Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | penpotWatchlist candidate | Figma MCPMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | First-party MCP ecosystem:penpot · Publisher source ↗ | First-party MCP Figma · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Mar 19, 2026 Package: Not documented | Repo: Not documented Package: Not documented |
| Popularity evidence | ||
| GitHub stars | 426 GitHub stars · checked 2026-08-14T18:46:26.000Z | Not documented |
| External adoption evidence |
| Not documented |
| Client coverage | ||
| Client coverage details | Claude Code✓ Streamable HTTP Claude Desktop✓ Streamable HTTP Codex✓ Streamable HTTP VS Code✓ Streamable HTTP Cursor✓ Streamable HTTP OpenCode✓ Streamable HTTP | Claude Code✓ Streamable HTTP Claude Desktop✓ Streamable HTTP Codex✓ Streamable HTTP VS Code✓ Streamable HTTP Cursor✓ Streamable HTTP OpenCode✓ Streamable HTTP |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | The implementation follows Penpot account and plugin authentication. | The recommended remote server at https://mcp.figma.com/mcp uses user OAuth. Desktop mode relies on the signed-in Figma desktop application and its local endpoint. |
| Cost | The MCP integration has no separately verified MCP100 price conclusion. Publisher subscriptions, API usage, compute, storage, and AI-client charges may apply. | Figma documents the MCP feature as free during its current beta and says it is expected to become usage-based paid. Underlying Figma plans and plan-specific features may also apply. |
| Permissions | Penpot project access and plugin/server configuration govern the design documents exposed. | OAuth grants access to authorized Figma resources. Available tools can read design context and, in supported workflows, create or modify canvas content. Desktop mode can also serve or download image and SVG assets. |
| Data handling | Authorized service data and tool results pass through the MCP server to the connected AI client. Review the publisher and client data policies before using sensitive design & creative information. | The remote service retrieves design nodes, components, variables, layouts, and potentially Make or Code Connect resources and returns them to the MCP client. Desktop mode can write downloaded assets into the local project. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | The project is young, has no formal releases, and requires a multi-process plugin setup. Use a test environment where practical, least-privilege credentials, narrowly enabled tools, and explicit confirmation for mutations. MCP100 did not execute third-party server code during this documentation review. | Private designs can be disclosed through tool results, and write-enabled tools can change shared design files. Restrict accessible files, review OAuth consent, require confirmation for writes, and inspect downloaded assets before committing them. |
| Evidence date | ||
| Editorial review | 2026-07-30 | 2026-07-24 |
| Candidate evidence | 2026-08-14T18:46:26.000Z | 2026-07-29T20:58:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →