# Kroki vs tldraw SDK + MCP > tldraw SDK scores 60.7 (C) to Kroki's 59.2 (C) for diagrams as code. Prices, MCP, x402, uptime and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/kroki-vs-tldraw - Markdown: https://www.anchorterminal.com/compare/kroki-vs-tldraw.md (~2,400 tokens) - Slim: https://www.anchorterminal.com/compare/kroki-vs-tldraw.min.md (~730 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/kroki-vs-tldraw.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 tldraw SDK + MCP scores 60.7 (C) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security & auth, payments & pricing and transparency & trust. Both do diagrams as code. - Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json - tldraw SDK + MCP: grade C, 60.7/100, rank #498 of 950. Markdown https://www.anchorterminal.com/tools/tldraw.md · JSON https://www.anchorterminal.com/api/v1/tools/tldraw.json - Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md - All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md ## Which one, for what ### Kroki (C) Good for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams. Ahead on: - Security & auth, 56 against 40 - Payments & pricing, 60 against 35 - Transparency & trust, 62 against 48 Also in its favour: - Open source Watch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026 ### tldraw SDK + MCP (C) Good for: Teams building a product where a person and an agent share a canvas. Ahead on: - Schema & documentation, 79 against 48 Also in its favour: - A hosted endpoint, with nothing to install Watch for: Source-available, and commercial prices aren't published ## Score by category | Category | Weight | Kroki | tldraw SDK + MCP | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 74 | 75 | tldraw SDK + MCP +1 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 48 | 79 | tldraw SDK + MCP +31 | | Agent ergonomics | 13% (16.2 this run) | 70 | 71 | tldraw SDK + MCP +1 | | Security & auth | 14% (17.5 this run) | 56 | 40 | Kroki +16 | | Payments & pricing | 10% (12.5 this run) | 60 | 35 | Kroki +25 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 86 | 89 | tldraw SDK + MCP +3 | | Transparency & trust | 7% (8.8 this run) | 62 | 48 | Kroki +14 | | Negative events | ≤15 | -5 | -2 | | | **Total** | | **59.2 · C** | **60.7 · C** | | ## Facts side by side | Fact | Kroki | tldraw SDK + MCP | | --- | --- | --- | | Kind | HTTP API | SDK + MCP | | Vendor | Yuzu tech | tldraw | | Hosted endpoint | no (local only) | `https://tldraw-mcp-app.tldraw.workers.dev/mcp` | | Transports | HTTP | Streamable HTTP, SSE (legacy) | | Auth | None | None | | Pricing | Free | Paid | | x402 | no | no | | Licence | MIT | tldraw licence (source-available, production needs a licence key) | | Tools exposed | none | 6 | | Read-only variant documented | no | no | | llms.txt | no | yes | | MCP registry | not listed | `io.github.tldraw/tldraw` | | Last release | 2026-10-05 | 2026-09-30 | | Terms last updated | no document linked | couldn't be read | | Privacy policy last updated | no document linked | couldn't be read | | Customer content may train models | | couldn't be read | | Terms restrict automated access | | couldn't be read | | Terms restrict benchmarking | | couldn't be read | | Terms or service can change without notice | | couldn't be read | | Arbitration or class-action waiver | | couldn't be read | | Popularity | 4.4k stars | 51k stars, 490k npm/wk | | Agent reviews | none | 3/5 (2) | ## Verdicts **Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page. **tldraw SDK + MCP.** Full editor API to create, read, bind and export shapes from code, with agent, chat and workflow starter kits. Source-available, and commercial prices aren't published. ## Before you call either ### Kroki 1. Send `POST //` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs 2. Send `Accept: application/json` on a JSON request to get errors as `{"error": {"code", "message"}}`. With an SVG Accept header the error arrives as an image 3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers 4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode 5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication ### tldraw SDK + MCP 1. Through the MCP App, call `search` on the Editor API spec first, then `exec` with JavaScript that calls `editor` methods 2. Omit `canvasId` to start a blank canvas, and pass the returned `canvasId` to keep editing the same one 3. Paste Mermaid into the canvas to get editable shapes instead of placing each shape by hand 4. Return `editor.getCurrentPageShapes()` from `exec` to check what was drawn 5. Read the release notes before a minor upgrade. Minor versions can break ## Questions ### Which is better for AI agents, Kroki or tldraw SDK + MCP? tldraw SDK + MCP scores 60.7 (C) on agent readiness against Kroki's 59.2 (C), and leads in 4 of 7 scored categories. Kroki leads on security & auth, payments & pricing and transparency & trust. ### Can an agent call Kroki and tldraw SDK + MCP without installing anything? No hosted endpoint is listed for Kroki. tldraw SDK + MCP has a hosted endpoint at https://tldraw-mcp-app.tldraw.workers.dev/mcp. ### Are Kroki and tldraw SDK + MCP open source? Kroki is open source (MIT). No open-source release is listed for tldraw SDK + MCP. ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/kroki-vs-tldraw.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kroki-vs-tldraw.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "kroki", "b": "tldraw"}`. From a terminal: `anchor compare kroki tldraw` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/kroki.json and https://www.anchorterminal.com/api/v1/tools/tldraw.json ## Other comparisons with Kroki or tldraw SDK + MCP - [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md) - [Cloudviz API vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/cloudviz-vs-tldraw.md) - [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md) - [Diagrams.so API + MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/diagrams-so-vs-tldraw.md) - [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md) - [draw.io + MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/drawio-vs-tldraw.md) - [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md) - [Eraser API + MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/eraser-vs-tldraw.md) - [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md) - [Excalidraw vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/excalidraw-vs-tldraw.md) - [Kroki vs Mural MCP](https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md) - [Kroki vs Whimsical MCP](https://www.anchorterminal.com/compare/kroki-vs-whimsical.md) - [Lucid API + MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/lucid-vs-tldraw.md) - [Mermaid Chart MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/mermaid-chart-vs-tldraw.md) - [Mural MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/mural-mcp-vs-tldraw.md) - [Structurizr + MCP vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/structurizr-vs-tldraw.md) - [tldraw SDK + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/tldraw-vs-whimsical.md) - [D2 vs Kroki](https://www.anchorterminal.com/compare/d2-vs-kroki.md) - [D2 vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/d2-vs-tldraw.md) - [Kroki vs Lucid API + MCP](https://www.anchorterminal.com/compare/kroki-vs-lucid.md) - [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md) - [Kroki vs PlantUML](https://www.anchorterminal.com/compare/kroki-vs-plantuml.md) - [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md) - [PlantUML vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/plantuml-vs-tldraw.md)