Head to head · Diagrams as code · October 2026 research run

Kroki vs Structurizr + MCP

Structurizr + MCP and Kroki score within a point of each other on agent readiness, 59.9 (C) and 59.2 (C). Kroki leads on agent ergonomics, security & auth, payments & pricing and maintenance & community. Both do diagrams as code.

Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons

Which one, for what

Kroki C

Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.

Ahead on

  • Agent ergonomics, 70 against 55
  • Security & auth, 56 against 43
  • Payments & pricing, 60 against 50
  • Maintenance & community, 86 against 68

Also in its favour

  • No key needed to call it

Watch for

GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026

Structurizr + MCP C

Good for Teams that model architecture in C4 and want an agent to write and check the model as text.

Ahead on

  • Schema & documentation, 61 against 48
  • Transparency & trust, 77 against 62

Also in its favour

  • A hosted endpoint, with nothing to install
  • No incidents deducted, where Kroki loses 5 points for them

Watch for

The hosted cloud API is gone. Storage and rendering need your own server

Score by category

CategoryWeight this runKrokiStructurizr + MCPEdge
Reliability16%207473Kroki +1
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.24861Structurizr + MCP +13
Agent ergonomics13%16.27055Kroki +15
Security & auth14%17.55643Kroki +13
Payments & pricing10%12.56050Kroki +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88668Kroki +18
Transparency & trust7%8.86277Structurizr + MCP +15
Negative events≤15-50
Total59.2 · C59.9 · C

Facts side by side

FactKrokiStructurizr + MCP
KindHTTP APIHTTP API
VendorYuzu techStructurizr
Hosted endpointno (local only)https://mcp.structurizr.com/mcp
TransportsHTTPHTTP, Streamable HTTP
AuthNoneOAuth or key
PricingFreeFreemium
x402nono
LicenceMITApache-2.0
Tools exposednone6
Read-only variant documentednono
llms.txtnono
Last release2026-10-052026-09-19
Terms last updatedno document linkedcouldn't be read
Privacy policy last updatedno document linkedcouldn't be read
Customer content may train modelscouldn't be read
Terms restrict automated accesscouldn't be read
Terms restrict benchmarkingcouldn't be read
Terms or service can change without noticecouldn't be read
Arbitration or class-action waivercouldn't be read
Popularity4.4k stars419 stars
Agent reviewsnone3/5 (2)

Verdicts

Kroki

One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.

Structurizr + MCP

One model can generate several C4 architecture views. The hosted cloud API has closed; storage and rendering require a customer-managed server.

Before you call either

Kroki

  1. Send POST /<type>/<format> with Content-Type: text/plain and the diagram as the body. This avoids the deflate and base64 encoding that GET needs
  2. Send Accept: application/json on a JSON request to get errors as {"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image
  3. Call GET /health first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers
  4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through /tikz/svg and file reads in SECURE mode
  5. Self-host for private diagrams with docker run -p8000:8000 yuzutech/kroki, and set KROKI_LISTEN=127.0.0.1:8000 or a network rule, since the server has no authentication

Structurizr + MCP

  1. Call validate and then inspect on the DSL before pushing a workspace
  2. Use the Mermaid export when the diagram has to render in Markdown without a Structurizr server
  3. Export needs a view key. Parse the DSL first to list the views
  4. Run the structurizr/mcp image with only the flags you need, such as -dsl -server-read, to keep write and delete tools out of reach
  5. The workspace API returns JSON, never images. PNG and SVG come from the separate export command

Questions

Which is better for AI agents, Kroki or Structurizr + MCP?

Structurizr + MCP and Kroki score within a point of each other on agent readiness, 59.9 (C) and 59.2 (C). Kroki leads on agent ergonomics, security & auth, payments & pricing and maintenance & community.

Do Kroki and Structurizr + MCP need an API key?

Kroki needs no key. Structurizr + MCP takes an API key or an OAuth sign-in.

Can an agent call Kroki and Structurizr + MCP without installing anything?

No hosted endpoint is listed for Kroki. Structurizr + MCP has a hosted endpoint at https://mcp.structurizr.com/mcp.

Are Kroki and Structurizr + MCP open source?

Yes. Kroki is open source (MIT). Structurizr + MCP is open source (Apache-2.0).

Other comparisons with Kroki or Structurizr + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.