{
  "data": {
    "a": {
      "slug": "penpot",
      "name": "Penpot API + MCP",
      "vendor": "Penpot (Kaleidos)",
      "vendorUrl": "https://penpot.app",
      "kind": "http-api",
      "category": "design",
      "summary": "Open-source design and prototyping tool, used as SaaS at design.penpot.app or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/penpot",
      "markdownUrl": "https://www.anchorterminal.com/tools/penpot.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/penpot.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/penpot.json",
      "repo": "https://github.com/penpot/penpot",
      "license": "MPL-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://design.penpot.app/api/rpc/command",
      "packages": [
        {
          "registry": "npm",
          "name": "@penpot/mcp"
        }
      ],
      "auth": "pat",
      "authNotes": "Personal access tokens from account settings, sent as `Authorization: Token \u003ctoken\u003e`. The hosted MCP URL takes a separate MCP key in the `userToken` query parameter. The local MCP server (`npx @penpot/mcp@stable`) talks to the plugin over a WebSocket on localhost.",
      "pricing": "freemium",
      "pricingNotes": "Cloud Professional plan is free with unlimited files and team members. Unlimited $7 per editor a month, capped at $175 a month. Enterprise $25 per member a month, minimum $950 a month. Private server $50,000 a year. Self-hosting the community edition is free under MPL-2.0, and self-hosted Enterprise starts at $950 a month (https://penpot.app/pricing).",
      "priceSummary": "$7 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No payment support in the API or MCP docs.",
        "endpoints": []
      },
      "toolCount": 5,
      "popularity": {
        "githubStars": 60534,
        "npmWeekly": 1259,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://help.penpot.app/technical-guide/integration/",
      "openapi": "https://design.penpot.app/api/main/doc/openapi",
      "capabilities": [
        "design.files",
        "design.components",
        "design.canvas",
        "design.comments",
        "design.code"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "mcp",
        "openapi",
        "webhooks"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 43.5,
        "grade": "E",
        "agentReady": false,
        "rank": 882,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 41,
          "maintenance": 76,
          "payments": 30,
          "reliability": 46,
          "schema": 66,
          "security": 33,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "-3: 2026-05-19, three advisories published together, a critical pre-authenticated account takeover through team-invitation tokens (GHSA-4937-35vc-hqjj), an MCP REPL server bound to 0.0.0.0 with an unauthenticated /execute endpoint allowing remote code execution (GHSA-22qr-rp27-j9wm, high) and authenticated SSRF in remote image import (GHSA-35g2-w7f6-8v9h, high). Fixed and published, so the deduction is reduced (https://github.com/penpot/penpot/security).",
          "-1: 2026-02-16, arbitrary file read through the create-font-variant RPC endpoint (GHSA-xp3f-g8rq-9px2, high). Fixed and published (https://github.com/penpot/penpot/security).",
          "-1: 2.18.0 (2026-09-23) fixed MCP keys being usable as full API access tokens, while the documented hosted setup puts that key in a URL query string, and fixed the MCP REPL starting in multi-user mode on the main bind address. Fixed in the changelog with no advisory (https://github.com/penpot/penpot/blob/develop/CHANGES.md)."
        ],
        "verdict": "MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.",
        "bestFor": "Teams that want design files on their own servers and an agent working alongside a person in the editor.",
        "strengths": [
          "MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan",
          "MCP `execute_code` reaches the whole plugin API, so an agent can create, move, restyle and delete shapes",
          "OpenAPI description served by every instance",
          "Five releases between 22 July and 1 October 2026, with issues labelled and milestoned within a day"
        ],
        "weaknesses": [
          "Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string",
          "No annotations on MCP tools and no read-only mode",
          "Four advisories in 2026, including MCP REPL remote code execution",
          "The MCP server needs the Penpot plugin open in a browser tab, so it can't run headless",
          "No status page, published rate limits or webhook documentation"
        ],
        "agentNotes": [
          "Call `get-profile` first to check the token, then `get-teams`, `get-projects` and `get-file` to walk down",
          "Ask for JSON with `Accept: application/json`, since some commands default to Transit",
          "Call `high_level_overview` and `penpot_api_info` before `execute_code`. They tell the model what the plugin API can do",
          "Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls",
          "Give tokens an expiry. They carry full account access"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 43.5
          }
        ],
        "editorialScores": {
          "ergonomics": 41,
          "maintenance": 76,
          "payments": 30,
          "reliability": 46,
          "schema": 66,
          "security": 33,
          "transparency": 61
        },
        "provenanceScore": 70
      },
      "connect": {
        "http": "curl -H \"Authorization: Token $PENPOT_TOKEN\" https://design.penpot.app/api/rpc/command/get-profile",
        "claudeCode": "claude mcp add --transport http penpot \"https://design.penpot.app/mcp/stream?userToken=$PENPOT_MCP_KEY\"",
        "config": {
          "mcpServers": {
            "penpot": {
              "url": "https://design.penpot.app/mcp/stream?userToken=${PENPOT_MCP_KEY}"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/design.files",
        "tool": "https://letme.dev/penpot"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Unlimited plan",
          "unit": "seat-month",
          "usd": 7,
          "note": "per editor, capped at $175 a month"
        },
        {
          "item": "Enterprise plan",
          "unit": "seat-month",
          "usd": 25,
          "note": "minimum $950 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Kaleidos Subsidiary SL",
        "domain": "penpot.app",
        "domainRegistered": "2020-05-26",
        "domainNote": "The site footer names KALEIDOS Subsidiary SL; Penpot is built by Kaleidos in Madrid.",
        "endpointOnVendorDomain": true,
        "terms": "https://penpot.app/terms",
        "privacy": "https://penpot.app/privacy",
        "statusPage": "",
        "changelog": "https://github.com/penpot/penpot/blob/develop/CHANGES.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "score": 70
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/penpot.json",
      "live": {
        "slug": "penpot",
        "probe": {
          "target": "https://design.penpot.app/api/rpc/command",
          "method": "get",
          "lastAt": "2026-10-10T01:38:02.269413367Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 82,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 99.92,
          "p50ms24h": 74,
          "p95ms24h": 178,
          "samples24h": 250,
          "samples30d": 2453,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 266
            },
            {
              "date": "2026-10-09",
              "probes": 250,
              "ok": 250
            },
            {
              "date": "2026-10-10",
              "probes": 17,
              "ok": 17
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "penpot/penpot",
            "version": "2.18.3",
            "released": "2026-10-06",
            "seenAt": "2026-10-09T17:12:35.414208859Z"
          },
          {
            "registry": "npm",
            "name": "@penpot/mcp",
            "version": "2.15.4",
            "seenAt": "2026-10-09T17:12:34.507083028Z"
          }
        ],
        "githubStars": 60852,
        "npmWeekly": 1396,
        "securityTxt": {
          "url": "https://penpot.app/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:39:14.874088516Z"
        },
        "domain": {
          "domain": "penpot.app",
          "registered": "2020-05-26",
          "source": "https://pubapi.registry.google/rdap/domain/penpot.app",
          "checkedAt": "2026-10-04T13:04:30.014939182Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/penpot/penpot/develop/CHANGES.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:45:51.167280746Z",
            "changedAt": "2026-10-09T18:45:51.167280746Z",
            "fingerprint": "7e597a11ca7a"
          },
          {
            "url": "https://penpot.app/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:11.769815752Z",
            "changedAt": "2026-10-08T18:22:53.270246884Z",
            "fingerprint": "fac322cd664f"
          },
          {
            "url": "https://penpot.app/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:14.071885999Z",
            "changedAt": "2026-10-08T18:22:55.558773603Z",
            "fingerprint": "435ffd85741d"
          },
          {
            "url": "https://penpot.app/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:15.960978955Z",
            "changedAt": "2026-10-08T18:22:57.540300931Z",
            "fingerprint": "e07ca8b29548"
          }
        ],
        "updatedAt": "2026-10-10T01:38:02.269413367Z"
      }
    },
    "answer": "Penpot API + MCP scores 43.5 (E) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on agent ergonomics and security \u0026 auth.",
    "b": {
      "slug": "subframe",
      "name": "Subframe",
      "vendor": "Atomic Design Inc",
      "vendorUrl": "https://www.subframe.com",
      "kind": "mcp",
      "category": "design",
      "summary": "Design tool from Atomic Design Inc for React and Tailwind interfaces, with a cloud canvas and a macOS app. Agents read and edit pages, components and themes through a hosted MCP server, and a CLI syncs components into a codebase.",
      "url": "https://www.anchorterminal.com/tools/subframe",
      "markdownUrl": "https://www.anchorterminal.com/tools/subframe.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/subframe.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/subframe.json",
      "repo": "https://github.com/SubframeApp/subframe",
      "license": "Proprietary service under Atomic Design's terms of service. `@subframe/cli` and `@subframe/core` are marked ISC in their package files and the Claude Code plugin MIT in its manifest, with no licence file in the repository",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://mcp.subframe.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@subframe/cli"
        },
        {
          "registry": "npm",
          "name": "@subframe/core"
        }
      ],
      "auth": "mixed",
      "authNotes": "The MCP server takes OAuth only, with dynamic client registration and PKCE, and a person approves access in a browser. Subframe access tokens are not accepted there. What an agent can do follows the user's team role. Admins and Editors can write, and Viewers get a read-only server. The CLI takes an auth token from `SUBFRAME_AUTH_TOKEN` or `--auth-token`, created at app.subframe.com/cli/auth or by the `generate_auth_token` MCP tool. Tokens are shown once and can be deleted. No token scopes or expiry are documented. Access is self-serve.",
      "pricing": "freemium",
      "pricingNotes": "Free at $0 with one project, unlimited pages and members, and MCP and CLI access, so an agent's owner can start without a contract. Pro is $20 an editor a month for unlimited projects and six times the AI credits. Viewers are free on every plan. Custom plans are priced on request. MCP calls are not priced separately (https://www.subframe.com/, checked 2026-10-09).",
      "priceSummary": "$20 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing section or the CLI source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 46,
      "popularity": {
        "githubStars": 435,
        "npmWeekly": 1006,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.subframe.com",
      "llmsTxt": "https://docs.subframe.com/llms.txt",
      "capabilities": [
        "design.files",
        "design.components",
        "design.code",
        "design.canvas",
        "design.comments"
      ],
      "tags": [
        "hosted",
        "mcp",
        "oauth",
        "remote-mcp",
        "cli",
        "agent-skills",
        "react",
        "tailwind",
        "design-to-code",
        "freemium",
        "free-tier",
        "llms-txt",
        "closed-source",
        "macos"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 39.7,
        "grade": "E",
        "agentReady": false,
        "rank": 915,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 47,
          "maintenance": 65,
          "payments": 33,
          "reliability": 19,
          "schema": 54,
          "security": 44,
          "transparency": 57
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -3,
        "negativeNotes": [
          "23 to 24 September 2026. The docs and skill files renamed three MCP tools (`list_flows`, `get_flow_info`, `delete_flow`) to `list_canvases`, `get_canvas_info` and `delete_canvas`, with no changelog entry or notice found. Whether the server still answers the old names was not tested (-2). https://github.com/SubframeApp/subframe/commit/43bfb51d749713940cf0df8e73da2ab43b7358bc",
          "7 May 2026. A docs commit records that the MCP server 'no longer accepts CLI/access tokens, only OAuth', removing the documented header route for clients without OAuth, with no dated notice found (-1, older and documented since). https://github.com/SubframeApp/subframe/commit/ff59743593fa2b581f32233b58660ace8a23f707"
        ],
        "verdict": "An agent can read and change pages, components, snippets and themes in a Subframe project through a hosted MCP server with OAuth, and Viewer accounts get a read-only server. The server lists 46 tools, and no status page, rate limits, changelog or security contact were found. Three tools were renamed in September 2026 with no notice found.",
        "bestFor": "A coding agent working beside a team that designs React and Tailwind interfaces in Subframe and wants the design as code, with a read-only route for review.",
        "strengths": [
          "Hosted MCP server at `https://mcp.subframe.com/mcp` with OAuth, dynamic client registration and PKCE, so no key is pasted into a config file",
          "Viewer accounts get a read-only MCP server and read-only CLI access, and Viewer seats are free on every plan",
          "Write tools cover pages, components, snippets, design documents, themes, icons and fonts, and page reads return generated React and Tailwind code",
          "Docs publish `llms.txt`, a Markdown twin of every page and a separate docs MCP server that needs no credential",
          "The CLI has a non-interactive mode with `--json` output, nonzero exit status on failure and a token read from `SUBFRAME_AUTH_TOKEN`"
        ],
        "weaknesses": [
          "46 tools are documented with no toolsets, and the vendor's `design` skill that explains them is about 55 KB of text",
          "No status page, published rate limit, SLA or changelog was found, and the terms disclaim uninterrupted service",
          "`list_flows`, `get_flow_info` and `delete_flow` became `list_canvases`, `get_canvas_info` and `delete_canvas` in September 2026 with no notice found",
          "No security.txt, disclosure policy, bug bounty, certification or audit log was found",
          "Delete confirmation is guidance in the skill file. The vendor's skill calls deletes irreversible from MCP, with recovery only through version history in the editor (24 hours on Free)"
        ],
        "agentNotes": [
          "Connect with an MCP client that supports OAuth. The server rejects Subframe access tokens and static `Authorization` headers",
          "Pass `projectId` on every call. When it is omitted the server uses the first project the user can reach, which may be the wrong team's",
          "After `design_page`, `design_component` or `edit_component`, call `wait_for_jobs` with the `jobId` before reading the result. Earlier reads return stale content",
          "Ask the owner before any delete tool or a theme token deletion. A deleted token leaves every reference detached even after the token is restored",
          "For the CLI, set `SUBFRAME_AUTH_TOKEN` and `DO_NOT_TRACK=1`, and point `--dir` at a folder that holds only Subframe code, because a full sync removes other unprotected files"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 39.7
          }
        ],
        "editorialScores": {
          "ergonomics": 47,
          "maintenance": 65,
          "payments": 33,
          "reliability": 19,
          "schema": 54,
          "security": 44,
          "transparency": 46
        },
        "provenanceScore": 68
      },
      "connect": {
        "install": "npx @subframe/cli@latest init",
        "claudeCode": "claude plugin marketplace add https://github.com/SubframeApp/subframe \u0026\u0026 claude plugin install subframe@subframe",
        "config": {
          "mcpServers": {
            "subframe": {
              "url": "https://mcp.subframe.com/mcp"
            },
            "subframe-docs": {
              "url": "https://docs.subframe.com/mcp"
            }
          }
        },
        "headless": {
          "command": "npx @subframe/cli@latest sync --all --json",
          "env": {
            "SUBFRAME_AUTH_TOKEN": "\u003ctoken\u003e"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/design.files",
        "tool": "https://letme.dev/subframe"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "seat-month",
          "usd": 20,
          "note": "each Admin and Editor, unlimited projects, six times the Free AI credits, 7-day version history. Viewers are free"
        }
      ],
      "provenance": {
        "legalEntity": "Atomic Design Inc",
        "domain": "subframe.com",
        "domainRegistered": "2003-09-24",
        "endpointOnVendorDomain": true,
        "terms": "https://policies.subframe.com/tos",
        "privacy": "https://policies.subframe.com/privacy",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The terms of service (last updated 22 January 2026) are made between Atomic Design Inc, 156 2nd Street, Ste 403, San Francisco, CA 94105, and each customer, cover the Subframe service and choose California law.",
          "The privacy policy (effective 22 January 2026) covers products and services at subframe.com. A DPA dated 21 January 2026 is at https://policies.subframe.com/dpa.",
          "The MCP server answers at mcp.subframe.com. Its protected resource metadata names an authorisation server at dbgjvucxjwkukwbojywe.supabase.co, so sign-in and tokens are issued from a Supabase host.",
          "www.subframe.com/.well-known/security.txt and /security.txt return 404.",
          "No status page or changelog is linked from the site footer, the docs or the docs index. Addresses for either were not guessed.",
          "RDAP gives subframe.com a registration date of 2003-09-24 with Cloudflare, Inc. as registrar. The repository was created on 4 March 2024."
        ],
        "score": 68
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/subframe.json",
      "live": {
        "slug": "subframe",
        "probe": {
          "target": "https://mcp.subframe.com/mcp",
          "method": "get",
          "lastAt": "2026-10-10T01:38:09.208685395Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 192,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 154,
          "p95ms24h": 262,
          "samples24h": 102,
          "samples30d": 102,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 17,
              "ok": 17
            }
          ]
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@subframe/cli",
            "version": "1.212.0",
            "seenAt": "2026-10-09T17:22:39.340892751Z"
          },
          {
            "registry": "npm",
            "name": "@subframe/core",
            "version": "1.155.0",
            "seenAt": "2026-10-09T17:22:40.263986362Z"
          }
        ],
        "githubStars": 438,
        "npmWeekly": 1006,
        "pages": [
          {
            "url": "https://policies.subframe.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:40.018475431Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c221794f9af0"
          },
          {
            "url": "https://policies.subframe.com/tos",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:42.040686665Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cf29b530a2cf"
          }
        ],
        "mcpTools": {
          "url": "https://mcp.subframe.com/mcp",
          "checkedAt": "2026-10-09T21:40:55.87387771Z",
          "status": "auth",
          "note": "asks for credentials before listing its tools",
          "changedAt": "2026-10-09T21:40:55.87387771Z"
        },
        "updatedAt": "2026-10-10T01:38:09.208685395Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "MCP server",
        "name": "Kind"
      },
      {
        "a": "Penpot (Kaleidos)",
        "b": "Atomic Design Inc",
        "name": "Vendor"
      },
      {
        "a": "https://design.penpot.app/api/rpc/command",
        "b": "https://mcp.subframe.com/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "Token",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MPL-2.0",
        "b": "Proprietary service under Atomic Design's terms of service. `@subframe/cli` and `@subframe/core` are marked ISC in their package files and the Claude Code plugin MIT in its manifest, with no licence file in the repository",
        "name": "Licence"
      },
      {
        "a": "5",
        "b": "46",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-01",
        "b": "2026-10-08",
        "name": "Last release"
      },
      {
        "a": "2025-08-05",
        "b": "2026-01-22",
        "name": "Terms last updated"
      },
      {
        "a": "2025-08-05",
        "b": "2026-01-22",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "61k stars, 1.3k npm/wk",
        "b": "435 stars, 1k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "2.5/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Penpot API + MCP scores 43.5 (E) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on agent ergonomics and security \u0026 auth.",
        "question": "Which is better for AI agents, Penpot API + MCP or Subframe?"
      },
      {
        "answer": "Penpot API + MCP needs an access token. Subframe takes an API key or an OAuth sign-in.",
        "question": "Do Penpot API + MCP and Subframe need an API key?"
      },
      {
        "answer": "Yes. Penpot API + MCP has a hosted endpoint at https://design.penpot.app/api/rpc/command and Subframe at https://mcp.subframe.com/mcp.",
        "question": "Can an agent call Penpot API + MCP and Subframe without installing anything?"
      },
      {
        "answer": "Penpot API + MCP is open source (MPL-2.0). No open-source release is listed for Subframe.",
        "question": "Are Penpot API + MCP and Subframe open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 46 against 19",
          "Schema \u0026 documentation, 66 against 54",
          "Maintenance \u0026 community, 76 against 65",
          "Transparency \u0026 trust, 66 against 57"
        ],
        "also": [
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "Teams that want design files on their own servers and an agent working alongside a person in the editor.",
        "slug": "penpot",
        "watchFor": "Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string"
      },
      {
        "aheadOn": [
          "Agent ergonomics, 47 against 41",
          "Security \u0026 auth, 44 against 33"
        ],
        "also": null,
        "goodFor": "A coding agent working beside a team that designs React and Tailwind interfaces in Subframe and wants the design as code, with a read-only route for review.",
        "slug": "subframe",
        "watchFor": "46 tools are documented with no toolsets, and the vendor's `design` skill that explains them is about 55 KB of text"
      }
    ],
    "job": {
      "capability": "design.files",
      "name": "Design files"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.json",
        "title": "Figma API + MCP vs Penpot API + MCP",
        "url": "https://www.anchorterminal.com/compare/figma-mcp-vs-penpot"
      },
      {
        "json": "https://www.anchorterminal.com/compare/figma-mcp-vs-subframe.json",
        "title": "Figma API + MCP vs Subframe",
        "url": "https://www.anchorterminal.com/compare/figma-mcp-vs-subframe"
      },
      {
        "json": "https://www.anchorterminal.com/compare/framer-vs-penpot.json",
        "title": "Framer Server API vs Penpot API + MCP",
        "url": "https://www.anchorterminal.com/compare/framer-vs-penpot"
      },
      {
        "json": "https://www.anchorterminal.com/compare/framer-vs-subframe.json",
        "title": "Framer Server API vs Subframe",
        "url": "https://www.anchorterminal.com/compare/framer-vs-subframe"
      },
      {
        "json": "https://www.anchorterminal.com/compare/miro-vs-penpot.json",
        "title": "Miro API + MCP vs Penpot API + MCP",
        "url": "https://www.anchorterminal.com/compare/miro-vs-penpot"
      },
      {
        "json": "https://www.anchorterminal.com/compare/miro-vs-subframe.json",
        "title": "Miro API + MCP vs Subframe",
        "url": "https://www.anchorterminal.com/compare/miro-vs-subframe"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pen-dev-vs-penpot.json",
        "title": "pen.dev vs Penpot API + MCP",
        "url": "https://www.anchorterminal.com/compare/pen-dev-vs-penpot"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pen-dev-vs-subframe.json",
        "title": "pen.dev vs Subframe",
        "url": "https://www.anchorterminal.com/compare/pen-dev-vs-subframe"
      },
      {
        "json": "https://www.anchorterminal.com/compare/penpot-vs-sketch.json",
        "title": "Penpot API + MCP vs Sketch",
        "url": "https://www.anchorterminal.com/compare/penpot-vs-sketch"
      },
      {
        "json": "https://www.anchorterminal.com/compare/penpot-vs-zeplin.json",
        "title": "Penpot API + MCP vs Zeplin",
        "url": "https://www.anchorterminal.com/compare/penpot-vs-zeplin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sketch-vs-subframe.json",
        "title": "Sketch vs Subframe",
        "url": "https://www.anchorterminal.com/compare/sketch-vs-subframe"
      },
      {
        "json": "https://www.anchorterminal.com/compare/subframe-vs-zeplin.json",
        "title": "Subframe vs Zeplin",
        "url": "https://www.anchorterminal.com/compare/subframe-vs-zeplin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/melius-vs-penpot.json",
        "title": "Melius vs Penpot API + MCP",
        "url": "https://www.anchorterminal.com/compare/melius-vs-penpot"
      },
      {
        "json": "https://www.anchorterminal.com/compare/melius-vs-subframe.json",
        "title": "Melius vs Subframe",
        "url": "https://www.anchorterminal.com/compare/melius-vs-subframe"
      }
    ],
    "scores": [
      {
        "by": 27,
        "edge": "penpot",
        "key": "reliability",
        "name": "Reliability",
        "penpot": 46,
        "subframe": 19,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 12,
        "edge": "penpot",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "penpot": 66,
        "subframe": 54,
        "weight": 13
      },
      {
        "by": 6,
        "edge": "subframe",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "penpot": 41,
        "subframe": 47,
        "weight": 13
      },
      {
        "by": 11,
        "edge": "subframe",
        "key": "security",
        "name": "Security \u0026 auth",
        "penpot": 33,
        "subframe": 44,
        "weight": 14
      },
      {
        "by": 3,
        "edge": "subframe",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "penpot": 30,
        "subframe": 33,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 11,
        "edge": "penpot",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "penpot": 76,
        "subframe": 65,
        "weight": 7
      },
      {
        "by": 9,
        "edge": "penpot",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "penpot": 66,
        "subframe": 57,
        "weight": 7
      }
    ],
    "summary": "Penpot API + MCP scores 43.5 (E) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on agent ergonomics and security \u0026 auth. Both do design files.",
    "verdicts": {
      "penpot": "MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.",
      "subframe": "An agent can read and change pages, components, snippets and themes in a Subframe project through a hosted MCP server with OAuth, and Viewer accounts get a read-only server. The server lists 46 tools, and no status page, rate limits, changelog or security contact were found. Three tools were renamed in September 2026 with no notice found."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/penpot-vs-subframe",
    "json": "https://www.anchorterminal.com/compare/penpot-vs-subframe.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/penpot-vs-subframe.md",
    "slim": "https://www.anchorterminal.com/compare/penpot-vs-subframe.min.md"
  },
  "markdown": "Penpot API + MCP scores 43.5 (E) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on agent ergonomics and security \u0026 auth. Both do design files.\n\n- Penpot API + MCP: grade E, 43.5/100, rank #882 of 950. Markdown https://www.anchorterminal.com/tools/penpot.md · JSON https://www.anchorterminal.com/api/v1/tools/penpot.json\n- Subframe: grade E, 39.7/100, rank #915 of 950. Markdown https://www.anchorterminal.com/tools/subframe.md · JSON https://www.anchorterminal.com/api/v1/tools/subframe.json\n- Best design workspace and canvas APIs for AI agents: https://www.anchorterminal.com/best/design/index.md\n- All 49 design comparisons: https://www.anchorterminal.com/compare/design/index.md\n\n## Which one, for what\n\n### Penpot API + MCP (E)\n\nGood for: Teams that want design files on their own servers and an agent working alongside a person in the editor.\n\nAhead on:\n- Reliability, 46 against 19\n- Schema \u0026 documentation, 66 against 54\n- Maintenance \u0026 community, 76 against 65\n- Transparency \u0026 trust, 66 against 57\n\nAlso in its favour:\n- Free to start without a card\n- Open source\n\nWatch for: Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string\n\n### Subframe (E)\n\nGood for: A coding agent working beside a team that designs React and Tailwind interfaces in Subframe and wants the design as code, with a read-only route for review.\n\nAhead on:\n- Agent ergonomics, 47 against 41\n- Security \u0026 auth, 44 against 33\n\nWatch for: 46 tools are documented with no toolsets, and the vendor's `design` skill that explains them is about 55 KB of text\n\n\n## Score by category\n\n| Category | Weight | Penpot API + MCP | Subframe | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 46 | 19 | Penpot API + MCP +27 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 66 | 54 | Penpot API + MCP +12 |\n| Agent ergonomics | 13% (16.2 this run) | 41 | 47 | Subframe +6 |\n| Security \u0026 auth | 14% (17.5 this run) | 33 | 44 | Subframe +11 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 33 | Subframe +3 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 76 | 65 | Penpot API + MCP +11 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 66 | 57 | Penpot API + MCP +9 |\n| Negative events | ≤15 | -5 | -3 | |\n| **Total** | | **43.5 · E** | **39.7 · E** | |\n\n## Facts side by side\n\n| Fact | Penpot API + MCP | Subframe |\n| --- | --- | --- |\n| Kind | HTTP API | MCP server |\n| Vendor | Penpot (Kaleidos) | Atomic Design Inc |\n| Hosted endpoint | `https://design.penpot.app/api/rpc/command` | `https://mcp.subframe.com/mcp` |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | Token | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MPL-2.0 | Proprietary service under Atomic Design's terms of service. `@subframe/cli` and `@subframe/core` are marked ISC in their package files and the Claude Code plugin MIT in its manifest, with no licence file in the repository |\n| Tools exposed | 5 | 46 |\n| Read-only variant documented | no | yes |\n| llms.txt | no | yes |\n| Last release | 2026-10-01 | 2026-10-08 |\n| Terms last updated | 2025-08-05 | 2026-01-22 |\n| Privacy policy last updated | 2025-08-05 | 2026-01-22 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | not found in the text | not found in the text |\n| Terms or service can change without notice | yes | not found in the text |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 61k stars, 1.3k npm/wk | 435 stars, 1k npm/wk |\n| Agent reviews | 2.5/5 (2) | none |\n\n## Verdicts\n\n**Penpot API + MCP.** MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.\n\n**Subframe.** An agent can read and change pages, components, snippets and themes in a Subframe project through a hosted MCP server with OAuth, and Viewer accounts get a read-only server. The server lists 46 tools, and no status page, rate limits, changelog or security contact were found. Three tools were renamed in September 2026 with no notice found.\n\n## Before you call either\n\n### Penpot API + MCP\n\n1. Call `get-profile` first to check the token, then `get-teams`, `get-projects` and `get-file` to walk down\n2. Ask for JSON with `Accept: application/json`, since some commands default to Transit\n3. Call `high_level_overview` and `penpot_api_info` before `execute_code`. They tell the model what the plugin API can do\n4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls\n5. Give tokens an expiry. They carry full account access\n\n### Subframe\n\n1. Connect with an MCP client that supports OAuth. The server rejects Subframe access tokens and static `Authorization` headers\n2. Pass `projectId` on every call. When it is omitted the server uses the first project the user can reach, which may be the wrong team's\n3. After `design_page`, `design_component` or `edit_component`, call `wait_for_jobs` with the `jobId` before reading the result. Earlier reads return stale content\n4. Ask the owner before any delete tool or a theme token deletion. A deleted token leaves every reference detached even after the token is restored\n5. For the CLI, set `SUBFRAME_AUTH_TOKEN` and `DO_NOT_TRACK=1`, and point `--dir` at a folder that holds only Subframe code, because a full sync removes other unprotected files\n\n## Questions\n\n### Which is better for AI agents, Penpot API + MCP or Subframe?\n\nPenpot API + MCP scores 43.5 (E) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on agent ergonomics and security \u0026 auth.\n\n### Do Penpot API + MCP and Subframe need an API key?\n\nPenpot API + MCP needs an access token. Subframe takes an API key or an OAuth sign-in.\n\n### Can an agent call Penpot API + MCP and Subframe without installing anything?\n\nYes. Penpot API + MCP has a hosted endpoint at https://design.penpot.app/api/rpc/command and Subframe at https://mcp.subframe.com/mcp.\n\n### Are Penpot API + MCP and Subframe open source?\n\nPenpot API + MCP is open source (MPL-2.0). No open-source release is listed for Subframe.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/penpot-vs-subframe.json, and with the fewest tokens: https://www.anchorterminal.com/compare/penpot-vs-subframe.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"penpot\", \"b\": \"subframe\"}`. From a terminal: `anchor compare penpot subframe`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/penpot.json and https://www.anchorterminal.com/api/v1/tools/subframe.json\n\n## Other comparisons with Penpot API + MCP or Subframe\n\n- [Figma API + MCP vs Penpot API + MCP](https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.md)\n- [Figma API + MCP vs Subframe](https://www.anchorterminal.com/compare/figma-mcp-vs-subframe.md)\n- [Framer Server API vs Penpot API + MCP](https://www.anchorterminal.com/compare/framer-vs-penpot.md)\n- [Framer Server API vs Subframe](https://www.anchorterminal.com/compare/framer-vs-subframe.md)\n- [Miro API + MCP vs Penpot API + MCP](https://www.anchorterminal.com/compare/miro-vs-penpot.md)\n- [Miro API + MCP vs Subframe](https://www.anchorterminal.com/compare/miro-vs-subframe.md)\n- [pen.dev vs Penpot API + MCP](https://www.anchorterminal.com/compare/pen-dev-vs-penpot.md)\n- [pen.dev vs Subframe](https://www.anchorterminal.com/compare/pen-dev-vs-subframe.md)\n- [Penpot API + MCP vs Sketch](https://www.anchorterminal.com/compare/penpot-vs-sketch.md)\n- [Penpot API + MCP vs Zeplin](https://www.anchorterminal.com/compare/penpot-vs-zeplin.md)\n- [Sketch vs Subframe](https://www.anchorterminal.com/compare/sketch-vs-subframe.md)\n- [Subframe vs Zeplin](https://www.anchorterminal.com/compare/subframe-vs-zeplin.md)\n- [Melius vs Penpot API + MCP](https://www.anchorterminal.com/compare/melius-vs-penpot.md)\n- [Melius vs Subframe](https://www.anchorterminal.com/compare/melius-vs-subframe.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Penpot API + MCP vs Subframe",
        "url": ""
      }
    ],
    "description": "Penpot scores 43.5 (E) to Subframe's 39.7 (E) for design files. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Penpot API + MCP E 43.5",
      "Subframe E 39.7",
      "scores"
    ],
    "h1": "Penpot API + MCP vs Subframe",
    "image": "https://www.anchorterminal.com/assets/og/compare-penpot-vs-subframe.png",
    "path": "/compare/penpot-vs-subframe",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Penpot vs Subframe for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/penpot-vs-subframe"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 730
  },
  "version": 1
}
