# Kroki (slim) > Kroki is an open-source HTTP server from Yuzu tech that converts diagram text in 29 formats, including PlantUML, Mermaid, GraphViz and D2, into SVG, PNG or PDF. Owners run it from Docker images, and kroki.io is a free public instance. - Full: https://www.anchorterminal.com/tools/kroki.md (~6,500 tokens) · this version ~1,730 tokens · JSON https://www.anchorterminal.com/tools/kroki.json · canonical https://www.anchorterminal.com/tools/kroki - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **C · 59.2/100 · rank #558 of 950 · #8 in Diagramming · not agent-ready · confidence medium** Assessment: One unauthenticated POST with diagram text returns an image for 29 diagram types, and five versions shipped between 15 July and 5 October 2026. Four advisories were published in July and August 2026, one an unauthenticated remote code execution on `/tikz/svg`, all fixed. No OpenAPI file exists, and the public instance has no terms, privacy policy or status page. ## Facts - Kind: HTTP API · vendor: Yuzu tech · category: Diagramming · legal entity: Yuzu tech, a French software firm. No registered legal form found · provenance 56/100 - Local only (HTTP): oci `yuzutech/kroki`, oci `yuzutech/kroki-mermaid`, oci `yuzutech/kroki-bpmn`, oci `yuzutech/kroki-excalidraw` - Auth: None · pricing: Free · x402: no · licence: MIT - Probe metrics: not measured yet (probes haven't run) - Surfaces: HTTP API on a self-hosted gateway server (Java, Vert.x) or the public instance at https://kroki.io. A separate Go CLI, `kroki`, calls either - Requests: `GET ///`, `POST /` with `diagram_source`, `diagram_type`, `output_format` and optional `diagram_options`, or `POST /` and `POST //` with a plain text or JSON body - Diagram types: 29 on the home page. ActDiag, BlockDiag, BPMN, Bytefield, C4 with PlantUML, D2, DBML, Ditaa, Erd, Excalidraw, GoAT, GraphViz, Mermaid, Nomnoml, NwDiag, PacketDiag, Pikchr, PlantUML, RackDiag, SeqDiag, Structurizr, Svgbob, Symbolator, TikZ, UMlet, Vega, Vega-Lite, WaveDrom and WireViz. diagrams.net is experimental - Export formats: SVG for every type. PNG for 18, PDF for 14, JPEG for four, and `txt` and `base64` for PlantUML, C4 and Structurizr, per the home page table - Containers: `yuzutech/kroki` is the gateway with 25 endpoints built in. Mermaid, BPMN, Excalidraw and diagrams.net run in companion containers `yuzutech/kroki-mermaid`, `-bpmn`, `-excalidraw` and `-diagramsnet` - Safe mode: `KROKI_SAFE_MODE` is `SECURE` by default, with `SAFE` and `UNSAFE`. `SECURE` maps PlantUML to its `SANDBOX` profile and Structurizr to restricted mode - Limits: 5 seconds for a diagram binary, 20 for a Java library, 30 for a companion and 10 for a Mermaid render. URI 4,096 characters, headers 8,192, Mermaid source 50,000 characters and 500 edges. All set by environment variables - Errors: HTTP status with a body in the format the Accept header asks for, JSON `{"error": {"code", "message"}}`, plain text, HTML or an SVG image of the message (from `ErrorHandler.java`) - Operations: `GET /health` (also `/v1/health` and `/healthz`) lists library versions, `GET /metrics`, OpenTelemetry tracing by environment variable, and TLS with `KROKI_SSL` - Public instance: https://kroki.io, free and paid for by sponsors, with no key. No terms, privacy policy, status page or rate limit is published. The CLI page says the demonstration server is for reasonable, non-commercial use with no uptime guarantee - Scores: Reliability 74, Performance pending, Schema & documentation 48, Agent ergonomics 70, Security & auth 56, Payments & pricing 60, Task success pending, Maintenance & community 86, Transparency & trust 62 · negative events -5 · total over the 7 assessed categories - Why: Reliability, Read with the local-software lines, because the listing grades the server an owner runs. · Schema & documentation, No OpenAPI file or other machine-readable contract. · Agent ergonomics, One request with diagram text in and an image out, and no tool definitions to load. · Security & auth, No credential exists to leak or scope. · Payments & pricing, Read with the self-hosted rule. · Maintenance & community, Version 0.33.0 on 5 October 2026, four days before the check (30). · Transparency & trust, MIT licence, with every component in one public repository (30). - Sources: 14, open questions: 9, both in the full twin - Capabilities: diagram.as-code, diagram.create, diagram.export, diagram.architecture - JSON: https://www.anchorterminal.com/api/v1/tools/kroki.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/kroki.svg` or a link to https://www.anchorterminal.com/tools/kroki from a page on kroki.io or one of its subdomains, or the README of github.com/yuzutech/kroki, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `POST //` with `Content-Type: text/plain` and the diagram as the body. This avoids the deflate and base64 encoding that GET needs 2. Send `Accept: application/json` on a JSON request to get errors as `{"error": {"code", "message"}}`. With an SVG Accept header the error arrives as an image 3. Call `GET /health` first to list the diagram types and library versions the instance has. Mermaid, BPMN, Excalidraw and diagrams.net need companion containers 4. Run 0.32.1 or later before rendering untrusted text. Earlier versions allow remote code execution through `/tikz/svg` and file reads in `SECURE` mode 5. Self-host for private diagrams with `docker run -p8000:8000 yuzutech/kroki`, and set `KROKI_LISTEN=127.0.0.1:8000` or a network rule, since the server has no authentication ## Connect ```bash docker run -p8000:8000 yuzutech/kroki ``` ```bash curl https://kroki.io/graphviz/svg --data-raw 'digraph G {Hello->World}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/kroki ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | PlantUML | B | 66.9 | diagram.as-code, diagram.create, diagram.export, diagram.architecture | https://www.anchorterminal.com/tools/plantuml.min.md | | D2 | B | 65.3 | diagram.as-code, diagram.create, diagram.export, diagram.architecture | https://www.anchorterminal.com/tools/d2.min.md | | draw.io + MCP | B | 62.2 | diagram.create, diagram.as-code, diagram.export, diagram.architecture | https://www.anchorterminal.com/tools/drawio.min.md | | Structurizr + MCP | C | 59.9 | diagram.create, diagram.as-code, diagram.export, diagram.architecture | https://www.anchorterminal.com/tools/structurizr.min.md | | Eraser API + MCP | E | 38.6 | diagram.create, diagram.as-code, diagram.export, diagram.architecture | https://www.anchorterminal.com/tools/eraser.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)