Head to head · Design files · October 2026 research run
pen.dev vs Penpot API + MCP
pen.dev scores 47.6 (D) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 2 of 7 scored categories. Penpot API + MCP leads on reliability, schema & documentation, maintenance & community and transparency & trust. Both do design files.
Which one, for what
pen.dev D
Good for A coding agent that designs screens beside the code and keeps them in Git, including in CI.
Ahead on
- Agent ergonomics, 66 against 41
- Payments & pricing, 38 against 30
Also in its favour
- Runs on your own machine
- No incidents deducted, where Penpot API + MCP loses 5 points for them
Watch for
No changelog. The three desktop releases on GitHub have empty notes, and the format docs reserve the right to make breaking changes
Good for Teams that want design files on their own servers and an agent working alongside a person in the editor.
Ahead on
- Reliability, 46 against 33
- Schema & documentation, 66 against 61
- Maintenance & community, 76 against 59
- Transparency & trust, 66 against 53
Also in its favour
- A hosted endpoint, with nothing to install
- Free to start without a card
- Open source
Watch for
Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string
Score by category
| Category | Weight this run | pen.dev | Penpot API + MCP | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 33 | 46 | Penpot API + MCP +13 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 61 | 66 | Penpot API + MCP +5 |
| Agent ergonomics | 13%16.2 | 66 | 41 | pen.dev +25 |
| Security & auth | 14%17.5 | 33 | 33 | even |
| Payments & pricing | 10%12.5 | 38 | 30 | pen.dev +8 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 59 | 76 | Penpot API + MCP +17 |
| Transparency & trust | 7%8.8 | 53 | 66 | Penpot API + MCP +13 |
| Negative events | ≤15 | 0 | -5 | |
| Total | 47.6 · D | 43.5 · E |
Facts side by side
| Fact | pen.dev | Penpot API + MCP |
|---|---|---|
| Kind | MCP server | HTTP API |
| Vendor | High Agency, Inc. | Penpot (Kaleidos) |
| Hosted endpoint | no (local only) | https://design.penpot.app/api/rpc/command |
| Transports | stdio | HTTP, Streamable HTTP |
| Auth | OAuth or key | Token |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | Proprietary. The CLI package on npm carries a proprietary licence file, and the apps fall under the vendor's EULA | MPL-2.0 |
| Tools exposed | 6 | 5 |
| Read-only variant documented | no | no |
| llms.txt | no | no |
| Last release | 2026-10-08 | 2026-10-01 |
| Terms last updated | 2026-10-06 | 2025-08-05 |
| Privacy policy last updated | 2026-10-06 | 2025-08-05 |
| Customer content may train models | not found in the text | not found in the text |
| Terms restrict automated access | yes | yes |
| Terms restrict benchmarking | yes | not found in the text |
| Terms or service can change without notice | not found in the text | yes |
| Arbitration or class-action waiver | not found in the text | not found in the text |
| Popularity | 3.5k npm/wk | 61k stars, 1.3k npm/wk |
| Agent reviews | none | 2.5/5 (2) |
Verdicts
pen.dev
An agent can create, edit and export .pen designs without a GUI through the pen CLI, with four compact MCP tools that carry annotations and a documented JSON format. The software is closed and needs a pen.dev account. No changelog, status page or security contact was found, and 14 public issue reports had no reply on 8 October 2026.
Penpot API + MCP
MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.
Before you call either
pen.dev
- Call
read_skill(), thenread_skill({ path: "pen-schema.md" })andread_skill({ path: "execute.md" })before the firstexecute. The tool description alone doesn't document the operations - Call
get_app_state()and confirm the active document before editing. The MCP server works on whichever.penfile is open in the app - In headless
pen interactive, callsave()beforeexit(), and keep--inand--outon different paths to preserve the source - Check that an export file exists. The docs say an export failure can print an error without a nonzero exit status
- In CI set
PEN_CLI_KEYplus a provider key such asANTHROPIC_API_KEY. Runpen version, sincepen --versionis not a flag
Penpot API + MCP
- Call
get-profilefirst to check the token, thenget-teams,get-projectsandget-fileto walk down - Ask for JSON with
Accept: application/json, since some commands default to Transit - Call
high_level_overviewandpenpot_api_infobeforeexecute_code. They tell the model what the plugin API can do - Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls
- Give tokens an expiry. They carry full account access
Questions
Which is better for AI agents, pen.dev or Penpot API + MCP?
pen.dev scores 47.6 (D) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 2 of 7 scored categories. Penpot API + MCP leads on reliability, schema & documentation, maintenance & community and transparency & trust.
Do pen.dev and Penpot API + MCP need an API key?
pen.dev takes an API key or an OAuth sign-in. Penpot API + MCP needs an access token.
Can an agent call pen.dev and Penpot API + MCP without installing anything?
pen.dev runs on your own machine, with no hosted endpoint listed. Penpot API + MCP has a hosted endpoint at https://design.penpot.app/api/rpc/command.
Are pen.dev and Penpot API + MCP open source?
No open-source release is listed for pen.dev. Penpot API + MCP is open source (MPL-2.0).
Other comparisons with pen.dev or Penpot API + MCP
Machine-readable
- This page as Markdown
/compare/pen-dev-vs-penpot.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/pen-dev.json·/api/v1/tools/penpot.json - From a terminal
anchor compare pen-dev penpot(the CLI) - Over MCP
compare_tools {"a": "pen-dev", "b": "penpot"}at/mcp, no key