For context: Figma has two MCPs. The local "dev" MCP that works through the Desktop app, and the remote MCP that requires a connection to Figma. Companies need to be whitelisted to use the remote MCP, which is the only one that allows agents edit access to Figma documents.
I only found out about Figma's limitation when I was trying to add the remote MCP server to GitHub Copilot Desktop and kept running into errors. Turns out they whitelisted GitHub Copilot CLI but not the Desktop app and had put a pause on enabling any more vendors. Eventually someone (not sure which side) got it working.
Kind of strange to limit edit access only to the Remote MCP when their competitors like Pen[1] and Paper[2] allow any local agent to edit.
As someone making my own harness, this makes me sad. Pi is a big inspiration and one of the best open source harnesses, but there are many others. dsh, opencode, hermes, etc. MCP is such a thin layer to implement for any harness, this just seems arbitrary.
Funny enough, I saw some tweet earlier today about their company trying to get past the legal hurdles with getting figma mcp to work and ended up bluntly giving up. Wonder if this is related.
This was always a possibility, when my team dug into the concentration of MCP server usage a year ago we found that the top 10 servers had half of all GitHub stars (the Figma server was in 10th at the time).
We're talking about client request headers, right? Why even bother with such a thing? Malicious users will just spoof those, you're only going to annoy legitimate users.
> Open MCP basically kills your product in my opinion, you can't charge for any feature the LLM can do itself.
For products for which this is true resorting to whitelisting clients simply accelerates your obsolescence by creating a temporary market for products that are MCP, and open agent, friendly.
Welcome to where this was inevitably all going to go eventually. The entirety of commercial personal computing is going this direction: locking down APIs to make sure you’re not only doing what the company wants, but also the way the company wants. Mobile phones provide countless examples already; applying those examples to LLM world isn’t far fetched - and Anthropic already started down the road of “any old agent isn’t OUR agent” months ago.
I think we'll see more of this. Of course SAAS companies like Figma, and soon Adobe and ... will see that their tools are still useful. And they are useful to LLMs like they are useful to humans.
The obvious play to "extract value" from that is to restrict access to bots and offer LLM integration themselves, for a fee.
Soon they might require a vendor specific api key to access it and that requires support from the big players (anthropic,openai). They’re laying down the “framework” now.
Another thing they do that I find equally frustrating is their MCP can do things you cannot do via API so you are forced to use theirs and cannot implement your own
OpenCode seems to have been given the run-around as well:
> on the figma mcp, we've had an email thread going on for 8 months trying to get it setup in opencode
> they seem very concerned with the labs competing with them
> finally got unblocked after i sent this email and it'll be rolled out in a week or so
The email:
> looking through the legal stuff the amount of things in there seems pretty crazy
> this is just an mcp server, there are thousands of them. we're not going to treat figma like its special
> we've been talking about this for this entire year, i don't think this makes much sense and i don't want my team burning more time on this
> once again, for a simple mcp server
— https://x.com/GayaniFigma/status/2105295629941350454
For context: Figma has two MCPs. The local "dev" MCP that works through the Desktop app, and the remote MCP that requires a connection to Figma. Companies need to be whitelisted to use the remote MCP, which is the only one that allows agents edit access to Figma documents.
I only found out about Figma's limitation when I was trying to add the remote MCP server to GitHub Copilot Desktop and kept running into errors. Turns out they whitelisted GitHub Copilot CLI but not the Desktop app and had put a pause on enabling any more vendors. Eventually someone (not sure which side) got it working.
Kind of strange to limit edit access only to the Remote MCP when their competitors like Pen[1] and Paper[2] allow any local agent to edit.
[1] https://www.pen.dev/
[2] https://paper.design/
As someone making my own harness, this makes me sad. Pi is a big inspiration and one of the best open source harnesses, but there are many others. dsh, opencode, hermes, etc. MCP is such a thin layer to implement for any harness, this just seems arbitrary.
Funny enough, I saw some tweet earlier today about their company trying to get past the legal hurdles with getting figma mcp to work and ended up bluntly giving up. Wonder if this is related.
https://nitter.meowing.monster/GayaniFigma/status/2105295629...
Penpot has an mcp… might be time to take a look.
This was always a possibility, when my team dug into the concentration of MCP server usage a year ago we found that the top 10 servers had half of all GitHub stars (the Figma server was in 10th at the time).
https://www.oreilly.com/radar/mcp-in-practice/
MCP is only as useful as the servers people use are open.
I've seen other apps do this as well e.g. Cal.com
That is very old, I use a figma CLI patched to look like Claude code so I can use it for everything
Allow-listed would be a more accurate and more inclusive term.
We're talking about client request headers, right? Why even bother with such a thing? Malicious users will just spoof those, you're only going to annoy legitimate users.
Frankly, “whitelisting” clients is against the spirit of MCP.
Spam is against the spirit of email.
MCP creator said the same thing: https://twitter.com/dsp_/status/2105316536852320279
Open MCP basically kills your product in my opinion, you can't charge for any feature the LLM can do itself.
It's probably good news for users and open source though, why would you pay for something if a free tool with an MCP can do it.
> Open MCP basically kills your product in my opinion, you can't charge for any feature the LLM can do itself.
For products for which this is true resorting to whitelisting clients simply accelerates your obsolescence by creating a temporary market for products that are MCP, and open agent, friendly.
Welcome to where this was inevitably all going to go eventually. The entirety of commercial personal computing is going this direction: locking down APIs to make sure you’re not only doing what the company wants, but also the way the company wants. Mobile phones provide countless examples already; applying those examples to LLM world isn’t far fetched - and Anthropic already started down the road of “any old agent isn’t OUR agent” months ago.
I think we'll see more of this. Of course SAAS companies like Figma, and soon Adobe and ... will see that their tools are still useful. And they are useful to LLMs like they are useful to humans.
The obvious play to "extract value" from that is to restrict access to bots and offer LLM integration themselves, for a fee.
How does restricting the MCP ""user agent"" to only claude and codex and whatever enable Figma to extract value?
Soon they might require a vendor specific api key to access it and that requires support from the big players (anthropic,openai). They’re laying down the “framework” now.
Another thing they do that I find equally frustrating is their MCP can do things you cannot do via API so you are forced to use theirs and cannot implement your own
We need to fake User-Agent now for our MCP clients? Could have just sticked to plain old HTTP then ;)