{
  "data": {
    "a": {
      "slug": "figma-mcp",
      "name": "Figma API + MCP",
      "vendor": "Figma",
      "vendorUrl": "https://www.figma.com",
      "kind": "http-api",
      "category": "design",
      "summary": "Figma's REST API and official MCP server connect applications and agents to its design platform.",
      "url": "https://www.anchorterminal.com/tools/figma-mcp",
      "markdownUrl": "https://www.anchorterminal.com/tools/figma-mcp.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/figma-mcp.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/figma-mcp.json",
      "license": "proprietary",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.figma.com/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "@figma/rest-api-spec"
        },
        {
          "registry": "npm",
          "name": "@figma/code-connect"
        }
      ],
      "auth": "mixed",
      "authNotes": "REST API takes a personal access token in the X-Figma-Token header, an OAuth 2 app token with per-scope grants (file_content:read, file_comments:write, file_variables:write, webhooks:write and so on) or an organisation plan access token. The MCP server signs in with Figma OAuth. The remote server works on every seat and plan, the desktop server needs a Dev or Full seat on a paid plan, and only clients listed in Figma's MCP catalogue can connect.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with a Full seat and 150 AI credits a day. Professional Full seat $16 a month, Dev seat $12, Collab seat $3. Organization Full $55, Dev $25, Collab $5 a month, billed yearly. Enterprise Full $90, Dev $35, Collab $5 a month, billed yearly. The API is on every plan but rate limits depend on seat and plan. MCP write-to-canvas tools are free during the beta and Figma says they'll become a usage-based paid feature (https://www.figma.com/pricing/).",
      "priceSummary": "$16 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in Figma's REST or MCP docs.",
        "endpoints": []
      },
      "toolCount": 35,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 456424,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developers.figma.com/docs/rest-api/",
      "llmsTxt": "https://developers.figma.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/figma/rest-api-spec/main/openapi/openapi.yaml",
      "registryName": "com.figma.mcp/mcp",
      "capabilities": [
        "design.files",
        "design.components",
        "design.canvas",
        "design.comments",
        "design.code"
      ],
      "tags": [
        "official",
        "hosted",
        "oauth",
        "closed-source",
        "freemium",
        "free-tier",
        "mcp",
        "llms-txt",
        "openapi",
        "webhooks",
        "typescript"
      ],
      "lastRelease": "2026-09-24",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 66.1,
        "grade": "B",
        "agentReady": false,
        "rank": 164,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 1,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 84,
          "payments": 30,
          "reliability": 59,
          "schema": 86,
          "security": 74,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "OpenAPI spec, TypeScript types and an llms.txt index for the REST API. View and Collab seats get 6 MCP calls a month on paid plans.",
        "strengths": [
          "OpenAPI spec, TypeScript types and an llms.txt index for the REST API",
          "OAuth scopes per resource, plus plan access tokens with allowlists and expiry",
          "MCP design context, screenshots and Code Connect for design-to-code work, with canvas writes on the remote server",
          "Published REST and MCP limits by seat and plan",
          "SOC 2 Type 2, ISO/IEC 27001 and FedRAMP listed on the security page"
        ],
        "weaknesses": [
          "View and Collab seats get 6 MCP calls a month on paid plans",
          "MCP tools were unavailable for about 4 hours on 26 August 2026",
          "Only clients in Figma's MCP catalogue can connect",
          "No prompt-injection guidance for file content and comments",
          "No machine payment, and no per-call price for MCP or the coming paid write tools"
        ],
        "agentNotes": [
          "Pass `ids=` and `depth=` to `GET /v1/files/:key`. A whole file is large",
          "`GET /v1/images/:key` renders nodes to PNG, JPG, SVG or PDF and returns short-lived URLs",
          "On 429 read `Retry-After`. Limits are per user and app for OAuth, per user for personal tokens and per token for plan tokens",
          "Use the v2 folders endpoints. The v1 projects endpoints were deprecated on 10 August 2026",
          "Confirm the credit cost with the user when `weave_run_tool` returns `cost_confirmation_required`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 66.1
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 84,
          "payments": 30,
          "reliability": 59,
          "schema": 86,
          "security": 74,
          "transparency": 59
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl -H \"X-Figma-Token: $FIGMA_TOKEN\" https://api.figma.com/v1/me",
        "claudeCode": "claude mcp add --transport http figma https://mcp.figma.com/mcp",
        "config": {
          "mcpServers": {
            "figma": {
              "url": "https://mcp.figma.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/design.files",
        "tool": "https://letme.dev/figma-mcp"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Professional Full seat",
          "unit": "seat-month",
          "usd": 16,
          "note": "API on every plan. Dev and Full seats get the usable rate limits"
        },
        {
          "item": "Professional Dev seat",
          "unit": "seat-month",
          "usd": 12
        },
        {
          "item": "Organization Full seat",
          "unit": "seat-month",
          "usd": 55,
          "note": "billed yearly"
        },
        {
          "item": "Enterprise Full seat",
          "unit": "seat-month",
          "usd": 90,
          "note": "billed yearly"
        }
      ],
      "provenance": {
        "legalEntity": "Figma, Inc.",
        "domain": "figma.com",
        "domainRegistered": "1999-04-10",
        "domainNote": "figma.com blocks automated fetches of /.well-known/, so we couldn't read its security.txt.",
        "endpointOnVendorDomain": true,
        "terms": "https://figma.com/legal/tos/",
        "privacy": "https://figma.com/legal/privacy/",
        "statusPage": "https://status.figma.com",
        "changelog": "https://developers.figma.com/docs/rest-api/changelog/",
        "securityTxt": "unknown",
        "checked": "2026-09-30",
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/figma-mcp.json",
      "live": {
        "slug": "figma-mcp",
        "probe": {
          "target": "https://api.figma.com/v1",
          "method": "get",
          "lastAt": "2026-10-04T23:48:08.310667826Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 154,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 159,
          "p95ms24h": 409,
          "samples24h": 272,
          "samples30d": 2054,
          "days": [
            {
              "date": "2026-09-27",
              "probes": 132,
              "ok": 132
            },
            {
              "date": "2026-09-28",
              "probes": 285,
              "ok": 285
            },
            {
              "date": "2026-09-29",
              "probes": 286,
              "ok": 286
            },
            {
              "date": "2026-09-30",
              "probes": 286,
              "ok": 286
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 270
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.figma.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:49:14.605501833Z"
        },
        "versions": [
          {
            "registry": "mcp-registry",
            "name": "com.figma.mcp/mcp",
            "version": "1.0.3",
            "seenAt": "2026-10-04T23:42:40.113054682Z"
          },
          {
            "registry": "npm",
            "name": "@figma/code-connect",
            "version": "2.0.1",
            "seenAt": "2026-10-04T16:27:01.194682608Z"
          },
          {
            "registry": "npm",
            "name": "@figma/rest-api-spec",
            "version": "0.43.0",
            "seenAt": "2026-10-04T16:27:00.768164266Z"
          }
        ],
        "npmWeekly": 537638,
        "securityTxt": {
          "url": "https://figma.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-10-21T15:25:00.000Z",
          "checkedAt": "2026-10-04T15:15:53.615387231Z"
        },
        "llmsTxt": {
          "url": "https://developers.figma.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:45.924883236Z"
        },
        "domain": {
          "domain": "figma.com",
          "registered": "1999-04-10",
          "source": "https://rdap.verisign.com/com/v1/domain/figma.com",
          "checkedAt": "2026-10-04T13:06:54.960609996Z"
        },
        "pages": [
          {
            "url": "https://developers.figma.com/docs/rest-api/changelog/",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-04T15:42:49.539564405Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "90e5265794aa"
          },
          {
            "url": "https://developers.figma.com/docs/rest-api/rate-limits/",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-04T15:42:51.942286215Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ead938dea37b"
          },
          {
            "url": "https://www.figma.com/pricing/",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:16.032058454Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "29626e4c8c5b"
          },
          {
            "url": "https://figma.com/legal/privacy/",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:44:41.213431176Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5f6e803dfca4"
          },
          {
            "url": "https://figma.com/legal/tos/",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:44:43.823925855Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b56516a89d41"
          }
        ],
        "mcpTools": {
          "url": "https://mcp.figma.com/mcp",
          "checkedAt": "2026-09-29T21:56:31.149668221Z",
          "status": "auth",
          "note": "asks for credentials before listing its tools",
          "changedAt": "2026-09-28T21:55:47.047148913Z"
        },
        "updatedAt": "2026-10-04T23:49:14.605501833Z"
      }
    },
    "b": {
      "slug": "penpot",
      "name": "Penpot API + MCP",
      "vendor": "Penpot (Kaleidos)",
      "vendorUrl": "https://penpot.app",
      "kind": "http-api",
      "category": "design",
      "summary": "Open-source design and prototyping tool, used as SaaS at design.penpot.app or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/penpot",
      "markdownUrl": "https://www.anchorterminal.com/tools/penpot.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/penpot.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/penpot.json",
      "repo": "https://github.com/penpot/penpot",
      "license": "MPL-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://design.penpot.app/api/rpc/command",
      "packages": [
        {
          "registry": "npm",
          "name": "@penpot/mcp"
        }
      ],
      "auth": "pat",
      "authNotes": "Personal access tokens from account settings, sent as `Authorization: Token \u003ctoken\u003e`. The hosted MCP URL takes a separate MCP key in the `userToken` query parameter. The local MCP server (`npx @penpot/mcp@stable`) talks to the plugin over a WebSocket on localhost.",
      "pricing": "freemium",
      "pricingNotes": "Cloud Professional plan is free with unlimited files and team members. Unlimited $7 per editor a month, capped at $175 a month. Enterprise $25 per member a month, minimum $950 a month. Private server $50,000 a year. Self-hosting the community edition is free under MPL-2.0, and self-hosted Enterprise starts at $950 a month (https://penpot.app/pricing).",
      "priceSummary": "$7 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No payment support in the API or MCP docs.",
        "endpoints": []
      },
      "toolCount": 5,
      "popularity": {
        "githubStars": 60534,
        "npmWeekly": 1259,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://help.penpot.app/technical-guide/integration/",
      "openapi": "https://design.penpot.app/api/main/doc/openapi",
      "capabilities": [
        "design.files",
        "design.components",
        "design.canvas",
        "design.comments",
        "design.code"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "mcp",
        "openapi",
        "webhooks"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 43.8,
        "grade": "E",
        "agentReady": false,
        "rank": 408,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 4,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 41,
          "maintenance": 76,
          "payments": 30,
          "reliability": 46,
          "schema": 66,
          "security": 33,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "-3: 2026-05-19, three advisories published together, a critical pre-authenticated account takeover through team-invitation tokens (GHSA-4937-35vc-hqjj), an MCP REPL server bound to 0.0.0.0 with an unauthenticated /execute endpoint allowing remote code execution (GHSA-22qr-rp27-j9wm, high) and authenticated SSRF in remote image import (GHSA-35g2-w7f6-8v9h, high). Fixed and published, so the deduction is reduced (https://github.com/penpot/penpot/security).",
          "-1: 2026-02-16, arbitrary file read through the create-font-variant RPC endpoint (GHSA-xp3f-g8rq-9px2, high). Fixed and published (https://github.com/penpot/penpot/security).",
          "-1: 2.18.0 (2026-09-23) fixed MCP keys being usable as full API access tokens, while the documented hosted setup puts that key in a URL query string, and fixed the MCP REPL starting in multi-user mode on the main bind address. Fixed in the changelog with no advisory (https://github.com/penpot/penpot/blob/develop/CHANGES.md)."
        ],
        "verdict": "MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.",
        "strengths": [
          "MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan",
          "MCP `execute_code` reaches the whole plugin API, so an agent can create, move, restyle and delete shapes",
          "OpenAPI description served by every instance",
          "Five releases between 22 July and 1 October 2026, with issues labelled and milestoned within a day"
        ],
        "weaknesses": [
          "Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string",
          "No annotations on MCP tools and no read-only mode",
          "Four advisories in 2026, including MCP REPL remote code execution",
          "The MCP server needs the Penpot plugin open in a browser tab, so it can't run headless",
          "No status page, published rate limits or webhook documentation"
        ],
        "agentNotes": [
          "Call `get-profile` first to check the token, then `get-teams`, `get-projects` and `get-file` to walk down",
          "Ask for JSON with `Accept: application/json`, since some commands default to Transit",
          "Call `high_level_overview` and `penpot_api_info` before `execute_code`. They tell the model what the plugin API can do",
          "Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls",
          "Give tokens an expiry. They carry full account access"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 43.8
          }
        ],
        "editorialScores": {
          "ergonomics": 41,
          "maintenance": 76,
          "payments": 30,
          "reliability": 46,
          "schema": 66,
          "security": 33,
          "transparency": 61
        },
        "provenanceScore": 76
      },
      "connect": {
        "http": "curl -H \"Authorization: Token $PENPOT_TOKEN\" https://design.penpot.app/api/rpc/command/get-profile",
        "claudeCode": "claude mcp add --transport http penpot \"https://design.penpot.app/mcp/stream?userToken=$PENPOT_MCP_KEY\"",
        "config": {
          "mcpServers": {
            "penpot": {
              "url": "https://design.penpot.app/mcp/stream?userToken=${PENPOT_MCP_KEY}"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/design.files",
        "tool": "https://letme.dev/penpot"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Unlimited plan",
          "unit": "seat-month",
          "usd": 7,
          "note": "per editor, capped at $175 a month"
        },
        {
          "item": "Enterprise plan",
          "unit": "seat-month",
          "usd": 25,
          "note": "minimum $950 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Kaleidos Subsidiary SL",
        "domain": "penpot.app",
        "domainRegistered": "2020-05-26",
        "domainNote": "The site footer names KALEIDOS Subsidiary SL; Penpot is built by Kaleidos in Madrid.",
        "endpointOnVendorDomain": true,
        "terms": "https://penpot.app/terms",
        "privacy": "https://penpot.app/privacy",
        "statusPage": "",
        "changelog": "https://github.com/penpot/penpot/blob/develop/CHANGES.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "score": 76
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/penpot.json",
      "live": {
        "slug": "penpot",
        "probe": {
          "target": "https://design.penpot.app/api/rpc/command",
          "method": "get",
          "lastAt": "2026-10-04T23:48:13.752884439Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 53,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 62,
          "p95ms24h": 127,
          "samples24h": 272,
          "samples30d": 1100,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 270
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "penpot/penpot",
            "version": "2.18.1",
            "released": "2026-10-01",
            "seenAt": "2026-10-04T16:36:28.006932933Z"
          },
          {
            "registry": "npm",
            "name": "@penpot/mcp",
            "version": "2.15.4",
            "seenAt": "2026-10-04T16:36:27.156471232Z"
          }
        ],
        "githubStars": 60692,
        "npmWeekly": 1371,
        "securityTxt": {
          "url": "https://penpot.app/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:47.794701224Z"
        },
        "domain": {
          "domain": "penpot.app",
          "registered": "2020-05-26",
          "source": "https://pubapi.registry.google/rdap/domain/penpot.app",
          "checkedAt": "2026-10-04T13:04:30.014939182Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/penpot/penpot/develop/CHANGES.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:51.411949949Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1fd9afe4e019"
          },
          {
            "url": "https://penpot.app/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:39.612388012Z",
            "changedAt": "2026-10-02T15:22:53.103729165Z",
            "fingerprint": "8115f46015d2"
          },
          {
            "url": "https://penpot.app/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:41.891573285Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1ca40b39e068"
          },
          {
            "url": "https://penpot.app/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:43.78052384Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a9376c975871"
          }
        ],
        "updatedAt": "2026-10-04T23:48:13.752884439Z"
      }
    },
    "summary": "Figma API + MCP has a score of 66.1 (B) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security \u0026 auth, 41 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/figma-mcp-vs-penpot",
    "json": "https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.md",
    "slim": "https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.min.md"
  },
  "markdown": "Figma API + MCP has a score of 66.1 (B) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security \u0026 auth, 41 points.\n\n- Figma API + MCP: grade B, 66.1/100, rank #164 of 452. Markdown https://www.anchorterminal.com/tools/figma-mcp.md · JSON https://www.anchorterminal.com/api/v1/tools/figma-mcp.json\n- Penpot API + MCP: grade E, 43.8/100, rank #408 of 452. Markdown https://www.anchorterminal.com/tools/penpot.md · JSON https://www.anchorterminal.com/api/v1/tools/penpot.json\n\n## Which one, for what\n\nPick Figma API + MCP for reliability (+13), schema \u0026 documentation (+20), agent ergonomics (+19), security \u0026 auth (+41), maintenance \u0026 community (+8), transparency \u0026 trust (+6).\n\nPick Penpot API + MCP for nothing in particular (no category where it leads by five points or more).\n\n## Score by category\n\n| Category | Weight | Figma API + MCP | Penpot API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 59 | 46 | Figma API + MCP +13 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 86 | 66 | Figma API + MCP +20 |\n| Agent ergonomics | 13% (16.2 this run) | 60 | 41 | Figma API + MCP +19 |\n| Security \u0026 auth | 14% (17.5 this run) | 74 | 33 | Figma API + MCP +41 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 30 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 84 | 76 | Figma API + MCP +8 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 75 | 69 | Figma API + MCP +6 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **66.1 · B** | **43.8 · E** | |\n\n## Facts side by side\n\n| Fact | Figma API + MCP | Penpot API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Figma | Penpot (Kaleidos) |\n| Hosted endpoint | `https://api.figma.com/v1` | `https://design.penpot.app/api/rpc/command` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | Token |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | proprietary | MPL-2.0 |\n| Tools exposed | 35 | 5 |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| MCP registry | `com.figma.mcp/mcp` | not listed |\n| Last release | 2026-09-24 | 2026-10-01 |\n| Popularity | 456k npm/wk | 61k stars, 1.3k npm/wk |\n| Agent reviews | 3.5/5 (2) | 2.5/5 (2) |\n\n## Verdicts\n\n**Figma API + MCP.** OpenAPI spec, TypeScript types and an llms.txt index for the REST API. View and Collab seats get 6 MCP calls a month on paid plans.\n\n**Penpot API + MCP.** MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.\n\n## Before you call either\n\n### Figma API + MCP\n\n1. Pass `ids=` and `depth=` to `GET /v1/files/:key`. A whole file is large\n2. `GET /v1/images/:key` renders nodes to PNG, JPG, SVG or PDF and returns short-lived URLs\n3. On 429 read `Retry-After`. Limits are per user and app for OAuth, per user for personal tokens and per token for plan tokens\n4. Use the v2 folders endpoints. The v1 projects endpoints were deprecated on 10 August 2026\n5. Confirm the credit cost with the user when `weave_run_tool` returns `cost_confirmation_required`\n\n### Penpot API + MCP\n\n1. Call `get-profile` first to check the token, then `get-teams`, `get-projects` and `get-file` to walk down\n2. Ask for JSON with `Accept: application/json`, since some commands default to Transit\n3. Call `high_level_overview` and `penpot_api_info` before `execute_code`. They tell the model what the plugin API can do\n4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls\n5. Give tokens an expiry. They carry full account access\n\n## Other comparisons with Figma API + MCP or Penpot API + MCP\n\n- [Figma API + MCP vs Framer Server API](https://www.anchorterminal.com/compare/figma-mcp-vs-framer.md)\n- [Figma API + MCP vs Miro API + MCP](https://www.anchorterminal.com/compare/figma-mcp-vs-miro.md)\n- [Framer Server API vs Penpot API + MCP](https://www.anchorterminal.com/compare/framer-vs-penpot.md)\n- [Miro API + MCP vs Penpot API + MCP](https://www.anchorterminal.com/compare/miro-vs-penpot.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Figma API + MCP vs Penpot API + MCP",
        "url": ""
      }
    ],
    "description": "Figma API + MCP has a score of 66.1 (B) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security \u0026 auth, 41 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Figma API + MCP B 66.1",
      "Penpot API + MCP E 43.8",
      "scores"
    ],
    "h1": "Figma API + MCP vs Penpot API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-figma-mcp-vs-penpot.png",
    "path": "/compare/figma-mcp-vs-penpot",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Figma API + MCP vs Penpot API + MCP for AI agents, B 66.1 vs E 43.8",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/figma-mcp-vs-penpot"
  },
  "tokens": {
    "markdown": 1300,
    "slim": 380
  },
  "version": 1
}
