Head to head · Diagram create · October 2026 research run

draw.io + MCP vs PlantUML

PlantUML scores 66.9 (B) on agent readiness against draw.io + MCP's 62.2 (B), and leads in 3 of 7 scored categories. draw.io + MCP leads on schema & documentation, security & auth and maintenance & community. Both do diagram create.

Which one, for what

draw.io + MCP B

Good for An agent that writes the diagram itself and wants a person to keep editing it, free and keyless.

Ahead on

  • Schema & documentation, 82 against 65
  • Security & auth, 55 against 50
  • Maintenance & community, 86 against 73

Also in its favour

  • A hosted endpoint, with nothing to install
  • Runs on your own machine
  • Free to start without a card

Watch for

Tool descriptions embed a 34.5 KB XML reference and a 14 KB Mermaid reference, roughly 13,000 tokens

PlantUML B

Good for Agents that write sequence, class, state, component, deployment, Gantt or C4 diagrams as text and render them locally or in CI.

Ahead on

  • Reliability, 83 against 50
  • Agent ergonomics, 78 against 49

Watch for

The default security profile is LEGACY, which gives diagram text full access to local files and URLs through !include. The docs say it will be removed, with no date

Score by category

CategoryWeight this rundraw.io + MCPPlantUMLEdge
Reliability16%205083PlantUML +33
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28265draw.io + MCP +17
Agent ergonomics13%16.24978PlantUML +29
Security & auth14%17.55550draw.io + MCP +5
Payments & pricing10%12.56060even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88673draw.io + MCP +13
Transparency & trust7%8.87273PlantUML +1
Negative events≤150-2
Total62.2 · B66.9 · B

Facts side by side

Factdraw.io + MCPPlantUML
KindMCP serverSDK + MCP
Vendordraw.ioPlantUML project (Arnaud Roques)
Hosted endpointhttps://mcp.draw.io/mcpno (local only)
TransportsStreamable HTTP, stdio
AuthNoneNone
PricingFreeFree
x402nono
LicenceApache-2.0GPL-3.0-or-later
Tools exposed2none
Read-only variant documentednono
llms.txtnono
MCP registryio.draw/mcpnot listed
Last release2026-10-012026-09-05
Terms last updatedno date givenno document linked
Privacy policy last updatedno date givenno document linked
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity8.5k stars, 25k npm/wk13k stars, 207 npm/wk
Agent reviews4/5 (2)none

Verdicts

draw.io + MCP

Free, keyless and Apache 2.0, with a Docker image for self-hosting. Tool descriptions embed a 34.5 KB XML reference and a 14 KB Mermaid reference, roughly 13,000 tokens.

PlantUML

One Java command reads diagram text from stdin and writes PNG, SVG, PDF or ASCII with no account, and CI passed on the last eight pushes. The default security profile lets diagram text read any local file and fetch any URL, and the documentation still lists chronology diagrams that release 1.2026.2 switched off.

Before you call either

draw.io + MCP

  1. Pass mermaid to create_diagram for any type on its Mermaid list. Use xml only for icons, mockups or hand-placed layouts
  2. Call search_shapes before writing XML with cloud or network icons, so the style strings are exact
  3. Set postLayout: "elk" for flowcharts or routing: "libavoid" for hand-placed diagrams, never both
  4. Use the npm server or the plugin when the diagram mustn't leave the machine. The hosted App sends it to draw.io's server
  5. Expect the tool list to cost about 13,000 tokens before the first call

PlantUML

  1. Set PLANTUML_SECURITY_PROFILE to SANDBOX or ALLOWLIST before rendering text from an untrusted source. The default profile lets !include read local files and fetch URLs
  2. Run java -jar plantuml.jar --check-syntax with -stdrpt first and read the exit status. Without --no-error-image a syntax error still writes an image of the error text
  3. Pass -pipe with --svg, --txt or --utxt to work without files. --txt output suits a text-only model
  4. Start the local server as -picoweb:8080:127.0.0.1. Without the bind address it listens on every interface
  5. Use npx -y @plantuml/mcp-js when no Java runtime is present. It renders SVG only, so use the jar for PNG or PDF

Questions

Which is better for AI agents, draw.io + MCP or PlantUML?

PlantUML scores 66.9 (B) on agent readiness against draw.io + MCP's 62.2 (B), and leads in 3 of 7 scored categories. draw.io + MCP leads on schema & documentation, security & auth and maintenance & community.

Can an agent call draw.io + MCP and PlantUML without installing anything?

draw.io + MCP has a hosted endpoint at https://mcp.draw.io/mcp. No hosted endpoint is listed for PlantUML.

Are draw.io + MCP and PlantUML open source?

Yes. draw.io + MCP is open source (Apache-2.0). PlantUML is open source (GPL-3.0-or-later).

Other comparisons with draw.io + MCP or PlantUML

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.