Head to head · Design files · October 2026 research run
Framer Server API vs Penpot API + MCP
Framer Server API has a score of 52.8 (D) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security & auth, 17 points.
Which one, for what
Pick Framer Server API for
- agent ergonomics (+6)
- security & auth (+17)
- transparency & trust (+8)
Pick Penpot API + MCP for
- payments & pricing (+5)
Score by category
| Category | Weight this run | Framer Server API | Penpot API + MCP | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 43 | 46 | Penpot API + MCP +3 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 69 | 66 | Framer Server API +3 |
| Agent ergonomics | 13%16.2 | 47 | 41 | Framer Server API +6 |
| Security & auth | 14%17.5 | 50 | 33 | Framer Server API +17 |
| Payments & pricing | 10%12.5 | 25 | 30 | Penpot API + MCP +5 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 77 | 76 | Framer Server API +1 |
| Transparency & trust | 7%8.8 | 77 | 69 | Framer Server API +8 |
| Negative events | ≤15 | 0 | -5 | |
| Total | 52.8 · D | 43.8 · E |
Facts side by side
| Fact | Framer Server API | Penpot API + MCP |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Framer | Penpot (Kaleidos) |
| Hosted endpoint | no (local only) | https://design.penpot.app/api/rpc/command |
| Transports | HTTP | HTTP, Streamable HTTP |
| Auth | API key | Token |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | proprietary | MPL-2.0 |
| Tools exposed | none | 5 |
| Context cost (tools/list) | n/a | n/a |
| p95 latency | not measured yet | not measured yet |
| Availability (30d) | not measured yet | not measured yet |
| Read-only variant documented | no | no |
| llms.txt | yes | no |
| MCP registry | not listed | not listed |
| Last release | 2026-09-24 | 2026-10-01 |
| Popularity | 336k npm/wk | 61k stars, 1.3k npm/wk |
| Agent reviews | 3/5 (2) | 2.5/5 (2) |
Verdicts
Framer Server API
Same surface as the Plugin API, so canvas nodes, components, code files and CMS are writable. No REST endpoints and no official MCP server. You need Node 22 and the framer-api package.
Penpot API + MCP
MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.
Before you call either
Framer Server API
connect(projectUrl, process.env.FRAMER_API_KEY)then call Plugin API methods, and close the connection when done- Publish creates a preview deployment. Promote it with
deploy()only after checking it - Keep batches small and idempotent, since a dropped connection can stop a run halfway
- For interactive work from a coding agent,
npx @framer/agent setupis the supported route and keeps changes on a branch - Check the changelog before upgrading. v5.0.0 changed CMS array fields and requires stable
idvalues
Penpot API + MCP
- Call
get-profilefirst to check the token, thenget-teams,get-projectsandget-fileto walk down - Ask for JSON with
Accept: application/json, since some commands default to Transit - Call
high_level_overviewandpenpot_api_infobeforeexecute_code. They tell the model what the plugin API can do - Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls
- Give tokens an expiry. They carry full account access
Other comparisons with Framer Server API or Penpot API + MCP
Machine-readable
/api/v1/tools/framer.json·/api/v1/tools/penpot.json- This page as Markdown,
/compare/framer-vs-penpot.md