{
  "data": {
    "a": {
      "slug": "kroki",
      "name": "Kroki",
      "vendor": "Yuzu tech",
      "vendorUrl": "https://kroki.io",
      "kind": "http-api",
      "category": "diagramming",
      "summary": "Kroki is an open-source HTTP server from Yuzu tech that converts diagram text in 29 formats, including PlantUML, Mermaid, GraphViz and D2, into SVG, PNG or PDF. Owners run it from Docker images, and kroki.io is a free public instance.",
      "url": "https://www.anchorterminal.com/tools/kroki",
      "markdownUrl": "https://www.anchorterminal.com/tools/kroki.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kroki.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kroki.json",
      "repo": "https://github.com/yuzutech/kroki",
      "license": "MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "yuzutech/kroki"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-mermaid"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-bpmn"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-excalidraw"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or login on the convert endpoints, on a self-hosted server or on the public instance at kroki.io. The server binds all interfaces on port 8000 unless `KROKI_LISTEN` says otherwise. An optional bearer token, `KROKI_COMPANION_REGISTRATION_TOKEN`, protects only the `/services` registration API, which is off by default.",
      "pricing": "free",
      "pricingNotes": "Free under the MIT licence, with nothing to buy. The public instance at kroki.io is free and paid for by sponsors, for reasonable, non-commercial use with no uptime guarantee. Third parties sell hosting, which the project says it does not operate.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4365,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.kroki.io/kroki/setup/usage/",
      "capabilities": [
        "diagram.as-code",
        "diagram.create",
        "diagram.export",
        "diagram.architecture"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "http-api",
        "docker",
        "diagram-as-code",
        "plantuml",
        "mermaid",
        "graphviz",
        "no-auth",
        "free"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.2,
        "grade": "C",
        "agentReady": false,
        "rank": 558,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -5,
        "negativeNotes": [
          "27 July to 12 August 2026. Four advisories on the repository. GHSA-wmpp-fj9c-w766 (critical, CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in 0.21.0 up to 0.32.0 whatever the safe mode. GHSA-r54f-fq6c-53vw (high, CVE-2026-102359), GHSA-px99-rjv4-49g8 (medium, CVE-2026-102356) and GHSA-9p7m-vrmg-qp4q (high) let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed, in 0.32.1 at the latest, and the maintainers published each with a changelog entry, so the deduction is five points (https://github.com/yuzutech/kroki/security/advisories)."
        ],
        "verdict": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
        "bestFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "strengths": [
          "`POST /` with `diagram_source`, `diagram_type` and `output_format`, or plain text to `/\u003ctype\u003e/\u003cformat\u003e`, returns the image. No account or key",
          "One API covers 29 diagram types, among them PlantUML, C4, Structurizr, Mermaid, GraphViz, D2, DBML, BPMN, Excalidraw and Vega",
          "`KROKI_SAFE_MODE` defaults to `SECURE`, which blocks file and network reads by diagram libraries, and the container runs as the non-root user `kroki`",
          "Five versions shipped between 15 July and 5 October 2026, and the `main.yaml` workflow passed on the last ten pushes to `main`",
          "MIT licence. The maintainers published four security advisories in 2026, each with a fixed version and a changelog entry"
        ],
        "weaknesses": [
          "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026",
          "Three more advisories in July and August 2026 let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed in 0.32.1",
          "No OpenAPI file, llms.txt or error catalogue. The JSON error shape is in the source and not in the documentation",
          "The public instance at kroki.io has no terms, privacy policy, status page or published rate limit. The CLI page limits the demonstration server to reasonable, non-commercial use",
          "The server has no authentication on its convert endpoints and binds all interfaces on port 8000 by default. The version is 0.33.0, with no 1.0"
        ],
        "agentNotes": [
          "Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs",
          "Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image",
          "Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers",
          "Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode",
          "Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.2
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 67
        },
        "provenanceScore": 56
      },
      "connect": {
        "install": "docker run -p8000:8000 yuzutech/kroki",
        "http": "curl https://kroki.io/graphviz/svg --data-raw 'digraph G {Hello-\u003eWorld}'"
      },
      "letme": {
        "capability": "https://letme.dev/diagram.as-code",
        "tool": "https://letme.dev/kroki"
      },
      "area": "design-diagrams",
      "provenance": {
        "legalEntity": "Yuzu tech, a French software firm. No registered legal form found",
        "domain": "kroki.io",
        "domainRegistered": "2019-01-06",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/yuzutech/kroki/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The kroki.io home page says Kroki is built and maintained by Yuzu tech, and links https://yuzutech.fr, whose pages name no legal form or registration number. `LICENSE` reads Copyright (c) 2020-present Kroki",
          "No terms or privacy document was found on kroki.io or docs.kroki.io, for the software or for the public instance. The MIT licence stands in for the software",
          "https://kroki.io/.well-known/security.txt answered 404 on 9 October 2026. `SECURITY.md` asks for reports through a private GitHub security advisory",
          "The lead wrote the vendor as Yuzutech. The site writes Yuzu tech, and the GitHub organisation is `yuzutech`",
          "The endpoint on the vendor's domain is the free public instance. The listing grades the server an owner runs"
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kroki.json",
      "live": {
        "slug": "kroki",
        "versions": [
          {
            "registry": "github",
            "name": "yuzutech/kroki",
            "version": "v0.33.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-09T17:00:57.82489933Z"
          }
        ],
        "githubStars": 4365,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/yuzutech/kroki/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:46:31.151891385Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3e34fa594488"
          }
        ],
        "updatedAt": "2026-10-09T18:46:31.151891385Z"
      }
    },
    "answer": "PlantUML scores 66.9 (B) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security \u0026 auth and maintenance \u0026 community.",
    "b": {
      "slug": "plantuml",
      "name": "PlantUML",
      "vendor": "PlantUML project (Arnaud Roques)",
      "vendorUrl": "https://plantuml.com",
      "kind": "sdk",
      "category": "diagramming",
      "summary": "PlantUML is open-source software that turns text descriptions into UML, architecture, Gantt, mind map and other diagrams. Agents run it as a Java command-line tool, a Java library, a local HTTP server or the `@plantuml/mcp-js` MCP server.",
      "url": "https://www.anchorterminal.com/tools/plantuml",
      "markdownUrl": "https://www.anchorterminal.com/tools/plantuml.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/plantuml.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/plantuml.json",
      "repo": "https://github.com/plantuml/plantuml",
      "license": "GPL-3.0-or-later",
      "transports": [],
      "packages": [
        {
          "registry": "maven",
          "name": "net.sourceforge.plantuml:plantuml"
        },
        {
          "registry": "npm",
          "name": "@plantuml/mcp-js"
        },
        {
          "registry": "oci",
          "name": "plantuml/plantuml"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or login. The jar, the Java library and the MCP server run on the owner's machine with the owner's file and network rights. The built-in `-picoweb` HTTP server has no authentication and listens on all interfaces unless a bind address is given.",
      "pricing": "free",
      "pricingNotes": "Free under GPL-3.0-or-later, with the same source also under GPL-2.0, LGPL, Apache-2.0, BSD-3-Clause, EPL and MIT. Nothing to buy. The project takes donations through GitHub Sponsors and Patreon.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 13356,
        "npmWeekly": 207,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://plantuml.com/command-line",
      "capabilities": [
        "diagram.as-code",
        "diagram.create",
        "diagram.export",
        "diagram.architecture"
      ],
      "tags": [
        "open-source",
        "local",
        "cli",
        "java",
        "mcp",
        "diagram-as-code",
        "uml",
        "no-auth",
        "free",
        "docker"
      ],
      "lastRelease": "2026-09-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 66.9,
        "grade": "B",
        "agentReady": false,
        "rank": 270,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 73,
          "payments": 60,
          "reliability": 83,
          "schema": 65,
          "security": 50,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -2,
        "negativeNotes": [
          "27 February 2026. Release 1.2026.2 switched off chronology diagrams, and its change log calls the removal temporary. On 8 October 2026 the factory is still commented out in `PSystemBuilder.java`, while the README lists the chronology diagram as supported and https://plantuml.com/chronology-diagram documents it. Two points, because the removal is in the change log (https://github.com/plantuml/plantuml/blob/master/CHANGES.md)."
        ],
        "verdict": "One Java command reads diagram text from stdin and writes PNG, SVG, PDF or ASCII with no account, and CI passed on the last eight pushes. The default security profile lets diagram text read any local file and fetch any URL, and the documentation still lists chronology diagrams that release 1.2026.2 switched off.",
        "bestFor": "Agents that write sequence, class, state, component, deployment, Gantt or C4 diagrams as text and render them locally or in CI.",
        "strengths": [
          "`java -jar plantuml.jar -pipe` reads a diagram from stdin and writes PNG, SVG, PDF, EPS, LaTeX or ASCII to stdout, with no account or key",
          "`--check-syntax` and `-stdrpt` report errors as `file:line:error` lines, and exit codes 0, 50, 100 and 200 are documented",
          "The official `@plantuml/mcp-js` server has four tools, needs only Node.js, and returns the same SVG bytes for the same source on any machine",
          "Version 1.2026.8 of 5 September 2026 is on GitHub, Maven Central, Homebrew and Docker Hub, and the `ci` workflow passed on the last eight pushes",
          "The same source is available under GPL-3.0-or-later, GPL-2.0, LGPL, Apache-2.0, BSD-3-Clause, EPL and MIT, and generated images carry no licence obligation"
        ],
        "weaknesses": [
          "The default security profile is LEGACY, which gives diagram text full access to local files and URLs through `!include`. The docs say it will be removed, with no date",
          "`-picoweb` listens on all network interfaces by default and has no authentication",
          "Chronology diagrams were switched off in 1.2026.2 on 27 February 2026 and are still listed in the README and documented on plantuml.com",
          "The command-line page gives the HTTP server's default port as 4242 in one help listing and 8080 in another. The source uses 8080",
          "No llms.txt, no security.txt and no published advisories. The security policy is one email address, and 575 issues are open"
        ],
        "agentNotes": [
          "Set `PLANTUML_SECURITY_PROFILE` to `SANDBOX` or `ALLOWLIST` before rendering text from an untrusted source. The default profile lets `!include` read local files and fetch URLs",
          "Run `java -jar plantuml.jar --check-syntax` with `-stdrpt` first and read the exit status. Without `--no-error-image` a syntax error still writes an image of the error text",
          "Pass `-pipe` with `--svg`, `--txt` or `--utxt` to work without files. `--txt` output suits a text-only model",
          "Start the local server as `-picoweb:8080:127.0.0.1`. Without the bind address it listens on every interface",
          "Use `npx -y @plantuml/mcp-js` when no Java runtime is present. It renders SVG only, so use the jar for PNG or PDF"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 66.9
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 73,
          "payments": 60,
          "reliability": 83,
          "schema": 65,
          "security": 50,
          "transparency": 73
        },
        "provenanceScore": 73
      },
      "connect": {
        "install": "brew install plantuml   # or download plantuml.jar from https://github.com/plantuml/plantuml/releases, or docker run ghcr.io/plantuml/plantuml",
        "config": {
          "mcpServers": {
            "plantuml-js": {
              "args": [
                "-y",
                "@plantuml/mcp-js"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/diagram.as-code",
        "tool": "https://letme.dev/plantuml"
      },
      "area": "design-diagrams",
      "provenance": {
        "legalEntity": "No legal entity found. Copyright Arnaud Roques",
        "domain": "plantuml.com",
        "domainRegistered": "2010-11-28",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/plantuml/plantuml/blob/master/CHANGES.md",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "`LICENSES.md` reads Copyright (C) 2009-2026, Arnaud Roques. No company or foundation is named in the repository or on the pages read",
          "No terms or privacy document governs the software. The GPL-3.0-or-later licence, or one of the six alternatives, stands in",
          "https://plantuml.com/.well-known/security.txt answered 404 on 8 October 2026. `docs/SECURITY.md` asks for reports by email to a Gmail address",
          "The lead named PlantUML as vendor. It is a community project led by one author, with no company behind it that we found"
        ],
        "score": 73
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/plantuml.json",
      "live": {
        "slug": "plantuml",
        "versions": [
          {
            "registry": "github",
            "name": "plantuml/plantuml",
            "version": "v1.2026.8",
            "released": "2026-09-05",
            "seenAt": "2026-10-09T17:13:38.093637775Z"
          },
          {
            "registry": "npm",
            "name": "@plantuml/mcp-js",
            "version": "0.2.2",
            "seenAt": "2026-10-09T17:13:37.231958705Z"
          }
        ],
        "githubStars": 13357,
        "npmWeekly": 211,
        "securityTxt": {
          "url": "https://plantuml.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:39:50.311845942Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/plantuml/plantuml/master/CHANGES.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:45:55.134028932Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b79647d80ba7"
          }
        ],
        "updatedAt": "2026-10-09T18:45:55.134028932Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "SDK + MCP",
        "name": "Kind"
      },
      {
        "a": "Yuzu tech",
        "b": "PlantUML project (Arnaud Roques)",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "GPL-3.0-or-later",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-05",
        "b": "2026-09-05",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "4.4k stars",
        "b": "13k stars, 207 npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "PlantUML scores 66.9 (B) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security \u0026 auth and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Kroki or PlantUML?"
      },
      {
        "answer": "No hosted endpoint is listed for Kroki. No hosted endpoint is listed for PlantUML.",
        "question": "Can an agent call Kroki and PlantUML without installing anything?"
      },
      {
        "answer": "Yes. Kroki is open source (MIT). PlantUML is open source (GPL-3.0-or-later).",
        "question": "Are Kroki and PlantUML open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Security \u0026 auth, 56 against 50",
          "Maintenance \u0026 community, 86 against 73"
        ],
        "also": null,
        "goodFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "slug": "kroki",
        "watchFor": "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026"
      },
      {
        "aheadOn": [
          "Reliability, 83 against 74",
          "Schema \u0026 documentation, 65 against 48",
          "Agent ergonomics, 78 against 70",
          "Transparency \u0026 trust, 73 against 62"
        ],
        "also": null,
        "goodFor": "Agents that write sequence, class, state, component, deployment, Gantt or C4 diagrams as text and render them locally or in CI.",
        "slug": "plantuml",
        "watchFor": "The default security profile is LEGACY, which gives diagram text full access to local files and URLs through `!include`. The docs say it will be removed, with no date"
      }
    ],
    "job": {
      "capability": "diagram.as-code",
      "name": "Diagrams as code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki.json",
        "title": "Cloudviz API vs Kroki",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-plantuml.json",
        "title": "Cloudviz API vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.json",
        "title": "Diagrams.so API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-plantuml.json",
        "title": "Diagrams.so API + MCP vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-kroki.json",
        "title": "draw.io + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-plantuml.json",
        "title": "draw.io + MCP vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-kroki.json",
        "title": "Eraser API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-plantuml.json",
        "title": "Eraser API + MCP vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki.json",
        "title": "Excalidraw vs Kroki",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-plantuml.json",
        "title": "Excalidraw vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.json",
        "title": "Kroki vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-whimsical.json",
        "title": "Kroki vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lucid-vs-plantuml.json",
        "title": "Lucid API + MCP vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/lucid-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mermaid-chart-vs-plantuml.json",
        "title": "Mermaid Chart MCP vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/mermaid-chart-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mural-mcp-vs-plantuml.json",
        "title": "Mural MCP vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/mural-mcp-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/plantuml-vs-whimsical.json",
        "title": "PlantUML vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/plantuml-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-kroki.json",
        "title": "D2 vs Kroki",
        "url": "https://www.anchorterminal.com/compare/d2-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-plantuml.json",
        "title": "D2 vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/d2-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-lucid.json",
        "title": "Kroki vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.json",
        "title": "Kroki vs Mermaid Chart MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-structurizr.json",
        "title": "Kroki vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-tldraw.json",
        "title": "Kroki vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/plantuml-vs-structurizr.json",
        "title": "PlantUML vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/plantuml-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/plantuml-vs-tldraw.json",
        "title": "PlantUML vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/plantuml-vs-tldraw"
      }
    ],
    "scores": [
      {
        "by": 9,
        "edge": "plantuml",
        "key": "reliability",
        "kroki": 74,
        "name": "Reliability",
        "plantuml": 83,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 17,
        "edge": "plantuml",
        "key": "schema",
        "kroki": 48,
        "name": "Schema \u0026 documentation",
        "plantuml": 65,
        "weight": 13
      },
      {
        "by": 8,
        "edge": "plantuml",
        "key": "ergonomics",
        "kroki": 70,
        "name": "Agent ergonomics",
        "plantuml": 78,
        "weight": 13
      },
      {
        "by": 6,
        "edge": "kroki",
        "key": "security",
        "kroki": 56,
        "name": "Security \u0026 auth",
        "plantuml": 50,
        "weight": 14
      },
      {
        "by": 0,
        "edge": "",
        "key": "payments",
        "kroki": 60,
        "name": "Payments \u0026 pricing",
        "plantuml": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 13,
        "edge": "kroki",
        "key": "maintenance",
        "kroki": 86,
        "name": "Maintenance \u0026 community",
        "plantuml": 73,
        "weight": 7
      },
      {
        "by": 11,
        "edge": "plantuml",
        "key": "transparency",
        "kroki": 62,
        "name": "Transparency \u0026 trust",
        "plantuml": 73,
        "weight": 7
      }
    ],
    "summary": "PlantUML scores 66.9 (B) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security \u0026 auth and maintenance \u0026 community. Both do diagrams as code.",
    "verdicts": {
      "kroki": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
      "plantuml": "One Java command reads diagram text from stdin and writes PNG, SVG, PDF or ASCII with no account, and CI passed on the last eight pushes. The default security profile lets diagram text read any local file and fetch any URL, and the documentation still lists chronology diagrams that release 1.2026.2 switched off."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/kroki-vs-plantuml",
    "json": "https://www.anchorterminal.com/compare/kroki-vs-plantuml.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/kroki-vs-plantuml.md",
    "slim": "https://www.anchorterminal.com/compare/kroki-vs-plantuml.min.md"
  },
  "markdown": "PlantUML scores 66.9 (B) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security \u0026 auth and maintenance \u0026 community. Both do diagrams as code.\n\n- Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json\n- PlantUML: grade B, 66.9/100, rank #270 of 950. Markdown https://www.anchorterminal.com/tools/plantuml.md · JSON https://www.anchorterminal.com/api/v1/tools/plantuml.json\n- Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md\n- All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md\n\n## Which one, for what\n\n### Kroki (C)\n\nGood for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.\n\nAhead on:\n- Security \u0026 auth, 56 against 50\n- Maintenance \u0026 community, 86 against 73\n\nWatch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026\n\n### PlantUML (B)\n\nGood for: Agents that write sequence, class, state, component, deployment, Gantt or C4 diagrams as text and render them locally or in CI.\n\nAhead on:\n- Reliability, 83 against 74\n- Schema \u0026 documentation, 65 against 48\n- Agent ergonomics, 78 against 70\n- Transparency \u0026 trust, 73 against 62\n\nWatch for: The default security profile is LEGACY, which gives diagram text full access to local files and URLs through `!include`. The docs say it will be removed, with no date\n\n\n## Score by category\n\n| Category | Weight | Kroki | PlantUML | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 74 | 83 | PlantUML +9 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 48 | 65 | PlantUML +17 |\n| Agent ergonomics | 13% (16.2 this run) | 70 | 78 | PlantUML +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 56 | 50 | Kroki +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 60 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 86 | 73 | Kroki +13 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 62 | 73 | PlantUML +11 |\n| Negative events | ≤15 | -5 | -2 | |\n| **Total** | | **59.2 · C** | **66.9 · B** | |\n\n## Facts side by side\n\n| Fact | Kroki | PlantUML |\n| --- | --- | --- |\n| Kind | HTTP API | SDK + MCP |\n| Vendor | Yuzu tech | PlantUML project (Arnaud Roques) |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP |  |\n| Auth | None | None |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | MIT | GPL-3.0-or-later |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| Last release | 2026-10-05 | 2026-09-05 |\n| Terms last updated | no document linked | no document linked |\n| Privacy policy last updated | no document linked | no document linked |\n| Customer content may train models |  |  |\n| Terms restrict automated access |  |  |\n| Terms restrict benchmarking |  |  |\n| Terms or service can change without notice |  |  |\n| Arbitration or class-action waiver |  |  |\n| Popularity | 4.4k stars | 13k stars, 207 npm/wk |\n\n## Verdicts\n\n**Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.\n\n**PlantUML.** One Java command reads diagram text from stdin and writes PNG, SVG, PDF or ASCII with no account, and CI passed on the last eight pushes. The default security profile lets diagram text read any local file and fetch any URL, and the documentation still lists chronology diagrams that release 1.2026.2 switched off.\n\n## Before you call either\n\n### Kroki\n\n1. Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs\n2. Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image\n3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers\n4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode\n5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication\n\n### PlantUML\n\n1. Set `PLANTUML_SECURITY_PROFILE` to `SANDBOX` or `ALLOWLIST` before rendering text from an untrusted source. The default profile lets `!include` read local files and fetch URLs\n2. Run `java -jar plantuml.jar --check-syntax` with `-stdrpt` first and read the exit status. Without `--no-error-image` a syntax error still writes an image of the error text\n3. Pass `-pipe` with `--svg`, `--txt` or `--utxt` to work without files. `--txt` output suits a text-only model\n4. Start the local server as `-picoweb:8080:127.0.0.1`. Without the bind address it listens on every interface\n5. Use `npx -y @plantuml/mcp-js` when no Java runtime is present. It renders SVG only, so use the jar for PNG or PDF\n\n## Questions\n\n### Which is better for AI agents, Kroki or PlantUML?\n\nPlantUML scores 66.9 (B) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security \u0026 auth and maintenance \u0026 community.\n\n### Can an agent call Kroki and PlantUML without installing anything?\n\nNo hosted endpoint is listed for Kroki. No hosted endpoint is listed for PlantUML.\n\n### Are Kroki and PlantUML open source?\n\nYes. Kroki is open source (MIT). PlantUML is open source (GPL-3.0-or-later).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/kroki-vs-plantuml.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kroki-vs-plantuml.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"kroki\", \"b\": \"plantuml\"}`. From a terminal: `anchor compare kroki plantuml`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/kroki.json and https://www.anchorterminal.com/api/v1/tools/plantuml.json\n\n## Other comparisons with Kroki or PlantUML\n\n- [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md)\n- [Cloudviz API vs PlantUML](https://www.anchorterminal.com/compare/cloudviz-vs-plantuml.md)\n- [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md)\n- [Diagrams.so API + MCP vs PlantUML](https://www.anchorterminal.com/compare/diagrams-so-vs-plantuml.md)\n- [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md)\n- [draw.io + MCP vs PlantUML](https://www.anchorterminal.com/compare/drawio-vs-plantuml.md)\n- [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md)\n- [Eraser API + MCP vs PlantUML](https://www.anchorterminal.com/compare/eraser-vs-plantuml.md)\n- [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md)\n- [Excalidraw vs PlantUML](https://www.anchorterminal.com/compare/excalidraw-vs-plantuml.md)\n- [Kroki vs Mural MCP](https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md)\n- [Kroki vs Whimsical MCP](https://www.anchorterminal.com/compare/kroki-vs-whimsical.md)\n- [Lucid API + MCP vs PlantUML](https://www.anchorterminal.com/compare/lucid-vs-plantuml.md)\n- [Mermaid Chart MCP vs PlantUML](https://www.anchorterminal.com/compare/mermaid-chart-vs-plantuml.md)\n- [Mural MCP vs PlantUML](https://www.anchorterminal.com/compare/mural-mcp-vs-plantuml.md)\n- [PlantUML vs Whimsical MCP](https://www.anchorterminal.com/compare/plantuml-vs-whimsical.md)\n- [D2 vs Kroki](https://www.anchorterminal.com/compare/d2-vs-kroki.md)\n- [D2 vs PlantUML](https://www.anchorterminal.com/compare/d2-vs-plantuml.md)\n- [Kroki vs Lucid API + MCP](https://www.anchorterminal.com/compare/kroki-vs-lucid.md)\n- [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md)\n- [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md)\n- [Kroki vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/kroki-vs-tldraw.md)\n- [PlantUML vs Structurizr + MCP](https://www.anchorterminal.com/compare/plantuml-vs-structurizr.md)\n- [PlantUML vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/plantuml-vs-tldraw.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Kroki vs PlantUML",
        "url": ""
      }
    ],
    "description": "PlantUML scores 66.9 (B) to Kroki's 59.2 (C) for diagrams as code. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Kroki C 59.2",
      "PlantUML B 66.9",
      "scores"
    ],
    "h1": "Kroki vs PlantUML",
    "image": "https://www.anchorterminal.com/assets/og/compare-kroki-vs-plantuml.png",
    "path": "/compare/kroki-vs-plantuml",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Kroki vs PlantUML for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/kroki-vs-plantuml"
  },
  "tokens": {
    "markdown": 2400,
    "slim": 530
  },
  "version": 1
}
