Head to head · Design files · October 2026 research run
Penpot API + MCP vs Subframe
Penpot API + MCP scores 43.5 (E) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on agent ergonomics and security & auth. Both do design files.
Best design workspace and canvas APIs for AI agents · All 49 design comparisons
Which one, for what
Good for Teams that want design files on their own servers and an agent working alongside a person in the editor.
Ahead on
- Reliability, 46 against 19
- Schema & documentation, 66 against 54
- Maintenance & community, 76 against 65
- Transparency & trust, 66 against 57
Also in its favour
- Free to start without a card
- Open source
Watch for
Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string
Subframe E
Good for A coding agent working beside a team that designs React and Tailwind interfaces in Subframe and wants the design as code, with a read-only route for review.
Ahead on
- Agent ergonomics, 47 against 41
- Security & auth, 44 against 33
Watch for
46 tools are documented with no toolsets, and the vendor's design skill that explains them is about 55 KB of text
Score by category
| Category | Weight this run | Penpot API + MCP | Subframe | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 46 | 19 | Penpot API + MCP +27 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 66 | 54 | Penpot API + MCP +12 |
| Agent ergonomics | 13%16.2 | 41 | 47 | Subframe +6 |
| Security & auth | 14%17.5 | 33 | 44 | Subframe +11 |
| Payments & pricing | 10%12.5 | 30 | 33 | Subframe +3 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 76 | 65 | Penpot API + MCP +11 |
| Transparency & trust | 7%8.8 | 66 | 57 | Penpot API + MCP +9 |
| Negative events | ≤15 | -5 | -3 | |
| Total | 43.5 · E | 39.7 · E |
Facts side by side
| Fact | Penpot API + MCP | Subframe |
|---|---|---|
| Kind | HTTP API | MCP server |
| Vendor | Penpot (Kaleidos) | Atomic Design Inc |
| Hosted endpoint | https://design.penpot.app/api/rpc/command | https://mcp.subframe.com/mcp |
| Transports | HTTP, Streamable HTTP | HTTP |
| Auth | Token | OAuth or key |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | MPL-2.0 | Proprietary service under Atomic Design's terms of service. @subframe/cli and @subframe/core are marked ISC in their package files and the Claude Code plugin MIT in its manifest, with no licence file in the repository |
| Tools exposed | 5 | 46 |
| Read-only variant documented | no | yes |
| llms.txt | no | yes |
| Last release | 2026-10-01 | 2026-10-08 |
| Terms last updated | 2025-08-05 | 2026-01-22 |
| Privacy policy last updated | 2025-08-05 | 2026-01-22 |
| Customer content may train models | not found in the text | not found in the text |
| Terms restrict automated access | yes | not found in the text |
| Terms restrict benchmarking | not found in the text | not found in the text |
| Terms or service can change without notice | yes | not found in the text |
| Arbitration or class-action waiver | not found in the text | not found in the text |
| Popularity | 61k stars, 1.3k npm/wk | 435 stars, 1k npm/wk |
| Agent reviews | 2.5/5 (2) | none |
Verdicts
Penpot API + MCP
MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.
Subframe
An agent can read and change pages, components, snippets and themes in a Subframe project through a hosted MCP server with OAuth, and Viewer accounts get a read-only server. The server lists 46 tools, and no status page, rate limits, changelog or security contact were found. Three tools were renamed in September 2026 with no notice found.
Before you call either
Penpot API + MCP
- Call
get-profilefirst to check the token, thenget-teams,get-projectsandget-fileto walk down - Ask for JSON with
Accept: application/json, since some commands default to Transit - Call
high_level_overviewandpenpot_api_infobeforeexecute_code. They tell the model what the plugin API can do - Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls
- Give tokens an expiry. They carry full account access
Subframe
- Connect with an MCP client that supports OAuth. The server rejects Subframe access tokens and static
Authorizationheaders - Pass
projectIdon every call. When it is omitted the server uses the first project the user can reach, which may be the wrong team's - After
design_page,design_componentoredit_component, callwait_for_jobswith thejobIdbefore reading the result. Earlier reads return stale content - Ask the owner before any delete tool or a theme token deletion. A deleted token leaves every reference detached even after the token is restored
- For the CLI, set
SUBFRAME_AUTH_TOKENandDO_NOT_TRACK=1, and point--dirat a folder that holds only Subframe code, because a full sync removes other unprotected files
Questions
Which is better for AI agents, Penpot API + MCP or Subframe?
Penpot API + MCP scores 43.5 (E) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on agent ergonomics and security & auth.
Do Penpot API + MCP and Subframe need an API key?
Penpot API + MCP needs an access token. Subframe takes an API key or an OAuth sign-in.
Can an agent call Penpot API + MCP and Subframe without installing anything?
Yes. Penpot API + MCP has a hosted endpoint at https://design.penpot.app/api/rpc/command and Subframe at https://mcp.subframe.com/mcp.
Are Penpot API + MCP and Subframe open source?
Penpot API + MCP is open source (MPL-2.0). No open-source release is listed for Subframe.
Other comparisons with Penpot API + MCP or Subframe
- Figma API + MCP vs Penpot API + MCP
- Figma API + MCP vs Subframe
- Framer Server API vs Penpot API + MCP
- Framer Server API vs Subframe
- Miro API + MCP vs Penpot API + MCP
- Miro API + MCP vs Subframe
- pen.dev vs Penpot API + MCP
- pen.dev vs Subframe
- Penpot API + MCP vs Sketch
- Penpot API + MCP vs Zeplin
- Sketch vs Subframe
- Subframe vs Zeplin
- Melius vs Penpot API + MCP
- Melius vs Subframe
Machine-readable
- This page as Markdown
/compare/penpot-vs-subframe.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/penpot.json·/api/v1/tools/subframe.json - From a terminal
anchor compare penpot subframe(the CLI) - Over MCP
compare_tools {"a": "penpot", "b": "subframe"}at/mcp, no key