Figma for AI agents

Figma is a collaborative interface design tool where teams build, comment on, and hand off product designs and design systems. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Design and imagesOAuth 2.0MCP + RESTfigma.com
AUDIT LOG · FIGMAPOLICY: acme-support
09:41:07 · claude · u_8f2read
figma.get_style
Get style✓ allowed · 212ms
09:41:08 · claude · u_8f2read
figma.get_payments
Get payments✓ allowed · 164ms
09:41:09 · claude · u_8f2write
figma.create_a_webhook
Create a webhook✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
figma.delete_a_comment
Delete a comment✕ blocked · policy: deny
EVERY FIGMA CALL, ON THE RECORD
01 · USE CASES

What agents do in Figma.

01

Pull design tokens from a file

Extract design tokens from a file so a developer can sync them with the codebase.

02

Add a comment to a design

Add a comment to a file once a reviewer flags feedback on a specific frame.

03

Confirm before deleting variables

Require approval before deleting variables, since design files elsewhere may reference them.

02 · ACTIONS

53 Figma actions, graded by risk.

Every Figma action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

39

Look things up. Allowed by default.

  • figma.get_style
    Get style
  • figma.get_payments
    Get payments
  • figma.get_a_webhook
    Get a webhook
  • figma.get_component
    Get component (Deprecated)
  • figma.get_file_json
    Get file json
  • figma.get_component2
    Get component
  • figma.get_file_nodes
    Get file nodes
  • figma.get_file_styles
    Get file styles
  • figma.get_image_fills
    Get image fills
  • figma.get_team_styles
    Get team styles
  • figma.get_current_user
    Get current user
  • figma.get_activity_logs
    Get activity logs
  • figma.get_component_set
    Get component set
  • figma.get_dev_resources
    Get dev resources
  • figma.get_file_metadata
    Get file metadata
  • figma.get_team_webhooks
    Get webhooks
+ 23 MORE

write

9

Create and change things. Allow, or ask the user first.

  • figma.create_a_webhook
    Create a webhook
  • figma.update_a_webhook
    Update a webhook
  • figma.create_dev_resources
    Create dev resources
  • figma.update_dev_resources
    Update dev resources
  • figma.add_a_comment_to_a_file
    Add a comment to a file
  • figma.add_a_reaction_to_a_comment
    Add a reaction to a comment
  • figma.discover_figma_resources
    Discover Figma Resources
  • figma.design_tokens_to_tailwind
    Design tokens to tailwind
  • figma.render_images_of_file_nodes
    Render images of file nodes

destructive

5

Delete, cancel or archive. Ask first, or deny outright.

  • figma.delete_a_comment
    Delete a comment
  • figma.delete_a_webhook
    Delete a webhook
  • figma.delete_a_reaction
    Delete a reaction
  • figma.delete_dev_resource
    Delete dev resource
  • figma.create_modify_delete_variables
    Create, modify, or delete variables
03 · HOW IT WORKS

Figma in three steps.

  1. 01Your users connect FigmaThey sign in to Figma on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create a webhook” can wait for the user, and “delete a comment” can be denied outright.
  3. 03Any agent can actYour agent calls Figma through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('figma', {
  read: 'allow',
  write: 'ask',        // create_a_webhook
  destructive: 'deny',  // delete_a_comment
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Figma connects.

Users sign in to Figma on Arc0 Connect and approve the scopes you request. Build with Arc0’s Figma OAuth app, or bring your own so the Figma consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same Figma connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key · OAuth 2.0
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Figma from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Figma and Arc0, answered.

Q01

Can I use Figma with Claude, ChatGPT or Cursor?

Yes. Connect Figma to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Figma actions you allow.

Q02

How do users connect Figma?

Users sign in to Figma on Arc0 Connect and approve the scopes you request. Build with Arc0’s Figma OAuth app, or bring your own so the Figma consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which Figma actions can my agent take?

53 in total: 39 read, 9 write and 5 destructive, such as “create a webhook”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Figma?

Yes. Actions like “delete a comment” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Figma too?

Yes. The same Figma connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Figma into your agent.

Your users connect Figma once, under your brand. Your agent gets 53 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan