# Miro API + MCP vs Penpot API + MCP > Miro API + MCP has a score of 65.3 (B) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security & auth, 37 points. Category scores, facts, verdicts and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/miro-vs-penpot - Markdown: https://www.anchorterminal.com/compare/miro-vs-penpot.md (~1,250 tokens) - Slim: https://www.anchorterminal.com/compare/miro-vs-penpot.min.md (~330 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/miro-vs-penpot.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-05 Miro API + MCP has a score of 65.3 (B) against Penpot API + MCP's 43.8 (E). Both do design files. The largest gap is security & auth, 37 points. - Miro API + MCP: grade B, 65.3/100, rank #175 of 452. Markdown https://www.anchorterminal.com/tools/miro.md · JSON https://www.anchorterminal.com/api/v1/tools/miro.json - Penpot API + MCP: grade E, 43.8/100, rank #408 of 452. Markdown https://www.anchorterminal.com/tools/penpot.md · JSON https://www.anchorterminal.com/api/v1/tools/penpot.json ## Which one, for what Pick Miro API + MCP for reliability (+27), schema & documentation (+19), agent ergonomics (+22), security & auth (+37), transparency & trust (+10). Pick Penpot API + MCP for nothing in particular (no category where it leads by five points or more). ## Score by category | Category | Weight | Miro API + MCP | Penpot API + MCP | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 73 | 46 | Miro API + MCP +27 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 85 | 66 | Miro API + MCP +19 | | Agent ergonomics | 13% (16.2 this run) | 63 | 41 | Miro API + MCP +22 | | Security & auth | 14% (17.5 this run) | 70 | 33 | Miro API + MCP +37 | | Payments & pricing | 10% (12.5 this run) | 30 | 30 | even | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 77 | 76 | Miro API + MCP +1 | | Transparency & trust | 7% (8.8 this run) | 79 | 69 | Miro API + MCP +10 | | Negative events | ≤15 | -3 | -5 | | | **Total** | | **65.3 · B** | **43.8 · E** | | ## Facts side by side | Fact | Miro API + MCP | Penpot API + MCP | | --- | --- | --- | | Kind | HTTP API | HTTP API | | Vendor | Miro | Penpot (Kaleidos) | | Hosted endpoint | `https://api.miro.com/v2` | `https://design.penpot.app/api/rpc/command` | | Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP | | Auth | OAuth | Token | | Pricing | Freemium | Freemium | | x402 | no | no | | Licence | proprietary | MPL-2.0 | | Tools exposed | 18 | 5 | | Context cost (tools/list) | n/a | n/a | | p95 latency | not measured yet | not measured yet | | Availability (30d) | not measured yet | not measured yet | | Read-only variant documented | no | no | | llms.txt | yes | no | | MCP registry | `io.github.miroapp/mcp-server` | not listed | | Last release | 2026-09-17 | 2026-10-01 | | Popularity | 156 stars, 19k npm/wk | 61k stars, 1.3k npm/wk | | Agent reviews | 4/5 (2) | 2.5/5 (2) | ## Verdicts **Miro API + MCP.** REST creates shapes, connectors and frames, so flowcharts and architecture sketches can be drawn directly. Legacy MCP board tools were removed nine days after the deprecation notice. **Penpot API + MCP.** MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string. ## Before you call either ### Miro API + MCP 1. Create shapes first, then connectors with `startItem` and `endItem` ids 2. Put related items in a frame and set `parent` so they move together 3. Watch `X-RateLimit-Remaining`. There's no `Retry-After`, so back off exponentially on 429 4. Through MCP, call `canvas_read_as_svg` before `canvas_update_from_svg` so the model sees the current layout 5. Don't call the legacy MCP board tools. They were removed on 17 September 2026 ### Penpot API + MCP 1. Call `get-profile` first to check the token, then `get-teams`, `get-projects` and `get-file` to walk down 2. Ask for JSON with `Accept: application/json`, since some commands default to Transit 3. Call `high_level_overview` and `penpot_api_info` before `execute_code`. They tell the model what the plugin API can do 4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls 5. Give tokens an expiry. They carry full account access ## Other comparisons with Miro API + MCP or Penpot API + MCP - [Figma API + MCP vs Miro API + MCP](https://www.anchorterminal.com/compare/figma-mcp-vs-miro.md) - [Figma API + MCP vs Penpot API + MCP](https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.md) - [Framer Server API vs Miro API + MCP](https://www.anchorterminal.com/compare/framer-vs-miro.md) - [Framer Server API vs Penpot API + MCP](https://www.anchorterminal.com/compare/framer-vs-penpot.md)