{
  "data": {
    "a": {
      "slug": "pen-dev",
      "name": "pen.dev",
      "vendor": "High Agency, Inc.",
      "vendorUrl": "https://pen.dev",
      "kind": "mcp",
      "category": "design",
      "summary": "Design canvas from High Agency, Inc. that stores designs as JSON `.pen` files. Agents edit them through a local MCP server in the desktop app or IDE extension, or through a headless CLI. It was called Pencil until 2026.",
      "url": "https://www.anchorterminal.com/tools/pen-dev",
      "markdownUrl": "https://www.anchorterminal.com/tools/pen-dev.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/pen-dev.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/pen-dev.json",
      "repo": "https://github.com/highagency/pen-desktop-releases",
      "license": "Proprietary. The CLI package on npm carries a proprietary licence file, and the apps fall under the vendor's EULA",
      "transports": [
        "stdio"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@pen.dev/cli"
        }
      ],
      "auth": "mixed",
      "authNotes": "A pen.dev account is required for the desktop app, the extension and the CLI. The MCP server takes no credential of its own and reaches the signed-in app over a local socket, after the owner enables each client in Settings, MCP. The CLI signs in with `pen login` (email with password or one-time code) or with `PEN_CLI_KEY`, an organisation-scoped key created in Developer Keys on the web app. No key scopes are documented. Access is self-serve.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 with 5 agent days and 25 image or SVG generations a month, including the CLI, MCP access and personal developer keys, so an agent's owner can start without a contract. Pro is $16 and Ultra $48 a user a month, and Enterprise is priced on request. Model usage on the user's own provider key is billed by that provider (https://pen.dev/pricing, checked 2026-10-08).",
      "priceSummary": "$16 / seat-mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the CLI reference (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 6,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 3548,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.pen.dev",
      "capabilities": [
        "design.files",
        "design.canvas",
        "design.components",
        "design.code"
      ],
      "tags": [
        "local",
        "desktop",
        "cli",
        "headless",
        "mcp",
        "stdio",
        "closed-source",
        "freemium",
        "free-tier",
        "vscode",
        "design-to-code"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 47.6,
        "grade": "D",
        "agentReady": false,
        "rank": 832,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 66,
          "maintenance": 59,
          "payments": 38,
          "reliability": 33,
          "schema": 61,
          "security": 33,
          "transparency": 53
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "An agent can create, edit and export `.pen` designs without a GUI through the `pen` CLI, with four compact MCP tools that carry annotations and a documented JSON format. The software is closed and needs a pen.dev account. No changelog, status page or security contact was found, and 14 public issue reports had no reply on 8 October 2026.",
        "bestFor": "A coding agent that designs screens beside the code and keeps them in Git, including in CI.",
        "strengths": [
          "Headless CLI (`@pen.dev/cli`) runs the same editor engine as the desktop app and exports PNG, JPEG, WEBP, PDF and HTML",
          "Four standard MCP tools with typed inputs and readOnlyHint and destructiveHint annotations, plus two conditional tools",
          "The `.pen` format is JSON with a published TypeScript schema, so designs sit in Git beside code",
          "Free plan includes the CLI, MCP access and personal developer keys, with five agent days a month",
          "Privacy policy has a retention table and says prompts sent with the user's own provider key never reach the vendor's servers"
        ],
        "weaknesses": [
          "No changelog. The three desktop releases on GitHub have empty notes, and the format docs reserve the right to make breaking changes",
          "14 issues opened between 28 July and 6 October 2026 in highagency/pen-desktop-releases had no comment or closure on 8 October",
          "No status page, security.txt, disclosure policy, bug bounty or certification was found",
          "`execute` takes one JavaScript snippet and carries destructiveHint true, with no read-only mode for an external MCP client",
          "Closed source under a proprietary licence that forbids reverse engineering, and every surface needs a pen.dev account"
        ],
        "agentNotes": [
          "Call `read_skill()`, then `read_skill({ path: \"pen-schema.md\" })` and `read_skill({ path: \"execute.md\" })` before the first `execute`. The tool description alone doesn't document the operations",
          "Call `get_app_state()` and confirm the active document before editing. The MCP server works on whichever `.pen` file is open in the app",
          "In headless `pen interactive`, call `save()` before `exit()`, and keep `--in` and `--out` on different paths to preserve the source",
          "Check that an export file exists. The docs say an export failure can print an error without a nonzero exit status",
          "In CI set `PEN_CLI_KEY` plus a provider key such as `ANTHROPIC_API_KEY`. Run `pen version`, since `pen --version` is not a flag"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 47.6
          }
        ],
        "editorialScores": {
          "ergonomics": 66,
          "maintenance": 59,
          "payments": 38,
          "reliability": 33,
          "schema": 61,
          "security": 33,
          "transparency": 54
        },
        "provenanceScore": 51
      },
      "connect": {
        "install": "npm install -g @pen.dev/cli",
        "headless": {
          "command": "pen --out design.pen --prompt \"$TASK\"",
          "env": {
            "ANTHROPIC_API_KEY": "\u003ckey\u003e",
            "PEN_CLI_KEY": "\u003ckey starting pencil_cli_\u003e"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/design.files",
        "tool": "https://letme.dev/pen-dev"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "seat-month",
          "usd": 16,
          "note": "unlimited agent days, 350 image or SVG generations a month, up to 3 agents in parallel"
        },
        {
          "item": "Ultra plan",
          "unit": "seat-month",
          "usd": 48,
          "note": "750 image or SVG generations a month, up to 6 agents in parallel"
        }
      ],
      "provenance": {
        "legalEntity": "High Agency, Inc.",
        "domain": "pen.dev",
        "domainRegistered": "2025-09-10",
        "endpointOnVendorDomain": true,
        "terms": "https://pen.dev/terms-of-use",
        "privacy": "https://pen.dev/privacy-policy",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms of use, EULA and privacy policy, each effective 6 October 2026, name High Agency, Inc., 440 N Barranca Ave #2993, Covina, CA 91723, USA, and choose Delaware law.",
          "The terms of use cover the desktop app, web app, extensions and CLI and hold the billing terms. A separate EULA at https://pen.dev/eula governs the installed software and prevails for it where the two conflict.",
          "The MCP server is local. The CLI and app sign in against https://api.pen.dev, and the web app is app.pen.dev.",
          "RDAP gives pen.dev a registration date of 2025-09-10 with Name.com, and pencil.dev the same day with GoDaddy. www.pencil.dev now answers with the pen.dev site.",
          "pen.dev/.well-known/security.txt and /security.txt return 404. status.pen.dev, pen.dev/changelog and pen.dev/security return 404.",
          "The footer says the company is backed by a16z speedrun."
        ],
        "score": 51
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/pen-dev.json",
      "live": {
        "slug": "pen-dev",
        "versions": [
          {
            "registry": "github",
            "name": "highagency/pen-desktop-releases",
            "version": "v1.2.16",
            "released": "2026-10-08",
            "seenAt": "2026-10-09T17:12:26.673481677Z"
          },
          {
            "registry": "npm",
            "name": "@pen.dev/cli",
            "version": "0.3.11",
            "seenAt": "2026-10-09T17:12:26.399136026Z"
          }
        ],
        "githubStars": 1,
        "npmWeekly": 3431,
        "securityTxt": {
          "url": "https://pen.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:40:15.315318737Z"
        },
        "pages": [
          {
            "url": "https://pen.dev/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:09.445912384Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ed8fa3e44c29"
          },
          {
            "url": "https://pen.dev/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:11.510157249Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6c017a8257b0"
          },
          {
            "url": "https://pen.dev/terms-of-use",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:13.613926839Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "860c9c6b2b08"
          }
        ],
        "updatedAt": "2026-10-09T18:43:13.613926839Z"
      }
    },
    "answer": "pen.dev scores 47.6 (D) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on security \u0026 auth and maintenance \u0026 community.",
    "b": {
      "slug": "subframe",
      "name": "Subframe",
      "vendor": "Atomic Design Inc",
      "vendorUrl": "https://www.subframe.com",
      "kind": "mcp",
      "category": "design",
      "summary": "Design tool from Atomic Design Inc for React and Tailwind interfaces, with a cloud canvas and a macOS app. Agents read and edit pages, components and themes through a hosted MCP server, and a CLI syncs components into a codebase.",
      "url": "https://www.anchorterminal.com/tools/subframe",
      "markdownUrl": "https://www.anchorterminal.com/tools/subframe.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/subframe.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/subframe.json",
      "repo": "https://github.com/SubframeApp/subframe",
      "license": "Proprietary service under Atomic Design's terms of service. `@subframe/cli` and `@subframe/core` are marked ISC in their package files and the Claude Code plugin MIT in its manifest, with no licence file in the repository",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://mcp.subframe.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@subframe/cli"
        },
        {
          "registry": "npm",
          "name": "@subframe/core"
        }
      ],
      "auth": "mixed",
      "authNotes": "The MCP server takes OAuth only, with dynamic client registration and PKCE, and a person approves access in a browser. Subframe access tokens are not accepted there. What an agent can do follows the user's team role. Admins and Editors can write, and Viewers get a read-only server. The CLI takes an auth token from `SUBFRAME_AUTH_TOKEN` or `--auth-token`, created at app.subframe.com/cli/auth or by the `generate_auth_token` MCP tool. Tokens are shown once and can be deleted. No token scopes or expiry are documented. Access is self-serve.",
      "pricing": "freemium",
      "pricingNotes": "Free at $0 with one project, unlimited pages and members, and MCP and CLI access, so an agent's owner can start without a contract. Pro is $20 an editor a month for unlimited projects and six times the AI credits. Viewers are free on every plan. Custom plans are priced on request. MCP calls are not priced separately (https://www.subframe.com/, checked 2026-10-09).",
      "priceSummary": "$20 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing section or the CLI source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 46,
      "popularity": {
        "githubStars": 435,
        "npmWeekly": 1006,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.subframe.com",
      "llmsTxt": "https://docs.subframe.com/llms.txt",
      "capabilities": [
        "design.files",
        "design.components",
        "design.code",
        "design.canvas",
        "design.comments"
      ],
      "tags": [
        "hosted",
        "mcp",
        "oauth",
        "remote-mcp",
        "cli",
        "agent-skills",
        "react",
        "tailwind",
        "design-to-code",
        "freemium",
        "free-tier",
        "llms-txt",
        "closed-source",
        "macos"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 39.7,
        "grade": "E",
        "agentReady": false,
        "rank": 915,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 47,
          "maintenance": 65,
          "payments": 33,
          "reliability": 19,
          "schema": 54,
          "security": 44,
          "transparency": 57
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -3,
        "negativeNotes": [
          "23 to 24 September 2026. The docs and skill files renamed three MCP tools (`list_flows`, `get_flow_info`, `delete_flow`) to `list_canvases`, `get_canvas_info` and `delete_canvas`, with no changelog entry or notice found. Whether the server still answers the old names was not tested (-2). https://github.com/SubframeApp/subframe/commit/43bfb51d749713940cf0df8e73da2ab43b7358bc",
          "7 May 2026. A docs commit records that the MCP server 'no longer accepts CLI/access tokens, only OAuth', removing the documented header route for clients without OAuth, with no dated notice found (-1, older and documented since). https://github.com/SubframeApp/subframe/commit/ff59743593fa2b581f32233b58660ace8a23f707"
        ],
        "verdict": "An agent can read and change pages, components, snippets and themes in a Subframe project through a hosted MCP server with OAuth, and Viewer accounts get a read-only server. The server lists 46 tools, and no status page, rate limits, changelog or security contact were found. Three tools were renamed in September 2026 with no notice found.",
        "bestFor": "A coding agent working beside a team that designs React and Tailwind interfaces in Subframe and wants the design as code, with a read-only route for review.",
        "strengths": [
          "Hosted MCP server at `https://mcp.subframe.com/mcp` with OAuth, dynamic client registration and PKCE, so no key is pasted into a config file",
          "Viewer accounts get a read-only MCP server and read-only CLI access, and Viewer seats are free on every plan",
          "Write tools cover pages, components, snippets, design documents, themes, icons and fonts, and page reads return generated React and Tailwind code",
          "Docs publish `llms.txt`, a Markdown twin of every page and a separate docs MCP server that needs no credential",
          "The CLI has a non-interactive mode with `--json` output, nonzero exit status on failure and a token read from `SUBFRAME_AUTH_TOKEN`"
        ],
        "weaknesses": [
          "46 tools are documented with no toolsets, and the vendor's `design` skill that explains them is about 55 KB of text",
          "No status page, published rate limit, SLA or changelog was found, and the terms disclaim uninterrupted service",
          "`list_flows`, `get_flow_info` and `delete_flow` became `list_canvases`, `get_canvas_info` and `delete_canvas` in September 2026 with no notice found",
          "No security.txt, disclosure policy, bug bounty, certification or audit log was found",
          "Delete confirmation is guidance in the skill file. The vendor's skill calls deletes irreversible from MCP, with recovery only through version history in the editor (24 hours on Free)"
        ],
        "agentNotes": [
          "Connect with an MCP client that supports OAuth. The server rejects Subframe access tokens and static `Authorization` headers",
          "Pass `projectId` on every call. When it is omitted the server uses the first project the user can reach, which may be the wrong team's",
          "After `design_page`, `design_component` or `edit_component`, call `wait_for_jobs` with the `jobId` before reading the result. Earlier reads return stale content",
          "Ask the owner before any delete tool or a theme token deletion. A deleted token leaves every reference detached even after the token is restored",
          "For the CLI, set `SUBFRAME_AUTH_TOKEN` and `DO_NOT_TRACK=1`, and point `--dir` at a folder that holds only Subframe code, because a full sync removes other unprotected files"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 39.7
          }
        ],
        "editorialScores": {
          "ergonomics": 47,
          "maintenance": 65,
          "payments": 33,
          "reliability": 19,
          "schema": 54,
          "security": 44,
          "transparency": 46
        },
        "provenanceScore": 68
      },
      "connect": {
        "install": "npx @subframe/cli@latest init",
        "claudeCode": "claude plugin marketplace add https://github.com/SubframeApp/subframe \u0026\u0026 claude plugin install subframe@subframe",
        "config": {
          "mcpServers": {
            "subframe": {
              "url": "https://mcp.subframe.com/mcp"
            },
            "subframe-docs": {
              "url": "https://docs.subframe.com/mcp"
            }
          }
        },
        "headless": {
          "command": "npx @subframe/cli@latest sync --all --json",
          "env": {
            "SUBFRAME_AUTH_TOKEN": "\u003ctoken\u003e"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/design.files",
        "tool": "https://letme.dev/subframe"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "seat-month",
          "usd": 20,
          "note": "each Admin and Editor, unlimited projects, six times the Free AI credits, 7-day version history. Viewers are free"
        }
      ],
      "provenance": {
        "legalEntity": "Atomic Design Inc",
        "domain": "subframe.com",
        "domainRegistered": "2003-09-24",
        "endpointOnVendorDomain": true,
        "terms": "https://policies.subframe.com/tos",
        "privacy": "https://policies.subframe.com/privacy",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The terms of service (last updated 22 January 2026) are made between Atomic Design Inc, 156 2nd Street, Ste 403, San Francisco, CA 94105, and each customer, cover the Subframe service and choose California law.",
          "The privacy policy (effective 22 January 2026) covers products and services at subframe.com. A DPA dated 21 January 2026 is at https://policies.subframe.com/dpa.",
          "The MCP server answers at mcp.subframe.com. Its protected resource metadata names an authorisation server at dbgjvucxjwkukwbojywe.supabase.co, so sign-in and tokens are issued from a Supabase host.",
          "www.subframe.com/.well-known/security.txt and /security.txt return 404.",
          "No status page or changelog is linked from the site footer, the docs or the docs index. Addresses for either were not guessed.",
          "RDAP gives subframe.com a registration date of 2003-09-24 with Cloudflare, Inc. as registrar. The repository was created on 4 March 2024."
        ],
        "score": 68
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/subframe.json",
      "live": {
        "slug": "subframe",
        "probe": {
          "target": "https://mcp.subframe.com/mcp",
          "method": "get",
          "lastAt": "2026-10-10T05:39:06.602307481Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 235,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 151,
          "p95ms24h": 259,
          "samples24h": 143,
          "samples30d": 143,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 58,
              "ok": 58
            }
          ]
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@subframe/cli",
            "version": "1.212.0",
            "seenAt": "2026-10-09T17:22:39.340892751Z"
          },
          {
            "registry": "npm",
            "name": "@subframe/core",
            "version": "1.155.0",
            "seenAt": "2026-10-09T17:22:40.263986362Z"
          }
        ],
        "githubStars": 438,
        "npmWeekly": 1006,
        "pages": [
          {
            "url": "https://policies.subframe.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:40.018475431Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c221794f9af0"
          },
          {
            "url": "https://policies.subframe.com/tos",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:42.040686665Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cf29b530a2cf"
          }
        ],
        "mcpTools": {
          "url": "https://mcp.subframe.com/mcp",
          "checkedAt": "2026-10-09T21:40:55.87387771Z",
          "status": "auth",
          "note": "asks for credentials before listing its tools",
          "changedAt": "2026-10-09T21:40:55.87387771Z"
        },
        "updatedAt": "2026-10-10T05:39:06.602307481Z"
      }
    },
    "facts": [
      {
        "a": "MCP server",
        "b": "MCP server",
        "name": "Kind"
      },
      {
        "a": "High Agency, Inc.",
        "b": "Atomic Design Inc",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://mcp.subframe.com/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "stdio",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary. The CLI package on npm carries a proprietary licence file, and the apps fall under the vendor's EULA",
        "b": "Proprietary service under Atomic Design's terms of service. `@subframe/cli` and `@subframe/core` are marked ISC in their package files and the Claude Code plugin MIT in its manifest, with no licence file in the repository",
        "name": "Licence"
      },
      {
        "a": "6",
        "b": "46",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-08",
        "b": "2026-10-08",
        "name": "Last release"
      },
      {
        "a": "2026-10-06",
        "b": "2026-01-22",
        "name": "Terms last updated"
      },
      {
        "a": "2026-10-06",
        "b": "2026-01-22",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "3.5k npm/wk",
        "b": "435 stars, 1k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "pen.dev scores 47.6 (D) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on security \u0026 auth and maintenance \u0026 community.",
        "question": "Which is better for AI agents, pen.dev or Subframe?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do pen.dev and Subframe need an API key?"
      },
      {
        "answer": "pen.dev runs on your own machine, with no hosted endpoint listed. Subframe has a hosted endpoint at https://mcp.subframe.com/mcp.",
        "question": "Can an agent call pen.dev and Subframe without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 33 against 19",
          "Schema \u0026 documentation, 61 against 54",
          "Agent ergonomics, 66 against 47",
          "Payments \u0026 pricing, 38 against 33"
        ],
        "also": [
          "Runs on your own machine",
          "No incidents deducted, where Subframe loses 3 points for them"
        ],
        "goodFor": "A coding agent that designs screens beside the code and keeps them in Git, including in CI.",
        "slug": "pen-dev",
        "watchFor": "No changelog. The three desktop releases on GitHub have empty notes, and the format docs reserve the right to make breaking changes"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 44 against 33",
          "Maintenance \u0026 community, 65 against 59"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "A coding agent working beside a team that designs React and Tailwind interfaces in Subframe and wants the design as code, with a read-only route for review.",
        "slug": "subframe",
        "watchFor": "46 tools are documented with no toolsets, and the vendor's `design` skill that explains them is about 55 KB of text"
      }
    ],
    "job": {
      "capability": "design.files",
      "name": "Design files"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/figma-mcp-vs-pen-dev.json",
        "title": "Figma API + MCP vs pen.dev",
        "url": "https://www.anchorterminal.com/compare/figma-mcp-vs-pen-dev"
      },
      {
        "json": "https://www.anchorterminal.com/compare/figma-mcp-vs-subframe.json",
        "title": "Figma API + MCP vs Subframe",
        "url": "https://www.anchorterminal.com/compare/figma-mcp-vs-subframe"
      },
      {
        "json": "https://www.anchorterminal.com/compare/framer-vs-pen-dev.json",
        "title": "Framer Server API vs pen.dev",
        "url": "https://www.anchorterminal.com/compare/framer-vs-pen-dev"
      },
      {
        "json": "https://www.anchorterminal.com/compare/framer-vs-subframe.json",
        "title": "Framer Server API vs Subframe",
        "url": "https://www.anchorterminal.com/compare/framer-vs-subframe"
      },
      {
        "json": "https://www.anchorterminal.com/compare/miro-vs-pen-dev.json",
        "title": "Miro API + MCP vs pen.dev",
        "url": "https://www.anchorterminal.com/compare/miro-vs-pen-dev"
      },
      {
        "json": "https://www.anchorterminal.com/compare/miro-vs-subframe.json",
        "title": "Miro API + MCP vs Subframe",
        "url": "https://www.anchorterminal.com/compare/miro-vs-subframe"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pen-dev-vs-penpot.json",
        "title": "pen.dev vs Penpot API + MCP",
        "url": "https://www.anchorterminal.com/compare/pen-dev-vs-penpot"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pen-dev-vs-sketch.json",
        "title": "pen.dev vs Sketch",
        "url": "https://www.anchorterminal.com/compare/pen-dev-vs-sketch"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pen-dev-vs-zeplin.json",
        "title": "pen.dev vs Zeplin",
        "url": "https://www.anchorterminal.com/compare/pen-dev-vs-zeplin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/penpot-vs-subframe.json",
        "title": "Penpot API + MCP vs Subframe",
        "url": "https://www.anchorterminal.com/compare/penpot-vs-subframe"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sketch-vs-subframe.json",
        "title": "Sketch vs Subframe",
        "url": "https://www.anchorterminal.com/compare/sketch-vs-subframe"
      },
      {
        "json": "https://www.anchorterminal.com/compare/subframe-vs-zeplin.json",
        "title": "Subframe vs Zeplin",
        "url": "https://www.anchorterminal.com/compare/subframe-vs-zeplin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/melius-vs-pen-dev.json",
        "title": "Melius vs pen.dev",
        "url": "https://www.anchorterminal.com/compare/melius-vs-pen-dev"
      },
      {
        "json": "https://www.anchorterminal.com/compare/melius-vs-subframe.json",
        "title": "Melius vs Subframe",
        "url": "https://www.anchorterminal.com/compare/melius-vs-subframe"
      }
    ],
    "scores": [
      {
        "by": 14,
        "edge": "pen-dev",
        "key": "reliability",
        "name": "Reliability",
        "pen-dev": 33,
        "subframe": 19,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 7,
        "edge": "pen-dev",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "pen-dev": 61,
        "subframe": 54,
        "weight": 13
      },
      {
        "by": 19,
        "edge": "pen-dev",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "pen-dev": 66,
        "subframe": 47,
        "weight": 13
      },
      {
        "by": 11,
        "edge": "subframe",
        "key": "security",
        "name": "Security \u0026 auth",
        "pen-dev": 33,
        "subframe": 44,
        "weight": 14
      },
      {
        "by": 5,
        "edge": "pen-dev",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "pen-dev": 38,
        "subframe": 33,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 6,
        "edge": "subframe",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "pen-dev": 59,
        "subframe": 65,
        "weight": 7
      },
      {
        "by": 4,
        "edge": "subframe",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "pen-dev": 53,
        "subframe": 57,
        "weight": 7
      }
    ],
    "summary": "pen.dev scores 47.6 (D) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on security \u0026 auth and maintenance \u0026 community. Both do design files.",
    "verdicts": {
      "pen-dev": "An agent can create, edit and export `.pen` designs without a GUI through the `pen` CLI, with four compact MCP tools that carry annotations and a documented JSON format. The software is closed and needs a pen.dev account. No changelog, status page or security contact was found, and 14 public issue reports had no reply on 8 October 2026.",
      "subframe": "An agent can read and change pages, components, snippets and themes in a Subframe project through a hosted MCP server with OAuth, and Viewer accounts get a read-only server. The server lists 46 tools, and no status page, rate limits, changelog or security contact were found. Three tools were renamed in September 2026 with no notice found."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/pen-dev-vs-subframe",
    "json": "https://www.anchorterminal.com/compare/pen-dev-vs-subframe.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/pen-dev-vs-subframe.md",
    "slim": "https://www.anchorterminal.com/compare/pen-dev-vs-subframe.min.md"
  },
  "markdown": "pen.dev scores 47.6 (D) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on security \u0026 auth and maintenance \u0026 community. Both do design files.\n\n- pen.dev: grade D, 47.6/100, rank #832 of 950. Markdown https://www.anchorterminal.com/tools/pen-dev.md · JSON https://www.anchorterminal.com/api/v1/tools/pen-dev.json\n- Subframe: grade E, 39.7/100, rank #915 of 950. Markdown https://www.anchorterminal.com/tools/subframe.md · JSON https://www.anchorterminal.com/api/v1/tools/subframe.json\n- Best design workspace and canvas APIs for AI agents: https://www.anchorterminal.com/best/design/index.md\n- All 49 design comparisons: https://www.anchorterminal.com/compare/design/index.md\n\n## Which one, for what\n\n### pen.dev (D)\n\nGood for: A coding agent that designs screens beside the code and keeps them in Git, including in CI.\n\nAhead on:\n- Reliability, 33 against 19\n- Schema \u0026 documentation, 61 against 54\n- Agent ergonomics, 66 against 47\n- Payments \u0026 pricing, 38 against 33\n\nAlso in its favour:\n- Runs on your own machine\n- No incidents deducted, where Subframe loses 3 points for them\n\nWatch for: No changelog. The three desktop releases on GitHub have empty notes, and the format docs reserve the right to make breaking changes\n\n### Subframe (E)\n\nGood for: A coding agent working beside a team that designs React and Tailwind interfaces in Subframe and wants the design as code, with a read-only route for review.\n\nAhead on:\n- Security \u0026 auth, 44 against 33\n- Maintenance \u0026 community, 65 against 59\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: 46 tools are documented with no toolsets, and the vendor's `design` skill that explains them is about 55 KB of text\n\n\n## Score by category\n\n| Category | Weight | pen.dev | Subframe | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 33 | 19 | pen.dev +14 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 61 | 54 | pen.dev +7 |\n| Agent ergonomics | 13% (16.2 this run) | 66 | 47 | pen.dev +19 |\n| Security \u0026 auth | 14% (17.5 this run) | 33 | 44 | Subframe +11 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 38 | 33 | pen.dev +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 59 | 65 | Subframe +6 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 53 | 57 | Subframe +4 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **47.6 · D** | **39.7 · E** | |\n\n## Facts side by side\n\n| Fact | pen.dev | Subframe |\n| --- | --- | --- |\n| Kind | MCP server | MCP server |\n| Vendor | High Agency, Inc. | Atomic Design Inc |\n| Hosted endpoint | no (local only) | `https://mcp.subframe.com/mcp` |\n| Transports | stdio | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary. The CLI package on npm carries a proprietary licence file, and the apps fall under the vendor's EULA | Proprietary service under Atomic Design's terms of service. `@subframe/cli` and `@subframe/core` are marked ISC in their package files and the Claude Code plugin MIT in its manifest, with no licence file in the repository |\n| Tools exposed | 6 | 46 |\n| Read-only variant documented | no | yes |\n| llms.txt | no | yes |\n| Last release | 2026-10-08 | 2026-10-08 |\n| Terms last updated | 2026-10-06 | 2026-01-22 |\n| Privacy policy last updated | 2026-10-06 | 2026-01-22 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 3.5k npm/wk | 435 stars, 1k npm/wk |\n\n## Verdicts\n\n**pen.dev.** An agent can create, edit and export `.pen` designs without a GUI through the `pen` CLI, with four compact MCP tools that carry annotations and a documented JSON format. The software is closed and needs a pen.dev account. No changelog, status page or security contact was found, and 14 public issue reports had no reply on 8 October 2026.\n\n**Subframe.** An agent can read and change pages, components, snippets and themes in a Subframe project through a hosted MCP server with OAuth, and Viewer accounts get a read-only server. The server lists 46 tools, and no status page, rate limits, changelog or security contact were found. Three tools were renamed in September 2026 with no notice found.\n\n## Before you call either\n\n### pen.dev\n\n1. Call `read_skill()`, then `read_skill({ path: \"pen-schema.md\" })` and `read_skill({ path: \"execute.md\" })` before the first `execute`. The tool description alone doesn't document the operations\n2. Call `get_app_state()` and confirm the active document before editing. The MCP server works on whichever `.pen` file is open in the app\n3. In headless `pen interactive`, call `save()` before `exit()`, and keep `--in` and `--out` on different paths to preserve the source\n4. Check that an export file exists. The docs say an export failure can print an error without a nonzero exit status\n5. In CI set `PEN_CLI_KEY` plus a provider key such as `ANTHROPIC_API_KEY`. Run `pen version`, since `pen --version` is not a flag\n\n### Subframe\n\n1. Connect with an MCP client that supports OAuth. The server rejects Subframe access tokens and static `Authorization` headers\n2. Pass `projectId` on every call. When it is omitted the server uses the first project the user can reach, which may be the wrong team's\n3. After `design_page`, `design_component` or `edit_component`, call `wait_for_jobs` with the `jobId` before reading the result. Earlier reads return stale content\n4. Ask the owner before any delete tool or a theme token deletion. A deleted token leaves every reference detached even after the token is restored\n5. For the CLI, set `SUBFRAME_AUTH_TOKEN` and `DO_NOT_TRACK=1`, and point `--dir` at a folder that holds only Subframe code, because a full sync removes other unprotected files\n\n## Questions\n\n### Which is better for AI agents, pen.dev or Subframe?\n\npen.dev scores 47.6 (D) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on security \u0026 auth and maintenance \u0026 community.\n\n### Do pen.dev and Subframe need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call pen.dev and Subframe without installing anything?\n\npen.dev runs on your own machine, with no hosted endpoint listed. Subframe has a hosted endpoint at https://mcp.subframe.com/mcp.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/pen-dev-vs-subframe.json, and with the fewest tokens: https://www.anchorterminal.com/compare/pen-dev-vs-subframe.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"pen-dev\", \"b\": \"subframe\"}`. From a terminal: `anchor compare pen-dev subframe`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/pen-dev.json and https://www.anchorterminal.com/api/v1/tools/subframe.json\n\n## Other comparisons with pen.dev or Subframe\n\n- [Figma API + MCP vs pen.dev](https://www.anchorterminal.com/compare/figma-mcp-vs-pen-dev.md)\n- [Figma API + MCP vs Subframe](https://www.anchorterminal.com/compare/figma-mcp-vs-subframe.md)\n- [Framer Server API vs pen.dev](https://www.anchorterminal.com/compare/framer-vs-pen-dev.md)\n- [Framer Server API vs Subframe](https://www.anchorterminal.com/compare/framer-vs-subframe.md)\n- [Miro API + MCP vs pen.dev](https://www.anchorterminal.com/compare/miro-vs-pen-dev.md)\n- [Miro API + MCP vs Subframe](https://www.anchorterminal.com/compare/miro-vs-subframe.md)\n- [pen.dev vs Penpot API + MCP](https://www.anchorterminal.com/compare/pen-dev-vs-penpot.md)\n- [pen.dev vs Sketch](https://www.anchorterminal.com/compare/pen-dev-vs-sketch.md)\n- [pen.dev vs Zeplin](https://www.anchorterminal.com/compare/pen-dev-vs-zeplin.md)\n- [Penpot API + MCP vs Subframe](https://www.anchorterminal.com/compare/penpot-vs-subframe.md)\n- [Sketch vs Subframe](https://www.anchorterminal.com/compare/sketch-vs-subframe.md)\n- [Subframe vs Zeplin](https://www.anchorterminal.com/compare/subframe-vs-zeplin.md)\n- [Melius vs pen.dev](https://www.anchorterminal.com/compare/melius-vs-pen-dev.md)\n- [Melius vs Subframe](https://www.anchorterminal.com/compare/melius-vs-subframe.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "pen.dev vs Subframe",
        "url": ""
      }
    ],
    "description": "pen.dev scores 47.6 (D) to Subframe's 39.7 (E) for design files. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "pen.dev D 47.6",
      "Subframe E 39.7",
      "scores"
    ],
    "h1": "pen.dev vs Subframe",
    "image": "https://www.anchorterminal.com/assets/og/compare-pen-dev-vs-subframe.png",
    "path": "/compare/pen-dev-vs-subframe",
    "published": "2026-10-01",
    "section": "tools",
    "title": "pen.dev vs Subframe for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/pen-dev-vs-subframe"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 730
  },
  "version": 1
}
