Head to head · Design canvas · October 2026 research run
Melius vs Penpot API + MCP
Melius scores 54.1 (C) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 4 of 7 scored categories. Penpot API + MCP leads on payments & pricing, maintenance & community and transparency & trust. Both do design canvas.
Which one, for what
Melius C
Good for An agent producing batches of ad creative, product images or short videos on a shared canvas that people then review, with many models behind one key.
Ahead on
- Reliability, 69 against 46
- Agent ergonomics, 51 against 41
- Security & auth, 43 against 33
Also in its favour
- No incidents deducted, where Penpot API + MCP loses 5 points for them
Watch for
API keys have no scopes. A key works with its creator's role in every team the creator belongs to
Good for Teams that want design files on their own servers and an agent working alongside a person in the editor.
Ahead on
- Payments & pricing, 30 against 20
- Maintenance & community, 76 against 66
- Transparency & trust, 66 against 55
Also in its favour
- Free to start without a card
- Open source
Watch for
Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string
Score by category
| Category | Weight this run | Melius | Penpot API + MCP | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 69 | 46 | Melius +23 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 70 | 66 | Melius +4 |
| Agent ergonomics | 13%16.2 | 51 | 41 | Melius +10 |
| Security & auth | 14%17.5 | 43 | 33 | Melius +10 |
| Payments & pricing | 10%12.5 | 20 | 30 | Penpot API + MCP +10 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 66 | 76 | Penpot API + MCP +10 |
| Transparency & trust | 7%8.8 | 55 | 66 | Penpot API + MCP +11 |
| Negative events | ≤15 | 0 | -5 | |
| Total | 54.1 · C | 43.5 · E |
Facts side by side
| Fact | Melius | Penpot API + MCP |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Melius AI, Inc. | Penpot (Kaleidos) |
| Hosted endpoint | https://api.melius.com/api/v1 | https://design.penpot.app/api/rpc/command |
| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |
| Auth | OAuth or key | Token |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | Proprietary service under Melius's terms of service. The mel CLI on npm is MIT, with no public source repository found | MPL-2.0 |
| Tools exposed | 75 | 5 |
| Read-only variant documented | no | no |
| llms.txt | yes | no |
| Last release | 2026-09-10 | 2026-10-01 |
| Terms last updated | no date given | 2025-08-05 |
| Privacy policy last updated | no date given | 2025-08-05 |
| Customer content may train models | not found in the text | not found in the text |
| Terms restrict automated access | yes | yes |
| Terms restrict benchmarking | yes | not found in the text |
| Terms or service can change without notice | yes | yes |
| Arbitration or class-action waiver | yes | not found in the text |
| Popularity | 9 npm/wk | 61k stars, 1.3k npm/wk |
| Agent reviews | none | 2.5/5 (2) |
Verdicts
Melius
One backend serves a 59-operation REST API with a public OpenAPI spec, a hosted MCP server with OAuth sign-in and a JSON-only CLI, and the status page shows no incidents since July 2026. API keys carry no scopes and work with their creator's role, and no rate-limit numbers, changelog or per-model credit prices are published.
Penpot API + MCP
MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.
Before you call either
Melius
- Generate by creating a node on a canvas, starting a run with POST /nodes/{nodeId}/runs, then polling GET /node-runs/{nodeRunId} until
statusis finished or failed - Over MCP, call
get_guidefirst,show_presencebefore node changes andcanvas_plan_layoutbeforebulk_create_nodes - On 429 wait
Retry-Afterseconds. After a timeout or 5xx on a write, read the canvas or run state before resubmitting, because there are no idempotency keys - Read credit costs from GET /generation/models?category=image before a bulk run. A 400 can mean the team is out of credits
- Downloads arrive as a ZIP from a signed URL. Fetch that URL without the
Authorizationheader
Penpot API + MCP
- Call
get-profilefirst to check the token, thenget-teams,get-projectsandget-fileto walk down - Ask for JSON with
Accept: application/json, since some commands default to Transit - Call
high_level_overviewandpenpot_api_infobeforeexecute_code. They tell the model what the plugin API can do - Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls
- Give tokens an expiry. They carry full account access
Questions
Which is better for AI agents, Melius or Penpot API + MCP?
Melius scores 54.1 (C) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 4 of 7 scored categories. Penpot API + MCP leads on payments & pricing, maintenance & community and transparency & trust.
Do Melius and Penpot API + MCP need an API key?
Melius takes an API key or an OAuth sign-in. Penpot API + MCP needs an access token.
Can an agent call Melius and Penpot API + MCP without installing anything?
Yes. Melius has a hosted endpoint at https://api.melius.com/api/v1 and Penpot API + MCP at https://design.penpot.app/api/rpc/command.
Are Melius and Penpot API + MCP open source?
No open-source release is listed for Melius. Penpot API + MCP is open source (MPL-2.0).
Other comparisons with Melius or Penpot API + MCP
Machine-readable
- This page as Markdown
/compare/melius-vs-penpot.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/melius.json·/api/v1/tools/penpot.json - From a terminal
anchor compare melius penpot(the CLI) - Over MCP
compare_tools {"a": "melius", "b": "penpot"}at/mcp, no key