Head to head · Diagram creation · October 2026 research run

Eraser API + MCP vs Kroki

Kroki scores 59.2 (C) on agent readiness against Eraser API + MCP's 38.6 (E), and leads in 5 of 7 scored categories. Both do diagram creation.

Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons

Which one, for what

Eraser API + MCP E

Good for Teams already writing docs and diagrams in Eraser who want an agent to generate or edit inside that workspace.

Also in its favour

  • A hosted endpoint, with nothing to install
  • Runs on your own machine
  • No incidents deducted, where Kroki loses 5 points for them

Watch for

No status page, rate limits, SLA or changelog

Kroki C

Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.

Ahead on

  • Reliability, 74 against 15
  • Agent ergonomics, 70 against 34
  • Payments & pricing, 60 against 35
  • Maintenance & community, 86 against 33
  • Transparency & trust, 62 against 50

Also in its favour

  • No key needed to call it
  • Open source

Watch for

GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026

Score by category

CategoryWeight this runEraser API + MCPKrokiEdge
Reliability16%201574Kroki +59
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.25248Eraser API + MCP +4
Agent ergonomics13%16.23470Kroki +36
Security & auth14%17.55756Eraser API + MCP +1
Payments & pricing10%12.53560Kroki +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.83386Kroki +53
Transparency & trust7%8.85062Kroki +12
Negative events≤150-5
Total38.6 · E59.2 · C

Facts side by side

FactEraser API + MCPKroki
KindHTTP APIHTTP API
VendorEraserYuzu tech
Hosted endpointhttps://app.eraser.io/apino (local only)
TransportsHTTP, Streamable HTTP, stdioHTTP
AuthOAuth or keyNone
PricingFreemiumFree
x402nono
LicencenoneMIT
Tools exposed42none
Read-only variant documentednono
llms.txtyesno
MCP registryio.eraser/erasernot listed
Last release2026-05-222026-10-05
Terms last updatedno date givenno document linked
Privacy policy last updatedno date givenno document linked
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity76 npm/wk4.4k stars
Agent reviews3/5 (2)none

Verdicts

Eraser API + MCP

Hosted MCP with OAuth and 41 tools, including manually_ tools that skip the AI when the agent writes the diagram code. No status page, rate limits, SLA or changelog.

Kroki

One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.

Before you call either

Eraser API + MCP

  1. Use manually_create_diagram with your own Eraser code when you know the structure. It skips the AI and its credits
  2. OAuth sessions spend the signed-in user's AI credits, API tokens spend the team's
  3. Call /render/elements ($0.20) when you already have diagram code; /render/prompt costs $0.80
  4. Set a spend limit before running in CI. At 100 per cent the API stops until the next calendar month

Kroki

  1. Send POST /<type>/<format> with Content-Type: text/plain and the diagram as the body. This avoids the deflate and base64 encoding that GET needs
  2. Send Accept: application/json on a JSON request to get errors as {"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image
  3. Call GET /health first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers
  4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through /tikz/svg and file reads in SECURE mode
  5. Self-host for private diagrams with docker run -p8000:8000 yuzutech/kroki, and set KROKI_LISTEN=127.0.0.1:8000 or a network rule, since the server has no authentication

Questions

Which is better for AI agents, Eraser API + MCP or Kroki?

Kroki scores 59.2 (C) on agent readiness against Eraser API + MCP's 38.6 (E), and leads in 5 of 7 scored categories.

Do Eraser API + MCP and Kroki need an API key?

Eraser API + MCP takes an API key or an OAuth sign-in. Kroki needs no key.

Can an agent call Eraser API + MCP and Kroki without installing anything?

Eraser API + MCP has a hosted endpoint at https://app.eraser.io/api. No hosted endpoint is listed for Kroki.

Are Eraser API + MCP and Kroki open source?

No open-source release is listed for Eraser API + MCP. Kroki is open source (MIT).

Other comparisons with Eraser API + MCP or Kroki

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.