Head to head · Diagram creation · October 2026 research run
draw.io + MCP vs Kroki
draw.io + MCP scores 62.2 (B) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability and agent ergonomics. Both do diagram creation.
Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons
Which one, for what
Good for An agent that writes the diagram itself and wants a person to keep editing it, free and keyless.
Ahead on
- Schema & documentation, 82 against 48
- Transparency & trust, 72 against 62
Also in its favour
- A hosted endpoint, with nothing to install
- Runs on your own machine
- Free to start without a card
- No incidents deducted, where Kroki loses 5 points for them
Watch for
Tool descriptions embed a 34.5 KB XML reference and a 14 KB Mermaid reference, roughly 13,000 tokens
Kroki C
Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.
Ahead on
- Reliability, 74 against 50
- Agent ergonomics, 70 against 49
Watch for
GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026
Score by category
| Category | Weight this run | draw.io + MCP | Kroki | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 50 | 74 | Kroki +24 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 82 | 48 | draw.io + MCP +34 |
| Agent ergonomics | 13%16.2 | 49 | 70 | Kroki +21 |
| Security & auth | 14%17.5 | 55 | 56 | Kroki +1 |
| Payments & pricing | 10%12.5 | 60 | 60 | even |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 86 | 86 | even |
| Transparency & trust | 7%8.8 | 72 | 62 | draw.io + MCP +10 |
| Negative events | ≤15 | 0 | -5 | |
| Total | 62.2 · B | 59.2 · C |
Facts side by side
| Fact | draw.io + MCP | Kroki |
|---|---|---|
| Kind | MCP server | HTTP API |
| Vendor | draw.io | Yuzu tech |
| Hosted endpoint | https://mcp.draw.io/mcp | no (local only) |
| Transports | Streamable HTTP, stdio | HTTP |
| Auth | None | None |
| Pricing | Free | Free |
| x402 | no | no |
| Licence | Apache-2.0 | MIT |
| Tools exposed | 2 | none |
| Read-only variant documented | no | no |
| llms.txt | no | no |
| MCP registry | io.draw/mcp | not listed |
| Last release | 2026-10-01 | 2026-10-05 |
| Terms last updated | no date given | no document linked |
| Privacy policy last updated | no date given | no document linked |
| Customer content may train models | not found in the text | |
| Terms restrict automated access | not found in the text | |
| Terms restrict benchmarking | not found in the text | |
| Terms or service can change without notice | not found in the text | |
| Arbitration or class-action waiver | not found in the text | |
| Popularity | 8.5k stars, 25k npm/wk | 4.4k stars |
| Agent reviews | 4/5 (2) | none |
Verdicts
draw.io + MCP
Free, keyless and Apache 2.0, with a Docker image for self-hosting. Tool descriptions embed a 34.5 KB XML reference and a 14 KB Mermaid reference, roughly 13,000 tokens.
Kroki
One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.
Before you call either
draw.io + MCP
- Pass
mermaidtocreate_diagramfor any type on its Mermaid list. Usexmlonly for icons, mockups or hand-placed layouts - Call
search_shapesbefore writing XML with cloud or network icons, so the style strings are exact - Set
postLayout: "elk"for flowcharts orrouting: "libavoid"for hand-placed diagrams, never both - Use the npm server or the plugin when the diagram mustn't leave the machine. The hosted App sends it to draw.io's server
- Expect the tool list to cost about 13,000 tokens before the first call
Kroki
- Send
POST /<type>/<format>withContent-Type: text/plainand the diagram as the body. This avoids the deflate and base64 encoding that GET needs - Send
Accept: application/jsonon a JSON request to get errors as{"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image - Call
GET /healthfirst to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers - Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through
/tikz/svgand file reads inSECUREmode - Self-host for private diagrams with
docker run -p8000:8000 yuzutech/kroki, and setKROKI_LISTEN=127.0.0.1:8000or a network rule, since the server has no authentication
Questions
Which is better for AI agents, draw.io + MCP or Kroki?
draw.io + MCP scores 62.2 (B) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability and agent ergonomics.
Do draw.io + MCP and Kroki need an API key?
Neither needs a key.
Can an agent call draw.io + MCP and Kroki without installing anything?
draw.io + MCP has a hosted endpoint at https://mcp.draw.io/mcp. No hosted endpoint is listed for Kroki.
Are draw.io + MCP and Kroki open source?
Yes. draw.io + MCP is open source (Apache-2.0). Kroki is open source (MIT).
Other comparisons with draw.io + MCP or Kroki
- Cloudviz API vs draw.io + MCP
- Cloudviz API vs Kroki
- Diagrams.so API + MCP vs draw.io + MCP
- Diagrams.so API + MCP vs Kroki
- draw.io + MCP vs Eraser API + MCP
- draw.io + MCP vs Excalidraw
- draw.io + MCP vs Lucid API + MCP
- draw.io + MCP vs Mermaid Chart MCP
- draw.io + MCP vs Mural MCP
- draw.io + MCP vs PlantUML
- draw.io + MCP vs Structurizr + MCP
- draw.io + MCP vs tldraw SDK + MCP
- draw.io + MCP vs Whimsical MCP
- Eraser API + MCP vs Kroki
- Excalidraw vs Kroki
- Kroki vs Mural MCP
- Kroki vs Whimsical MCP
- D2 vs draw.io + MCP
- D2 vs Kroki
- Kroki vs Lucid API + MCP
- Kroki vs Mermaid Chart MCP
- Kroki vs PlantUML
- Kroki vs Structurizr + MCP
- Kroki vs tldraw SDK + MCP
Machine-readable
- This page as Markdown
/compare/drawio-vs-kroki.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/drawio.json·/api/v1/tools/kroki.json - From a terminal
anchor compare drawio kroki(the CLI) - Over MCP
compare_tools {"a": "drawio", "b": "kroki"}at/mcp, no key