# Subframe
> Design tool from Atomic Design Inc for React and Tailwind interfaces, with a cloud canvas and a macOS app. Agents read and edit pages, components and themes through a hosted MCP server, and a CLI syncs components into a codebase.
- Canonical: https://www.anchorterminal.com/tools/subframe
- Markdown: https://www.anchorterminal.com/tools/subframe.md (~7,950 tokens)
- Slim: https://www.anchorterminal.com/tools/subframe.min.md (~1,930 tokens, same facts, less prose, for token-sensitive contexts)
- JSON: https://www.anchorterminal.com/tools/subframe.json (this page as data, same URL with Accept: application/json)
- Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt)
- API: https://www.anchorterminal.com/api/v1/index.json
- Updated: 2026-10-10
## Overview
**Grade E · 39.7/100 · rank #915 of 950 · #9 in Design workspaces & canvases · not agent-ready · confidence medium**
## Assessment
An agent can read and change pages, components, snippets and themes in a Subframe project through a hosted MCP server with OAuth, and Viewer accounts get a read-only server. The server lists 46 tools, and no status page, rate limits, changelog or security contact were found. Three tools were renamed in September 2026 with no notice found.
## Facts
| Field | Value |
| --- | --- |
| Vendor | Atomic Design Inc (https://www.subframe.com) |
| Kind | MCP server |
| Category | Design workspaces & canvases (https://www.anchorterminal.com/categories/design) |
| Transport | HTTP |
| Endpoint | `https://mcp.subframe.com/mcp` |
| Auth | OAuth or key · The MCP server takes OAuth only, with dynamic client registration and PKCE, and a person approves access in a browser. Subframe access tokens are not accepted there. What an agent can do follows the user's team role. Admins and Editors can write, and Viewers get a read-only server. The CLI takes an auth token from `SUBFRAME_AUTH_TOKEN` or `--auth-token`, created at app.subframe.com/cli/auth or by the `generate_auth_token` MCP tool. Tokens are shown once and can be deleted. No token scopes or expiry are documented. Access is self-serve. |
| Pricing | Freemium ($20 / seat-mo) · Free at $0 with one project, unlimited pages and members, and MCP and CLI access, so an agent's owner can start without a contract. Pro is $20 an editor a month for unlimited projects and six times the AI credits. Viewers are free on every plan. Custom plans are priced on request. MCP calls are not priced separately (https://www.subframe.com/, checked 2026-10-09). |
| x402 | No · No x402, MPP or L402 in the docs, the pricing section or the CLI source (checked 2026-10-09). |
| Licence | Proprietary service under Atomic Design's terms of service. `@subframe/cli` and `@subframe/core` are marked ISC in their package files and the Claude Code plugin MIT in its manifest, with no licence file in the repository |
| Tools exposed | 46 |
| Packages | npm: `@subframe/cli`; npm: `@subframe/core` |
| Source | https://github.com/SubframeApp/subframe |
| Docs | https://docs.subframe.com |
| llms.txt | https://docs.subframe.com/llms.txt |
| Last release | 2026-10-08 |
| GitHub stars | 435 (as of 2026-10-09) |
| npm downloads / week | 1,006 |
| Surfaces | Hosted MCP server at `https://mcp.subframe.com/mcp` (streamable HTTP, OAuth), a docs MCP server at `https://docs.subframe.com/mcp` (no credential), three agent skills, and the `@subframe/cli` package for syncing components. A web app and a macOS desktop app hold the canvas |
| MCP tools | 46 documented. Reads such as `list_pages`, `get_page_info`, `get_component_info`, `get_theme`, `list_comments`, `screenshot_page` and `read_prototype_file`. Writes such as `design_page`, `edit_page`, `update_node_styles`, `design_component`, `edit_component`, `write_design_document`, `edit_theme`, `add_icons`, `rename`, `move`, `duplicate` and six delete tools |
| Read vs write | Viewers get a read-only server. Admins and Editors get every tool. Comments can be listed but not answered or resolved over MCP |
| Credentials | MCP: OAuth with dynamic client registration and PKCE, identity scopes only, authorisation server on a Supabase host. CLI: an auth token in `SUBFRAME_AUTH_TOKEN` or `--auth-token`, shown once, deletable, with no documented scopes or expiry |
| Background jobs | `design_page`, `design_component` and `edit_component` return a URL and a `jobId`. `wait_for_jobs` reports `running`, `done`, `error` or `not_found`, and a job silent for about 10 minutes becomes `error` |
| Output | Page and component reads return generated React and Tailwind code. `export_image` returns a download URL for PNG, JPG, WebP or PDF. Prototypes read back as a runnable Vite app, one file a call |
| CLI | `@subframe/cli` 1.212.0 (5 October 2026), commands `init` and `sync`, with `--yes`, `--non-interactive` and `--json`. Sync is one-way from Subframe to code. `push-component` is marked experimental |
| Free tier | One project, unlimited pages, prototypes and team members, a limited AI credit allocation, 24-hour version history, MCP and CLI access |
| Rate limits | None published |
| Version history | 24 hours on Free, 7 days on Pro, 30 days or more on Custom. Restores a page, component, snippet, theme or the whole project from the editor |
| Telemetry | The CLI sends crash reports to Sentry and usage events to Segment. `DO_NOT_TRACK=1` turns both off. The privacy policy names Google Analytics, PostHog, Segment and LogRocket for the service |
| Data handling | Terms of 22 January 2026 say customer data is not used to train AI models unless the customer is notified otherwise, with an opt-out. A DPA of 21 January 2026 is public. The sub-processor list is a linked Google Sheet |
| Capabilities | design.files, design.components, design.code, design.canvas, design.comments |
| Tags | hosted, mcp, oauth, remote-mcp, cli, agent-skills, react, tailwind, design-to-code, freemium, free-tier, llms-txt, closed-source, macos |
| JSON | https://www.anchorterminal.com/api/v1/tools/subframe.json |
## Score breakdown (methodology v0.4, October 2026 research run)
Assessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points.
| Category | Weight | This run | Score (0–100) | Points |
| --- | --- | --- | --- | --- |
| Reliability | 16% | 20 | 19 | 3.8 |
| Performance | 10% | pending | pending | n/a |
| Schema & documentation | 13% | 16.2 | 54 | 8.8 |
| Agent ergonomics | 13% | 16.2 | 47 | 7.6 |
| Security & auth | 14% | 17.5 | 44 | 7.7 |
| Payments & pricing | 10% | 12.5 | 33 | 4.1 |
| Task success | 10% | pending | pending | n/a |
| Maintenance & community | 7% | 8.8 | 65 | 5.7 |
| Transparency & trust (editorial 46, provenance 68) | 7% | 8.8 | 57 | 5.0 |
| Negative events | up to −15 | up to −15 | 23 to 24 September 2026. The docs and skill files renamed three MCP tools (`list_flows`, `get_flow_info`, `delete_flow`) to `list_canvases`, `get_canvas_info` and `delete_canvas`, with no changelog entry or notice found. Whether the server still answers the old names was not tested (-2). https://github.com/SubframeApp/subframe/commit/43bfb51d749713940cf0df8e73da2ab43b7358bc 7 May 2026. A docs commit records that the MCP server 'no longer accepts CLI/access tokens, only OAuth', removing the documented header route for clients without OAuth, with no dated notice found (-1, older and documented since). https://github.com/SubframeApp/subframe/commit/ff59743593fa2b581f32233b58660ace8a23f707 | -3 |
| **Total** | | | | **39.7 → E** |
### Why each score
- Reliability 19: Read with the hosted lines, because the surface an agent uses is the MCP server at mcp.subframe.com. No status page was found on the site, the docs or the footer (0 of 20). With no page there is no incident history to read (5 of 30). No rate limit is published in the docs or the skill files (0 of 15). No 429 or backoff guidance was found. The docs do say a background job that stops reporting for about 10 minutes is returned as `error`, and the CLI retries a failed request once (4 of 15). No SLA is published, and the terms say the service is not warranted to be uninterrupted (0 of 10). The MCP server carries no beta label, though the CLI's `push-component` command is marked experimental (10 of 10).
- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.
- Schema & documentation 54: The MCP server is closed and answers 401 without OAuth, so the tool definitions and their input schemas were not read. The docs list 46 tools by name and the public skill files give parameters for most of them (12 of 25, on that partial evidence). docs.subframe.com publishes `llms.txt`, a Markdown twin of each page and a docs MCP server (10 of 10). The `design` skill states for each tool what it is for and when another tool fits better, for example `edit_page` against `design_page`. The docs table gives one line a tool (15 of 20). Parameters are named in the skill (`id`, `name` or `url`, `force`, `deleteChildPages`, `includeResolved`), while the design tools take a free-text description (6 of 15). Ten example prompts and a troubleshooting section, with no list of error responses (7 of 15). The plugin and the CLI carry version numbers, with no changelog (4 of 15).
- Agent ergonomics 47: 46 documented tools is over 30 (5), with 3 added back because a Viewer account gets a read-only server. No toolsets or dynamic loading are documented, and the `design` skill adds about 55 KB when loaded (8 of 25). `list_comments` can be scoped to a page, a canvas or the project, screenshots can target one element or breakpoint and `read_prototype_file` returns one file. No paging is documented (10 of 20). `wait_for_jobs` reports `running`, `done`, `error` or `not_found`, delete tools refuse when the item is referenced, `edit_page` returns `appliedCode` and parser warnings, and the CLI prints a JSON error envelope (13 of 20). No idempotency keys. Tool annotations could not be read. Deletes need `force` when references exist, and version history can restore (8 of 20). `projectId` falls back to the first project and items are addressed by id, name or URL. No API SDK (8 of 15).
- Security & auth 44: The MCP server uses OAuth with dynamic client registration, PKCE and refresh tokens, and rejects static tokens. The authorisation server lists only identity scopes (openid, profile, email, phone, offline_access), so access follows the user's team role and not a scope. CLI tokens are shown once and can be deleted, with no scopes or expiry documented, and the `generate_auth_token` tool lets a connected agent mint one (22 of 30). Viewers get a read-only MCP server and read-only CLI access. Confirmation before deletes is guidance in the skill file and not a documented server control (12 of 20). `list_comments`, design documents and `search_docs` return text other people wrote, and no prompt-injection guidance was found (3 of 15). No audit log is documented. Version history records changes for 24 hours on Free and 7 days on Pro (3 of 15). No security.txt, disclosure policy, bug bounty or certification was found. The DPA's Annex 2 lists security measures and the docs cover Okta SSO (4 of 20).
- Payments & pricing 33: No machine payment protocol (0 of 40). Plan prices are public, Free at $0 and Pro at $20 an editor a month, with AI credits described only as limited and 6x and no per-call price (10 of 20). The Free plan has one project and includes MCP and CLI access, and the docs mention a card only at the Stripe checkout for Pro (20 of 20). A person has to sign in through a browser to approve OAuth. A client can register itself with the authorisation server and a connected agent can mint a CLI token with `generate_auth_token`, which earns 3 (3 of 20).
- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.
- Maintenance & community 65: The Claude Code plugin reached 1.0.30 on 8 October 2026 and `@subframe/cli` 1.212.0 on 5 October 2026 (30 of 30). The plugin version changed ten times between 13 July and 8 October, and the CLI had three versions on 5 October after none since 24 June (20 of 20). The repository has 13 issues in all. Seven are open, among them a Codex MCP install error from 30 March 2026 and a Claude Code plugin install error from 13 February 2026 with one and two comments, and three with none. Pull requests merge most days. The Slack community was not read (10 of 25). A search of the official MCP registry for 'subframe' returned no entry (0 of 15). A commit of 12 August 2026 fixed dependency vulnerabilities. The CLI has unit and end-to-end tests in the repository, and the only public workflow publishes the package (5 of 10).
- Transparency & trust 57: The service is closed under terms of service dated 22 January 2026. The CLI and `@subframe/core` are public and marked ISC in their package files, and the plugin MIT in its manifest, but the repository has no licence file (17 of 30). Terms, privacy policy (22 January 2026) and DPA (21 January 2026) agree with each other. The privacy policy gives no retention periods, and the terms say 'Unless Customer is notified otherwise, Customer Data is not used to train AI models', which leaves the default open to change by notice (15 of 30). No deprecation policy. A migration page explains the move to component directories, and three MCP tools were renamed with no notice found (4 of 20). The DPA links a sub-processor list held in a Google Sheet, which we did not read. The privacy policy names Google Analytics, PostHog, Segment and LogRocket, and the CLI's README discloses crash and usage reporting with `DO_NOT_TRACK=1` as the opt-out (10 of 20).
Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (23 items): https://www.anchorterminal.com/fixes/subframe.md (JSON https://www.anchorterminal.com/fixes/subframe.json)
### What we couldn't check
- unchecked: the MCP tool definitions. mcp.subframe.com answers 401 without OAuth and the server is closed, so input schemas, descriptions and annotations were read only from the docs and the public skill files.
- unchecked: the sub-processor list, which the DPA links as a Google Sheet.
- unchecked: the Slack community, so support responsiveness there is unknown.
- Whether the server still accepts the three old flow tool names after the September 2026 rename.
- Whether sign-up asks for a card or a particular sign-in method. The docs mention a card only at Pro checkout.
- No status page, changelog, rate limit, SLA or security contact was found on the site, the docs or the policies site. status and changelog addresses were not guessed.
- The amount of AI credit on each plan is not published (Free 'Limited', Pro '6x').
- The lead called the CLI open source. Its source is public and its package file says ISC, but the repository has no licence file and GitHub reports no licence.
- The `design` skill's front matter tells a model to load it for any action through the Subframe MCP server. We read it as data.
- No first release date was established. `@subframe/cli` was created on npm on 17 May 2023.
### Sources
- home page, plans and prices: (seen 2026-10-09)
- MCP server docs and tool list: (seen 2026-10-09)
- docs index for agents: (seen 2026-10-09)
- CLI in CI and agents: (seen 2026-10-09)
- auth tokens: (seen 2026-10-09)
- plans and AI credits: (seen 2026-10-09)
- team roles and permissions: (seen 2026-10-09)
- version history retention: (seen 2026-10-09)
- syncing components: (seen 2026-10-09)
- desktop app platforms: (seen 2026-10-09)
- terms of service: (seen 2026-10-09)
- privacy policy: (seen 2026-10-09)
- data processing agreement: (seen 2026-10-09)
- MCP protected resource metadata: (seen 2026-10-09)
- authorisation server metadata: (seen 2026-10-09)
- public repository (CLI source, skills, plugin manifest, docs source, history): (seen 2026-10-09)
- design skill: (seen 2026-10-09)
- repository facts and issues: (seen 2026-10-09)
- npm registry document for the CLI: (seen 2026-10-09)
- npm weekly downloads: (seen 2026-10-09)
- official MCP registry search: (seen 2026-10-09)
- domain registration: (seen 2026-10-09)
- security.txt (404): (seen 2026-10-09)
## Who's behind it (provenance 68/100, checked 2026-10-09)
| Check | Finding | Points |
| --- | --- | --- |
| Legal entity named | Atomic Design Inc | 20/20 |
| Domain age | subframe.com, registered 2003-09-24 (23 years) | 15/15 |
| Endpoint on the vendor's domain | mcp.subframe.com | 15/15 |
| Terms of service | read, states 5 of the 7 things a reader expects | 8.3/10 |
| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |
| Status page | not found | 0/10 |
| Changelog | not found | 0/10 |
| security.txt | not found | 0/10 |
The terms of service (last updated 22 January 2026) are made between Atomic Design Inc, 156 2nd Street, Ste 403, San Francisco, CA 94105, and each customer, cover the Subframe service and choose California law.
The privacy policy (effective 22 January 2026) covers products and services at subframe.com. A DPA dated 21 January 2026 is at https://policies.subframe.com/dpa.
The MCP server answers at mcp.subframe.com. Its protected resource metadata names an authorisation server at dbgjvucxjwkukwbojywe.supabase.co, so sign-in and tokens are issued from a Supabase host.
www.subframe.com/.well-known/security.txt and /security.txt return 404.
No status page or changelog is linked from the site footer, the docs or the docs index. Addresses for either were not guessed.
RDAP gives subframe.com a registration date of 2003-09-24 with Cloudflare, Inc. as registrar. The repository was created on 4 March 2024.
### Terms and privacy, as read
A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.
**Terms of service** (https://policies.subframe.com/tos), read 2026-10-09, dated 2026-01-22, states 5 of the 7 things a reader expects.
- Gives the date it was last updated. Last updated 2026-01-22.
- Names the governing law or courts. The law of the State of California.
- States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence.
- Not found in the text. Says how changes to the terms are announced.
- Not found in the text. Refers to a service level or uptime commitment.
- Also in the text (2026-10-08). Customer Data is not used to train AI models unless the customer is notified otherwise, and the customer may opt out of AI training at any time. "Unless Customer is notified otherwise, Customer Data is not used to train AI models. Customer may opt out of AI training at any time."
- Also in the text (2026-10-08). When the agreement or an order ends, other than by the customer for the vendor's breach, the customer must immediately pay the remaining balance for the rest of the subscription term. "Customer will immediately pay Atomic Design, as liquidated damages based on the varying levels of effort required over time to maintain Customer’s subscription, the remaining balance (if any) identified on the Order Form for the remainder of the subscription term."
- Also in the text (2026-10-08). The vendor may name the customer as a user and use its name and logo in customer lists, press releases, blog posts, advertisements and its website. "Customer agrees that Atomic Design may identify customer as a user of Atomic Design products and may use Customer’s name and logo in Atomic Design's customer list, press releases, blog posts, advertisements, and website."
**Privacy policy** (https://policies.subframe.com/privacy), read 2026-10-09, dated 2026-01-22, states 8 of the 8 things a reader expects.
- Gives the date it was last updated. Last updated 2026-01-22.
- Says how long data is kept. For as long as needed, with no period named.
- Gives a privacy contact. support@subframe.com.
- Says where data is transferred or stored. Data goes to the United States.
## Live (updated 2026-10-10 01:38 UTC)
- Right now: up, HTTP 401, 192 ms, checked 2026-10-10 01:38 UTC (get on `https://mcp.subframe.com/mcp`, asks for auth)
- Uptime 24h 100.0% (102 probes) · 30 days 100.0% (102 probes) · p50 154 ms · p95 262 ms
- npm `@subframe/cli` 1.212.0
- npm `@subframe/core` 1.155.0
- Watching privacy
- Watching terms
- Tools: the endpoint asks for credentials before listing them (checked 2026-10-09 21:40 UTC)
- Always current: https://www.anchorterminal.com/api/v1/live/subframe.json
## Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.
## Prices
| Item | Price | Unit | Note |
| --- | --- | --- | --- |
| Pro plan | $20 | per seat per month | each Admin and Editor, unlimited projects, six times the Free AI credits, 7-day version history. Viewers are free |
Across all listings: https://www.anchorterminal.com/prices/index.md
## Strengths
- Hosted MCP server at `https://mcp.subframe.com/mcp` with OAuth, dynamic client registration and PKCE, so no key is pasted into a config file
- Viewer accounts get a read-only MCP server and read-only CLI access, and Viewer seats are free on every plan
- Write tools cover pages, components, snippets, design documents, themes, icons and fonts, and page reads return generated React and Tailwind code
- Docs publish `llms.txt`, a Markdown twin of every page and a separate docs MCP server that needs no credential
- The CLI has a non-interactive mode with `--json` output, nonzero exit status on failure and a token read from `SUBFRAME_AUTH_TOKEN`
## Weaknesses
- 46 tools are documented with no toolsets, and the vendor's `design` skill that explains them is about 55 KB of text
- No status page, published rate limit, SLA or changelog was found, and the terms disclaim uninterrupted service
- `list_flows`, `get_flow_info` and `delete_flow` became `list_canvases`, `get_canvas_info` and `delete_canvas` in September 2026 with no notice found
- No security.txt, disclosure policy, bug bounty, certification or audit log was found
- Delete confirmation is guidance in the skill file. The vendor's skill calls deletes irreversible from MCP, with recovery only through version history in the editor (24 hours on Free)
## Before you call it (notes for agents)
1. Connect with an MCP client that supports OAuth. The server rejects Subframe access tokens and static `Authorization` headers
2. Pass `projectId` on every call. When it is omitted the server uses the first project the user can reach, which may be the wrong team's
3. After `design_page`, `design_component` or `edit_component`, call `wait_for_jobs` with the `jobId` before reading the result. Earlier reads return stale content
4. Ask the owner before any delete tool or a theme token deletion. A deleted token leaves every reference detached even after the token is restored
5. For the CLI, set `SUBFRAME_AUTH_TOKEN` and `DO_NOT_TRACK=1`, and point `--dir` at a folder that holds only Subframe code, because a full sync removes other unprotected files
## Connect
Install:
```bash
npx @subframe/cli@latest init
```
Claude Code:
```bash
claude plugin marketplace add https://github.com/SubframeApp/subframe && claude plugin install subframe@subframe
```
MCP client configuration:
```json
{
"mcpServers": {
"subframe": {
"url": "https://mcp.subframe.com/mcp"
},
"subframe-docs": {
"url": "https://docs.subframe.com/mcp"
}
}
}
```
Headless / CI:
```json
{
"command": "npx @subframe/cli@latest sync --all --json",
"env": {
"SUBFRAME_AUTH_TOKEN": "\u003ctoken\u003e"
}
}
```
Through letme (picks today, calling later): https://letme.dev/subframe. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md
## Similar tools
Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.
| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |
| --- | --- | --- | --- | --- | --- | --- |
| Figma API + MCP | B | 66 | 303 | design.files, design.components, design.canvas, design.comments, design.code | no | https://www.anchorterminal.com/tools/figma-mcp.md |
| Penpot API + MCP | E | 43.5 | 882 | design.files, design.components, design.canvas, design.comments, design.code | no | https://www.anchorterminal.com/tools/penpot.md |
| Sketch | D | 53.5 | 707 | design.files, design.canvas, design.components, design.code | no | https://www.anchorterminal.com/tools/sketch.md |
| Framer Server API | D | 52.6 | 730 | design.files, design.components, design.canvas, design.code | no | https://www.anchorterminal.com/tools/framer.md |
| pen.dev | D | 47.6 | 832 | design.files, design.canvas, design.components, design.code | no | https://www.anchorterminal.com/tools/pen-dev.md |
| Zeplin | D | 47.5 | 834 | design.files, design.components, design.comments, design.code | no | https://www.anchorterminal.com/tools/zeplin.md |
## Panel reviews (0)
Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .
Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md
## Notable
- The MCP docs list 46 tools across projects, pages, components, snippets, canvases, comments, image export, prototypes, design documents, theme, icons and fonts (source: )
- Viewers get a read-only MCP server. Read, screenshot, export and search tools work, and tools that design or edit need an Editor seat (source: )
- `design_page`, `design_component` and `edit_component` run as background jobs. A job silent for about 10 minutes is reported as `error` by `wait_for_jobs` (source: )
- The MCP server's OAuth runs on a Supabase project host, not on subframe.com. Its metadata lists dynamic client registration, PKCE and identity scopes only (source: )
- Three agent skills (`design`, `develop`, `install`) ship in the public repository and install as a Claude Code plugin or with `npx skills add`. The `design` skill is about 55 KB (source: )
- CLI sync is one-way from Subframe to the codebase and overwrites local changes to synced files unless a file carries `@subframe/sync-disable` (source: )
- The CLI reports crashes to Sentry and usage events to Segment, and `DO_NOT_TRACK=1` turns both off (source: )
- The desktop app is macOS only. The docs say Windows and Linux are coming (source: )
- #10 of 10 in Best design workspace and canvas APIs for AI agents: https://www.anchorterminal.com/best/design/index.md
- All 49 design comparisons: https://www.anchorterminal.com/compare/design/index.md
## Compare
- [Figma API + MCP vs Subframe](https://www.anchorterminal.com/compare/figma-mcp-vs-subframe.md): B 66 vs E 39.7
- [Framer Server API vs Subframe](https://www.anchorterminal.com/compare/framer-vs-subframe.md): D 52.6 vs E 39.7
- [Miro API + MCP vs Subframe](https://www.anchorterminal.com/compare/miro-vs-subframe.md): B 65 vs E 39.7
- [pen.dev vs Subframe](https://www.anchorterminal.com/compare/pen-dev-vs-subframe.md): D 47.6 vs E 39.7
- [Penpot API + MCP vs Subframe](https://www.anchorterminal.com/compare/penpot-vs-subframe.md): E 43.5 vs E 39.7
- [Sketch vs Subframe](https://www.anchorterminal.com/compare/sketch-vs-subframe.md): D 53.5 vs E 39.7
- [Subframe vs Zeplin](https://www.anchorterminal.com/compare/subframe-vs-zeplin.md): E 39.7 vs D 47.5
- [Melius vs Subframe](https://www.anchorterminal.com/compare/melius-vs-subframe.md): C 54.1 vs E 39.7
## Verify this listing
For the vendor. The badge or a plain link to this page verifies the listing, from a page on subframe.com or one of its subdomains, or the README of github.com/SubframeApp/subframe. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "subframe", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify
HTML badge:
```html
```
Markdown badge, for a README:
```markdown
[](https://www.anchorterminal.com/tools/subframe)
```
Plain link:
```html
Subframe on Anchor Terminal
```
## Share this listing
For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Subframe is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.
- Dark: https://www.anchorterminal.com/assets/share/subframe-dark.png
- Light: https://www.anchorterminal.com/assets/share/subframe-light.png