Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Shameless plug,

    I created an opensource unofficial mcp/skill/cli here git@github.com:allan-simon/figma-kiwi-protocol.git

    Its based on a reverse engineering of the kiwi protocol and it works for read/write , comments etc. and it does not require anything except a cookie session ( I usually automate this part by having a isolated chrome with CDP activated)

    I created sometimes ago because I had to work with some customers who didnt want to pay for a full seat for my account so the official mcp was not possible at all.

  • Dylan Field has shared some thoughts on this: https://x.com/zoink/status/2105369960008855914?s=46&t=bwJTI_...
    by jjcm
  • Even if you’re whitelisted you get only 6 accesses a day on a standard account, have to pay for a dev account to get 200/day which still isn’t great.

    For my Figma needs, having Codex do computer use seems just as good as their mcp. I can tell it, “go download the assets for what I need and take a few screenshots for reference”.

  • by thdr
  • I like how Pi released an updated with a new oauth client name field for mcp where I just wrote Codex and Figma mcp works now.
  • I do security review for my company. I suspect this is a means of containing OAuth redirect vulnerabilities. We basically needed to do the same thing with our MCP server.

    The security problem is two fold: (1) companies want control over where their data goes. Figma allowing any MCP creates problems (2) open redirects can create phishing issues. If your using Pi, you’re probably thinking of this. Most users aren’t.

    For us, we decided to do an allowlist pattern because it was a reasonable tradeoff. The solution is allowing per-tenant client configuration, but that comes with its own set of issues (dev time, support, maintenance, etc). When nearly all of the money is flowing through a handful of well-known MCPs there’s little reason to out effort into supporting every MCP.

  • OpenCode seems to have been given the run-around as well:

    > on the figma mcp, we've had an email thread going on for 8 months trying to get it setup in opencode

    > they seem very concerned with the labs competing with them

    > finally got unblocked after i sent this email and it'll be rolled out in a week or so

    The email:

    > looking through the legal stuff the amount of things in there seems pretty crazy

    > this is just an mcp server, there are thousands of them. we're not going to treat figma like its special

    > we've been talking about this for this entire year, i don't think this makes much sense and i don't want my team burning more time on this

    > once again, for a simple mcp server

    — https://www.threads.com/@thdxr/post/Dd7LN-ylLQW

  • For context: Figma has two MCPs. The local "dev" MCP that works through the Desktop app, and the remote MCP that requires a connection to Figma. Companies need to be whitelisted to use the remote MCP, which is the only one that allows agents edit access to Figma documents.

    I only found out about Figma's limitation when I was trying to add the remote MCP server to GitHub Copilot Desktop and kept running into errors. Turns out they whitelisted GitHub Copilot CLI but not the Desktop app and had put a pause on enabling any more vendors. Eventually someone (not sure which side) got it working.

    Kind of strange to limit edit access only to the Remote MCP when their competitors like Pen[1] and Paper[2] allow any local agent to edit.

    [1] https://www.pen.dev/

    [2] https://paper.design/

Explore Birbla archives