logoalt Hacker News

Figma restricts MCP access to whitelisted clients, excluding Pi

166 points • by thdr • today at 3:10 PM • 96 comments • view on HN

Comments

miguel-muniz • today at 3:43 PM

For context: Figma has two MCPs. The local "dev" MCP that works through the Desktop app, and the remote MCP that requires a connection to Figma. Companies need to be whitelisted to use the remote MCP, which is the only one that allows agents edit access to Figma documents.

I only found out about Figma's limitation when I was trying to add the remote MCP server to GitHub Copilot Desktop and kept running into errors. Turns out they whitelisted GitHub Copilot CLI but not the Desktop app and had put a pause on enabling any more vendors. Eventually someone (not sure which side) got it working.

Kind of strange to limit edit access only to the Remote MCP when their competitors like Pen[1] and Paper[2] allow any local agent to edit.

[1] https://www.pen.dev/

[2] https://paper.design/

➕ show 5 replies
JimDabell • today at 4:08 PM

OpenCode seems to have been given the run-around as well:

> on the figma mcp, we've had an email thread going on for 8 months trying to get it setup in opencode

> they seem very concerned with the labs competing with them

> finally got unblocked after i sent this email and it'll be rolled out in a week or so

The email:

> looking through the legal stuff the amount of things in there seems pretty crazy

> this is just an mcp server, there are thousands of them. we're not going to treat figma like its special

> we've been talking about this for this entire year, i don't think this makes much sense and i don't want my team burning more time on this

> once again, for a simple mcp server

— https://www.threads.com/@thdxr/post/Dd7LN-ylLQW

ig0r0 • today at 4:34 PM

I like how Pi released an updated with a new oauth client name field for mcp where I just wrote Codex and Figma mcp works now.

➕ show 1 reply
SkyPuncher • today at 4:27 PM

I do security review for my company. I suspect this is a means of containing OAuth redirect vulnerabilities. We basically needed to do the same thing with our MCP server.

The security problem is two fold: (1) companies want control over where their data goes. Figma allowing any MCP creates problems (2) open redirects can create phishing issues. If your using Pi, you’re probably thinking of this. Most users aren’t.

For us, we decided to do an allowlist pattern because it was a reasonable tradeoff. The solution is allowing per-tenant client configuration, but that comes with its own set of issues (dev time, support, maintenance, etc). When nearly all of the money is flowing through a handful of well-known MCPs there’s little reason to out effort into supporting every MCP.

➕ show 3 replies
jjcm • today at 5:26 PM

Dylan Field has shared some thoughts on this: https://x.com/zoink/status/2105369960008855914?s=46&t=bwJTI_...

➕ show 3 replies
WhitneyLand • today at 4:30 PM

Even if you’re whitelisted you get only 6 accesses a day on a standard account, have to pay for a dev account to get 200/day which still isn’t great.

For my Figma needs, having Codex do computer use seems just as good as their mcp. I can tell it, “go download the assets for what I need and take a few screenshots for reference”.

➕ show 1 reply
thefourthchime • today at 6:46 PM

Funny timing. Just yesterday I threw Opus 5.5 at excalidraw.com and told it to diagram the architecture of the software I'm working on.

It did an amazing job.

➕ show 1 reply
mcbuilder • today at 4:07 PM

As someone making my own harness, this makes me sad. Pi is a big inspiration and one of the best open source harnesses, but there are many others. dsh, opencode, hermes, etc. MCP is such a thin layer to implement for any harness, this just seems arbitrary.

allan_s • today at 5:09 PM

Shameless plug,

I created an opensource unofficial mcp/skill/cli here [email protected]:allan-simon/figma-kiwi-protocol.git

Its based on a reverse engineering of the kiwi protocol and it works for read/write , comments etc. and it does not require anything except a cookie session ( I usually automate this part by having a isolated chrome with CDP activated)

I created sometimes ago because I had to work with some customers who didnt want to pay for a full seat for my account so the official mcp was not possible at all.

hadi77ir • today at 4:20 PM

What happens if someone sends requests that look like to be OpenCode, but from Pi? What is stopping people from doing it? And how these measures are going to benefit Figma? I don't get it.

➕ show 1 reply
anandchowdhary • today at 4:54 PM

Slack does the same thing:

> Get started using the Slack MCP server by setting up a connection with an available partner

https://slack.com/help/articles/48855576908307-Guide-to-Mode...

➕ show 3 replies
srulyrosenblat • today at 3:45 PM

This was always a possibility, when my team dug into the concentration of MCP server usage a year ago we found that the top 10 servers had half of all GitHub stars (the Figma server was in 10th at the time).

https://www.oreilly.com/radar/mcp-in-practice/

MCP is only as useful as the servers people use are open.

sneezychl • today at 7:28 PM

I've been using OpenPencil as a drop-in replacement for Figma and it works fine for my needs. These days there are open source alternatives just as good as commercial solutions if you're willing to get your hands dirty and self host.

rirze • today at 4:01 PM

Funny enough, I saw some tweet earlier today about their company trying to get past the legal hurdles with getting figma mcp to work and ended up bluntly giving up. Wonder if this is related.

alex7o • today at 3:30 PM

That is very old, I use a figma CLI patched to look like Claude code so I can use it for everything

mococa • today at 8:40 PM

Is OpenCode already in the allowlist?

linuxftw • today at 3:38 PM

We're talking about client request headers, right? Why even bother with such a thing? Malicious users will just spoof those, you're only going to annoy legitimate users.

randbyte • today at 4:31 PM

This is naive. With extreme prevalence of vibe coding it’s a matter of time before someone turns their local app into an mcp proxy.

happyPersonR • today at 4:06 PM

Penpot has an mcp… might be time to take a look.

jedisct1 • today at 9:09 PM

Moonshot AI are also whitelisting user-agents: https://swival.dev/pages/providers.html#generic-openai-compa...

Weird.

godwinson__4-8 • today at 5:11 PM

Open MCP access should become a legal imperative.

Better consumer choice, less companies stifling competition.

Tell your Congressperson! An easy way to frame it: why should I have to cross check Amazon or eBay or Walmart or w/e stupid janky frontend myself and find the best price/product? Why isn't it good for the economy if any agent harness can interface with such data as a consumer right?

The question is no different here. But most people don't know what figma is (it will probably not exist in 10 years anyway). However if we focus on the big abusers of platform economics, then the benefits we accrue from highlighting the tensions with consumers at those entities will simply flow downstream into the wider economy.

An economy that is more transparent is also a necessary precursor to robust UBI. When a company like Figma makes this move, the correct read should be they are buying into a playbook bent on depriving all of us of a more equitable future - one of the few optimistic possibilities for the highly contested future we are rapidly approaching.

thehappypm • today at 4:27 PM

Why is this a global config — shouldn’t this be configurable per customer?

sparkling • today at 3:57 PM

We need to fake User-Agent now for our MCP clients? Could have just sticked to plain old HTTP then ;)

pjm331 • today at 3:28 PM

Another thing they do that I find equally frustrating is their MCP can do things you cannot do via API so you are forced to use theirs and cannot implement your own

dyllon • today at 3:26 PM

Frankly, “whitelisting” clients is against the spirit of MCP.

➕ show 4 replies
tomaskafka • today at 7:11 PM

Figma, now that’s a name I didn’t hear for a long time. I have memories of working in it for hours a day, it was some tool from the covid era, right?

gitowiec • today at 5:43 PM

Figma srigma, who cares, they still in business?

xnx • today at 5:16 PM

Best to migrate off of Figma rather than get locked into further enshitification.

RobertDeNiro • today at 4:33 PM

Figma has been absolute dog shit about opening up to mcp usage. We have been trying to include them in an internal tool we are building, but that would require a service account, which they refuse to offer.

triyambakam • today at 4:07 PM

I've seen other apps do this as well e.g. Cal.com

spwa4 • today at 3:50 PM

I think we'll see more of this. Of course SAAS companies like Figma, and soon Adobe and ... will see that their tools are still useful. And they are useful to LLMs like they are useful to humans.

The obvious play to "extract value" from that is to restrict access to bots and offer LLM integration themselves, for a fee.

➕ show 1 reply
katzzzari • today at 6:40 PM

[dead]

ihsw • today at 4:22 PM

[dead]

cosmotic • today at 4:03 PM

Allow-listed would be a more accurate and more inclusive term.

➕ show 1 reply