# D2 vs Kroki > D2 scores 65.3 (B) to Kroki's 59.2 (C) for diagrams as code. Prices, MCP, x402, uptime and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/d2-vs-kroki - Markdown: https://www.anchorterminal.com/compare/d2-vs-kroki.md (~2,300 tokens) - Slim: https://www.anchorterminal.com/compare/d2-vs-kroki.min.md (~530 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/d2-vs-kroki.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 D2 scores 65.3 (B) on agent readiness against Kroki's 59.2 (C), and leads in 3 of 7 scored categories. Kroki leads on reliability, security & auth and maintenance & community. Both do diagrams as code. - D2: grade B, 65.3/100, rank #322 of 950. Markdown https://www.anchorterminal.com/tools/d2.md · JSON https://www.anchorterminal.com/api/v1/tools/d2.json - Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json - Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md - All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md ## Which one, for what ### D2 (B) Good for: Agents that need to produce or edit architecture, sequence, grid, SQL table or class diagrams as reviewable text and render them locally. Ahead on: - Schema & documentation, 65 against 48 - Agent ergonomics, 78 against 70 - Transparency & trust, 69 against 62 Also in its favour: - No incidents deducted, where Kroki loses 5 points for them Watch for: No 1.0 release. The maintainer lists a stable 1.0 with a formal grammar as a goal, and 0.8.2 changed Dagre and ELK layout output ### Kroki (C) Good for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams. Ahead on: - Reliability, 74 against 68 - Security & auth, 56 against 48 - Maintenance & community, 86 against 74 Watch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026 ## Score by category | Category | Weight | D2 | Kroki | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 68 | 74 | Kroki +6 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 65 | 48 | D2 +17 | | Agent ergonomics | 13% (16.2 this run) | 78 | 70 | D2 +8 | | Security & auth | 14% (17.5 this run) | 48 | 56 | Kroki +8 | | Payments & pricing | 10% (12.5 this run) | 60 | 60 | even | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 74 | 86 | Kroki +12 | | Transparency & trust | 7% (8.8 this run) | 69 | 62 | D2 +7 | | Negative events | ≤15 | 0 | -5 | | | **Total** | | **65.3 · B** | **59.2 · C** | | ## Facts side by side | Fact | D2 | Kroki | | --- | --- | --- | | Kind | SDK + MCP | HTTP API | | Vendor | D2 project (The Hack Foundation) | Yuzu tech | | Hosted endpoint | no (local only) | no (local only) | | Transports | | HTTP | | Auth | None | None | | Pricing | Free | Free | | x402 | no | no | | Licence | MPL-2.0 | MIT | | Read-only variant documented | no | no | | llms.txt | no | no | | Last release | 2026-09-07 | 2026-10-05 | | Terms last updated | no document linked | no document linked | | Privacy policy last updated | no document linked | no document linked | | Customer content may train models | | | | Terms restrict automated access | | | | Terms restrict benchmarking | | | | Terms or service can change without notice | | | | Arbitration or class-action waiver | | | | Popularity | 26k stars, 22k npm/wk | 4.4k stars | ## Verdicts **D2.** A single local command turns text into a diagram in six formats with no account, key or network call, and CI passes on the default branch. The language is at 0.9.0 with no stable release, its company sponsor has shut down, and one maintainer with limited time wrote every commit since July. **Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page. ## Before you call either ### D2 1. Check the exit status of `d2`, never the output file. The man page says a partial render can be written when an error occurs 2. Run `d2 validate file.d2` before rendering, and `d2 fmt` to normalise the source 3. Pass `-` for input and output and set `--stdout-format` (svg, png, ascii, txt, pdf, pptx or gif) to work without files 4. Use `--stdout-format ascii` when the reader is a text-only model 5. Pass `--bundle=false` or review image URLs and imports before rendering D2 text from an untrusted source. Release 0.9.0 fetches remote images when bundling ### Kroki 1. Send `POST //` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs 2. Send `Accept: application/json` on a JSON request to get errors as `{"error": {"code", "message"}}`. With an SVG Accept header the error arrives as an image 3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers 4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode 5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication ## Questions ### Which is better for AI agents, D2 or Kroki? D2 scores 65.3 (B) on agent readiness against Kroki's 59.2 (C), and leads in 3 of 7 scored categories. Kroki leads on reliability, security & auth and maintenance & community. ### Can an agent call D2 and Kroki without installing anything? No hosted endpoint is listed for D2. No hosted endpoint is listed for Kroki. ### Are D2 and Kroki open source? Yes. D2 is open source (MPL-2.0). Kroki is open source (MIT). ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/d2-vs-kroki.json, and with the fewest tokens: https://www.anchorterminal.com/compare/d2-vs-kroki.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "d2", "b": "kroki"}`. From a terminal: `anchor compare d2 kroki` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/d2.json and https://www.anchorterminal.com/api/v1/tools/kroki.json ## Other comparisons with D2 or Kroki - [Cloudviz API vs D2](https://www.anchorterminal.com/compare/cloudviz-vs-d2.md) - [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md) - [D2 vs Diagrams.so API + MCP](https://www.anchorterminal.com/compare/d2-vs-diagrams-so.md) - [D2 vs Mural MCP](https://www.anchorterminal.com/compare/d2-vs-mural-mcp.md) - [D2 vs Whimsical MCP](https://www.anchorterminal.com/compare/d2-vs-whimsical.md) - [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md) - [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md) - [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md) - [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md) - [Kroki vs Mural MCP](https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md) - [Kroki vs Whimsical MCP](https://www.anchorterminal.com/compare/kroki-vs-whimsical.md) - [D2 vs draw.io + MCP](https://www.anchorterminal.com/compare/d2-vs-drawio.md) - [D2 vs Eraser API + MCP](https://www.anchorterminal.com/compare/d2-vs-eraser.md) - [D2 vs Excalidraw](https://www.anchorterminal.com/compare/d2-vs-excalidraw.md) - [D2 vs Lucid API + MCP](https://www.anchorterminal.com/compare/d2-vs-lucid.md) - [D2 vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/d2-vs-mermaid-chart.md) - [D2 vs PlantUML](https://www.anchorterminal.com/compare/d2-vs-plantuml.md) - [D2 vs Structurizr + MCP](https://www.anchorterminal.com/compare/d2-vs-structurizr.md) - [D2 vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/d2-vs-tldraw.md) - [Kroki vs Lucid API + MCP](https://www.anchorterminal.com/compare/kroki-vs-lucid.md) - [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md) - [Kroki vs PlantUML](https://www.anchorterminal.com/compare/kroki-vs-plantuml.md) - [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md) - [Kroki vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/kroki-vs-tldraw.md)