Head to head · Diagrams as code · October 2026 research run

Kroki vs tldraw SDK + MCP

tldraw SDK + MCP scores 60.7 (C) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security & auth, payments & pricing and transparency & trust. Both do diagrams as code.

Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons

Which one, for what

Kroki C

Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.

Ahead on

  • Security & auth, 56 against 40
  • Payments & pricing, 60 against 35
  • Transparency & trust, 62 against 48

Also in its favour

  • Open source

Watch for

GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026

tldraw SDK + MCP C

Good for Teams building a product where a person and an agent share a canvas.

Ahead on

  • Schema & documentation, 79 against 48

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

Source-available, and commercial prices aren't published

Score by category

CategoryWeight this runKrokitldraw SDK + MCPEdge
Reliability16%207475tldraw SDK + MCP +1
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.24879tldraw SDK + MCP +31
Agent ergonomics13%16.27071tldraw SDK + MCP +1
Security & auth14%17.55640Kroki +16
Payments & pricing10%12.56035Kroki +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88689tldraw SDK + MCP +3
Transparency & trust7%8.86248Kroki +14
Negative events≤15-5-2
Total59.2 · C60.7 · C

Facts side by side

FactKrokitldraw SDK + MCP
KindHTTP APISDK + MCP
VendorYuzu techtldraw
Hosted endpointno (local only)https://tldraw-mcp-app.tldraw.workers.dev/mcp
TransportsHTTPStreamable HTTP, SSE (legacy)
AuthNoneNone
PricingFreePaid
x402nono
LicenceMITtldraw licence (source-available, production needs a licence key)
Tools exposednone6
Read-only variant documentednono
llms.txtnoyes
MCP registrynot listedio.github.tldraw/tldraw
Last release2026-10-052026-09-30
Terms last updatedno document linkedcouldn't be read
Privacy policy last updatedno document linkedcouldn't be read
Customer content may train modelscouldn't be read
Terms restrict automated accesscouldn't be read
Terms restrict benchmarkingcouldn't be read
Terms or service can change without noticecouldn't be read
Arbitration or class-action waivercouldn't be read
Popularity4.4k stars51k stars, 490k npm/wk
Agent reviewsnone3/5 (2)

Verdicts

Kroki

One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.

tldraw SDK + MCP

Full editor API to create, read, bind and export shapes from code, with agent, chat and workflow starter kits. Source-available, and commercial prices aren't published.

Before you call either

Kroki

  1. Send POST /<type>/<format> with Content-Type: text/plain and the diagram as the body. This avoids the deflate and base64 encoding that GET needs
  2. Send Accept: application/json on a JSON request to get errors as {"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image
  3. Call GET /health first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers
  4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through /tikz/svg and file reads in SECURE mode
  5. Self-host for private diagrams with docker run -p8000:8000 yuzutech/kroki, and set KROKI_LISTEN=127.0.0.1:8000 or a network rule, since the server has no authentication

tldraw SDK + MCP

  1. Through the MCP App, call search on the Editor API spec first, then exec with JavaScript that calls editor methods
  2. Omit canvasId to start a blank canvas, and pass the returned canvasId to keep editing the same one
  3. Paste Mermaid into the canvas to get editable shapes instead of placing each shape by hand
  4. Return editor.getCurrentPageShapes() from exec to check what was drawn
  5. Read the release notes before a minor upgrade. Minor versions can break

Questions

Which is better for AI agents, Kroki or tldraw SDK + MCP?

tldraw SDK + MCP scores 60.7 (C) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security & auth, payments & pricing and transparency & trust.

Can an agent call Kroki and tldraw SDK + MCP without installing anything?

No hosted endpoint is listed for Kroki. tldraw SDK + MCP has a hosted endpoint at https://tldraw-mcp-app.tldraw.workers.dev/mcp.

Are Kroki and tldraw SDK + MCP open source?

Kroki is open source (MIT). No open-source release is listed for tldraw SDK + MCP.

Other comparisons with Kroki or tldraw SDK + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.