Server data from the Official MCP Registry
Figma MCP: list frames in a file and fetch one frame's JSON and image safely. 2 tools.
About
Figma MCP: list frames in a file and fetch one frame's JSON and image safely. 2 tools.
Security Report
Valid MCP server (0 strong, 2 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.
5 files analyzed · 1 issue found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: FIGMA_TOKEN
Environment variable: FIGMA_API_BASE_URL
Environment variable: FIGMA_REQUEST_TIMEOUT_MS
Environment variable: FIGMA_MAX_JSON_BYTES
Environment variable: FIGMA_MAX_FRAME_BYTES
Environment variable: FIGMA_OUTPUT_ROOT
Environment variable: FIGMA_ALLOW_HTTP_FOR_TESTS
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-scalably-figma-mcp": {
"env": {
"FIGMA_TOKEN": "your-figma-token-here",
"FIGMA_OUTPUT_ROOT": "your-figma-output-root-here",
"FIGMA_API_BASE_URL": "your-figma-api-base-url-here",
"FIGMA_MAX_JSON_BYTES": "your-figma-max-json-bytes-here",
"FIGMA_MAX_FRAME_BYTES": "your-figma-max-frame-bytes-here",
"FIGMA_REQUEST_TIMEOUT_MS": "your-figma-request-timeout-ms-here",
"FIGMA_ALLOW_HTTP_FOR_TESTS": "your-figma-allow-http-for-tests-here"
},
"args": [
"-y",
"@scalably-io/figma-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
Figma MCP
Figma REST API MCP server. 2 tools list the top-level frames in a file and fetch one frame's rendered PNG plus its node JSON and image-fill map into a local output directory.
Install
Claude Code:
claude mcp add figma -e FIGMA_TOKEN=your-token -- npx -y @scalably-io/figma-mcp
Codex:
codex mcp add figma --env FIGMA_TOKEN=your-token -- npx -y @scalably-io/figma-mcp
Claude Desktop: download figma-mcp.mcpb from the latest GitHub release and open it.
Setup
- Create a personal access token at figma.com under account settings, with
file_content:readscope. - Find the file key in any Figma file URL: it is the segment after
/design/or/file/, for examplehttps://www.figma.com/design/AbC123xyz/My-filegivesAbC123xyz. Both tools take it asfile_key. - If
FIGMA_TOKENis not set the server still starts and lists its tools; every call then fails withFIGMA_NOT_CONFIGUREDuntil the token is provided. fetch_frameis the only tool that writes files (so it is not marked read-only); it writesframe.png,node.json, andfills.jsoninto a directory below the configured output root (default./figma-output). The other tool is fully read-only.
Tools (2)
| Tool | What it does |
|---|---|
list_frames | List and optionally filter all top-level FRAME nodes in a Figma file, with exact page/name/node-id data, dimensions, and file metadata |
fetch_frame | Fetch one Figma frame and transactionally write frame.png, node.json, and a normalized image-fill map into a directory below the output root |
Configuration
| Variable | Required | Purpose |
|---|---|---|
FIGMA_TOKEN | yes | Figma personal access token with file_content:read |
FIGMA_API_BASE_URL | no | Override the Figma REST API base URL (default https://api.figma.com/v1) |
FIGMA_REQUEST_TIMEOUT_MS | no | Per-request timeout in milliseconds (default 60000) |
FIGMA_MAX_JSON_BYTES | no | Upper bound on a Figma JSON response, in bytes (default 104857600) |
FIGMA_MAX_FRAME_BYTES | no | Upper bound on a downloaded frame PNG, in bytes (default 104857600) |
FIGMA_OUTPUT_ROOT | no | Directory that every fetch_frame output directory must stay below (default ./figma-output, created on first use) |
FIGMA_ALLOW_HTTP_FOR_TESTS | no | Test suite only: 1 allows a plain-HTTP loopback API base. Never set it in normal use |
Reply shape
Every tool returns plain JSON with status (succeeded, partial, no_op), summary, target, result, proof, warnings, recovery. Failures throw a plain error string: <code>: <message> <hint>.
Limits
fetch_frame renders through Figma's image API, so very large frames or extreme scale values can exceed the configured JSON or frame byte limits; lower scale or split the frame if that happens. fills.json URLs are temporary and expire within 14 days.
Verify
Each release lists the package version, the .mcpb sha256 and the production commit it was derived from in CHANGELOG.md. CI runs the tests and a clean install of the packed tarball on every push.
Privacy Policy
This server runs locally, on your machine, under your own credentials. It collects no personal data, contains no telemetry, stores nothing persistently beyond the frame bundles you explicitly fetch, and talks only to the vendor API it wraps. No third party, including Scalably, receives your data. Contact: hello@scalably.io. Canonical copy: https://scalably.io/connector-privacy.html
License
MIT. Copyright Scalably.
Reviews
No reviews yet
Be the first to review this server!
More Design MCP Servers
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
FinAgent
Freeby mcp-marketplace · Finance
Free stock data and market news for any MCP-compatible AI assistant.
Google Workspace MCP
Freeby Taylorwilsdon · Productivity
Control Gmail, Calendar, Docs, Sheets, Drive, and more from your AI
