{
  "data": {
    "a": {
      "slug": "kroki",
      "name": "Kroki",
      "vendor": "Yuzu tech",
      "vendorUrl": "https://kroki.io",
      "kind": "http-api",
      "category": "diagramming",
      "summary": "Kroki is an open-source HTTP server from Yuzu tech that converts diagram text in 29 formats, including PlantUML, Mermaid, GraphViz and D2, into SVG, PNG or PDF. Owners run it from Docker images, and kroki.io is a free public instance.",
      "url": "https://www.anchorterminal.com/tools/kroki",
      "markdownUrl": "https://www.anchorterminal.com/tools/kroki.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kroki.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kroki.json",
      "repo": "https://github.com/yuzutech/kroki",
      "license": "MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "yuzutech/kroki"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-mermaid"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-bpmn"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-excalidraw"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or login on the convert endpoints, on a self-hosted server or on the public instance at kroki.io. The server binds all interfaces on port 8000 unless `KROKI_LISTEN` says otherwise. An optional bearer token, `KROKI_COMPANION_REGISTRATION_TOKEN`, protects only the `/services` registration API, which is off by default.",
      "pricing": "free",
      "pricingNotes": "Free under the MIT licence, with nothing to buy. The public instance at kroki.io is free and paid for by sponsors, for reasonable, non-commercial use with no uptime guarantee. Third parties sell hosting, which the project says it does not operate.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4365,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.kroki.io/kroki/setup/usage/",
      "capabilities": [
        "diagram.as-code",
        "diagram.create",
        "diagram.export",
        "diagram.architecture"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "http-api",
        "docker",
        "diagram-as-code",
        "plantuml",
        "mermaid",
        "graphviz",
        "no-auth",
        "free"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.2,
        "grade": "C",
        "agentReady": false,
        "rank": 558,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -5,
        "negativeNotes": [
          "27 July to 12 August 2026. Four advisories on the repository. GHSA-wmpp-fj9c-w766 (critical, CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in 0.21.0 up to 0.32.0 whatever the safe mode. GHSA-r54f-fq6c-53vw (high, CVE-2026-102359), GHSA-px99-rjv4-49g8 (medium, CVE-2026-102356) and GHSA-9p7m-vrmg-qp4q (high) let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed, in 0.32.1 at the latest, and the maintainers published each with a changelog entry, so the deduction is five points (https://github.com/yuzutech/kroki/security/advisories)."
        ],
        "verdict": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
        "bestFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "strengths": [
          "`POST /` with `diagram_source`, `diagram_type` and `output_format`, or plain text to `/\u003ctype\u003e/\u003cformat\u003e`, returns the image. No account or key",
          "One API covers 29 diagram types, among them PlantUML, C4, Structurizr, Mermaid, GraphViz, D2, DBML, BPMN, Excalidraw and Vega",
          "`KROKI_SAFE_MODE` defaults to `SECURE`, which blocks file and network reads by diagram libraries, and the container runs as the non-root user `kroki`",
          "Five versions shipped between 15 July and 5 October 2026, and the `main.yaml` workflow passed on the last ten pushes to `main`",
          "MIT licence. The maintainers published four security advisories in 2026, each with a fixed version and a changelog entry"
        ],
        "weaknesses": [
          "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026",
          "Three more advisories in July and August 2026 let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed in 0.32.1",
          "No OpenAPI file, llms.txt or error catalogue. The JSON error shape is in the source and not in the documentation",
          "The public instance at kroki.io has no terms, privacy policy, status page or published rate limit. The CLI page limits the demonstration server to reasonable, non-commercial use",
          "The server has no authentication on its convert endpoints and binds all interfaces on port 8000 by default. The version is 0.33.0, with no 1.0"
        ],
        "agentNotes": [
          "Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs",
          "Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image",
          "Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers",
          "Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode",
          "Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.2
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 67
        },
        "provenanceScore": 56
      },
      "connect": {
        "install": "docker run -p8000:8000 yuzutech/kroki",
        "http": "curl https://kroki.io/graphviz/svg --data-raw 'digraph G {Hello-\u003eWorld}'"
      },
      "letme": {
        "capability": "https://letme.dev/diagram.as-code",
        "tool": "https://letme.dev/kroki"
      },
      "area": "design-diagrams",
      "provenance": {
        "legalEntity": "Yuzu tech, a French software firm. No registered legal form found",
        "domain": "kroki.io",
        "domainRegistered": "2019-01-06",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/yuzutech/kroki/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The kroki.io home page says Kroki is built and maintained by Yuzu tech, and links https://yuzutech.fr, whose pages name no legal form or registration number. `LICENSE` reads Copyright (c) 2020-present Kroki",
          "No terms or privacy document was found on kroki.io or docs.kroki.io, for the software or for the public instance. The MIT licence stands in for the software",
          "https://kroki.io/.well-known/security.txt answered 404 on 9 October 2026. `SECURITY.md` asks for reports through a private GitHub security advisory",
          "The lead wrote the vendor as Yuzutech. The site writes Yuzu tech, and the GitHub organisation is `yuzutech`",
          "The endpoint on the vendor's domain is the free public instance. The listing grades the server an owner runs"
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kroki.json",
      "live": {
        "slug": "kroki",
        "versions": [
          {
            "registry": "github",
            "name": "yuzutech/kroki",
            "version": "v0.33.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-09T17:00:57.82489933Z"
          }
        ],
        "githubStars": 4365,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/yuzutech/kroki/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:46:31.151891385Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3e34fa594488"
          }
        ],
        "updatedAt": "2026-10-09T18:46:31.151891385Z"
      }
    },
    "answer": "Lucid API + MCP scores 60.6 (C) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability, agent ergonomics, payments \u0026 pricing and maintenance \u0026 community.",
    "b": {
      "slug": "lucid",
      "name": "Lucid API + MCP",
      "vendor": "Lucid Software",
      "vendorUrl": "https://lucid.co",
      "kind": "http-api",
      "category": "diagramming",
      "summary": "REST API and hosted MCP server for creating, reading and managing Lucidchart and Lucidspark diagrams.",
      "url": "https://www.anchorterminal.com/tools/lucid",
      "markdownUrl": "https://www.anchorterminal.com/tools/lucid.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/lucid.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/lucid.json",
      "license": "proprietary",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.lucid.co",
      "packages": [],
      "auth": "mixed",
      "authNotes": "API keys (Bearer, with grants such as DocumentEdit) from the developer portal once developer tools are enabled in user settings or an admin assigns the developer role. OAuth 2.0 with scopes such as lucidchart.document.content, which sharing and embed endpoints require. Every call needs a `Lucid-Api-Version` header. The MCP server uses OAuth with dynamic client registration, and account admins can switch it on for the whole account.",
      "pricing": "freemium",
      "pricingNotes": "Free plan with limited editable documents. Individual $9 a month and Team $10 per user a month with a 3-user minimum, billed yearly. Enterprise custom. Lucid doesn't publish API or MCP limits by plan (https://lucid.app/pricing/lucidchart).",
      "priceSummary": "$9 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No payment support in the REST or MCP docs.",
        "endpoints": []
      },
      "toolCount": 9,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://lucid.readme.io/reference/overview",
      "llmsTxt": "https://lucid.readme.io/llms.txt",
      "registryName": "app.lucid.mcp/lucid",
      "capabilities": [
        "diagram.create",
        "diagram.as-code",
        "diagram.edit",
        "diagram.export",
        "design.files",
        "design.canvas",
        "design.comments"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "closed-source",
        "mcp",
        "llms-txt",
        "diagram-as-code",
        "async-jobs",
        "enterprise"
      ],
      "lastRelease": "2026-06-15",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.6,
        "grade": "C",
        "agentReady": false,
        "rank": 502,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 62,
          "maintenance": 33,
          "payments": 25,
          "reliability": 67,
          "schema": 73,
          "security": 80,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "OAuth 2.0 scopes with `:readonly` variants, and audit log endpoints in the REST API. No public changelog for the API or the MCP server.",
        "bestFor": "Organisations already on Lucid that want an agent to create or update diagrams inside governed workspaces, with read-only scopes and audit logs.",
        "strengths": [
          "OAuth 2.0 scopes with `:readonly` variants, and audit log endpoints in the REST API",
          "Mermaid in through REST, PlantUML sequence diagrams through MCP, both editable afterwards",
          "Per-operation rate limits in each reference page's OpenAPI fragment, such as 60 a minute on Create Mermaid Diagram",
          "Nine compact MCP tools, listed in the official registry as app.lucid.mcp/lucid at 1.0.0",
          "SOC 2 Type II, ISO 27001, FedRAMP Moderate and a HackerOne bug bounty"
        ],
        "weaknesses": [
          "No public changelog for the API or the MCP server",
          "The status page doesn't monitor the API or the MCP server",
          "No single OpenAPI file and no official REST SDK",
          "Developer tools and MCP depend on user settings or admin approval",
          "No published price for API or MCP use beyond seat plans"
        ],
        "agentNotes": [
          "Always send `Lucid-Api-Version: 1`, or prefix the path with /v1",
          "For flowcharts and sequence diagrams, post Mermaid markup (up to 100,000 characters) instead of building Standard Import JSON",
          "Request `:readonly` scopes when the agent only reads documents",
          "On 429, wait 60 seconds or back off. Create Mermaid Diagram allows 60 calls a minute",
          "Sharing and embed endpoints need an OAuth token. An API key won't work there"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.6
          }
        ],
        "editorialScores": {
          "ergonomics": 62,
          "maintenance": 33,
          "payments": 25,
          "reliability": 67,
          "schema": 73,
          "security": 80,
          "transparency": 61
        },
        "provenanceScore": 59
      },
      "connect": {
        "http": "curl https://api.lucid.co/users/me/profile -H \"Authorization: Bearer $LUCID_API_KEY\" -H \"Lucid-Api-Version: 1\"",
        "claudeCode": "claude mcp add --transport http lucid https://mcp.lucid.app/mcp",
        "config": {
          "mcpServers": {
            "lucid": {
              "url": "https://mcp.lucid.app/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/diagram.create",
        "tool": "https://letme.dev/lucid"
      },
      "alsoIn": [
        "design"
      ],
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Individual plan",
          "unit": "seat-month",
          "usd": 9,
          "note": "billed yearly"
        },
        {
          "item": "Team plan",
          "unit": "seat-month",
          "usd": 10,
          "note": "billed yearly, 3-user minimum"
        }
      ],
      "provenance": {
        "legalEntity": "Lucid Software Inc.",
        "domain": "lucid.co",
        "domainRegistered": "",
        "domainNote": "The .co registry has no RDAP service we could query, so the registration date is blank. The MCP server runs on lucid.app, Lucid's product domain.",
        "endpointOnVendorDomain": true,
        "terms": "https://lucid.co/tos",
        "privacy": "https://lucid.co/privacy",
        "statusPage": "https://status.lucid.co",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "The status page has no API or MCP component",
          "security.txt not rechecked on 2026-10-01; none per the 30 September check"
        ],
        "score": 59
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/lucid.json",
      "live": {
        "slug": "lucid",
        "probe": {
          "target": "https://api.lucid.co",
          "method": "get",
          "lastAt": "2026-10-10T02:07:14.675631791Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 202,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 276,
          "p95ms24h": 442,
          "samples24h": 250,
          "samples30d": 2458,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 250,
              "ok": 250
            },
            {
              "date": "2026-10-10",
              "probes": 22,
              "ok": 22
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.lucid.co",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-10T02:06:07.56703698Z"
        },
        "versions": [
          {
            "registry": "mcp-registry",
            "name": "app.lucid.mcp/lucid",
            "version": "1.0.0",
            "seenAt": "2026-10-09T02:57:46.004536428Z"
          }
        ],
        "securityTxt": {
          "url": "https://lucid.co/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:40:02.337495136Z"
        },
        "llmsTxt": {
          "url": "https://lucid.readme.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-09T14:02:15.201786623Z"
        },
        "domain": {
          "domain": "lucid.co",
          "checkedAt": "2026-10-04T13:08:39.466296912Z"
        },
        "pages": [
          {
            "url": "https://lucid.app/pricing/lucidchart",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:41:35.878848555Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ba6244b9a39a"
          },
          {
            "url": "https://lucid.co/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:41:37.287448985Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "42182e432bc9"
          },
          {
            "url": "https://lucid.co/tos",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:41:39.740542601Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "522f8449b0a1"
          }
        ],
        "updatedAt": "2026-10-10T02:07:14.675631791Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Yuzu tech",
        "b": "Lucid Software",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://api.lucid.co",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "proprietary",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "9",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "app.lucid.mcp/lucid",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-05",
        "b": "2026-06-15",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "4.4k stars",
        "b": "none",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Lucid API + MCP scores 60.6 (C) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability, agent ergonomics, payments \u0026 pricing and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Kroki or Lucid API + MCP?"
      },
      {
        "answer": "Kroki needs no key. Lucid API + MCP takes an API key or an OAuth sign-in.",
        "question": "Do Kroki and Lucid API + MCP need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Kroki. Lucid API + MCP has a hosted endpoint at https://api.lucid.co.",
        "question": "Can an agent call Kroki and Lucid API + MCP without installing anything?"
      },
      {
        "answer": "Kroki is open source (MIT). No open-source release is listed for Lucid API + MCP.",
        "question": "Are Kroki and Lucid API + MCP open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 74 against 67",
          "Agent ergonomics, 70 against 62",
          "Payments \u0026 pricing, 60 against 25",
          "Maintenance \u0026 community, 86 against 33"
        ],
        "also": [
          "No key needed to call it",
          "Open source"
        ],
        "goodFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "slug": "kroki",
        "watchFor": "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 73 against 48",
          "Security \u0026 auth, 80 against 56"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "No incidents deducted, where Kroki loses 5 points for them"
        ],
        "goodFor": "Organisations already on Lucid that want an agent to create or update diagrams inside governed workspaces, with read-only scopes and audit logs.",
        "slug": "lucid",
        "watchFor": "No public changelog for the API or the MCP server"
      }
    ],
    "job": {
      "capability": "diagram.as-code",
      "name": "Diagrams as code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki.json",
        "title": "Cloudviz API vs Kroki",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-lucid.json",
        "title": "Cloudviz API vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.json",
        "title": "Diagrams.so API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-lucid.json",
        "title": "Diagrams.so API + MCP vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-kroki.json",
        "title": "draw.io + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-lucid.json",
        "title": "draw.io + MCP vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-kroki.json",
        "title": "Eraser API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-lucid.json",
        "title": "Eraser API + MCP vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki.json",
        "title": "Excalidraw vs Kroki",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-lucid.json",
        "title": "Excalidraw vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.json",
        "title": "Kroki vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-whimsical.json",
        "title": "Kroki vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lucid-vs-mermaid-chart.json",
        "title": "Lucid API + MCP vs Mermaid Chart MCP",
        "url": "https://www.anchorterminal.com/compare/lucid-vs-mermaid-chart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lucid-vs-mural-mcp.json",
        "title": "Lucid API + MCP vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/lucid-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lucid-vs-plantuml.json",
        "title": "Lucid API + MCP vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/lucid-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lucid-vs-structurizr.json",
        "title": "Lucid API + MCP vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/lucid-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lucid-vs-tldraw.json",
        "title": "Lucid API + MCP vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/lucid-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lucid-vs-whimsical.json",
        "title": "Lucid API + MCP vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/lucid-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-kroki.json",
        "title": "D2 vs Kroki",
        "url": "https://www.anchorterminal.com/compare/d2-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-lucid.json",
        "title": "D2 vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/d2-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.json",
        "title": "Kroki vs Mermaid Chart MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-plantuml.json",
        "title": "Kroki vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-structurizr.json",
        "title": "Kroki vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-tldraw.json",
        "title": "Kroki vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-tldraw"
      }
    ],
    "scores": [
      {
        "by": 7,
        "edge": "kroki",
        "key": "reliability",
        "kroki": 74,
        "lucid": 67,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 25,
        "edge": "lucid",
        "key": "schema",
        "kroki": 48,
        "lucid": 73,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 8,
        "edge": "kroki",
        "key": "ergonomics",
        "kroki": 70,
        "lucid": 62,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 24,
        "edge": "lucid",
        "key": "security",
        "kroki": 56,
        "lucid": 80,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 35,
        "edge": "kroki",
        "key": "payments",
        "kroki": 60,
        "lucid": 25,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 53,
        "edge": "kroki",
        "key": "maintenance",
        "kroki": 86,
        "lucid": 33,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 2,
        "edge": "kroki",
        "key": "transparency",
        "kroki": 62,
        "lucid": 60,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Lucid API + MCP scores 60.6 (C) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability, agent ergonomics, payments \u0026 pricing and maintenance \u0026 community. Both do diagrams as code.",
    "verdicts": {
      "kroki": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
      "lucid": "OAuth 2.0 scopes with `:readonly` variants, and audit log endpoints in the REST API. No public changelog for the API or the MCP server."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/kroki-vs-lucid",
    "json": "https://www.anchorterminal.com/compare/kroki-vs-lucid.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/kroki-vs-lucid.md",
    "slim": "https://www.anchorterminal.com/compare/kroki-vs-lucid.min.md"
  },
  "markdown": "Lucid API + MCP scores 60.6 (C) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability, agent ergonomics, payments \u0026 pricing and maintenance \u0026 community. Both do diagrams as code.\n\n- Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json\n- Lucid API + MCP: grade C, 60.6/100, rank #502 of 950. Markdown https://www.anchorterminal.com/tools/lucid.md · JSON https://www.anchorterminal.com/api/v1/tools/lucid.json\n- Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md\n- All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md\n- Best design workspace and canvas APIs for AI agents: https://www.anchorterminal.com/best/design/index.md\n- All 49 design comparisons: https://www.anchorterminal.com/compare/design/index.md\n\n## Which one, for what\n\n### Kroki (C)\n\nGood for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.\n\nAhead on:\n- Reliability, 74 against 67\n- Agent ergonomics, 70 against 62\n- Payments \u0026 pricing, 60 against 25\n- Maintenance \u0026 community, 86 against 33\n\nAlso in its favour:\n- No key needed to call it\n- Open source\n\nWatch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026\n\n### Lucid API + MCP (C)\n\nGood for: Organisations already on Lucid that want an agent to create or update diagrams inside governed workspaces, with read-only scopes and audit logs.\n\nAhead on:\n- Schema \u0026 documentation, 73 against 48\n- Security \u0026 auth, 80 against 56\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- No incidents deducted, where Kroki loses 5 points for them\n\nWatch for: No public changelog for the API or the MCP server\n\n\n## Score by category\n\n| Category | Weight | Kroki | Lucid API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 74 | 67 | Kroki +7 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 48 | 73 | Lucid API + MCP +25 |\n| Agent ergonomics | 13% (16.2 this run) | 70 | 62 | Kroki +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 56 | 80 | Lucid API + MCP +24 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 25 | Kroki +35 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 86 | 33 | Kroki +53 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 62 | 60 | Kroki +2 |\n| Negative events | ≤15 | -5 | 0 | |\n| **Total** | | **59.2 · C** | **60.6 · C** | |\n\n## Facts side by side\n\n| Fact | Kroki | Lucid API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Yuzu tech | Lucid Software |\n| Hosted endpoint | no (local only) | `https://api.lucid.co` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | None | OAuth or key |\n| Pricing | Free | Freemium |\n| x402 | no | no |\n| Licence | MIT | proprietary |\n| Tools exposed | none | 9 |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| MCP registry | not listed | `app.lucid.mcp/lucid` |\n| Last release | 2026-10-05 | 2026-06-15 |\n| Terms last updated | no document linked | couldn't be read |\n| Privacy policy last updated | no document linked | couldn't be read |\n| Customer content may train models |  | couldn't be read |\n| Terms restrict automated access |  | couldn't be read |\n| Terms restrict benchmarking |  | couldn't be read |\n| Terms or service can change without notice |  | couldn't be read |\n| Arbitration or class-action waiver |  | couldn't be read |\n| Popularity | 4.4k stars | none |\n| Agent reviews | none | 3/5 (2) |\n\n## Verdicts\n\n**Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.\n\n**Lucid API + MCP.** OAuth 2.0 scopes with `:readonly` variants, and audit log endpoints in the REST API. No public changelog for the API or the MCP server.\n\n## Before you call either\n\n### Kroki\n\n1. Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs\n2. Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image\n3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers\n4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode\n5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication\n\n### Lucid API + MCP\n\n1. Always send `Lucid-Api-Version: 1`, or prefix the path with /v1\n2. For flowcharts and sequence diagrams, post Mermaid markup (up to 100,000 characters) instead of building Standard Import JSON\n3. Request `:readonly` scopes when the agent only reads documents\n4. On 429, wait 60 seconds or back off. Create Mermaid Diagram allows 60 calls a minute\n5. Sharing and embed endpoints need an OAuth token. An API key won't work there\n\n## Questions\n\n### Which is better for AI agents, Kroki or Lucid API + MCP?\n\nLucid API + MCP scores 60.6 (C) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability, agent ergonomics, payments \u0026 pricing and maintenance \u0026 community.\n\n### Do Kroki and Lucid API + MCP need an API key?\n\nKroki needs no key. Lucid API + MCP takes an API key or an OAuth sign-in.\n\n### Can an agent call Kroki and Lucid API + MCP without installing anything?\n\nNo hosted endpoint is listed for Kroki. Lucid API + MCP has a hosted endpoint at https://api.lucid.co.\n\n### Are Kroki and Lucid API + MCP open source?\n\nKroki is open source (MIT). No open-source release is listed for Lucid API + MCP.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/kroki-vs-lucid.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kroki-vs-lucid.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"kroki\", \"b\": \"lucid\"}`. From a terminal: `anchor compare kroki lucid`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/kroki.json and https://www.anchorterminal.com/api/v1/tools/lucid.json\n\n## Other comparisons with Kroki or Lucid API + MCP\n\n- [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md)\n- [Cloudviz API vs Lucid API + MCP](https://www.anchorterminal.com/compare/cloudviz-vs-lucid.md)\n- [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md)\n- [Diagrams.so API + MCP vs Lucid API + MCP](https://www.anchorterminal.com/compare/diagrams-so-vs-lucid.md)\n- [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md)\n- [draw.io + MCP vs Lucid API + MCP](https://www.anchorterminal.com/compare/drawio-vs-lucid.md)\n- [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md)\n- [Eraser API + MCP vs Lucid API + MCP](https://www.anchorterminal.com/compare/eraser-vs-lucid.md)\n- [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md)\n- [Excalidraw vs Lucid API + MCP](https://www.anchorterminal.com/compare/excalidraw-vs-lucid.md)\n- [Kroki vs Mural MCP](https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md)\n- [Kroki vs Whimsical MCP](https://www.anchorterminal.com/compare/kroki-vs-whimsical.md)\n- [Lucid API + MCP vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/lucid-vs-mermaid-chart.md)\n- [Lucid API + MCP vs Mural MCP](https://www.anchorterminal.com/compare/lucid-vs-mural-mcp.md)\n- [Lucid API + MCP vs PlantUML](https://www.anchorterminal.com/compare/lucid-vs-plantuml.md)\n- [Lucid API + MCP vs Structurizr + MCP](https://www.anchorterminal.com/compare/lucid-vs-structurizr.md)\n- [Lucid API + MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/lucid-vs-tldraw.md)\n- [Lucid API + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/lucid-vs-whimsical.md)\n- [D2 vs Kroki](https://www.anchorterminal.com/compare/d2-vs-kroki.md)\n- [D2 vs Lucid API + MCP](https://www.anchorterminal.com/compare/d2-vs-lucid.md)\n- [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md)\n- [Kroki vs PlantUML](https://www.anchorterminal.com/compare/kroki-vs-plantuml.md)\n- [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md)\n- [Kroki vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/kroki-vs-tldraw.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Kroki vs Lucid API + MCP",
        "url": ""
      }
    ],
    "description": "Lucid scores 60.6 (C) to Kroki's 59.2 (C) for diagrams as code. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Kroki C 59.2",
      "Lucid API + MCP C 60.6",
      "scores"
    ],
    "h1": "Kroki vs Lucid API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-kroki-vs-lucid.png",
    "path": "/compare/kroki-vs-lucid",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Kroki vs Lucid for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/kroki-vs-lucid"
  },
  "tokens": {
    "markdown": 2500,
    "slim": 730
  },
  "version": 1
}
