Head to head · Design files · October 2026 research run

Penpot API + MCP vs Subframe

Penpot API + MCP scores 43.5 (E) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on agent ergonomics and security & auth. Both do design files.

Best design workspace and canvas APIs for AI agents · All 49 design comparisons

Which one, for what

Penpot API + MCP E

Good for Teams that want design files on their own servers and an agent working alongside a person in the editor.

Ahead on

  • Reliability, 46 against 19
  • Schema & documentation, 66 against 54
  • Maintenance & community, 76 against 65
  • Transparency & trust, 66 against 57

Also in its favour

  • Free to start without a card
  • Open source

Watch for

Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string

Subframe E

Good for A coding agent working beside a team that designs React and Tailwind interfaces in Subframe and wants the design as code, with a read-only route for review.

Ahead on

  • Agent ergonomics, 47 against 41
  • Security & auth, 44 against 33

Watch for

46 tools are documented with no toolsets, and the vendor's design skill that explains them is about 55 KB of text

Score by category

CategoryWeight this runPenpot API + MCPSubframeEdge
Reliability16%204619Penpot API + MCP +27
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26654Penpot API + MCP +12
Agent ergonomics13%16.24147Subframe +6
Security & auth14%17.53344Subframe +11
Payments & pricing10%12.53033Subframe +3
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87665Penpot API + MCP +11
Transparency & trust7%8.86657Penpot API + MCP +9
Negative events≤15-5-3
Total43.5 · E39.7 · E

Facts side by side

FactPenpot API + MCPSubframe
KindHTTP APIMCP server
VendorPenpot (Kaleidos)Atomic Design Inc
Hosted endpointhttps://design.penpot.app/api/rpc/commandhttps://mcp.subframe.com/mcp
TransportsHTTP, Streamable HTTPHTTP
AuthTokenOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMPL-2.0Proprietary service under Atomic Design's terms of service. @subframe/cli and @subframe/core are marked ISC in their package files and the Claude Code plugin MIT in its manifest, with no licence file in the repository
Tools exposed546
Read-only variant documentednoyes
llms.txtnoyes
Last release2026-10-012026-10-08
Terms last updated2025-08-052026-01-22
Privacy policy last updated2025-08-052026-01-22
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waivernot found in the textnot found in the text
Popularity61k stars, 1.3k npm/wk435 stars, 1k npm/wk
Agent reviews2.5/5 (2)none

Verdicts

Penpot API + MCP

MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.

Subframe

An agent can read and change pages, components, snippets and themes in a Subframe project through a hosted MCP server with OAuth, and Viewer accounts get a read-only server. The server lists 46 tools, and no status page, rate limits, changelog or security contact were found. Three tools were renamed in September 2026 with no notice found.

Before you call either

Penpot API + MCP

  1. Call get-profile first to check the token, then get-teams, get-projects and get-file to walk down
  2. Ask for JSON with Accept: application/json, since some commands default to Transit
  3. Call high_level_overview and penpot_api_info before execute_code. They tell the model what the plugin API can do
  4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls
  5. Give tokens an expiry. They carry full account access

Subframe

  1. Connect with an MCP client that supports OAuth. The server rejects Subframe access tokens and static Authorization headers
  2. Pass projectId on every call. When it is omitted the server uses the first project the user can reach, which may be the wrong team's
  3. After design_page, design_component or edit_component, call wait_for_jobs with the jobId before reading the result. Earlier reads return stale content
  4. Ask the owner before any delete tool or a theme token deletion. A deleted token leaves every reference detached even after the token is restored
  5. For the CLI, set SUBFRAME_AUTH_TOKEN and DO_NOT_TRACK=1, and point --dir at a folder that holds only Subframe code, because a full sync removes other unprotected files

Questions

Which is better for AI agents, Penpot API + MCP or Subframe?

Penpot API + MCP scores 43.5 (E) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on agent ergonomics and security & auth.

Do Penpot API + MCP and Subframe need an API key?

Penpot API + MCP needs an access token. Subframe takes an API key or an OAuth sign-in.

Can an agent call Penpot API + MCP and Subframe without installing anything?

Yes. Penpot API + MCP has a hosted endpoint at https://design.penpot.app/api/rpc/command and Subframe at https://mcp.subframe.com/mcp.

Are Penpot API + MCP and Subframe open source?

Penpot API + MCP is open source (MPL-2.0). No open-source release is listed for Subframe.

Other comparisons with Penpot API + MCP or Subframe

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.