Hey David, Gayani here from Figma. You're right that our remote MCP server only accepts clients on our supported list, and Pi isn't on it yet. You can see the current list in our MCP catalog at https://t.co/T0hj2nTIWa.…

125 points•thdr•about 4 hours ago•70 comments•

70 comments

miguel-munizabout 3 hours ago
For context: Figma has two MCPs. The local "dev" MCP that works through the Desktop app, and the remote MCP that requires a connection to Figma. Companies need to be whitelisted to use the remote MCP, which is the only one that allows agents edit access to Figma documents.

I only found out about Figma's limitation when I was trying to add the remote MCP server to GitHub Copilot Desktop and kept running into errors. Turns out they whitelisted GitHub Copilot CLI but not the Desktop app and had put a pause on enabling any more vendors. Eventually someone (not sure which side) got it working.

Kind of strange to limit edit access only to the Remote MCP when their competitors like Pen[1] and Paper[2] allow any local agent to edit.

[1] https://www.pen.dev/

[2] https://paper.design/

miguel-munizabout 2 hours ago
To speak more broadly, Figma is in a really tough spot right now. I see more and more designers in my circle saying they are skipping design tools entirely to prototype in code or ship directly in their product's code base. Honestly I find myself doing the same.

Figma's main value used to be in providing designers a canvas to iterate and explore ideas since the majority of designers did not code, but AI has completely changed that.

I fear Figma's reluctance to integrate with all the popular AI tools might actually accelerate their decline. AI provides so much value, that I would rather base my software purchasing decisions around what is compatible with my AI of choice rather than pick an AI that is compatible with Figma.

oh_noabout 2 hours ago
yeah it's 100% the wrong move for them to make, I think there is probably a lot of value in AI driving Figma, and if I can't do that, Figma will fall out of the ecosystem.
dataviz1000about 1 hour ago
Everyone is in a really tough spot.

The AI companies focused most their effort on writing software and continue to do so. Software, SaaS, and software engineers are the first to be disrupted.

> but AI has completely changed that.

Exactly. However, it is because AI is focused on solving writing software first which is the step to solving everything else.

varispeedabout 2 hours ago
The poor value proposition of Figma is that nobody even bothers to vibe code a competitor. It's useless.
locallostabout 2 hours ago
I think it's really interesting how these areas are merging, and I'm not sure who goes. Designers or "coders". Probably both depending on the context. The expectations though from every field seems to be that they'll be the last man standing. My best guess is, management has the worst cards.

I am 100% in agreement that companies that try to shut down access to agents will be replaced. It's just the future for a lot of work and workflows. In a way it's an opportunity for someone.

evek9 minutes ago
I’ve been using a 3rd party MCP that uses a desktop plugin as a bridge, it allows for llm driven design, export, etc.

https://github.com/southleft/figma-console-mcp/tree/main

No affiliation, just found it useful.

TeMPOraLabout 2 hours ago
They're realizing what most product companies aren't yet (at least not openly): AI subsumes products.

Most companies seem to still be in denial about it, and hope that if they add some more AI into their product, or do it just right, it will make sense. But it won't. AI is destined to sit on the outside, and products to be reduced into a bag of tools for AI to call.

Taking away write access from AI tools outside their contractual control is an expected knee-jerk reaction, but it'll probably just hasten the product's slide into irrelevancy by ceding ground to competition (that will ultimately share the same fate, too, but is still in denial about it).

miguel-munizabout 1 hour ago
I imagine every CEO breaks out in night sweats thinking of the Chegg stock chart. I don't envy them, these are hard waters to navigate and many of us are still blind as to where we are going. Seems like the new moat is just the data each company holds, I guess they're holding onto it for dear life
amoorthyabout 1 hour ago
This is the crux of the issue. I think for infrequent use cases (question/answer) an MCP with tool-calls to some product makes sense.

But for frequent use cases - something you do daily or weekly perhaps - then a native interface still has merit. i.e. I don't think AI subsumes the product in this case.

cellularmitosisabout 3 hours ago
I found figma’s remote MCP to be a poor fit for iOS development (it sets tokens on fire and gives Claude the details as React+Tailwind) and got much better results by having Claude build a set of “lens” tools around their REST API (“give me all of the fonts”, “give me the layout dimensions”, “give me the colors”, etc).

The key to making it token efficient was allowing Claude to invent its own plaintext markup format for the lens output.

btownabout 3 hours ago
Is this the API surface you're referring to?

https://developers.figma.com/docs/rest-api/file-endpoints/#g...

https://developers.figma.com/docs/rest-api/file-node-types/

Seems read-only, which means we're stuck with the MCP for updating Figma files... unless you've found a workaround there too?

guluarteabout 2 hours ago
last time i used figma you also need to pay a dev seat PER team to use the MCP
miguel-munizabout 1 hour ago
I wasn't aware of this and went to look it up to see if it's true. Then I read that the MCP is only free for a limited time and in the future they're going to start charging based on usage [1]. That's crazy

[1] https://help.figma.com/hc/en-us/articles/32132100833559-Guid...

JimDabellabout 3 hours ago
OpenCode seems to have been given the run-around as well:

> on the figma mcp, we've had an email thread going on for 8 months trying to get it setup in opencode

> they seem very concerned with the labs competing with them

> finally got unblocked after i sent this email and it'll be rolled out in a week or so

The email:

> looking through the legal stuff the amount of things in there seems pretty crazy

> this is just an mcp server, there are thousands of them. we're not going to treat figma like its special

> we've been talking about this for this entire year, i don't think this makes much sense and i don't want my team burning more time on this

> once again, for a simple mcp server

— https://www.threads.com/@thdxr/post/Dd7LN-ylLQW

thefourthchime22 minutes ago
Funny timing. Just yesterday I threw Opus 5.5 at excalidraw.com and told it to diagram the architecture of the software I'm working on.

It did an amazing job.

ig0r0about 3 hours ago
I like how Pi released an updated with a new oauth client name field for mcp where I just wrote Codex and Figma mcp works now.
SkyPuncherabout 3 hours ago
I do security review for my company. I suspect this is a means of containing OAuth redirect vulnerabilities. We basically needed to do the same thing with our MCP server.

The security problem is two fold: (1) companies want control over where their data goes. Figma allowing any MCP creates problems (2) open redirects can create phishing issues. If your using Pi, you’re probably thinking of this. Most users aren’t.

For us, we decided to do an allowlist pattern because it was a reasonable tradeoff. The solution is allowing per-tenant client configuration, but that comes with its own set of issues (dev time, support, maintenance, etc). When nearly all of the money is flowing through a handful of well-known MCPs there’s little reason to out effort into supporting every MCP.

dbuxtonabout 1 hour ago
It’s not a very good way of doing that though. Rather than constraining the callback url to pre-registered partners, you just need to enter “Claude Code” as your product name and it lets you in.
htrp27 minutes ago
you're not being sarcastic here?
hparadizabout 2 hours ago
We need OIDC tokens generated at the SSO placed on the dev environment upon user authentication and then have those OIDCs reusable among multiple mcps. People don't wanna login to 10 different mcps every morning.

Read the full thread on Hacker News →

Related stories