Figma limits its remote MCP server to whitelisted clients, and MCP's creator calls the restriction sad
- Figma confirmed on X that its remote MCP server only accepts clients on its supported list, and Pi is not on it. Users who want a client considered must fill out a form.
- David Soria Parra, who created MCP, replied that he envisioned an open ecosystem and called the restriction sad, asking Figma to be more open or at least make allowlist entry easy. His reply drew 1,599 likes against 92 on Figma's answer.
- Armin Ronacher replied to the exchange with "Explain this" (337 likes), and Matthew Tanous compared checking the client to letting only Firefox reach a website (230 likes).
- Commenters point out Figma runs two MCP servers: a local dev MCP through the desktop app, and a remote MCP that is the only route for agents to edit documents. OpenCode spent 8 months in email threads with Figma before getting unblocked.
- A commenter who does security review for their company argues the allowlist is a way to contain OAuth redirect and data-flow risks, and that per-tenant client configuration is the real fix.
Hacker News opinions
Whitelisting clients is straight up against the spirit of MCP. This is where commercial computing was always going: lock the API down so you not only do what the company wants, but in the way the company wants. Anthropic already started this months ago with any old agent isn't OUR agent.
Open MCP basically kills your product though. You can't charge for anything the LLM can do itself. Probably good news for users and open source, why pay for something a free tool with an MCP can do.
The MCP creator said the same thing in that thread, so it's not just us complaining.
Another thing that frustrates me: their MCP can do things you cannot do through the API, so you're forced to use theirs and can't build your own.
We're talking about client request headers here, right? Why bother. Anyone malicious just spoofs them, and you only annoy legitimate users.
For context, Figma has two MCPs. The local dev MCP works through the desktop app, and the remote one needs a Figma connection. Only the remote MCP gives agents edit access to documents, and vendors need to be whitelisted for it. I found out when I tried adding it to GitHub Copilot Desktop and kept getting errors. They whitelisted Copilot CLI but not the Desktop app.
The remote MCP was a bad fit for iOS work for me. It sets tokens on fire and hands Claude React plus Tailwind. I got much better results building my own lens tools over their REST API, like give me all the fonts, the layout dimensions, the colors.
Last time I used Figma you also needed to pay for a dev seat per team just to use the MCP.
Also worth saying: Figma is in a tough spot. Designers in my circle are skipping design tools and prototyping in code now. Their main value was the canvas for people who don't code, and AI ate that. Refusing to integrate with popular AI tools will speed up the decline.
We need to fake User-Agent strings for our MCP clients now? Could have just stuck with plain old HTTP.
OpenCode got the runaround too. Eight months of email threads trying to get it set up, and they seem very worried about labs competing with them. Unblocked only after someone sent a blunt email saying this is just an MCP server, there are thousands of them.
Why is this a global config? Shouldn't it be configurable per customer?
I do security review for my company and we ended up doing the same allowlist pattern. Companies want control over where their data goes, and open redirects create phishing problems. The clean fix is per-tenant client config, but that costs dev time and support.
Penpot has an MCP. Might be time to take a look.
As someone building my own harness, this makes me sad. Pi is one of the best open source harnesses out there, and MCP is such a thin layer to implement. This just seems arbitrary.
Worth remembering the concentration here: a year ago the top 10 MCP servers had half of all GitHub stars, and the Figma server was tenth. MCP is only as useful as the servers people use are open.