# Subframe (slim) > Design tool from Atomic Design Inc for React and Tailwind interfaces, with a cloud canvas and a macOS app. Agents read and edit pages, components and themes through a hosted MCP server, and a CLI syncs components into a codebase. - Full: https://www.anchorterminal.com/tools/subframe.md (~7,950 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/subframe.json · canonical https://www.anchorterminal.com/tools/subframe - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 **E · 39.7/100 · rank #915 of 950 · #9 in Design workspaces & canvases · not agent-ready · confidence medium** Assessment: An agent can read and change pages, components, snippets and themes in a Subframe project through a hosted MCP server with OAuth, and Viewer accounts get a read-only server. The server lists 46 tools, and no status page, rate limits, changelog or security contact were found. Three tools were renamed in September 2026 with no notice found. ## Facts - Kind: MCP server · vendor: Atomic Design Inc · category: Design workspaces & canvases · legal entity: Atomic Design Inc · provenance 68/100 - Endpoint: `https://mcp.subframe.com/mcp` (HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Atomic Design's terms of service. `@subframe/cli` and `@subframe/core` are marked ISC in their package files and the Claude Code plugin MIT in its manifest, with no licence file in the repository - Probe metrics: not measured yet (probes haven't run) - Surfaces: Hosted MCP server at `https://mcp.subframe.com/mcp` (streamable HTTP, OAuth), a docs MCP server at `https://docs.subframe.com/mcp` (no credential), three agent skills, and the `@subframe/cli` package for syncing components. A web app and a macOS desktop app hold the canvas - MCP tools: 46 documented. Reads such as `list_pages`, `get_page_info`, `get_component_info`, `get_theme`, `list_comments`, `screenshot_page` and `read_prototype_file`. Writes such as `design_page`, `edit_page`, `update_node_styles`, `design_component`, `edit_component`, `write_design_document`, `edit_theme`, `add_icons`, `rename`, `move`, `duplicate` and six delete tools - Read vs write: Viewers get a read-only server. Admins and Editors get every tool. Comments can be listed but not answered or resolved over MCP - Credentials: MCP: OAuth with dynamic client registration and PKCE, identity scopes only, authorisation server on a Supabase host. CLI: an auth token in `SUBFRAME_AUTH_TOKEN` or `--auth-token`, shown once, deletable, with no documented scopes or expiry - Background jobs: `design_page`, `design_component` and `edit_component` return a URL and a `jobId`. `wait_for_jobs` reports `running`, `done`, `error` or `not_found`, and a job silent for about 10 minutes becomes `error` - Output: Page and component reads return generated React and Tailwind code. `export_image` returns a download URL for PNG, JPG, WebP or PDF. Prototypes read back as a runnable Vite app, one file a call - CLI: `@subframe/cli` 1.212.0 (5 October 2026), commands `init` and `sync`, with `--yes`, `--non-interactive` and `--json`. Sync is one-way from Subframe to code. `push-component` is marked experimental - Free tier: One project, unlimited pages, prototypes and team members, a limited AI credit allocation, 24-hour version history, MCP and CLI access - Rate limits: None published - Version history: 24 hours on Free, 7 days on Pro, 30 days or more on Custom. Restores a page, component, snippet, theme or the whole project from the editor - Telemetry: The CLI sends crash reports to Sentry and usage events to Segment. `DO_NOT_TRACK=1` turns both off. The privacy policy names Google Analytics, PostHog, Segment and LogRocket for the service - Data handling: Terms of 22 January 2026 say customer data is not used to train AI models unless the customer is notified otherwise, with an opt-out. A DPA of 21 January 2026 is public. The sub-processor list is a linked Google Sheet - Prices: Pro plan $20 per seat per month - Scores: Reliability 19, Performance pending, Schema & documentation 54, Agent ergonomics 47, Security & auth 44, Payments & pricing 33, Task success pending, Maintenance & community 65, Transparency & trust 57 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines, because the surface an agent uses is the MCP server at mcp.subframe.com. · Schema & documentation, The MCP server is closed and answers 401 without OAuth, so the tool definitions and their input schemas were not read. · Agent ergonomics, 46 documented tools is over 30 (5), with 3 added back because a Viewer account gets a read-only server. · Security & auth, The MCP server uses OAuth with dynamic client registration, PKCE and refresh tokens, and rejects static tokens. · Payments & pricing, No machine payment protocol (0 of 40). · Maintenance & community, The Claude Code plugin reached 1.0.30 on 8 October 2026 and `@subframe/cli` 1.212.0 on 5 October 2026 (30 of 30). · Transparency & trust, The service is closed under terms of service dated 22 January 2026. The CLI and `@subframe/core` are public and marked ISC in their package… - Sources: 23, open questions: 10, both in the full twin - Capabilities: design.files, design.components, design.code, design.canvas, design.comments - JSON: https://www.anchorterminal.com/api/v1/tools/subframe.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/subframe.svg` or a link to https://www.anchorterminal.com/tools/subframe from a page on subframe.com or one of its subdomains, or the README of github.com/SubframeApp/subframe, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Connect with an MCP client that supports OAuth. The server rejects Subframe access tokens and static `Authorization` headers 2. Pass `projectId` on every call. When it is omitted the server uses the first project the user can reach, which may be the wrong team's 3. After `design_page`, `design_component` or `edit_component`, call `wait_for_jobs` with the `jobId` before reading the result. Earlier reads return stale content 4. Ask the owner before any delete tool or a theme token deletion. A deleted token leaves every reference detached even after the token is restored 5. For the CLI, set `SUBFRAME_AUTH_TOKEN` and `DO_NOT_TRACK=1`, and point `--dir` at a folder that holds only Subframe code, because a full sync removes other unprotected files ## Connect ```bash npx @subframe/cli@latest init ``` ```bash claude plugin marketplace add https://github.com/SubframeApp/subframe && claude plugin install subframe@subframe ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/subframe ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Figma API + MCP | B | 66 | design.files, design.components, design.canvas, design.comments, design.code | https://www.anchorterminal.com/tools/figma-mcp.min.md | | Penpot API + MCP | E | 43.5 | design.files, design.components, design.canvas, design.comments, design.code | https://www.anchorterminal.com/tools/penpot.min.md | | Sketch | D | 53.5 | design.files, design.canvas, design.components, design.code | https://www.anchorterminal.com/tools/sketch.min.md | | Framer Server API | D | 52.6 | design.files, design.components, design.canvas, design.code | https://www.anchorterminal.com/tools/framer.min.md | | pen.dev | D | 47.6 | design.files, design.canvas, design.components, design.code | https://www.anchorterminal.com/tools/pen-dev.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)