{
  "data": {
    "a": {
      "slug": "excalidraw",
      "name": "Excalidraw",
      "vendor": "Excalidraw s.r.o.",
      "vendorUrl": "https://plus.excalidraw.com",
      "kind": "http-api",
      "category": "diagramming",
      "summary": "Excalidraw is a hand-drawn style whiteboard and diagram editor from Excalidraw s.r.o. in Brno. Agents reach it through the Excalidraw+ REST API and MCP server (public beta), a free keyless MCP App, and the open-source editor on npm (MIT).",
      "url": "https://www.anchorterminal.com/tools/excalidraw",
      "markdownUrl": "https://www.anchorterminal.com/tools/excalidraw.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/excalidraw.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/excalidraw.json",
      "repo": "https://github.com/excalidraw/excalidraw",
      "license": "Excalidraw+ is a proprietary service under Excalidraw's terms of use. The editor and the MCP App on GitHub are MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.excalidraw.com/api/v1/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@excalidraw/excalidraw"
        }
      ],
      "auth": "api-key",
      "authNotes": "A person creates an API key in Excalidraw+ workspace settings, and the full key is shown once. Keys are sent as `Authorization: Bearer \u003cAPI_KEY\u003e`, belong to one workspace, take `read` or `full` permission or specific routes, and expire on a set date. Personal keys act as one member and need a workspace admin to enable them. Workspace keys act as the workspace. The free MCP App at https://mcp.excalidraw.com takes no credential.",
      "pricing": "freemium",
      "pricingNotes": "API and MCP access is listed under the Plus plan at $6 a user a month, 14 per cent less billed yearly, with a 14-day trial. The page does not say whether the trial takes a card. The Free plan, the free MCP App and the npm editor cost nothing, so an agent can draw without a contract but cannot reach a workspace (checked 2026-10-09).",
      "priceSummary": "$6 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs dump, the pricing page or the MCP App source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 37,
      "popularity": {
        "githubStars": 133534,
        "npmWeekly": 675606,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://plus.excalidraw.com/docs",
      "llmsTxt": "https://plus.excalidraw.com/llms.txt",
      "capabilities": [
        "diagram.create",
        "diagram.edit",
        "diagram.export",
        "diagram.as-code"
      ],
      "tags": [
        "hosted",
        "mcp",
        "api-key",
        "llms-txt",
        "freemium",
        "beta",
        "status-page",
        "soc2",
        "open-source",
        "typescript",
        "eu"
      ],
      "lastRelease": "2026-09-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 54.5,
        "grade": "C",
        "agentReady": false,
        "rank": 683,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 58,
          "maintenance": 44,
          "payments": 35,
          "reliability": 50,
          "schema": 65,
          "security": 73,
          "transparency": 63
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -2,
        "negativeNotes": [
          "Checked 2026-10-09. GHSA-39h7-pwv7-rc3x (CVE-2025-54881, medium), cross-site scripting in the Mermaid to Excalidraw conversion step, was published on 21 April 2026 and fixed in `@excalidraw/excalidraw` 0.18.1 and `@excalidraw/mermaid-to-excalidraw` 1.1.3. Fixed and published, so 2 points (https://github.com/excalidraw/excalidraw/security/advisories/GHSA-39h7-pwv7-rc3x)."
        ],
        "verdict": "Excalidraw+ keys carry read or full permission, route restrictions and an expiry, and the MCP server shows a key only the tools its routes allow. The API and MCP server are in public beta with breaking changes expected, sit behind the $6 Plus plan, and have no published OpenAPI file, SDK or idempotency keys.",
        "bestFor": "Teams already on Excalidraw+ that want agents to create and edit hand-drawn diagrams, slides and wireframes in a shared workspace, and one-off sketches through the free MCP App.",
        "strengths": [
          "API keys take `read` or `full` permission, route restrictions and an expiry, and can be rotated. The MCP server lists only the tools a key's routes allow",
          "`create_diagram` lays out nodes, edges and groups into editable shapes with bound arrows, and `take_screenshot` returns a PNG to check the result",
          "`search_scene_content` returns only matching elements, so an agent need not load a whole scene",
          "`llms.txt` and a 110 KB `llms-full.txt` carry the API and MCP docs, and `GET /logs` returns the workspace audit log",
          "A free MCP App at https://mcp.excalidraw.com needs no account or key, and the editor is MIT on npm with 675,606 downloads in the week to 7 October 2026"
        ],
        "weaknesses": [
          "The API and MCP server are in public beta. The docs say endpoints, tool names and schemas may change and to expect breaking changes",
          "API and MCP access needs the Plus plan at $6 a user a month. No per-call price, and no SDK for the API",
          "No OpenAPI file is linked from the docs, although the reference pages are generated from one. No idempotency keys and no SLA found",
          "The terms of use (in effect 1 June 2022) forbid access through a bot or script and do not mention the API. This matters before any probe is run",
          "The privacy policy is dated 29 April 2021 and names no AI providers. The sub-processor list sits in a script-drawn trust centre",
          "In the free MCP App, `create_view` is marked read-only yet stores a checkpoint for 30 days, and its reply names a `read_widget_context` tool the server does not register"
        ],
        "agentNotes": [
          "Send `Authorization: Bearer \u003cAPI_KEY\u003e` to https://api.excalidraw.com/api/v1. For MCP, use `POST /api/v1/mcp` only. The server is stateless and answers 405 to other methods",
          "Use a personal key to reach the owner's private collection with the collection ID `private`. A workspace admin must enable personal keys first",
          "Call `read_diagram_format`, `read_presentation_format` or `read_freeform_format` before the first scene write in a session",
          "Write with `edit_scene_content` and bind arrows through `startBinding` and `endBinding` with `tempId` references. `PUT /scenes/{sceneId}/content` removes every element left out of the request",
          "Stay under 600 requests a minute per IP and wait until `X-RateLimit-Reset` after a 429"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 54.5
          }
        ],
        "editorialScores": {
          "ergonomics": 58,
          "maintenance": 44,
          "payments": 35,
          "reliability": 50,
          "schema": 65,
          "security": 73,
          "transparency": 45
        },
        "provenanceScore": 80
      },
      "connect": {
        "install": "npm install react react-dom @excalidraw/excalidraw",
        "http": "curl https://api.excalidraw.com/api/v1/collections \\\n  -H \"Authorization: Bearer \u003cAPI_KEY\u003e\"",
        "config": {
          "mcpServers": {
            "excalidraw": {
              "headers": {
                "Authorization": "Bearer \u003cAPI_KEY\u003e"
              },
              "type": "http",
              "url": "https://api.excalidraw.com/api/v1/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/diagram.create",
        "tool": "https://letme.dev/excalidraw"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Plus plan",
          "unit": "seat-month",
          "usd": 6,
          "note": "billed monthly, 14 per cent less billed yearly. API and MCP access, 100 AI requests a day"
        }
      ],
      "provenance": {
        "legalEntity": "Excalidraw s.r.o.",
        "domain": "excalidraw.com",
        "domainRegistered": "2020-01-03",
        "endpointOnVendorDomain": true,
        "terms": "https://plus.excalidraw.com/terms-of-service",
        "privacy": "https://plus.excalidraw.com/privacy-policy",
        "statusPage": "https://status.excalidraw.com",
        "changelog": "https://plus.excalidraw.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The terms of use and the privacy policy name Excalidraw s.r.o., Pražákova 1008/69, Brno 639 00, Czech Republic. The terms are governed by Czech law.",
          "The terms of use (published 30 May 2022) are the only terms found. They cover the Site and the subscription and do not mention the API or MCP server.",
          "The privacy policy is dated 29 April 2021. A DPA dated 13 January 2026 is at https://plus.excalidraw.com/data-processing-agreement-dpa.",
          "plus.excalidraw.com/.well-known/security.txt returns 404. excalidraw.com was not asked, because its robots.txt is ambiguous for unnamed agents.",
          "RDAP for excalidraw.com gives a registration date of 2020-01-03.",
          "The robots.txt files of api.excalidraw.com and status.excalidraw.com disallow every path."
        ],
        "score": 80
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/excalidraw.json",
      "live": {
        "slug": "excalidraw",
        "probe": {
          "target": "https://api.excalidraw.com/api/v1/mcp",
          "method": "get",
          "lastAt": "2026-10-10T02:07:08.331803805Z",
          "lastOk": true,
          "lastStatus": 405,
          "lastMs": 354,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 338,
          "p95ms24h": 401,
          "samples24h": 107,
          "samples30d": 107,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 22,
              "ok": 22
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.excalidraw.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:50:32.425887728Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "excalidraw/excalidraw",
            "version": "v0.18.1",
            "released": "2026-04-21",
            "seenAt": "2026-10-09T16:52:20.443420866Z"
          },
          {
            "registry": "npm",
            "name": "@excalidraw/excalidraw",
            "version": "0.18.1",
            "seenAt": "2026-10-09T16:52:19.575748854Z"
          }
        ],
        "githubStars": 133551,
        "npmWeekly": 675606,
        "pages": [
          {
            "url": "https://plus.excalidraw.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:35.623690787Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "7a9250424db5"
          },
          {
            "url": "https://plus.excalidraw.com/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:37.662006429Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8328a24b3944"
          },
          {
            "url": "https://plus.excalidraw.com/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:39.940578591Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3dc978ec9eff"
          }
        ],
        "updatedAt": "2026-10-10T02:07:08.331803805Z"
      }
    },
    "answer": "Kroki scores 59.2 (C) on agent readiness against Excalidraw's 54.5 (C), and leads in 4 of 7 scored categories. Excalidraw leads on schema \u0026 documentation and security \u0026 auth.",
    "b": {
      "slug": "kroki",
      "name": "Kroki",
      "vendor": "Yuzu tech",
      "vendorUrl": "https://kroki.io",
      "kind": "http-api",
      "category": "diagramming",
      "summary": "Kroki is an open-source HTTP server from Yuzu tech that converts diagram text in 29 formats, including PlantUML, Mermaid, GraphViz and D2, into SVG, PNG or PDF. Owners run it from Docker images, and kroki.io is a free public instance.",
      "url": "https://www.anchorterminal.com/tools/kroki",
      "markdownUrl": "https://www.anchorterminal.com/tools/kroki.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kroki.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kroki.json",
      "repo": "https://github.com/yuzutech/kroki",
      "license": "MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "yuzutech/kroki"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-mermaid"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-bpmn"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-excalidraw"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or login on the convert endpoints, on a self-hosted server or on the public instance at kroki.io. The server binds all interfaces on port 8000 unless `KROKI_LISTEN` says otherwise. An optional bearer token, `KROKI_COMPANION_REGISTRATION_TOKEN`, protects only the `/services` registration API, which is off by default.",
      "pricing": "free",
      "pricingNotes": "Free under the MIT licence, with nothing to buy. The public instance at kroki.io is free and paid for by sponsors, for reasonable, non-commercial use with no uptime guarantee. Third parties sell hosting, which the project says it does not operate.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4365,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.kroki.io/kroki/setup/usage/",
      "capabilities": [
        "diagram.as-code",
        "diagram.create",
        "diagram.export",
        "diagram.architecture"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "http-api",
        "docker",
        "diagram-as-code",
        "plantuml",
        "mermaid",
        "graphviz",
        "no-auth",
        "free"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.2,
        "grade": "C",
        "agentReady": false,
        "rank": 558,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -5,
        "negativeNotes": [
          "27 July to 12 August 2026. Four advisories on the repository. GHSA-wmpp-fj9c-w766 (critical, CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in 0.21.0 up to 0.32.0 whatever the safe mode. GHSA-r54f-fq6c-53vw (high, CVE-2026-102359), GHSA-px99-rjv4-49g8 (medium, CVE-2026-102356) and GHSA-9p7m-vrmg-qp4q (high) let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed, in 0.32.1 at the latest, and the maintainers published each with a changelog entry, so the deduction is five points (https://github.com/yuzutech/kroki/security/advisories)."
        ],
        "verdict": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
        "bestFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "strengths": [
          "`POST /` with `diagram_source`, `diagram_type` and `output_format`, or plain text to `/\u003ctype\u003e/\u003cformat\u003e`, returns the image. No account or key",
          "One API covers 29 diagram types, among them PlantUML, C4, Structurizr, Mermaid, GraphViz, D2, DBML, BPMN, Excalidraw and Vega",
          "`KROKI_SAFE_MODE` defaults to `SECURE`, which blocks file and network reads by diagram libraries, and the container runs as the non-root user `kroki`",
          "Five versions shipped between 15 July and 5 October 2026, and the `main.yaml` workflow passed on the last ten pushes to `main`",
          "MIT licence. The maintainers published four security advisories in 2026, each with a fixed version and a changelog entry"
        ],
        "weaknesses": [
          "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026",
          "Three more advisories in July and August 2026 let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed in 0.32.1",
          "No OpenAPI file, llms.txt or error catalogue. The JSON error shape is in the source and not in the documentation",
          "The public instance at kroki.io has no terms, privacy policy, status page or published rate limit. The CLI page limits the demonstration server to reasonable, non-commercial use",
          "The server has no authentication on its convert endpoints and binds all interfaces on port 8000 by default. The version is 0.33.0, with no 1.0"
        ],
        "agentNotes": [
          "Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs",
          "Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image",
          "Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers",
          "Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode",
          "Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.2
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 67
        },
        "provenanceScore": 56
      },
      "connect": {
        "install": "docker run -p8000:8000 yuzutech/kroki",
        "http": "curl https://kroki.io/graphviz/svg --data-raw 'digraph G {Hello-\u003eWorld}'"
      },
      "letme": {
        "capability": "https://letme.dev/diagram.as-code",
        "tool": "https://letme.dev/kroki"
      },
      "area": "design-diagrams",
      "provenance": {
        "legalEntity": "Yuzu tech, a French software firm. No registered legal form found",
        "domain": "kroki.io",
        "domainRegistered": "2019-01-06",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/yuzutech/kroki/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The kroki.io home page says Kroki is built and maintained by Yuzu tech, and links https://yuzutech.fr, whose pages name no legal form or registration number. `LICENSE` reads Copyright (c) 2020-present Kroki",
          "No terms or privacy document was found on kroki.io or docs.kroki.io, for the software or for the public instance. The MIT licence stands in for the software",
          "https://kroki.io/.well-known/security.txt answered 404 on 9 October 2026. `SECURITY.md` asks for reports through a private GitHub security advisory",
          "The lead wrote the vendor as Yuzutech. The site writes Yuzu tech, and the GitHub organisation is `yuzutech`",
          "The endpoint on the vendor's domain is the free public instance. The listing grades the server an owner runs"
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kroki.json",
      "live": {
        "slug": "kroki",
        "versions": [
          {
            "registry": "github",
            "name": "yuzutech/kroki",
            "version": "v0.33.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-09T17:00:57.82489933Z"
          }
        ],
        "githubStars": 4365,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/yuzutech/kroki/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:46:31.151891385Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3e34fa594488"
          }
        ],
        "updatedAt": "2026-10-09T18:46:31.151891385Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Excalidraw s.r.o.",
        "b": "Yuzu tech",
        "name": "Vendor"
      },
      {
        "a": "https://api.excalidraw.com/api/v1/mcp",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Excalidraw+ is a proprietary service under Excalidraw's terms of use. The editor and the MCP App on GitHub are MIT",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "37",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-01",
        "b": "2026-10-05",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2021-04-29",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "134k stars, 676k npm/wk",
        "b": "4.4k stars",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Kroki scores 59.2 (C) on agent readiness against Excalidraw's 54.5 (C), and leads in 4 of 7 scored categories. Excalidraw leads on schema \u0026 documentation and security \u0026 auth.",
        "question": "Which is better for AI agents, Excalidraw or Kroki?"
      },
      {
        "answer": "Excalidraw needs an API key. Kroki needs no key.",
        "question": "Do Excalidraw and Kroki need an API key?"
      },
      {
        "answer": "Excalidraw has a hosted endpoint at https://api.excalidraw.com/api/v1/mcp. No hosted endpoint is listed for Kroki.",
        "question": "Can an agent call Excalidraw and Kroki without installing anything?"
      },
      {
        "answer": "Yes. Excalidraw is open source (Excalidraw+ is a proprietary service under Excalidraw's terms of use. The editor and the MCP App on GitHub are MIT). Kroki is open source (MIT).",
        "question": "Are Excalidraw and Kroki open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 65 against 48",
          "Security \u0026 auth, 73 against 56"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Teams already on Excalidraw+ that want agents to create and edit hand-drawn diagrams, slides and wireframes in a shared workspace, and one-off sketches through the free MCP App.",
        "slug": "excalidraw",
        "watchFor": "The API and MCP server are in public beta. The docs say endpoints, tool names and schemas may change and to expect breaking changes"
      },
      {
        "aheadOn": [
          "Reliability, 74 against 50",
          "Agent ergonomics, 70 against 58",
          "Payments \u0026 pricing, 60 against 35",
          "Maintenance \u0026 community, 86 against 44"
        ],
        "also": [
          "No key needed to call it"
        ],
        "goodFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "slug": "kroki",
        "watchFor": "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026"
      }
    ],
    "job": {
      "capability": "diagram.create",
      "name": "Diagram creation"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-excalidraw.json",
        "title": "Cloudviz API vs Excalidraw",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-excalidraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki.json",
        "title": "Cloudviz API vs Kroki",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-excalidraw.json",
        "title": "Diagrams.so API + MCP vs Excalidraw",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-excalidraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.json",
        "title": "Diagrams.so API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-excalidraw.json",
        "title": "draw.io + MCP vs Excalidraw",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-excalidraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-kroki.json",
        "title": "draw.io + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-excalidraw.json",
        "title": "Eraser API + MCP vs Excalidraw",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-excalidraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-kroki.json",
        "title": "Eraser API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-lucid.json",
        "title": "Excalidraw vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-mermaid-chart.json",
        "title": "Excalidraw vs Mermaid Chart MCP",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-mermaid-chart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-mural-mcp.json",
        "title": "Excalidraw vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-plantuml.json",
        "title": "Excalidraw vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-structurizr.json",
        "title": "Excalidraw vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-tldraw.json",
        "title": "Excalidraw vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-whimsical.json",
        "title": "Excalidraw vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.json",
        "title": "Kroki vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-whimsical.json",
        "title": "Kroki vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-excalidraw.json",
        "title": "D2 vs Excalidraw",
        "url": "https://www.anchorterminal.com/compare/d2-vs-excalidraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-kroki.json",
        "title": "D2 vs Kroki",
        "url": "https://www.anchorterminal.com/compare/d2-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-lucid.json",
        "title": "Kroki vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.json",
        "title": "Kroki vs Mermaid Chart MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-plantuml.json",
        "title": "Kroki vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-structurizr.json",
        "title": "Kroki vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-tldraw.json",
        "title": "Kroki vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-tldraw"
      }
    ],
    "scores": [
      {
        "by": 24,
        "edge": "kroki",
        "excalidraw": 50,
        "key": "reliability",
        "kroki": 74,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 17,
        "edge": "excalidraw",
        "excalidraw": 65,
        "key": "schema",
        "kroki": 48,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 12,
        "edge": "kroki",
        "excalidraw": 58,
        "key": "ergonomics",
        "kroki": 70,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 17,
        "edge": "excalidraw",
        "excalidraw": 73,
        "key": "security",
        "kroki": 56,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 25,
        "edge": "kroki",
        "excalidraw": 35,
        "key": "payments",
        "kroki": 60,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 42,
        "edge": "kroki",
        "excalidraw": 44,
        "key": "maintenance",
        "kroki": 86,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 1,
        "edge": "excalidraw",
        "excalidraw": 63,
        "key": "transparency",
        "kroki": 62,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Kroki scores 59.2 (C) on agent readiness against Excalidraw's 54.5 (C), and leads in 4 of 7 scored categories. Excalidraw leads on schema \u0026 documentation and security \u0026 auth. Both do diagram creation.",
    "verdicts": {
      "excalidraw": "Excalidraw+ keys carry read or full permission, route restrictions and an expiry, and the MCP server shows a key only the tools its routes allow. The API and MCP server are in public beta with breaking changes expected, sit behind the $6 Plus plan, and have no published OpenAPI file, SDK or idempotency keys.",
      "kroki": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki",
    "json": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md",
    "slim": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki.min.md"
  },
  "markdown": "Kroki scores 59.2 (C) on agent readiness against Excalidraw's 54.5 (C), and leads in 4 of 7 scored categories. Excalidraw leads on schema \u0026 documentation and security \u0026 auth. Both do diagram creation.\n\n- Excalidraw: grade C, 54.5/100, rank #683 of 950. Markdown https://www.anchorterminal.com/tools/excalidraw.md · JSON https://www.anchorterminal.com/api/v1/tools/excalidraw.json\n- Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json\n- Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md\n- All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md\n\n## Which one, for what\n\n### Excalidraw (C)\n\nGood for: Teams already on Excalidraw+ that want agents to create and edit hand-drawn diagrams, slides and wireframes in a shared workspace, and one-off sketches through the free MCP App.\n\nAhead on:\n- Schema \u0026 documentation, 65 against 48\n- Security \u0026 auth, 73 against 56\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: The API and MCP server are in public beta. The docs say endpoints, tool names and schemas may change and to expect breaking changes\n\n### Kroki (C)\n\nGood for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.\n\nAhead on:\n- Reliability, 74 against 50\n- Agent ergonomics, 70 against 58\n- Payments \u0026 pricing, 60 against 35\n- Maintenance \u0026 community, 86 against 44\n\nAlso in its favour:\n- No key needed to call it\n\nWatch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026\n\n\n## Score by category\n\n| Category | Weight | Excalidraw | Kroki | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 50 | 74 | Kroki +24 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 65 | 48 | Excalidraw +17 |\n| Agent ergonomics | 13% (16.2 this run) | 58 | 70 | Kroki +12 |\n| Security \u0026 auth | 14% (17.5 this run) | 73 | 56 | Excalidraw +17 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 35 | 60 | Kroki +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 44 | 86 | Kroki +42 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 63 | 62 | Excalidraw +1 |\n| Negative events | ≤15 | -2 | -5 | |\n| **Total** | | **54.5 · C** | **59.2 · C** | |\n\n## Facts side by side\n\n| Fact | Excalidraw | Kroki |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Excalidraw s.r.o. | Yuzu tech |\n| Hosted endpoint | `https://api.excalidraw.com/api/v1/mcp` | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | API key | None |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | Excalidraw+ is a proprietary service under Excalidraw's terms of use. The editor and the MCP App on GitHub are MIT | MIT |\n| Tools exposed | 37 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| Last release | 2026-09-01 | 2026-10-05 |\n| Terms last updated | no date given | no document linked |\n| Privacy policy last updated | 2021-04-29 | no document linked |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | yes |  |\n| Terms restrict benchmarking | not found in the text |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | yes |  |\n| Popularity | 134k stars, 676k npm/wk | 4.4k stars |\n\n## Verdicts\n\n**Excalidraw.** Excalidraw+ keys carry read or full permission, route restrictions and an expiry, and the MCP server shows a key only the tools its routes allow. The API and MCP server are in public beta with breaking changes expected, sit behind the $6 Plus plan, and have no published OpenAPI file, SDK or idempotency keys.\n\n**Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.\n\n## Before you call either\n\n### Excalidraw\n\n1. Send `Authorization: Bearer \u003cAPI_KEY\u003e` to https://api.excalidraw.com/api/v1. For MCP, use `POST /api/v1/mcp` only. The server is stateless and answers 405 to other methods\n2. Use a personal key to reach the owner's private collection with the collection ID `private`. A workspace admin must enable personal keys first\n3. Call `read_diagram_format`, `read_presentation_format` or `read_freeform_format` before the first scene write in a session\n4. Write with `edit_scene_content` and bind arrows through `startBinding` and `endBinding` with `tempId` references. `PUT /scenes/{sceneId}/content` removes every element left out of the request\n5. Stay under 600 requests a minute per IP and wait until `X-RateLimit-Reset` after a 429\n\n### Kroki\n\n1. Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs\n2. Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image\n3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers\n4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode\n5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication\n\n## Questions\n\n### Which is better for AI agents, Excalidraw or Kroki?\n\nKroki scores 59.2 (C) on agent readiness against Excalidraw's 54.5 (C), and leads in 4 of 7 scored categories. Excalidraw leads on schema \u0026 documentation and security \u0026 auth.\n\n### Do Excalidraw and Kroki need an API key?\n\nExcalidraw needs an API key. Kroki needs no key.\n\n### Can an agent call Excalidraw and Kroki without installing anything?\n\nExcalidraw has a hosted endpoint at https://api.excalidraw.com/api/v1/mcp. No hosted endpoint is listed for Kroki.\n\n### Are Excalidraw and Kroki open source?\n\nYes. Excalidraw is open source (Excalidraw+ is a proprietary service under Excalidraw's terms of use. The editor and the MCP App on GitHub are MIT). Kroki is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/excalidraw-vs-kroki.json, and with the fewest tokens: https://www.anchorterminal.com/compare/excalidraw-vs-kroki.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"excalidraw\", \"b\": \"kroki\"}`. From a terminal: `anchor compare excalidraw kroki`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/excalidraw.json and https://www.anchorterminal.com/api/v1/tools/kroki.json\n\n## Other comparisons with Excalidraw or Kroki\n\n- [Cloudviz API vs Excalidraw](https://www.anchorterminal.com/compare/cloudviz-vs-excalidraw.md)\n- [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md)\n- [Diagrams.so API + MCP vs Excalidraw](https://www.anchorterminal.com/compare/diagrams-so-vs-excalidraw.md)\n- [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md)\n- [draw.io + MCP vs Excalidraw](https://www.anchorterminal.com/compare/drawio-vs-excalidraw.md)\n- [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md)\n- [Eraser API + MCP vs Excalidraw](https://www.anchorterminal.com/compare/eraser-vs-excalidraw.md)\n- [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md)\n- [Excalidraw vs Lucid API + MCP](https://www.anchorterminal.com/compare/excalidraw-vs-lucid.md)\n- [Excalidraw vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/excalidraw-vs-mermaid-chart.md)\n- [Excalidraw vs Mural MCP](https://www.anchorterminal.com/compare/excalidraw-vs-mural-mcp.md)\n- [Excalidraw vs PlantUML](https://www.anchorterminal.com/compare/excalidraw-vs-plantuml.md)\n- [Excalidraw vs Structurizr + MCP](https://www.anchorterminal.com/compare/excalidraw-vs-structurizr.md)\n- [Excalidraw vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/excalidraw-vs-tldraw.md)\n- [Excalidraw vs Whimsical MCP](https://www.anchorterminal.com/compare/excalidraw-vs-whimsical.md)\n- [Kroki vs Mural MCP](https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md)\n- [Kroki vs Whimsical MCP](https://www.anchorterminal.com/compare/kroki-vs-whimsical.md)\n- [D2 vs Excalidraw](https://www.anchorterminal.com/compare/d2-vs-excalidraw.md)\n- [D2 vs Kroki](https://www.anchorterminal.com/compare/d2-vs-kroki.md)\n- [Kroki vs Lucid API + MCP](https://www.anchorterminal.com/compare/kroki-vs-lucid.md)\n- [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md)\n- [Kroki vs PlantUML](https://www.anchorterminal.com/compare/kroki-vs-plantuml.md)\n- [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md)\n- [Kroki vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/kroki-vs-tldraw.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Excalidraw vs Kroki",
        "url": ""
      }
    ],
    "description": "Kroki scores 59.2 (C) to Excalidraw's 54.5 (C) for diagram creation. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Excalidraw C 54.5",
      "Kroki C 59.2",
      "scores"
    ],
    "h1": "Excalidraw vs Kroki",
    "image": "https://www.anchorterminal.com/assets/og/compare-excalidraw-vs-kroki.png",
    "path": "/compare/excalidraw-vs-kroki",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Excalidraw vs Kroki for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki"
  },
  "tokens": {
    "markdown": 2550,
    "slim": 730
  },
  "version": 1
}
