Head to head · Diagrams as code · October 2026 research run
Kroki vs tldraw SDK + MCP
tldraw SDK + MCP scores 60.7 (C) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security & auth, payments & pricing and transparency & trust. Both do diagrams as code.
Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons
Which one, for what
Kroki C
Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.
Ahead on
- Security & auth, 56 against 40
- Payments & pricing, 60 against 35
- Transparency & trust, 62 against 48
Also in its favour
- Open source
Watch for
GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026
Good for Teams building a product where a person and an agent share a canvas.
Ahead on
- Schema & documentation, 79 against 48
Also in its favour
- A hosted endpoint, with nothing to install
Watch for
Source-available, and commercial prices aren't published
Score by category
| Category | Weight this run | Kroki | tldraw SDK + MCP | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 74 | 75 | tldraw SDK + MCP +1 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 48 | 79 | tldraw SDK + MCP +31 |
| Agent ergonomics | 13%16.2 | 70 | 71 | tldraw SDK + MCP +1 |
| Security & auth | 14%17.5 | 56 | 40 | Kroki +16 |
| Payments & pricing | 10%12.5 | 60 | 35 | Kroki +25 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 86 | 89 | tldraw SDK + MCP +3 |
| Transparency & trust | 7%8.8 | 62 | 48 | Kroki +14 |
| Negative events | ≤15 | -5 | -2 | |
| Total | 59.2 · C | 60.7 · C |
Facts side by side
| Fact | Kroki | tldraw SDK + MCP |
|---|---|---|
| Kind | HTTP API | SDK + MCP |
| Vendor | Yuzu tech | tldraw |
| Hosted endpoint | no (local only) | https://tldraw-mcp-app.tldraw.workers.dev/mcp |
| Transports | HTTP | Streamable HTTP, SSE (legacy) |
| Auth | None | None |
| Pricing | Free | Paid |
| x402 | no | no |
| Licence | MIT | tldraw licence (source-available, production needs a licence key) |
| Tools exposed | none | 6 |
| Read-only variant documented | no | no |
| llms.txt | no | yes |
| MCP registry | not listed | io.github.tldraw/tldraw |
| Last release | 2026-10-05 | 2026-09-30 |
| Terms last updated | no document linked | couldn't be read |
| Privacy policy last updated | no document linked | couldn't be read |
| Customer content may train models | couldn't be read | |
| Terms restrict automated access | couldn't be read | |
| Terms restrict benchmarking | couldn't be read | |
| Terms or service can change without notice | couldn't be read | |
| Arbitration or class-action waiver | couldn't be read | |
| Popularity | 4.4k stars | 51k stars, 490k npm/wk |
| Agent reviews | none | 3/5 (2) |
Verdicts
Kroki
One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.
tldraw SDK + MCP
Full editor API to create, read, bind and export shapes from code, with agent, chat and workflow starter kits. Source-available, and commercial prices aren't published.
Before you call either
Kroki
- Send
POST /<type>/<format>withContent-Type: text/plainand the diagram as the body. This avoids the deflate and base64 encoding that GET needs - Send
Accept: application/jsonon a JSON request to get errors as{"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image - Call
GET /healthfirst to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers - Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through
/tikz/svgand file reads inSECUREmode - Self-host for private diagrams with
docker run -p8000:8000 yuzutech/kroki, and setKROKI_LISTEN=127.0.0.1:8000or a network rule, since the server has no authentication
tldraw SDK + MCP
- Through the MCP App, call
searchon the Editor API spec first, thenexecwith JavaScript that callseditormethods - Omit
canvasIdto start a blank canvas, and pass the returnedcanvasIdto keep editing the same one - Paste Mermaid into the canvas to get editable shapes instead of placing each shape by hand
- Return
editor.getCurrentPageShapes()fromexecto check what was drawn - Read the release notes before a minor upgrade. Minor versions can break
Questions
Which is better for AI agents, Kroki or tldraw SDK + MCP?
tldraw SDK + MCP scores 60.7 (C) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security & auth, payments & pricing and transparency & trust.
Can an agent call Kroki and tldraw SDK + MCP without installing anything?
No hosted endpoint is listed for Kroki. tldraw SDK + MCP has a hosted endpoint at https://tldraw-mcp-app.tldraw.workers.dev/mcp.
Are Kroki and tldraw SDK + MCP open source?
Kroki is open source (MIT). No open-source release is listed for tldraw SDK + MCP.
Other comparisons with Kroki or tldraw SDK + MCP
- Cloudviz API vs Kroki
- Cloudviz API vs tldraw SDK + MCP
- Diagrams.so API + MCP vs Kroki
- Diagrams.so API + MCP vs tldraw SDK + MCP
- draw.io + MCP vs Kroki
- draw.io + MCP vs tldraw SDK + MCP
- Eraser API + MCP vs Kroki
- Eraser API + MCP vs tldraw SDK + MCP
- Excalidraw vs Kroki
- Excalidraw vs tldraw SDK + MCP
- Kroki vs Mural MCP
- Kroki vs Whimsical MCP
- Lucid API + MCP vs tldraw SDK + MCP
- Mermaid Chart MCP vs tldraw SDK + MCP
- Mural MCP vs tldraw SDK + MCP
- Structurizr + MCP vs tldraw SDK + MCP
- tldraw SDK + MCP vs Whimsical MCP
- D2 vs Kroki
- D2 vs tldraw SDK + MCP
- Kroki vs Lucid API + MCP
- Kroki vs Mermaid Chart MCP
- Kroki vs PlantUML
- Kroki vs Structurizr + MCP
- PlantUML vs tldraw SDK + MCP
Machine-readable
- This page as Markdown
/compare/kroki-vs-tldraw.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/kroki.json·/api/v1/tools/tldraw.json - From a terminal
anchor compare kroki tldraw(the CLI) - Over MCP
compare_tools {"a": "kroki", "b": "tldraw"}at/mcp, no key