# Kroki vs Whimsical MCP > Kroki scores 59.2 (C) to Whimsical MCP's 52.6 (D) for diagram creation. Prices, MCP, x402, uptime and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/kroki-vs-whimsical - Markdown: https://www.anchorterminal.com/compare/kroki-vs-whimsical.md (~2,400 tokens) - Slim: https://www.anchorterminal.com/compare/kroki-vs-whimsical.min.md (~730 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/kroki-vs-whimsical.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 Kroki scores 59.2 (C) on agent readiness against Whimsical MCP's 52.6 (D), and leads in 4 of 7 scored categories. Whimsical MCP leads on schema & documentation and transparency & trust. Both do diagram creation. - Kroki: grade C, 59.2/100, rank #558 of 950. Markdown https://www.anchorterminal.com/tools/kroki.md · JSON https://www.anchorterminal.com/api/v1/tools/kroki.json - Whimsical MCP: grade D, 52.6/100, rank #731 of 950. Markdown https://www.anchorterminal.com/tools/whimsical.md · JSON https://www.anchorterminal.com/api/v1/tools/whimsical.json - Best diagramming APIs and diagram-as-code for AI agents: https://www.anchorterminal.com/best/diagramming/index.md - All 99 diagrams comparisons: https://www.anchorterminal.com/compare/diagramming/index.md ## Which one, for what ### Kroki (C) Good for: Agents that write diagrams in several text formats and want one render endpoint, on a private network or through the public instance for non-sensitive diagrams. Ahead on: - Reliability, 74 against 60 - Agent ergonomics, 70 against 46 - Payments & pricing, 60 against 25 - Maintenance & community, 86 against 56 Also in its favour: - No key needed to call it - Open source Watch for: GHSA-wmpp-fj9c-w766 (CVSS 9.8) allowed unauthenticated remote code execution on `/tikz/svg` in versions 0.21.0 up to 0.32.0, whatever the safe mode. Fixed 3 August 2026 ### Whimsical MCP (D) Good for: A person who already uses Whimsical and wants an agent to draft flowcharts, mind maps or wireframes into the shared workspace. Ahead on: - Schema & documentation, 54 against 48 - Transparency & trust, 70 against 62 Also in its favour: - A hosted endpoint, with nothing to install - No incidents deducted, where Kroki loses 5 points for them Watch for: No API keys, so it can't run headless or in CI ## Score by category | Category | Weight | Kroki | Whimsical MCP | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 74 | 60 | Kroki +14 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 48 | 54 | Whimsical MCP +6 | | Agent ergonomics | 13% (16.2 this run) | 70 | 46 | Kroki +24 | | Security & auth | 14% (17.5 this run) | 56 | 58 | Whimsical MCP +2 | | Payments & pricing | 10% (12.5 this run) | 60 | 25 | Kroki +35 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 86 | 56 | Kroki +30 | | Transparency & trust | 7% (8.8 this run) | 62 | 70 | Whimsical MCP +8 | | Negative events | ≤15 | -5 | 0 | | | **Total** | | **59.2 · C** | **52.6 · D** | | ## Facts side by side | Fact | Kroki | Whimsical MCP | | --- | --- | --- | | Kind | HTTP API | MCP server | | Vendor | Yuzu tech | Whimsical | | Hosted endpoint | no (local only) | `https://mcp.whimsical.com/mcp` | | Transports | HTTP | Streamable HTTP | | Auth | None | OAuth | | Pricing | Free | Freemium | | x402 | no | no | | Licence | MIT | proprietary | | Tools exposed | none | 18 | | Read-only variant documented | no | no | | llms.txt | no | no | | MCP registry | not listed | `com.whimsical/mcp` | | Last release | 2026-10-05 | 2026-09-08 | | Terms last updated | no document linked | 2025-07-30 | | Privacy policy last updated | no document linked | 2025-08-01 | | Customer content may train models | | not found in the text | | Terms restrict automated access | | yes | | Terms restrict benchmarking | | not found in the text | | Terms or service can change without notice | | not found in the text | | Arbitration or class-action waiver | | yes | | Popularity | 4.4k stars | 5 stars | | Agent reviews | none | 3/5 (2) | ## Verdicts **Kroki.** One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page. **Whimsical MCP.** OAuth 2.1 with PKCE and separate read and write scopes. No API keys, so it can't run headless or in CI. ## Before you call either ### Kroki 1. Send `POST //` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs 2. Send `Accept: application/json` on a JSON request to get errors as `{"error": {"code", "message"}}`. With an SVG Accept header the error arrives as an image 3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers 4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode 5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication ### Whimsical MCP 1. Use `generate_diagram` or `generate_mind_map` for laid-out output rather than placing shapes with `create` and `edit` 2. Call `how_to` for Whimsical's syntax before writing a large diagram 3. Use `fetch` when you need a PNG snapshot of a board 4. `delete` removes files or objects without asking. Confirm with the person first ## Questions ### Which is better for AI agents, Kroki or Whimsical MCP? Kroki scores 59.2 (C) on agent readiness against Whimsical MCP's 52.6 (D), and leads in 4 of 7 scored categories. Whimsical MCP leads on schema & documentation and transparency & trust. ### Do Kroki and Whimsical MCP need an API key? Kroki needs no key. Whimsical MCP uses an OAuth sign-in. ### Can an agent call Kroki and Whimsical MCP without installing anything? No hosted endpoint is listed for Kroki. Whimsical MCP has a hosted endpoint at https://mcp.whimsical.com/mcp. ### Are Kroki and Whimsical MCP open source? Kroki is open source (MIT). No open-source release is listed for Whimsical MCP. ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/kroki-vs-whimsical.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kroki-vs-whimsical.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "kroki", "b": "whimsical"}`. From a terminal: `anchor compare kroki whimsical` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/kroki.json and https://www.anchorterminal.com/api/v1/tools/whimsical.json ## Other comparisons with Kroki or Whimsical MCP - [Cloudviz API vs Kroki](https://www.anchorterminal.com/compare/cloudviz-vs-kroki.md) - [Cloudviz API vs Whimsical MCP](https://www.anchorterminal.com/compare/cloudviz-vs-whimsical.md) - [D2 vs Whimsical MCP](https://www.anchorterminal.com/compare/d2-vs-whimsical.md) - [Diagrams.so API + MCP vs Kroki](https://www.anchorterminal.com/compare/diagrams-so-vs-kroki.md) - [Diagrams.so API + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/diagrams-so-vs-whimsical.md) - [draw.io + MCP vs Kroki](https://www.anchorterminal.com/compare/drawio-vs-kroki.md) - [draw.io + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/drawio-vs-whimsical.md) - [Eraser API + MCP vs Kroki](https://www.anchorterminal.com/compare/eraser-vs-kroki.md) - [Eraser API + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/eraser-vs-whimsical.md) - [Excalidraw vs Kroki](https://www.anchorterminal.com/compare/excalidraw-vs-kroki.md) - [Excalidraw vs Whimsical MCP](https://www.anchorterminal.com/compare/excalidraw-vs-whimsical.md) - [Kroki vs Mural MCP](https://www.anchorterminal.com/compare/kroki-vs-mural-mcp.md) - [Lucid API + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/lucid-vs-whimsical.md) - [Mermaid Chart MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/mermaid-chart-vs-whimsical.md) - [Mural MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/mural-mcp-vs-whimsical.md) - [PlantUML vs Whimsical MCP](https://www.anchorterminal.com/compare/plantuml-vs-whimsical.md) - [Structurizr + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/structurizr-vs-whimsical.md) - [tldraw SDK + MCP vs Whimsical MCP](https://www.anchorterminal.com/compare/tldraw-vs-whimsical.md) - [D2 vs Kroki](https://www.anchorterminal.com/compare/d2-vs-kroki.md) - [Kroki vs Lucid API + MCP](https://www.anchorterminal.com/compare/kroki-vs-lucid.md) - [Kroki vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/kroki-vs-mermaid-chart.md) - [Kroki vs PlantUML](https://www.anchorterminal.com/compare/kroki-vs-plantuml.md) - [Kroki vs Structurizr + MCP](https://www.anchorterminal.com/compare/kroki-vs-structurizr.md) - [Kroki vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/kroki-vs-tldraw.md)