# Kroki vs PlantUML > PlantUML scores 66.9 (B) to Kroki's 59.2 (C) for diagrams as code. Prices, MCP, x402, uptime and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/kroki-vs-plantuml - Markdown: https://www.anchorterminal.com/compare/kroki-vs-plantuml.md (~2,400 tokens) - Slim: https://www.anchorterminal.com/compare/kroki-vs-plantuml.min.md (~530 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/kroki-vs-plantuml.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 PlantUML scores 66.9 (B) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security & auth and maintenance & community. Both do diagrams as code. - Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json - PlantUML: grade B, 66.9/100, rank #270 of 950. Markdown https://www.anchorterminal.com/tools/plantuml.md · JSON https://www.anchorterminal.com/api/v1/tools/plantuml.json - Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md - All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md ## Which one, for what ### Kroki (C) Good for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams. Ahead on: - Security & auth, 56 against 50 - Maintenance & community, 86 against 73 Watch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026 ### PlantUML (B) Good for: Agents that write sequence, class, state, component, deployment, Gantt or C4 diagrams as text and render them locally or in CI. Ahead on: - Reliability, 83 against 74 - Schema & documentation, 65 against 48 - Agent ergonomics, 78 against 70 - Transparency & trust, 73 against 62 Watch for: The default security profile is LEGACY, which gives diagram text full access to local files and URLs through `!include`. The docs say it will be removed, with no date ## Score by category | Category | Weight | Kroki | PlantUML | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 74 | 83 | PlantUML +9 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 48 | 65 | PlantUML +17 | | Agent ergonomics | 13% (16.2 this run) | 70 | 78 | PlantUML +8 | | Security & auth | 14% (17.5 this run) | 56 | 50 | Kroki +6 | | Payments & pricing | 10% (12.5 this run) | 60 | 60 | even | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 86 | 73 | Kroki +13 | | Transparency & trust | 7% (8.8 this run) | 62 | 73 | PlantUML +11 | | Negative events | ≤15 | -5 | -2 | | | **Total** | | **59.2 · C** | **66.9 · B** | | ## Facts side by side | Fact | Kroki | PlantUML | | --- | --- | --- | | Kind | HTTP API | SDK + MCP | | Vendor | Yuzu tech | PlantUML project (Arnaud Roques) | | Hosted endpoint | no (local only) | no (local only) | | Transports | HTTP | | | Auth | None | None | | Pricing | Free | Free | | x402 | no | no | | Licence | MIT | GPL-3.0-or-later | | Read-only variant documented | no | no | | llms.txt | no | no | | Last release | 2026-10-05 | 2026-09-05 | | Terms last updated | no document linked | no document linked | | Privacy policy last updated | no document linked | no document linked | | Customer content may train models | | | | Terms restrict automated access | | | | Terms restrict benchmarking | | | | Terms or service can change without notice | | | | Arbitration or class-action waiver | | | | Popularity | 4.4k stars | 13k stars, 207 npm/wk | ## Verdicts **Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page. **PlantUML.** One Java command reads diagram text from stdin and writes PNG, SVG, PDF or ASCII with no account, and CI passed on the last eight pushes. The default security profile lets diagram text read any local file and fetch any URL, and the documentation still lists chronology diagrams that release 1.2026.2 switched off. ## Before you call either ### Kroki 1. Send `POST //` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs 2. Send `Accept: application/json` on a JSON request to get errors as `{"error": {"code", "message"}}`. With an SVG Accept header the error arrives as an image 3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers 4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode 5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication ### PlantUML 1. Set `PLANTUML_SECURITY_PROFILE` to `SANDBOX` or `ALLOWLIST` before rendering text from an untrusted source. The default profile lets `!include` read local files and fetch URLs 2. Run `java -jar plantuml.jar --check-syntax` with `-stdrpt` first and read the exit status. Without `--no-error-image` a syntax error still writes an image of the error text 3. Pass `-pipe` with `--svg`, `--txt` or `--utxt` to work without files. `--txt` output suits a text-only model 4. Start the local server as `-picoweb:8080:127.0.0.1`. Without the bind address it listens on every interface 5. Use `npx -y @plantuml/mcp-js` when no Java runtime is present. It renders SVG only, so use the jar for PNG or PDF ## Questions ### Which is better for AI agents, Kroki or PlantUML? PlantUML scores 66.9 (B) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security & auth and maintenance & community. ### Can an agent call Kroki and PlantUML without installing anything? No hosted endpoint is listed for Kroki. No hosted endpoint is listed for PlantUML. ### Are Kroki and PlantUML open source? Yes. Kroki is open source (MIT). PlantUML is open source (GPL-3.0-or-later). ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/kroki-vs-plantuml.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kroki-vs-plantuml.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "kroki", "b": "plantuml"}`. From a terminal: `anchor compare kroki plantuml` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/kroki.json and https://www.anchorterminal.com/api/v1/tools/plantuml.json ## Other comparisons with Kroki or PlantUML - [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md) - [Cloudviz API vs PlantUML](https://www.anchorterminal.com/compare/cloudviz-vs-plantuml.md) - [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md) - [Diagrams.so API + MCP vs PlantUML](https://www.anchorterminal.com/compare/diagrams-so-vs-plantuml.md) - [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md) - [draw.io + MCP vs PlantUML](https://www.anchorterminal.com/compare/drawio-vs-plantuml.md) - [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md) - [Eraser API + MCP vs PlantUML](https://www.anchorterminal.com/compare/eraser-vs-plantuml.md) - [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md) - [Excalidraw vs PlantUML](https://www.anchorterminal.com/compare/excalidraw-vs-plantuml.md) - [Kroki vs Mural MCP](https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md) - [Kroki vs Whimsical MCP](https://www.anchorterminal.com/compare/kroki-vs-whimsical.md) - [Lucid API + MCP vs PlantUML](https://www.anchorterminal.com/compare/lucid-vs-plantuml.md) - [Mermaid Chart MCP vs PlantUML](https://www.anchorterminal.com/compare/mermaid-chart-vs-plantuml.md) - [Mural MCP vs PlantUML](https://www.anchorterminal.com/compare/mural-mcp-vs-plantuml.md) - [PlantUML vs Whimsical MCP](https://www.anchorterminal.com/compare/plantuml-vs-whimsical.md) - [D2 vs Kroki](https://www.anchorterminal.com/compare/d2-vs-kroki.md) - [D2 vs PlantUML](https://www.anchorterminal.com/compare/d2-vs-plantuml.md) - [Kroki vs Lucid API + MCP](https://www.anchorterminal.com/compare/kroki-vs-lucid.md) - [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md) - [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md) - [Kroki vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/kroki-vs-tldraw.md) - [PlantUML vs Structurizr + MCP](https://www.anchorterminal.com/compare/plantuml-vs-structurizr.md) - [PlantUML vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/plantuml-vs-tldraw.md)