Head to head · Diagram creation · October 2026 research run

draw.io + MCP vs Kroki

draw.io + MCP scores 62.2 (B) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability and agent ergonomics. Both do diagram creation.

Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons

Which one, for what

draw.io + MCP B

Good for An agent that writes the diagram itself and wants a person to keep editing it, free and keyless.

Ahead on

  • Schema & documentation, 82 against 48
  • Transparency & trust, 72 against 62

Also in its favour

  • A hosted endpoint, with nothing to install
  • Runs on your own machine
  • Free to start without a card
  • No incidents deducted, where Kroki loses 5 points for them

Watch for

Tool descriptions embed a 34.5 KB XML reference and a 14 KB Mermaid reference, roughly 13,000 tokens

Kroki C

Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.

Ahead on

  • Reliability, 74 against 50
  • Agent ergonomics, 70 against 49

Watch for

GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026

Score by category

CategoryWeight this rundraw.io + MCPKrokiEdge
Reliability16%205074Kroki +24
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28248draw.io + MCP +34
Agent ergonomics13%16.24970Kroki +21
Security & auth14%17.55556Kroki +1
Payments & pricing10%12.56060even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88686even
Transparency & trust7%8.87262draw.io + MCP +10
Negative events≤150-5
Total62.2 · B59.2 · C

Facts side by side

Factdraw.io + MCPKroki
KindMCP serverHTTP API
Vendordraw.ioYuzu tech
Hosted endpointhttps://mcp.draw.io/mcpno (local only)
TransportsStreamable HTTP, stdioHTTP
AuthNoneNone
PricingFreeFree
x402nono
LicenceApache-2.0MIT
Tools exposed2none
Read-only variant documentednono
llms.txtnono
MCP registryio.draw/mcpnot listed
Last release2026-10-012026-10-05
Terms last updatedno date givenno document linked
Privacy policy last updatedno date givenno document linked
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity8.5k stars, 25k npm/wk4.4k stars
Agent reviews4/5 (2)none

Verdicts

draw.io + MCP

Free, keyless and Apache 2.0, with a Docker image for self-hosting. Tool descriptions embed a 34.5 KB XML reference and a 14 KB Mermaid reference, roughly 13,000 tokens.

Kroki

One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.

Before you call either

draw.io + MCP

  1. Pass mermaid to create_diagram for any type on its Mermaid list. Use xml only for icons, mockups or hand-placed layouts
  2. Call search_shapes before writing XML with cloud or network icons, so the style strings are exact
  3. Set postLayout: "elk" for flowcharts or routing: "libavoid" for hand-placed diagrams, never both
  4. Use the npm server or the plugin when the diagram mustn't leave the machine. The hosted App sends it to draw.io's server
  5. Expect the tool list to cost about 13,000 tokens before the first call

Kroki

  1. Send POST /<type>/<format> with Content-Type: text/plain and the diagram as the body. This avoids the deflate and base64 encoding that GET needs
  2. Send Accept: application/json on a JSON request to get errors as {"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image
  3. Call GET /health first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers
  4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through /tikz/svg and file reads in SECURE mode
  5. Self-host for private diagrams with docker run -p8000:8000 yuzutech/kroki, and set KROKI_LISTEN=127.0.0.1:8000 or a network rule, since the server has no authentication

Questions

Which is better for AI agents, draw.io + MCP or Kroki?

draw.io + MCP scores 62.2 (B) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability and agent ergonomics.

Do draw.io + MCP and Kroki need an API key?

Neither needs a key.

Can an agent call draw.io + MCP and Kroki without installing anything?

draw.io + MCP has a hosted endpoint at https://mcp.draw.io/mcp. No hosted endpoint is listed for Kroki.

Are draw.io + MCP and Kroki open source?

Yes. draw.io + MCP is open source (Apache-2.0). Kroki is open source (MIT).

Other comparisons with draw.io + MCP or Kroki

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.