{
  "data": {
    "a": {
      "slug": "kroki",
      "name": "Kroki",
      "vendor": "Yuzu tech",
      "vendorUrl": "https://kroki.io",
      "kind": "http-api",
      "category": "diagramming",
      "summary": "Kroki is an open-source HTTP server from Yuzu tech that converts diagram text in 29 formats, including PlantUML, Mermaid, GraphViz and D2, into SVG, PNG or PDF. Owners run it from Docker images, and kroki.io is a free public instance.",
      "url": "https://www.anchorterminal.com/tools/kroki",
      "markdownUrl": "https://www.anchorterminal.com/tools/kroki.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kroki.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kroki.json",
      "repo": "https://github.com/yuzutech/kroki",
      "license": "MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "yuzutech/kroki"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-mermaid"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-bpmn"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-excalidraw"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or login on the convert endpoints, on a self-hosted server or on the public instance at kroki.io. The server binds all interfaces on port 8000 unless `KROKI_LISTEN` says otherwise. An optional bearer token, `KROKI_COMPANION_REGISTRATION_TOKEN`, protects only the `/services` registration API, which is off by default.",
      "pricing": "free",
      "pricingNotes": "Free under the MIT licence, with nothing to buy. The public instance at kroki.io is free and paid for by sponsors, for reasonable, non-commercial use with no uptime guarantee. Third parties sell hosting, which the project says it does not operate.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4365,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.kroki.io/kroki/setup/usage/",
      "capabilities": [
        "diagram.as-code",
        "diagram.create",
        "diagram.export",
        "diagram.architecture"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "http-api",
        "docker",
        "diagram-as-code",
        "plantuml",
        "mermaid",
        "graphviz",
        "no-auth",
        "free"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.2,
        "grade": "C",
        "agentReady": false,
        "rank": 558,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -5,
        "negativeNotes": [
          "27 July to 12 August 2026. Four advisories on the repository. GHSA-wmpp-fj9c-w766 (critical, CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in 0.21.0 up to 0.32.0 whatever the safe mode. GHSA-r54f-fq6c-53vw (high, CVE-2026-102359), GHSA-px99-rjv4-49g8 (medium, CVE-2026-102356) and GHSA-9p7m-vrmg-qp4q (high) let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed, in 0.32.1 at the latest, and the maintainers published each with a changelog entry, so the deduction is five points (https://github.com/yuzutech/kroki/security/advisories)."
        ],
        "verdict": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
        "bestFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "strengths": [
          "`POST /` with `diagram_source`, `diagram_type` and `output_format`, or plain text to `/\u003ctype\u003e/\u003cformat\u003e`, returns the image. No account or key",
          "One API covers 29 diagram types, among them PlantUML, C4, Structurizr, Mermaid, GraphViz, D2, DBML, BPMN, Excalidraw and Vega",
          "`KROKI_SAFE_MODE` defaults to `SECURE`, which blocks file and network reads by diagram libraries, and the container runs as the non-root user `kroki`",
          "Five versions shipped between 15 July and 5 October 2026, and the `main.yaml` workflow passed on the last ten pushes to `main`",
          "MIT licence. The maintainers published four security advisories in 2026, each with a fixed version and a changelog entry"
        ],
        "weaknesses": [
          "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026",
          "Three more advisories in July and August 2026 let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed in 0.32.1",
          "No OpenAPI file, llms.txt or error catalogue. The JSON error shape is in the source and not in the documentation",
          "The public instance at kroki.io has no terms, privacy policy, status page or published rate limit. The CLI page limits the demonstration server to reasonable, non-commercial use",
          "The server has no authentication on its convert endpoints and binds all interfaces on port 8000 by default. The version is 0.33.0, with no 1.0"
        ],
        "agentNotes": [
          "Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs",
          "Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image",
          "Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers",
          "Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode",
          "Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.2
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 67
        },
        "provenanceScore": 56
      },
      "connect": {
        "install": "docker run -p8000:8000 yuzutech/kroki",
        "http": "curl https://kroki.io/graphviz/svg --data-raw 'digraph G {Hello-\u003eWorld}'"
      },
      "letme": {
        "capability": "https://letme.dev/diagram.as-code",
        "tool": "https://letme.dev/kroki"
      },
      "area": "design-diagrams",
      "provenance": {
        "legalEntity": "Yuzu tech, a French software firm. No registered legal form found",
        "domain": "kroki.io",
        "domainRegistered": "2019-01-06",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/yuzutech/kroki/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The kroki.io home page says Kroki is built and maintained by Yuzu tech, and links https://yuzutech.fr, whose pages name no legal form or registration number. `LICENSE` reads Copyright (c) 2020-present Kroki",
          "No terms or privacy document was found on kroki.io or docs.kroki.io, for the software or for the public instance. The MIT licence stands in for the software",
          "https://kroki.io/.well-known/security.txt answered 404 on 9 October 2026. `SECURITY.md` asks for reports through a private GitHub security advisory",
          "The lead wrote the vendor as Yuzutech. The site writes Yuzu tech, and the GitHub organisation is `yuzutech`",
          "The endpoint on the vendor's domain is the free public instance. The listing grades the server an owner runs"
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kroki.json",
      "live": {
        "slug": "kroki",
        "versions": [
          {
            "registry": "github",
            "name": "yuzutech/kroki",
            "version": "v0.33.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-09T17:00:57.82489933Z"
          }
        ],
        "githubStars": 4365,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/yuzutech/kroki/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:46:31.151891385Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3e34fa594488"
          }
        ],
        "updatedAt": "2026-10-09T18:46:31.151891385Z"
      }
    },
    "answer": "Structurizr + MCP and Kroki score within a point of each other on agent readiness, 59.9 (C) and 59.2 (C). Kroki leads on agent ergonomics, security \u0026 auth, payments \u0026 pricing and maintenance \u0026 community.",
    "b": {
      "slug": "structurizr",
      "name": "Structurizr + MCP",
      "vendor": "Structurizr",
      "vendorUrl": "https://structurizr.com",
      "kind": "http-api",
      "category": "diagramming",
      "summary": "Diagram-as-code tool for software architecture using the C4 model.",
      "url": "https://www.anchorterminal.com/tools/structurizr",
      "markdownUrl": "https://www.anchorterminal.com/tools/structurizr.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/structurizr.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/structurizr.json",
      "repo": "https://github.com/structurizr/structurizr",
      "license": "Apache-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://mcp.structurizr.com/mcp",
      "packages": [],
      "auth": "mixed",
      "authNotes": "The workspace API on a Structurizr server takes a per-workspace key in the X-Authorization header, and listing all workspaces needs the admin API key. Server authentication can be switched off. The hosted MCP at mcp.structurizr.com needs no key.",
      "pricing": "freemium",
      "pricingNotes": "The DSL, local, the playground and the MCP server are free and Apache 2.0. Running the server from the prebuilt binaries needs a yearly licence priced by unique users (people or automated processes) per installation, from £300 a month for 1 to 20 users up to £2,400 a month for over 1,000, billed annually and bought by email, paid by bank transfer or PayPal invoice. 14-day trial licence from trial.structurizr.com. Building the server from source needs no licence. The cloud service took no new sign-ups after 31 December 2025 and shut down on 30 September 2026 (https://docs.structurizr.com/server/pricing).",
      "priceSummary": "$400 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 6,
      "popularity": {
        "githubStars": 419,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.structurizr.com",
      "openapi": "https://raw.githubusercontent.com/structurizr/structurizr/refs/heads/main/structurizr-json/structurizr.yaml",
      "capabilities": [
        "diagram.create",
        "diagram.as-code",
        "diagram.edit",
        "diagram.export",
        "diagram.architecture"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "mcp",
        "diagram-as-code",
        "openapi",
        "free-tier"
      ],
      "lastRelease": "2026-09-19",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.9,
        "grade": "C",
        "agentReady": false,
        "rank": 533,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 55,
          "maintenance": 68,
          "payments": 50,
          "reliability": 73,
          "schema": 61,
          "security": 43,
          "transparency": 77
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "One model can generate several C4 architecture views. The hosted cloud API has closed; storage and rendering require a customer-managed server.",
        "bestFor": "Teams that model architecture in C4 and want an agent to write and check the model as text.",
        "strengths": [
          "One text model yields context, container, component, dynamic and deployment views",
          "Free hosted MCP at mcp.structurizr.com validates, parses, inspects and exports DSL with no key",
          "Apache 2.0 code, an OpenAPI 3.0 definition and dated changelogs",
          "Release 2026.09.19 on 19 September 2026, with reported issues fixed within weeks",
          "Nine months' dated notice before the cloud service shut down"
        ],
        "weaknesses": [
          "The hosted cloud API is gone. Storage and rendering need your own server",
          "Prebuilt server binaries need a paid licence counted per unique user, including API clients",
          "The MCP module is labelled experimental, with one-line tool descriptions",
          "Self-hosted MCP server tools take the workspace API key as a tool argument",
          "No security.txt or disclosure policy, and one maintainer wrote every commit since February"
        ],
        "agentNotes": [
          "Call `validate` and then `inspect` on the DSL before pushing a workspace",
          "Use the Mermaid export when the diagram has to render in Markdown without a Structurizr server",
          "Export needs a view key. Parse the DSL first to list the views",
          "Run the `structurizr/mcp` image with only the flags you need, such as `-dsl -server-read`, to keep write and delete tools out of reach",
          "The workspace API returns JSON, never images. PNG and SVG come from the separate export command"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.9
          }
        ],
        "editorialScores": {
          "ergonomics": 55,
          "maintenance": 68,
          "payments": 50,
          "reliability": 73,
          "schema": 61,
          "security": 43,
          "transparency": 80
        },
        "provenanceScore": 74
      },
      "connect": {
        "http": "curl \"$STRUCTURIZR_URL/api/workspace/1\" -H \"X-Authorization: $STRUCTURIZR_API_KEY\"",
        "claudeCode": "claude mcp add --transport http structurizr https://mcp.structurizr.com/mcp",
        "config": {
          "mcpServers": {
            "structurizr": {
              "url": "https://mcp.structurizr.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/diagram.create",
        "tool": "https://letme.dev/structurizr"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Server licence, 1 to 20 users",
          "unit": "month",
          "usd": 400,
          "note": "£300 a month billed annually, converted at about $1.34 a pound"
        },
        {
          "item": "Server licence, 21 to 50 users",
          "unit": "month",
          "usd": 800,
          "note": "£600 a month billed annually, converted at about $1.34 a pound"
        }
      ],
      "provenance": {
        "legalEntity": "Structurizr Limited",
        "domain": "structurizr.com",
        "domainRegistered": "2013-11-04",
        "endpointOnVendorDomain": true,
        "terms": "https://structurizr.com/terms-and-conditions",
        "privacy": "https://structurizr.com/privacy-policy",
        "statusPage": "",
        "changelog": "https://github.com/structurizr/structurizr/blob/main/changelog-application.md",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "Structurizr Limited is a private company registered in Jersey, Channel Islands, Jersey Financial Services Commission registry number 303857 (server EULA)",
          "The Pingdom status page linked from structurizr.com monitored the cloud service, which shut down on 30 September 2026, so it isn't listed",
          "Server terms and privacy policy for the licence also live at https://docs.structurizr.com/server/terms-and-conditions and https://docs.structurizr.com/server/privacy-policy"
        ],
        "score": 74
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/structurizr.json",
      "live": {
        "slug": "structurizr",
        "probe": {
          "target": "https://mcp.structurizr.com/mcp",
          "method": "get",
          "lastAt": "2026-10-10T03:53:45.617999496Z",
          "lastOk": true,
          "lastStatus": 405,
          "lastMs": 71,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 92,
          "p95ms24h": 1082,
          "samples24h": 249,
          "samples30d": 2476,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 250,
              "ok": 250
            },
            {
              "date": "2026-10-10",
              "probes": 40,
              "ok": 40
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "structurizr/structurizr",
            "version": "v2026.09.19",
            "released": "2026-09-19",
            "seenAt": "2026-10-09T17:22:31.459492562Z"
          }
        ],
        "githubStars": 449,
        "securityTxt": {
          "url": "https://structurizr.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:39:49.773304473Z"
        },
        "domain": {
          "domain": "structurizr.com",
          "registered": "2013-11-04",
          "source": "https://rdap.verisign.com/com/v1/domain/structurizr.com",
          "checkedAt": "2026-10-04T13:06:16.957209253Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/structurizr/structurizr/main/changelog-application.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-09T18:46:09.252012036Z",
            "changedAt": "2026-10-02T15:24:03.368547202Z",
            "fingerprint": "7d7f8d519415"
          },
          {
            "url": "https://docs.structurizr.com/cloud",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-09T18:38:24.803904785Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f3914c04c843"
          },
          {
            "url": "https://docs.structurizr.com/server/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-09T18:38:26.918343227Z",
            "changedAt": "2026-10-02T15:20:28.925834824Z",
            "fingerprint": "30400863f0dd"
          },
          {
            "url": "https://structurizr.com/privacy-policy",
            "kind": "privacy",
            "status": 404,
            "checkedAt": "2026-10-09T18:46:08.565853393Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://structurizr.com/terms-and-conditions",
            "kind": "terms",
            "status": 404,
            "checkedAt": "2026-10-09T18:46:10.739850595Z",
            "changedAt": "0001-01-01T00:00:00Z"
          }
        ],
        "updatedAt": "2026-10-10T03:53:45.617999496Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Yuzu tech",
        "b": "Structurizr",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://mcp.structurizr.com/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "6",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-05",
        "b": "2026-09-19",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "4.4k stars",
        "b": "419 stars",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Structurizr + MCP and Kroki score within a point of each other on agent readiness, 59.9 (C) and 59.2 (C). Kroki leads on agent ergonomics, security \u0026 auth, payments \u0026 pricing and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Kroki or Structurizr + MCP?"
      },
      {
        "answer": "Kroki needs no key. Structurizr + MCP takes an API key or an OAuth sign-in.",
        "question": "Do Kroki and Structurizr + MCP need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Kroki. Structurizr + MCP has a hosted endpoint at https://mcp.structurizr.com/mcp.",
        "question": "Can an agent call Kroki and Structurizr + MCP without installing anything?"
      },
      {
        "answer": "Yes. Kroki is open source (MIT). Structurizr + MCP is open source (Apache-2.0).",
        "question": "Are Kroki and Structurizr + MCP open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Agent ergonomics, 70 against 55",
          "Security \u0026 auth, 56 against 43",
          "Payments \u0026 pricing, 60 against 50",
          "Maintenance \u0026 community, 86 against 68"
        ],
        "also": [
          "No key needed to call it"
        ],
        "goodFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "slug": "kroki",
        "watchFor": "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 61 against 48",
          "Transparency \u0026 trust, 77 against 62"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "No incidents deducted, where Kroki loses 5 points for them"
        ],
        "goodFor": "Teams that model architecture in C4 and want an agent to write and check the model as text.",
        "slug": "structurizr",
        "watchFor": "The hosted cloud API is gone. Storage and rendering need your own server"
      }
    ],
    "job": {
      "capability": "diagram.as-code",
      "name": "Diagrams as code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki.json",
        "title": "Cloudviz API vs Kroki",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-structurizr.json",
        "title": "Cloudviz API vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.json",
        "title": "Diagrams.so API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-structurizr.json",
        "title": "Diagrams.so API + MCP vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-kroki.json",
        "title": "draw.io + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-structurizr.json",
        "title": "draw.io + MCP vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-kroki.json",
        "title": "Eraser API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-structurizr.json",
        "title": "Eraser API + MCP vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki.json",
        "title": "Excalidraw vs Kroki",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-structurizr.json",
        "title": "Excalidraw vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.json",
        "title": "Kroki vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-whimsical.json",
        "title": "Kroki vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lucid-vs-structurizr.json",
        "title": "Lucid API + MCP vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/lucid-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mermaid-chart-vs-structurizr.json",
        "title": "Mermaid Chart MCP vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/mermaid-chart-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mural-mcp-vs-structurizr.json",
        "title": "Mural MCP vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/mural-mcp-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/structurizr-vs-tldraw.json",
        "title": "Structurizr + MCP vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/structurizr-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/structurizr-vs-whimsical.json",
        "title": "Structurizr + MCP vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/structurizr-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-kroki.json",
        "title": "D2 vs Kroki",
        "url": "https://www.anchorterminal.com/compare/d2-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-structurizr.json",
        "title": "D2 vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/d2-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-lucid.json",
        "title": "Kroki vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.json",
        "title": "Kroki vs Mermaid Chart MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-plantuml.json",
        "title": "Kroki vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-tldraw.json",
        "title": "Kroki vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/plantuml-vs-structurizr.json",
        "title": "PlantUML vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/plantuml-vs-structurizr"
      }
    ],
    "scores": [
      {
        "by": 1,
        "edge": "kroki",
        "key": "reliability",
        "kroki": 74,
        "name": "Reliability",
        "structurizr": 73,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 13,
        "edge": "structurizr",
        "key": "schema",
        "kroki": 48,
        "name": "Schema \u0026 documentation",
        "structurizr": 61,
        "weight": 13
      },
      {
        "by": 15,
        "edge": "kroki",
        "key": "ergonomics",
        "kroki": 70,
        "name": "Agent ergonomics",
        "structurizr": 55,
        "weight": 13
      },
      {
        "by": 13,
        "edge": "kroki",
        "key": "security",
        "kroki": 56,
        "name": "Security \u0026 auth",
        "structurizr": 43,
        "weight": 14
      },
      {
        "by": 10,
        "edge": "kroki",
        "key": "payments",
        "kroki": 60,
        "name": "Payments \u0026 pricing",
        "structurizr": 50,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 18,
        "edge": "kroki",
        "key": "maintenance",
        "kroki": 86,
        "name": "Maintenance \u0026 community",
        "structurizr": 68,
        "weight": 7
      },
      {
        "by": 15,
        "edge": "structurizr",
        "key": "transparency",
        "kroki": 62,
        "name": "Transparency \u0026 trust",
        "structurizr": 77,
        "weight": 7
      }
    ],
    "summary": "Structurizr + MCP and Kroki score within a point of each other on agent readiness, 59.9 (C) and 59.2 (C). Kroki leads on agent ergonomics, security \u0026 auth, payments \u0026 pricing and maintenance \u0026 community. Both do diagrams as code.",
    "verdicts": {
      "kroki": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
      "structurizr": "One model can generate several C4 architecture views. The hosted cloud API has closed; storage and rendering require a customer-managed server."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/kroki-vs-structurizr",
    "json": "https://www.anchorterminal.com/compare/kroki-vs-structurizr.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/kroki-vs-structurizr.md",
    "slim": "https://www.anchorterminal.com/compare/kroki-vs-structurizr.min.md"
  },
  "markdown": "Structurizr + MCP and Kroki score within a point of each other on agent readiness, 59.9 (C) and 59.2 (C). Kroki leads on agent ergonomics, security \u0026 auth, payments \u0026 pricing and maintenance \u0026 community. Both do diagrams as code.\n\n- Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json\n- Structurizr + MCP: grade C, 59.9/100, rank #533 of 950. Markdown https://www.anchorterminal.com/tools/structurizr.md · JSON https://www.anchorterminal.com/api/v1/tools/structurizr.json\n- Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md\n- All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md\n\n## Which one, for what\n\n### Kroki (C)\n\nGood for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.\n\nAhead on:\n- Agent ergonomics, 70 against 55\n- Security \u0026 auth, 56 against 43\n- Payments \u0026 pricing, 60 against 50\n- Maintenance \u0026 community, 86 against 68\n\nAlso in its favour:\n- No key needed to call it\n\nWatch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026\n\n### Structurizr + MCP (C)\n\nGood for: Teams that model architecture in C4 and want an agent to write and check the model as text.\n\nAhead on:\n- Schema \u0026 documentation, 61 against 48\n- Transparency \u0026 trust, 77 against 62\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- No incidents deducted, where Kroki loses 5 points for them\n\nWatch for: The hosted cloud API is gone. Storage and rendering need your own server\n\n\n## Score by category\n\n| Category | Weight | Kroki | Structurizr + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 74 | 73 | Kroki +1 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 48 | 61 | Structurizr + MCP +13 |\n| Agent ergonomics | 13% (16.2 this run) | 70 | 55 | Kroki +15 |\n| Security \u0026 auth | 14% (17.5 this run) | 56 | 43 | Kroki +13 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 50 | Kroki +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 86 | 68 | Kroki +18 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 62 | 77 | Structurizr + MCP +15 |\n| Negative events | ≤15 | -5 | 0 | |\n| **Total** | | **59.2 · C** | **59.9 · C** | |\n\n## Facts side by side\n\n| Fact | Kroki | Structurizr + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Yuzu tech | Structurizr |\n| Hosted endpoint | no (local only) | `https://mcp.structurizr.com/mcp` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | None | OAuth or key |\n| Pricing | Free | Freemium |\n| x402 | no | no |\n| Licence | MIT | Apache-2.0 |\n| Tools exposed | none | 6 |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| Last release | 2026-10-05 | 2026-09-19 |\n| Terms last updated | no document linked | couldn't be read |\n| Privacy policy last updated | no document linked | couldn't be read |\n| Customer content may train models |  | couldn't be read |\n| Terms restrict automated access |  | couldn't be read |\n| Terms restrict benchmarking |  | couldn't be read |\n| Terms or service can change without notice |  | couldn't be read |\n| Arbitration or class-action waiver |  | couldn't be read |\n| Popularity | 4.4k stars | 419 stars |\n| Agent reviews | none | 3/5 (2) |\n\n## Verdicts\n\n**Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.\n\n**Structurizr + MCP.** One model can generate several C4 architecture views. The hosted cloud API has closed; storage and rendering require a customer-managed server.\n\n## Before you call either\n\n### Kroki\n\n1. Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs\n2. Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image\n3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers\n4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode\n5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication\n\n### Structurizr + MCP\n\n1. Call `validate` and then `inspect` on the DSL before pushing a workspace\n2. Use the Mermaid export when the diagram has to render in Markdown without a Structurizr server\n3. Export needs a view key. Parse the DSL first to list the views\n4. Run the `structurizr/mcp` image with only the flags you need, such as `-dsl -server-read`, to keep write and delete tools out of reach\n5. The workspace API returns JSON, never images. PNG and SVG come from the separate export command\n\n## Questions\n\n### Which is better for AI agents, Kroki or Structurizr + MCP?\n\nStructurizr + MCP and Kroki score within a point of each other on agent readiness, 59.9 (C) and 59.2 (C). Kroki leads on agent ergonomics, security \u0026 auth, payments \u0026 pricing and maintenance \u0026 community.\n\n### Do Kroki and Structurizr + MCP need an API key?\n\nKroki needs no key. Structurizr + MCP takes an API key or an OAuth sign-in.\n\n### Can an agent call Kroki and Structurizr + MCP without installing anything?\n\nNo hosted endpoint is listed for Kroki. Structurizr + MCP has a hosted endpoint at https://mcp.structurizr.com/mcp.\n\n### Are Kroki and Structurizr + MCP open source?\n\nYes. Kroki is open source (MIT). Structurizr + MCP is open source (Apache-2.0).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/kroki-vs-structurizr.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kroki-vs-structurizr.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"kroki\", \"b\": \"structurizr\"}`. From a terminal: `anchor compare kroki structurizr`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/kroki.json and https://www.anchorterminal.com/api/v1/tools/structurizr.json\n\n## Other comparisons with Kroki or Structurizr + MCP\n\n- [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md)\n- [Cloudviz API vs Structurizr + MCP](https://www.anchorterminal.com/compare/cloudviz-vs-structurizr.md)\n- [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md)\n- [Diagrams.so API + MCP vs Structurizr + MCP](https://www.anchorterminal.com/compare/diagrams-so-vs-structurizr.md)\n- [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md)\n- [draw.io + MCP vs Structurizr + MCP](https://www.anchorterminal.com/compare/drawio-vs-structurizr.md)\n- [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md)\n- [Eraser API + MCP vs Structurizr + MCP](https://www.anchorterminal.com/compare/eraser-vs-structurizr.md)\n- [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md)\n- [Excalidraw vs Structurizr + MCP](https://www.anchorterminal.com/compare/excalidraw-vs-structurizr.md)\n- [Kroki vs Mural MCP](https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md)\n- [Kroki vs Whimsical MCP](https://www.anchorterminal.com/compare/kroki-vs-whimsical.md)\n- [Lucid API + MCP vs Structurizr + MCP](https://www.anchorterminal.com/compare/lucid-vs-structurizr.md)\n- [Mermaid Chart MCP vs Structurizr + MCP](https://www.anchorterminal.com/compare/mermaid-chart-vs-structurizr.md)\n- [Mural MCP vs Structurizr + MCP](https://www.anchorterminal.com/compare/mural-mcp-vs-structurizr.md)\n- [Structurizr + MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/structurizr-vs-tldraw.md)\n- [Structurizr + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/structurizr-vs-whimsical.md)\n- [D2 vs Kroki](https://www.anchorterminal.com/compare/d2-vs-kroki.md)\n- [D2 vs Structurizr + MCP](https://www.anchorterminal.com/compare/d2-vs-structurizr.md)\n- [Kroki vs Lucid API + MCP](https://www.anchorterminal.com/compare/kroki-vs-lucid.md)\n- [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md)\n- [Kroki vs PlantUML](https://www.anchorterminal.com/compare/kroki-vs-plantuml.md)\n- [Kroki vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/kroki-vs-tldraw.md)\n- [PlantUML vs Structurizr + MCP](https://www.anchorterminal.com/compare/plantuml-vs-structurizr.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Kroki vs Structurizr + MCP",
        "url": ""
      }
    ],
    "description": "Structurizr and Kroki score within a point of each other for diagrams as code, 59.9 and 59.2 out of 100. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Kroki C 59.2",
      "Structurizr + MCP C 59.9",
      "scores"
    ],
    "h1": "Kroki vs Structurizr + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-kroki-vs-structurizr.png",
    "path": "/compare/kroki-vs-structurizr",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Kroki vs Structurizr for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/kroki-vs-structurizr"
  },
  "tokens": {
    "markdown": 2500,
    "slim": 730
  },
  "version": 1
}
