{
  "data": {
    "a": {
      "slug": "pen-dev",
      "name": "pen.dev",
      "vendor": "High Agency, Inc.",
      "vendorUrl": "https://pen.dev",
      "kind": "mcp",
      "category": "design",
      "summary": "Design canvas from High Agency, Inc. that stores designs as JSON `.pen` files. Agents edit them through a local MCP server in the desktop app or IDE extension, or through a headless CLI. It was called Pencil until 2026.",
      "url": "https://www.anchorterminal.com/tools/pen-dev",
      "markdownUrl": "https://www.anchorterminal.com/tools/pen-dev.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/pen-dev.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/pen-dev.json",
      "repo": "https://github.com/highagency/pen-desktop-releases",
      "license": "Proprietary. The CLI package on npm carries a proprietary licence file, and the apps fall under the vendor's EULA",
      "transports": [
        "stdio"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@pen.dev/cli"
        }
      ],
      "auth": "mixed",
      "authNotes": "A pen.dev account is required for the desktop app, the extension and the CLI. The MCP server takes no credential of its own and reaches the signed-in app over a local socket, after the owner enables each client in Settings, MCP. The CLI signs in with `pen login` (email with password or one-time code) or with `PEN_CLI_KEY`, an organisation-scoped key created in Developer Keys on the web app. No key scopes are documented. Access is self-serve.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 with 5 agent days and 25 image or SVG generations a month, including the CLI, MCP access and personal developer keys, so an agent's owner can start without a contract. Pro is $16 and Ultra $48 a user a month, and Enterprise is priced on request. Model usage on the user's own provider key is billed by that provider (https://pen.dev/pricing, checked 2026-10-08).",
      "priceSummary": "$16 / seat-mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the CLI reference (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 6,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 3548,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.pen.dev",
      "capabilities": [
        "design.files",
        "design.canvas",
        "design.components",
        "design.code"
      ],
      "tags": [
        "local",
        "desktop",
        "cli",
        "headless",
        "mcp",
        "stdio",
        "closed-source",
        "freemium",
        "free-tier",
        "vscode",
        "design-to-code"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 47.6,
        "grade": "D",
        "agentReady": false,
        "rank": 740,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 66,
          "maintenance": 59,
          "payments": 38,
          "reliability": 33,
          "schema": 61,
          "security": 33,
          "transparency": 53
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "An agent can create, edit and export `.pen` designs without a GUI through the `pen` CLI, with four compact MCP tools that carry annotations and a documented JSON format. The software is closed and needs a pen.dev account. No changelog, status page or security contact was found, and 14 public issue reports had no reply on 8 October 2026.",
        "bestFor": "A coding agent that designs screens beside the code and keeps them in Git, including in CI.",
        "strengths": [
          "Headless CLI (`@pen.dev/cli`) runs the same editor engine as the desktop app and exports PNG, JPEG, WEBP, PDF and HTML",
          "Four standard MCP tools with typed inputs and readOnlyHint and destructiveHint annotations, plus two conditional tools",
          "The `.pen` format is JSON with a published TypeScript schema, so designs sit in Git beside code",
          "Free plan includes the CLI, MCP access and personal developer keys, with five agent days a month",
          "Privacy policy has a retention table and says prompts sent with the user's own provider key never reach the vendor's servers"
        ],
        "weaknesses": [
          "No changelog. The three desktop releases on GitHub have empty notes, and the format docs reserve the right to make breaking changes",
          "14 issues opened between 28 July and 6 October 2026 in highagency/pen-desktop-releases had no comment or closure on 8 October",
          "No status page, security.txt, disclosure policy, bug bounty or certification was found",
          "`execute` takes one JavaScript snippet and carries destructiveHint true, with no read-only mode for an external MCP client",
          "Closed source under a proprietary licence that forbids reverse engineering, and every surface needs a pen.dev account"
        ],
        "agentNotes": [
          "Call `read_skill()`, then `read_skill({ path: \"pen-schema.md\" })` and `read_skill({ path: \"execute.md\" })` before the first `execute`. The tool description alone doesn't document the operations",
          "Call `get_app_state()` and confirm the active document before editing. The MCP server works on whichever `.pen` file is open in the app",
          "In headless `pen interactive`, call `save()` before `exit()`, and keep `--in` and `--out` on different paths to preserve the source",
          "Check that an export file exists. The docs say an export failure can print an error without a nonzero exit status",
          "In CI set `PEN_CLI_KEY` plus a provider key such as `ANTHROPIC_API_KEY`. Run `pen version`, since `pen --version` is not a flag"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 47.6
          }
        ],
        "editorialScores": {
          "ergonomics": 66,
          "maintenance": 59,
          "payments": 38,
          "reliability": 33,
          "schema": 61,
          "security": 33,
          "transparency": 54
        },
        "provenanceScore": 51
      },
      "connect": {
        "install": "npm install -g @pen.dev/cli",
        "headless": {
          "command": "pen --out design.pen --prompt \"$TASK\"",
          "env": {
            "ANTHROPIC_API_KEY": "\u003ckey\u003e",
            "PEN_CLI_KEY": "\u003ckey starting pencil_cli_\u003e"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/design.files",
        "tool": "https://letme.dev/pen-dev"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "seat-month",
          "usd": 16,
          "note": "unlimited agent days, 350 image or SVG generations a month, up to 3 agents in parallel"
        },
        {
          "item": "Ultra plan",
          "unit": "seat-month",
          "usd": 48,
          "note": "750 image or SVG generations a month, up to 6 agents in parallel"
        }
      ],
      "provenance": {
        "legalEntity": "High Agency, Inc.",
        "domain": "pen.dev",
        "domainRegistered": "2025-09-10",
        "endpointOnVendorDomain": true,
        "terms": "https://pen.dev/terms-of-use",
        "privacy": "https://pen.dev/privacy-policy",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms of use, EULA and privacy policy, each effective 6 October 2026, name High Agency, Inc., 440 N Barranca Ave #2993, Covina, CA 91723, USA, and choose Delaware law.",
          "The terms of use cover the desktop app, web app, extensions and CLI and hold the billing terms. A separate EULA at https://pen.dev/eula governs the installed software and prevails for it where the two conflict.",
          "The MCP server is local. The CLI and app sign in against https://api.pen.dev, and the web app is app.pen.dev.",
          "RDAP gives pen.dev a registration date of 2025-09-10 with Name.com, and pencil.dev the same day with GoDaddy. www.pencil.dev now answers with the pen.dev site.",
          "pen.dev/.well-known/security.txt and /security.txt return 404. status.pen.dev, pen.dev/changelog and pen.dev/security return 404.",
          "The footer says the company is backed by a16z speedrun."
        ],
        "score": 51
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/pen-dev.json"
    },
    "answer": "pen.dev scores 47.6 (D) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 2 of 7 scored categories. Penpot API + MCP leads on reliability, schema \u0026 documentation, maintenance \u0026 community and transparency \u0026 trust.",
    "b": {
      "slug": "penpot",
      "name": "Penpot API + MCP",
      "vendor": "Penpot (Kaleidos)",
      "vendorUrl": "https://penpot.app",
      "kind": "http-api",
      "category": "design",
      "summary": "Open-source design and prototyping tool, used as SaaS at design.penpot.app or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/penpot",
      "markdownUrl": "https://www.anchorterminal.com/tools/penpot.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/penpot.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/penpot.json",
      "repo": "https://github.com/penpot/penpot",
      "license": "MPL-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://design.penpot.app/api/rpc/command",
      "packages": [
        {
          "registry": "npm",
          "name": "@penpot/mcp"
        }
      ],
      "auth": "pat",
      "authNotes": "Personal access tokens from account settings, sent as `Authorization: Token \u003ctoken\u003e`. The hosted MCP URL takes a separate MCP key in the `userToken` query parameter. The local MCP server (`npx @penpot/mcp@stable`) talks to the plugin over a WebSocket on localhost.",
      "pricing": "freemium",
      "pricingNotes": "Cloud Professional plan is free with unlimited files and team members. Unlimited $7 per editor a month, capped at $175 a month. Enterprise $25 per member a month, minimum $950 a month. Private server $50,000 a year. Self-hosting the community edition is free under MPL-2.0, and self-hosted Enterprise starts at $950 a month (https://penpot.app/pricing).",
      "priceSummary": "$7 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No payment support in the API or MCP docs.",
        "endpoints": []
      },
      "toolCount": 5,
      "popularity": {
        "githubStars": 60534,
        "npmWeekly": 1259,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://help.penpot.app/technical-guide/integration/",
      "openapi": "https://design.penpot.app/api/main/doc/openapi",
      "capabilities": [
        "design.files",
        "design.components",
        "design.canvas",
        "design.comments",
        "design.code"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "mcp",
        "openapi",
        "webhooks"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 43.5,
        "grade": "E",
        "agentReady": false,
        "rank": 783,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 41,
          "maintenance": 76,
          "payments": 30,
          "reliability": 46,
          "schema": 66,
          "security": 33,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "-3: 2026-05-19, three advisories published together, a critical pre-authenticated account takeover through team-invitation tokens (GHSA-4937-35vc-hqjj), an MCP REPL server bound to 0.0.0.0 with an unauthenticated /execute endpoint allowing remote code execution (GHSA-22qr-rp27-j9wm, high) and authenticated SSRF in remote image import (GHSA-35g2-w7f6-8v9h, high). Fixed and published, so the deduction is reduced (https://github.com/penpot/penpot/security).",
          "-1: 2026-02-16, arbitrary file read through the create-font-variant RPC endpoint (GHSA-xp3f-g8rq-9px2, high). Fixed and published (https://github.com/penpot/penpot/security).",
          "-1: 2.18.0 (2026-09-23) fixed MCP keys being usable as full API access tokens, while the documented hosted setup puts that key in a URL query string, and fixed the MCP REPL starting in multi-user mode on the main bind address. Fixed in the changelog with no advisory (https://github.com/penpot/penpot/blob/develop/CHANGES.md)."
        ],
        "verdict": "MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.",
        "bestFor": "Teams that want design files on their own servers and an agent working alongside a person in the editor.",
        "strengths": [
          "MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan",
          "MCP `execute_code` reaches the whole plugin API, so an agent can create, move, restyle and delete shapes",
          "OpenAPI description served by every instance",
          "Five releases between 22 July and 1 October 2026, with issues labelled and milestoned within a day"
        ],
        "weaknesses": [
          "Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string",
          "No annotations on MCP tools and no read-only mode",
          "Four advisories in 2026, including MCP REPL remote code execution",
          "The MCP server needs the Penpot plugin open in a browser tab, so it can't run headless",
          "No status page, published rate limits or webhook documentation"
        ],
        "agentNotes": [
          "Call `get-profile` first to check the token, then `get-teams`, `get-projects` and `get-file` to walk down",
          "Ask for JSON with `Accept: application/json`, since some commands default to Transit",
          "Call `high_level_overview` and `penpot_api_info` before `execute_code`. They tell the model what the plugin API can do",
          "Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls",
          "Give tokens an expiry. They carry full account access"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 43.5
          }
        ],
        "editorialScores": {
          "ergonomics": 41,
          "maintenance": 76,
          "payments": 30,
          "reliability": 46,
          "schema": 66,
          "security": 33,
          "transparency": 61
        },
        "provenanceScore": 70
      },
      "connect": {
        "http": "curl -H \"Authorization: Token $PENPOT_TOKEN\" https://design.penpot.app/api/rpc/command/get-profile",
        "claudeCode": "claude mcp add --transport http penpot \"https://design.penpot.app/mcp/stream?userToken=$PENPOT_MCP_KEY\"",
        "config": {
          "mcpServers": {
            "penpot": {
              "url": "https://design.penpot.app/mcp/stream?userToken=${PENPOT_MCP_KEY}"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/design.files",
        "tool": "https://letme.dev/penpot"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Unlimited plan",
          "unit": "seat-month",
          "usd": 7,
          "note": "per editor, capped at $175 a month"
        },
        {
          "item": "Enterprise plan",
          "unit": "seat-month",
          "usd": 25,
          "note": "minimum $950 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Kaleidos Subsidiary SL",
        "domain": "penpot.app",
        "domainRegistered": "2020-05-26",
        "domainNote": "The site footer names KALEIDOS Subsidiary SL; Penpot is built by Kaleidos in Madrid.",
        "endpointOnVendorDomain": true,
        "terms": "https://penpot.app/terms",
        "privacy": "https://penpot.app/privacy",
        "statusPage": "",
        "changelog": "https://github.com/penpot/penpot/blob/develop/CHANGES.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "score": 70
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/penpot.json",
      "live": {
        "slug": "penpot",
        "probe": {
          "target": "https://design.penpot.app/api/rpc/command",
          "method": "get",
          "lastAt": "2026-10-09T09:27:00.418995624Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 118,
          "authRequired": false,
          "uptime24h": 99.23,
          "uptime30d": 99.91,
          "p50ms24h": 74,
          "p95ms24h": 137,
          "samples24h": 261,
          "samples30d": 2287,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 266
            },
            {
              "date": "2026-10-09",
              "probes": 101,
              "ok": 101
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "penpot/penpot",
            "version": "2.18.3",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:25:04.847886147Z"
          },
          {
            "registry": "npm",
            "name": "@penpot/mcp",
            "version": "2.15.4",
            "seenAt": "2026-10-08T16:25:03.845868588Z"
          }
        ],
        "githubStars": 60819,
        "npmWeekly": 1325,
        "securityTxt": {
          "url": "https://penpot.app/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:42.635545118Z"
        },
        "domain": {
          "domain": "penpot.app",
          "registered": "2020-05-26",
          "source": "https://pubapi.registry.google/rdap/domain/penpot.app",
          "checkedAt": "2026-10-04T13:04:30.014939182Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/penpot/penpot/develop/CHANGES.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-08T18:24:37.830244856Z",
            "changedAt": "2026-10-07T18:09:22.72857124Z",
            "fingerprint": "d7de8bf8741b"
          },
          {
            "url": "https://penpot.app/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:53.270246884Z",
            "changedAt": "2026-10-08T18:22:53.270246884Z",
            "fingerprint": "fac322cd664f"
          },
          {
            "url": "https://penpot.app/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:55.558773603Z",
            "changedAt": "2026-10-08T18:22:55.558773603Z",
            "fingerprint": "435ffd85741d"
          },
          {
            "url": "https://penpot.app/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:57.540300931Z",
            "changedAt": "2026-10-08T18:22:57.540300931Z",
            "fingerprint": "e07ca8b29548"
          }
        ],
        "updatedAt": "2026-10-09T09:27:00.418995624Z"
      }
    },
    "facts": [
      {
        "a": "MCP server",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "High Agency, Inc.",
        "b": "Penpot (Kaleidos)",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://design.penpot.app/api/rpc/command",
        "name": "Hosted endpoint"
      },
      {
        "a": "stdio",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "Token",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary. The CLI package on npm carries a proprietary licence file, and the apps fall under the vendor's EULA",
        "b": "MPL-2.0",
        "name": "Licence"
      },
      {
        "a": "6",
        "b": "5",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-08",
        "b": "2026-10-01",
        "name": "Last release"
      },
      {
        "a": "2026-10-06",
        "b": "2025-08-05",
        "name": "Terms last updated"
      },
      {
        "a": "2026-10-06",
        "b": "2025-08-05",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "3.5k npm/wk",
        "b": "61k stars, 1.3k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "2.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "pen.dev scores 47.6 (D) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 2 of 7 scored categories. Penpot API + MCP leads on reliability, schema \u0026 documentation, maintenance \u0026 community and transparency \u0026 trust.",
        "question": "Which is better for AI agents, pen.dev or Penpot API + MCP?"
      },
      {
        "answer": "pen.dev takes an API key or an OAuth sign-in. Penpot API + MCP needs an access token.",
        "question": "Do pen.dev and Penpot API + MCP need an API key?"
      },
      {
        "answer": "pen.dev runs on your own machine, with no hosted endpoint listed. Penpot API + MCP has a hosted endpoint at https://design.penpot.app/api/rpc/command.",
        "question": "Can an agent call pen.dev and Penpot API + MCP without installing anything?"
      },
      {
        "answer": "No open-source release is listed for pen.dev. Penpot API + MCP is open source (MPL-2.0).",
        "question": "Are pen.dev and Penpot API + MCP open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Agent ergonomics, 66 against 41",
          "Payments \u0026 pricing, 38 against 30"
        ],
        "also": [
          "Runs on your own machine",
          "No incidents deducted, where Penpot API + MCP loses 5 points for them"
        ],
        "goodFor": "A coding agent that designs screens beside the code and keeps them in Git, including in CI.",
        "slug": "pen-dev",
        "watchFor": "No changelog. The three desktop releases on GitHub have empty notes, and the format docs reserve the right to make breaking changes"
      },
      {
        "aheadOn": [
          "Reliability, 46 against 33",
          "Schema \u0026 documentation, 66 against 61",
          "Maintenance \u0026 community, 76 against 59",
          "Transparency \u0026 trust, 66 against 53"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "Teams that want design files on their own servers and an agent working alongside a person in the editor.",
        "slug": "penpot",
        "watchFor": "Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string"
      }
    ],
    "job": {
      "capability": "design.files",
      "name": "Design files"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/figma-mcp-vs-pen-dev.json",
        "title": "Figma API + MCP vs pen.dev",
        "url": "https://www.anchorterminal.com/compare/figma-mcp-vs-pen-dev"
      },
      {
        "json": "https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.json",
        "title": "Figma API + MCP vs Penpot API + MCP",
        "url": "https://www.anchorterminal.com/compare/figma-mcp-vs-penpot"
      },
      {
        "json": "https://www.anchorterminal.com/compare/framer-vs-pen-dev.json",
        "title": "Framer Server API vs pen.dev",
        "url": "https://www.anchorterminal.com/compare/framer-vs-pen-dev"
      },
      {
        "json": "https://www.anchorterminal.com/compare/framer-vs-penpot.json",
        "title": "Framer Server API vs Penpot API + MCP",
        "url": "https://www.anchorterminal.com/compare/framer-vs-penpot"
      },
      {
        "json": "https://www.anchorterminal.com/compare/miro-vs-pen-dev.json",
        "title": "Miro API + MCP vs pen.dev",
        "url": "https://www.anchorterminal.com/compare/miro-vs-pen-dev"
      },
      {
        "json": "https://www.anchorterminal.com/compare/miro-vs-penpot.json",
        "title": "Miro API + MCP vs Penpot API + MCP",
        "url": "https://www.anchorterminal.com/compare/miro-vs-penpot"
      },
      {
        "json": "https://www.anchorterminal.com/compare/melius-vs-pen-dev.json",
        "title": "Melius vs pen.dev",
        "url": "https://www.anchorterminal.com/compare/melius-vs-pen-dev"
      },
      {
        "json": "https://www.anchorterminal.com/compare/melius-vs-penpot.json",
        "title": "Melius vs Penpot API + MCP",
        "url": "https://www.anchorterminal.com/compare/melius-vs-penpot"
      }
    ],
    "scores": [
      {
        "by": 13,
        "edge": "penpot",
        "key": "reliability",
        "name": "Reliability",
        "pen-dev": 33,
        "penpot": 46,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 5,
        "edge": "penpot",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "pen-dev": 61,
        "penpot": 66,
        "weight": 13
      },
      {
        "by": 25,
        "edge": "pen-dev",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "pen-dev": 66,
        "penpot": 41,
        "weight": 13
      },
      {
        "by": 0,
        "edge": "",
        "key": "security",
        "name": "Security \u0026 auth",
        "pen-dev": 33,
        "penpot": 33,
        "weight": 14
      },
      {
        "by": 8,
        "edge": "pen-dev",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "pen-dev": 38,
        "penpot": 30,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 17,
        "edge": "penpot",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "pen-dev": 59,
        "penpot": 76,
        "weight": 7
      },
      {
        "by": 13,
        "edge": "penpot",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "pen-dev": 53,
        "penpot": 66,
        "weight": 7
      }
    ],
    "summary": "pen.dev scores 47.6 (D) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 2 of 7 scored categories. Penpot API + MCP leads on reliability, schema \u0026 documentation, maintenance \u0026 community and transparency \u0026 trust. Both do design files.",
    "verdicts": {
      "pen-dev": "An agent can create, edit and export `.pen` designs without a GUI through the `pen` CLI, with four compact MCP tools that carry annotations and a documented JSON format. The software is closed and needs a pen.dev account. No changelog, status page or security contact was found, and 14 public issue reports had no reply on 8 October 2026.",
      "penpot": "MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/pen-dev-vs-penpot",
    "json": "https://www.anchorterminal.com/compare/pen-dev-vs-penpot.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/pen-dev-vs-penpot.md",
    "slim": "https://www.anchorterminal.com/compare/pen-dev-vs-penpot.min.md"
  },
  "markdown": "pen.dev scores 47.6 (D) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 2 of 7 scored categories. Penpot API + MCP leads on reliability, schema \u0026 documentation, maintenance \u0026 community and transparency \u0026 trust. Both do design files.\n\n- pen.dev: grade D, 47.6/100, rank #740 of 842. Markdown https://www.anchorterminal.com/tools/pen-dev.md · JSON https://www.anchorterminal.com/api/v1/tools/pen-dev.json\n- Penpot API + MCP: grade E, 43.5/100, rank #783 of 842. Markdown https://www.anchorterminal.com/tools/penpot.md · JSON https://www.anchorterminal.com/api/v1/tools/penpot.json\n\n## Which one, for what\n\n### pen.dev (D)\n\nGood for: A coding agent that designs screens beside the code and keeps them in Git, including in CI.\n\nAhead on:\n- Agent ergonomics, 66 against 41\n- Payments \u0026 pricing, 38 against 30\n\nAlso in its favour:\n- Runs on your own machine\n- No incidents deducted, where Penpot API + MCP loses 5 points for them\n\nWatch for: No changelog. The three desktop releases on GitHub have empty notes, and the format docs reserve the right to make breaking changes\n\n### Penpot API + MCP (E)\n\nGood for: Teams that want design files on their own servers and an agent working alongside a person in the editor.\n\nAhead on:\n- Reliability, 46 against 33\n- Schema \u0026 documentation, 66 against 61\n- Maintenance \u0026 community, 76 against 59\n- Transparency \u0026 trust, 66 against 53\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n- Open source\n\nWatch for: Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string\n\n\n## Score by category\n\n| Category | Weight | pen.dev | Penpot API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 33 | 46 | Penpot API + MCP +13 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 61 | 66 | Penpot API + MCP +5 |\n| Agent ergonomics | 13% (16.2 this run) | 66 | 41 | pen.dev +25 |\n| Security \u0026 auth | 14% (17.5 this run) | 33 | 33 | even |\n| Payments \u0026 pricing | 10% (12.5 this run) | 38 | 30 | pen.dev +8 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 59 | 76 | Penpot API + MCP +17 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 53 | 66 | Penpot API + MCP +13 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **47.6 · D** | **43.5 · E** | |\n\n## Facts side by side\n\n| Fact | pen.dev | Penpot API + MCP |\n| --- | --- | --- |\n| Kind | MCP server | HTTP API |\n| Vendor | High Agency, Inc. | Penpot (Kaleidos) |\n| Hosted endpoint | no (local only) | `https://design.penpot.app/api/rpc/command` |\n| Transports | stdio | HTTP, Streamable HTTP |\n| Auth | OAuth or key | Token |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary. The CLI package on npm carries a proprietary licence file, and the apps fall under the vendor's EULA | MPL-2.0 |\n| Tools exposed | 6 | 5 |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| Last release | 2026-10-08 | 2026-10-01 |\n| Terms last updated | 2026-10-06 | 2025-08-05 |\n| Privacy policy last updated | 2026-10-06 | 2025-08-05 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | yes | yes |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 3.5k npm/wk | 61k stars, 1.3k npm/wk |\n| Agent reviews | none | 2.5/5 (2) |\n\n## Verdicts\n\n**pen.dev.** An agent can create, edit and export `.pen` designs without a GUI through the `pen` CLI, with four compact MCP tools that carry annotations and a documented JSON format. The software is closed and needs a pen.dev account. No changelog, status page or security contact was found, and 14 public issue reports had no reply on 8 October 2026.\n\n**Penpot API + MCP.** MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.\n\n## Before you call either\n\n### pen.dev\n\n1. Call `read_skill()`, then `read_skill({ path: \"pen-schema.md\" })` and `read_skill({ path: \"execute.md\" })` before the first `execute`. The tool description alone doesn't document the operations\n2. Call `get_app_state()` and confirm the active document before editing. The MCP server works on whichever `.pen` file is open in the app\n3. In headless `pen interactive`, call `save()` before `exit()`, and keep `--in` and `--out` on different paths to preserve the source\n4. Check that an export file exists. The docs say an export failure can print an error without a nonzero exit status\n5. In CI set `PEN_CLI_KEY` plus a provider key such as `ANTHROPIC_API_KEY`. Run `pen version`, since `pen --version` is not a flag\n\n### Penpot API + MCP\n\n1. Call `get-profile` first to check the token, then `get-teams`, `get-projects` and `get-file` to walk down\n2. Ask for JSON with `Accept: application/json`, since some commands default to Transit\n3. Call `high_level_overview` and `penpot_api_info` before `execute_code`. They tell the model what the plugin API can do\n4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls\n5. Give tokens an expiry. They carry full account access\n\n## Questions\n\n### Which is better for AI agents, pen.dev or Penpot API + MCP?\n\npen.dev scores 47.6 (D) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 2 of 7 scored categories. Penpot API + MCP leads on reliability, schema \u0026 documentation, maintenance \u0026 community and transparency \u0026 trust.\n\n### Do pen.dev and Penpot API + MCP need an API key?\n\npen.dev takes an API key or an OAuth sign-in. Penpot API + MCP needs an access token.\n\n### Can an agent call pen.dev and Penpot API + MCP without installing anything?\n\npen.dev runs on your own machine, with no hosted endpoint listed. Penpot API + MCP has a hosted endpoint at https://design.penpot.app/api/rpc/command.\n\n### Are pen.dev and Penpot API + MCP open source?\n\nNo open-source release is listed for pen.dev. Penpot API + MCP is open source (MPL-2.0).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/pen-dev-vs-penpot.json, and with the fewest tokens: https://www.anchorterminal.com/compare/pen-dev-vs-penpot.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"pen-dev\", \"b\": \"penpot\"}`. From a terminal: `anchor compare pen-dev penpot`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/pen-dev.json and https://www.anchorterminal.com/api/v1/tools/penpot.json\n\n## Other comparisons with pen.dev or Penpot API + MCP\n\n- [Figma API + MCP vs pen.dev](https://www.anchorterminal.com/compare/figma-mcp-vs-pen-dev.md)\n- [Figma API + MCP vs Penpot API + MCP](https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.md)\n- [Framer Server API vs pen.dev](https://www.anchorterminal.com/compare/framer-vs-pen-dev.md)\n- [Framer Server API vs Penpot API + MCP](https://www.anchorterminal.com/compare/framer-vs-penpot.md)\n- [Miro API + MCP vs pen.dev](https://www.anchorterminal.com/compare/miro-vs-pen-dev.md)\n- [Miro API + MCP vs Penpot API + MCP](https://www.anchorterminal.com/compare/miro-vs-penpot.md)\n- [Melius vs pen.dev](https://www.anchorterminal.com/compare/melius-vs-pen-dev.md)\n- [Melius vs Penpot API + MCP](https://www.anchorterminal.com/compare/melius-vs-penpot.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "pen.dev vs Penpot API + MCP",
        "url": ""
      }
    ],
    "description": "pen.dev scores 47.6 (D) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 2 of 7 scored categories. Penpot API + MCP leads on reliability, schema \u0026 documentation, maintenance \u0026 community and transparency \u0026 trust. Both do design files. Category scores, facts…",
    "facts": [
      "pen.dev D 47.6",
      "Penpot API + MCP E 43.5",
      "scores"
    ],
    "h1": "pen.dev vs Penpot API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-pen-dev-vs-penpot.png",
    "path": "/compare/pen-dev-vs-penpot",
    "published": "2026-10-01",
    "section": "tools",
    "title": "pen.dev vs Penpot API + MCP for AI agents, D 47.6 vs E 43.5",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/pen-dev-vs-penpot"
  },
  "tokens": {
    "markdown": 2100,
    "slim": 730
  },
  "version": 1
}
