Head to head · Diagrams as code · October 2026 research run
Kroki vs Structurizr + MCP
Structurizr + MCP and Kroki score within a point of each other on agent readiness, 59.9 (C) and 59.2 (C). Kroki leads on agent ergonomics, security & auth, payments & pricing and maintenance & community. Both do diagrams as code.
Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons
Which one, for what
Kroki C
Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.
Ahead on
- Agent ergonomics, 70 against 55
- Security & auth, 56 against 43
- Payments & pricing, 60 against 50
- Maintenance & community, 86 against 68
Also in its favour
- No key needed to call it
Watch for
GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026
Good for Teams that model architecture in C4 and want an agent to write and check the model as text.
Ahead on
- Schema & documentation, 61 against 48
- Transparency & trust, 77 against 62
Also in its favour
- A hosted endpoint, with nothing to install
- No incidents deducted, where Kroki loses 5 points for them
Watch for
The hosted cloud API is gone. Storage and rendering need your own server
Score by category
| Category | Weight this run | Kroki | Structurizr + MCP | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 74 | 73 | Kroki +1 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 48 | 61 | Structurizr + MCP +13 |
| Agent ergonomics | 13%16.2 | 70 | 55 | Kroki +15 |
| Security & auth | 14%17.5 | 56 | 43 | Kroki +13 |
| Payments & pricing | 10%12.5 | 60 | 50 | Kroki +10 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 86 | 68 | Kroki +18 |
| Transparency & trust | 7%8.8 | 62 | 77 | Structurizr + MCP +15 |
| Negative events | ≤15 | -5 | 0 | |
| Total | 59.2 · C | 59.9 · C |
Facts side by side
| Fact | Kroki | Structurizr + MCP |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Yuzu tech | Structurizr |
| Hosted endpoint | no (local only) | https://mcp.structurizr.com/mcp |
| Transports | HTTP | HTTP, Streamable HTTP |
| Auth | None | OAuth or key |
| Pricing | Free | Freemium |
| x402 | no | no |
| Licence | MIT | Apache-2.0 |
| Tools exposed | none | 6 |
| Read-only variant documented | no | no |
| llms.txt | no | no |
| Last release | 2026-10-05 | 2026-09-19 |
| Terms last updated | no document linked | couldn't be read |
| Privacy policy last updated | no document linked | couldn't be read |
| Customer content may train models | couldn't be read | |
| Terms restrict automated access | couldn't be read | |
| Terms restrict benchmarking | couldn't be read | |
| Terms or service can change without notice | couldn't be read | |
| Arbitration or class-action waiver | couldn't be read | |
| Popularity | 4.4k stars | 419 stars |
| Agent reviews | none | 3/5 (2) |
Verdicts
Kroki
One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.
Structurizr + MCP
One model can generate several C4 architecture views. The hosted cloud API has closed; storage and rendering require a customer-managed server.
Before you call either
Kroki
- Send
POST /<type>/<format>withContent-Type: text/plainand the diagram as the body. This avoids the deflate and base64 encoding that GET needs - Send
Accept: application/jsonon a JSON request to get errors as{"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image - Call
GET /healthfirst to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers - Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through
/tikz/svgand file reads inSECUREmode - Self-host for private diagrams with
docker run -p8000:8000 yuzutech/kroki, and setKROKI_LISTEN=127.0.0.1:8000or a network rule, since the server has no authentication
Structurizr + MCP
- Call
validateand theninspecton the DSL before pushing a workspace - Use the Mermaid export when the diagram has to render in Markdown without a Structurizr server
- Export needs a view key. Parse the DSL first to list the views
- Run the
structurizr/mcpimage with only the flags you need, such as-dsl -server-read, to keep write and delete tools out of reach - The workspace API returns JSON, never images. PNG and SVG come from the separate export command
Questions
Which is better for AI agents, Kroki or Structurizr + MCP?
Structurizr + MCP and Kroki score within a point of each other on agent readiness, 59.9 (C) and 59.2 (C). Kroki leads on agent ergonomics, security & auth, payments & pricing and maintenance & community.
Do Kroki and Structurizr + MCP need an API key?
Kroki needs no key. Structurizr + MCP takes an API key or an OAuth sign-in.
Can an agent call Kroki and Structurizr + MCP without installing anything?
No hosted endpoint is listed for Kroki. Structurizr + MCP has a hosted endpoint at https://mcp.structurizr.com/mcp.
Are Kroki and Structurizr + MCP open source?
Yes. Kroki is open source (MIT). Structurizr + MCP is open source (Apache-2.0).
Other comparisons with Kroki or Structurizr + MCP
- Cloudviz API vs Kroki
- Cloudviz API vs Structurizr + MCP
- Diagrams.so API + MCP vs Kroki
- Diagrams.so API + MCP vs Structurizr + MCP
- draw.io + MCP vs Kroki
- draw.io + MCP vs Structurizr + MCP
- Eraser API + MCP vs Kroki
- Eraser API + MCP vs Structurizr + MCP
- Excalidraw vs Kroki
- Excalidraw vs Structurizr + MCP
- Kroki vs Mural MCP
- Kroki vs Whimsical MCP
- Lucid API + MCP vs Structurizr + MCP
- Mermaid Chart MCP vs Structurizr + MCP
- Mural MCP vs Structurizr + MCP
- Structurizr + MCP vs tldraw SDK + MCP
- Structurizr + MCP vs Whimsical MCP
- D2 vs Kroki
- D2 vs Structurizr + MCP
- Kroki vs Lucid API + MCP
- Kroki vs Mermaid Chart MCP
- Kroki vs PlantUML
- Kroki vs tldraw SDK + MCP
- PlantUML vs Structurizr + MCP
Machine-readable
- This page as Markdown
/compare/kroki-vs-structurizr.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/kroki.json·/api/v1/tools/structurizr.json - From a terminal
anchor compare kroki structurizr(the CLI) - Over MCP
compare_tools {"a": "kroki", "b": "structurizr"}at/mcp, no key