Best of · Design & diagrams

Best design workspace and canvas APIs for AI agents

All 10 ranked design workspace and canvas APIs on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.

  • 10 ranked
  • 0 agent-ready
  • 6 hosted endpoints
  • Updated 9 October 2026

Top three

Picks by need

Worked out from the scores, prices and facts, so they change when the research does.

Highest score overall

Figma API + MCP B

B, 66/100 on the benchmark.

Also Miro API + MCP, B, 65/100.

Reliability

Miro API + MCP B

73/100 on reliability, against 59 for the overall leader.

Agent ergonomics

Sketch D

70/100 on agent ergonomics, against 60 for the overall leader.

Security & auth

Lucid API + MCP C

80/100 on security & auth, against 74 for the overall leader.

Transparency & trust

Miro API + MCP B

76/100 on transparency & trust, against 73 for the overall leader.

Self-hosting under an open licence

Penpot API + MCP E

self-hosted, MPL-2 licence.

The shortlist

#ToolGradeBest forPriceWhere
1 Figma API + MCP
Figma
B 66 Design-to-code agents and teams already paying for Dev or Full seats. $16 / seat-mo hosted
2 Miro API + MCP
Miro
B 65 Agents that draw diagrams, maps and planning boards people will keep editing. $8 / seat-mo hosted
3 Lucid API + MCP
Lucid Software
C 60.6 Organisations already on Lucid that want an agent to create or update diagrams inside governed workspaces, with read-only scopes and audit logs. $9 / seat-mo hosted
4 Melius
Melius AI, Inc.
C 54.1 An agent producing batches of ad creative, product images or short videos on a shared canvas that people then review, with many models behind one key. $20 / mo hosted
5 Sketch
Sketch B.V.
D 53.5 A designer or developer at a Mac who wants an agent to inspect, audit, export or edit an open Sketch document, or turn a frame into code. $12 / seat-mo local
6 Framer Server API
Framer
D 52.6 Coding agents that build or update Framer sites, CMS content and code components and can run Node. $10 / mo local
7 pen.dev
High Agency, Inc.
D 47.6 A coding agent that designs screens beside the code and keeps them in Git, including in CI. $16 / seat-mo local
8 Zeplin
Zeplin, Inc.
D 47.5 Teams that already publish designs to Zeplin and want an agent to read screens, components, tokens and notes, or turn a screen into code through the MCP server. $13.75 / mo local
9 Penpot API + MCP
Penpot (Kaleidos)
E 43.5 Teams that want design files on their own servers and an agent working alongside a person in the editor. $7 / seat-mo hosted
10 Subframe
Atomic Design Inc
E 39.7 A coding agent working beside a team that designs React and Tailwind interfaces in Subframe and wants the design as code, with a read-only route for review. $20 / seat-mo hosted

How to choose

  1. Read and write coverageCheck which objects the API can change as well as read, since an agent that can only read frames cannot apply the fixes it finds.
  2. Auth scopes and accessCheck that access scopes can be limited to single files, because a token that opens a whole team gives an agent more reach than the task needs.
  3. Design-to-code and export formatsCheck which export formats and design-to-code outputs are available, since an agent that turns a frame into code needs output it can parse without a manual step.
  4. MCP tools and rate limitsList the MCP tools and their rate limits, because an agent that reads a canvas one frame at a time can hit a limit before the design is finished.

Each one in detail

#1

Figma API + MCP

B 66/100

Figma's REST API and official MCP server connect applications and agents to its design platform.

Verdict OpenAPI spec, TypeScript types and an llms.txt index for the REST API. View and Collab seats get 6 MCP calls a month on paid plans.

Choose it for Design-to-code agents and teams already paying for Dev or Full seats.

Strengths

  • OpenAPI spec, TypeScript types and an llms.txt index for the REST API
  • OAuth scopes per resource, plus plan access tokens with allowlists and expiry
  • MCP design context, screenshots and Code Connect for design-to-code work, with canvas writes on the remote server

Weaknesses

  • View and Collab seats get 6 MCP calls a month on paid plans
  • MCP tools were unavailable for about 4 hours on 26 August 2026
  • Only clients in Figma's MCP catalogue can connect

Price $16 / seat-moAuth OAuth or keyx402 nohosted

Full assessment

#2

Miro API + MCP

B 65/100

Miro's REST API v2 reads and writes boards and board items (sticky notes, shapes, connectors, frames, cards, text, images, documents), tags and members, so an agent can lay out diagrams as well as notes.

Verdict REST creates shapes, connectors and frames, so flowcharts and architecture sketches can be drawn directly. Legacy MCP board tools were removed nine days after the deprecation notice.

Choose it for Agents that draw diagrams, maps and planning boards people will keep editing.

Strengths

  • REST creates shapes, connectors and frames, so flowcharts and architecture sketches can be drawn directly
  • Hosted MCP server with OAuth 2.1 on every plan including Free, and no delete tool in its 18
  • Published REST credit limits and MCP daily caps per plan

Weaknesses

  • Legacy MCP board tools were removed nine days after the deprecation notice
  • No prompt-injection guidance for board content written by collaborators
  • OAuth scopes are coarse (boards:read, boards:write)

Price $8 / seat-moAuth OAuthx402 nohosted

Full assessment · Against #1, Figma API + MCP

#3

Lucid API + MCP

C 60.6/100

REST API and hosted MCP server for creating, reading and managing Lucidchart and Lucidspark diagrams.

Verdict OAuth 2.0 scopes with :readonly variants, and audit log endpoints in the REST API. No public changelog for the API or the MCP server.

Choose it for Organisations already on Lucid that want an agent to create or update diagrams inside governed workspaces, with read-only scopes and audit logs.

Strengths

  • OAuth 2.0 scopes with :readonly variants, and audit log endpoints in the REST API
  • Mermaid in through REST, PlantUML sequence diagrams through MCP, both editable afterwards
  • Per-operation rate limits in each reference page's OpenAPI fragment, such as 60 a minute on Create Mermaid Diagram

Weaknesses

  • No public changelog for the API or the MCP server
  • The status page doesn't monitor the API or the MCP server
  • No single OpenAPI file and no official REST SDK

Price $9 / seat-moAuth OAuth or keyx402 nohosted

Full assessment

#4

Melius

C 54.1/100

Melius is a hosted node-based canvas for generating images, video, audio and text with many third-party models. Outside agents read and write projects, canvases, nodes, edges, runs and comments through a REST API, an MCP server and the mel CLI.

Verdict One backend serves a 59-operation REST API with a public OpenAPI spec, a hosted MCP server with OAuth sign-in and a JSON-only CLI, and the status page shows no incidents since July 2026. API keys carry no scopes and work with their creator's role, and no rate-limit numbers, changelog or per-model credit prices are published.

Choose it for An agent producing batches of ad creative, product images or short videos on a shared canvas that people then review, with many models behind one key.

Strengths

  • Public OpenAPI 3.0.2 spec with 59 operations, plus llms.txt, llms-full.txt and a Markdown copy of every docs page
  • Hosted MCP server with OAuth sign-in (PKCE, dynamic client registration) or a bearer API key, tied to one team chosen at authorisation
  • 429 responses carry Retry-After and retryAfterSeconds, and the docs give a bounded retry policy

Weaknesses

  • API keys have no scopes. A key works with its creator's role in every team the creator belongs to
  • No rate-limit numbers, SLA, public changelog or API deprecation policy found in the reviewed documentation
  • The MCP reference lists 75 tools, and the setup guide tells users to select Always Allow for all of them

Price $20 / moAuth OAuth or keyx402 nohosted

Full assessment · Against #1, Figma API + MCP

#5

Sketch

D 53.5/100

Mac design application from Sketch B.V. with a built-in local MCP server. Connected AI clients read open documents, layers, symbols and libraries, take screenshots, and run scripts against the Sketch JavaScript API to edit designs.

Verdict Eight compact tools carry typed inputs and read-only or destructive annotations in Sketch's published connector, and run_code reaches the full JavaScript API. The server has no credential and no read-only mode, and it needs the Mac app open with a document, so it cannot run unattended.

Choose it for A designer or developer at a Mac who wants an agent to inspect, audit, export or edit an open Sketch document, or turn a frame into code.

Strengths

  • Eight tools, seven marked read-only and run_code marked destructive in the connector source
  • run_code runs scripts against the documented Sketch JavaScript API, so an agent can create, edit and export layers
  • The server is off by default and listens on localhost only, per the docs

Weaknesses

  • No credential or token is documented for the local server at port 31126
  • No read-only mode. run_code is always listed, and approval depends on the connected client
  • Needs the Mac app running with a document open. No hosted or headless route was found

Price $12 / seat-moAuth Nonex402 nolocal

Full assessment · Against #1, Figma API + MCP

#6

Framer Server API

D 52.6/100

Framer is a website builder with a design canvas.

Verdict Same surface as the Plugin API, so canvas nodes, components, code files and CMS are writable. No REST endpoints and no official MCP server. You need Node 22 and the framer-api package.

Choose it for Coding agents that build or update Framer sites, CMS content and code components and can run Node.

Strengths

  • Same surface as the Plugin API, so canvas nodes, components, code files and CMS are writable
  • @framer/agent puts every agent change on a branch and limits it to the projects you connect
  • Publish makes a preview deployment that a separate deploy promotes

Weaknesses

  • No REST endpoints and no official MCP server. You need Node 22 and the framer-api package
  • Open beta with no published rate limits, price or SLA
  • Not transactional, so failures can leave partial edits

Price $10 / moAuth API keyx402 nolocal

Full assessment · Against #1, Figma API + MCP

#7

pen.dev

D 47.6/100

Design canvas from High Agency, Inc. that stores designs as JSON .pen files. Agents edit them through a local MCP server in the desktop app or IDE extension, or through a headless CLI. It was called Pencil until 2026.

Verdict An agent can create, edit and export .pen designs without a GUI through the pen CLI, with four compact MCP tools that carry annotations and a documented JSON format. The software is closed and needs a pen.dev account. No changelog, status page or security contact was found, and 14 public issue reports had no reply on 8 October 2026.

Choose it for A coding agent that designs screens beside the code and keeps them in Git, including in CI.

Strengths

  • Headless CLI (@pen.dev/cli) runs the same editor engine as the desktop app and exports PNG, JPEG, WEBP, PDF and HTML
  • Four standard MCP tools with typed inputs and readOnlyHint and destructiveHint annotations, plus two conditional tools
  • The .pen format is JSON with a published TypeScript schema, so designs sit in Git beside code

Weaknesses

  • No changelog. The three desktop releases on GitHub have empty notes, and the format docs reserve the right to make breaking changes
  • 14 issues opened between 28 July and 6 October 2026 in highagency/pen-desktop-releases had no comment or closure on 8 October
  • No status page, security.txt, disclosure policy, bug bounty or certification was found

Price $16 / seat-moAuth OAuth or keyx402 nolocal

Full assessment · Against #1, Figma API + MCP

#8

Zeplin

D 47.5/100

Design handoff platform from Zeplin, Inc. where teams publish finished screens, components and design tokens. Its REST API and webhooks read and partly edit that data, and an official local MCP server gives coding agents screen and component specifications.

Verdict The API documents 123 operations with typed parameters, a 200-requests-a-minute limit and OAuth with PKCE, and every plan includes it. Tokens carry no scopes, no status page was found on the pages read, and the API changelog's last entry is dated 11 May 2021.

Choose it for Teams that already publish designs to Zeplin and want an agent to read screens, components, tokens and notes, or turn a screen into code through the MCP server.

Strengths

  • 123 documented operations, each with an OpenAPI 3.0.2 definition in a Markdown twin, indexed by llms.txt
  • Rate limit stated as 200 requests a minute per user, with Zeplin-RateLimit-Limit, -Remaining and -Reset response headers
  • OAuth 2.0 authorisation code grant with PKCE, one-hour access tokens and single-use refresh tokens

Weaknesses

  • OAuth tokens and personal access tokens carry no scopes. The OpenAPI security scheme lists none
  • No status page is linked from the site, docs or help centre pages read
  • The API changelog's last entry is 11 May 2021, though the reference has since gained variables, flow boards and annotations

Price $13.75 / moAuth OAuth or keyx402 nolocal

Full assessment · Against #1, Figma API + MCP

#9

Penpot API + MCP

E 43.5/100

Open-source design and prototyping tool, used as SaaS at design.penpot.app or self-hosted.

Verdict MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.

Choose it for Teams that want design files on their own servers and an agent working alongside a person in the editor.

Strengths

  • MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan
  • MCP execute_code reaches the whole plugin API, so an agent can create, move, restyle and delete shapes
  • OpenAPI description served by every instance

Weaknesses

  • Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string
  • No annotations on MCP tools and no read-only mode
  • Four advisories in 2026, including MCP REPL remote code execution

Price $7 / seat-moAuth Tokenx402 nohosted

Full assessment · Against #1, Figma API + MCP

#10

Subframe

E 39.7/100

Design tool from Atomic Design Inc for React and Tailwind interfaces, with a cloud canvas and a macOS app. Agents read and edit pages, components and themes through a hosted MCP server, and a CLI syncs components into a codebase.

Verdict An agent can read and change pages, components, snippets and themes in a Subframe project through a hosted MCP server with OAuth, and Viewer accounts get a read-only server. The server lists 46 tools, and no status page, rate limits, changelog or security contact were found. Three tools were renamed in September 2026 with no notice found.

Choose it for A coding agent working beside a team that designs React and Tailwind interfaces in Subframe and wants the design as code, with a read-only route for review.

Strengths

  • Hosted MCP server at https://mcp.subframe.com/mcp with OAuth, dynamic client registration and PKCE, so no key is pasted into a config file
  • Viewer accounts get a read-only MCP server and read-only CLI access, and Viewer seats are free on every plan
  • Write tools cover pages, components, snippets, design documents, themes, icons and fonts, and page reads return generated React and Tailwind code

Weaknesses

  • 46 tools are documented with no toolsets, and the vendor's design skill that explains them is about 55 KB of text
  • No status page, published rate limit, SLA or changelog was found, and the terms disclaim uninterrupted service
  • list_flows, get_flow_info and delete_flow became list_canvases, get_canvas_info and delete_canvas in September 2026 with no notice found

Price $20 / seat-moAuth OAuth or keyx402 nohosted

Full assessment · Against #1, Figma API + MCP

Head to head

All 49 comparisons in this category

Questions

What are the highest-rated design workspace and canvas APIs for AI agents?

Figma API + MCP has the highest benchmark score of the 10 ranked design workspace and canvas APIs, 66 (B). Miro API + MCP is second with 65 (B).

How many design workspace and canvas APIs are agent-ready?

0 of the 10 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.

Which design workspace and canvas APIs accept x402 payments?

None of the ranked listings here accepts x402 for its main call yet.

How is this list ranked?

By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026.

How this list is made

The order is the Anchor benchmark score, the same number as on each listing and in the top list. Each listing is graded from public evidence against the benchmark checklist, and the picks above are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.

Full ranked table · 49 head-to-head comparisons · Best tools in every category

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.