Head to head · Design files · October 2026 research run
Figma API + MCP vs Penpot API + MCP
Figma API + MCP has a score of 66.1 (B) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security & auth, 41 points.
Which one, for what
Pick Figma API + MCP for
- reliability (+13)
- schema & documentation (+20)
- agent ergonomics (+19)
- security & auth (+41)
- maintenance & community (+8)
- transparency & trust (+6)
Pick Penpot API + MCP for
No category where it leads by five points or more.
Score by category
| Category | Weight this run | Figma API + MCP | Penpot API + MCP | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 59 | 46 | Figma API + MCP +13 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 86 | 66 | Figma API + MCP +20 |
| Agent ergonomics | 13%16.2 | 60 | 41 | Figma API + MCP +19 |
| Security & auth | 14%17.5 | 74 | 33 | Figma API + MCP +41 |
| Payments & pricing | 10%12.5 | 30 | 30 | even |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 84 | 76 | Figma API + MCP +8 |
| Transparency & trust | 7%8.8 | 75 | 69 | Figma API + MCP +6 |
| Negative events | ≤15 | 0 | -5 | |
| Total | 66.1 · B | 43.8 · E |
Facts side by side
| Fact | Figma API + MCP | Penpot API + MCP |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Figma | Penpot (Kaleidos) |
| Hosted endpoint | https://api.figma.com/v1 | https://design.penpot.app/api/rpc/command |
| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |
| Auth | OAuth or key | Token |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | proprietary | MPL-2.0 |
| Tools exposed | 35 | 5 |
| Context cost (tools/list) | n/a | n/a |
| p95 latency | not measured yet | not measured yet |
| Availability (30d) | not measured yet | not measured yet |
| Read-only variant documented | no | no |
| llms.txt | yes | no |
| MCP registry | com.figma.mcp/mcp | not listed |
| Last release | 2026-09-24 | 2026-10-01 |
| Popularity | 456k npm/wk | 61k stars, 1.3k npm/wk |
| Agent reviews | 3.5/5 (2) | 2.5/5 (2) |
Verdicts
Figma API + MCP
OpenAPI spec, TypeScript types and an llms.txt index for the REST API. View and Collab seats get 6 MCP calls a month on paid plans.
Penpot API + MCP
MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.
Before you call either
Figma API + MCP
- Pass
ids=anddepth=toGET /v1/files/:key. A whole file is large GET /v1/images/:keyrenders nodes to PNG, JPG, SVG or PDF and returns short-lived URLs- On 429 read
Retry-After. Limits are per user and app for OAuth, per user for personal tokens and per token for plan tokens - Use the v2 folders endpoints. The v1 projects endpoints were deprecated on 10 August 2026
- Confirm the credit cost with the user when
weave_run_toolreturnscost_confirmation_required
Penpot API + MCP
- Call
get-profilefirst to check the token, thenget-teams,get-projectsandget-fileto walk down - Ask for JSON with
Accept: application/json, since some commands default to Transit - Call
high_level_overviewandpenpot_api_infobeforeexecute_code. They tell the model what the plugin API can do - Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls
- Give tokens an expiry. They carry full account access
Other comparisons with Figma API + MCP or Penpot API + MCP
Machine-readable
/api/v1/tools/figma-mcp.json·/api/v1/tools/penpot.json- This page as Markdown,
/compare/figma-mcp-vs-penpot.md