{
  "data": {
    "a": {
      "slug": "kroki",
      "name": "Kroki",
      "vendor": "Yuzu tech",
      "vendorUrl": "https://kroki.io",
      "kind": "http-api",
      "category": "diagramming",
      "summary": "Kroki is an open-source HTTP server from Yuzu tech that converts diagram text in 29 formats, including PlantUML, Mermaid, GraphViz and D2, into SVG, PNG or PDF. Owners run it from Docker images, and kroki.io is a free public instance.",
      "url": "https://www.anchorterminal.com/tools/kroki",
      "markdownUrl": "https://www.anchorterminal.com/tools/kroki.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kroki.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kroki.json",
      "repo": "https://github.com/yuzutech/kroki",
      "license": "MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "yuzutech/kroki"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-mermaid"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-bpmn"
        },
        {
          "registry": "oci",
          "name": "yuzutech/kroki-excalidraw"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or login on the convert endpoints, on a self-hosted server or on the public instance at kroki.io. The server binds all interfaces on port 8000 unless `KROKI_LISTEN` says otherwise. An optional bearer token, `KROKI_COMPANION_REGISTRATION_TOKEN`, protects only the `/services` registration API, which is off by default.",
      "pricing": "free",
      "pricingNotes": "Free under the MIT licence, with nothing to buy. The public instance at kroki.io is free and paid for by sponsors, for reasonable, non-commercial use with no uptime guarantee. Third parties sell hosting, which the project says it does not operate.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4365,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.kroki.io/kroki/setup/usage/",
      "capabilities": [
        "diagram.as-code",
        "diagram.create",
        "diagram.export",
        "diagram.architecture"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "http-api",
        "docker",
        "diagram-as-code",
        "plantuml",
        "mermaid",
        "graphviz",
        "no-auth",
        "free"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.2,
        "grade": "C",
        "agentReady": false,
        "rank": 558,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -5,
        "negativeNotes": [
          "27 July to 12 August 2026. Four advisories on the repository. GHSA-wmpp-fj9c-w766 (critical, CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in 0.21.0 up to 0.32.0 whatever the safe mode. GHSA-r54f-fq6c-53vw (high, CVE-2026-102359), GHSA-px99-rjv4-49g8 (medium, CVE-2026-102356) and GHSA-9p7m-vrmg-qp4q (high) let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed, in 0.32.1 at the latest, and the maintainers published each with a changelog entry, so the deduction is five points (https://github.com/yuzutech/kroki/security/advisories)."
        ],
        "verdict": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
        "bestFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "strengths": [
          "`POST /` with `diagram_source`, `diagram_type` and `output_format`, or plain text to `/\u003ctype\u003e/\u003cformat\u003e`, returns the image. No account or key",
          "One API covers 29 diagram types, among them PlantUML, C4, Structurizr, Mermaid, GraphViz, D2, DBML, BPMN, Excalidraw and Vega",
          "`KROKI_SAFE_MODE` defaults to `SECURE`, which blocks file and network reads by diagram libraries, and the container runs as the non-root user `kroki`",
          "Five versions shipped between 15 July and 5 October 2026, and the `main.yaml` workflow passed on the last ten pushes to `main`",
          "MIT licence. The maintainers published four security advisories in 2026, each with a fixed version and a changelog entry"
        ],
        "weaknesses": [
          "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026",
          "Three more advisories in July and August 2026 let TikZ, Mermaid and Vega diagrams read local files or fetch URLs in `SECURE` mode. All are fixed in 0.32.1",
          "No OpenAPI file, llms.txt or error catalogue. The JSON error shape is in the source and not in the documentation",
          "The public instance at kroki.io has no terms, privacy policy, status page or published rate limit. The CLI page limits the demonstration server to reasonable, non-commercial use",
          "The server has no authentication on its convert endpoints and binds all interfaces on port 8000 by default. The version is 0.33.0, with no 1.0"
        ],
        "agentNotes": [
          "Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs",
          "Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image",
          "Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers",
          "Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode",
          "Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.2
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 86,
          "payments": 60,
          "reliability": 74,
          "schema": 48,
          "security": 56,
          "transparency": 67
        },
        "provenanceScore": 56
      },
      "connect": {
        "install": "docker run -p8000:8000 yuzutech/kroki",
        "http": "curl https://kroki.io/graphviz/svg --data-raw 'digraph G {Hello-\u003eWorld}'"
      },
      "letme": {
        "capability": "https://letme.dev/diagram.as-code",
        "tool": "https://letme.dev/kroki"
      },
      "area": "design-diagrams",
      "provenance": {
        "legalEntity": "Yuzu tech, a French software firm. No registered legal form found",
        "domain": "kroki.io",
        "domainRegistered": "2019-01-06",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/yuzutech/kroki/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The kroki.io home page says Kroki is built and maintained by Yuzu tech, and links https://yuzutech.fr, whose pages name no legal form or registration number. `LICENSE` reads Copyright (c) 2020-present Kroki",
          "No terms or privacy document was found on kroki.io or docs.kroki.io, for the software or for the public instance. The MIT licence stands in for the software",
          "https://kroki.io/.well-known/security.txt answered 404 on 9 October 2026. `SECURITY.md` asks for reports through a private GitHub security advisory",
          "The lead wrote the vendor as Yuzutech. The site writes Yuzu tech, and the GitHub organisation is `yuzutech`",
          "The endpoint on the vendor's domain is the free public instance. The listing grades the server an owner runs"
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kroki.json",
      "live": {
        "slug": "kroki",
        "versions": [
          {
            "registry": "github",
            "name": "yuzutech/kroki",
            "version": "v0.33.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-09T17:00:57.82489933Z"
          }
        ],
        "githubStars": 4365,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/yuzutech/kroki/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:46:31.151891385Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3e34fa594488"
          }
        ],
        "updatedAt": "2026-10-09T18:46:31.151891385Z"
      }
    },
    "answer": "tldraw SDK + MCP scores 60.7 (C) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security \u0026 auth, payments \u0026 pricing and transparency \u0026 trust.",
    "b": {
      "slug": "tldraw",
      "name": "tldraw SDK + MCP",
      "vendor": "tldraw",
      "vendorUrl": "https://tldraw.dev",
      "kind": "sdk",
      "category": "diagramming",
      "summary": "A React infinite-canvas SDK that an agent can drive through the editor API, creating, reading and changing shapes, turning Mermaid into shapes and exporting images.",
      "url": "https://www.anchorterminal.com/tools/tldraw",
      "markdownUrl": "https://www.anchorterminal.com/tools/tldraw.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/tldraw.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/tldraw.json",
      "repo": "https://github.com/tldraw/tldraw",
      "license": "tldraw licence (source-available, production needs a licence key)",
      "transports": [
        "streamable-http",
        "sse"
      ],
      "remoteUrl": "https://tldraw-mcp-app.tldraw.workers.dev/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "tldraw"
        }
      ],
      "auth": "none",
      "authNotes": "The SDK runs in your app and needs no API key. It checks a public licence key on the client, offline, and won't run in production without one. The hosted MCP App needs no auth.",
      "pricing": "paid",
      "pricingNotes": "Free to use in development. Production needs a licence key. A 100-day trial is free with no card, a hobby licence for non-commercial projects is free at tldraw's discretion and shows a watermark, and commercial licences are annual with value-based pricing agreed with sales. Startup discounts are available. The MCP App is free (https://tldraw.dev/pricing).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 6,
      "popularity": {
        "githubStars": 50672,
        "npmWeekly": 490141,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://tldraw.dev/docs/ai",
      "llmsTxt": "https://tldraw.dev/llms.txt",
      "registryName": "io.github.tldraw/tldraw",
      "capabilities": [
        "diagram.create",
        "diagram.as-code",
        "diagram.edit",
        "diagram.export"
      ],
      "tags": [
        "typescript",
        "hosted",
        "mcp",
        "llms-txt",
        "free-tier"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.7,
        "grade": "C",
        "agentReady": false,
        "rank": 498,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 89,
          "payments": 35,
          "reliability": 75,
          "schema": 79,
          "security": 40,
          "transparency": 48
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -2,
        "negativeNotes": [
          "Checked 2026-10-01. The licence page says hobby licences send nothing and trial licences send only a hash of the key, with no user data. The SDK's LicenseManager sends the licence ID, SKU, environment and the full page URL (window.location.href) for trial, hobby-with-watermark and unlicensed production deployments, and the licence key page lists most of this. A full page URL can carry user data in its path or query (https://github.com/tldraw/tldraw/blob/main/packages/editor/src/lib/license/LicenseManager.ts, https://tldraw.dev/community/license)."
        ],
        "verdict": "Full editor API to create, read, bind and export shapes from code, with agent, chat and workflow starter kits. Source-available, and commercial prices aren't published.",
        "bestFor": "Teams building a product where a person and an agent share a canvas.",
        "strengths": [
          "Full editor API to create, read, bind and export shapes from code, with agent, chat and workflow starter kits",
          "Hosted MCP App with two model-facing tools, all six tools annotated",
          "At least six releases between 15 July and 30 September 2026, with dated release notes",
          "Development use and a 100-day production trial need no payment"
        ],
        "weaknesses": [
          "Source-available, and commercial prices aren't published",
          "`exec` runs model-written JavaScript on the canvas with no approval step",
          "Licence pings send the licence ID and full page URL for trial and hobby keys, more than the licence page says",
          "SECURITY.md lists only 3.x as supported while the current release is 5.5",
          "No server-side REST API, and the MCP App needs a host that renders MCP Apps"
        ],
        "agentNotes": [
          "Through the MCP App, call `search` on the Editor API spec first, then `exec` with JavaScript that calls `editor` methods",
          "Omit `canvasId` to start a blank canvas, and pass the returned `canvasId` to keep editing the same one",
          "Paste Mermaid into the canvas to get editable shapes instead of placing each shape by hand",
          "Return `editor.getCurrentPageShapes()` from `exec` to check what was drawn",
          "Read the release notes before a minor upgrade. Minor versions can break"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.7
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 89,
          "payments": 35,
          "reliability": 75,
          "schema": 79,
          "security": 40,
          "transparency": 45
        },
        "provenanceScore": 51
      },
      "connect": {
        "install": "npm install tldraw",
        "claudeCode": "claude mcp add --transport http tldraw https://tldraw-mcp-app.tldraw.workers.dev/mcp",
        "config": {
          "mcpServers": {
            "tldraw": {
              "url": "https://tldraw-mcp-app.tldraw.workers.dev/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/diagram.create",
        "tool": "https://letme.dev/tldraw"
      },
      "area": "design-diagrams",
      "provenance": {
        "legalEntity": "tldraw, Inc.",
        "domain": "tldraw.dev",
        "domainRegistered": "2022-04-11",
        "endpointOnVendorDomain": false,
        "terms": "https://www.tldraw.com/tos.html",
        "privacy": "https://www.tldraw.com/privacy.html",
        "statusPage": "",
        "changelog": "https://tldraw.dev/releases",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The hosted MCP App runs on a workers.dev subdomain, not on a tldraw domain"
        ],
        "score": 51
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/tldraw.json",
      "live": {
        "slug": "tldraw",
        "probe": {
          "target": "https://tldraw-mcp-app.tldraw.workers.dev/mcp",
          "method": "mcp-initialize",
          "lastAt": "2026-10-10T02:55:13.148072553Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 603,
          "lastNote": "initialize answered",
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 792,
          "p95ms24h": 1185,
          "samples24h": 249,
          "samples30d": 2466,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 250,
              "ok": 250
            },
            {
              "date": "2026-10-10",
              "probes": 30,
              "ok": 30
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "tldraw/tldraw",
            "version": "v5.5.2",
            "released": "2026-10-02",
            "seenAt": "2026-10-09T17:24:41.43205374Z"
          },
          {
            "registry": "mcp-registry",
            "name": "io.github.tldraw/tldraw",
            "version": "0.1.0",
            "seenAt": "2026-10-09T02:57:46.004536428Z"
          },
          {
            "registry": "npm",
            "name": "tldraw",
            "version": "5.5.2",
            "seenAt": "2026-10-09T17:24:40.599893975Z"
          }
        ],
        "githubStars": 50823,
        "npmWeekly": 430719,
        "securityTxt": {
          "url": "https://tldraw.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:40:25.25980169Z"
        },
        "llmsTxt": {
          "url": "https://tldraw.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-09T14:02:53.812410402Z"
        },
        "domain": {
          "domain": "tldraw.dev",
          "registered": "2022-04-11",
          "source": "https://pubapi.registry.google/rdap/domain/tldraw.dev",
          "checkedAt": "2026-10-04T13:10:18.060433565Z"
        },
        "pages": [
          {
            "url": "https://tldraw.dev/releases",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-09T18:46:46.809787133Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6de3df0f9614"
          },
          {
            "url": "https://tldraw.dev/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:46:44.532573009Z",
            "changedAt": "2026-10-08T18:25:17.082181385Z",
            "fingerprint": "5f8bf1cdd732"
          },
          {
            "url": "https://www.tldraw.com/privacy.html",
            "kind": "privacy",
            "status": 0,
            "checkedAt": "2026-10-09T18:54:58.628332809Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          },
          {
            "url": "https://www.tldraw.com/tos.html",
            "kind": "terms",
            "status": 0,
            "checkedAt": "2026-10-09T18:54:58.735013817Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          }
        ],
        "updatedAt": "2026-10-10T02:55:13.148072553Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "SDK + MCP",
        "name": "Kind"
      },
      {
        "a": "Yuzu tech",
        "b": "tldraw",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://tldraw-mcp-app.tldraw.workers.dev/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "Streamable HTTP, SSE (legacy)",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "tldraw licence (source-available, production needs a licence key)",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "6",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "io.github.tldraw/tldraw",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-05",
        "b": "2026-09-30",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "4.4k stars",
        "b": "51k stars, 490k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "tldraw SDK + MCP scores 60.7 (C) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security \u0026 auth, payments \u0026 pricing and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Kroki or tldraw SDK + MCP?"
      },
      {
        "answer": "No hosted endpoint is listed for Kroki. tldraw SDK + MCP has a hosted endpoint at https://tldraw-mcp-app.tldraw.workers.dev/mcp.",
        "question": "Can an agent call Kroki and tldraw SDK + MCP without installing anything?"
      },
      {
        "answer": "Kroki is open source (MIT). No open-source release is listed for tldraw SDK + MCP.",
        "question": "Are Kroki and tldraw SDK + MCP open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Security \u0026 auth, 56 against 40",
          "Payments \u0026 pricing, 60 against 35",
          "Transparency \u0026 trust, 62 against 48"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.",
        "slug": "kroki",
        "watchFor": "GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 79 against 48"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Teams building a product where a person and an agent share a canvas.",
        "slug": "tldraw",
        "watchFor": "Source-available, and commercial prices aren't published"
      }
    ],
    "job": {
      "capability": "diagram.as-code",
      "name": "Diagrams as code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki.json",
        "title": "Cloudviz API vs Kroki",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudviz-vs-tldraw.json",
        "title": "Cloudviz API vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/cloudviz-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.json",
        "title": "Diagrams.so API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/diagrams-so-vs-tldraw.json",
        "title": "Diagrams.so API + MCP vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/diagrams-so-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-kroki.json",
        "title": "draw.io + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/drawio-vs-tldraw.json",
        "title": "draw.io + MCP vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/drawio-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-kroki.json",
        "title": "Eraser API + MCP vs Kroki",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/eraser-vs-tldraw.json",
        "title": "Eraser API + MCP vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/eraser-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki.json",
        "title": "Excalidraw vs Kroki",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/excalidraw-vs-tldraw.json",
        "title": "Excalidraw vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/excalidraw-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.json",
        "title": "Kroki vs Mural MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mural-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-whimsical.json",
        "title": "Kroki vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lucid-vs-tldraw.json",
        "title": "Lucid API + MCP vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/lucid-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mermaid-chart-vs-tldraw.json",
        "title": "Mermaid Chart MCP vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/mermaid-chart-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mural-mcp-vs-tldraw.json",
        "title": "Mural MCP vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/mural-mcp-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/structurizr-vs-tldraw.json",
        "title": "Structurizr + MCP vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/structurizr-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/tldraw-vs-whimsical.json",
        "title": "tldraw SDK + MCP vs Whimsical MCP",
        "url": "https://www.anchorterminal.com/compare/tldraw-vs-whimsical"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-kroki.json",
        "title": "D2 vs Kroki",
        "url": "https://www.anchorterminal.com/compare/d2-vs-kroki"
      },
      {
        "json": "https://www.anchorterminal.com/compare/d2-vs-tldraw.json",
        "title": "D2 vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/d2-vs-tldraw"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-lucid.json",
        "title": "Kroki vs Lucid API + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-lucid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.json",
        "title": "Kroki vs Mermaid Chart MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-plantuml.json",
        "title": "Kroki vs PlantUML",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-plantuml"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kroki-vs-structurizr.json",
        "title": "Kroki vs Structurizr + MCP",
        "url": "https://www.anchorterminal.com/compare/kroki-vs-structurizr"
      },
      {
        "json": "https://www.anchorterminal.com/compare/plantuml-vs-tldraw.json",
        "title": "PlantUML vs tldraw SDK + MCP",
        "url": "https://www.anchorterminal.com/compare/plantuml-vs-tldraw"
      }
    ],
    "scores": [
      {
        "by": 1,
        "edge": "tldraw",
        "key": "reliability",
        "kroki": 74,
        "name": "Reliability",
        "tldraw": 75,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 31,
        "edge": "tldraw",
        "key": "schema",
        "kroki": 48,
        "name": "Schema \u0026 documentation",
        "tldraw": 79,
        "weight": 13
      },
      {
        "by": 1,
        "edge": "tldraw",
        "key": "ergonomics",
        "kroki": 70,
        "name": "Agent ergonomics",
        "tldraw": 71,
        "weight": 13
      },
      {
        "by": 16,
        "edge": "kroki",
        "key": "security",
        "kroki": 56,
        "name": "Security \u0026 auth",
        "tldraw": 40,
        "weight": 14
      },
      {
        "by": 25,
        "edge": "kroki",
        "key": "payments",
        "kroki": 60,
        "name": "Payments \u0026 pricing",
        "tldraw": 35,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "edge": "tldraw",
        "key": "maintenance",
        "kroki": 86,
        "name": "Maintenance \u0026 community",
        "tldraw": 89,
        "weight": 7
      },
      {
        "by": 14,
        "edge": "kroki",
        "key": "transparency",
        "kroki": 62,
        "name": "Transparency \u0026 trust",
        "tldraw": 48,
        "weight": 7
      }
    ],
    "summary": "tldraw SDK + MCP scores 60.7 (C) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security \u0026 auth, payments \u0026 pricing and transparency \u0026 trust. Both do diagrams as code.",
    "verdicts": {
      "kroki": "One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.",
      "tldraw": "Full editor API to create, read, bind and export shapes from code, with agent, chat and workflow starter kits. Source-available, and commercial prices aren't published."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/kroki-vs-tldraw",
    "json": "https://www.anchorterminal.com/compare/kroki-vs-tldraw.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/kroki-vs-tldraw.md",
    "slim": "https://www.anchorterminal.com/compare/kroki-vs-tldraw.min.md"
  },
  "markdown": "tldraw SDK + MCP scores 60.7 (C) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security \u0026 auth, payments \u0026 pricing and transparency \u0026 trust. Both do diagrams as code.\n\n- Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json\n- tldraw SDK + MCP: grade C, 60.7/100, rank #498 of 950. Markdown https://www.anchorterminal.com/tools/tldraw.md · JSON https://www.anchorterminal.com/api/v1/tools/tldraw.json\n- Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md\n- All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md\n\n## Which one, for what\n\n### Kroki (C)\n\nGood for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.\n\nAhead on:\n- Security \u0026 auth, 56 against 40\n- Payments \u0026 pricing, 60 against 35\n- Transparency \u0026 trust, 62 against 48\n\nAlso in its favour:\n- Open source\n\nWatch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026\n\n### tldraw SDK + MCP (C)\n\nGood for: Teams building a product where a person and an agent share a canvas.\n\nAhead on:\n- Schema \u0026 documentation, 79 against 48\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: Source-available, and commercial prices aren't published\n\n\n## Score by category\n\n| Category | Weight | Kroki | tldraw SDK + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 74 | 75 | tldraw SDK + MCP +1 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 48 | 79 | tldraw SDK + MCP +31 |\n| Agent ergonomics | 13% (16.2 this run) | 70 | 71 | tldraw SDK + MCP +1 |\n| Security \u0026 auth | 14% (17.5 this run) | 56 | 40 | Kroki +16 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 35 | Kroki +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 86 | 89 | tldraw SDK + MCP +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 62 | 48 | Kroki +14 |\n| Negative events | ≤15 | -5 | -2 | |\n| **Total** | | **59.2 · C** | **60.7 · C** | |\n\n## Facts side by side\n\n| Fact | Kroki | tldraw SDK + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | SDK + MCP |\n| Vendor | Yuzu tech | tldraw |\n| Hosted endpoint | no (local only) | `https://tldraw-mcp-app.tldraw.workers.dev/mcp` |\n| Transports | HTTP | Streamable HTTP, SSE (legacy) |\n| Auth | None | None |\n| Pricing | Free | Paid |\n| x402 | no | no |\n| Licence | MIT | tldraw licence (source-available, production needs a licence key) |\n| Tools exposed | none | 6 |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| MCP registry | not listed | `io.github.tldraw/tldraw` |\n| Last release | 2026-10-05 | 2026-09-30 |\n| Terms last updated | no document linked | couldn't be read |\n| Privacy policy last updated | no document linked | couldn't be read |\n| Customer content may train models |  | couldn't be read |\n| Terms restrict automated access |  | couldn't be read |\n| Terms restrict benchmarking |  | couldn't be read |\n| Terms or service can change without notice |  | couldn't be read |\n| Arbitration or class-action waiver |  | couldn't be read |\n| Popularity | 4.4k stars | 51k stars, 490k npm/wk |\n| Agent reviews | none | 3/5 (2) |\n\n## Verdicts\n\n**Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.\n\n**tldraw SDK + MCP.** Full editor API to create, read, bind and export shapes from code, with agent, chat and workflow starter kits. Source-available, and commercial prices aren't published.\n\n## Before you call either\n\n### Kroki\n\n1. Send `POST /\u003ctype\u003e/\u003cformat\u003e` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs\n2. Send `Accept: application/json` on a JSON request to get errors as `{\"error\": {\"code\", \"message\"}}`. With an SVG Accept header the error arrives as an image\n3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers\n4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode\n5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication\n\n### tldraw SDK + MCP\n\n1. Through the MCP App, call `search` on the Editor API spec first, then `exec` with JavaScript that calls `editor` methods\n2. Omit `canvasId` to start a blank canvas, and pass the returned `canvasId` to keep editing the same one\n3. Paste Mermaid into the canvas to get editable shapes instead of placing each shape by hand\n4. Return `editor.getCurrentPageShapes()` from `exec` to check what was drawn\n5. Read the release notes before a minor upgrade. Minor versions can break\n\n## Questions\n\n### Which is better for AI agents, Kroki or tldraw SDK + MCP?\n\ntldraw SDK + MCP scores 60.7 (C) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security \u0026 auth, payments \u0026 pricing and transparency \u0026 trust.\n\n### Can an agent call Kroki and tldraw SDK + MCP without installing anything?\n\nNo hosted endpoint is listed for Kroki. tldraw SDK + MCP has a hosted endpoint at https://tldraw-mcp-app.tldraw.workers.dev/mcp.\n\n### Are Kroki and tldraw SDK + MCP open source?\n\nKroki is open source (MIT). No open-source release is listed for tldraw SDK + MCP.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/kroki-vs-tldraw.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kroki-vs-tldraw.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"kroki\", \"b\": \"tldraw\"}`. From a terminal: `anchor compare kroki tldraw`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/kroki.json and https://www.anchorterminal.com/api/v1/tools/tldraw.json\n\n## Other comparisons with Kroki or tldraw SDK + MCP\n\n- [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md)\n- [Cloudviz API vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/cloudviz-vs-tldraw.md)\n- [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md)\n- [Diagrams.so API + MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/diagrams-so-vs-tldraw.md)\n- [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md)\n- [draw.io + MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/drawio-vs-tldraw.md)\n- [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md)\n- [Eraser API + MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/eraser-vs-tldraw.md)\n- [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md)\n- [Excalidraw vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/excalidraw-vs-tldraw.md)\n- [Kroki vs Mural MCP](https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md)\n- [Kroki vs Whimsical MCP](https://www.anchorterminal.com/compare/kroki-vs-whimsical.md)\n- [Lucid API + MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/lucid-vs-tldraw.md)\n- [Mermaid Chart MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/mermaid-chart-vs-tldraw.md)\n- [Mural MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/mural-mcp-vs-tldraw.md)\n- [Structurizr + MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/structurizr-vs-tldraw.md)\n- [tldraw SDK + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/tldraw-vs-whimsical.md)\n- [D2 vs Kroki](https://www.anchorterminal.com/compare/d2-vs-kroki.md)\n- [D2 vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/d2-vs-tldraw.md)\n- [Kroki vs Lucid API + MCP](https://www.anchorterminal.com/compare/kroki-vs-lucid.md)\n- [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md)\n- [Kroki vs PlantUML](https://www.anchorterminal.com/compare/kroki-vs-plantuml.md)\n- [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md)\n- [PlantUML vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/plantuml-vs-tldraw.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Kroki vs tldraw SDK + MCP",
        "url": ""
      }
    ],
    "description": "tldraw SDK scores 60.7 (C) to Kroki's 59.2 (C) for diagrams as code. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Kroki C 59.2",
      "tldraw SDK + MCP C 60.7",
      "scores"
    ],
    "h1": "Kroki vs tldraw SDK + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-kroki-vs-tldraw.png",
    "path": "/compare/kroki-vs-tldraw",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Kroki vs tldraw SDK for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/kroki-vs-tldraw"
  },
  "tokens": {
    "markdown": 2400,
    "slim": 730
  },
  "version": 1
}
