{
  "data": {
    "a": {
      "slug": "kroki",
      "name": "Kroki",
      "vendor": "Yuzu tech",
      "vendorUrl": "https://kroki.io",
      "kind": "http-api",
      "category": "diagramming",
      "summary": "Kroki is an open-source HTTP server from Yuzu tech that converts diagram text in 29 formats, including PlantUML, Mermaid, GraphViz and D2, into SVG, PNG or PDF. Owners run it from Docker images, and kroki.io is a free public instance.",
      "url": "https://www.anchorterminal.com/tools/kroki",
      "markdownUrl": "https://www.anchorterminal.com/tools/kroki.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kroki.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kroki.json",
      "repo": "https://github.com/yuzutech/kroki",
      "license": "MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "yuzutech/kroki"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-mermaid"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-bpmn"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-excalidraw"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or login on the convert endpoints, on a self-hosted server or on the public instance at kroki.io. The server binds all interfaces on port 8000 unless `KROKI_LISTEN` says otherwise. An optional bearer token, `KROKI_COMPANION_REGISTRATION_TOKEN`, protects only the `/services` registration API, which is off by default.",
      "pricing": "free",
      "pricingNotes": "Free under the MIT licence, with nothing to buy. The public instance at kroki.io is free and paid for by sponsors, for reasonable, non-commercial use with no uptime guarantee. Third parties sell hosting, which the project says it does not operate.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4365,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.kroki.io/kroki/setup/usage/",
      "capabilities": [
        "diagram.as-code",
        "diagram.create",
        "diagram.export",
        "diagram.architecture"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "http-api",
        "docker",
        "diagram-as-code",
        "plantuml",
        "mermaid",
        "graphviz",
        "no-auth",
        "free"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.2,
        "grade": "C",
        "agentReady": false,
        "rank": 558,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -5,
        "negativeNotes": [
          "27 July to 12 August 2026. Four advisories on the repository. GHSA-wmpp-fj9c-w766 (critical, CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in 0.21.0 up to 0.32.0 whatever the safe mode. GHSA-r54f-fq6c-53vw (high, CVE-2026-102359), GHSA-px99-rjv4-49g8 (medium, CVE-2026-102356) and GHSA-9p7m-vrmg-qp4q (high) let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed, in 0.32.1 at the latest, and the maintainers published each with a changelog entry, so the deduction is five points (https://github.com/yuzutech/kroki/security/advisories)."
        ],
        "verdict": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
        "bestFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "strengths": [
          "`POST /` with `diagram_source`, `diagram_type` and `output_format`, or plain text to `/\u003ctype\u003e/\u003cformat\u003e`, returns the image. No account or key",
          "One API covers 29 diagram types, among them PlantUML, C4, Structurizr, Mermaid, GraphViz, D2, DBML, BPMN, Excalidraw and Vega",
          "`KROKI_SAFE_MODE` defaults to `SECURE`, which blocks file and network reads by diagram libraries, and the container runs as the non-root user `kroki`",
          "Five versions shipped between 15 July and 5 October 2026, and the `main.yaml` workflow passed on the last ten pushes to `main`",
          "MIT licence. The maintainers published four security advisories in 2026, each with a fixed version and a changelog entry"
        ],
        "weaknesses": [
          "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026",
          "Three more advisories in July and August 2026 let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed in 0.32.1",
          "No OpenAPI file, llms.txt or error catalogue. The JSON error shape is in the source and not in the documentation",
          "The public instance at kroki.io has no terms, privacy policy, status page or published rate limit. The CLI page limits the demonstration server to reasonable, non-commercial use",
          "The server has no authentication on its convert endpoints and binds all interfaces on port 8000 by default. The version is 0.33.0, with no 1.0"
        ],
        "agentNotes": [
          "Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs",
          "Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image",
          "Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers",
          "Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode",
          "Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.2
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 67
        },
        "provenanceScore": 56
      },
      "connect": {
        "install": "docker run -p8000:8000 yuzutech/kroki",
        "http": "curl https://kroki.io/graphviz/svg --data-raw 'digraph G {Hello-\u003eWorld}'"
      },
      "letme": {
        "capability": "https://letme.dev/diagram.as-code",
        "tool": "https://letme.dev/kroki"
      },
      "area": "design-diagrams",
      "provenance": {
        "legalEntity": "Yuzu tech, a French software firm. No registered legal form found",
        "domain": "kroki.io",
        "domainRegistered": "2019-01-06",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/yuzutech/kroki/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The kroki.io home page says Kroki is built and maintained by Yuzu tech, and links https://yuzutech.fr, whose pages name no legal form or registration number. `LICENSE` reads Copyright (c) 2020-present Kroki",
          "No terms or privacy document was found on kroki.io or docs.kroki.io, for the software or for the public instance. The MIT licence stands in for the software",
          "https://kroki.io/.well-known/security.txt answered 404 on 9 October 2026. `SECURITY.md` asks for reports through a private GitHub security advisory",
          "The lead wrote the vendor as Yuzutech. The site writes Yuzu tech, and the GitHub organisation is `yuzutech`",
          "The endpoint on the vendor's domain is the free public instance. The listing grades the server an owner runs"
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kroki.json",
      "live": {
        "slug": "kroki",
        "versions": [
          {
            "registry": "github",
            "name": "yuzutech/kroki",
            "version": "v0.33.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-09T17:00:57.82489933Z"
          }
        ],
        "githubStars": 4365,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/yuzutech/kroki/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:46:31.151891385Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3e34fa594488"
          }
        ],
        "updatedAt": "2026-10-09T18:46:31.151891385Z"
      }
    },
    "answer": "Kroki scores 59.2 (C) on agent readiness against Mural MCP's 41.9 (E), and leads in 6 of 7 scored categories. Mural MCP leads on security \u0026 auth.",
    "b": {
      "slug": "mural-mcp",
      "name": "Mural MCP",
      "vendor": "Tactivos, Inc. (d/b/a Mural)",
      "vendorUrl": "https://www.mural.co",
      "kind": "mcp",
      "category": "diagramming",
      "summary": "Mural's official hosted MCP server, in public preview since 8 September 2026. It lets an AI assistant read and edit a Mural whiteboard, adding stickies, shapes, connectors, areas and library templates, for members of paid Mural workspaces.",
      "url": "https://www.anchorterminal.com/tools/mural-mcp",
      "markdownUrl": "https://www.anchorterminal.com/tools/mural-mcp.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/mural-mcp.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/mural-mcp.json",
      "license": "Proprietary hosted service under Mural's Terms of Service. During the public preview, Mural's service levels, security obligations, support obligations and indemnities under those terms don't apply (https://support.mural.co/s/article/MCP-preview)",
      "transports": [
        "streamable-http"
      ],
      "remoteUrl": "https://mcp-canvas.mural.co/mcp",
      "packages": [],
      "auth": "oauth",
      "authNotes": "OAuth only, no API keys. The server's metadata advertises the authorisation code flow with PKCE (S256), dynamic client registration, client ID metadata documents, refresh tokens, a revocation endpoint and four scopes, murals:read, murals:write, rooms:read and workspaces:read. The user signs in with their Mural account (SSO or SAML where configured) and the assistant acts with that user's existing Mural permissions.",
      "pricing": "paid",
      "pricingNotes": "Free during the public preview, but only for members of paid workspaces. Team+ is $9.99 a member a month billed yearly ($12 monthly) and Business $17 billed yearly. The Free plan is excluded. Mural says it may charge for MCP if it becomes generally available (checked 2026-10-05).",
      "priceSummary": "$9.99 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the MCP help article, the MCP landing page, the pricing page or the server's OAuth metadata (checked 2026-10-05).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-05"
      },
      "docsUrl": "https://support.mural.co/s/article/MCP-preview",
      "registryName": "co.mural/mural",
      "capabilities": [
        "diagram.create",
        "diagram.edit",
        "design.canvas"
      ],
      "tags": [
        "hosted",
        "mcp",
        "oauth",
        "preview",
        "closed-source",
        "paid-plan",
        "status-page",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 41.9,
        "grade": "E",
        "agentReady": false,
        "rank": 899,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 11,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 26,
          "maintenance": 75,
          "payments": 10,
          "reliability": 35,
          "schema": 30,
          "security": 72,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "low",
          "date": "2026-10-05"
        },
        "negative": 0,
        "verdict": "Mural's own MCP server signs in by OAuth with read and write scopes and logs every agent action in the mural's audit trail. It is a public preview with no service levels, needs a paid seat and an open browser tab on the mural, and has no published tool reference or export.",
        "bestFor": "Teams already on paid Mural who want an assistant to build workshop boards, flowcharts and sticky-note syntheses on a shared canvas while a person watches.",
        "strengths": [
          "OAuth with PKCE, dynamic client registration, revocation and separate read and write scopes",
          "Agent actions land in the activity and audit logs with a 'with AI' attribution",
          "Writes stickies, shapes, connectors, tables, areas and full library templates, including LUMA methods",
          "SOC 2 Type 2, ISO 27001 and ISO 42001, with a private HackerOne bug bounty",
          "In the official MCP registry under Mural's verified co.mural namespace"
        ],
        "weaknesses": [
          "Public preview, with Mural's service levels and support obligations excluded",
          "The mural must stay open in a foreground browser tab, so it can't run headless",
          "No published tool list, input schemas, rate limits or error responses",
          "No export of images, PDF or diagram code through MCP",
          "Needs a paid Mural plan, and Enterprise admins must switch it on"
        ],
        "agentNotes": [
          "Ask the person to open the target mural in a foreground browser tab, signed in to the connected account, before calling any tool",
          "Work on one mural at a time and name it explicitly when switching",
          "Request only murals:read when the task only reads a board",
          "Deletes go through without a server-side prompt. Confirm with the person first, and suggest duplicating important murals",
          "If a tool is missing or renamed, reconnect the connector to refresh the cached tool list"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 1,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "low",
            "grade": "E",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 41.9
          }
        ],
        "editorialScores": {
          "ergonomics": 26,
          "maintenance": 75,
          "payments": 10,
          "reliability": 35,
          "schema": 30,
          "security": 72,
          "transparency": 51
        },
        "provenanceScore": 70
      },
      "connect": {
        "config": {
          "mcpServers": {
            "mural": {
              "url": "https://mcp-canvas.mural.co/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/diagram.create",
        "tool": "https://letme.dev/mural-mcp"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Team+ plan",
          "unit": "seat-month",
          "usd": 9.99,
          "note": "per member, billed yearly ($12 billed monthly). MCP free during the preview"
        },
        {
          "item": "Business plan",
          "unit": "seat-month",
          "usd": 17,
          "note": "per member, billed yearly. Adds SAML SSO"
        }
      ],
      "provenance": {
        "legalEntity": "Tactivos, Inc. (d/b/a Mural)",
        "domain": "mural.co",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://www.mural.co/terms/terms-of-service",
        "privacy": "https://www.mural.co/terms/privacy-statement",
        "statusPage": "https://status.mural.co",
        "changelog": "https://www.mural.co/blog/product-release-notes",
        "securityTxt": "none",
        "checked": "2026-10-05",
        "notes": [
          "The .co registry has no RDAP service we could query, so the registration date is blank. The MCP server runs on mcp-canvas.mural.co",
          "The site footer names Tactivos, Inc. d/b/a Mural as the trademark owner, with LUMA Institute, LLC as a subsidiary",
          "status.mural.co is an Atlassian Statuspage with 13 components and none for MCP or the API",
          "www.mural.co/.well-known/security.txt returns 404 and app.mural.co returns the web app's HTML. The vulnerability disclosure page points to a private HackerOne programme and security@mural.co",
          "Product release notes are weekly posts on the Mural blog. The developer API changelog's last entry is from December 2023"
        ],
        "score": 70
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/mural-mcp.json",
      "live": {
        "slug": "mural-mcp",
        "probe": {
          "target": "https://mcp-canvas.mural.co/mcp",
          "method": "mcp-initialize",
          "lastAt": "2026-10-10T03:53:35.199533503Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 272,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 270,
          "p95ms24h": 330,
          "samples24h": 249,
          "samples30d": 1100,
          "days": [
            {
              "date": "2026-10-06",
              "probes": 270,
              "ok": 270
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 250,
              "ok": 250
            },
            {
              "date": "2026-10-10",
              "probes": 40,
              "ok": 40
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.mural.co",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-10T03:58:28.646300135Z"
        },
        "versions": [
          {
            "registry": "mcp-registry",
            "name": "co.mural/mural",
            "version": "1.0.1",
            "seenAt": "2026-10-10T03:11:32.438759038Z"
          }
        ],
        "securityTxt": {
          "url": "https://mural.co/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:40:11.40023093Z"
        },
        "pages": [
          {
            "url": "https://www.mural.co/blog/product-release-notes",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:52:22.795531888Z",
            "changedAt": "2026-10-09T18:52:22.795531888Z",
            "fingerprint": "1150ca5e84fb"
          },
          {
            "url": "https://www.mural.co/terms/privacy-statement",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:52:24.871967663Z",
            "changedAt": "2026-10-09T18:52:24.871967663Z",
            "fingerprint": "3aefdec26932"
          },
          {
            "url": "https://www.mural.co/terms/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:52:26.874710992Z",
            "changedAt": "2026-10-09T18:52:26.874710992Z",
            "fingerprint": "de57955d9300"
          }
        ],
        "mcpTools": {
          "url": "https://mcp-canvas.mural.co/mcp",
          "checkedAt": "2026-10-09T21:40:46.580605557Z",
          "status": "auth",
          "note": "asks for credentials before listing its tools",
          "changedAt": "2026-10-06T22:38:15.17024466Z"
        },
        "updatedAt": "2026-10-10T03:58:28.646300135Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "MCP server",
        "name": "Kind"
      },
      {
        "a": "Yuzu tech",
        "b": "Tactivos, Inc. (d/b/a Mural)",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://mcp-canvas.mural.co/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "Proprietary hosted service under Mural's Terms of Service. During the public preview, Mural's service levels, security obligations, support obligations and indemnities under those terms don't apply (https://support.mural.co/s/article/MCP-preview)",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "co.mural/mural",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-05",
        "b": "2026-10-05",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2026-07-01",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "4.4k stars",
        "b": "none",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "2/5 (1)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Kroki scores 59.2 (C) on agent readiness against Mural MCP's 41.9 (E), and leads in 6 of 7 scored categories. Mural MCP leads on security \u0026 auth.",
        "question": "Which is better for AI agents, Kroki or Mural MCP?"
      },
      {
        "answer": "Kroki needs no key. Mural MCP uses an OAuth sign-in.",
        "question": "Do Kroki and Mural MCP need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Kroki. Mural MCP has a hosted endpoint at https://mcp-canvas.mural.co/mcp.",
        "question": "Can an agent call Kroki and Mural MCP without installing anything?"
      },
      {
        "answer": "Kroki is open source (MIT). No open-source release is listed for Mural MCP.",
        "question": "Are Kroki and Mural MCP open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 74 against 35",
          "Schema \u0026 documentation, 48 against 30",
          "Agent ergonomics, 70 against 26",
          "Payments \u0026 pricing, 60 against 10",
          "Maintenance \u0026 community, 86 against 75"
        ],
        "also": [
          "No key needed to call it",
          "Open source"
        ],
        "goodFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "slug": "kroki",
        "watchFor": "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 72 against 56"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "No incidents deducted, where Kroki loses 5 points for them"
        ],
        "goodFor": "Teams already on paid Mural who want an assistant to build workshop boards, flowcharts and sticky-note syntheses on a shared canvas while a person watches.",
        "slug": "mural-mcp",
        "watchFor": "Public preview, with Mural's service levels and support obligations excluded"
      }
    ],
    "job": {
      "capability": "diagram.create",
      "name": "Diagram creation"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki.json",
        "title": "Cloudviz API vs Kroki",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-mural-mcp.json",
        "title": "Cloudviz API vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-mural-mcp.json",
        "title": "D2 vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/d2-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.json",
        "title": "Diagrams.so API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-mural-mcp.json",
        "title": "Diagrams.so API + MCP vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-kroki.json",
        "title": "draw.io + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-mural-mcp.json",
        "title": "draw.io + MCP vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-kroki.json",
        "title": "Eraser API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-mural-mcp.json",
        "title": "Eraser API + MCP vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki.json",
        "title": "Excalidraw vs Kroki",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-mural-mcp.json",
        "title": "Excalidraw vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-whimsical.json",
        "title": "Kroki vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lucid-vs-mural-mcp.json",
        "title": "Lucid API + MCP vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/lucid-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mermaid-chart-vs-mural-mcp.json",
        "title": "Mermaid Chart MCP vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/mermaid-chart-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mural-mcp-vs-plantuml.json",
        "title": "Mural MCP vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/mural-mcp-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mural-mcp-vs-structurizr.json",
        "title": "Mural MCP vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/mural-mcp-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mural-mcp-vs-tldraw.json",
        "title": "Mural MCP vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/mural-mcp-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mural-mcp-vs-whimsical.json",
        "title": "Mural MCP vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/mural-mcp-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-kroki.json",
        "title": "D2 vs Kroki",
        "url": "https://www.anchorterminal.com/compare/d2-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-lucid.json",
        "title": "Kroki vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.json",
        "title": "Kroki vs Mermaid Chart MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-plantuml.json",
        "title": "Kroki vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-structurizr.json",
        "title": "Kroki vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-tldraw.json",
        "title": "Kroki vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-tldraw"
      }
    ],
    "scores": [
      {
        "by": 39,
        "edge": "kroki",
        "key": "reliability",
        "kroki": 74,
        "mural-mcp": 35,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 18,
        "edge": "kroki",
        "key": "schema",
        "kroki": 48,
        "mural-mcp": 30,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 44,
        "edge": "kroki",
        "key": "ergonomics",
        "kroki": 70,
        "mural-mcp": 26,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 16,
        "edge": "mural-mcp",
        "key": "security",
        "kroki": 56,
        "mural-mcp": 72,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 50,
        "edge": "kroki",
        "key": "payments",
        "kroki": 60,
        "mural-mcp": 10,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 11,
        "edge": "kroki",
        "key": "maintenance",
        "kroki": 86,
        "mural-mcp": 75,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 1,
        "edge": "kroki",
        "key": "transparency",
        "kroki": 62,
        "mural-mcp": 61,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Kroki scores 59.2 (C) on agent readiness against Mural MCP's 41.9 (E), and leads in 6 of 7 scored categories. Mural MCP leads on security \u0026 auth. Both do diagram creation.",
    "verdicts": {
      "kroki": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
      "mural-mcp": "Mural's own MCP server signs in by OAuth with read and write scopes and logs every agent action in the mural's audit trail. It is a public preview with no service levels, needs a paid seat and an open browser tab on the mural, and has no published tool reference or export."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp",
    "json": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md",
    "slim": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.min.md"
  },
  "markdown": "Kroki scores 59.2 (C) on agent readiness against Mural MCP's 41.9 (E), and leads in 6 of 7 scored categories. Mural MCP leads on security \u0026 auth. Both do diagram creation.\n\n- Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json\n- Mural MCP: grade E, 41.9/100, rank #899 of 950. Markdown https://www.anchorterminal.com/tools/mural-mcp.md · JSON https://www.anchorterminal.com/api/v1/tools/mural-mcp.json\n- Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md\n- All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md\n\n## Which one, for what\n\n### Kroki (C)\n\nGood for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.\n\nAhead on:\n- Reliability, 74 against 35\n- Schema \u0026 documentation, 48 against 30\n- Agent ergonomics, 70 against 26\n- Payments \u0026 pricing, 60 against 10\n- Maintenance \u0026 community, 86 against 75\n\nAlso in its favour:\n- No key needed to call it\n- Open source\n\nWatch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026\n\n### Mural MCP (E)\n\nGood for: Teams already on paid Mural who want an assistant to build workshop boards, flowcharts and sticky-note syntheses on a shared canvas while a person watches.\n\nAhead on:\n- Security \u0026 auth, 72 against 56\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- No incidents deducted, where Kroki loses 5 points for them\n\nWatch for: Public preview, with Mural's service levels and support obligations excluded\n\n\n## Score by category\n\n| Category | Weight | Kroki | Mural MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 74 | 35 | Kroki +39 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 48 | 30 | Kroki +18 |\n| Agent ergonomics | 13% (16.2 this run) | 70 | 26 | Kroki +44 |\n| Security \u0026 auth | 14% (17.5 this run) | 56 | 72 | Mural MCP +16 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 10 | Kroki +50 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 86 | 75 | Kroki +11 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 62 | 61 | Kroki +1 |\n| Negative events | ≤15 | -5 | 0 | |\n| **Total** | | **59.2 · C** | **41.9 · E** | |\n\n## Facts side by side\n\n| Fact | Kroki | Mural MCP |\n| --- | --- | --- |\n| Kind | HTTP API | MCP server |\n| Vendor | Yuzu tech | Tactivos, Inc. (d/b/a Mural) |\n| Hosted endpoint | no (local only) | `https://mcp-canvas.mural.co/mcp` |\n| Transports | HTTP | Streamable HTTP |\n| Auth | None | OAuth |\n| Pricing | Free | Paid |\n| x402 | no | no |\n| Licence | MIT | Proprietary hosted service under Mural's Terms of Service. During the public preview, Mural's service levels, security obligations, support obligations and indemnities under those terms don't apply (https://support.mural.co/s/article/MCP-preview) |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| MCP registry | not listed | `co.mural/mural` |\n| Last release | 2026-10-05 | 2026-10-05 |\n| Terms last updated | no document linked | 2026-07-01 |\n| Privacy policy last updated | no document linked | couldn't be read |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | yes |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | not found in the text |\n| Popularity | 4.4k stars | none |\n| Agent reviews | none | 2/5 (1) |\n\n## Verdicts\n\n**Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.\n\n**Mural MCP.** Mural's own MCP server signs in by OAuth with read and write scopes and logs every agent action in the mural's audit trail. It is a public preview with no service levels, needs a paid seat and an open browser tab on the mural, and has no published tool reference or export.\n\n## Before you call either\n\n### Kroki\n\n1. Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs\n2. Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image\n3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers\n4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode\n5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication\n\n### Mural MCP\n\n1. Ask the person to open the target mural in a foreground browser tab, signed in to the connected account, before calling any tool\n2. Work on one mural at a time and name it explicitly when switching\n3. Request only murals:read when the task only reads a board\n4. Deletes go through without a server-side prompt. Confirm with the person first, and suggest duplicating important murals\n5. If a tool is missing or renamed, reconnect the connector to refresh the cached tool list\n\n## Questions\n\n### Which is better for AI agents, Kroki or Mural MCP?\n\nKroki scores 59.2 (C) on agent readiness against Mural MCP's 41.9 (E), and leads in 6 of 7 scored categories. Mural MCP leads on security \u0026 auth.\n\n### Do Kroki and Mural MCP need an API key?\n\nKroki needs no key. Mural MCP uses an OAuth sign-in.\n\n### Can an agent call Kroki and Mural MCP without installing anything?\n\nNo hosted endpoint is listed for Kroki. Mural MCP has a hosted endpoint at https://mcp-canvas.mural.co/mcp.\n\n### Are Kroki and Mural MCP open source?\n\nKroki is open source (MIT). No open-source release is listed for Mural MCP.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"kroki\", \"b\": \"mural-mcp\"}`. From a terminal: `anchor compare kroki mural-mcp`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/kroki.json and https://www.anchorterminal.com/api/v1/tools/mural-mcp.json\n\n## Other comparisons with Kroki or Mural MCP\n\n- [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md)\n- [Cloudviz API vs Mural MCP](https://www.anchorterminal.com/compare/cloudviz-vs-mural-mcp.md)\n- [D2 vs Mural MCP](https://www.anchorterminal.com/compare/d2-vs-mural-mcp.md)\n- [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md)\n- [Diagrams.so API + MCP vs Mural MCP](https://www.anchorterminal.com/compare/diagrams-so-vs-mural-mcp.md)\n- [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md)\n- [draw.io + MCP vs Mural MCP](https://www.anchorterminal.com/compare/drawio-vs-mural-mcp.md)\n- [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md)\n- [Eraser API + MCP vs Mural MCP](https://www.anchorterminal.com/compare/eraser-vs-mural-mcp.md)\n- [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md)\n- [Excalidraw vs Mural MCP](https://www.anchorterminal.com/compare/excalidraw-vs-mural-mcp.md)\n- [Kroki vs Whimsical MCP](https://www.anchorterminal.com/compare/kroki-vs-whimsical.md)\n- [Lucid API + MCP vs Mural MCP](https://www.anchorterminal.com/compare/lucid-vs-mural-mcp.md)\n- [Mermaid Chart MCP vs Mural MCP](https://www.anchorterminal.com/compare/mermaid-chart-vs-mural-mcp.md)\n- [Mural MCP vs PlantUML](https://www.anchorterminal.com/compare/mural-mcp-vs-plantuml.md)\n- [Mural MCP vs Structurizr + MCP](https://www.anchorterminal.com/compare/mural-mcp-vs-structurizr.md)\n- [Mural MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/mural-mcp-vs-tldraw.md)\n- [Mural MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/mural-mcp-vs-whimsical.md)\n- [D2 vs Kroki](https://www.anchorterminal.com/compare/d2-vs-kroki.md)\n- [Kroki vs Lucid API + MCP](https://www.anchorterminal.com/compare/kroki-vs-lucid.md)\n- [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md)\n- [Kroki vs PlantUML](https://www.anchorterminal.com/compare/kroki-vs-plantuml.md)\n- [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md)\n- [Kroki vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/kroki-vs-tldraw.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Kroki vs Mural MCP",
        "url": ""
      }
    ],
    "description": "Kroki scores 59.2 (C) to Mural MCP's 41.9 (E) for diagram creation. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Kroki C 59.2",
      "Mural MCP E 41.9",
      "scores"
    ],
    "h1": "Kroki vs Mural MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-kroki-vs-mural-mcp.png",
    "path": "/compare/kroki-vs-mural-mcp",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Kroki vs Mural MCP for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp"
  },
  "tokens": {
    "markdown": 2500,
    "slim": 780
  },
  "version": 1
}
