Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | penpotWatchlist candidate | Framelink MCP for FigmaMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | First-party MCP ecosystem:penpot · Publisher source ↗ | Community implementation io.github.GLips · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Mar 19, 2026 Package: Not documented | Repo: Aug 7, 2026 Package: Jun 18, 2026 |
| Popularity evidence | ||
| GitHub stars | 426 GitHub stars · checked 2026-08-14T18:46:26.000Z | 15,658 GitHub stars · checked 2026-08-14T18:46:26.000Z |
| 30-day package downloads | No reliable download data | 350,316 30-day package downloads · checked 2026-08-14T18:46:26.000Z |
| External adoption evidence |
|
|
| Client coverage | ||
| Client coverage details | Claude Code✓ Streamable HTTP Claude Desktop✓ Streamable HTTP Codex✓ Streamable HTTP VS Code✓ Streamable HTTP Cursor✓ Streamable HTTP OpenCode✓ Streamable HTTP | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | The implementation follows Penpot account and plugin authentication. | Uses a personal access token through FIGMA_API_KEY or X-Figma-Token, or an OAuth bearer token. HTTP also supports per-request token headers. |
| Cost | The MCP integration has no separately verified MCP100 price conclusion. Publisher subscriptions, API usage, compute, storage, and AI-client charges may apply. | The MIT-licensed server lists no MCP fee. Figma plan and API limits, client, and model costs are separate. |
| Permissions | Penpot project access and plugin/server configuration govern the design documents exposed. | Reads Figma file and node data through the Figma API and downloads PNG, SVG, or GIF assets into a configured local image directory; no Figma write capability is documented. |
| Data handling | Authorized service data and tool results pass through the MCP server to the connected AI client. Review the publisher and client data policies before using sensitive design & creative information. | Figma metadata and API responses are returned to the MCP client; raw tools write figma-raw.json locally and image tools save assets locally. Telemetry sends server, platform, session, and event metadata by default; retention is not documented. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | The project is young, has no formal releases, and requires a multi-process plugin setup. Use a test environment where practical, least-privilege credentials, narrowly enabled tools, and explicit confirmation for mutations. MCP100 did not execute third-party server code during this documentation review. | Private design data and assets can reach the MCP client or model and local raw logs; telemetry adds metadata transmission. Protect tokens, restrict the image directory, and review downloaded and raw files. |
| Evidence date | ||
| Editorial review | 2026-07-30 | 2026-08-11 |
| Candidate evidence | 2026-08-14T18:46:26.000Z | 2026-08-14T18:46:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →