Head to head · Diagrams as code · October 2026 research run

Kroki vs PlantUML

PlantUML scores 66.9 (B) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security & auth and maintenance & community. Both do diagrams as code.

Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons

Which one, for what

Kroki C

Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.

Ahead on

  • Security & auth, 56 against 50
  • Maintenance & community, 86 against 73

Watch for

GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026

PlantUML B

Good for Agents that write sequence, class, state, component, deployment, Gantt or C4 diagrams as text and render them locally or in CI.

Ahead on

  • Reliability, 83 against 74
  • Schema & documentation, 65 against 48
  • Agent ergonomics, 78 against 70
  • Transparency & trust, 73 against 62

Watch for

The default security profile is LEGACY, which gives diagram text full access to local files and URLs through !include. The docs say it will be removed, with no date

Score by category

CategoryWeight this runKrokiPlantUMLEdge
Reliability16%207483PlantUML +9
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.24865PlantUML +17
Agent ergonomics13%16.27078PlantUML +8
Security & auth14%17.55650Kroki +6
Payments & pricing10%12.56060even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88673Kroki +13
Transparency & trust7%8.86273PlantUML +11
Negative events≤15-5-2
Total59.2 · C66.9 · B

Facts side by side

FactKrokiPlantUML
KindHTTP APISDK + MCP
VendorYuzu techPlantUML project (Arnaud Roques)
Hosted endpointno (local only)no (local only)
TransportsHTTP
AuthNoneNone
PricingFreeFree
x402nono
LicenceMITGPL-3.0-or-later
Read-only variant documentednono
llms.txtnono
Last release2026-10-052026-09-05
Terms last updatedno document linkedno document linked
Privacy policy last updatedno document linkedno document linked
Customer content may train models
Terms restrict automated access
Terms restrict benchmarking
Terms or service can change without notice
Arbitration or class-action waiver
Popularity4.4k stars13k stars, 207 npm/wk

Verdicts

Kroki

One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.

PlantUML

One Java command reads diagram text from stdin and writes PNG, SVG, PDF or ASCII with no account, and CI passed on the last eight pushes. The default security profile lets diagram text read any local file and fetch any URL, and the documentation still lists chronology diagrams that release 1.2026.2 switched off.

Before you call either

Kroki

  1. Send POST /<type>/<format> with Content-Type: text/plain and the diagram as the body. This avoids the deflate and base64 encoding that GET needs
  2. Send Accept: application/json on a JSON request to get errors as {"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image
  3. Call GET /health first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers
  4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through /tikz/svg and file reads in SECURE mode
  5. Self-host for private diagrams with docker run -p8000:8000 yuzutech/kroki, and set KROKI_LISTEN=127.0.0.1:8000 or a network rule, since the server has no authentication

PlantUML

  1. Set PLANTUML_SECURITY_PROFILE to SANDBOX or ALLOWLIST before rendering text from an untrusted source. The default profile lets !include read local files and fetch URLs
  2. Run java -jar plantuml.jar --check-syntax with -stdrpt first and read the exit status. Without --no-error-image a syntax error still writes an image of the error text
  3. Pass -pipe with --svg, --txt or --utxt to work without files. --txt output suits a text-only model
  4. Start the local server as -picoweb:8080:127.0.0.1. Without the bind address it listens on every interface
  5. Use npx -y @plantuml/mcp-js when no Java runtime is present. It renders SVG only, so use the jar for PNG or PDF

Questions

Which is better for AI agents, Kroki or PlantUML?

PlantUML scores 66.9 (B) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security & auth and maintenance & community.

Can an agent call Kroki and PlantUML without installing anything?

No hosted endpoint is listed for Kroki. No hosted endpoint is listed for PlantUML.

Are Kroki and PlantUML open source?

Yes. Kroki is open source (MIT). PlantUML is open source (GPL-3.0-or-later).

Other comparisons with Kroki or PlantUML

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.