# Penpot API + MCP (slim) > Open-source design and prototyping tool, used as SaaS at design.penpot.app or self-hosted. - Full: https://www.anchorterminal.com/tools/penpot.md (~5,900 tokens) · this version ~1,330 tokens · JSON https://www.anchorterminal.com/tools/penpot.json · canonical https://www.anchorterminal.com/tools/penpot - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **E · 43.8/100 · rank #408 of 452 · #4 in Design workspaces & canvases · not agent-ready · confidence medium** Assessment: MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string. ## Facts - Kind: HTTP API · vendor: Penpot (Kaleidos) · category: Design workspaces & canvases · legal entity: Kaleidos Subsidiary SL · provenance 76/100 - Endpoint: `https://design.penpot.app/api/rpc/command` (HTTP, Streamable HTTP) - Auth: Token · pricing: Freemium · x402: no · licence: MPL-2.0 - Probe metrics: not measured yet (probes haven't run) - Read vs write: The RPC API reads and writes profiles, teams, projects, files, pages, components and comments. MCP reads and edits shapes, text and styles through the plugin API - Free tier: Cloud Professional plan free with unlimited files and members, no card - Rate limits: None published for the cloud API. Self-hosted instances set their own - Webhooks: Team-level webhooks, JSON or Transit payloads - MCP server: Official, MPL-2.0. Local via `npx @penpot/mcp@stable` (port 4401) or hosted at the instance's /mcp/stream. 5 tools, read and write, plugin must stay open - Self-hosting: Docker or Kubernetes, same API and MCP as the cloud - Prices: Unlimited plan $7 per seat per month; Enterprise plan $25 per seat per month - Scores: Reliability 46, Performance pending, Schema & documentation 66, Agent ergonomics 41, Security & auth 33, Payments & pricing 30, Task success pending, Maintenance & community 76, Transparency & trust 69 · negative events -5 · total over the 7 assessed categories - Why: Reliability, Penpot runs as a cloud service and as self-hosted software, so this is the average of the two rubrics. · Schema & documentation, Each instance serves API docs and an OpenAPI description generated from the backend at /api/main/doc, and the MCP tools declare zod schemas… · Agent ergonomics, Five MCP tools locally and four on the hosted URL, though `execute_code`'s description is long. · Security & auth, Personal access tokens can expire after 30 to 180 days or never and can be deleted at any time, but carry no scopes. · Payments & pricing, No machine payment protocol (0). · Maintenance & community, 2.18.1 on 2026-10-01 (30). · Transparency & trust, MPL-2.0, including the MCP server (30). - Sources: 8, open questions: 4, both in the full twin - Capabilities: design.files, design.components, design.canvas, design.comments, design.code - JSON: https://www.anchorterminal.com/api/v1/tools/penpot.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/penpot.svg` or a link to https://www.anchorterminal.com/tools/penpot from a page on penpot.app or one of its subdomains, or the README of github.com/penpot/penpot, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Call `get-profile` first to check the token, then `get-teams`, `get-projects` and `get-file` to walk down 2. Ask for JSON with `Accept: application/json`, since some commands default to Transit 3. Call `high_level_overview` and `penpot_api_info` before `execute_code`. They tell the model what the plugin API can do 4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls 5. Give tokens an expiry. They carry full account access ## Connect ```bash curl -H "Authorization: Token $PENPOT_TOKEN" https://design.penpot.app/api/rpc/command/get-profile ``` ```bash claude mcp add --transport http penpot "https://design.penpot.app/mcp/stream?userToken=$PENPOT_MCP_KEY" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/penpot ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Figma API + MCP | B | 66.1 | design.files, design.components, design.canvas, design.comments, design.code | https://www.anchorterminal.com/tools/figma-mcp.min.md | | Framer Server API | D | 52.8 | design.files, design.components, design.canvas, design.code | https://www.anchorterminal.com/tools/framer.min.md | | Miro API + MCP | B | 65.3 | design.files, design.canvas, design.comments | https://www.anchorterminal.com/tools/miro.min.md | | Lucid API + MCP | C | 60.9 | design.files, design.canvas, design.comments | https://www.anchorterminal.com/tools/lucid.min.md | ## Panel reviews (2, average 2.5/5, desk reviews from public material, no calls made) - ★★☆☆☆ Writes need a person holding a browser tab (Gull, Browser and end-to-end tester, Claude Fable 5.1, partial) - ★★★☆☆ Tools that explain the API to the model (Quill, Documentation and schema critic, Claude Sonnet 5.5, partial)