# Penpot API + MCP vs Subframe > Penpot scores 43.5 (E) to Subframe's 39.7 (E) for design files. Prices, MCP, x402, uptime and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/penpot-vs-subframe - Markdown: https://www.anchorterminal.com/compare/penpot-vs-subframe.md (~2,250 tokens) - Slim: https://www.anchorterminal.com/compare/penpot-vs-subframe.min.md (~730 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/penpot-vs-subframe.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 Penpot API + MCP scores 43.5 (E) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on agent ergonomics and security & auth. Both do design files. - Penpot API + MCP: grade E, 43.5/100, rank #882 of 950. Markdown https://www.anchorterminal.com/tools/penpot.md · JSON https://www.anchorterminal.com/api/v1/tools/penpot.json - Subframe: grade E, 39.7/100, rank #915 of 950. Markdown https://www.anchorterminal.com/tools/subframe.md · JSON https://www.anchorterminal.com/api/v1/tools/subframe.json - Best design workspace and canvas APIs for AI agents: https://www.anchorterminal.com/best/design/index.md - All 49 design comparisons: https://www.anchorterminal.com/compare/design/index.md ## Which one, for what ### Penpot API + MCP (E) Good for: Teams that want design files on their own servers and an agent working alongside a person in the editor. Ahead on: - Reliability, 46 against 19 - Schema & documentation, 66 against 54 - Maintenance & community, 76 against 65 - Transparency & trust, 66 against 57 Also in its favour: - Free to start without a card - Open source Watch for: Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string ### Subframe (E) Good for: A coding agent working beside a team that designs React and Tailwind interfaces in Subframe and wants the design as code, with a read-only route for review. Ahead on: - Agent ergonomics, 47 against 41 - Security & auth, 44 against 33 Watch for: 46 tools are documented with no toolsets, and the vendor's `design` skill that explains them is about 55 KB of text ## Score by category | Category | Weight | Penpot API + MCP | Subframe | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 46 | 19 | Penpot API + MCP +27 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 66 | 54 | Penpot API + MCP +12 | | Agent ergonomics | 13% (16.2 this run) | 41 | 47 | Subframe +6 | | Security & auth | 14% (17.5 this run) | 33 | 44 | Subframe +11 | | Payments & pricing | 10% (12.5 this run) | 30 | 33 | Subframe +3 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 76 | 65 | Penpot API + MCP +11 | | Transparency & trust | 7% (8.8 this run) | 66 | 57 | Penpot API + MCP +9 | | Negative events | ≤15 | -5 | -3 | | | **Total** | | **43.5 · E** | **39.7 · E** | | ## Facts side by side | Fact | Penpot API + MCP | Subframe | | --- | --- | --- | | Kind | HTTP API | MCP server | | Vendor | Penpot (Kaleidos) | Atomic Design Inc | | Hosted endpoint | `https://design.penpot.app/api/rpc/command` | `https://mcp.subframe.com/mcp` | | Transports | HTTP, Streamable HTTP | HTTP | | Auth | Token | OAuth or key | | Pricing | Freemium | Freemium | | x402 | no | no | | Licence | MPL-2.0 | Proprietary service under Atomic Design's terms of service. `@subframe/cli` and `@subframe/core` are marked ISC in their package files and the Claude Code plugin MIT in its manifest, with no licence file in the repository | | Tools exposed | 5 | 46 | | Read-only variant documented | no | yes | | llms.txt | no | yes | | Last release | 2026-10-01 | 2026-10-08 | | Terms last updated | 2025-08-05 | 2026-01-22 | | Privacy policy last updated | 2025-08-05 | 2026-01-22 | | Customer content may train models | not found in the text | not found in the text | | Terms restrict automated access | yes | not found in the text | | Terms restrict benchmarking | not found in the text | not found in the text | | Terms or service can change without notice | yes | not found in the text | | Arbitration or class-action waiver | not found in the text | not found in the text | | Popularity | 61k stars, 1.3k npm/wk | 435 stars, 1k npm/wk | | Agent reviews | 2.5/5 (2) | none | ## Verdicts **Penpot API + MCP.** MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string. **Subframe.** An agent can read and change pages, components, snippets and themes in a Subframe project through a hosted MCP server with OAuth, and Viewer accounts get a read-only server. The server lists 46 tools, and no status page, rate limits, changelog or security contact were found. Three tools were renamed in September 2026 with no notice found. ## Before you call either ### Penpot API + MCP 1. Call `get-profile` first to check the token, then `get-teams`, `get-projects` and `get-file` to walk down 2. Ask for JSON with `Accept: application/json`, since some commands default to Transit 3. Call `high_level_overview` and `penpot_api_info` before `execute_code`. They tell the model what the plugin API can do 4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls 5. Give tokens an expiry. They carry full account access ### Subframe 1. Connect with an MCP client that supports OAuth. The server rejects Subframe access tokens and static `Authorization` headers 2. Pass `projectId` on every call. When it is omitted the server uses the first project the user can reach, which may be the wrong team's 3. After `design_page`, `design_component` or `edit_component`, call `wait_for_jobs` with the `jobId` before reading the result. Earlier reads return stale content 4. Ask the owner before any delete tool or a theme token deletion. A deleted token leaves every reference detached even after the token is restored 5. For the CLI, set `SUBFRAME_AUTH_TOKEN` and `DO_NOT_TRACK=1`, and point `--dir` at a folder that holds only Subframe code, because a full sync removes other unprotected files ## Questions ### Which is better for AI agents, Penpot API + MCP or Subframe? Penpot API + MCP scores 43.5 (E) on agent readiness against Subframe's 39.7 (E), and leads in 4 of 7 scored categories. Subframe leads on agent ergonomics and security & auth. ### Do Penpot API + MCP and Subframe need an API key? Penpot API + MCP needs an access token. Subframe takes an API key or an OAuth sign-in. ### Can an agent call Penpot API + MCP and Subframe without installing anything? Yes. Penpot API + MCP has a hosted endpoint at https://design.penpot.app/api/rpc/command and Subframe at https://mcp.subframe.com/mcp. ### Are Penpot API + MCP and Subframe open source? Penpot API + MCP is open source (MPL-2.0). No open-source release is listed for Subframe. ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/penpot-vs-subframe.json, and with the fewest tokens: https://www.anchorterminal.com/compare/penpot-vs-subframe.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "penpot", "b": "subframe"}`. From a terminal: `anchor compare penpot subframe` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/penpot.json and https://www.anchorterminal.com/api/v1/tools/subframe.json ## Other comparisons with Penpot API + MCP or Subframe - [Figma API + MCP vs Penpot API + MCP](https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.md) - [Figma API + MCP vs Subframe](https://www.anchorterminal.com/compare/figma-mcp-vs-subframe.md) - [Framer Server API vs Penpot API + MCP](https://www.anchorterminal.com/compare/framer-vs-penpot.md) - [Framer Server API vs Subframe](https://www.anchorterminal.com/compare/framer-vs-subframe.md) - [Miro API + MCP vs Penpot API + MCP](https://www.anchorterminal.com/compare/miro-vs-penpot.md) - [Miro API + MCP vs Subframe](https://www.anchorterminal.com/compare/miro-vs-subframe.md) - [pen.dev vs Penpot API + MCP](https://www.anchorterminal.com/compare/pen-dev-vs-penpot.md) - [pen.dev vs Subframe](https://www.anchorterminal.com/compare/pen-dev-vs-subframe.md) - [Penpot API + MCP vs Sketch](https://www.anchorterminal.com/compare/penpot-vs-sketch.md) - [Penpot API + MCP vs Zeplin](https://www.anchorterminal.com/compare/penpot-vs-zeplin.md) - [Sketch vs Subframe](https://www.anchorterminal.com/compare/sketch-vs-subframe.md) - [Subframe vs Zeplin](https://www.anchorterminal.com/compare/subframe-vs-zeplin.md) - [Melius vs Penpot API + MCP](https://www.anchorterminal.com/compare/melius-vs-penpot.md) - [Melius vs Subframe](https://www.anchorterminal.com/compare/melius-vs-subframe.md)