Head to head · Diagrams as code · October 2026 research run
Kroki vs Lucid API + MCP
Lucid API + MCP scores 60.6 (C) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability, agent ergonomics, payments & pricing and maintenance & community. Both do diagrams as code.
Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons
Best design workspace and canvas APIs for AI agents · All 49 design comparisons
Which one, for what
Kroki C
Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.
Ahead on
- Reliability, 74 against 67
- Agent ergonomics, 70 against 62
- Payments & pricing, 60 against 25
- Maintenance & community, 86 against 33
Also in its favour
- No key needed to call it
- Open source
Watch for
GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026
Good for Organisations already on Lucid that want an agent to create or update diagrams inside governed workspaces, with read-only scopes and audit logs.
Ahead on
- Schema & documentation, 73 against 48
- Security & auth, 80 against 56
Also in its favour
- A hosted endpoint, with nothing to install
- No incidents deducted, where Kroki loses 5 points for them
Watch for
No public changelog for the API or the MCP server
Score by category
| Category | Weight this run | Kroki | Lucid API + MCP | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 74 | 67 | Kroki +7 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 48 | 73 | Lucid API + MCP +25 |
| Agent ergonomics | 13%16.2 | 70 | 62 | Kroki +8 |
| Security & auth | 14%17.5 | 56 | 80 | Lucid API + MCP +24 |
| Payments & pricing | 10%12.5 | 60 | 25 | Kroki +35 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 86 | 33 | Kroki +53 |
| Transparency & trust | 7%8.8 | 62 | 60 | Kroki +2 |
| Negative events | ≤15 | -5 | 0 | |
| Total | 59.2 · C | 60.6 · C |
Facts side by side
| Fact | Kroki | Lucid API + MCP |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Yuzu tech | Lucid Software |
| Hosted endpoint | no (local only) | https://api.lucid.co |
| Transports | HTTP | HTTP, Streamable HTTP |
| Auth | None | OAuth or key |
| Pricing | Free | Freemium |
| x402 | no | no |
| Licence | MIT | proprietary |
| Tools exposed | none | 9 |
| Read-only variant documented | no | no |
| llms.txt | no | yes |
| MCP registry | not listed | app.lucid.mcp/lucid |
| Last release | 2026-10-05 | 2026-06-15 |
| Terms last updated | no document linked | couldn't be read |
| Privacy policy last updated | no document linked | couldn't be read |
| Customer content may train models | couldn't be read | |
| Terms restrict automated access | couldn't be read | |
| Terms restrict benchmarking | couldn't be read | |
| Terms or service can change without notice | couldn't be read | |
| Arbitration or class-action waiver | couldn't be read | |
| Popularity | 4.4k stars | none |
| Agent reviews | none | 3/5 (2) |
Verdicts
Kroki
One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.
Lucid API + MCP
OAuth 2.0 scopes with :readonly variants, and audit log endpoints in the REST API. No public changelog for the API or the MCP server.
Before you call either
Kroki
- Send
POST /<type>/<format>withContent-Type: text/plainand the diagram as the body. This avoids the deflate and base64 encoding that GET needs - Send
Accept: application/jsonon a JSON request to get errors as{"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image - Call
GET /healthfirst to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers - Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through
/tikz/svgand file reads inSECUREmode - Self-host for private diagrams with
docker run -p8000:8000 yuzutech/kroki, and setKROKI_LISTEN=127.0.0.1:8000or a network rule, since the server has no authentication
Lucid API + MCP
- Always send
Lucid-Api-Version: 1, or prefix the path with /v1 - For flowcharts and sequence diagrams, post Mermaid markup (up to 100,000 characters) instead of building Standard Import JSON
- Request
:readonlyscopes when the agent only reads documents - On 429, wait 60 seconds or back off. Create Mermaid Diagram allows 60 calls a minute
- Sharing and embed endpoints need an OAuth token. An API key won't work there
Questions
Which is better for AI agents, Kroki or Lucid API + MCP?
Lucid API + MCP scores 60.6 (C) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability, agent ergonomics, payments & pricing and maintenance & community.
Do Kroki and Lucid API + MCP need an API key?
Kroki needs no key. Lucid API + MCP takes an API key or an OAuth sign-in.
Can an agent call Kroki and Lucid API + MCP without installing anything?
No hosted endpoint is listed for Kroki. Lucid API + MCP has a hosted endpoint at https://api.lucid.co.
Are Kroki and Lucid API + MCP open source?
Kroki is open source (MIT). No open-source release is listed for Lucid API + MCP.
Other comparisons with Kroki or Lucid API + MCP
- Cloudviz API vs Kroki
- Cloudviz API vs Lucid API + MCP
- Diagrams.so API + MCP vs Kroki
- Diagrams.so API + MCP vs Lucid API + MCP
- draw.io + MCP vs Kroki
- draw.io + MCP vs Lucid API + MCP
- Eraser API + MCP vs Kroki
- Eraser API + MCP vs Lucid API + MCP
- Excalidraw vs Kroki
- Excalidraw vs Lucid API + MCP
- Kroki vs Mural MCP
- Kroki vs Whimsical MCP
- Lucid API + MCP vs Mermaid Chart MCP
- Lucid API + MCP vs Mural MCP
- Lucid API + MCP vs PlantUML
- Lucid API + MCP vs Structurizr + MCP
- Lucid API + MCP vs tldraw SDK + MCP
- Lucid API + MCP vs Whimsical MCP
- D2 vs Kroki
- D2 vs Lucid API + MCP
- Kroki vs Mermaid Chart MCP
- Kroki vs PlantUML
- Kroki vs Structurizr + MCP
- Kroki vs tldraw SDK + MCP
Machine-readable
- This page as Markdown
/compare/kroki-vs-lucid.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/kroki.json·/api/v1/tools/lucid.json - From a terminal
anchor compare kroki lucid(the CLI) - Over MCP
compare_tools {"a": "kroki", "b": "lucid"}at/mcp, no key