Figma Restricts Remote MCP Server Access to Whitelisted Clients
Figma Implements Client Whitelisting for Remote MCP Server
Figma has restricted access to its remote Model Context Protocol (MCP) server, allowing only a specific list of supported clients to connect. This restriction was confirmed by Figma staff in response to users reporting that the Pi AI client was unable to access the server. Users wishing to have a client added to the supported list must now submit a request via a formal application form.
Remote vs. Local MCP Implementations
Figma maintains two distinct MCP configurations with different access levels:
- Local "Dev" MCP: Operates through the Figma Desktop app and is generally more accessible.
- Remote MCP: Requires a direct connection to Figma's servers. This is the only implementation that grants AI agents edit access to Figma documents.
Because the Remote MCP provides write capabilities, Figma has restricted its use to a whitelist of approved vendors. This has led to friction for developers using alternative harnesses such as Pi, OpenCode, and various custom-built MCP clients.
Community Response and Ecosystem Impact
The decision to whitelist clients has drawn significant criticism from the developer community, particularly from those who view the Model Context Protocol as a foundation for an open ecosystem.
Arguments Against Whitelisting
Critics argue that restricting access based on the client harness is arbitrary and counter-productive. Some community members have compared the restriction to a website blocking all browsers except Firefox, noting that malicious actors can easily spoof user-agent headers to bypass such filters.
"I think in spirit, when I created MCP, I envisioned an open ecosystem. That to me feels core. Seeing restrictions like this is sad..."
Potential Justifications
Some security professionals suggest that whitelisting may be a strategic move to mitigate specific technical risks, such as:
- OAuth Redirect Vulnerabilities: Controlling the list of approved clients can help prevent open redirect phishing attacks.
- Data Governance: Companies often require strict control over which third-party entities can access and move their proprietary design data.
Workarounds and Alternatives
In response to these restrictions, users and developers have sought several alternatives to maintain AI-driven design workflows:
- Header Spoofing: Some users report bypassing the whitelist by modifying their client's OAuth client name or user-agent headers to mimic approved clients like "Codex" or "Claude Code."
- Unofficial Protocols: Third-party developers have created unofficial implementations, such as the "figma-kiwi-protocol," which reverse-engineers Figma's internal protocols to provide read/write access without requiring an official MCP whitelist.
- Alternative Tools: Users have mentioned migrating to competitors like Penpot or Paper, which reportedly offer more open access for local agents to edit documents.
Usage Limitations
Beyond client whitelisting, users have noted significant rate limits on the official MCP. Standard accounts are reportedly limited to 6 accesses per day, while paid developer accounts are limited to 200 per day, which some users find insufficient for professional AI-assisted workflows.
Sources
Related
- Project
- Project
- Project
- Project