Head to head · Diagram creation · October 2026 research run
Excalidraw vs Kroki
Kroki scores 59.2 (C) on agent readiness against Excalidraw's 54.5 (C), and leads in 4 of 7 scored categories. Excalidraw leads on schema & documentation and security & auth. Both do diagram creation.
Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons
Which one, for what
Good for Teams already on Excalidraw+ that want agents to create and edit hand-drawn diagrams, slides and wireframes in a shared workspace, and one-off sketches through the free MCP App.
Ahead on
- Schema & documentation, 65 against 48
- Security & auth, 73 against 56
Also in its favour
- A hosted endpoint, with nothing to install
Watch for
The API and MCP server are in public beta. The docs say endpoints, tool names and schemas may change and to expect breaking changes
Kroki C
Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.
Ahead on
- Reliability, 74 against 50
- Agent ergonomics, 70 against 58
- Payments & pricing, 60 against 35
- Maintenance & community, 86 against 44
Also in its favour
- No key needed to call it
Watch for
GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026
Score by category
| Category | Weight this run | Excalidraw | Kroki | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 50 | 74 | Kroki +24 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 65 | 48 | Excalidraw +17 |
| Agent ergonomics | 13%16.2 | 58 | 70 | Kroki +12 |
| Security & auth | 14%17.5 | 73 | 56 | Excalidraw +17 |
| Payments & pricing | 10%12.5 | 35 | 60 | Kroki +25 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 44 | 86 | Kroki +42 |
| Transparency & trust | 7%8.8 | 63 | 62 | Excalidraw +1 |
| Negative events | ≤15 | -2 | -5 | |
| Total | 54.5 · C | 59.2 · C |
Facts side by side
| Fact | Excalidraw | Kroki |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Excalidraw s.r.o. | Yuzu tech |
| Hosted endpoint | https://api.excalidraw.com/api/v1/mcp | no (local only) |
| Transports | HTTP, Streamable HTTP | HTTP |
| Auth | API key | None |
| Pricing | Freemium | Free |
| x402 | no | no |
| Licence | Excalidraw+ is a proprietary service under Excalidraw's terms of use. The editor and the MCP App on GitHub are MIT | MIT |
| Tools exposed | 37 | none |
| Read-only variant documented | no | no |
| llms.txt | yes | no |
| Last release | 2026-09-01 | 2026-10-05 |
| Terms last updated | no date given | no document linked |
| Privacy policy last updated | 2021-04-29 | no document linked |
| Customer content may train models | not found in the text | |
| Terms restrict automated access | yes | |
| Terms restrict benchmarking | not found in the text | |
| Terms or service can change without notice | yes | |
| Arbitration or class-action waiver | yes | |
| Popularity | 134k stars, 676k npm/wk | 4.4k stars |
Verdicts
Excalidraw
Excalidraw+ keys carry read or full permission, route restrictions and an expiry, and the MCP server shows a key only the tools its routes allow. The API and MCP server are in public beta with breaking changes expected, sit behind the $6 Plus plan, and have no published OpenAPI file, SDK or idempotency keys.
Kroki
One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.
Before you call either
Excalidraw
- Send
Authorization: Bearer <API_KEY>to https://api.excalidraw.com/api/v1. For MCP, usePOST /api/v1/mcponly. The server is stateless and answers 405 to other methods - Use a personal key to reach the owner's private collection with the collection ID
private. A workspace admin must enable personal keys first - Call
read_diagram_format,read_presentation_formatorread_freeform_formatbefore the first scene write in a session - Write with
edit_scene_contentand bind arrows throughstartBindingandendBindingwithtempIdreferences.PUT /scenes/{sceneId}/contentremoves every element left out of the request - Stay under 600 requests a minute per IP and wait until
X-RateLimit-Resetafter a 429
Kroki
- Send
POST /<type>/<format>withContent-Type: text/plainand the diagram as the body. This avoids the deflate and base64 encoding that GET needs - Send
Accept: application/jsonon a JSON request to get errors as{"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image - Call
GET /healthfirst to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers - Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through
/tikz/svgand file reads inSECUREmode - Self-host for private diagrams with
docker run -p8000:8000 yuzutech/kroki, and setKROKI_LISTEN=127.0.0.1:8000or a network rule, since the server has no authentication
Questions
Which is better for AI agents, Excalidraw or Kroki?
Kroki scores 59.2 (C) on agent readiness against Excalidraw's 54.5 (C), and leads in 4 of 7 scored categories. Excalidraw leads on schema & documentation and security & auth.
Do Excalidraw and Kroki need an API key?
Excalidraw needs an API key. Kroki needs no key.
Can an agent call Excalidraw and Kroki without installing anything?
Excalidraw has a hosted endpoint at https://api.excalidraw.com/api/v1/mcp. No hosted endpoint is listed for Kroki.
Are Excalidraw and Kroki open source?
Yes. Excalidraw is open source (Excalidraw+ is a proprietary service under Excalidraw's terms of use. The editor and the MCP App on GitHub are MIT). Kroki is open source (MIT).
Other comparisons with Excalidraw or Kroki
- Cloudviz API vs Excalidraw
- Cloudviz API vs Kroki
- Diagrams.so API + MCP vs Excalidraw
- Diagrams.so API + MCP vs Kroki
- draw.io + MCP vs Excalidraw
- draw.io + MCP vs Kroki
- Eraser API + MCP vs Excalidraw
- Eraser API + MCP vs Kroki
- Excalidraw vs Lucid API + MCP
- Excalidraw vs Mermaid Chart MCP
- Excalidraw vs Mural MCP
- Excalidraw vs PlantUML
- Excalidraw vs Structurizr + MCP
- Excalidraw vs tldraw SDK + MCP
- Excalidraw vs Whimsical MCP
- Kroki vs Mural MCP
- Kroki vs Whimsical MCP
- D2 vs Excalidraw
- D2 vs Kroki
- Kroki vs Lucid API + MCP
- Kroki vs Mermaid Chart MCP
- Kroki vs PlantUML
- Kroki vs Structurizr + MCP
- Kroki vs tldraw SDK + MCP
Machine-readable
- This page as Markdown
/compare/excalidraw-vs-kroki.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/excalidraw.json·/api/v1/tools/kroki.json - From a terminal
anchor compare excalidraw kroki(the CLI) - Over MCP
compare_tools {"a": "excalidraw", "b": "kroki"}at/mcp, no key