{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "subframe",
    "name": "Subframe",
    "vendor": "Atomic Design Inc",
    "vendorUrl": "https://www.subframe.com",
    "kind": "mcp",
    "category": "design",
    "summary": "Design tool from Atomic Design Inc for React and Tailwind interfaces, with a cloud canvas and a macOS app. Agents read and edit pages, components and themes through a hosted MCP server, and a CLI syncs components into a codebase.",
    "url": "https://www.anchorterminal.com/tools/subframe",
    "markdownUrl": "https://www.anchorterminal.com/tools/subframe.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/subframe.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/subframe.json",
    "repo": "https://github.com/SubframeApp/subframe",
    "license": "Proprietary service under Atomic Design's terms of service. `@subframe/cli` and `@subframe/core` are marked ISC in their package files and the Claude Code plugin MIT in its manifest, with no licence file in the repository",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://mcp.subframe.com/mcp",
    "packages": [
      {
        "registry": "npm",
        "name": "@subframe/cli"
      },
      {
        "registry": "npm",
        "name": "@subframe/core"
      }
    ],
    "auth": "mixed",
    "authNotes": "The MCP server takes OAuth only, with dynamic client registration and PKCE, and a person approves access in a browser. Subframe access tokens are not accepted there. What an agent can do follows the user's team role. Admins and Editors can write, and Viewers get a read-only server. The CLI takes an auth token from `SUBFRAME_AUTH_TOKEN` or `--auth-token`, created at app.subframe.com/cli/auth or by the `generate_auth_token` MCP tool. Tokens are shown once and can be deleted. No token scopes or expiry are documented. Access is self-serve.",
    "pricing": "freemium",
    "pricingNotes": "Free at $0 with one project, unlimited pages and members, and MCP and CLI access, so an agent's owner can start without a contract. Pro is $20 an editor a month for unlimited projects and six times the AI credits. Viewers are free on every plan. Custom plans are priced on request. MCP calls are not priced separately (https://www.subframe.com/, checked 2026-10-09).",
    "priceSummary": "$20 / seat-mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs, the pricing section or the CLI source (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": 46,
    "popularity": {
      "githubStars": 435,
      "npmWeekly": 1006,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://docs.subframe.com",
    "mcpTools": {
      "url": "https://mcp.subframe.com/mcp",
      "checkedAt": "2026-10-09T21:40:55.87387771Z",
      "status": "auth",
      "note": "asks for credentials before listing its tools",
      "changedAt": "2026-10-09T21:40:55.87387771Z"
    },
    "llmsTxt": "https://docs.subframe.com/llms.txt",
    "capabilities": [
      "design.files",
      "design.components",
      "design.code",
      "design.canvas",
      "design.comments"
    ],
    "tags": [
      "hosted",
      "mcp",
      "oauth",
      "remote-mcp",
      "cli",
      "agent-skills",
      "react",
      "tailwind",
      "design-to-code",
      "freemium",
      "free-tier",
      "llms-txt",
      "closed-source",
      "macos"
    ],
    "lastRelease": "2026-10-08",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 39.7,
      "grade": "E",
      "agentReady": false,
      "rank": 915,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 9,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 47,
        "maintenance": 65,
        "payments": 33,
        "reliability": 19,
        "schema": 54,
        "security": 44,
        "transparency": 57
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 19,
          "points": 3.8,
          "reason": "Read with the hosted lines, because the surface an agent uses is the MCP server at mcp.subframe.com. No status page was found on the site, the docs or the footer (0 of 20). With no page there is no incident history to read (5 of 30). No rate limit is published in the docs or the skill files (0 of 15). No 429 or backoff guidance was found. The docs do say a background job that stops reporting for about 10 minutes is returned as `error`, and the CLI retries a failed request once (4 of 15). No SLA is published, and the terms say the service is not warranted to be uninterrupted (0 of 10). The MCP server carries no beta label, though the CLI's `push-component` command is marked experimental (10 of 10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 54,
          "points": 8.78,
          "reason": "The MCP server is closed and answers 401 without OAuth, so the tool definitions and their input schemas were not read. The docs list 46 tools by name and the public skill files give parameters for most of them (12 of 25, on that partial evidence). docs.subframe.com publishes `llms.txt`, a Markdown twin of each page and a docs MCP server (10 of 10). The `design` skill states for each tool what it is for and when another tool fits better, for example `edit_page` against `design_page`. The docs table gives one line a tool (15 of 20). Parameters are named in the skill (`id`, `name` or `url`, `force`, `deleteChildPages`, `includeResolved`), while the design tools take a free-text description (6 of 15). Ten example prompts and a troubleshooting section, with no list of error responses (7 of 15). The plugin and the CLI carry version numbers, with no changelog (4 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 47,
          "points": 7.64,
          "reason": "46 documented tools is over 30 (5), with 3 added back because a Viewer account gets a read-only server. No toolsets or dynamic loading are documented, and the `design` skill adds about 55 KB when loaded (8 of 25). `list_comments` can be scoped to a page, a canvas or the project, screenshots can target one element or breakpoint and `read_prototype_file` returns one file. No paging is documented (10 of 20). `wait_for_jobs` reports `running`, `done`, `error` or `not_found`, delete tools refuse when the item is referenced, `edit_page` returns `appliedCode` and parser warnings, and the CLI prints a JSON error envelope (13 of 20). No idempotency keys. Tool annotations could not be read. Deletes need `force` when references exist, and version history can restore (8 of 20). `projectId` falls back to the first project and items are addressed by id, name or URL. No API SDK (8 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 44,
          "points": 7.7,
          "reason": "The MCP server uses OAuth with dynamic client registration, PKCE and refresh tokens, and rejects static tokens. The authorisation server lists only identity scopes (openid, profile, email, phone, offline_access), so access follows the user's team role and not a scope. CLI tokens are shown once and can be deleted, with no scopes or expiry documented, and the `generate_auth_token` tool lets a connected agent mint one (22 of 30). Viewers get a read-only MCP server and read-only CLI access. Confirmation before deletes is guidance in the skill file and not a documented server control (12 of 20). `list_comments`, design documents and `search_docs` return text other people wrote, and no prompt-injection guidance was found (3 of 15). No audit log is documented. Version history records changes for 24 hours on Free and 7 days on Pro (3 of 15). No security.txt, disclosure policy, bug bounty or certification was found. The DPA's Annex 2 lists security measures and the docs cover Okta SSO (4 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 33,
          "points": 4.13,
          "reason": "No machine payment protocol (0 of 40). Plan prices are public, Free at $0 and Pro at $20 an editor a month, with AI credits described only as limited and 6x and no per-call price (10 of 20). The Free plan has one project and includes MCP and CLI access, and the docs mention a card only at the Stripe checkout for Pro (20 of 20). A person has to sign in through a browser to approve OAuth. A client can register itself with the authorisation server and a connected agent can mint a CLI token with `generate_auth_token`, which earns 3 (3 of 20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 65,
          "points": 5.69,
          "reason": "The Claude Code plugin reached 1.0.30 on 8 October 2026 and `@subframe/cli` 1.212.0 on 5 October 2026 (30 of 30). The plugin version changed ten times between 13 July and 8 October, and the CLI had three versions on 5 October after none since 24 June (20 of 20). The repository has 13 issues in all. Seven are open, among them a Codex MCP install error from 30 March 2026 and a Claude Code plugin install error from 13 February 2026 with one and two comments, and three with none. Pull requests merge most days. The Slack community was not read (10 of 25). A search of the official MCP registry for 'subframe' returned no entry (0 of 15). A commit of 12 August 2026 fixed dependency vulnerabilities. The CLI has unit and end-to-end tests in the repository, and the only public workflow publishes the package (5 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 57,
          "points": 4.99,
          "note": "editorial 46, provenance 68",
          "reason": "The service is closed under terms of service dated 22 January 2026. The CLI and `@subframe/core` are public and marked ISC in their package files, and the plugin MIT in its manifest, but the repository has no licence file (17 of 30). Terms, privacy policy (22 January 2026) and DPA (21 January 2026) agree with each other. The privacy policy gives no retention periods, and the terms say 'Unless Customer is notified otherwise, Customer Data is not used to train AI models', which leaves the default open to change by notice (15 of 30). No deprecation policy. A migration page explains the move to component directories, and three MCP tools were renamed with no notice found (4 of 20). The DPA links a sub-processor list held in a Google Sheet, which we did not read. The privacy policy names Google Analytics, PostHog, Segment and LogRocket, and the CLI's README discloses crash and usage reporting with `DO_NOT_TRACK=1` as the opt-out (10 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "46 documented tools is over 30 (5), with 3 added back because a Viewer account gets a read-only server. No toolsets or dynamic loading are documented, and the `design` skill adds about 55 KB when loaded (8 of 25). `list_comments` can be scoped to a page, a canvas or the project, screenshots can target one element or breakpoint and `read_prototype_file` returns one file. No paging is documented (10 of 20). `wait_for_jobs` reports `running`, `done`, `error` or `not_found`, delete tools refuse when the item is referenced, `edit_page` returns `appliedCode` and parser warnings, and the CLI prints a JSON error envelope (13 of 20). No idempotency keys. Tool annotations could not be read. Deletes need `force` when references exist, and version history can restore (8 of 20). `projectId` falls back to the first project and items are addressed by id, name or URL. No API SDK (8 of 15).",
          "maintenance": "The Claude Code plugin reached 1.0.30 on 8 October 2026 and `@subframe/cli` 1.212.0 on 5 October 2026 (30 of 30). The plugin version changed ten times between 13 July and 8 October, and the CLI had three versions on 5 October after none since 24 June (20 of 20). The repository has 13 issues in all. Seven are open, among them a Codex MCP install error from 30 March 2026 and a Claude Code plugin install error from 13 February 2026 with one and two comments, and three with none. Pull requests merge most days. The Slack community was not read (10 of 25). A search of the official MCP registry for 'subframe' returned no entry (0 of 15). A commit of 12 August 2026 fixed dependency vulnerabilities. The CLI has unit and end-to-end tests in the repository, and the only public workflow publishes the package (5 of 10).",
          "payments": "No machine payment protocol (0 of 40). Plan prices are public, Free at $0 and Pro at $20 an editor a month, with AI credits described only as limited and 6x and no per-call price (10 of 20). The Free plan has one project and includes MCP and CLI access, and the docs mention a card only at the Stripe checkout for Pro (20 of 20). A person has to sign in through a browser to approve OAuth. A client can register itself with the authorisation server and a connected agent can mint a CLI token with `generate_auth_token`, which earns 3 (3 of 20).",
          "reliability": "Read with the hosted lines, because the surface an agent uses is the MCP server at mcp.subframe.com. No status page was found on the site, the docs or the footer (0 of 20). With no page there is no incident history to read (5 of 30). No rate limit is published in the docs or the skill files (0 of 15). No 429 or backoff guidance was found. The docs do say a background job that stops reporting for about 10 minutes is returned as `error`, and the CLI retries a failed request once (4 of 15). No SLA is published, and the terms say the service is not warranted to be uninterrupted (0 of 10). The MCP server carries no beta label, though the CLI's `push-component` command is marked experimental (10 of 10).",
          "schema": "The MCP server is closed and answers 401 without OAuth, so the tool definitions and their input schemas were not read. The docs list 46 tools by name and the public skill files give parameters for most of them (12 of 25, on that partial evidence). docs.subframe.com publishes `llms.txt`, a Markdown twin of each page and a docs MCP server (10 of 10). The `design` skill states for each tool what it is for and when another tool fits better, for example `edit_page` against `design_page`. The docs table gives one line a tool (15 of 20). Parameters are named in the skill (`id`, `name` or `url`, `force`, `deleteChildPages`, `includeResolved`), while the design tools take a free-text description (6 of 15). Ten example prompts and a troubleshooting section, with no list of error responses (7 of 15). The plugin and the CLI carry version numbers, with no changelog (4 of 15).",
          "security": "The MCP server uses OAuth with dynamic client registration, PKCE and refresh tokens, and rejects static tokens. The authorisation server lists only identity scopes (openid, profile, email, phone, offline_access), so access follows the user's team role and not a scope. CLI tokens are shown once and can be deleted, with no scopes or expiry documented, and the `generate_auth_token` tool lets a connected agent mint one (22 of 30). Viewers get a read-only MCP server and read-only CLI access. Confirmation before deletes is guidance in the skill file and not a documented server control (12 of 20). `list_comments`, design documents and `search_docs` return text other people wrote, and no prompt-injection guidance was found (3 of 15). No audit log is documented. Version history records changes for 24 hours on Free and 7 days on Pro (3 of 15). No security.txt, disclosure policy, bug bounty or certification was found. The DPA's Annex 2 lists security measures and the docs cover Okta SSO (4 of 20).",
          "transparency": "The service is closed under terms of service dated 22 January 2026. The CLI and `@subframe/core` are public and marked ISC in their package files, and the plugin MIT in its manifest, but the repository has no licence file (17 of 30). Terms, privacy policy (22 January 2026) and DPA (21 January 2026) agree with each other. The privacy policy gives no retention periods, and the terms say 'Unless Customer is notified otherwise, Customer Data is not used to train AI models', which leaves the default open to change by notice (15 of 30). No deprecation policy. A migration page explains the move to component directories, and three MCP tools were renamed with no notice found (4 of 20). The DPA links a sub-processor list held in a Google Sheet, which we did not read. The privacy policy names Google Analytics, PostHog, Segment and LogRocket, and the CLI's README discloses crash and usage reporting with `DO_NOT_TRACK=1` as the opt-out (10 of 20)."
        },
        "sources": [
          {
            "what": "home page, plans and prices",
            "url": "https://www.subframe.com/",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP server docs and tool list",
            "url": "https://docs.subframe.com/agent/mcp-server.md",
            "seen": "2026-10-09"
          },
          {
            "what": "docs index for agents",
            "url": "https://docs.subframe.com/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "CLI in CI and agents",
            "url": "https://docs.subframe.com/develop/guides/cli-automation.md",
            "seen": "2026-10-09"
          },
          {
            "what": "auth tokens",
            "url": "https://docs.subframe.com/admin/auth-tokens.md",
            "seen": "2026-10-09"
          },
          {
            "what": "plans and AI credits",
            "url": "https://docs.subframe.com/admin/pricing-and-plans.md",
            "seen": "2026-10-09"
          },
          {
            "what": "team roles and permissions",
            "url": "https://docs.subframe.com/admin/managing-team.md",
            "seen": "2026-10-09"
          },
          {
            "what": "version history retention",
            "url": "https://docs.subframe.com/design/projects/version-history.md",
            "seen": "2026-10-09"
          },
          {
            "what": "syncing components",
            "url": "https://docs.subframe.com/develop/concepts/syncing-components.md",
            "seen": "2026-10-09"
          },
          {
            "what": "desktop app platforms",
            "url": "https://docs.subframe.com/desktop-app.md",
            "seen": "2026-10-09"
          },
          {
            "what": "terms of service",
            "url": "https://policies.subframe.com/tos",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy",
            "url": "https://policies.subframe.com/privacy",
            "seen": "2026-10-09"
          },
          {
            "what": "data processing agreement",
            "url": "https://policies.subframe.com/dpa",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP protected resource metadata",
            "url": "https://mcp.subframe.com/.well-known/oauth-protected-resource",
            "seen": "2026-10-09"
          },
          {
            "what": "authorisation server metadata",
            "url": "https://dbgjvucxjwkukwbojywe.supabase.co/.well-known/oauth-authorization-server/auth/v1",
            "seen": "2026-10-09"
          },
          {
            "what": "public repository (CLI source, skills, plugin manifest, docs source, history)",
            "url": "https://github.com/SubframeApp/subframe",
            "seen": "2026-10-09"
          },
          {
            "what": "design skill",
            "url": "https://github.com/SubframeApp/subframe/blob/main/plugins/claude/subframe/skills/design/SKILL.md",
            "seen": "2026-10-09"
          },
          {
            "what": "repository facts and issues",
            "url": "https://api.github.com/repos/SubframeApp/subframe",
            "seen": "2026-10-09"
          },
          {
            "what": "npm registry document for the CLI",
            "url": "https://registry.npmjs.org/@subframe%2Fcli",
            "seen": "2026-10-09"
          },
          {
            "what": "npm weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/@subframe/cli",
            "seen": "2026-10-09"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=subframe",
            "seen": "2026-10-09"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.org/domain/subframe.com",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt (404)",
            "url": "https://www.subframe.com/.well-known/security.txt",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: the MCP tool definitions. mcp.subframe.com answers 401 without OAuth and the server is closed, so input schemas, descriptions and annotations were read only from the docs and the public skill files.",
          "unchecked: the sub-processor list, which the DPA links as a Google Sheet.",
          "unchecked: the Slack community, so support responsiveness there is unknown.",
          "Whether the server still accepts the three old flow tool names after the September 2026 rename.",
          "Whether sign-up asks for a card or a particular sign-in method. The docs mention a card only at Pro checkout.",
          "No status page, changelog, rate limit, SLA or security contact was found on the site, the docs or the policies site. status and changelog addresses were not guessed.",
          "The amount of AI credit on each plan is not published (Free 'Limited', Pro '6x').",
          "The lead called the CLI open source. Its source is public and its package file says ISC, but the repository has no licence file and GitHub reports no licence.",
          "The `design` skill's front matter tells a model to load it for any action through the Subframe MCP server. We read it as data.",
          "No first release date was established. `@subframe/cli` was created on npm on 17 May 2023."
        ]
      },
      "negative": -3,
      "negativeNotes": [
        "23 to 24 September 2026. The docs and skill files renamed three MCP tools (`list_flows`, `get_flow_info`, `delete_flow`) to `list_canvases`, `get_canvas_info` and `delete_canvas`, with no changelog entry or notice found. Whether the server still answers the old names was not tested (-2). https://github.com/SubframeApp/subframe/commit/43bfb51d749713940cf0df8e73da2ab43b7358bc",
        "7 May 2026. A docs commit records that the MCP server 'no longer accepts CLI/access tokens, only OAuth', removing the documented header route for clients without OAuth, with no dated notice found (-1, older and documented since). https://github.com/SubframeApp/subframe/commit/ff59743593fa2b581f32233b58660ace8a23f707"
      ],
      "verdict": "An agent can read and change pages, components, snippets and themes in a Subframe project through a hosted MCP server with OAuth, and Viewer accounts get a read-only server. The server lists 46 tools, and no status page, rate limits, changelog or security contact were found. Three tools were renamed in September 2026 with no notice found.",
      "bestFor": "A coding agent working beside a team that designs React and Tailwind interfaces in Subframe and wants the design as code, with a read-only route for review.",
      "strengths": [
        "Hosted MCP server at `https://mcp.subframe.com/mcp` with OAuth, dynamic client registration and PKCE, so no key is pasted into a config file",
        "Viewer accounts get a read-only MCP server and read-only CLI access, and Viewer seats are free on every plan",
        "Write tools cover pages, components, snippets, design documents, themes, icons and fonts, and page reads return generated React and Tailwind code",
        "Docs publish `llms.txt`, a Markdown twin of every page and a separate docs MCP server that needs no credential",
        "The CLI has a non-interactive mode with `--json` output, nonzero exit status on failure and a token read from `SUBFRAME_AUTH_TOKEN`"
      ],
      "weaknesses": [
        "46 tools are documented with no toolsets, and the vendor's `design` skill that explains them is about 55 KB of text",
        "No status page, published rate limit, SLA or changelog was found, and the terms disclaim uninterrupted service",
        "`list_flows`, `get_flow_info` and `delete_flow` became `list_canvases`, `get_canvas_info` and `delete_canvas` in September 2026 with no notice found",
        "No security.txt, disclosure policy, bug bounty, certification or audit log was found",
        "Delete confirmation is guidance in the skill file. The vendor's skill calls deletes irreversible from MCP, with recovery only through version history in the editor (24 hours on Free)"
      ],
      "agentNotes": [
        "Connect with an MCP client that supports OAuth. The server rejects Subframe access tokens and static `Authorization` headers",
        "Pass `projectId` on every call. When it is omitted the server uses the first project the user can reach, which may be the wrong team's",
        "After `design_page`, `design_component` or `edit_component`, call `wait_for_jobs` with the `jobId` before reading the result. Earlier reads return stale content",
        "Ask the owner before any delete tool or a theme token deletion. A deleted token leaves every reference detached even after the token is restored",
        "For the CLI, set `SUBFRAME_AUTH_TOKEN` and `DO_NOT_TRACK=1`, and point `--dir` at a folder that holds only Subframe code, because a full sync removes other unprotected files"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "E",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 39.7
        }
      ],
      "editorialScores": {
        "ergonomics": 47,
        "maintenance": 65,
        "payments": 33,
        "reliability": 19,
        "schema": 54,
        "security": 44,
        "transparency": 46
      },
      "provenanceScore": 68
    },
    "connect": {
      "install": "npx @subframe/cli@latest init",
      "claudeCode": "claude plugin marketplace add https://github.com/SubframeApp/subframe \u0026\u0026 claude plugin install subframe@subframe",
      "config": {
        "mcpServers": {
          "subframe": {
            "url": "https://mcp.subframe.com/mcp"
          },
          "subframe-docs": {
            "url": "https://docs.subframe.com/mcp"
          }
        }
      },
      "headless": {
        "command": "npx @subframe/cli@latest sync --all --json",
        "env": {
          "SUBFRAME_AUTH_TOKEN": "\u003ctoken\u003e"
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/design.files",
      "tool": "https://letme.dev/subframe"
    },
    "notable": [
      "The MCP docs list 46 tools across projects, pages, components, snippets, canvases, comments, image export, prototypes, design documents, theme, icons and fonts (https://docs.subframe.com/agent/mcp-server)",
      "Viewers get a read-only MCP server. Read, screenshot, export and search tools work, and tools that design or edit need an Editor seat (https://docs.subframe.com/agent/mcp-server)",
      "`design_page`, `design_component` and `edit_component` run as background jobs. A job silent for about 10 minutes is reported as `error` by `wait_for_jobs` (https://docs.subframe.com/agent/mcp-server)",
      "The MCP server's OAuth runs on a Supabase project host, not on subframe.com. Its metadata lists dynamic client registration, PKCE and identity scopes only (https://mcp.subframe.com/.well-known/oauth-protected-resource)",
      "Three agent skills (`design`, `develop`, `install`) ship in the public repository and install as a Claude Code plugin or with `npx skills add`. The `design` skill is about 55 KB (https://github.com/SubframeApp/subframe/tree/main/plugins/claude/subframe/skills)",
      "CLI sync is one-way from Subframe to the codebase and overwrites local changes to synced files unless a file carries `@subframe/sync-disable` (https://docs.subframe.com/develop/concepts/syncing-components)",
      "The CLI reports crashes to Sentry and usage events to Segment, and `DO_NOT_TRACK=1` turns both off (https://github.com/SubframeApp/subframe/blob/main/packages/subframe-cli/README.md)",
      "The desktop app is macOS only. The docs say Windows and Linux are coming (https://docs.subframe.com/desktop-app)"
    ],
    "area": "design-diagrams",
    "details": [
      {
        "label": "Surfaces",
        "value": "Hosted MCP server at `https://mcp.subframe.com/mcp` (streamable HTTP, OAuth), a docs MCP server at `https://docs.subframe.com/mcp` (no credential), three agent skills, and the `@subframe/cli` package for syncing components. A web app and a macOS desktop app hold the canvas"
      },
      {
        "label": "MCP tools",
        "value": "46 documented. Reads such as `list_pages`, `get_page_info`, `get_component_info`, `get_theme`, `list_comments`, `screenshot_page` and `read_prototype_file`. Writes such as `design_page`, `edit_page`, `update_node_styles`, `design_component`, `edit_component`, `write_design_document`, `edit_theme`, `add_icons`, `rename`, `move`, `duplicate` and six delete tools"
      },
      {
        "label": "Read vs write",
        "value": "Viewers get a read-only server. Admins and Editors get every tool. Comments can be listed but not answered or resolved over MCP"
      },
      {
        "label": "Credentials",
        "value": "MCP: OAuth with dynamic client registration and PKCE, identity scopes only, authorisation server on a Supabase host. CLI: an auth token in `SUBFRAME_AUTH_TOKEN` or `--auth-token`, shown once, deletable, with no documented scopes or expiry"
      },
      {
        "label": "Background jobs",
        "value": "`design_page`, `design_component` and `edit_component` return a URL and a `jobId`. `wait_for_jobs` reports `running`, `done`, `error` or `not_found`, and a job silent for about 10 minutes becomes `error`"
      },
      {
        "label": "Output",
        "value": "Page and component reads return generated React and Tailwind code. `export_image` returns a download URL for PNG, JPG, WebP or PDF. Prototypes read back as a runnable Vite app, one file a call"
      },
      {
        "label": "CLI",
        "value": "`@subframe/cli` 1.212.0 (5 October 2026), commands `init` and `sync`, with `--yes`, `--non-interactive` and `--json`. Sync is one-way from Subframe to code. `push-component` is marked experimental"
      },
      {
        "label": "Free tier",
        "value": "One project, unlimited pages, prototypes and team members, a limited AI credit allocation, 24-hour version history, MCP and CLI access"
      },
      {
        "label": "Rate limits",
        "value": "None published"
      },
      {
        "label": "Version history",
        "value": "24 hours on Free, 7 days on Pro, 30 days or more on Custom. Restores a page, component, snippet, theme or the whole project from the editor"
      },
      {
        "label": "Telemetry",
        "value": "The CLI sends crash reports to Sentry and usage events to Segment. `DO_NOT_TRACK=1` turns both off. The privacy policy names Google Analytics, PostHog, Segment and LogRocket for the service"
      },
      {
        "label": "Data handling",
        "value": "Terms of 22 January 2026 say customer data is not used to train AI models unless the customer is notified otherwise, with an opt-out. A DPA of 21 January 2026 is public. The sub-processor list is a linked Google Sheet"
      }
    ],
    "unitPrices": [
      {
        "item": "Pro plan",
        "unit": "seat-month",
        "usd": 20,
        "note": "each Admin and Editor, unlimited projects, six times the Free AI credits, 7-day version history. Viewers are free"
      }
    ],
    "provenance": {
      "legalEntity": "Atomic Design Inc",
      "domain": "subframe.com",
      "domainRegistered": "2003-09-24",
      "endpointOnVendorDomain": true,
      "terms": "https://policies.subframe.com/tos",
      "privacy": "https://policies.subframe.com/privacy",
      "statusPage": "",
      "changelog": "",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The terms of service (last updated 22 January 2026) are made between Atomic Design Inc, 156 2nd Street, Ste 403, San Francisco, CA 94105, and each customer, cover the Subframe service and choose California law.",
        "The privacy policy (effective 22 January 2026) covers products and services at subframe.com. A DPA dated 21 January 2026 is at https://policies.subframe.com/dpa.",
        "The MCP server answers at mcp.subframe.com. Its protected resource metadata names an authorisation server at dbgjvucxjwkukwbojywe.supabase.co, so sign-in and tokens are issued from a Supabase host.",
        "www.subframe.com/.well-known/security.txt and /security.txt return 404.",
        "No status page or changelog is linked from the site footer, the docs or the docs index. Addresses for either were not guessed.",
        "RDAP gives subframe.com a registration date of 2003-09-24 with Cloudflare, Inc. as registrar. The repository was created on 4 March 2024."
      ],
      "score": 68,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Atomic Design Inc",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "subframe.com, registered 2003-09-24 (23 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "mcp.subframe.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects",
          "points": 8.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://policies.subframe.com/tos",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2026-01-22",
          "words": 4465,
          "points": 8.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: January 22, 2026",
              "says": "Last updated 2026-01-22"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "This Agreement shall be governed by the laws of the State of California, United States of America without regard to its conflict of laws provisions.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "In no event shall either party or its agents and suppliers (including their directors, officers, employees, representatives, agents and suppliers) be liable for any indirect, incidental, special or consequential damages, including without limitation procurement of substitute products or services or loss of profits, re…",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If payment is not received by the due date, Atomic Design may suspend Customer’s access to Service until overdue amounts are paid in full."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Customer will not, directly or indirectly: (a) reverse engineer, decompile, disassemble or otherwise attempt to discover source code underlying the Service;"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Customer Data is not used to train AI models unless the customer is notified otherwise, and the customer may opt out of AI training at any time.",
              "quote": "Unless Customer is notified otherwise, Customer Data is not used to train AI models. Customer may opt out of AI training at any time."
            },
            {
              "date": "2026-10-08",
              "text": "When the agreement or an order ends, other than by the customer for the vendor's breach, the customer must immediately pay the remaining balance for the rest of the subscription term.",
              "quote": "Customer will immediately pay Atomic Design, as liquidated damages based on the varying levels of effort required over time to maintain Customer’s subscription, the remaining balance (if any) identified on the Order Form for the remainder of the subscription term."
            },
            {
              "date": "2026-10-08",
              "text": "The vendor may name the customer as a user and use its name and logo in customer lists, press releases, blog posts, advertisements and its website.",
              "quote": "Customer agrees that Atomic Design may identify customer as a user of Atomic Design products and may use Customer’s name and logo in Atomic Design's customer list, press releases, blog posts, advertisements, and website."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://policies.subframe.com/privacy",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2026-01-22",
          "words": 2299,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective date: January 22, 2026",
              "says": "Last updated 2026-01-22"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Personal Data We Collect and How We Collect It"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Atomic Design will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We may partner with third parties, including, but not limited to, advertising and remarketing providers, or other brand partners, for purposes of personalizing or otherwise understanding how you engage with ads or other content."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "For Google AdWords, you can set preferences for how Google advertises to you using the Google Ad Preferences page, and if you want to you can opt out of interest-based advertising entirely by cookie settings or permanently using a browser plugin."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "The right to access, update or delete the information we have on you."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have any questions about this Privacy Policy, please contact us at support@subframe.com.",
              "says": "support@subframe.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "If you are located outside United States and choose to provide information to us, please note that we transfer the data, including Personal Data, to United States and process it there.",
              "says": "Data goes to the United States"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/subframe.json",
    "live": {
      "slug": "subframe",
      "probe": {
        "target": "https://mcp.subframe.com/mcp",
        "method": "get",
        "lastAt": "2026-10-10T02:07:26.557346882Z",
        "lastOk": true,
        "lastStatus": 401,
        "lastMs": 122,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 154,
        "p95ms24h": 262,
        "samples24h": 107,
        "samples30d": 107,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 22,
            "ok": 22
          }
        ]
      },
      "versions": [
        {
          "registry": "npm",
          "name": "@subframe/cli",
          "version": "1.212.0",
          "seenAt": "2026-10-09T17:22:39.340892751Z"
        },
        {
          "registry": "npm",
          "name": "@subframe/core",
          "version": "1.155.0",
          "seenAt": "2026-10-09T17:22:40.263986362Z"
        }
      ],
      "githubStars": 438,
      "npmWeekly": 1006,
      "pages": [
        {
          "url": "https://policies.subframe.com/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:43:40.018475431Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "c221794f9af0"
        },
        {
          "url": "https://policies.subframe.com/tos",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:43:42.040686665Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "cf29b530a2cf"
        }
      ],
      "mcpTools": {
        "url": "https://mcp.subframe.com/mcp",
        "checkedAt": "2026-10-09T21:40:55.87387771Z",
        "status": "auth",
        "note": "asks for credentials before listing its tools",
        "changedAt": "2026-10-09T21:40:55.87387771Z"
      },
      "updatedAt": "2026-10-10T02:07:26.557346882Z"
    }
  }
}
