FigmaCAUTION
Model Context Protocol server implementation for Figma API
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that provides integration with Figma's API through Claude and other MCP-compatible clients. Currently supports read-only access to Figma files and projects, with server-side architecture capable of supporting more advanced design token and theme management features (pending Figma API enhancements or plugin development).
Project Status
Current Progress
- ✅ Core Implementation: Successfully built a TypeScript server following the Model Context Protocol (MCP)
- ✅ Claude Desktop Integration: Tested and functional with Claude Desktop
- ✅ Read Operations: Working
get-fileandlist-filestools for Figma file access - ✅ Server Architecture: Caching system, error handling, and stats monitoring implemented
- ✅ Transport Protocols: Both stdio and SSE transport mechanisms supported
Potential Full Functionality
The server has been designed with code to support these features (currently limited by API restrictions):
- Variable Management: Create, read, update, and delete design tokens (variables)
- Reference Handling: Create and validate relationships between tokens
- Theme Management: Create themes with multiple modes (e.g., light/dark)
- Dependency Analysis: Detect and prevent circular references
- Batch Operations: Perform bulk actions on variables and themes
With Figma plugin development or expanded API access, these features could be fully enabled.
Features
- 🔑 Secure authentication with Figma API
- 📁 File operations (read, list)
- 🎨 Design system management
- Variable creation and management
- Theme creation and configuration
- Reference handling and validation
- 🚀 Performance optimized
- LRU caching
- Rate limit handling
- Connection pooling
- 📊 Comprehensive monitoring
- Health checks
- Usage statistics
- Error tracking
Prerequisites
- Node.js 18.x or higher
- Figma access token with appropriate permissions
- Basic understandi
afeb891d4cc5OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add figma-mcp-server --env FIGMA_ACCESS_TOKEN=${FIGMA_ACCESS_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"figma-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"FIGMA_ACCESS_TOKEN": "${FIGMA_ACCESS_TOKEN}"
}
}
}
}Exposed tools (11)
6 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create_reference | write | Create a reference between variables |
create_theme | write | Create a theme with variable mode configurations |
create_variables | write | Create variables in a Figma file |
delete_variables | destructive | Delete variables from a Figma file |
get-file | read | Get details of a Figma file |
get_file_details | read | Get detailed information about a specific Figma file |
list-files | read | List files in a Figma project |
list_components | read | List all components in a Figma file |
search_files | read | Search for Figma files by name or keywords |
update_variables | write | Update existing variables in a Figma file |
validate_references | read | Check for circular references and validate dependencies |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
.DS_Store
.DS_Store
delete_variables
.DS_Store
.DS_Store
@modelcontextprotocol/sdk, @types/debug, axios, debug, dotenv, lru-cache, node-fetch, zod
Gates applied: no_behavioural_pass, no_license.
afeb891d4cc5full audit observations/trust-audit/mcp-server/timholden__figma-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | afeb891d4cc5 | CAUTION | B | 86 | first audit |
Questions
What is the Figma MCP server?
Model Context Protocol server implementation for Figma API
What tools does Figma expose?
11 in total: 6 read-only, 4 that write, and 1 that can delete or overwrite (delete_variables). Every one is listed on this page with its risk.
Is Figma safe to connect to an agent?
With care. The audit graded it B (86/100) and found 7 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Figma need?
It reads FIGMA_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Figma run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as figma-mcp-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (afeb891d4cc5), read on 2026-10-07. The repository is watched and re-audited when it changes.