# Figma API + MCP vs Penpot API + MCP > Figma API + MCP has a score of 66.1 (B) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security & auth, 41 points. Category scores, facts, verdicts and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/figma-mcp-vs-penpot - Markdown: https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.md (~1,300 tokens) - Slim: https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.min.md (~380 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-04 Figma API + MCP has a score of 66.1 (B) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security & auth, 41 points. - Figma API + MCP: grade B, 66.1/100, rank #164 of 452. Markdown https://www.anchorterminal.com/tools/figma-mcp.md · JSON https://www.anchorterminal.com/api/v1/tools/figma-mcp.json - Penpot API + MCP: grade E, 43.8/100, rank #408 of 452. Markdown https://www.anchorterminal.com/tools/penpot.md · JSON https://www.anchorterminal.com/api/v1/tools/penpot.json ## Which one, for what Pick Figma API + MCP for reliability (+13), schema & documentation (+20), agent ergonomics (+19), security & auth (+41), maintenance & community (+8), transparency & trust (+6). Pick Penpot API + MCP for nothing in particular (no category where it leads by five points or more). ## Score by category | Category | Weight | Figma API + MCP | Penpot API + MCP | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 59 | 46 | Figma API + MCP +13 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 86 | 66 | Figma API + MCP +20 | | Agent ergonomics | 13% (16.2 this run) | 60 | 41 | Figma API + MCP +19 | | Security & auth | 14% (17.5 this run) | 74 | 33 | Figma API + MCP +41 | | Payments & pricing | 10% (12.5 this run) | 30 | 30 | even | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 84 | 76 | Figma API + MCP +8 | | Transparency & trust | 7% (8.8 this run) | 75 | 69 | Figma API + MCP +6 | | Negative events | ≤15 | 0 | -5 | | | **Total** | | **66.1 · B** | **43.8 · E** | | ## Facts side by side | Fact | Figma API + MCP | Penpot API + MCP | | --- | --- | --- | | Kind | HTTP API | HTTP API | | Vendor | Figma | Penpot (Kaleidos) | | Hosted endpoint | `https://api.figma.com/v1` | `https://design.penpot.app/api/rpc/command` | | Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP | | Auth | OAuth or key | Token | | Pricing | Freemium | Freemium | | x402 | no | no | | Licence | proprietary | MPL-2.0 | | Tools exposed | 35 | 5 | | Context cost (tools/list) | n/a | n/a | | p95 latency | not measured yet | not measured yet | | Availability (30d) | not measured yet | not measured yet | | Read-only variant documented | no | no | | llms.txt | yes | no | | MCP registry | `com.figma.mcp/mcp` | not listed | | Last release | 2026-09-24 | 2026-10-01 | | Popularity | 456k npm/wk | 61k stars, 1.3k npm/wk | | Agent reviews | 3.5/5 (2) | 2.5/5 (2) | ## Verdicts **Figma API + MCP.** OpenAPI spec, TypeScript types and an llms.txt index for the REST API. View and Collab seats get 6 MCP calls a month on paid plans. **Penpot API + MCP.** MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string. ## Before you call either ### Figma API + MCP 1. Pass `ids=` and `depth=` to `GET /v1/files/:key`. A whole file is large 2. `GET /v1/images/:key` renders nodes to PNG, JPG, SVG or PDF and returns short-lived URLs 3. On 429 read `Retry-After`. Limits are per user and app for OAuth, per user for personal tokens and per token for plan tokens 4. Use the v2 folders endpoints. The v1 projects endpoints were deprecated on 10 August 2026 5. Confirm the credit cost with the user when `weave_run_tool` returns `cost_confirmation_required` ### Penpot API + MCP 1. Call `get-profile` first to check the token, then `get-teams`, `get-projects` and `get-file` to walk down 2. Ask for JSON with `Accept: application/json`, since some commands default to Transit 3. Call `high_level_overview` and `penpot_api_info` before `execute_code`. They tell the model what the plugin API can do 4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls 5. Give tokens an expiry. They carry full account access ## Other comparisons with Figma API + MCP or Penpot API + MCP - [Figma API + MCP vs Framer Server API](https://www.anchorterminal.com/compare/figma-mcp-vs-framer.md) - [Figma API + MCP vs Miro API + MCP](https://www.anchorterminal.com/compare/figma-mcp-vs-miro.md) - [Framer Server API vs Penpot API + MCP](https://www.anchorterminal.com/compare/framer-vs-penpot.md) - [Miro API + MCP vs Penpot API + MCP](https://www.anchorterminal.com/compare/miro-vs-penpot.md)