> on the figma mcp, we've had an email thread going on for 8 months trying to get it setup in opencode
> they seem very concerned with the labs competing with them
> finally got unblocked after i sent this email and it'll be rolled out in a week or so
The email:
> looking through the legal stuff the amount of things in there seems pretty crazy
> this is just an mcp server, there are thousands of them. we're not going to treat figma like its special
> we've been talking about this for this entire year, i don't think this makes much sense and i don't want my team burning more time on this
> once again, for a simple mcp server
It's really silly that this was the only means of blocking access. I expected them to have, I don't know, some sort of cryptographic signature or something.
An additional JWT with a long expiry time would even work here, anything.
The security problem is two fold: (1) companies want control over where their data goes. Figma allowing any MCP creates problems (2) open redirects can create phishing issues. If your using Pi, you’re probably thinking of this. Most users aren’t.
For us, we decided to do an allowlist pattern because it was a reasonable tradeoff. The solution is allowing per-tenant client configuration, but that comes with its own set of issues (dev time, support, maintenance, etc). When nearly all of the money is flowing through a handful of well-known MCPs there’s little reason to out effort into supporting every MCP.
That's the age-old problem that's the root of this debacle, too. Both the companies and the users want control over a shared resource, and each side has a different opinion on where the border lies :).
(In practice, as a user, that's why my mind reads the phrase "OAuth redirect vulnerabilities" as a feature of a product, not a bug.)
I'm unfortunately inclined to think its the first because a reply as such from anybody who thought about this for even a minute would realize his reply has literally nothing to do with the original issue.
For my Figma needs, having Codex do computer use seems just as good as their mcp. I can tell it, “go download the assets for what I need and take a few screenshots for reference”.
I couldn't believe it when file annotations are only visible to users with design and dev seats. Like my PMs will never be able to read the annotations. I stopped using that feature entirely after that, and just stuck to pasting in FigJam sticky notes instead.
It did an amazing job.
I created an opensource unofficial mcp/skill/cli here git@github.com:allan-simon/figma-kiwi-protocol.git
Its based on a reverse engineering of the kiwi protocol and it works for read/write , comments etc. and it does not require anything except a cookie session ( I usually automate this part by having a isolated chrome with CDP activated)
I created sometimes ago because I had to work with some customers who didnt want to pay for a full seat for my account so the official mcp was not possible at all.
> Get started using the Slack MCP server by setting up a connection with an available partner
https://slack.com/help/articles/48855576908307-Guide-to-Mode...
https://www.oreilly.com/radar/mcp-in-practice/
MCP is only as useful as the servers people use are open.
Weird.
Better consumer choice, less companies stifling competition.
Tell your Congressperson! An easy way to frame it: why should I have to cross check Amazon or eBay or Walmart or w/e stupid janky frontend myself and find the best price/product? Why isn't it good for the economy if any agent harness can interface with such data as a consumer right?
The question is no different here. But most people don't know what figma is (it will probably not exist in 10 years anyway). However if we focus on the big abusers of platform economics, then the benefits we accrue from highlighting the tensions with consumers at those entities will simply flow downstream into the wider economy.
An economy that is more transparent is also a necessary precursor to robust UBI. When a company like Figma makes this move, the correct read should be they are buying into a playbook bent on depriving all of us of a more equitable future - one of the few optimistic possibilities for the highly contested future we are rapidly approaching.
It's probably good news for users and open source though, why would you pay for something if a free tool with an MCP can do it.
For products for which this is true resorting to whitelisting clients simply accelerates your obsolescence by creating a temporary market for products that are MCP, and open agent, friendly.
The obvious play to "extract value" from that is to restrict access to bots and offer LLM integration themselves, for a fee.
I only found out about Figma's limitation when I was trying to add the remote MCP server to GitHub Copilot Desktop and kept running into errors. Turns out they whitelisted GitHub Copilot CLI but not the Desktop app and had put a pause on enabling any more vendors. Eventually someone (not sure which side) got it working.
Kind of strange to limit edit access only to the Remote MCP when their competitors like Pen[1] and Paper[2] allow any local agent to edit.
[1] https://www.pen.dev/
[2] https://paper.design/
Figma's main value used to be in providing designers a canvas to iterate and explore ideas since the majority of designers did not code, but AI has completely changed that.
I fear Figma's reluctance to integrate with all the popular AI tools might actually accelerate their decline. AI provides so much value, that I would rather base my software purchasing decisions around what is compatible with my AI of choice rather than pick an AI that is compatible with Figma.
Code connect was supposed to bridge this gap, allowing users to define how Figma components should generate relevant code snippets, but it only worked with React and they had some janky string based templating language for everything else. And of course, it meant someone would have to go through the effort of creating mappings for every component in your system. It's like writing a component twice, the same pitfall we were trying to avoid in the first place.
Now people will just ask their AI to pull the frames from Figma through the remote MCP and have the AI implement it that way. But to that end, why not just have designers make a branch in the codebase and have them implement the UI? This is the question many of us have been asking ourselves lately.
They continue to iterate though. They've introduced Code Layers so real codebases can render on the canvas, but in infamous Figma fashion it only works with a limited set of React codebases. Figma Make (their Lovable, Bolt.new, Claude Design like product) can also pull in existing codebases, but again it is very limited in the types of code bases it can work on.
These limitations are all so exhuasting. It's just so much easier to use Claude Code or Codex to do what I need. At this point Figma is more of a secondary tool for when I need to document a prototype or want a canvas for exploration purposes.
The AI companies focused most their effort on writing software and continue to do so. Software, SaaS, and software engineers are the first to be disrupted.
> but AI has completely changed that.
Exactly. However, it is because AI is focused on solving writing software first which is the step to solving everything else.
I am 100% in agreement that companies that try to shut down access to agents will be replaced. It's just the future for a lot of work and workflows. In a way it's an opportunity for someone.
Neither of them, not yet. What will go away is the products currently used by these groups.
It's happening in software development, too. In the past 3 months, I used an IDE for maybe few hours total. 99% of my technical work is now easier and better done through agentic chat interface.
The way I have made peace with it in my mind is at the end of the day, I am the expert in UI/UX. There are many product teams I've joined that have operated without a designer and you can tell (bless their souls). Component libraries, templates, articles, video courses, and etc. have all existed throughout this time so it's not like they've been operating completely blind to design and UX. I don't think AI would be different. Sure it may raise the floor a little, but in the end someone needs to evaluate the output and hold responsibility for the UI/UX.
It was an uncomfortable idea to come to terms with though, I like many other designers spent a decade getting good at Figma. Figma and design almost felt intertwined for a moment, but designers have a long history of having their craft disrupted by new technology. Decades ago designers were cutting and pasting paper, then moved to digital publishing; and in product design we've gone through software such as Photoshop, Fireworks, Sketch, and Figma, just to name a few. Design has survived all this and will continue to survive in the future.
I think the same applies to the other disciplines. Sure I could have AI spin up a backend, but I don't really have the expertise to understand whether what it is doing is good or full of security vulnerabilities.
I don't know in the future if we will create a new path for product builders, individuals who are knowledgeable in all aspects of product management, software engineering, and product design. I also don't know if teams will have as much need for individuals with the efficiency gains from AI.
Most companies seem to still be in denial about it, and hope that if they add some more AI into their product, or do it just right, it will make sense. But it won't. AI is destined to sit on the outside, and products to be reduced into a bag of tools for AI to call.
Taking away write access from AI tools outside their contractual control is an expected knee-jerk reaction, but it'll probably just hasten the product's slide into irrelevancy by ceding ground to competition (that will ultimately share the same fate, too, but is still in denial about it).
But for frequent use cases - something you do daily or weekly perhaps - then a native interface still has merit. i.e. I don't think AI subsumes the product in this case.
You need other programs to do other parts of the same work - design in Figma, code in VS Code, collaboration in Google/Microsoft office suite, shitposting (er, well-being and psychological hygiene at work) in Slack, etc. AI sitting on the outside is able to operate all of them, combining their capabilities for you, to do what you want and how you want it. AI sitting inside a single product is limited only to the surface of that product, and is limited to capabilities the vendor wants.
While Figma could probably survive that way for some time, most software products can't, because they don't have anything special in them.
--
Fundamentally, a product is our industry's "unit of billable good/service". It's composed of a number of "operations" that are more or less closely related to each other, that someone grouped together into a larger whole with a User Interface, and slapped a brand on, so it can be sold.
From user's POV, that UI is something standing in between the user and the problem they want solved. Sometimes it's what they need, other times - not quite. From vendor's POV, UI is the mechanism of control over what users can and cannot do, and a prime sales/marketing channel, because the audience is captive.
Now, the AI sitting on the outside, operating on the functionality under UI, and composing it with functionality of other applications, gives users a superior meta-application, solving their own problem (and AI is not restricted to chat UI - there just hasn't been that much work done yet on ad-hoc, problem/user-specific UIs).
For users, that's a win - the AI may not be perfect mode of interaction (can get close with custom UIs), but it does not obstruct them. For vendors, that's a disaster, because it destroys coherence of a product, reducing it to a bag of tool calls, with zero branding and no control/upsell surface.
That's what I mean by AI subsuming products, and it being a mortal threat to most of the software companies today.
These thoughts, I mostly refined over time on this very forum over the past year; some of those, in reverse-chronological order: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
EDIT: in this very thread, you have an example of why AI on the outside beats AI on the inside: https://news.ycombinator.com/item?id=49923571.
I imagine I also want a specialized tool for, say, reviewing 3D models before printing them. And they would definitely like addresses to be shown in a navigable map.
But that type of interface already exist (and has been #killedbygoogle) - its Google Wave.
"I need an interface like ${this specific product} for my 3D scenes, but I also need to review each 3D model, which I normally do in ${that specialized tool}, and I'd love to have the two in one UI, well integrated, so I can ${description of your process}. Make it so."
Put that in Antigravity/Claude Code/Codex/whatever harness backed by a decent model, and good chances are, you'll have exactly what you wanted in less than half an hour.
All of my self hosted SAAS (redmine , gitea, discourse , vaultwaden , GLPI etc etc ) (even the cloudron pass if all runs on) is exactly that.
It’s beautiful! Of course as a self hoster that’s quite different then SAAS vendors who need to earn a profit I guess.
The key to making it token efficient was allowing Claude to invent its own plaintext markup format for the lens output.
https://developers.figma.com/docs/rest-api/file-endpoints/#g...
https://developers.figma.com/docs/rest-api/file-node-types/
Seems read-only, which means we're stuck with the MCP for updating Figma files... unless you've found a workaround there too?
https://github.com/southleft/figma-console-mcp/tree/main
No affiliation, just found it useful.
[1] https://help.figma.com/hc/en-us/articles/32132100833559-Guid...