Head to head · Design files · October 2026 research run

Miro API + MCP vs Penpot API + MCP

Miro API + MCP has a score of 65.3 (B) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security & auth, 37 points.

Which one, for what

Pick Miro API + MCP for

  • reliability (+27)
  • schema & documentation (+19)
  • agent ergonomics (+22)
  • security & auth (+37)
  • transparency & trust (+10)

Pick Penpot API + MCP for

No category where it leads by five points or more.

Score by category

CategoryWeight this runMiro API + MCPPenpot API + MCPEdge
Reliability16%207346Miro API + MCP +27
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28566Miro API + MCP +19
Agent ergonomics13%16.26341Miro API + MCP +22
Security & auth14%17.57033Miro API + MCP +37
Payments & pricing10%12.53030even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87776Miro API + MCP +1
Transparency & trust7%8.87969Miro API + MCP +10
Negative events≤15-3-5
Total65.3 · B43.8 · E

Facts side by side

FactMiro API + MCPPenpot API + MCP
KindHTTP APIHTTP API
VendorMiroPenpot (Kaleidos)
Hosted endpointhttps://api.miro.com/v2https://design.penpot.app/api/rpc/command
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuthToken
PricingFreemiumFreemium
x402nono
LicenceproprietaryMPL-2.0
Tools exposed185
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesno
MCP registryio.github.miroapp/mcp-servernot listed
Last release2026-09-172026-10-01
Popularity156 stars, 19k npm/wk61k stars, 1.3k npm/wk
Agent reviews4/5 (2)2.5/5 (2)

Verdicts

Miro API + MCP

REST creates shapes, connectors and frames, so flowcharts and architecture sketches can be drawn directly. Legacy MCP board tools were removed nine days after the deprecation notice.

Penpot API + MCP

MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.

Before you call either

Miro API + MCP

  1. Create shapes first, then connectors with startItem and endItem ids
  2. Put related items in a frame and set parent so they move together
  3. Watch X-RateLimit-Remaining. There's no Retry-After, so back off exponentially on 429
  4. Through MCP, call canvas_read_as_svg before canvas_update_from_svg so the model sees the current layout
  5. Don't call the legacy MCP board tools. They were removed on 17 September 2026

Penpot API + MCP

  1. Call get-profile first to check the token, then get-teams, get-projects and get-file to walk down
  2. Ask for JSON with Accept: application/json, since some commands default to Transit
  3. Call high_level_overview and penpot_api_info before execute_code. They tell the model what the plugin API can do
  4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls
  5. Give tokens an expiry. They carry full account access

Other comparisons with Miro API + MCP or Penpot API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.