# draw.io + MCP vs Kroki > draw.io scores 62.2 (B) to Kroki's 59.2 (C) for diagram creation. Prices, MCP, x402, uptime and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/drawio-vs-kroki - Markdown: https://www.anchorterminal.com/compare/drawio-vs-kroki.md (~2,400 tokens) - Slim: https://www.anchorterminal.com/compare/drawio-vs-kroki.min.md (~680 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/drawio-vs-kroki.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 draw.io + MCP scores 62.2 (B) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability and agent ergonomics. Both do diagram creation. - draw.io + MCP: grade B, 62.2/100, rank #439 of 950. Markdown https://www.anchorterminal.com/tools/drawio.md · JSON https://www.anchorterminal.com/api/v1/tools/drawio.json - Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json - Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md - All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md ## Which one, for what ### draw.io + MCP (B) Good for: An agent that writes the diagram itself and wants a person to keep editing it, free and keyless. Ahead on: - Schema & documentation, 82 against 48 - Transparency & trust, 72 against 62 Also in its favour: - A hosted endpoint, with nothing to install - Runs on your own machine - Free to start without a card - No incidents deducted, where Kroki loses 5 points for them Watch for: Tool descriptions embed a 34.5 KB XML reference and a 14 KB Mermaid reference, roughly 13,000 tokens ### Kroki (C) Good for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams. Ahead on: - Reliability, 74 against 50 - Agent ergonomics, 70 against 49 Watch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026 ## Score by category | Category | Weight | draw.io + MCP | Kroki | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 50 | 74 | Kroki +24 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 82 | 48 | draw.io + MCP +34 | | Agent ergonomics | 13% (16.2 this run) | 49 | 70 | Kroki +21 | | Security & auth | 14% (17.5 this run) | 55 | 56 | Kroki +1 | | Payments & pricing | 10% (12.5 this run) | 60 | 60 | even | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 86 | 86 | even | | Transparency & trust | 7% (8.8 this run) | 72 | 62 | draw.io + MCP +10 | | Negative events | ≤15 | 0 | -5 | | | **Total** | | **62.2 · B** | **59.2 · C** | | ## Facts side by side | Fact | draw.io + MCP | Kroki | | --- | --- | --- | | Kind | MCP server | HTTP API | | Vendor | draw.io | Yuzu tech | | Hosted endpoint | `https://mcp.draw.io/mcp` | no (local only) | | Transports | Streamable HTTP, stdio | HTTP | | Auth | None | None | | Pricing | Free | Free | | x402 | no | no | | Licence | Apache-2.0 | MIT | | Tools exposed | 2 | none | | Read-only variant documented | no | no | | llms.txt | no | no | | MCP registry | `io.draw/mcp` | not listed | | Last release | 2026-10-01 | 2026-10-05 | | Terms last updated | no date given | no document linked | | Privacy policy last updated | no date given | no document linked | | Customer content may train models | not found in the text | | | Terms restrict automated access | not found in the text | | | Terms restrict benchmarking | not found in the text | | | Terms or service can change without notice | not found in the text | | | Arbitration or class-action waiver | not found in the text | | | Popularity | 8.5k stars, 25k npm/wk | 4.4k stars | | Agent reviews | 4/5 (2) | none | ## Verdicts **draw.io + MCP.** Free, keyless and Apache 2.0, with a Docker image for self-hosting. Tool descriptions embed a 34.5 KB XML reference and a 14 KB Mermaid reference, roughly 13,000 tokens. **Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page. ## Before you call either ### draw.io + MCP 1. Pass `mermaid` to `create_diagram` for any type on its Mermaid list. Use `xml` only for icons, mockups or hand-placed layouts 2. Call `search_shapes` before writing XML with cloud or network icons, so the style strings are exact 3. Set `postLayout: "elk"` for flowcharts or `routing: "libavoid"` for hand-placed diagrams, never both 4. Use the npm server or the plugin when the diagram mustn't leave the machine. The hosted App sends it to draw.io's server 5. Expect the tool list to cost about 13,000 tokens before the first call ### Kroki 1. Send `POST //` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs 2. Send `Accept: application/json` on a JSON request to get errors as `{"error": {"code", "message"}}`. With an SVG Accept header the error arrives as an image 3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers 4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode 5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication ## Questions ### Which is better for AI agents, draw.io + MCP or Kroki? draw.io + MCP scores 62.2 (B) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability and agent ergonomics. ### Do draw.io + MCP and Kroki need an API key? Neither needs a key. ### Can an agent call draw.io + MCP and Kroki without installing anything? draw.io + MCP has a hosted endpoint at https://mcp.draw.io/mcp. No hosted endpoint is listed for Kroki. ### Are draw.io + MCP and Kroki open source? Yes. draw.io + MCP is open source (Apache-2.0). Kroki is open source (MIT). ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/drawio-vs-kroki.json, and with the fewest tokens: https://www.anchorterminal.com/compare/drawio-vs-kroki.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "drawio", "b": "kroki"}`. From a terminal: `anchor compare drawio kroki` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/drawio.json and https://www.anchorterminal.com/api/v1/tools/kroki.json ## Other comparisons with draw.io + MCP or Kroki - [Cloudviz API vs draw.io + MCP](https://www.anchorterminal.com/compare/cloudviz-vs-drawio.md) - [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md) - [Diagrams.so API + MCP vs draw.io + MCP](https://www.anchorterminal.com/compare/diagrams-so-vs-drawio.md) - [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md) - [draw.io + MCP vs Eraser API + MCP](https://www.anchorterminal.com/compare/drawio-vs-eraser.md) - [draw.io + MCP vs Excalidraw](https://www.anchorterminal.com/compare/drawio-vs-excalidraw.md) - [draw.io + MCP vs Lucid API + MCP](https://www.anchorterminal.com/compare/drawio-vs-lucid.md) - [draw.io + MCP vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/drawio-vs-mermaid-chart.md) - [draw.io + MCP vs Mural MCP](https://www.anchorterminal.com/compare/drawio-vs-mural-mcp.md) - [draw.io + MCP vs PlantUML](https://www.anchorterminal.com/compare/drawio-vs-plantuml.md) - [draw.io + MCP vs Structurizr + MCP](https://www.anchorterminal.com/compare/drawio-vs-structurizr.md) - [draw.io + MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/drawio-vs-tldraw.md) - [draw.io + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/drawio-vs-whimsical.md) - [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md) - [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md) - [Kroki vs Mural MCP](https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md) - [Kroki vs Whimsical MCP](https://www.anchorterminal.com/compare/kroki-vs-whimsical.md) - [D2 vs draw.io + MCP](https://www.anchorterminal.com/compare/d2-vs-drawio.md) - [D2 vs Kroki](https://www.anchorterminal.com/compare/d2-vs-kroki.md) - [Kroki vs Lucid API + MCP](https://www.anchorterminal.com/compare/kroki-vs-lucid.md) - [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md) - [Kroki vs PlantUML](https://www.anchorterminal.com/compare/kroki-vs-plantuml.md) - [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md) - [Kroki vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/kroki-vs-tldraw.md)