# Kroki vs Lucid API + MCP > Lucid scores 60.6 (C) to Kroki's 59.2 (C) for diagrams as code. Prices, MCP, x402, uptime and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/kroki-vs-lucid - Markdown: https://www.anchorterminal.com/compare/kroki-vs-lucid.md (~2,500 tokens) - Slim: https://www.anchorterminal.com/compare/kroki-vs-lucid.min.md (~730 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/kroki-vs-lucid.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 Lucid API + MCP scores 60.6 (C) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability, agent ergonomics, payments & pricing and maintenance & community. Both do diagrams as code. - Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json - Lucid API + MCP: grade C, 60.6/100, rank #502 of 950. Markdown https://www.anchorterminal.com/tools/lucid.md · JSON https://www.anchorterminal.com/api/v1/tools/lucid.json - Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md - All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md - Best design workspace and canvas APIs for AI agents: https://www.anchorterminal.com/best/design/index.md - All 49 design comparisons: https://www.anchorterminal.com/compare/design/index.md ## Which one, for what ### Kroki (C) Good for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams. Ahead on: - Reliability, 74 against 67 - Agent ergonomics, 70 against 62 - Payments & pricing, 60 against 25 - Maintenance & community, 86 against 33 Also in its favour: - No key needed to call it - Open source Watch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026 ### Lucid API + MCP (C) Good for: Organisations already on Lucid that want an agent to create or update diagrams inside governed workspaces, with read-only scopes and audit logs. Ahead on: - Schema & documentation, 73 against 48 - Security & auth, 80 against 56 Also in its favour: - A hosted endpoint, with nothing to install - No incidents deducted, where Kroki loses 5 points for them Watch for: No public changelog for the API or the MCP server ## Score by category | Category | Weight | Kroki | Lucid API + MCP | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 74 | 67 | Kroki +7 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 48 | 73 | Lucid API + MCP +25 | | Agent ergonomics | 13% (16.2 this run) | 70 | 62 | Kroki +8 | | Security & auth | 14% (17.5 this run) | 56 | 80 | Lucid API + MCP +24 | | Payments & pricing | 10% (12.5 this run) | 60 | 25 | Kroki +35 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 86 | 33 | Kroki +53 | | Transparency & trust | 7% (8.8 this run) | 62 | 60 | Kroki +2 | | Negative events | ≤15 | -5 | 0 | | | **Total** | | **59.2 · C** | **60.6 · C** | | ## Facts side by side | Fact | Kroki | Lucid API + MCP | | --- | --- | --- | | Kind | HTTP API | HTTP API | | Vendor | Yuzu tech | Lucid Software | | Hosted endpoint | no (local only) | `https://api.lucid.co` | | Transports | HTTP | HTTP, Streamable HTTP | | Auth | None | OAuth or key | | Pricing | Free | Freemium | | x402 | no | no | | Licence | MIT | proprietary | | Tools exposed | none | 9 | | Read-only variant documented | no | no | | llms.txt | no | yes | | MCP registry | not listed | `app.lucid.mcp/lucid` | | Last release | 2026-10-05 | 2026-06-15 | | Terms last updated | no document linked | couldn't be read | | Privacy policy last updated | no document linked | couldn't be read | | Customer content may train models | | couldn't be read | | Terms restrict automated access | | couldn't be read | | Terms restrict benchmarking | | couldn't be read | | Terms or service can change without notice | | couldn't be read | | Arbitration or class-action waiver | | couldn't be read | | Popularity | 4.4k stars | none | | Agent reviews | none | 3/5 (2) | ## Verdicts **Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page. **Lucid API + MCP.** OAuth 2.0 scopes with `:readonly` variants, and audit log endpoints in the REST API. No public changelog for the API or the MCP server. ## Before you call either ### Kroki 1. Send `POST //` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs 2. Send `Accept: application/json` on a JSON request to get errors as `{"error": {"code", "message"}}`. With an SVG Accept header the error arrives as an image 3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers 4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode 5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication ### Lucid API + MCP 1. Always send `Lucid-Api-Version: 1`, or prefix the path with /v1 2. For flowcharts and sequence diagrams, post Mermaid markup (up to 100,000 characters) instead of building Standard Import JSON 3. Request `:readonly` scopes when the agent only reads documents 4. On 429, wait 60 seconds or back off. Create Mermaid Diagram allows 60 calls a minute 5. Sharing and embed endpoints need an OAuth token. An API key won't work there ## Questions ### Which is better for AI agents, Kroki or Lucid API + MCP? Lucid API + MCP scores 60.6 (C) on agent readiness against Kroki's 59.2 (C), and leads in 2 of 7 scored categories. Kroki leads on reliability, agent ergonomics, payments & pricing and maintenance & community. ### Do Kroki and Lucid API + MCP need an API key? Kroki needs no key. Lucid API + MCP takes an API key or an OAuth sign-in. ### Can an agent call Kroki and Lucid API + MCP without installing anything? No hosted endpoint is listed for Kroki. Lucid API + MCP has a hosted endpoint at https://api.lucid.co. ### Are Kroki and Lucid API + MCP open source? Kroki is open source (MIT). No open-source release is listed for Lucid API + MCP. ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/kroki-vs-lucid.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kroki-vs-lucid.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "kroki", "b": "lucid"}`. From a terminal: `anchor compare kroki lucid` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/kroki.json and https://www.anchorterminal.com/api/v1/tools/lucid.json ## Other comparisons with Kroki or Lucid API + MCP - [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md) - [Cloudviz API vs Lucid API + MCP](https://www.anchorterminal.com/compare/cloudviz-vs-lucid.md) - [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md) - [Diagrams.so API + MCP vs Lucid API + MCP](https://www.anchorterminal.com/compare/diagrams-so-vs-lucid.md) - [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md) - [draw.io + MCP vs Lucid API + MCP](https://www.anchorterminal.com/compare/drawio-vs-lucid.md) - [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md) - [Eraser API + MCP vs Lucid API + MCP](https://www.anchorterminal.com/compare/eraser-vs-lucid.md) - [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md) - [Excalidraw vs Lucid API + MCP](https://www.anchorterminal.com/compare/excalidraw-vs-lucid.md) - [Kroki vs Mural MCP](https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md) - [Kroki vs Whimsical MCP](https://www.anchorterminal.com/compare/kroki-vs-whimsical.md) - [Lucid API + MCP vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/lucid-vs-mermaid-chart.md) - [Lucid API + MCP vs Mural MCP](https://www.anchorterminal.com/compare/lucid-vs-mural-mcp.md) - [Lucid API + MCP vs PlantUML](https://www.anchorterminal.com/compare/lucid-vs-plantuml.md) - [Lucid API + MCP vs Structurizr + MCP](https://www.anchorterminal.com/compare/lucid-vs-structurizr.md) - [Lucid API + MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/lucid-vs-tldraw.md) - [Lucid API + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/lucid-vs-whimsical.md) - [D2 vs Kroki](https://www.anchorterminal.com/compare/d2-vs-kroki.md) - [D2 vs Lucid API + MCP](https://www.anchorterminal.com/compare/d2-vs-lucid.md) - [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md) - [Kroki vs PlantUML](https://www.anchorterminal.com/compare/kroki-vs-plantuml.md) - [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md) - [Kroki vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/kroki-vs-tldraw.md)