Field-by-field comparison

Compare the evidence before choosing an MCP.

Each signal stays separate, missing facts remain visible, and the column order follows your selection.

MCPs in this comparison

Uncheck an MCP to remove it. Comparing two or three keeps each signal in its own row.

Open canonical comparison link

Comparable alternatives

Shown only when capability or industry context overlaps.

Side-by-side MCP evidence comparison
Evidence fieldpenpotWatchlist candidateFigma MCPMCP100 Selected
Task fit
Best for
  • Open-source product-design inspection and controlled design edits.
  • Turning selected Figma frames into implementation context
  • Design-system teams using variables, components, and Code Connect
  • Human-supervised creation or modification of native Figma content
Not ideal for
  • Production use before the documented maturity gaps are resolved
  • MCP clients outside Figma's supported catalog
  • Teams expecting one-click pixel-perfect production code
  • Headless automation that cannot complete user OAuth
Avoid when
  • The connected identity is broader than the task requires
  • Tool calls cannot be reviewed before consequential mutations
  • Proprietary design content cannot be exposed to the selected AI client or model
  • Canvas writes cannot be reviewed before execution
  • A stable long-term zero-cost commitment is required
Provenance
Provenance details

First-party MCP

ecosystem:penpot · Publisher source ↗

First-party MCP

Figma · Publisher source ↗

Maintenance
Maintenance details

Repo: Mar 19, 2026

Package: Not documented

Repo: Not documented

Package: Not documented

Popularity evidence
GitHub stars

426

GitHub stars · checked 2026-08-14T18:46:26.000Z

Not documented
External adoption evidence
  • github: repository stars: 426Exact attributable signal.github: repository stars · Admission snapshot · checked 2026-08-14T18:46:26.000ZEvidence source ↗
Not documented
Client coverage
Client coverage details
Claude CodeStreamable HTTP
Claude DesktopStreamable HTTP
CodexStreamable HTTP
VS CodeStreamable HTTP
CursorStreamable HTTP
OpenCodeStreamable HTTP
Claude CodeStreamable HTTP
Claude DesktopStreamable HTTP
CodexStreamable HTTP
VS CodeStreamable HTTP
CursorStreamable HTTP
OpenCodeStreamable HTTP
Client coverage noteLocal stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server.
Access and data
AuthenticationThe implementation follows Penpot account and plugin authentication.The recommended remote server at https://mcp.figma.com/mcp uses user OAuth. Desktop mode relies on the signed-in Figma desktop application and its local endpoint.
CostThe MCP integration has no separately verified MCP100 price conclusion. Publisher subscriptions, API usage, compute, storage, and AI-client charges may apply.Figma documents the MCP feature as free during its current beta and says it is expected to become usage-based paid. Underlying Figma plans and plan-specific features may also apply.
PermissionsPenpot project access and plugin/server configuration govern the design documents exposed.OAuth grants access to authorized Figma resources. Available tools can read design context and, in supported workflows, create or modify canvas content. Desktop mode can also serve or download image and SVG assets.
Data handlingAuthorized service data and tool results pass through the MCP server to the connected AI client. Review the publisher and client data policies before using sensitive design & creative information.The remote service retrieves design nodes, components, variables, layouts, and potentially Make or Code Connect resources and returns them to the MCP client. Desktop mode can write downloaded assets into the local project.
Limitations
Tradeoffs
  • The project is young, has no formal releases, and requires a multi-process plugin setup.
  • The hosted endpoint is easiest to connect and has the broadest feature set, but authorized design context passes through Figma and the connected AI workflow.
  • The desktop server is locally reachable through the Figma app, but it is intended for narrower organization and enterprise use cases.
  • Code Connect can improve component reuse but requires additional design-system setup.
Risk contextThe project is young, has no formal releases, and requires a multi-process plugin setup. Use a test environment where practical, least-privilege credentials, narrowly enabled tools, and explicit confirmation for mutations. MCP100 did not execute third-party server code during this documentation review.Private designs can be disclosed through tool results, and write-enabled tools can change shared design files. Restrict accessible files, review OAuth consent, require confirmation for writes, and inspect downloaded assets before committing them.
Evidence date
Editorial review2026-07-302026-07-24
Candidate evidence2026-08-14T18:46:26.000Z2026-07-29T20:58:26.000Z

Popularity, maintenance, fit, permissions, and client support are independent evidence fields.

Read the evidence method →
Compare MCPs | MCP100 Index