D2
by D2 project (The Hack Foundation) SDK + MCP in Diagramming
The Hack Foundation · d2lang.com since 2022 · who's behind it
D2 is an open-source diagram scripting language that turns text into SVG, PNG, PDF, PPTX, GIF or ASCII diagrams. Agents run it as a local CLI, a Go library or the @d2lang/d2 WebAssembly package.
Good for Agents that need to produce or edit architecture, sequence, grid, SQL table or class diagrams as reviewable text and render them locally.
Is this your product? Claim this listing or verify it
Assessment. A single local command turns text into a diagram in six formats with no account, key or network call, and CI passes on the default branch. The language is at 0.9.0 with no stable release, its company sponsor has shut down, and one maintainer with limited time wrote every commit since July.
Facts
- Auth
- None
- Pricing
- Free · Free · OSS
- x402
- No
- Licence
- MPL-2.0
- Packages
npm@d2lang/d2gogithub.com/d2lang/d2ocid2lang/d2- Source
- github.com/d2lang/d2
- llms.txt
- not found
- Last release
- GitHub stars
- 26k
- npm / week
- 22k
- Surfaces
- CLI
d2, Go packagesd2lib(compile and render) andd2oracle(programmatic edits), and@d2lang/d20.1.34 for Node and browsers through WebAssembly - Export formats
- SVG (default), PNG, PDF, PPTX, GIF and ASCII text. PNG needs no browser since 0.9.0
- Commands
d2 in.d2 out.svg,d2 validate,d2 fmt(with--check),d2 layout,d2 themes,d2 play, and--watchfor live reload- Layout engines
- Dagre (default), ELK and TALA, all bundled as Go code. TALA takes fixed positions for chosen nodes and routes the rest
- Install
- Install script, Homebrew (0.9.0), release archives for six platforms, a Windows MSI, Docker image
d2lang/d2, orgo install. Binaries built with Go 1.27 need macOS 13 or newer - Limits
- 120 second default timeout (
--timeout). PNG up to 32,768 pixels a side. The FAQ says D2 is not tested on thousands of nodes - Telemetry
- None, per the FAQ, which adds that the CLI checks GitHub for new versions periodically
- Governance
- Fiscally sponsored by The Hack Foundation since August 2026, with a public fund at https://hcb.hackclub.com/d2. One lead maintainer
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- One command reads D2 from stdin and writes SVG, PNG, PDF, PPTX, GIF or ASCII to stdout, with no account or key
- MPL-2.0 throughout, and the TALA layout engine has been open source and bundled since 0.9.0 on 7 September 2026
d2 validateandd2 fmt --checklet an agent test a diagram before rendering it- The
d2oracleGo package creates, sets, moves, renames and deletes shapes without mutating the input graph - Release archives carry SHA-256 sums, signed provenance and SBOM attestations since 0.8.2
Weaknesses
- No 1.0 release. The maintainer lists a stable 1.0 with a formal grammar as a goal, and 0.8.2 changed Dagre and ELK layout output
- Terrastruct, the company that built D2, is shutting down. The project is now donation-funded under The Hack Foundation
- All 317 commits since 8 July 2026 are by one maintainer, who says his time on D2 is limited
- A security hardening pass merged on 11 and 12 September 2026 is not in a release yet, and the repository has no security policy
- No llms.txt, no machine-readable grammar and no MCP server. The maintainer rules out an MCP server and a hosted API
Before you call it notes for agents
- Check the exit status of
d2, never the output file. The man page says a partial render can be written when an error occurs - Run
d2 validate file.d2before rendering, andd2 fmtto normalise the source - Pass
-for input and output and set--stdout-format(svg, png, ascii, txt, pdf, pptx or gif) to work without files - Use
--stdout-format asciiwhen the reader is a text-only model - Pass
--bundle=falseor review image URLs and imports before rendering D2 text from an untrusted source. Release 0.9.0 fetches remote images when bundling
Who's behind it provenance 63/100
- Legal entity namedThe Hack Foundation (Hack Club), fiscal sponsor of the D2 project20/20
- Domain aged2lang.com, registered 2022-10-24 (3 years)7/15
- Endpoint on the vendor's domainno hosted endpointn/a
- Terms of servicenothing hosted, so the MPL-2.0 licence stands in10/10
- Privacy policynothing hosted, not scoredn/a
- Status pagenot found0/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service none to read
TL;DR Nothing is hosted by the vendor, so there are no terms of service to read. The MPL-2.0 licence stands in and the check scores in full.
Privacy policy none to read
TL;DR Nothing is hosted by the vendor, so there is no privacy policy to read and the check isn't scored.
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The sponsor page says D2 is fiscally sponsored by The Hack Foundation, the 501(c)(3) nonprofit behind Hack Club, after the lead maintainer donated the project in August 2026 (https://d2lang.com/sponsor/)
LICENSE.txt still reads Copyright 2022 Terrastruct Inc. The 5 September 2026 post says that company is shutting down, and terrastruct.com now redirects to d2lang.com
No terms or privacy document governs the software. The MPL-2.0 licence stands in
https://d2lang.com/.well-known/security.txt answered 404 on 8 October 2026, and the repository has no SECURITY.md
The repository moved from github.com/terrastruct/d2, which redirects, to github.com/d2lang/d2
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Notable
- D2 left Terrastruct for Hack Club. A post dated 5 September 2026 says the company is shutting down and D2 continues as a donation-funded project, with the maintainer's time limited source
- The same post rules out anything that needs a server. It lists no MCP server, no API, no user accounts and no server rendering source
- Release 0.9.0 on 7 September 2026 bundled TALA as open source and moved PNG, GIF, PDF and PPTX export to a built-in renderer with no browser source
- Release 0.8.2 replaced the embedded JavaScript Dagre, ELK and MathJax runtimes with Go ports, and its notes warn that node positions and edge routes change in some diagrams source
- Unreleased notes on the default branch list fixes that escape diagram values in SVG output, block image fetches to private networks by default and cap compiler expansion source
- The maintainer's post says all his future contributions will be written with AI source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 13.6 | |
Read with the local-software lines, because D2 runs on the owner's machine. Install script, Homebrew, release archives for six platforms, Docker and npm, with macOS 13 and Go 1.27 stated (20). The ci workflow passed on the last four pushes to the default branch, the latest on 2 October 2026, and the repository holds 497 Go test files (25). GitHub counts 535 open issues and pull requests, and the five outside issues opened since 13 September have no reply (12). Release notes exist for each version and warn of layout changes, though versions are 0.x and we found no note for the Go import path moving to github.com/d2lang/d2 (11). The latest release is 0.9.0, and the maintainer lists a stable 1.0 as a goal (0). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 10.6 | |
| Read as a CLI and library. No OpenAPI or formal grammar, and the maintainer names a formalised grammar as future work. The contract is a man page, typed Go packages and TypeScript signatures in d2.js (12). No llms.txt (HTTP 404), though the docs are Markdown in a public repository (3). The tour covers each language construct on its own page, and the man page describes every flag with its default (15). Flags are typed with defaults and environment variables, and d2.js lists its compile and render options (10). Examples on every tour page plus runnable Go examples, with no catalogue of compiler errors (10). Release notes for every version on the docs site and a separate d2.js changelog (15). | |||
| Agent ergonomics | 13%16.2 | 12.7 | |
One command with text in and a diagram out, and no tool definitions to load (22). --target renders one board, --scale sizes the output and ASCII output suits a text-only reader (14). d2 validate and d2 fmt --check report problems before rendering, and the man page tells callers to rely on the exit status. No list of error codes (13). Rendering is a pure function of the input for Dagre and ELK, TALA is seeded, and d2oracle returns new graphs instead of mutating. A partial file can be written on error (15). d2 in.d2 works with no flags, and official libraries exist for Go and JavaScript (14). | |||
| Security & auth | 14%17.5 | 8.4 | |
No credential exists to leak or scope (20). The CLI runs with the owner's file and network rights. Release 0.9.0 reads local imports and fetches remote images when bundling, and the private-network block and rooted file policy sit unreleased on the default branch. --bundle=false avoids fetches (8). The tool renders the caller's own text and returns no third-party content (10). --debug logs only (3). No SECURITY.md, security.txt or published advisories. Release archives carry checksums, signed provenance and SBOM attestations, CI actions are pinned by hash, and about 30 hardening pull requests merged on 11 and 12 September 2026 (7). | |||
| Payments & pricing | 10%12.5 | 7.5 | |
| Read with the self-hosted rule. Free MPL-2.0 software with nothing to buy and no payment protocol (0). No price to publish (20). No card or trial needed (20). An agent can install and run it with no signup (20). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.5 | |
Release 0.9.0 on 7 September 2026, 31 days before the check (20). Four tagged versions since 10 July, 0.8.0 and 0.8.1 on 6 August, 0.8.2 on 24 August and 0.9.0 (20). All 317 commits since 8 July are by one maintainer, who wrote on 5 September that his time is limited, and outside issues opened since 13 September have no reply (10). The Go library and @d2lang/d2 0.1.34 match 0.9.0 (15). Go 1.27, dependencies refreshed in 0.8.2 and CI on every push (9). | |||
| Transparency & trusteditorial 74, provenance 63 | 7%8.8 | 6.0 | |
MPL-2.0 for the language, the renderers and TALA (30). No privacy policy, and the software runs locally. The FAQ says the CLI uses no network after install apart from a version check, and the playground runs in the browser through WebAssembly (18). Release notes mark deprecated Go and d2.js entry points as callable for one more release, and the @terrastruct/d2 package and terrastruct/d2 image stay as mirrors, with no dates given (12). The FAQ states there is no telemetry. We found no documented switch for the version check (14). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 65.3 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 16 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on D2, or have the agent fetch /fixes/d2.md. A fix counts at the next check, once it's public.
Show it
# Fix list: D2 From Anchor Terminal's listing at https://www.anchorterminal.com/tools/d2, the October 2026 research run, assessed 8 October 2026. Grade B, 65.3 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on D2: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Security & auth, 48 out of 100, up to 9.1 more on the total Why it scored 48: No credential exists to leak or scope (20). The CLI runs with the owner's file and network rights. Release 0.9.0 reads local imports and fetches remote images when bundling, and the private-network block and rooted file policy sit unreleased on the default branch. `--bundle=false` avoids fetches (8). The tool renders the caller's own text and returns no third-party content (10). `--debug` logs only (3). No SECURITY.md, security.txt or published advisories. Release archives carry checksums, signed provenance and SBOM attestations, CI actions are pinned by hash, and about 30 hardening pull requests merged on 11 and 12 September 2026 (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 2. Reliability, 68 out of 100, up to 6.4 more on the total Why it scored 68: Read with the local-software lines, because D2 runs on the owner's machine. Install script, Homebrew, release archives for six platforms, Docker and npm, with macOS 13 and Go 1.27 stated (20). The `ci` workflow passed on the last four pushes to the default branch, the latest on 2 October 2026, and the repository holds 497 Go test files (25). GitHub counts 535 open issues and pull requests, and the five outside issues opened since 13 September have no reply (12). Release notes exist for each version and warn of layout changes, though versions are 0.x and we found no note for the Go import path moving to `github.com/d2lang/d2` (11). The latest release is 0.9.0, and the maintainer lists a stable 1.0 as a goal (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 3. Schema & documentation, 65 out of 100, up to 5.7 more on the total Why it scored 65: Read as a CLI and library. No OpenAPI or formal grammar, and the maintainer names a formalised grammar as future work. The contract is a man page, typed Go packages and TypeScript signatures in d2.js (12). No llms.txt (HTTP 404), though the docs are Markdown in a public repository (3). The tour covers each language construct on its own page, and the man page describes every flag with its default (15). Flags are typed with defaults and environment variables, and d2.js lists its compile and render options (10). Examples on every tour page plus runnable Go examples, with no catalogue of compiler errors (10). Release notes for every version on the docs site and a separate d2.js changelog (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 4. Payments & pricing, 60 out of 100, up to 5 more on the total Why it scored 60: Read with the self-hosted rule. Free MPL-2.0 software with nothing to buy and no payment protocol (0). No price to publish (20). No card or trial needed (20). An agent can install and run it with no signup (20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 5. Agent ergonomics, 78 out of 100, up to 3.6 more on the total Why it scored 78: One command with text in and a diagram out, and no tool definitions to load (22). `--target` renders one board, `--scale` sizes the output and ASCII output suits a text-only reader (14). `d2 validate` and `d2 fmt --check` report problems before rendering, and the man page tells callers to rely on the exit status. No list of error codes (13). Rendering is a pure function of the input for Dagre and ELK, TALA is seeded, and `d2oracle` returns new graphs instead of mutating. A partial file can be written on error (15). `d2 in.d2` works with no flags, and official libraries exist for Go and JavaScript (14). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 6. Transparency & trust, 69 out of 100, up to 2.7 more on the total Made of editorial 74, provenance 63. Why it scored 69: MPL-2.0 for the language, the renderers and TALA (30). No privacy policy, and the software runs locally. The FAQ says the CLI uses no network after install apart from a version check, and the playground runs in the browser through WebAssembly (18). Release notes mark deprecated Go and d2.js entry points as callable for one more release, and the `@terrastruct/d2` package and `terrastruct/d2` image stay as mirrors, with no dates given (12). The FAQ states there is no telemetry. We found no documented switch for the version check (14). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: d2lang.com, registered 2022-10-24 (3 years) (7 of 15) - Status page: not found (0 of 10) - security.txt: not found (0 of 10) ## 7. Maintenance & community, 74 out of 100, up to 2.3 more on the total Why it scored 74: Release 0.9.0 on 7 September 2026, 31 days before the check (20). Four tagged versions since 10 July, 0.8.0 and 0.8.1 on 6 August, 0.8.2 on 24 August and 0.9.0 (20). All 317 commits since 8 July are by one maintainer, who wrote on 5 September that his time is limited, and outside issues opened since 13 September have no reply (10). The Go library and `@d2lang/d2` 0.1.34 match 0.9.0 (15). Go 1.27, dependencies refreshed in 0.8.2 and CI on every push (9). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - Whether the version check the FAQ describes still exists. A search of the CLI source found no call to GitHub, and no opt-out is documented - Whether the Go import path change from `oss.terrastruct.com/d2` to `github.com/d2lang/d2` was announced. Release notes for 0.8.0 and 0.8.1 are not in the repository, and the notes for 0.8.2 and 0.9.0 do not mention it - Which legal entity now holds the copyright. LICENSE.txt names Terrastruct Inc., and the sponsor page names The Hack Foundation as fiscal sponsor - How many of the 535 open items are crash or regression reports. Only the 30 newest issues and pull requests were read - unchecked: d2studio.ai, the editor that app.terrastruct.com redirects to. It is a separate product and was not read - The lead named Terrastruct as vendor. Terrastruct is shutting down and the project is now under The Hack Foundation ## Weaknesses - No 1.0 release. The maintainer lists a stable 1.0 with a formal grammar as a goal, and 0.8.2 changed Dagre and ELK layout output - Terrastruct, the company that built D2, is shutting down. The project is now donation-funded under The Hack Foundation - All 317 commits since 8 July 2026 are by one maintainer, who says his time on D2 is limited - A security hardening pass merged on 11 and 12 September 2026 is not in a release yet, and the repository has no security policy - No llms.txt, no machine-readable grammar and no MCP server. The maintainer rules out an MCP server and a hosted API ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Check the exit status of `d2`, never the output file. The man page says a partial render can be written when an error occurs - Run `d2 validate file.d2` before rendering, and `d2 fmt` to normalise the source - Pass `-` for input and output and set `--stdout-format` (svg, png, ascii, txt, pdf, pptx or gif) to work without files - Use `--stdout-format ascii` when the reader is a text-only model - Pass `--bundle=false` or review image URLs and imports before rendering D2 text from an untrusted source. Release 0.9.0 fetches remote images when bundling ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- Whether the version check the FAQ describes still exists. A search of the CLI source found no call to GitHub, and no opt-out is documented
- Whether the Go import path change from
oss.terrastruct.com/d2togithub.com/d2lang/d2was announced. Release notes for 0.8.0 and 0.8.1 are not in the repository, and the notes for 0.8.2 and 0.9.0 do not mention it - Which legal entity now holds the copyright. LICENSE.txt names Terrastruct Inc., and the sponsor page names The Hack Foundation as fiscal sponsor
- How many of the 535 open items are crash or regression reports. Only the 30 newest issues and pull requests were read
- unchecked: d2studio.ai, the editor that app.terrastruct.com redirects to. It is a separate product and was not read
- The lead named Terrastruct as vendor. Terrastruct is shutting down and the project is now under The Hack Foundation
Sources 13
- repository, README, LICENSE, man page, CI workflow and changelogs (shallow clone) github.com · seen 2026-10-08
- announcement that D2 moved to Hack Club and Terrastruct is shutting down d2lang.com · seen 2026-10-08
- sponsor page naming The Hack Foundation as fiscal sponsor d2lang.com · seen 2026-10-08
- release notes for 0.9.0 d2lang.com · seen 2026-10-08
- unreleased changes on the default branch github.com · seen 2026-10-08
- d2oracle Go API docs d2lang.com · seen 2026-10-08
- docs source for the FAQ, exports and install pages github.com · seen 2026-10-08
- d2.js README and changelog github.com · seen 2026-10-08
- repository statistics, CI runs, releases, advisories and recent issues api.github.com · seen 2026-10-08
- npm package version and weekly downloads registry.npmjs.org · seen 2026-10-08
- Homebrew formula version formulae.brew.sh · seen 2026-10-08
- domain registration rdap.verisign.com · seen 2026-10-08
- robots.txt, llms.txt and security.txt checks d2lang.com · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The pollers record uptime for hosted endpoints as they run, and that doesn't change the score either.
Pricing & changes
Free Free · OSS Free under MPL-2.0 with nothing to buy. The TALA layout engine, once a paid plugin with a licence key, has been bundled and open source since 0.9.0. The project takes donations through a public Hack Club fund (https://d2lang.com/sponsor/).
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/d2.xml, or this listing's score history at history.json.
Connect
Install
curl -fsSL https://d2lang.com/install.sh | sh -s -- # or: brew install d2, go install github.com/d2lang/d2@latest, npm install @d2lang/d2
Through letme picks today, calling later
GET https://letme.dev/d2
letme picks this listing for diagram.edit, because it's the top-graded tool for the job.
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
draw.io + MCP BStructurizr + MCP CEraser API + MCP EPlantUML Btldraw SDK + MCP CLucid API + MCP C
Head to head Cloudviz API vs D2 · D2 vs Diagrams.so API + MCP · D2 vs Mural MCP · D2 vs Whimsical MCP · D2 vs draw.io + MCP · D2 vs Eraser API + MCP · D2 vs Lucid API + MCP · D2 vs Mermaid Chart MCP · D2 vs PlantUML · D2 vs Structurizr + MCP · D2 vs tldraw SDK + MCP
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| draw.io + MCP draw.io | B | 62.2 | diagram.create diagram.as-code diagram.edit diagram.export diagram.architecture | no |
| Structurizr + MCP Structurizr | C | 59.9 | diagram.create diagram.as-code diagram.edit diagram.export diagram.architecture | no |
| Eraser API + MCP Eraser | E | 38.6 | diagram.create diagram.as-code diagram.edit diagram.export diagram.architecture | no |
| PlantUML PlantUML project (Arnaud Roques) | B | 66.9 | diagram.as-code diagram.create diagram.export diagram.architecture | no |
| tldraw SDK + MCP tldraw | C | 60.7 | diagram.create diagram.as-code diagram.edit diagram.export | no |
| Lucid API + MCP Lucid Software | C | 60.6 | diagram.create diagram.as-code diagram.edit diagram.export | no |
Machine-readable
- JSON
/api/v1/tools/d2.json· historyhistory.json· badge/badges/d2.svg· changes feed/feeds/tools/d2.xml - Markdown
/tools/d2.md· slim/tools/d2.min.md(or sendAccept: text/markdown) - Fix list
/fixes/d2.md·/fixes/d2.json - From a terminal
anchor tool d2 --md(the CLI) · over MCPget_tool {"slug": "d2"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/d2"><img src="https://www.anchorterminal.com/badges/d2.svg" alt="D2 on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/d2)<a href="https://www.anchorterminal.com/tools/d2">D2 on Anchor Terminal</a>It counts on a page on d2lang.com or one of its subdomains, or the README of github.com/d2lang/d2.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "d2", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


