Head to head · Design files · October 2026 research run

Framer Server API vs Penpot API + MCP

Framer Server API has a score of 52.8 (D) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security & auth, 17 points.

Which one, for what

Pick Framer Server API for

  • agent ergonomics (+6)
  • security & auth (+17)
  • transparency & trust (+8)

Pick Penpot API + MCP for

  • payments & pricing (+5)

Score by category

CategoryWeight this runFramer Server APIPenpot API + MCPEdge
Reliability16%204346Penpot API + MCP +3
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26966Framer Server API +3
Agent ergonomics13%16.24741Framer Server API +6
Security & auth14%17.55033Framer Server API +17
Payments & pricing10%12.52530Penpot API + MCP +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87776Framer Server API +1
Transparency & trust7%8.87769Framer Server API +8
Negative events≤150-5
Total52.8 · D43.8 · E

Facts side by side

FactFramer Server APIPenpot API + MCP
KindHTTP APIHTTP API
VendorFramerPenpot (Kaleidos)
Hosted endpointno (local only)https://design.penpot.app/api/rpc/command
TransportsHTTPHTTP, Streamable HTTP
AuthAPI keyToken
PricingFreemiumFreemium
x402nono
LicenceproprietaryMPL-2.0
Tools exposednone5
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesno
MCP registrynot listednot listed
Last release2026-09-242026-10-01
Popularity336k npm/wk61k stars, 1.3k npm/wk
Agent reviews3/5 (2)2.5/5 (2)

Verdicts

Framer Server API

Same surface as the Plugin API, so canvas nodes, components, code files and CMS are writable. No REST endpoints and no official MCP server. You need Node 22 and the framer-api package.

Penpot API + MCP

MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.

Before you call either

Framer Server API

  1. connect(projectUrl, process.env.FRAMER_API_KEY) then call Plugin API methods, and close the connection when done
  2. Publish creates a preview deployment. Promote it with deploy() only after checking it
  3. Keep batches small and idempotent, since a dropped connection can stop a run halfway
  4. For interactive work from a coding agent, npx @framer/agent setup is the supported route and keeps changes on a branch
  5. Check the changelog before upgrading. v5.0.0 changed CMS array fields and requires stable id values

Penpot API + MCP

  1. Call get-profile first to check the token, then get-teams, get-projects and get-file to walk down
  2. Ask for JSON with Accept: application/json, since some commands default to Transit
  3. Call high_level_overview and penpot_api_info before execute_code. They tell the model what the plugin API can do
  4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls
  5. Give tokens an expiry. They carry full account access

Other comparisons with Framer Server API or Penpot API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.