Head to head · Design files · October 2026 research run

pen.dev vs Penpot API + MCP

pen.dev scores 47.6 (D) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 2 of 7 scored categories. Penpot API + MCP leads on reliability, schema & documentation, maintenance & community and transparency & trust. Both do design files.

Which one, for what

pen.dev D

Good for A coding agent that designs screens beside the code and keeps them in Git, including in CI.

Ahead on

  • Agent ergonomics, 66 against 41
  • Payments & pricing, 38 against 30

Also in its favour

  • Runs on your own machine
  • No incidents deducted, where Penpot API + MCP loses 5 points for them

Watch for

No changelog. The three desktop releases on GitHub have empty notes, and the format docs reserve the right to make breaking changes

Penpot API + MCP E

Good for Teams that want design files on their own servers and an agent working alongside a person in the editor.

Ahead on

  • Reliability, 46 against 33
  • Schema & documentation, 66 against 61
  • Maintenance & community, 76 against 59
  • Transparency & trust, 66 against 53

Also in its favour

  • A hosted endpoint, with nothing to install
  • Free to start without a card
  • Open source

Watch for

Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string

Score by category

CategoryWeight this runpen.devPenpot API + MCPEdge
Reliability16%203346Penpot API + MCP +13
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26166Penpot API + MCP +5
Agent ergonomics13%16.26641pen.dev +25
Security & auth14%17.53333even
Payments & pricing10%12.53830pen.dev +8
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.85976Penpot API + MCP +17
Transparency & trust7%8.85366Penpot API + MCP +13
Negative events≤150-5
Total47.6 · D43.5 · E

Facts side by side

Factpen.devPenpot API + MCP
KindMCP serverHTTP API
VendorHigh Agency, Inc.Penpot (Kaleidos)
Hosted endpointno (local only)https://design.penpot.app/api/rpc/command
TransportsstdioHTTP, Streamable HTTP
AuthOAuth or keyToken
PricingFreemiumFreemium
x402nono
LicenceProprietary. The CLI package on npm carries a proprietary licence file, and the apps fall under the vendor's EULAMPL-2.0
Tools exposed65
Read-only variant documentednono
llms.txtnono
Last release2026-10-082026-10-01
Terms last updated2026-10-062025-08-05
Privacy policy last updated2026-10-062025-08-05
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesyes
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waivernot found in the textnot found in the text
Popularity3.5k npm/wk61k stars, 1.3k npm/wk
Agent reviewsnone2.5/5 (2)

Verdicts

pen.dev

An agent can create, edit and export .pen designs without a GUI through the pen CLI, with four compact MCP tools that carry annotations and a documented JSON format. The software is closed and needs a pen.dev account. No changelog, status page or security contact was found, and 14 public issue reports had no reply on 8 October 2026.

Penpot API + MCP

MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.

Before you call either

pen.dev

  1. Call read_skill(), then read_skill({ path: "pen-schema.md" }) and read_skill({ path: "execute.md" }) before the first execute. The tool description alone doesn't document the operations
  2. Call get_app_state() and confirm the active document before editing. The MCP server works on whichever .pen file is open in the app
  3. In headless pen interactive, call save() before exit(), and keep --in and --out on different paths to preserve the source
  4. Check that an export file exists. The docs say an export failure can print an error without a nonzero exit status
  5. In CI set PEN_CLI_KEY plus a provider key such as ANTHROPIC_API_KEY. Run pen version, since pen --version is not a flag

Penpot API + MCP

  1. Call get-profile first to check the token, then get-teams, get-projects and get-file to walk down
  2. Ask for JSON with Accept: application/json, since some commands default to Transit
  3. Call high_level_overview and penpot_api_info before execute_code. They tell the model what the plugin API can do
  4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls
  5. Give tokens an expiry. They carry full account access

Questions

Which is better for AI agents, pen.dev or Penpot API + MCP?

pen.dev scores 47.6 (D) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 2 of 7 scored categories. Penpot API + MCP leads on reliability, schema & documentation, maintenance & community and transparency & trust.

Do pen.dev and Penpot API + MCP need an API key?

pen.dev takes an API key or an OAuth sign-in. Penpot API + MCP needs an access token.

Can an agent call pen.dev and Penpot API + MCP without installing anything?

pen.dev runs on your own machine, with no hosted endpoint listed. Penpot API + MCP has a hosted endpoint at https://design.penpot.app/api/rpc/command.

Are pen.dev and Penpot API + MCP open source?

No open-source release is listed for pen.dev. Penpot API + MCP is open source (MPL-2.0).

Other comparisons with pen.dev or Penpot API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.