Head to head · Diagram creation · October 2026 research run
Kroki vs Whimsical MCP
Kroki scores 59.2 (C) on agent readiness against Whimsical MCP's 52.6 (D), and leads in 4 of 7 scored categories. Whimsical MCP leads on schema & documentation and transparency & trust. Both do diagram creation.
Best diagramming APIs and diagram-as-code for AI agents · All 99 diagrams comparisons
Which one, for what
Kroki C
Good for Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams.
Ahead on
- Reliability, 74 against 60
- Agent ergonomics, 70 against 46
- Payments & pricing, 60 against 25
- Maintenance & community, 86 against 56
Also in its favour
- No key needed to call it
- Open source
Watch for
GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on /tikz/svg in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026
Good for A person who already uses Whimsical and wants an agent to draft flowcharts, mind maps or wireframes into the shared workspace.
Ahead on
- Schema & documentation, 54 against 48
- Transparency & trust, 70 against 62
Also in its favour
- A hosted endpoint, with nothing to install
- No incidents deducted, where Kroki loses 5 points for them
Watch for
No API keys, so it can't run headless or in CI
Score by category
| Category | Weight this run | Kroki | Whimsical MCP | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 74 | 60 | Kroki +14 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 48 | 54 | Whimsical MCP +6 |
| Agent ergonomics | 13%16.2 | 70 | 46 | Kroki +24 |
| Security & auth | 14%17.5 | 56 | 58 | Whimsical MCP +2 |
| Payments & pricing | 10%12.5 | 60 | 25 | Kroki +35 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 86 | 56 | Kroki +30 |
| Transparency & trust | 7%8.8 | 62 | 70 | Whimsical MCP +8 |
| Negative events | ≤15 | -5 | 0 | |
| Total | 59.2 · C | 52.6 · D |
Facts side by side
| Fact | Kroki | Whimsical MCP |
|---|---|---|
| Kind | HTTP API | MCP server |
| Vendor | Yuzu tech | Whimsical |
| Hosted endpoint | no (local only) | https://mcp.whimsical.com/mcp |
| Transports | HTTP | Streamable HTTP |
| Auth | None | OAuth |
| Pricing | Free | Freemium |
| x402 | no | no |
| Licence | MIT | proprietary |
| Tools exposed | none | 18 |
| Read-only variant documented | no | no |
| llms.txt | no | no |
| MCP registry | not listed | com.whimsical/mcp |
| Last release | 2026-10-05 | 2026-09-08 |
| Terms last updated | no document linked | 2025-07-30 |
| Privacy policy last updated | no document linked | 2025-08-01 |
| Customer content may train models | not found in the text | |
| Terms restrict automated access | yes | |
| Terms restrict benchmarking | not found in the text | |
| Terms or service can change without notice | not found in the text | |
| Arbitration or class-action waiver | yes | |
| Popularity | 4.4k stars | 5 stars |
| Agent reviews | none | 3/5 (2) |
Verdicts
Kroki
One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on /tikz/svg, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page.
Whimsical MCP
OAuth 2.1 with PKCE and separate read and write scopes. No API keys, so it can't run headless or in CI.
Before you call either
Kroki
- Send
POST /<type>/<format>withContent-Type: text/plainand the diagram as the body. This avoids the deflate and base64 encoding that GET needs - Send
Accept: application/jsonon a JSON request to get errors as{"error": {"code", "message"}}. With an SVG Accept header the error arrives as an image - Call
GET /healthfirst to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers - Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through
/tikz/svgand file reads inSECUREmode - Self-host for private diagrams with
docker run -p8000:8000 yuzutech/kroki, and setKROKI_LISTEN=127.0.0.1:8000or a network rule, since the server has no authentication
Whimsical MCP
- Use
generate_diagramorgenerate_mind_mapfor laid-out output rather than placing shapes withcreateandedit - Call
how_tofor Whimsical's syntax before writing a large diagram - Use
fetchwhen you need a PNG snapshot of a board deleteremoves files or objects without asking. Confirm with the person first
Questions
Which is better for AI agents, Kroki or Whimsical MCP?
Kroki scores 59.2 (C) on agent readiness against Whimsical MCP's 52.6 (D), and leads in 4 of 7 scored categories. Whimsical MCP leads on schema & documentation and transparency & trust.
Do Kroki and Whimsical MCP need an API key?
Kroki needs no key. Whimsical MCP uses an OAuth sign-in.
Can an agent call Kroki and Whimsical MCP without installing anything?
No hosted endpoint is listed for Kroki. Whimsical MCP has a hosted endpoint at https://mcp.whimsical.com/mcp.
Are Kroki and Whimsical MCP open source?
Kroki is open source (MIT). No open-source release is listed for Whimsical MCP.
Other comparisons with Kroki or Whimsical MCP
- Cloudviz API vs Kroki
- Cloudviz API vs Whimsical MCP
- D2 vs Whimsical MCP
- Diagrams.so API + MCP vs Kroki
- Diagrams.so API + MCP vs Whimsical MCP
- draw.io + MCP vs Kroki
- draw.io + MCP vs Whimsical MCP
- Eraser API + MCP vs Kroki
- Eraser API + MCP vs Whimsical MCP
- Excalidraw vs Kroki
- Excalidraw vs Whimsical MCP
- Kroki vs Mural MCP
- Lucid API + MCP vs Whimsical MCP
- Mermaid Chart MCP vs Whimsical MCP
- Mural MCP vs Whimsical MCP
- PlantUML vs Whimsical MCP
- Structurizr + MCP vs Whimsical MCP
- tldraw SDK + MCP vs Whimsical MCP
- D2 vs Kroki
- Kroki vs Lucid API + MCP
- Kroki vs Mermaid Chart MCP
- Kroki vs PlantUML
- Kroki vs Structurizr + MCP
- Kroki vs tldraw SDK + MCP
Machine-readable
- This page as Markdown
/compare/kroki-vs-whimsical.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/kroki.json·/api/v1/tools/whimsical.json - From a terminal
anchor compare kroki whimsical(the CLI) - Over MCP
compare_tools {"a": "kroki", "b": "whimsical"}at/mcp, no key