Penpot for AI agents

Penpot is an open-source design and prototyping platform for teams to collaborate on interface design. Product and design teams use it as a self-hosted alternative to proprietary design tools. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Design and imagesAPI keyMCP + RESTpenpot.app
AUDIT LOG · PENPOTPOLICY: acme-support
09:41:07 · claude · u_8f2read
penpot.search_files
Search Files✓ allowed · 212ms
09:41:08 · claude · u_8f2read
penpot.get_file
Get File✓ allowed · 164ms
09:41:09 · claude · u_8f2write
penpot.create_file
Create File✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
penpot.delete_team
Delete Team✕ blocked · policy: deny
EVERY PENPOT CALL, ON THE RECORD
01 · USE CASES

What agents do in Penpot.

01

Create a comment thread on a file

Leave feedback on a specific part of a design file for the team to address.

02

Check a file's summary read-only

Look up a design file's summary and libraries before starting new work on it.

03

Delete a project with approval

Remove a design project only after the team confirms its files have been archived.

02 · ACTIONS

90 Penpot actions, graded by risk.

Every Penpot action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

36

Look things up. Allowed by default.

  • penpot.get_file
    Get File
  • penpot.get_page
    Get Page
  • penpot.get_team
    Get Team
  • penpot.get_teams
    Get Teams
  • penpot.get_project
    Get Project
  • penpot.get_comments
    Get Comments
  • penpot.get_webhooks
    Get Webhooks
  • penpot.search_files
    Search Files
  • penpot.get_file_info
    Get File Info
  • penpot.get_team_info
    Get Team Info
  • penpot.get_team_stats
    Get Team Stats
  • penpot.get_team_users
    Get Team Users
  • penpot.get_owned_teams
    Get Owned Teams
  • penpot.get_all_projects
    Get All Projects
  • penpot.get_file_summary
    Get File Summary
  • penpot.get_sso_provider
    Get SSO Provider
+ 20 MORE

write

45

Create and change things. Allow, or ask the user first.

  • penpot.create_file
    Create File
  • penpot.create_team
    Create Team
  • penpot.update_file
    Update File
  • penpot.update_font
    Update Font
  • penpot.update_team
    Update Team
  • penpot.create_project
    Create Project
  • penpot.create_webhook
    Create Webhook
  • penpot.update_comment
    Update Comment
  • penpot.update_profile
    Update Profile
  • penpot.update_webhook
    Update Webhook
  • penpot.send_user_feedback
    Send User Feedback
  • penpot.update_project_pin
    Update Project Pin
  • penpot.create_access_token
    Create Access Token
  • penpot.update_file_snapshot
    Update File Snapshot
  • penpot.update_profile_props
    Update Profile Props
  • penpot.create_comment_thread
    Create Comment Thread
+ 29 MORE

destructive

9

Delete, cancel or archive. Ask first, or deny outright.

  • penpot.delete_team
    Delete Team
  • penpot.delete_comment
    Delete Comment
  • penpot.delete_project
    Delete Project
  • penpot.delete_webhook
    Delete Webhook
  • penpot.delete_team_member
    Delete Team Member
  • penpot.delete_access_token
    Delete Access Token
  • penpot.delete_file_snapshot
    Delete File Snapshot
  • penpot.delete_team_invitation
    Delete Team Invitation
  • penpot.delete_team_files_permanently
    Permanently Delete Team Files
03 · HOW IT WORKS

Penpot in three steps.

  1. 01Your users connect PenpotThey add their Penpot api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create File” can wait for the user, and “delete Team” can be denied outright.
  3. 03Any agent can actYour agent calls Penpot through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('penpot', {
  read: 'allow',
  write: 'ask',        // create_file
  destructive: 'deny',  // delete_team
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Penpot connects.

Users add their Penpot api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Penpot connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Penpot from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Penpot and Arc0, answered.

Q01

Can I use Penpot with Claude, ChatGPT or Cursor?

Yes. Connect Penpot to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Penpot actions you allow.

Q02

How do users connect Penpot?

Users add their Penpot api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Penpot actions can my agent take?

90 in total: 36 read, 45 write and 9 destructive, such as “create File”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Penpot?

Yes. Actions like “delete Team” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Penpot too?

Yes. The same Penpot connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Penpot into your agent.

Your users connect Penpot once, under your brand. Your agent gets 90 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan