# D2 > D2 is an open-source diagram scripting language that turns text into SVG, PNG, PDF, PPTX, GIF or ASCII diagrams. Agents run it as a local CLI, a Go library or the @d2lang/d2 WebAssembly package. - Canonical: https://www.anchorterminal.com/tools/d2 - Markdown: https://www.anchorterminal.com/tools/d2.md (~5,400 tokens) - Slim: https://www.anchorterminal.com/tools/d2.min.md (~1,380 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/d2.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade B · 65.3/100 · rank #295 of 842 · #2 in Diagramming · not agent-ready · confidence medium** ## Assessment A single local command turns text into a diagram in six formats with no account, key or network call, and CI passes on the default branch. The language is at 0.9.0 with no stable release, its company sponsor has shut down, and one maintainer with limited time wrote every commit since July. ## Facts | Field | Value | | --- | --- | | Vendor | D2 project (The Hack Foundation) (https://d2lang.com) | | Kind | SDK + MCP | | Category | Diagramming (https://www.anchorterminal.com/categories/diagramming) | | Auth | None · No account, key or login. The CLI, the Go library and the WebAssembly package run on the owner's machine with the owner's file and network rights. `d2 --watch` serves a preview on localhost. | | Pricing | Free (Free · OSS) · Free under MPL-2.0 with nothing to buy. The TALA layout engine, once a paid plugin with a licence key, has been bundled and open source since 0.9.0. The project takes donations through a public Hack Club fund (https://d2lang.com/sponsor/). | | x402 | No · No x402, MPP or L402 in the docs or the source. The maintainer's 5 September 2026 post rules out any server-side service (checked 2026-10-08). | | Licence | MPL-2.0 | | Packages | npm: `@d2lang/d2`; go: `github.com/d2lang/d2`; oci: `d2lang/d2` | | Source | https://github.com/d2lang/d2 | | Docs | https://d2lang.com/tour/intro/ | | llms.txt | not found | | Last release | 2026-09-07 | | GitHub stars | 25,581 (as of 2026-10-08) | | npm downloads / week | 21,627 | | Surfaces | CLI `d2`, Go packages `d2lib` (compile and render) and `d2oracle` (programmatic edits), and `@d2lang/d2` 0.1.34 for Node and browsers through WebAssembly | | Export formats | SVG (default), PNG, PDF, PPTX, GIF and ASCII text. PNG needs no browser since 0.9.0 | | Commands | `d2 in.d2 out.svg`, `d2 validate`, `d2 fmt` (with `--check`), `d2 layout`, `d2 themes`, `d2 play`, and `--watch` for live reload | | Layout engines | Dagre (default), ELK and TALA, all bundled as Go code. TALA takes fixed positions for chosen nodes and routes the rest | | Install | Install script, Homebrew (0.9.0), release archives for six platforms, a Windows MSI, Docker image `d2lang/d2`, or `go install`. Binaries built with Go 1.27 need macOS 13 or newer | | Limits | 120 second default timeout (`--timeout`). PNG up to 32,768 pixels a side. The FAQ says D2 is not tested on thousands of nodes | | Telemetry | None, per the FAQ, which adds that the CLI checks GitHub for new versions periodically | | Governance | Fiscally sponsored by The Hack Foundation since August 2026, with a public fund at https://hcb.hackclub.com/d2. One lead maintainer | | Capabilities | diagram.as-code, diagram.create, diagram.export, diagram.edit, diagram.architecture | | Tags | open-source, local, cli, go, wasm, diagram-as-code, no-auth, free, non-profit, docker | | JSON | https://www.anchorterminal.com/api/v1/tools/d2.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 68 | 13.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 65 | 10.6 | | Agent ergonomics | 13% | 16.2 | 78 | 12.7 | | Security & auth | 14% | 17.5 | 48 | 8.4 | | Payments & pricing | 10% | 12.5 | 60 | 7.5 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 74 | 6.5 | | Transparency & trust (editorial 74, provenance 63) | 7% | 8.8 | 69 | 6.0 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **65.3 → B** | ### Why each score - Reliability 68: Read with the local-software lines, because D2 runs on the owner's machine. Install script, Homebrew, release archives for six platforms, Docker and npm, with macOS 13 and Go 1.27 stated (20). The `ci` workflow passed on the last four pushes to the default branch, the latest on 2 October 2026, and the repository holds 497 Go test files (25). GitHub counts 535 open issues and pull requests, and the five outside issues opened since 13 September have no reply (12). Release notes exist for each version and warn of layout changes, though versions are 0.x and we found no note for the Go import path moving to `github.com/d2lang/d2` (11). The latest release is 0.9.0, and the maintainer lists a stable 1.0 as a goal (0). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 65: Read as a CLI and library. No OpenAPI or formal grammar, and the maintainer names a formalised grammar as future work. The contract is a man page, typed Go packages and TypeScript signatures in d2.js (12). No llms.txt (HTTP 404), though the docs are Markdown in a public repository (3). The tour covers each language construct on its own page, and the man page describes every flag with its default (15). Flags are typed with defaults and environment variables, and d2.js lists its compile and render options (10). Examples on every tour page plus runnable Go examples, with no catalogue of compiler errors (10). Release notes for every version on the docs site and a separate d2.js changelog (15). - Agent ergonomics 78: One command with text in and a diagram out, and no tool definitions to load (22). `--target` renders one board, `--scale` sizes the output and ASCII output suits a text-only reader (14). `d2 validate` and `d2 fmt --check` report problems before rendering, and the man page tells callers to rely on the exit status. No list of error codes (13). Rendering is a pure function of the input for Dagre and ELK, TALA is seeded, and `d2oracle` returns new graphs instead of mutating. A partial file can be written on error (15). `d2 in.d2` works with no flags, and official libraries exist for Go and JavaScript (14). - Security & auth 48: No credential exists to leak or scope (20). The CLI runs with the owner's file and network rights. Release 0.9.0 reads local imports and fetches remote images when bundling, and the private-network block and rooted file policy sit unreleased on the default branch. `--bundle=false` avoids fetches (8). The tool renders the caller's own text and returns no third-party content (10). `--debug` logs only (3). No SECURITY.md, security.txt or published advisories. Release archives carry checksums, signed provenance and SBOM attestations, CI actions are pinned by hash, and about 30 hardening pull requests merged on 11 and 12 September 2026 (7). - Payments & pricing 60: Read with the self-hosted rule. Free MPL-2.0 software with nothing to buy and no payment protocol (0). No price to publish (20). No card or trial needed (20). An agent can install and run it with no signup (20). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 74: Release 0.9.0 on 7 September 2026, 31 days before the check (20). Four tagged versions since 10 July, 0.8.0 and 0.8.1 on 6 August, 0.8.2 on 24 August and 0.9.0 (20). All 317 commits since 8 July are by one maintainer, who wrote on 5 September that his time is limited, and outside issues opened since 13 September have no reply (10). The Go library and `@d2lang/d2` 0.1.34 match 0.9.0 (15). Go 1.27, dependencies refreshed in 0.8.2 and CI on every push (9). - Transparency & trust 69: MPL-2.0 for the language, the renderers and TALA (30). No privacy policy, and the software runs locally. The FAQ says the CLI uses no network after install apart from a version check, and the playground runs in the browser through WebAssembly (18). Release notes mark deprecated Go and d2.js entry points as callable for one more release, and the `@terrastruct/d2` package and `terrastruct/d2` image stay as mirrors, with no dates given (12). The FAQ states there is no telemetry. We found no documented switch for the version check (14). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (16 items): https://www.anchorterminal.com/fixes/d2.md (JSON https://www.anchorterminal.com/fixes/d2.json) ### What we couldn't check - Whether the version check the FAQ describes still exists. A search of the CLI source found no call to GitHub, and no opt-out is documented - Whether the Go import path change from `oss.terrastruct.com/d2` to `github.com/d2lang/d2` was announced. Release notes for 0.8.0 and 0.8.1 are not in the repository, and the notes for 0.8.2 and 0.9.0 do not mention it - Which legal entity now holds the copyright. LICENSE.txt names Terrastruct Inc., and the sponsor page names The Hack Foundation as fiscal sponsor - How many of the 535 open items are crash or regression reports. Only the 30 newest issues and pull requests were read - unchecked: d2studio.ai, the editor that app.terrastruct.com redirects to. It is a separate product and was not read - The lead named Terrastruct as vendor. Terrastruct is shutting down and the project is now under The Hack Foundation ### Sources - repository, README, LICENSE, man page, CI workflow and changelogs (shallow clone): (seen 2026-10-08) - announcement that D2 moved to Hack Club and Terrastruct is shutting down: (seen 2026-10-08) - sponsor page naming The Hack Foundation as fiscal sponsor: (seen 2026-10-08) - release notes for 0.9.0: (seen 2026-10-08) - unreleased changes on the default branch: (seen 2026-10-08) - d2oracle Go API docs: (seen 2026-10-08) - docs source for the FAQ, exports and install pages: (seen 2026-10-08) - d2.js README and changelog: (seen 2026-10-08) - repository statistics, CI runs, releases, advisories and recent issues: (seen 2026-10-08) - npm package version and weekly downloads: (seen 2026-10-08) - Homebrew formula version: (seen 2026-10-08) - domain registration: (seen 2026-10-08) - robots.txt, llms.txt and security.txt checks: (seen 2026-10-08) ## Who's behind it (provenance 63/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | The Hack Foundation (Hack Club), fiscal sponsor of the D2 project | 20/20 | | Domain age | d2lang.com, registered 2022-10-24 (3 years) | 7/15 | | Endpoint on the vendor's domain | no hosted endpoint | n/a | | Terms of service | nothing hosted, so the MPL-2.0 licence stands in | 10/10 | | Privacy policy | nothing hosted, not scored | n/a | | Status page | not found | 0/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The sponsor page says D2 is fiscally sponsored by The Hack Foundation, the 501(c)(3) nonprofit behind Hack Club, after the lead maintainer donated the project in August 2026 (https://d2lang.com/sponsor/) LICENSE.txt still reads Copyright 2022 Terrastruct Inc. The 5 September 2026 post says that company is shutting down, and terrastruct.com now redirects to d2lang.com No terms or privacy document governs the software. The MPL-2.0 licence stands in https://d2lang.com/.well-known/security.txt answered 404 on 8 October 2026, and the repository has no SECURITY.md The repository moved from github.com/terrastruct/d2, which redirects, to github.com/d2lang/d2 ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service**. Nothing is hosted by the vendor, so there are no terms of service to read. The MPL-2.0 licence stands in and the check scores in full. **Privacy policy**. Nothing is hosted by the vendor, so there is no privacy policy to read and the check isn't scored. ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - One command reads D2 from stdin and writes SVG, PNG, PDF, PPTX, GIF or ASCII to stdout, with no account or key - MPL-2.0 throughout, and the TALA layout engine has been open source and bundled since 0.9.0 on 7 September 2026 - `d2 validate` and `d2 fmt --check` let an agent test a diagram before rendering it - The `d2oracle` Go package creates, sets, moves, renames and deletes shapes without mutating the input graph - Release archives carry SHA-256 sums, signed provenance and SBOM attestations since 0.8.2 ## Weaknesses - No 1.0 release. The maintainer lists a stable 1.0 with a formal grammar as a goal, and 0.8.2 changed Dagre and ELK layout output - Terrastruct, the company that built D2, is shutting down. The project is now donation-funded under The Hack Foundation - All 317 commits since 8 July 2026 are by one maintainer, who says his time on D2 is limited - A security hardening pass merged on 11 and 12 September 2026 is not in a release yet, and the repository has no security policy - No llms.txt, no machine-readable grammar and no MCP server. The maintainer rules out an MCP server and a hosted API ## Before you call it (notes for agents) 1. Check the exit status of `d2`, never the output file. The man page says a partial render can be written when an error occurs 2. Run `d2 validate file.d2` before rendering, and `d2 fmt` to normalise the source 3. Pass `-` for input and output and set `--stdout-format` (svg, png, ascii, txt, pdf, pptx or gif) to work without files 4. Use `--stdout-format ascii` when the reader is a text-only model 5. Pass `--bundle=false` or review image URLs and imports before rendering D2 text from an untrusted source. Release 0.9.0 fetches remote images when bundling ## Connect Install: ```bash curl -fsSL https://d2lang.com/install.sh | sh -s -- # or: brew install d2, go install github.com/d2lang/d2@latest, npm install @d2lang/d2 ``` Through letme (picks today, calling later): https://letme.dev/d2 (letme picks it for diagram.edit, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | draw.io + MCP | B | 62.2 | 397 | diagram.create, diagram.as-code, diagram.edit, diagram.export, diagram.architecture | no | https://www.anchorterminal.com/tools/drawio.md | | Structurizr + MCP | C | 59.9 | 483 | diagram.create, diagram.as-code, diagram.edit, diagram.export, diagram.architecture | no | https://www.anchorterminal.com/tools/structurizr.md | | Eraser API + MCP | E | 38.6 | 811 | diagram.create, diagram.as-code, diagram.edit, diagram.export, diagram.architecture | no | https://www.anchorterminal.com/tools/eraser.md | | PlantUML | B | 66.9 | 251 | diagram.as-code, diagram.create, diagram.export, diagram.architecture | no | https://www.anchorterminal.com/tools/plantuml.md | | tldraw SDK + MCP | C | 60.7 | 451 | diagram.create, diagram.as-code, diagram.edit, diagram.export | no | https://www.anchorterminal.com/tools/tldraw.md | | Lucid API + MCP | C | 60.6 | 455 | diagram.create, diagram.as-code, diagram.edit, diagram.export | no | https://www.anchorterminal.com/tools/lucid.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - D2 left Terrastruct for Hack Club. A post dated 5 September 2026 says the company is shutting down and D2 continues as a donation-funded project, with the maintainer's time limited (source: ) - The same post rules out anything that needs a server. It lists no MCP server, no API, no user accounts and no server rendering (source: ) - Release 0.9.0 on 7 September 2026 bundled TALA as open source and moved PNG, GIF, PDF and PPTX export to a built-in renderer with no browser (source: ) - Release 0.8.2 replaced the embedded JavaScript Dagre, ELK and MathJax runtimes with Go ports, and its notes warn that node positions and edge routes change in some diagrams (source: ) - Unreleased notes on the default branch list fixes that escape diagram values in SVG output, block image fetches to private networks by default and cap compiler expansion (source: ) - The maintainer's post says all his future contributions will be written with AI (source: ) ## Compare - [Cloudviz API vs D2](https://www.anchorterminal.com/compare/cloudviz-vs-d2.md): F 37.7 vs B 65.3 - [D2 vs Diagrams.so API + MCP](https://www.anchorterminal.com/compare/d2-vs-diagrams-so.md): B 65.3 vs C 60 - [D2 vs Mural MCP](https://www.anchorterminal.com/compare/d2-vs-mural-mcp.md): B 65.3 vs E 41.9 - [D2 vs Whimsical MCP](https://www.anchorterminal.com/compare/d2-vs-whimsical.md): B 65.3 vs D 52.6 - [D2 vs draw.io + MCP](https://www.anchorterminal.com/compare/d2-vs-drawio.md): B 65.3 vs B 62.2 - [D2 vs Eraser API + MCP](https://www.anchorterminal.com/compare/d2-vs-eraser.md): B 65.3 vs E 38.6 - [D2 vs Lucid API + MCP](https://www.anchorterminal.com/compare/d2-vs-lucid.md): B 65.3 vs C 60.6 - [D2 vs Mermaid Chart MCP](https://www.anchorterminal.com/compare/d2-vs-mermaid-chart.md): B 65.3 vs F 31.4 - [D2 vs PlantUML](https://www.anchorterminal.com/compare/d2-vs-plantuml.md): B 65.3 vs B 66.9 - [D2 vs Structurizr + MCP](https://www.anchorterminal.com/compare/d2-vs-structurizr.md): B 65.3 vs C 59.9 - [D2 vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/d2-vs-tldraw.md): B 65.3 vs C 60.7 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on d2lang.com or one of its subdomains, or the README of github.com/d2lang/d2. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "d2", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html D2 on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![D2 on Anchor Terminal](https://www.anchorterminal.com/badges/d2.svg)](https://www.anchorterminal.com/tools/d2) ``` Plain link: ```html D2 on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say D2 is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/d2-dark.png - Light: https://www.anchorterminal.com/assets/share/d2-light.png