{
  "data": {
    "a": {
      "slug": "miro",
      "name": "Miro API + MCP",
      "vendor": "Miro",
      "vendorUrl": "https://miro.com",
      "kind": "http-api",
      "category": "design",
      "summary": "Miro's REST API v2 reads and writes boards and board items (sticky notes, shapes, connectors, frames, cards, text, images, documents), tags and members, so an agent can lay out diagrams as well as notes.",
      "url": "https://www.anchorterminal.com/tools/miro",
      "markdownUrl": "https://www.anchorterminal.com/tools/miro.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/miro.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/miro.json",
      "repo": "https://github.com/miroapp/miro-ai",
      "license": "proprietary",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.miro.com/v2",
      "packages": [
        {
          "registry": "npm",
          "name": "@mirohq/miro-api"
        }
      ],
      "auth": "oauth",
      "authNotes": "REST uses OAuth 2.0 tokens from a Miro app you create in the developer settings, with scopes such as boards:read and boards:write. The MCP server uses OAuth 2.1 with dynamic client registration and sees only boards the user can already open. On Enterprise, MCP is off until an admin enables it.",
      "pricing": "freemium",
      "pricingNotes": "Free plan with 3 editable boards. Starter $8 and Business $20 per member a month billed yearly (about 20 per cent more monthly). Enterprise custom, from 30 members. The REST API works on every plan. MCP tool calls a day are 100 on Free, 500 on Starter, 2,000 on Business and 10,000 on Enterprise (https://miro.com/pricing/).",
      "priceSummary": "$8 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No payment support in the REST or MCP docs.",
        "endpoints": []
      },
      "toolCount": 18,
      "popularity": {
        "githubStars": 156,
        "npmWeekly": 19028,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developers.miro.com/docs/rest-api-reference-guide",
      "llmsTxt": "https://developers.miro.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/miroapp/api-clients/main/packages/generator/spec.json",
      "registryName": "io.github.miroapp/mcp-server",
      "capabilities": [
        "design.files",
        "design.canvas",
        "design.comments",
        "diagram.create",
        "diagram.edit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "closed-source",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "enterprise"
      ],
      "lastRelease": "2026-09-17",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.3,
        "grade": "B",
        "agentReady": false,
        "rank": 175,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 2,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 77,
          "payments": 30,
          "reliability": 73,
          "schema": 85,
          "security": 70,
          "transparency": 79
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -3,
        "negativeNotes": [
          "-3: the changelog announced on 2026-09-08 that legacy MCP board tools would go, with a migration deadline of 14 September, and removed them on 2026-09-17. Notice was given, but nine days is short for a breaking change, so the lowest deduction (https://developers.miro.com/changelog.rss)."
        ],
        "verdict": "REST creates shapes, connectors and frames, so flowcharts and architecture sketches can be drawn directly. Legacy MCP board tools were removed nine days after the deprecation notice.",
        "strengths": [
          "REST creates shapes, connectors and frames, so flowcharts and architecture sketches can be drawn directly",
          "Hosted MCP server with OAuth 2.1 on every plan including Free, and no delete tool in its 18",
          "Published REST credit limits and MCP daily caps per plan",
          "ISO/IEC 27001, SOC 2 Type II, a public bug bounty and four data-residency regions",
          "Dated changelog with an RSS feed"
        ],
        "weaknesses": [
          "Legacy MCP board tools were removed nine days after the deprecation notice",
          "No prompt-injection guidance for board content written by collaborators",
          "OAuth scopes are coarse (`boards:read`, `boards:write`)",
          "The official Node client hasn't been released since February 2025",
          "MCP daily caps are low on Free (100) and Starter (500)"
        ],
        "agentNotes": [
          "Create shapes first, then connectors with `startItem` and `endItem` ids",
          "Put related items in a frame and set `parent` so they move together",
          "Watch `X-RateLimit-Remaining`. There's no `Retry-After`, so back off exponentially on 429",
          "Through MCP, call `canvas_read_as_svg` before `canvas_update_from_svg` so the model sees the current layout",
          "Don't call the legacy MCP board tools. They were removed on 17 September 2026"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 4,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.3
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 77,
          "payments": 30,
          "reliability": 73,
          "schema": 85,
          "security": 70,
          "transparency": 67
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl https://api.miro.com/v2/boards -H \"Authorization: Bearer $MIRO_ACCESS_TOKEN\"",
        "claudeCode": "claude mcp add --transport http miro https://mcp.miro.com/",
        "config": {
          "mcpServers": {
            "miro": {
              "url": "https://mcp.miro.com/"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/design.files",
        "tool": "https://letme.dev/miro"
      },
      "alsoIn": [
        "diagramming"
      ],
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Starter plan",
          "unit": "seat-month",
          "usd": 8,
          "note": "billed yearly, API and MCP included"
        },
        {
          "item": "Business plan",
          "unit": "seat-month",
          "usd": 20,
          "note": "billed yearly"
        }
      ],
      "provenance": {
        "legalEntity": "RealtimeBoard Inc. dba Miro",
        "domain": "miro.com",
        "domainRegistered": "1995-09-08",
        "domainNote": "miro.com was registered in 1995, long before RealtimeBoard renamed itself Miro in 2019.",
        "endpointOnVendorDomain": true,
        "terms": "https://miro.com/legal/terms-of-service/",
        "privacy": "https://miro.com/legal/privacy-policy/",
        "statusPage": "https://status.miro.com",
        "changelog": "https://developers.miro.com/changelog",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/miro.json",
      "live": {
        "slug": "miro",
        "probe": {
          "target": "https://api.miro.com/v2",
          "method": "get",
          "lastAt": "2026-10-05T01:43:41.3794889Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 89,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 99.91,
          "p50ms24h": 69,
          "p95ms24h": 123,
          "samples24h": 272,
          "samples30d": 1122,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 275
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.miro.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-05T01:46:37.994597922Z"
        },
        "versions": [
          {
            "registry": "mcp-registry",
            "name": "io.github.miroapp/mcp-server",
            "version": "1.0.2",
            "seenAt": "2026-10-04T23:42:40.113054682Z"
          },
          {
            "registry": "npm",
            "name": "@mirohq/miro-api",
            "version": "2.2.4",
            "seenAt": "2026-10-04T16:33:18.699471156Z"
          }
        ],
        "githubStars": 159,
        "npmWeekly": 23752,
        "securityTxt": {
          "url": "https://miro.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:40.18940121Z"
        },
        "llmsTxt": {
          "url": "https://developers.miro.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:58.983960622Z"
        },
        "domain": {
          "domain": "miro.com",
          "registered": "1995-09-08",
          "source": "https://rdap.verisign.com/com/v1/domain/miro.com",
          "checkedAt": "2026-10-04T13:10:39.715166897Z"
        },
        "pages": [
          {
            "url": "https://developers.miro.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:59.013238468Z",
            "changedAt": "2026-10-04T15:42:59.013238468Z",
            "fingerprint": "e14c99df0851"
          },
          {
            "url": "https://miro.com/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:03.716994192Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a1d5947bca11"
          },
          {
            "url": "https://miro.com/legal/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:59.582490288Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "143fa2733740"
          },
          {
            "url": "https://miro.com/legal/terms-of-service/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:01.674619063Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "64f4211c5b7e"
          }
        ],
        "updatedAt": "2026-10-05T01:46:37.994597922Z"
      }
    },
    "b": {
      "slug": "penpot",
      "name": "Penpot API + MCP",
      "vendor": "Penpot (Kaleidos)",
      "vendorUrl": "https://penpot.app",
      "kind": "http-api",
      "category": "design",
      "summary": "Open-source design and prototyping tool, used as SaaS at design.penpot.app or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/penpot",
      "markdownUrl": "https://www.anchorterminal.com/tools/penpot.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/penpot.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/penpot.json",
      "repo": "https://github.com/penpot/penpot",
      "license": "MPL-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://design.penpot.app/api/rpc/command",
      "packages": [
        {
          "registry": "npm",
          "name": "@penpot/mcp"
        }
      ],
      "auth": "pat",
      "authNotes": "Personal access tokens from account settings, sent as `Authorization: Token \u003ctoken\u003e`. The hosted MCP URL takes a separate MCP key in the `userToken` query parameter. The local MCP server (`npx @penpot/mcp@stable`) talks to the plugin over a WebSocket on localhost.",
      "pricing": "freemium",
      "pricingNotes": "Cloud Professional plan is free with unlimited files and team members. Unlimited $7 per editor a month, capped at $175 a month. Enterprise $25 per member a month, minimum $950 a month. Private server $50,000 a year. Self-hosting the community edition is free under MPL-2.0, and self-hosted Enterprise starts at $950 a month (https://penpot.app/pricing).",
      "priceSummary": "$7 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No payment support in the API or MCP docs.",
        "endpoints": []
      },
      "toolCount": 5,
      "popularity": {
        "githubStars": 60534,
        "npmWeekly": 1259,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://help.penpot.app/technical-guide/integration/",
      "openapi": "https://design.penpot.app/api/main/doc/openapi",
      "capabilities": [
        "design.files",
        "design.components",
        "design.canvas",
        "design.comments",
        "design.code"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "mcp",
        "openapi",
        "webhooks"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 43.8,
        "grade": "E",
        "agentReady": false,
        "rank": 408,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 4,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 41,
          "maintenance": 76,
          "payments": 30,
          "reliability": 46,
          "schema": 66,
          "security": 33,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "-3: 2026-05-19, three advisories published together, a critical pre-authenticated account takeover through team-invitation tokens (GHSA-4937-35vc-hqjj), an MCP REPL server bound to 0.0.0.0 with an unauthenticated /execute endpoint allowing remote code execution (GHSA-22qr-rp27-j9wm, high) and authenticated SSRF in remote image import (GHSA-35g2-w7f6-8v9h, high). Fixed and published, so the deduction is reduced (https://github.com/penpot/penpot/security).",
          "-1: 2026-02-16, arbitrary file read through the create-font-variant RPC endpoint (GHSA-xp3f-g8rq-9px2, high). Fixed and published (https://github.com/penpot/penpot/security).",
          "-1: 2.18.0 (2026-09-23) fixed MCP keys being usable as full API access tokens, while the documented hosted setup puts that key in a URL query string, and fixed the MCP REPL starting in multi-user mode on the main bind address. Fixed in the changelog with no advisory (https://github.com/penpot/penpot/blob/develop/CHANGES.md)."
        ],
        "verdict": "MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.",
        "strengths": [
          "MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan",
          "MCP `execute_code` reaches the whole plugin API, so an agent can create, move, restyle and delete shapes",
          "OpenAPI description served by every instance",
          "Five releases between 22 July and 1 October 2026, with issues labelled and milestoned within a day"
        ],
        "weaknesses": [
          "Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string",
          "No annotations on MCP tools and no read-only mode",
          "Four advisories in 2026, including MCP REPL remote code execution",
          "The MCP server needs the Penpot plugin open in a browser tab, so it can't run headless",
          "No status page, published rate limits or webhook documentation"
        ],
        "agentNotes": [
          "Call `get-profile` first to check the token, then `get-teams`, `get-projects` and `get-file` to walk down",
          "Ask for JSON with `Accept: application/json`, since some commands default to Transit",
          "Call `high_level_overview` and `penpot_api_info` before `execute_code`. They tell the model what the plugin API can do",
          "Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls",
          "Give tokens an expiry. They carry full account access"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 43.8
          }
        ],
        "editorialScores": {
          "ergonomics": 41,
          "maintenance": 76,
          "payments": 30,
          "reliability": 46,
          "schema": 66,
          "security": 33,
          "transparency": 61
        },
        "provenanceScore": 76
      },
      "connect": {
        "http": "curl -H \"Authorization: Token $PENPOT_TOKEN\" https://design.penpot.app/api/rpc/command/get-profile",
        "claudeCode": "claude mcp add --transport http penpot \"https://design.penpot.app/mcp/stream?userToken=$PENPOT_MCP_KEY\"",
        "config": {
          "mcpServers": {
            "penpot": {
              "url": "https://design.penpot.app/mcp/stream?userToken=${PENPOT_MCP_KEY}"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/design.files",
        "tool": "https://letme.dev/penpot"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Unlimited plan",
          "unit": "seat-month",
          "usd": 7,
          "note": "per editor, capped at $175 a month"
        },
        {
          "item": "Enterprise plan",
          "unit": "seat-month",
          "usd": 25,
          "note": "minimum $950 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Kaleidos Subsidiary SL",
        "domain": "penpot.app",
        "domainRegistered": "2020-05-26",
        "domainNote": "The site footer names KALEIDOS Subsidiary SL; Penpot is built by Kaleidos in Madrid.",
        "endpointOnVendorDomain": true,
        "terms": "https://penpot.app/terms",
        "privacy": "https://penpot.app/privacy",
        "statusPage": "",
        "changelog": "https://github.com/penpot/penpot/blob/develop/CHANGES.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "score": 76
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/penpot.json",
      "live": {
        "slug": "penpot",
        "probe": {
          "target": "https://design.penpot.app/api/rpc/command",
          "method": "get",
          "lastAt": "2026-10-05T01:43:42.891344031Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 64,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 63,
          "p95ms24h": 127,
          "samples24h": 272,
          "samples30d": 1122,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "penpot/penpot",
            "version": "2.18.1",
            "released": "2026-10-01",
            "seenAt": "2026-10-04T16:36:28.006932933Z"
          },
          {
            "registry": "npm",
            "name": "@penpot/mcp",
            "version": "2.15.4",
            "seenAt": "2026-10-04T16:36:27.156471232Z"
          }
        ],
        "githubStars": 60692,
        "npmWeekly": 1371,
        "securityTxt": {
          "url": "https://penpot.app/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:47.794701224Z"
        },
        "domain": {
          "domain": "penpot.app",
          "registered": "2020-05-26",
          "source": "https://pubapi.registry.google/rdap/domain/penpot.app",
          "checkedAt": "2026-10-04T13:04:30.014939182Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/penpot/penpot/develop/CHANGES.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:51.411949949Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1fd9afe4e019"
          },
          {
            "url": "https://penpot.app/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:39.612388012Z",
            "changedAt": "2026-10-02T15:22:53.103729165Z",
            "fingerprint": "8115f46015d2"
          },
          {
            "url": "https://penpot.app/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:41.891573285Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1ca40b39e068"
          },
          {
            "url": "https://penpot.app/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:43.78052384Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a9376c975871"
          }
        ],
        "updatedAt": "2026-10-05T01:43:42.891344031Z"
      }
    },
    "summary": "Miro API + MCP has a score of 65.3 (B) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security \u0026 auth, 37 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/miro-vs-penpot",
    "json": "https://www.anchorterminal.com/compare/miro-vs-penpot.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/miro-vs-penpot.md",
    "slim": "https://www.anchorterminal.com/compare/miro-vs-penpot.min.md"
  },
  "markdown": "Miro API + MCP has a score of 65.3 (B) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security \u0026 auth, 37 points.\n\n- Miro API + MCP: grade B, 65.3/100, rank #175 of 452. Markdown https://www.anchorterminal.com/tools/miro.md · JSON https://www.anchorterminal.com/api/v1/tools/miro.json\n- Penpot API + MCP: grade E, 43.8/100, rank #408 of 452. Markdown https://www.anchorterminal.com/tools/penpot.md · JSON https://www.anchorterminal.com/api/v1/tools/penpot.json\n\n## Which one, for what\n\nPick Miro API + MCP for reliability (+27), schema \u0026 documentation (+19), agent ergonomics (+22), security \u0026 auth (+37), transparency \u0026 trust (+10).\n\nPick Penpot API + MCP for nothing in particular (no category where it leads by five points or more).\n\n## Score by category\n\n| Category | Weight | Miro API + MCP | Penpot API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 73 | 46 | Miro API + MCP +27 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 85 | 66 | Miro API + MCP +19 |\n| Agent ergonomics | 13% (16.2 this run) | 63 | 41 | Miro API + MCP +22 |\n| Security \u0026 auth | 14% (17.5 this run) | 70 | 33 | Miro API + MCP +37 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 30 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 77 | 76 | Miro API + MCP +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 79 | 69 | Miro API + MCP +10 |\n| Negative events | ≤15 | -3 | -5 | |\n| **Total** | | **65.3 · B** | **43.8 · E** | |\n\n## Facts side by side\n\n| Fact | Miro API + MCP | Penpot API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Miro | Penpot (Kaleidos) |\n| Hosted endpoint | `https://api.miro.com/v2` | `https://design.penpot.app/api/rpc/command` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth | Token |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | proprietary | MPL-2.0 |\n| Tools exposed | 18 | 5 |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| MCP registry | `io.github.miroapp/mcp-server` | not listed |\n| Last release | 2026-09-17 | 2026-10-01 |\n| Popularity | 156 stars, 19k npm/wk | 61k stars, 1.3k npm/wk |\n| Agent reviews | 4/5 (2) | 2.5/5 (2) |\n\n## Verdicts\n\n**Miro API + MCP.** REST creates shapes, connectors and frames, so flowcharts and architecture sketches can be drawn directly. Legacy MCP board tools were removed nine days after the deprecation notice.\n\n**Penpot API + MCP.** MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.\n\n## Before you call either\n\n### Miro API + MCP\n\n1. Create shapes first, then connectors with `startItem` and `endItem` ids\n2. Put related items in a frame and set `parent` so they move together\n3. Watch `X-RateLimit-Remaining`. There's no `Retry-After`, so back off exponentially on 429\n4. Through MCP, call `canvas_read_as_svg` before `canvas_update_from_svg` so the model sees the current layout\n5. Don't call the legacy MCP board tools. They were removed on 17 September 2026\n\n### Penpot API + MCP\n\n1. Call `get-profile` first to check the token, then `get-teams`, `get-projects` and `get-file` to walk down\n2. Ask for JSON with `Accept: application/json`, since some commands default to Transit\n3. Call `high_level_overview` and `penpot_api_info` before `execute_code`. They tell the model what the plugin API can do\n4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls\n5. Give tokens an expiry. They carry full account access\n\n## Other comparisons with Miro API + MCP or Penpot API + MCP\n\n- [Figma API + MCP vs Miro API + MCP](https://www.anchorterminal.com/compare/figma-mcp-vs-miro.md)\n- [Figma API + MCP vs Penpot API + MCP](https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.md)\n- [Framer Server API vs Miro API + MCP](https://www.anchorterminal.com/compare/framer-vs-miro.md)\n- [Framer Server API vs Penpot API + MCP](https://www.anchorterminal.com/compare/framer-vs-penpot.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Miro API + MCP vs Penpot API + MCP",
        "url": ""
      }
    ],
    "description": "Miro API + MCP has a score of 65.3 (B) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security \u0026 auth, 37 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Miro API + MCP B 65.3",
      "Penpot API + MCP E 43.8",
      "scores"
    ],
    "h1": "Miro API + MCP vs Penpot API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-miro-vs-penpot.png",
    "path": "/compare/miro-vs-penpot",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Miro API + MCP vs Penpot API + MCP for AI agents, B 65.3 vs E 43.8",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/miro-vs-penpot"
  },
  "tokens": {
    "markdown": 1250,
    "slim": 330
  },
  "version": 1
}
