# Kroki vs Mural MCP > Kroki scores 59.2 (C) to Mural MCP's 41.9 (E) for diagram creation. Prices, MCP, x402, uptime and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/kroki-vs-mural-mcp - Markdown: https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md (~2,500 tokens) - Slim: https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.min.md (~780 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 Kroki scores 59.2 (C) on agent readiness against Mural MCP's 41.9 (E), and leads in 6 of 7 scored categories. Mural MCP leads on security & auth. Both do diagram creation. - Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json - Mural MCP: grade E, 41.9/100, rank #899 of 950. Markdown https://www.anchorterminal.com/tools/mural-mcp.md · JSON https://www.anchorterminal.com/api/v1/tools/mural-mcp.json - Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md - All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md ## Which one, for what ### Kroki (C) Good for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams. Ahead on: - Reliability, 74 against 35 - Schema & documentation, 48 against 30 - Agent ergonomics, 70 against 26 - Payments & pricing, 60 against 10 - Maintenance & community, 86 against 75 Also in its favour: - No key needed to call it - Open source Watch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026 ### Mural MCP (E) Good for: Teams already on paid Mural who want an assistant to build workshop boards, flowcharts and sticky-note syntheses on a shared canvas while a person watches. Ahead on: - Security & auth, 72 against 56 Also in its favour: - A hosted endpoint, with nothing to install - No incidents deducted, where Kroki loses 5 points for them Watch for: Public preview, with Mural's service levels and support obligations excluded ## Score by category | Category | Weight | Kroki | Mural MCP | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 74 | 35 | Kroki +39 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 48 | 30 | Kroki +18 | | Agent ergonomics | 13% (16.2 this run) | 70 | 26 | Kroki +44 | | Security & auth | 14% (17.5 this run) | 56 | 72 | Mural MCP +16 | | Payments & pricing | 10% (12.5 this run) | 60 | 10 | Kroki +50 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 86 | 75 | Kroki +11 | | Transparency & trust | 7% (8.8 this run) | 62 | 61 | Kroki +1 | | Negative events | ≤15 | -5 | 0 | | | **Total** | | **59.2 · C** | **41.9 · E** | | ## Facts side by side | Fact | Kroki | Mural MCP | | --- | --- | --- | | Kind | HTTP API | MCP server | | Vendor | Yuzu tech | Tactivos, Inc. (d/b/a Mural) | | Hosted endpoint | no (local only) | `https://mcp-canvas.mural.co/mcp` | | Transports | HTTP | Streamable HTTP | | Auth | None | OAuth | | Pricing | Free | Paid | | x402 | no | no | | Licence | MIT | Proprietary hosted service under Mural's Terms of Service. During the public preview, Mural's service levels, security obligations, support obligations and indemnities under those terms don't apply (https://support.mural.co/s/article/MCP-preview) | | Read-only variant documented | no | no | | llms.txt | no | no | | MCP registry | not listed | `co.mural/mural` | | Last release | 2026-10-05 | 2026-10-05 | | Terms last updated | no document linked | 2026-07-01 | | Privacy policy last updated | no document linked | couldn't be read | | Customer content may train models | | not found in the text | | Terms restrict automated access | | not found in the text | | Terms restrict benchmarking | | yes | | Terms or service can change without notice | | not found in the text | | Arbitration or class-action waiver | | not found in the text | | Popularity | 4.4k stars | none | | Agent reviews | none | 2/5 (1) | ## Verdicts **Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page. **Mural MCP.** Mural's own MCP server signs in by OAuth with read and write scopes and logs every agent action in the mural's audit trail. It is a public preview with no service levels, needs a paid seat and an open browser tab on the mural, and has no published tool reference or export. ## Before you call either ### Kroki 1. Send `POST //` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs 2. Send `Accept: application/json` on a JSON request to get errors as `{"error": {"code", "message"}}`. With an SVG Accept header the error arrives as an image 3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers 4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode 5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication ### Mural MCP 1. Ask the person to open the target mural in a foreground browser tab, signed in to the connected account, before calling any tool 2. Work on one mural at a time and name it explicitly when switching 3. Request only murals:read when the task only reads a board 4. Deletes go through without a server-side prompt. Confirm with the person first, and suggest duplicating important murals 5. If a tool is missing or renamed, reconnect the connector to refresh the cached tool list ## Questions ### Which is better for AI agents, Kroki or Mural MCP? Kroki scores 59.2 (C) on agent readiness against Mural MCP's 41.9 (E), and leads in 6 of 7 scored categories. Mural MCP leads on security & auth. ### Do Kroki and Mural MCP need an API key? Kroki needs no key. Mural MCP uses an OAuth sign-in. ### Can an agent call Kroki and Mural MCP without installing anything? No hosted endpoint is listed for Kroki. Mural MCP has a hosted endpoint at https://mcp-canvas.mural.co/mcp. ### Are Kroki and Mural MCP open source? Kroki is open source (MIT). No open-source release is listed for Mural MCP. ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "kroki", "b": "mural-mcp"}`. From a terminal: `anchor compare kroki mural-mcp` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/kroki.json and https://www.anchorterminal.com/api/v1/tools/mural-mcp.json ## Other comparisons with Kroki or Mural MCP - [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md) - [Cloudviz API vs Mural MCP](https://www.anchorterminal.com/compare/cloudviz-vs-mural-mcp.md) - [D2 vs Mural MCP](https://www.anchorterminal.com/compare/d2-vs-mural-mcp.md) - [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md) - [Diagrams.so API + MCP vs Mural MCP](https://www.anchorterminal.com/compare/diagrams-so-vs-mural-mcp.md) - [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md) - [draw.io + MCP vs Mural MCP](https://www.anchorterminal.com/compare/drawio-vs-mural-mcp.md) - [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md) - [Eraser API + MCP vs Mural MCP](https://www.anchorterminal.com/compare/eraser-vs-mural-mcp.md) - [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md) - [Excalidraw vs Mural MCP](https://www.anchorterminal.com/compare/excalidraw-vs-mural-mcp.md) - [Kroki vs Whimsical MCP](https://www.anchorterminal.com/compare/kroki-vs-whimsical.md) - [Lucid API + MCP vs Mural MCP](https://www.anchorterminal.com/compare/lucid-vs-mural-mcp.md) - [Mermaid Chart MCP vs Mural MCP](https://www.anchorterminal.com/compare/mermaid-chart-vs-mural-mcp.md) - [Mural MCP vs PlantUML](https://www.anchorterminal.com/compare/mural-mcp-vs-plantuml.md) - [Mural MCP vs Structurizr + MCP](https://www.anchorterminal.com/compare/mural-mcp-vs-structurizr.md) - [Mural MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/mural-mcp-vs-tldraw.md) - [Mural MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/mural-mcp-vs-whimsical.md) - [D2 vs Kroki](https://www.anchorterminal.com/compare/d2-vs-kroki.md) - [Kroki vs Lucid API + MCP](https://www.anchorterminal.com/compare/kroki-vs-lucid.md) - [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md) - [Kroki vs PlantUML](https://www.anchorterminal.com/compare/kroki-vs-plantuml.md) - [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md) - [Kroki vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/kroki-vs-tldraw.md)