Head to head · Diagram creation · October 2026 research run

Excalidraw vs Kroki

Kroki scores 59.2 (C) on agent readiness against Excalidraw's 54.5 (C), and leads in 4 of 7 scored categories. Excalidraw leads on schema & documentation and security & auth. Both do diagram creation.

Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons

Which one, for what

Excalidraw C

Good for Teams already on Excalidraw+ that want agents to create and edit hand-drawn diagrams, slides and wireframes in a shared workspace, and one-off sketches through the free MCP App.

Ahead on

  • Schema & documentation, 65 against 48
  • Security & auth, 73 against 56

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

The API and MCP server are in public beta. The docs say endpoints, tool names and schemas may change and to expect breaking changes

Kroki C

Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.

Ahead on

  • Reliability, 74 against 50
  • Agent ergonomics, 70 against 58
  • Payments & pricing, 60 against 35
  • Maintenance & community, 86 against 44

Also in its favour

  • No key needed to call it

Watch for

GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026

Score by category

CategoryWeight this runExcalidrawKrokiEdge
Reliability16%205074Kroki +24
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26548Excalidraw +17
Agent ergonomics13%16.25870Kroki +12
Security & auth14%17.57356Excalidraw +17
Payments & pricing10%12.53560Kroki +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.84486Kroki +42
Transparency & trust7%8.86362Excalidraw +1
Negative events≤15-2-5
Total54.5 · C59.2 · C

Facts side by side

FactExcalidrawKroki
KindHTTP APIHTTP API
VendorExcalidraw s.r.o.Yuzu tech
Hosted endpointhttps://api.excalidraw.com/api/v1/mcpno (local only)
TransportsHTTP, Streamable HTTPHTTP
AuthAPI keyNone
PricingFreemiumFree
x402nono
LicenceExcalidraw+ is a proprietary service under Excalidraw's terms of use. The editor and the MCP App on GitHub are MITMIT
Tools exposed37none
Read-only variant documentednono
llms.txtyesno
Last release2026-09-012026-10-05
Terms last updatedno date givenno document linked
Privacy policy last updated2021-04-29no document linked
Customer content may train modelsnot found in the text
Terms restrict automated accessyes
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticeyes
Arbitration or class-action waiveryes
Popularity134k stars, 676k npm/wk4.4k stars

Verdicts

Excalidraw

Excalidraw+ keys carry read or full permission, route restrictions and an expiry, and the MCP server shows a key only the tools its routes allow. The API and MCP server are in public beta with breaking changes expected, sit behind the $6 Plus plan, and have no published OpenAPI file, SDK or idempotency keys.

Kroki

One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.

Before you call either

Excalidraw

  1. Send Authorization: Bearer <API_KEY> to https://api.excalidraw.com/api/v1. For MCP, use POST /api/v1/mcp only. The server is stateless and answers 405 to other methods
  2. Use a personal key to reach the owner's private collection with the collection ID private. A workspace admin must enable personal keys first
  3. Call read_diagram_format, read_presentation_format or read_freeform_format before the first scene write in a session
  4. Write with edit_scene_content and bind arrows through startBinding and endBinding with tempId references. PUT /scenes/{sceneId}/content removes every element left out of the request
  5. Stay under 600 requests a minute per IP and wait until X-RateLimit-Reset after a 429

Kroki

  1. Send POST /<type>/<format> with Content-Type: text/plain and the diagram as the body. This avoids the deflate and base64 encoding that GET needs
  2. Send Accept: application/json on a JSON request to get errors as {"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image
  3. Call GET /health first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers
  4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through /tikz/svg and file reads in SECURE mode
  5. Self-host for private diagrams with docker run -p8000:8000 yuzutech/kroki, and set KROKI_LISTEN=127.0.0.1:8000 or a network rule, since the server has no authentication

Questions

Which is better for AI agents, Excalidraw or Kroki?

Kroki scores 59.2 (C) on agent readiness against Excalidraw's 54.5 (C), and leads in 4 of 7 scored categories. Excalidraw leads on schema & documentation and security & auth.

Do Excalidraw and Kroki need an API key?

Excalidraw needs an API key. Kroki needs no key.

Can an agent call Excalidraw and Kroki without installing anything?

Excalidraw has a hosted endpoint at https://api.excalidraw.com/api/v1/mcp. No hosted endpoint is listed for Kroki.

Are Excalidraw and Kroki open source?

Yes. Excalidraw is open source (Excalidraw+ is a proprietary service under Excalidraw's terms of use. The editor and the MCP App on GitHub are MIT). Kroki is open source (MIT).

Other comparisons with Excalidraw or Kroki

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.