# pen.dev (slim) > Design canvas from High Agency, Inc. that stores designs as JSON .pen files. Agents edit them through a local MCP server in the desktop app or IDE extension, or through a headless CLI. It was called Pencil until 2026. - Full: https://www.anchorterminal.com/tools/pen-dev.md (~7,250 tokens) · this version ~1,780 tokens · JSON https://www.anchorterminal.com/tools/pen-dev.json · canonical https://www.anchorterminal.com/tools/pen-dev - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **D · 47.6/100 · rank #740 of 842 · #5 in Design workspaces & canvases · not agent-ready · confidence medium** Assessment: An agent can create, edit and export `.pen` designs without a GUI through the `pen` CLI, with four compact MCP tools that carry annotations and a documented JSON format. The software is closed and needs a pen.dev account. No changelog, status page or security contact was found, and 14 public issue reports had no reply on 8 October 2026. ## Facts - Kind: MCP server · vendor: High Agency, Inc. · category: Design workspaces & canvases · legal entity: High Agency, Inc. · provenance 51/100 - Local only (stdio): npm `@pen.dev/cli` - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary. The CLI package on npm carries a proprietary licence file, and the apps fall under the vendor's EULA - Probe metrics: not measured yet (probes haven't run) - Surfaces: Local stdio MCP server bundled with the desktop app (macOS, Windows x64, Linux) and the VS Code and Cursor extension, and the `pen` CLI from npm (`@pen.dev/cli`, Node.js 22.19 or later). A web app at app.pen.dev holds workspaces, shares and developer keys - MCP tools: `get_style`, `read_skill`, `get_app_state`, `execute` as standard. `browser` when the server targets the desktop app. `spawn_agents` only with `-enable_spawn_agents` - Read vs write: `execute` runs a JavaScript snippet with operations such as Insert, Update, Delete, Move, Copy, Replace, Get, SetVariables, Generate, TakeScreenshot and Export. `get_app_state`, `get_style` and `read_skill` read - Credentials: `pen login` (email with password or one-time code) stores a session token in `~/.pencil/session-cli.json`. `PEN_CLI_KEY` is an organisation-scoped CLI key made in Developer Keys on the web app. The MCP server itself takes no credential and talks to a signed-in app on the same machine - Model access: The user's own provider key or subscription (Anthropic, OpenAI, Google, Cursor, GitHub Copilot and others) straight from the device, or pen.dev Pro models routed through the vendor to Fireworks AI - File format: `.pen`, JSON with a `version` field and a TypeScript schema on the docs site. Older versions are converted on open - Exports: PNG, JPEG, WEBP, PDF and HTML through `Export()`, and `--export` on the CLI - Free tier: 5 agent days and 25 image or SVG generations a month, one agent at a time, with CLI, MCP access and personal developer keys - Rate limits: None published. Plans cap agent days, image generations and parallel agents - Releases: `@pen.dev/cli` 0.3.11 on 8 October 2026, 13 versions since 9 July. Desktop v1.2.16 on 8 October. Extension 0.6.75 on 8 October. No release notes - Telemetry: PostHog product analytics and Sentry error reports, said to exclude prompts, outputs and source code. No opt-out for the desktop app or CLI was found - Sub-processors: 16 named on pen.dev/sub-processors (updated 6 October 2026), among them Fireworks AI, Google Cloud Platform, Vercel, Neon, Stripe, SendGrid, PostHog and Sentry. Locations not listed - Prices: Pro plan $16 per seat per month; Ultra plan $48 per seat per month - Scores: Reliability 33, Performance pending, Schema & documentation 61, Agent ergonomics 66, Security & auth 33, Payments & pricing 38, Task success pending, Maintenance & community 59, Transparency & trust 53 · total over the 7 assessed categories - Why: Reliability, Read with the local-software lines, because the MCP server and the CLI run on the owner's machine. · Schema & documentation, Each MCP tool we read declares a JSON Schema for its inputs, and the `.pen` format has a TypeScript schema on the docs site (25). · Agent ergonomics, Four standard tools with short definitions and two conditional ones, though the model must load skill files before `execute` is usable (22 o… · Security & auth, The CLI uses a stored session token or an organisation-scoped CLI key that the npm README says can be created and revoked in Developer Keys. · Payments & pricing, Read with the hosted lines, because the software is free to install but needs a pen.dev account and paid plans lift its limits. · Maintenance & community, `@pen.dev/cli` 0.3.11, desktop v1.2.16 and extension 0.6.75 were all published on 8 October 2026 (30). · Transparency & trust, Closed source with clear terms, an EULA and a proprietary licence file in the npm package (15 of 30). - Sources: 24, open questions: 8, both in the full twin - Capabilities: design.files, design.canvas, design.components, design.code - JSON: https://www.anchorterminal.com/api/v1/tools/pen-dev.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/pen-dev.svg` or a link to https://www.anchorterminal.com/tools/pen-dev from a page on pen.dev or one of its subdomains, or the README of github.com/highagency/pen-desktop-releases, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Call `read_skill()`, then `read_skill({ path: "pen-schema.md" })` and `read_skill({ path: "execute.md" })` before the first `execute`. The tool description alone doesn't document the operations 2. Call `get_app_state()` and confirm the active document before editing. The MCP server works on whichever `.pen` file is open in the app 3. In headless `pen interactive`, call `save()` before `exit()`, and keep `--in` and `--out` on different paths to preserve the source 4. Check that an export file exists. The docs say an export failure can print an error without a nonzero exit status 5. In CI set `PEN_CLI_KEY` plus a provider key such as `ANTHROPIC_API_KEY`. Run `pen version`, since `pen --version` is not a flag ## Connect ```bash npm install -g @pen.dev/cli ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/pen-dev ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Figma API + MCP | B | 66 | design.files, design.components, design.canvas, design.code | https://www.anchorterminal.com/tools/figma-mcp.min.md | | Framer Server API | D | 52.6 | design.files, design.components, design.canvas, design.code | https://www.anchorterminal.com/tools/framer.min.md | | Penpot API + MCP | E | 43.5 | design.files, design.components, design.canvas, design.code | https://www.anchorterminal.com/tools/penpot.min.md | | Miro API + MCP | B | 65 | design.files, design.canvas | https://www.anchorterminal.com/tools/miro.min.md | | Lucid API + MCP | C | 60.6 | design.files, design.canvas | https://www.anchorterminal.com/tools/lucid.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)