103 pointsby thdr2 hours ago30 comments
  • miguel-muniz2 hours ago
    For context: Figma has two MCPs. The local "dev" MCP that works through the Desktop app, and the remote MCP that requires a connection to Figma. Companies need to be whitelisted to use the remote MCP, which is the only one that allows agents edit access to Figma documents.

    I only found out about Figma's limitation when I was trying to add the remote MCP server to GitHub Copilot Desktop and kept running into errors. Turns out they whitelisted GitHub Copilot CLI but not the Desktop app and had put a pause on enabling any more vendors. Eventually someone (not sure which side) got it working.

    Kind of strange to limit edit access only to the Remote MCP when their competitors like Pen[1] and Paper[2] allow any local agent to edit.

    [1] https://www.pen.dev/

    [2] https://paper.design/

    • miguel-munizan hour ago
      To speak more broadly, Figma is in a really tough spot right now. I see more and more designers in my circle saying they are skipping design tools entirely to prototype in code or ship directly in their product's code base. Honestly I find myself doing the same.

      Figma's main value used to be in providing designers a canvas to iterate and explore ideas since the majority of designers did not code, but AI has completely changed that.

      I fear Figma's reluctance to integrate with all the popular AI tools might actually accelerate their decline. AI provides so much value, that I would rather base my software purchasing decisions around what is compatible with my AI of choice rather than pick an AI that is compatible with Figma.

      • oh_no35 minutes ago
        yeah it's 100% the wrong move for them to make, I think there is probably a lot of value in AI driving Figma, and if I can't do that, Figma will fall out of the ecosystem.
        • miguel-muniz15 minutes ago
          They have their own agent built into Figma, which of course uses credits which you must pay Figma for.
      • locallost31 minutes ago
        I think it's really interesting how these areas are merging, and I'm not sure who goes. Designers or "coders". Probably both depending on the context. The expectations though from every field seems to be that they'll be the last man standing. My best guess is, management has the worst cards.

        I am 100% in agreement that companies that try to shut down access to agents will be replaced. It's just the future for a lot of work and workflows. In a way it's an opportunity for someone.

        • TeMPOraL18 minutes ago
          > I think it's really interesting how these areas are merging, and I'm not sure who goes. Designers or "coders".

          Neither of them, not yet. What will go away is the products currently used by these groups.

          It's happening in software development, too. In the past 3 months, I used an IDE for maybe few hours total. 99% of my technical work is now easier and better done through agentic chat interface.

    • TeMPOraL20 minutes ago
      They're realizing what most product companies aren't yet (at least not openly): AI subsumes products.

      Most companies seem to still be in denial about it, and hope that if they add some more AI into their product, or do it just right, it will make sense. But it won't. AI is destined to sit on the outside, and products to be reduced into a bag of tools for AI to call.

      Taking away write access from AI tools outside their contractual control is an expected knee-jerk reaction, but it'll probably just hasten the product's slide into irrelevancy by ceding ground to competition (that will ultimately share the same fate, too, but is still in denial about it).

    • cellularmitosisan hour ago
      I found figma’s remote MCP to be a poor fit for iOS development (it sets tokens on fire and gives Claude the details as React+Tailwind) and got much better results by having Claude build a set of “lens” tools around their REST API (“give me all of the fonts”, “give me the layout dimensions”, “give me the colors”, etc).

      The key to making it token efficient was allowing Claude to invent its own plaintext markup format for the lens output.

    • guluarte28 minutes ago
      last time i used figma you also need to pay a dev seat PER team to use the MCP
  • JimDabell2 hours ago
    OpenCode seems to have been given the run-around as well:

    > on the figma mcp, we've had an email thread going on for 8 months trying to get it setup in opencode

    > they seem very concerned with the labs competing with them

    > finally got unblocked after i sent this email and it'll be rolled out in a week or so

    The email:

    > looking through the legal stuff the amount of things in there seems pretty crazy

    > this is just an mcp server, there are thousands of them. we're not going to treat figma like its special

    > we've been talking about this for this entire year, i don't think this makes much sense and i don't want my team burning more time on this

    > once again, for a simple mcp server

    — https://www.threads.com/@thdxr/post/Dd7LN-ylLQW

  • ig0r0an hour ago
    I like how Pi released an updated with a new oauth client name field for mcp where I just wrote Codex and Figma mcp works now.
  • jjcm12 minutes ago
    Dylan Field has shared some thoughts on this: https://x.com/zoink/status/2105369960008855914?s=46&t=bwJTI_...
  • thdr2 hours ago
    • king_geedorahan hour ago
      Seeing Anubis deployed on a site whose existence is largely predicated on twitter putting up roadblocks to anonymous access is rather amusing.
  • allan_s29 minutes ago
    Shameless plug,

    I created an opensource unofficial mcp/skill/cli here git@github.com:allan-simon/figma-kiwi-protocol.git

    Its based on a reverse engineering of the kiwi protocol and it works for read/write , comments etc. and it does not require anything except a cookie session ( I usually automate this part by having a isolated chrome with CDP activated)

    I created sometimes ago because I had to work with some customers who didnt want to pay for a full seat for my account so the official mcp was not possible at all.

  • anandchowdharyan hour ago
    Slack does the same thing:

    > Get started using the Slack MCP server by setting up a connection with an available partner

    https://slack.com/help/articles/48855576908307-Guide-to-Mode...

    • TeMPOraL10 minutes ago
      Another company desperately trying to enshittify their integrations as they realize AI agents are a mortal threat to their entire business.
  • WhitneyLandan hour ago
    Even if you’re whitelisted you get only 6 accesses a day on a standard account, have to pay for a dev account to get 200/day which still isn’t great.

    For my Figma needs, having Codex do computer use seems just as good as their mcp. I can tell it, “go download the assets for what I need and take a few screenshots for reference”.

    • miguel-munizan hour ago
      Dev seats always felt like a ripoff IMO. They are just nickel and diming enterprise orgs for features that should just be free. Especially now when AI makes Figma's own code generation useless.

      I couldn't believe it when file annotations are only visible to users with design and dev seats. Like my PMs will never be able to read the annotations. I stopped using that feature entirely after that, and just stuck to pasting in FigJam sticky notes instead.

  • SkyPuncheran hour ago
    I do security review for my company. I suspect this is a means of containing OAuth redirect vulnerabilities. We basically needed to do the same thing with our MCP server.

    The security problem is two fold: (1) companies want control over where their data goes. Figma allowing any MCP creates problems (2) open redirects can create phishing issues. If your using Pi, you’re probably thinking of this. Most users aren’t.

    For us, we decided to do an allowlist pattern because it was a reasonable tradeoff. The solution is allowing per-tenant client configuration, but that comes with its own set of issues (dev time, support, maintenance, etc). When nearly all of the money is flowing through a handful of well-known MCPs there’s little reason to out effort into supporting every MCP.

    • hparadizan hour ago
      We need OIDC tokens generated at the SSO placed on the dev environment upon user authentication and then have those OIDCs reusable among multiple mcps. People don't wanna login to 10 different mcps every morning.
  • mcbuilder2 hours ago
    As someone making my own harness, this makes me sad. Pi is a big inspiration and one of the best open source harnesses, but there are many others. dsh, opencode, hermes, etc. MCP is such a thin layer to implement for any harness, this just seems arbitrary.
  • hadi77iran hour ago
    What happens if someone sends requests that look like to be OpenCode, but from Pi? What is stopping people from doing it? And how these measures are going to benefit Figma? I don't get it.
    • Phemistan hour ago
      I guess this is in violation of the ToS on your account and can get your account closed? At least, that's how I imagine it would work.
  • rirze2 hours ago
    Funny enough, I saw some tweet earlier today about their company trying to get past the legal hurdles with getting figma mcp to work and ended up bluntly giving up. Wonder if this is related.
  • srulyrosenblat2 hours ago
    This was always a possibility, when my team dug into the concentration of MCP server usage a year ago we found that the top 10 servers had half of all GitHub stars (the Figma server was in 10th at the time).

    https://www.oreilly.com/radar/mcp-in-practice/

    MCP is only as useful as the servers people use are open.

  • randbytean hour ago
    This is naive. With extreme prevalence of vibe coding it’s a matter of time before someone turns their local app into an mcp proxy.
  • alex7o2 hours ago
    That is very old, I use a figma CLI patched to look like Claude code so I can use it for everything
  • happyPersonR2 hours ago
    Penpot has an mcp… might be time to take a look.
  • thehappypman hour ago
    Why is this a global config — shouldn’t this be configurable per customer?
  • an hour ago
    undefined
  • godwinson__4-827 minutes ago
    Open MCP access should become a legal imperative.

    Better consumer choice, less companies stifling competition.

    Tell your Congressperson! An easy way to frame it: why should I have to cross check Amazon or eBay or Walmart or w/e stupid janky frontend myself and find the best price/product? Why isn't it good for the economy if any agent harness can interface with such data as a consumer right?

    The question is no different here. But most people don't know what figma is (it will probably not exist in 10 years anyway). However if we focus on the big abusers of platform economics, then the benefits we accrue from highlighting the tensions with consumers at those entities will simply flow downstream into the wider economy.

    An economy that is more transparent is also a necessary precursor to robust UBI. When a company like Figma makes this move, the correct read should be they are buying into a playbook bent on depriving all of us of a more equitable future - one of the few optimistic possibilities for the highly contested future we are rapidly approaching.

  • linuxftw2 hours ago
    We're talking about client request headers, right? Why even bother with such a thing? Malicious users will just spoof those, you're only going to annoy legitimate users.
  • xnx22 minutes ago
    Best to migrate off of Figma rather than get locked into further enshitification.
  • sparkling2 hours ago
    We need to fake User-Agent now for our MCP clients? Could have just sticked to plain old HTTP then ;)
  • RobertDeNiroan hour ago
    Figma has been absolute dog shit about opening up to mcp usage. We have been trying to include them in an internal tool we are building, but that would require a service account, which they refuse to offer.
  • pjm3312 hours ago
    Another thing they do that I find equally frustrating is their MCP can do things you cannot do via API so you are forced to use theirs and cannot implement your own
  • dyllon2 hours ago
    Frankly, “whitelisting” clients is against the spirit of MCP.
    • fg1372 hours ago
    • klardotsh2 hours ago
      Welcome to where this was inevitably all going to go eventually. The entirety of commercial personal computing is going this direction: locking down APIs to make sure you’re not only doing what the company wants, but also the way the company wants. Mobile phones provide countless examples already; applying those examples to LLM world isn’t far fetched - and Anthropic already started down the road of “any old agent isn’t OUR agent” months ago.
    • recursive2 hours ago
      Spam is against the spirit of email.
    • chpatrick2 hours ago
      Open MCP basically kills your product in my opinion, you can't charge for any feature the LLM can do itself.

      It's probably good news for users and open source though, why would you pay for something if a free tool with an MCP can do it.

      • fidotron2 hours ago
        > Open MCP basically kills your product in my opinion, you can't charge for any feature the LLM can do itself.

        For products for which this is true resorting to whitelisting clients simply accelerates your obsolescence by creating a temporary market for products that are MCP, and open agent, friendly.

  • triyambakam2 hours ago
    I've seen other apps do this as well e.g. Cal.com
  • 2 hours ago
    undefined
  • spwa42 hours ago
    I think we'll see more of this. Of course SAAS companies like Figma, and soon Adobe and ... will see that their tools are still useful. And they are useful to LLMs like they are useful to humans.

    The obvious play to "extract value" from that is to restrict access to bots and offer LLM integration themselves, for a fee.

    • thenewnewguy2 hours ago
      How does restricting the MCP ""user agent"" to only claude and codex and whatever enable Figma to extract value?
      • Perz1valan hour ago
        "User agent" but do users run LLMs behind their agents on their hardware? No, it's run in an AI datacenter. They can easily make a deal to route that without involving user's machine, or they can route this via user's machine but attach a signature. Of course both parties must agree on that, but technically there's nothing stopping them
        • spwa4an hour ago
          No, you only get to use the Adobe LLM, which you pay adobe from. And yes, it runs remotely so they can charge you per-use.
      • adithyassekhar2 hours ago
        Soon they might require a vendor specific api key to access it and that requires support from the big players (anthropic,openai). They’re laying down the “framework” now.
  • ihswan hour ago
    [dead]
  • cosmotic2 hours ago
    Allow-listed would be a more accurate and more inclusive term.
    • ihswan hour ago
      [dead]