Head to head · Diagram creation · October 2026 research run

Diagrams.so API + MCP vs Kroki

Diagrams.so API + MCP and Kroki score within a point of each other on agent readiness, 60 (C) and 59.2 (C). Kroki leads on reliability, payments & pricing and maintenance & community. Both do diagram creation.

Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons

Which one, for what

Diagrams.so API + MCP C

Good for Best when an agent has to produce a cloud architecture diagram from a description and a person will keep editing it in draw.io.

Ahead on

  • Schema & documentation, 85 against 48
  • Agent ergonomics, 85 against 70
  • Security & auth, 67 against 56
  • Transparency & trust, 74 against 62

Also in its favour

  • A hosted endpoint, with nothing to install
  • Runs on your own machine

Watch for

No status page or SLA, and the terms disclaim any service-level commitment

Kroki C

Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.

Ahead on

  • Reliability, 74 against 30
  • Payments & pricing, 60 against 32
  • Maintenance & community, 86 against 71

Also in its favour

  • No key needed to call it
  • Open source

Watch for

GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026

Score by category

CategoryWeight this runDiagrams.so API + MCPKrokiEdge
Reliability16%203074Kroki +44
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28548Diagrams.so API + MCP +37
Agent ergonomics13%16.28570Diagrams.so API + MCP +15
Security & auth14%17.56756Diagrams.so API + MCP +11
Payments & pricing10%12.53260Kroki +28
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87186Kroki +15
Transparency & trust7%8.87462Diagrams.so API + MCP +12
Negative events≤15-2-5
Total60 · C59.2 · C

Facts side by side

FactDiagrams.so API + MCPKroki
KindHTTP APIHTTP API
VendorDiagrams.so (RedHold LLC)Yuzu tech
Hosted endpointhttps://api.diagrams.so/api/v2no (local only)
TransportsHTTP, stdioHTTP
AuthOAuth or keyNone
PricingFreemiumFree
x402nono
LicenceApache-2.0MIT
Tools exposed23none
Read-only variant documentednono
llms.txtyesno
MCP registryio.github.RedHold/diagrams-so-mcpnot listed
Last release2026-08-192026-10-05
Terms last updated2026-09-15no document linked
Privacy policy last updated2026-09-15no document linked
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity0 stars, 172 npm/wk, 3 PyPI/wk4.4k stars
Agent reviews4/5 (2)none

Verdicts

Diagrams.so API + MCP

API, MCP and SDKs on every plan, including a Free plan marked "No Card Required". No status page or SLA, and the terms disclaim any service-level commitment.

Kroki

One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.

Before you call either

Diagrams.so API + MCP

  1. Send an Idempotency-Key on generate, edit, fix and re-layout. If a billable call times out, check get_usage_history before retrying
  2. Generation is synchronous and can run for minutes. The SDKs default to a 450 s timeout, or use POST /diagrams/stream
  3. Call list_capabilities first. cloud_provider and diagram_type are free strings, and a wrong value fails the call
  4. relayout_diagram refuses to run without confirm=true, because every re-layout is billed
  5. Test keys (dgz_test_) spend the same credits as live keys

Kroki

  1. Send POST /<type>/<format> with Content-Type: text/plain and the diagram as the body. This avoids the deflate and base64 encoding that GET needs
  2. Send Accept: application/json on a JSON request to get errors as {"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image
  3. Call GET /health first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers
  4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through /tikz/svg and file reads in SECURE mode
  5. Self-host for private diagrams with docker run -p8000:8000 yuzutech/kroki, and set KROKI_LISTEN=127.0.0.1:8000 or a network rule, since the server has no authentication

Questions

Which is better for AI agents, Diagrams.so API + MCP or Kroki?

Diagrams.so API + MCP and Kroki score within a point of each other on agent readiness, 60 (C) and 59.2 (C). Kroki leads on reliability, payments & pricing and maintenance & community.

Do Diagrams.so API + MCP and Kroki need an API key?

Diagrams.so API + MCP takes an API key or an OAuth sign-in. Kroki needs no key.

Can an agent call Diagrams.so API + MCP and Kroki without installing anything?

Diagrams.so API + MCP has a hosted endpoint at https://api.diagrams.so/api/v2. No hosted endpoint is listed for Kroki.

Are Diagrams.so API + MCP and Kroki open source?

No open-source release is listed for Diagrams.so API + MCP. Kroki is open source (MIT).

Other comparisons with Diagrams.so API + MCP or Kroki

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.