Atlas / MCP servers / gethopp / Figma Bridge

Figma BridgeSAFE

mcp/gethopp/figma-bridge-2

Figma Plugin & MCP server to bypass API limits

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
40 15r · 22w · 3d
Transport
stdio
License
MIT
Stars
689
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://gethopp.app)

  • Demo
  • Quick Start
  • Available Tools
  • Local development
  • Structure
  • How it works
[!NOTE] Requires the Figma desktop app (macOS/Windows). The browser version of Figma does not support importing development plugins.

While other amazing Figma MCP servers like Figma-Context-MCP exist, one issues is the API limiting for free users.

The limit for free accounts is 6 requests per month, yes per month.

Figma MCP Bridge is a solution to this problem. It is a plugin + MCP server that streams live Figma document data to AI tools without hitting Figma API rate limits, so its Figma MCP for the rest of us ✊

It supports multiple Figma files connected simultaneously; open the plugin in each file and your AI agent can query any of them by fileKey. Single-file setups work exactly as before with no changes required.

It also includes a small, opt-in set of write tools for safe agent-driven edits — see Editing Notes below.

Demo

Watch a demo of building a UI in Cursor with Figma MCP Bridge

[](https://youtu.be/ouygIhFBx0g)

Quick Start

1. Add the MCP server to your favourite AI tool

Add the following to your AI tool's MCP configuration (e.g. Cursor, Windsurf, Claude Desktop):

{
"figma-bridge": {
"command": "npx",
"args": ["-y", "@gethopp/figma-mcp-bridge"]
}
}

That's it — no binaries to download or install.

2. Add the Figma plugin

Downl

Read from source at commit 5a3d1327257dOBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add figma-mcp-bridge -- npx -y @gethopp/[email protected]
claude-desktop
{
  "mcpServers": {
    "figma-mcp-bridge": {
      "command": "npx",
      "args": [
        "-y",
        "@gethopp/[email protected]"
      ]
    }
  }
}
03

Exposed tools (40)

15 read · 22 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
apply_animation_stylewriteApply a preset animation style to a node (Motion API beta). When multiple files are connected, specify fileKey.
apply_manual_keyframe_trackwriteApplies or replaces the manual Motion keyframe track for a property, paint, or effect field on a node. When multiple files are connected, specify fileKey.
create_framewriteCreate a new frame, optionally inside a specified parent. You can set name, size, position, and a solid fill. When multiple files are connected, specify fileKey.
create_imagewriteCreate an image-backed rectangle from a local file path, remote URL, or data URI. You can set its parent, position, size, corner radius, and fit mode. When multiple files are connected, specify fileKey.
create_pagewriteCreate a new page in the Figma document, optionally naming it and switching the editor to it. Returns the new page
create_shapewriteCreate a rectangle, ellipse, or line, optionally inside a specified parent. You can set its size, position, rotation, fill, and stroke. When multiple files are connected, specify fileKey.
create_textwriteCreate a new text node, optionally inside a specified parent. You can set its content, font, size, alignment, color, position, and bounds. When multiple files are connected, specify fileKey.
delete_nodesdestructiveDelete one or more nodes. This is destructive and requires confirm: true. Page and document nodes cannot be deleted through this tool. When multiple files are connected, specify fileKey.
duplicate_nodesreadDuplicate one or more nodes in place. The duplicates remain under the same parent as the originals. When multiple files are connected, specify fileKey.
get_design_contextreadGet the design context for the current selection or page. Returns a summarized tree structure optimized for understanding the current design context. When multiple files are connected, specify fileKey.
get_documentreadGet the current Figma page document tree. When multiple files are connected, specify fileKey.
get_layout_treereadRead absolute node transforms and layout bounds for a capture root. Separate screenshot calls are non-atomic.
get_metadatareadGet metadata about the current Figma document including file name, pages, and current page info. When multiple files are connected, specify fileKey.
get_motion_stylesreadList all available animation presets in Figma (Motion API beta). When multiple files are connected, specify fileKey.
get_nodereadGet a specific Figma node by ID. Accepts top-level IDs like
get_node_motionreadRead a node
get_screenshotreadExport a screenshot of the selected nodes or specific nodes by ID. Returns base64-encoded image data. When multiple files are connected, specify fileKey.
get_selectionreadGet the currently selected nodes in Figma. When multiple files are connected, specify fileKey.
get_stylesreadGet all local styles in the document. When multiple files are connected, specify fileKey.
get_variable_defsreadGet all local variable definitions including variable collections, modes, and variable values. Variables are Figma
group_nodesreadWrap a list of nodes in a new group. Nodes must share a common parent (or supply parentId explicitly). Returns the new group
import_html_layerswriteImport a DOM serialization (JSON produced by html-figma
list_filesreadList all currently connected Figma files. Returns fileKey and fileName for each. Use the fileKey to target a specific file in other tools.
remove_animation_styledestructiveRemove an applied animation style from a node (Motion API beta). If no animationStyleId is provided, removes all styles. When multiple files are connected, specify fileKey.
remove_manual_keyframe_trackdestructiveRemoves the manual Motion keyframe track for a property, paint, or effect field on a node. When multiple files are connected, specify fileKey.
reparent_nodeswriteMove one or more nodes into a different parent container. When multiple files are connected, specify fileKey.
save_screenshotswriteExport screenshots for multiple nodes and save them directly to the local filesystem. Returns metadata only (no base64). When multiple files are connected, specify fileKey.
scroll_and_zoom_into_viewreadScroll and zoom the Figma viewport so the given nodes are framed in view. Works in both design editor and Dev Mode.
set_auto_layoutwriteConfigure auto-layout on a frame: direction, gap, padding, alignment, sizing modes, wrap. Set layoutMode=
set_effectswriteReplace a node
set_gradient_fillwriteReplace a node
set_node_propertieswritePatch common node properties such as name, position, size, visibility, opacity, and corner radius. Only supported properties for the target node type may be changed. Use set_solid_fill or set_gradient_fill to change paints. When multiple files are connected, specify fileKey.
set_node_visibilitywriteShow or hide specific Figma nodes. Returns previous visibility for each node so you can restore them after. Useful for isolating a single layer before exporting: hide all siblings, export the frame, then restore visibility.
set_selectionwriteSet the current page selection to a list of node IDs. Pass an empty array to clear the selection. Works in both design editor and Dev Mode.
set_solid_fillwriteReplace a node
set_stroke_propertieswritePatch stroke geometry properties: weight, align, dash pattern, cap, join. Use set_solid_fill/set_gradient_fill with target=
set_text_contentwriteUpdate the contents of a single text node. The plugin loads the node
set_text_propertieswritePatch common text properties such as font family/style, size, alignment, auto-resize, line height, letter spacing, fill color, and bounds. When multiple files are connected, specify fileKey.
set_timeline_durationwriteSets the duration (in seconds) for a timeline. When multiple files are connected, specify fileKey.
ungroup_nodewriteUngroup a group or frame — its children move up to its parent and the wrapper is removed. Returns the IDs of the orphaned children in their new parent.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_nodes, remove_animation_style, remove_manual_keyframe_track
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
plugin/vite.config.ts:11
outDir: "../../dist",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
husky, lint-staged
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
plugin/package.json
react, react-dom, @figma/plugin-typings, @types/react, @types/react-dom, @vitejs/plugin-react, concurrently, typescript
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
server/package.json
@modelcontextprotocol/sdk, ws, zod, @types/node, @types/ws, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha 5a3d1327257dfull audit observations/trust-audit/mcp-server/gethopp__figma-bridge-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-305a3d1327257dSAFEB89first audit
06

Questions

What is the Figma Bridge MCP server?

Figma Plugin & MCP server to bypass API limits

What tools does Figma Bridge expose?

40 in total: 15 read-only, 22 that write, and 3 that can delete or overwrite (delete_nodes, remove_animation_style, remove_manual_keyframe_track). Every one is listed on this page with its risk.

Is Figma Bridge safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Figma Bridge need?

No credential environment variables were found in its source, so it appears to need none.

How does Figma Bridge run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @gethopp/figma-mcp-bridge at 0.1.1.

How current is this page?

The grade is for one exact copy of the source (5a3d1327257d), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement