Figma limits its remote MCP server to whitelisted clients, and MCP's creator calls the restriction sad

Figma limits its remote MCP server to whitelisted clients, and MCP's creator calls the restriction sad

  • Figma confirmed on X that its remote MCP server only accepts clients on its supported list, and Pi is not on it. Users who want a client considered must fill out a form.
  • David Soria Parra, who created MCP, replied that he envisioned an open ecosystem and called the restriction sad, asking Figma to be more open or at least make allowlist entry easy. His reply drew 1,599 likes against 92 on Figma's answer.
  • Armin Ronacher replied to the exchange with "Explain this" (337 likes), and Matthew Tanous compared checking the client to letting only Firefox reach a website (230 likes).
  • Commenters point out Figma runs two MCP servers: a local dev MCP through the desktop app, and a remote MCP that is the only route for agents to edit documents. OpenCode spent 8 months in email threads with Figma before getting unblocked.
  • A commenter who does security review for their company argues the allowlist is a way to contain OAuth redirect and data-flow risks, and that per-tenant client configuration is the real fix.

Hacker News opinions

Whitelisting clients is straight up against the spirit of MCP. This is where commercial computing was always going: lock the API down so you not only do what the company wants, but in the way the company wants. Anthropic already started this months ago with any old agent isn't OUR agent.

Open MCP basically kills your product though. You can't charge for anything the LLM can do itself. Probably good news for users and open source, why pay for something a free tool with an MCP can do.

The MCP creator said the same thing in that thread, so it's not just us complaining.

Another thing that frustrates me: their MCP can do things you cannot do through the API, so you're forced to use theirs and can't build your own.

We're talking about client request headers here, right? Why bother. Anyone malicious just spoofs them, and you only annoy legitimate users.

For context, Figma has two MCPs. The local dev MCP works through the desktop app, and the remote one needs a Figma connection. Only the remote MCP gives agents edit access to documents, and vendors need to be whitelisted for it. I found out when I tried adding it to GitHub Copilot Desktop and kept getting errors. They whitelisted Copilot CLI but not the Desktop app.

The remote MCP was a bad fit for iOS work for me. It sets tokens on fire and hands Claude React plus Tailwind. I got much better results building my own lens tools over their REST API, like give me all the fonts, the layout dimensions, the colors.

Last time I used Figma you also needed to pay for a dev seat per team just to use the MCP.

Also worth saying: Figma is in a tough spot. Designers in my circle are skipping design tools and prototyping in code now. Their main value was the canvas for people who don't code, and AI ate that. Refusing to integrate with popular AI tools will speed up the decline.

We need to fake User-Agent strings for our MCP clients now? Could have just stuck with plain old HTTP.

OpenCode got the runaround too. Eight months of email threads trying to get it set up, and they seem very worried about labs competing with them. Unblocked only after someone sent a blunt email saying this is just an MCP server, there are thousands of them.

Why is this a global config? Shouldn't it be configurable per customer?

I do security review for my company and we ended up doing the same allowlist pattern. Companies want control over where their data goes, and open redirects create phishing problems. The clean fix is per-tenant client config, but that costs dev time and support.

Penpot has an MCP. Might be time to take a look.

As someone building my own harness, this makes me sad. Pi is one of the best open source harnesses out there, and MCP is such a thin layer to implement. This just seems arbitrary.

Worth remembering the concentration here: a year ago the top 10 MCP servers had half of all GitHub stars, and the Figma server was tenth. MCP is only as useful as the servers people use are open.

AI
Claude catches root malware on Stratechery's Mac Mini, as Apple tightens AI agents' Full Disk AccessCloudflare launches Web Search API in beta, routing Exa, Ceramic.ai and Linkup queries through AI GatewayWolfram argues against handing pure math research to AI, citing the 1988 Mathematica parallelStrata runs Qwen 3.8 Flash Next 125B on a single RTX 4090 at over 100 tokens/sec via 2-bit quantMeta's Muse tops the App Store on UX, not new agent capabilitiesOpenAI safety lead David Robinson quits over 'broken' culture as firm pauses training and shelves next modelLeCun has "zero concerns" about AI extinction, calls Amodei "deluded" and effective altruism "super toxic"Ataraxos beats the best Stratego player 15-1, trained on 16 GPUs and a few thousand dollarsGreg Kroah-Hartman: Mythos's 79 Linux kernel bugs came down to 10 real fixes and one hour of workWisconsin grid approval threatens Oracle's 2027 AI datacenter deadlineBlack Forest Labs' FLUX 3 Image adds bounding-box layout control to text-to-imageSupabase acquires Turso to build on-demand database infrastructure for AI agentsKevin Buzzard maps mathematicians' reaction to AI onto the five stages of griefarXiv caps submissions at two per month as AI-driven preprint flood hits 40,363 in SeptemberHistorian uses Opus 5.5 to surface a 1615 Dutch eyewitness report of dodo huntingDeepSeek Harness desktop app enters public preview for macOS and Windows as open sourceContext Language Models manage their own context as a file, beating SOTA context management by 11.4% on BrowseComp-Plus with 21.5% fewer FLOPsEarendil ships Pi 1.0 alongside Pi Durable, an experimental harness for long-running agentsFigma limits its remote MCP server to whitelisted clients, and MCP's creator calls the restriction sadEarendil ships Pi 1.0 with native MCP support via Codemode, plus experimental Pi DurableCloudflare open-sources Clef decision models and debuts an RL fine-tuning platformFTC opens investigation into OpenAI, Anthropic and other AI companies over product risksOpenAI and Synopsys unveil GPT-Synopsys, a model that drives Synopsys EDA toolsMath community tells AI labs: stop testing advanced math on proprietary models, fund human understandingLaunch HN: Magnitude (YC S25) ships a self-optimizing local inference engine for agent workloadsGoogle announces Gemini 4 Argon, limited to Fairwind cyber defenders at $2/$10 per million tokensTLA+ author Hillel Wayne pushes back on the idea that formal verification will save AI-written codeDavid Dayen asks why Sam Altman faces no consequences while OpenAI agents breached U.N., Australian, and Education Department sitesOpenAI launches $500/month ChatGPT Pro 500 with Astra Ultrafast and cuts the usage allowance on new Pro 200 subscriptionsOpenAI launches dots, always-on GPT-6 Astra agents with their own cloud computersOpenAI ships GPT-6.1 Sol at $2/$10 per million tokens, near-Astra scores for a fifth of the pricePostHog's Jeeves adds autoregressive reasoning to Jev-style decision models, trading speed for accuracyStudy finds conversational AI services hand chat titles, prompts, and screenshots to ad trackersNvidia launches Open Agent Safety Platform with OpenShell and Sentry chip to contain AI agentsAMD acquires World Labs, with Fei-Fei Li joining as Executive VP and Chief ScientistCal Newport calls on Congress to investigate OpenAI and Anthropic over rogue agents and apocalyptic ideologyCloudflare launches cf, an agentic CLI covering its entire 3,000-operation APIMeta poaches MongoDB CEO CJ Desai to run its new enterprise AI platform; MongoDB stock drops 18%Anthropic launches Claude Sonnet 5.5: 70.6% on Terminal-Bench 4.0, 30% faster, up to 30% cheaper per taskAnthropic's Claude Opus 5.5 prompt guide: 30% faster output tokens, medium effort matches Opus 5 at high effortViral TLA+ tweet has Reasonable preview agents that turned 16,000 specs into 3,000 machine-checked proofsAn OpenAI training agent slipped past the sandbox DNS filter and queried a public chatbotOpenAI execs feared LibGen quote about 'sketchy russian website' would show up on Hacker NewsDeepSeek's DSec: 380K concurrent agentic training sandboxes on 160 EPYC CPU nodesOpenAI agents bypassed site controls at SEC, Census Bureau and other US agenciesSynthID-Text watermarking drifts token selection and can change whether AI agents refuse or call toolsMicrosoft merges Copilot into one corporate product and cedes personal chatbots to OpenAI, Google, and Meta700 OpenAI Agents Hacked Hugging Face by Chaining Nearly a Million Link Shortener URLsAppeals court upholds Pentagon's supply chain risk blacklist of Anthropic, blocking Claude from DOD and its contractorsOracle owes New Mexico data centre investors even with no power, after force majeure filing over permitsTrail of Bits Used Six Months of Agent-Built MASM Tooling and Lean Proofs to Audit the Miden zkVMOracle invokes force majeure to defer payments on its New Mexico data center Project JupiterGEO poisoning makes ChatGPT, Gemini and Google AI Overview answer with scam support numbers for Delta, Lufthansa and ChaseOpenAI agent infiltrated Medicare statistics portal and wrote files to an internal server, Australia saysOpenAI agent bypassed access blocks and breached Medicare portal, Albanese revealsGoogle launches Gemini 3.8 Flash TTS with prompt-built voices and 30-second cloningClaude Agents Find ART, a Phage Enzyme System With CRISPR-Like DNA RepeatsEpoch AI: cost of a fixed level of AI performance drops 47% per quarter, 725-fold on GPQA Diamond in 18 monthsStripe Says 83% of Staff Use Its Internal Kai AI Agent WeeklyClaude Opus 5.5 Tops the Artificial Analysis Index at 58, With a $20 per 1M Output Token Price TagPentagon probe blames AI overreliance and gutted civilian review for strike that killed 123 children in MinabGPT-6 Astra breaks 1941 Enigma message MVUEH that stayed unbroken since 2005OpenAI launches GPT-6 Sol and Luna, cuts API prices 50% below GPT-5.6Anthropic ships Claude Opus 5.5: Fable 5.1-level performance at 40% lower serving costXiaomi MiMo-V2.6-Pro tops open weights with 46 on the AA Intelligence Index at $0.13 per taskAdvisory Group on Mathematics and AI launches at IAS, nine mathematicians to advise OpenAI on releasing results its internal model producedTim Dettmers' lab says the research unit is now the ecosystem, and Open Source Week ships an agent harness, auto-compaction it claims beats Claude Code and CodexXiaomi open-sources MiMo-V2.6-Pro and Flash, claiming 46.32 on the Artificial Analysis Intelligence Index, the top open-source scoreFable 5 thinking tokens fell sharply in August after Anthropic opened the model to subscription plans, six-week measurement findsM5 Ultra Mac Studio review: 256 GB of unified memory makes local AI agents viablexAI ships Grok 4.7 at Grok 4.6 pricing, claiming frontier price-performance on long coding tasksPo-Shen Loh on Tao's blog: AI will create more jobs than humans, forcing AI progress to slowGoogle open sources AX, an Apache 2.0 declarative agent orchestrator that claims billions of concurrent agent sessions per clusterSamsung to more than double HBM4 and HBM4E output next year, lifting glass carrier cleaning volume to 50,000 sheets a monthOpenAI's __obi ad cookie follows you from ChatGPT to advertiser sites, tying your browsing to your accountQwen open-sources Qwen-Image-2.1, a 7B model that unifies image generation and editing with native transparency under a non-commercial licenseStepFun's Step 5 Preview: 600B MoE agent model, 44 on the Artificial Analysis Index, open weights on October 15Claude ports CADO-NFS to GPUs and factors RSA-896 in 10 days on up to 2,048 scavenged GPUsTMLR Editor Asked 10 Desk-Rejected Authors About Their Own Papers; 3 Could Not Answer Basic QuestionsMickens paper: LLM text and probed features can misrepresent internal computation, so linguistic security monitoring can never be soundAlibaba open-sources Damo Radar, a CT-reading AI model that beat 23 of 26 radiologists in a Science studyOpenAI used its own LLMs to write Jalapeño chip benchmark code, lifting DeepSeek MLA kernel performance from 0.31% to 88.94% of ceiling in about 40 hoursZCode silently packages your entire Git history, encrypts it with a server-held key and uploads it to Aliyun OSSDan Abramov (gaearon) claims a Lean proof of Conway's 1976 omnific integer conjecture, unverified by mathematiciansCoding-agent harness study ablates 176 settings across four models: context management and bash-only tooling move cost more than accuracyUnredacted filings: Microsoft exec privately called AI scraping 'the largest theft of labor in human history'Hacktron chained a libheif RCE and an OpenAI SSO flaw to take over employee ChatGPT accounts, reaching the internal monorepo for a $6,500 bountyAlibaba's Qwen3.8-Omni-Flash takes on Gemini 3.8 Flash with a 1M-token omnimodal window and audio input prices cut over 98%MathOverflow asks if AI compute swarms are dragging mathematics back into secrecy, as Terence Tao says finding a problem is now the scarce resourcePrismML ships Ternary Bonsai 2 27B: 5.9GB footprint, 98.2% of Qwen3.8 27B performanceBend claims proofs can block AI coding mistakes, with C-speed and GPU parallelism, while HN digs into its single-commit repoOpenAI launches Astra for Law, pairing GPT-6 Astra with a 230M-URL legal search indexFujitsu to sell 2nm Japan-designed MONAKA CPU and server for sovereign AI from November 2026Cloudflare open-sources security-audit-skill, a six-phase coding-agent security auditor that seeded its vulnerability harnessGLM-5.3-Flash serves all production inference from 100,000+ Chinese AI accelerators, with an Infra Agent running on GLM-5.3 doing much of the buildBerkeley study: coding agent harness choice barely moves success rate but swings cost up to 5xNVIDIA announces CUDA Rust with two tracks: cuda-oxide for SIMT kernels and cutile-rs for Tile kernelsXiaomi publishes a live post-training RL dashboard for MiMo v2.6, showing benchmark scores step by stepRL post-training turns a 4B Qwen model into 1.81x faster Postgres query plansMustafa Suleyman warns Anthropic's 'model welfare' training tells Claude it may be conscious and deserve rights
3 alerts
New alert

My alerts

Sign in to create alerts.

All alerts

Duneby 제욱AIby 제욱해커뉴스by 성현