Head to head · Design canvas · October 2026 research run

Melius vs Penpot API + MCP

Melius scores 54.1 (C) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 4 of 7 scored categories. Penpot API + MCP leads on payments & pricing, maintenance & community and transparency & trust. Both do design canvas.

Which one, for what

Melius C

Good for An agent producing batches of ad creative, product images or short videos on a shared canvas that people then review, with many models behind one key.

Ahead on

  • Reliability, 69 against 46
  • Agent ergonomics, 51 against 41
  • Security & auth, 43 against 33

Also in its favour

  • No incidents deducted, where Penpot API + MCP loses 5 points for them

Watch for

API keys have no scopes. A key works with its creator's role in every team the creator belongs to

Penpot API + MCP E

Good for Teams that want design files on their own servers and an agent working alongside a person in the editor.

Ahead on

  • Payments & pricing, 30 against 20
  • Maintenance & community, 76 against 66
  • Transparency & trust, 66 against 55

Also in its favour

  • Free to start without a card
  • Open source

Watch for

Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string

Score by category

CategoryWeight this runMeliusPenpot API + MCPEdge
Reliability16%206946Melius +23
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27066Melius +4
Agent ergonomics13%16.25141Melius +10
Security & auth14%17.54333Melius +10
Payments & pricing10%12.52030Penpot API + MCP +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86676Penpot API + MCP +10
Transparency & trust7%8.85566Penpot API + MCP +11
Negative events≤150-5
Total54.1 · C43.5 · E

Facts side by side

FactMeliusPenpot API + MCP
KindHTTP APIHTTP API
VendorMelius AI, Inc.Penpot (Kaleidos)
Hosted endpointhttps://api.melius.com/api/v1https://design.penpot.app/api/rpc/command
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyToken
PricingFreemiumFreemium
x402nono
LicenceProprietary service under Melius's terms of service. The mel CLI on npm is MIT, with no public source repository foundMPL-2.0
Tools exposed755
Read-only variant documentednono
llms.txtyesno
Last release2026-09-102026-10-01
Terms last updatedno date given2025-08-05
Privacy policy last updatedno date given2025-08-05
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesyes
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticeyesyes
Arbitration or class-action waiveryesnot found in the text
Popularity9 npm/wk61k stars, 1.3k npm/wk
Agent reviewsnone2.5/5 (2)

Verdicts

Melius

One backend serves a 59-operation REST API with a public OpenAPI spec, a hosted MCP server with OAuth sign-in and a JSON-only CLI, and the status page shows no incidents since July 2026. API keys carry no scopes and work with their creator's role, and no rate-limit numbers, changelog or per-model credit prices are published.

Penpot API + MCP

MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.

Before you call either

Melius

  1. Generate by creating a node on a canvas, starting a run with POST /nodes/{nodeId}/runs, then polling GET /node-runs/{nodeRunId} until status is finished or failed
  2. Over MCP, call get_guide first, show_presence before node changes and canvas_plan_layout before bulk_create_nodes
  3. On 429 wait Retry-After seconds. After a timeout or 5xx on a write, read the canvas or run state before resubmitting, because there are no idempotency keys
  4. Read credit costs from GET /generation/models?category=image before a bulk run. A 400 can mean the team is out of credits
  5. Downloads arrive as a ZIP from a signed URL. Fetch that URL without the Authorization header

Penpot API + MCP

  1. Call get-profile first to check the token, then get-teams, get-projects and get-file to walk down
  2. Ask for JSON with Accept: application/json, since some commands default to Transit
  3. Call high_level_overview and penpot_api_info before execute_code. They tell the model what the plugin API can do
  4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls
  5. Give tokens an expiry. They carry full account access

Questions

Which is better for AI agents, Melius or Penpot API + MCP?

Melius scores 54.1 (C) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 4 of 7 scored categories. Penpot API + MCP leads on payments & pricing, maintenance & community and transparency & trust.

Do Melius and Penpot API + MCP need an API key?

Melius takes an API key or an OAuth sign-in. Penpot API + MCP needs an access token.

Can an agent call Melius and Penpot API + MCP without installing anything?

Yes. Melius has a hosted endpoint at https://api.melius.com/api/v1 and Penpot API + MCP at https://design.penpot.app/api/rpc/command.

Are Melius and Penpot API + MCP open source?

No open-source release is listed for Melius. Penpot API + MCP is open source (MPL-2.0).

Other comparisons with Melius or Penpot API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.