FigmaSAFE
ModelContextProtocol for Figma's REST API
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/@MatthewDailey/figma-mcp)
A ModelContextProtocol server that enables AI assistants to interact with Figma files. This server provides tools for viewing, commenting, and analyzing Figma designs directly through the ModelContextProtocol.
Features
- Add a Figma file to your chat with Claude by providing the url
- Read and post comments on Figma files
Setup with Claude
Installing via Smithery
To install Figma MCP Server for Claude Desktop automatically via Smithery:
npx -y @smithery/cli install @MatthewDailey/figma-mcp --client claude
- Download and install Claude desktop app from claude.ai/download
- Get a Figma API Key (figma.com -> click your name top left -> settings -> Security). Grant
File contentandCommentsscopes.
- Configure Claude to use the Figma MCP server. If this is your first MCP server, run the following in terminal.
echo '{
"mcpServers": {
"figma-mcp": {
"command": "npx",
"args": ["figma-mcp"],
"env": {
"FIGMA_API_KEY": ""
}
}
}
}' > ~/Library/Application\ Support/Claude/claude_desktop_config.jsonIf it's not, copy the figma-mcp block to your claude_desktop_config.json
- Restart Claude Desktop.
- Look for the hammer icon with the number of available tools in Claude's interface to confirm the server is running.
Example usage
Start a new chat with claude desktop and paste the following
What's in this figma file? https://www.figma.com/design/MLkM98c1s4A9o9CMnHEyEC
Demo of a more realistic usage
https://www.loom.com/share/0e759622e05e4ab1819325bcf6128945?sid=bcf6125b-b5de-4098-bf81-baff157e3dc3
Development Setup
Running with Inspector
For development and debugging purposes, y
73354fa605d5OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add figma-mcp --env FIGMA_API_KEY=${FIGMA_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"figma-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"FIGMA_API_KEY": "${FIGMA_API_KEY}"
}
}
}
}Exposed tools (5)
3 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add_figma_file | write | Add a Figma file to your context |
post_comment | write | Post a comment on a node in a Figma file |
read_comments | read | Get all comments on a Figma file |
reply_to_comment | read | Reply to an existing comment in a Figma file |
view_node | read | Get a thumbnail for a specific node in a Figma file |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
@modelcontextprotocol/sdk, axios, @types/node, esbuild, prettier, shx, typescript
Gates applied: no_behavioural_pass, no_license.
73354fa605d5full audit observations/trust-audit/mcp-server/matthewdailey__figma.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 73354fa605d5 | SAFE | B | 89 | first audit |
Questions
What is the Figma MCP server?
ModelContextProtocol for Figma's REST API
What tools does Figma expose?
5 in total: 3 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Figma safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Figma need?
It reads FIGMA_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Figma run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as figma-mcp at 0.1.4.
How current is this page?
The grade is for one exact copy of the source (73354fa605d5), read on 2026-10-06. The repository is watched and re-audited when it changes.