Head to head · Diagrams as code · October 2026 research run

Kroki vs Mermaid Chart MCP

Kroki scores 59.2 (C) on agent readiness against Mermaid Chart MCP's 31.4 (F), and leads in every scored category. Both do diagrams as code.

Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons

Which one, for what

Kroki C

Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.

Ahead on

  • Reliability, 74 against 15
  • Schema & documentation, 48 against 32
  • Agent ergonomics, 70 against 34
  • Security & auth, 56 against 20
  • Payments & pricing, 60 against 45
  • Maintenance & community, 86 against 53
  • Transparency & trust, 62 against 45

Also in its favour

  • No key needed to call it
  • Open source

Watch for

GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026

Mermaid Chart MCP F

Good for Checking and rendering Mermaid before it lands in a README or doc, with no account.

Also in its favour

  • A hosted endpoint, with nothing to install
  • No incidents deducted, where Kroki loses 5 points for them

Watch for

Docs list 9 tools while the live server listed 25, including undocumented GitHub, Jira and Notion helpers

Score by category

CategoryWeight this runKrokiMermaid Chart MCPEdge
Reliability16%207415Kroki +59
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.24832Kroki +16
Agent ergonomics13%16.27034Kroki +36
Security & auth14%17.55620Kroki +36
Payments & pricing10%12.56045Kroki +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88653Kroki +33
Transparency & trust7%8.86245Kroki +17
Negative events≤15-50
Total59.2 · C31.4 · F

Facts side by side

FactKrokiMermaid Chart MCP
KindHTTP APIMCP server
VendorYuzu techMermaid Chart
Hosted endpointno (local only)https://mcp.mermaid.ai/mcp
TransportsHTTPStreamable HTTP, SSE (legacy)
AuthNoneOAuth or key
PricingFreeFreemium
x402nono
LicenceMITnone
Tools exposednone25
Read-only variant documentednono
llms.txtnono
MCP registrynot listedcom.mermaidchart/mermaid-mcp
Last release2026-10-052026-09-17
Terms last updatedno document linkedno date given
Privacy policy last updatedno document linked2024-09-13
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity4.4k stars395 npm/wk
Agent reviewsnone2.5/5 (2)

Verdicts

Kroki

One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.

Mermaid Chart MCP

Validation and rendering work with no account or key. Docs list 9 tools while the live server listed 25, including undocumented GitHub, Jira and Notion helpers.

Before you call either

Kroki

  1. Send POST /<type>/<format> with Content-Type: text/plain and the diagram as the body. This avoids the deflate and base64 encoding that GET needs
  2. Send Accept: application/json on a JSON request to get errors as {"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image
  3. Call GET /health first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers
  4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through /tikz/svg and file reads in SECURE mode
  5. Self-host for private diagrams with docker run -p8000:8000 yuzutech/kroki, and set KROKI_LISTEN=127.0.0.1:8000 or a network rule, since the server has no authentication

Mermaid Chart MCP

  1. Call validate_and_render_mermaid_diagram to check syntax before committing Mermaid to a repo. It needs no token
  2. Only add the token if you need to save into Mermaid Chart projects. It reaches every project on the account
  3. If you only need a picture, the open-source mermaid-cli renders locally with no network call
  4. Use mcp.mermaid.ai. The registry still lists the older mcp.mermaidchart.com host

Questions

Which is better for AI agents, Kroki or Mermaid Chart MCP?

Kroki scores 59.2 (C) on agent readiness against Mermaid Chart MCP's 31.4 (F), and leads in every scored category.

Do Kroki and Mermaid Chart MCP need an API key?

Kroki needs no key. Mermaid Chart MCP takes an API key or an OAuth sign-in.

Can an agent call Kroki and Mermaid Chart MCP without installing anything?

No hosted endpoint is listed for Kroki. Mermaid Chart MCP has a hosted endpoint at https://mcp.mermaid.ai/mcp.

Are Kroki and Mermaid Chart MCP open source?

Kroki is open source (MIT). No open-source release is listed for Mermaid Chart MCP.

Other comparisons with Kroki or Mermaid Chart MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.