\n\n### Kroki (C)\n\nGood for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.\n\nAhead on:\n- Reliability, 74 against 68\n- Security \u0026 auth, 56 against 48\n- Maintenance \u0026 community, 86 against 74\n\nWatch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026\n\n\n## Score by category\n\n| Category | Weight | D2 | Kroki | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 68 | 74 | Kroki +6 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 65 | 48 | D2 +17 |\n| Agent ergonomics | 13% (16.2 this run) | 78 | 70 | D2 +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 48 | 56 | Kroki +8 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 60 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 74 | 86 | Kroki +12 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 69 | 62 | D2 +7 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **65.3 · B** | **59.2 · C** | |\n\n## Facts side by side\n\n| Fact | D2 | Kroki |\n| --- | --- | --- |\n| Kind | SDK + MCP | HTTP API |\n| Vendor | D2 project (The Hack Foundation) | Yuzu tech |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  | HTTP |\n| Auth | None | None |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | MPL-2.0 | MIT |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| Last release | 2026-09-07 | 2026-10-05 |\n| Terms last updated | no document linked | no document linked |\n| Privacy policy last updated | no document linked | no document linked |\n| Customer content may train models |  |  |\n| Terms restrict automated access |  |  |\n| Terms restrict benchmarking |  |  |\n| Terms or service can change without notice |  |  |\n| Arbitration or class-action waiver |  |  |\n| Popularity | 26k stars, 22k npm/wk | 4.4k stars |\n\n## Verdicts\n\n**D2.** A single local command turns text into a diagram in six formats with no account, key or network call, and CI passes on the default branch. The language is at 0.9.0 with no stable release, its company sponsor has shut down, and one maintainer with limited time wrote every commit since July.\n\n**Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.\n\n## Before you call either\n\n### D2\n\n1. Check the exit status of `d2`, never the output file. The man page says a partial render can be written when an error occurs\n2. Run `d2 validate file.d2` before rendering, and `d2 fmt` to normalise the source\n3. Pass `-` for input and output and set `--stdout-format` (svg, png, ascii, txt, pdf, pptx or gif) to work without files\n4. Use `--stdout-format ascii` when the reader is a text-only model\n5. Pass `--bundle=false` or review image URLs and imports before rendering D2 text from an untrusted source. Release 0.9.0 fetches remote images when bundling\n\n### Kroki\n\n1. Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs\n2. Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image\n3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers\n4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode\n5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication\n\n## Questions\n\n### Which is better for AI agents, D2 or Kroki?\n\nD2 scores 65.3 (B) on agent readiness against Kroki's 59.2 (C), and leads in 3 of 7 scored categories. Kroki leads on reliability, security \u0026 auth and maintenance \u0026 community.\n\n### Can an agent call D2 and Kroki without installing anything?\n\nNo hosted endpoint is listed for D2. No hosted endpoint is listed for Kroki.\n\n### Are D2 and Kroki open source?\n\nYes. D2 is open source (MPL-2.0). Kroki is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/d2-vs-kroki.json, and with the fewest tokens: https://www.anchorterminal.com/compare/d2-vs-kroki.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"d2\", \"b\": \"kroki\"}`. From a terminal: `anchor compare d2 kroki`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/d2.json and https://www.anchorterminal.com/api/v1/tools/kroki.json\n\n## Other comparisons with D2 or Kroki\n\n- [Cloudviz API vs D2](https://www.anchorterminal.com/compare/cloudviz-vs-d2.md)\n- [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md)\n- [D2 vs Diagrams.so API + MCP](https://www.anchorterminal.com/compare/d2-vs-diagrams-so.md)\n- [D2 vs Mural MCP](https://www.anchorterminal.com/compare/d2-vs-mural-mcp.md)\n- [D2 vs Whimsical MCP](https://www.anchorterminal.com/compare/d2-vs-whimsical.md)\n- [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md)\n- [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md)\n- [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md)\n- [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md)\n- [Kroki vs Mural MCP](https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md)\n- [Kroki vs Whimsical MCP](https://www.anchorterminal.com/compare/kroki-vs-whimsical.md)\n- [D2 vs draw.io + MCP](https://www.anchorterminal.com/compare/d2-vs-drawio.md)\n- [D2 vs Eraser API + MCP](https://www.anchorterminal.com/compare/d2-vs-eraser.md)\n- [D2 vs Excalidraw](https://www.anchorterminal.com/compare/d2-vs-excalidraw.md)\n- [D2 vs Lucid API + MCP](https://www.anchorterminal.com/compare/d2-vs-lucid.md)\n- [D2 vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/d2-vs-mermaid-chart.md)\n- [D2 vs PlantUML](https://www.anchorterminal.com/compare/d2-vs-plantuml.md)\n- [D2 vs Structurizr + MCP](https://www.anchorterminal.com/compare/d2-vs-structurizr.md)\n- [D2 vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/d2-vs-tldraw.md)\n- [Kroki vs Lucid API + MCP](https://www.anchorterminal.com/compare/kroki-vs-lucid.md)\n- [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md)\n- [Kroki vs PlantUML](https://www.anchorterminal.com/compare/kroki-vs-plantuml.md)\n- [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md)\n- [Kroki vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/kroki-vs-tldraw.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "D2 vs Kroki",
        "url": ""
      }
    ],
    "description": "D2 scores 65.3 (B) to Kroki's 59.2 (C) for diagrams as code. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "D2 B 65.3",
      "Kroki C 59.2",
      "scores"
    ],
    "h1": "D2 vs Kroki",
    "image": "https://www.anchorterminal.com/assets/og/compare-d2-vs-kroki.png",
    "path": "/compare/d2-vs-kroki",
    "published": "2026-10-01",
    "section": "tools",
    "title": "D2 vs Kroki for AI agents in 2026: scores and prices | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/d2-vs-kroki"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 530
  },
  "version": 1
}
