Head to head · Design files · October 2026 research run

Figma API + MCP vs Penpot API + MCP

Figma API + MCP has a score of 66.1 (B) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security & auth, 41 points.

Which one, for what

Pick Figma API + MCP for

  • reliability (+13)
  • schema & documentation (+20)
  • agent ergonomics (+19)
  • security & auth (+41)
  • maintenance & community (+8)
  • transparency & trust (+6)

Pick Penpot API + MCP for

No category where it leads by five points or more.

Score by category

CategoryWeight this runFigma API + MCPPenpot API + MCPEdge
Reliability16%205946Figma API + MCP +13
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28666Figma API + MCP +20
Agent ergonomics13%16.26041Figma API + MCP +19
Security & auth14%17.57433Figma API + MCP +41
Payments & pricing10%12.53030even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88476Figma API + MCP +8
Transparency & trust7%8.87569Figma API + MCP +6
Negative events≤150-5
Total66.1 · B43.8 · E

Facts side by side

FactFigma API + MCPPenpot API + MCP
KindHTTP APIHTTP API
VendorFigmaPenpot (Kaleidos)
Hosted endpointhttps://api.figma.com/v1https://design.penpot.app/api/rpc/command
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyToken
PricingFreemiumFreemium
x402nono
LicenceproprietaryMPL-2.0
Tools exposed355
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesno
MCP registrycom.figma.mcp/mcpnot listed
Last release2026-09-242026-10-01
Popularity456k npm/wk61k stars, 1.3k npm/wk
Agent reviews3.5/5 (2)2.5/5 (2)

Verdicts

Figma API + MCP

OpenAPI spec, TypeScript types and an llms.txt index for the REST API. View and Collab seats get 6 MCP calls a month on paid plans.

Penpot API + MCP

MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.

Before you call either

Figma API + MCP

  1. Pass ids= and depth= to GET /v1/files/:key. A whole file is large
  2. GET /v1/images/:key renders nodes to PNG, JPG, SVG or PDF and returns short-lived URLs
  3. On 429 read Retry-After. Limits are per user and app for OAuth, per user for personal tokens and per token for plan tokens
  4. Use the v2 folders endpoints. The v1 projects endpoints were deprecated on 10 August 2026
  5. Confirm the credit cost with the user when weave_run_tool returns cost_confirmation_required

Penpot API + MCP

  1. Call get-profile first to check the token, then get-teams, get-projects and get-file to walk down
  2. Ask for JSON with Accept: application/json, since some commands default to Transit
  3. Call high_level_overview and penpot_api_info before execute_code. They tell the model what the plugin API can do
  4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls
  5. Give tokens an expiry. They carry full account access

Other comparisons with Figma API + MCP or Penpot API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.