Skip to main content
Glama

figmanage

에이전트가 Figma 워크스페이스를 관리하도록 하세요. 시트, 팀, 권한, 결제, 오프보딩, 정리까지 — 관리자 패널을 클릭하는 대신 대화로 처리합니다.

모든 Figma MCP는 디자인-투-코드입니다. figmanage는 관리 계층입니다: 에이전트가 워크스페이스 자체를 조작할 수 있게 해주는 102개의 도구를 제공합니다. Claude Code, Cursor, OpenClaw 또는 독립 실행형 CLI로 작동합니다.

npm downloads tests license MCP

예시

워크스페이스 관리 (관리자)

"which paid seats haven't been active in 30 days? how much would we save?"

"offboard sarah@company.com -- show me everything she owns, then transfer it
 to jake and remove her from the org"

"set up a new hire: invite alex@company.com to Design and Engineering as an editor"

"create a user group called Platform Design and add the three designers"

"run a quarterly design ops report for the org"

일상적인 디자인 작업 (모든 사용자)

"clean up the Mobile App project -- find stale files and archive dead branches"

"what are the unresolved comments across the Platform project?"

"export all the icons from the Design System file as SVGs"

"move the Q4 files into the Archive project"

"share the Homepage mockup with alex@company.com and set link access to view-only"

"summarize the Brand Guidelines file -- pages, components, styles"

Related MCP server: figma-pilot

설치

# Claude Code
claude mcp add figmanage -- npx -y figmanage

# Cursor / OpenClaw / other MCP clients
{
  "mcpServers": {
    "figmanage": {
      "command": "npx",
      "args": ["-y", "figmanage"]
    }
  }
}

최초 실행 시 figmanage가 대화에서 설정을 안내합니다 — Chrome 세션 쿠키를 추출하고, PAT 생성을 요청하며, 자격 증명을 로컬에 저장합니다. 환경 변수도, JSON 편집도 필요 없습니다.

CLI로도 사용할 수 있습니다:

npm install -g figmanage
figmanage login

작동 방식

Figma의 공개 REST API는 디자인 파일은 다루지만 관리 측면은 전혀 다루지 않습니다 — 시트, 팀, 권한, 결제가 모두 없습니다. figmanage는 두 API를 모두 사용합니다:

API

인증

적용 범위

내부

세션 쿠키

시트, 팀, 권한, 결제, 사용자 그룹, 조직 관리자, 검색

공개

개인 액세스 토큰

파일, 댓글, 내보내기, 컴포넌트, 버전, 웹훅, 변수

두 가지를 함께 사용하면 102개 도구를 모두 사용할 수 있습니다. 쿠키만 또는 PAT만으로도 작동하지만 사용 가능한 도구가 제한됩니다.

관리자 자동 감지. 시작 시 figmanage는 사용자가 조직 관리자인지 확인합니다. 관리자는 102개 도구를 모두 볼 수 있습니다. 비관리자는 조직 관리, 시트 변경, 결제, 사용자 그룹, 오프보딩을 제외한 68개 도구를 볼 수 있습니다. 구성이 필요 없습니다.

도구 모음 프리셋. FIGMA_TOOLSETS를 사용하여 특정 도구 그룹만 노출합니다:

프리셋

포함 항목

starter

탐색, 읽기, 댓글, 내보내기

admin

탐색, 조직, 권한, 분석, 팀, 라이브러리

readonly

탐색, 읽기, 댓글, 내보내기, 컴포넌트, 버전

full

전체 (기본값)

CLI

명령어는 명사-동사 패턴을 사용합니다: figmanage <그룹> <동작>.

figmanage org seat-optimization                    # find inactive paid seats
figmanage org offboard sarah@co.com                # audit what a user owns
figmanage org offboard sarah@co.com --execute \
  --transfer-to jake@co.com                        # soft offboard
figmanage org offboard sarah@co.com --execute \
  --transfer-to jake@co.com --remove-from-org      # hard offboard (permanent)
figmanage org onboard alex@co.com --teams 123,456 \
  --role editor --seat full --confirm              # set up a new hire
figmanage org quarterly-report                     # org-wide design ops snapshot
figmanage org members --search danny               # find org members
figmanage permissions audit --scope team --id 789  # audit a team's permissions
figmanage branches cleanup 573408414               # find stale branches

모든 명령어는 파이프되거나 --json이 전달되면 JSON을 출력합니다. 하위 명령어는 figmanage <그룹> --help를 실행하세요.

설정

Chrome에서 figma.com에 로그인한 후:

figmanage login     # extract cookie, create PAT, store credentials
figmanage whoami    # verify auth
figmanage logout    # clear credentials

자격 증명은 ~/.config/figmanage/에 0o600 권한으로 저장됩니다.

환경 변수(FIGMA_PAT, FIGMA_AUTH_COOKIE 등)는 구성 파일보다 우선합니다. HTTP 전송은 --mcp --http <포트>로 사용할 수 있습니다.

도구 참조

아래 표는 MCP 도구 이름(snake_case)을 보여줍니다. CLI에서는 kebab-case를 사용합니다: list_recent_files는 figmanage navigate list-recent-files가 됩니다.

navigate (10)

도구

인증

설명

check_auth

둘 다

PAT 및 쿠키 인증 확인

list_orgs

cookie

사용 가능한 Figma 워크스페이스 나열

switch_org

cookie

이 세션의 활성 워크스페이스 전환

list_teams

cookie

조직의 팀 나열

list_projects

둘 다

팀의 프로젝트 나열

list_files

둘 다

프로젝트의 파일 나열

list_recent_files

cookie

최근 조회/편집한 파일

search

cookie

워크스페이스 전체에서 파일 검색

get_file_info

둘 다

파일 메타데이터: 이름, 프로젝트, 팀, 링크 액세스

list_favorites

cookie

즐겨찾기한 파일 (깨짐 -- Figma BigInt 버그)

files (10)

도구

인증

설명

create_file

cookie

디자인, 화이트보드, 슬라이드 또는 사이트 파일 생성

rename_file

cookie

파일 이름 바꾸기

move_files

cookie

프로젝트 간 파일 이동 (일괄)

duplicate_file

cookie

파일 복사

trash_files

cookie

파일을 휴지통으로 이동 (일괄)

restore_files

cookie

휴지통에서 파일 복원 (일괄)

favorite_file

cookie

즐겨찾기에 추가/제거

set_link_access

cookie

링크 공유 수준 설정

file_summary

pat

페이지, 컴포넌트, 스타일, 댓글 수

cleanup_stale_files

둘 다

오래된 파일 찾기, 선택적으로 휴지통 이동 (기본값은 미리보기)

projects (8)

도구

인증

설명

create_project

cookie

팀에 프로젝트 생성

rename_project

cookie

프로젝트 이름 바꾸기

move_project

cookie

프로젝트를 다른 팀으로 이동

trash_project

cookie

프로젝트를 휴지통으로 이동

restore_project

cookie

휴지통에서 프로젝트 복원

set_project_description

cookie

프로젝트 설명 설정 또는 업데이트

organize_project

cookie

프로젝트로 파일 일괄 이동

setup_project_structure

cookie

계획에서 여러 프로젝트 생성

permissions (8)

도구

인증

설명

get_permissions

cookie

역할과 함께 액세스 권한이 있는 사용자 나열

set_permissions

cookie

사용자의 액세스 수준 변경

share

cookie

이메일로 초대

revoke_access

cookie

사용자의 액세스 권한 제거

list_role_requests

cookie

대기 중인 액세스 요청 나열

approve_role_request

cookie

액세스 요청 수락

deny_role_request

cookie

액세스 요청 거부

permission_audit

cookie

과다 공유 플래그가 있는 팀/프로젝트 액세스 감사

org (24, 관리자 전용)

도구

인증

설명

list_admins

cookie

권한 수준이 포함된 조직 관리자

list_org_teams

cookie

구성원 및 프로젝트 수가 포함된 모든 팀

seat_usage

cookie

유형 및 활동별 시트 분석

list_team_members

cookie

역할 및 활동이 포함된 팀 구성원

list_org_members

cookie

시트 및 활동이 포함된 모든 조직 구성원

contract_rates

cookie

좌석당 가격

change_seat

cookie

사용자의 시트 유형 변경

billing_overview

cookie

청구서 내역 및 결제 상태

list_invoices

cookie

미결제 및 예정 청구서

list_payments

cookie

결제된 청구서 / 결제 내역

org_domains

cookie

도메인 구성 및 SSO/SAML

ai_credit_usage

cookie

AI 크레딧 사용량 (팀에서 플랜 확인)

export_members

cookie

모든 구성원의 CSV 내보내기 트리거

activity_log

cookie

이메일 필터링 및 페이지네이션이 포함된 조직 감사 로그

create_user_group

cookie

사용자 그룹 생성

delete_user_groups

cookie

사용자 그룹 삭제

add_user_group_members

cookie

이메일로 사용자 그룹에 구성원 추가

remove_user_group_members

cookie

사용자 그룹에서 구성원 제거

remove_org_member

cookie

조직에서 구성원 영구 제거

workspace_overview

cookie

조직 스냅샷: 팀, 시트, 결제

seat_optimization

cookie

비용 분석이 포함된 비활성 시트 감지

offboard_user

cookie

사용자 이탈 감사 + 실행 (소프트 또는 하드)

onboard_user

cookie

팀에 일괄 초대, 파일 공유, 시트 설정

quarterly_design_ops_report

cookie

시트 활용도, 결제, 팀, 라이브러리 채택

teams (5, 관리자 전용)

도구

인증

설명

create_team

cookie

팀 생성

rename_team

cookie

팀 이름 바꾸기

delete_team

cookie

팀 삭제

add_team_member

cookie

이메일로 구성원 추가

remove_team_member

cookie

구성원 제거

analytics (2, 관리자 전용)

도구

인증

설명

library_usage

cookie

팀 수준 라이브러리 채택 지표

component_usage

cookie

파일별 컴포넌트 사용량

comments (9)

도구

인증

설명

list_comments

pat

스레드 구조가 포함된 댓글

post_comment

pat

댓글 게시

delete_comment

pat

댓글 삭제

resolve_comment

cookie

댓글 스레드 해결/해제

edit_comment

cookie

기존 댓글 텍스트 편집

list_comment_reactions

pat

댓글의 이모지 반응

add_comment_reaction

pat

이모지 반응 추가

remove_comment_reaction

pat

이모지 반응 제거

open_comments

pat

프로젝트 전체의 미해결 댓글

versions (2)

도구

인증

설명

list_versions

pat

버전 기록

create_version

cookie

명명된 버전 체크포인트 생성

branches (4)

도구

인증

설명

list_branches

either

파일의 브랜치 나열

create_branch

cookie

브랜치 생성

delete_branch

cookie

브랜치 보관

branch_cleanup

either

오래된 브랜치 감지 및 선택적 보관

읽기 (2)

도구

인증

설명

get_file

pat

깊이 제어로 파일을 노드 트리로 읽기

get_nodes

pat

ID로 특정 노드 읽기

내보내기 (2)

도구

인증

설명

export_nodes

pat

PNG, SVG, PDF 또는 JPG로 내보내기

get_image_fills

pat

채우기로 사용된 모든 이미지의 URL

컴포넌트 (7)

도구

인증

설명

list_file_components

pat

파일에서 게시된 컴포넌트

list_file_styles

pat

파일의 스타일

list_team_components

pat

팀 전체에서 게시된 컴포넌트

list_team_styles

pat

팀 전체에서 게시된 스타일

list_dev_resources

pat

파일의 개발 리소스 (링크, 주석)

create_dev_resource

pat

노드에 개발 리소스 연결

delete_dev_resource

pat

개발 리소스 제거

웹훅 (5)

도구

인증

설명

list_webhooks

pat

팀의 웹훅 나열

create_webhook

pat

웹훅 구독 생성

update_webhook

pat

웹훅 업데이트

delete_webhook

pat

웹훅 삭제

webhook_requests

pat

전달 기록 (최근 7일)

변수 (3, Enterprise)

도구

인증

설명

list_local_variables

pat

로컬 변수 및 컬렉션

list_published_variables

pat

라이브러리에서 게시된 변수

update_variables

pat

변수 대량 생성, 업데이트 또는 삭제

라이브러리 (1)

도구

인증

설명

list_org_libraries

cookie

공유 정보가 포함된 디자인 시스템 라이브러리

보안

모든 ID 매개변수는 /^[\w.:-]+$/에 대해 검증됩니다. 속도 제한 재시도는 안전한 HTTP 메서드로 제한됩니다. -- 변형은 절대 재시도되지 않습니다. 결제 응답은 PII를 제거합니다. 파괴적 작업은 기본적으로 드라이런 모드입니다. 조직 제거는 명시적인 이중 확인이 필요합니다. 구성 파일은 0o600 권한으로 저장됩니다.

알려진 제한 사항

  • list_favorites: Figma 서버의 BigInt 오버플로 버그. favorite_file은 정상 작동합니다.

  • 브랜치 병합 / 버전 복원: Figma의 멀티플레이어 프로토콜이 필요하며, REST 엔드포인트가 없습니다.

  • 쿠키 만료: 약 30일. figmanage login --refresh로 갱신하세요.

  • Windows 쿠키: 최선의 DPAPI 추출. PAT 전용으로 대체됩니다.

  • 변수: Enterprise 전용 범위.

  • 사용자 그룹: 쓰기 전용 (생성, 삭제, 멤버 추가/제거). 목록 엔드포인트 없음 -- Figma는 페이지를 서버 측에서 렌더링합니다.

개발

git clone https://github.com/dannykeane/figmanage.git
cd figmanage
npm install
npm run build
npm test

3계층 아키텍처: operations가 모든 비즈니스 로직을 보유하고, tools와 CLI는 얇은 래퍼입니다.

src/
  index.ts            Entry: --setup, --mcp, or CLI mode
  mcp.ts              MCP server setup, admin detection, toolset presets
  setup.ts            Cross-platform Chrome cookie extraction
  auth/               AuthConfig from env vars and config file
  clients/            Axios clients for internal (cookie) and public (PAT) APIs
  operations/         Shared business logic (19 modules)
  tools/              MCP tool wrappers (thin, call operations)
  cli/                CLI Commander wrappers (thin, call operations)
  types/figma.ts      Shared types including Toolset union

라이선스

MIT

Available Tools

4 tools
setup_extract_cookiesA

Read Figma sessions from Chrome for setup or recovery. Requires permission to read browser credentials; reuse permission already granted in this conversation. The user must be logged into Figma. macOS may show a Keychain prompt. Never returns cookies.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

Output Schema

ParametersJSON Schema
NameRequiredDescription
errorNo
resultNo

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description goes beyond the annotations by disclosing important behavioral traits: it requires permission to read browser credentials, may trigger a macOS Keychain prompt, and explicitly states it 'Never returns cookies' — a critical clarification given the tool name. This adds value beyond the sparse annotations and sets clear expectations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is three sentences, each with a distinct purpose: state the action, list prerequisites, and disclose behavioral outcomes (keychain prompt, no cookies). It is front-loaded with the core purpose and avoids filler. Every sentence adds necessary information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a zero-parameter tool with an output schema, the description covers all necessary context: prerequisites, permission requirements, potential system prompts, and what the tool does NOT return. The existence of an output schema handles return value details. The description is complete for an agent to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

There are zero parameters, so the baseline is 4. The description adds no parameter-specific details because none are needed. It does provide context about the operation's inputs (Chrome, Figma session) which is relevant but not parameter semantics. Since the schema is empty, no further clarification is required.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's function: 'Read Figma sessions from Chrome for setup or recovery.' It identifies the specific verb (read) and resource (Figma sessions from Chrome), and the context (setup or recovery) distinguishes it from siblings like setup_status (checking status) and setup_save_pat (saving a token). No ambiguity.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides context ('for setup or recovery') and specifies prerequisites (permission to read browser credentials, user logged into Figma). It does not explicitly mention when not to use it or compare with alternatives, but given the sibling tools, the use case is clear. Slightly more explicit exclusion would make it a 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

setup_save_patA

Validate and save a PAT already supplied by the user. Prefer local figmanage login --pat-only to keep tokens out of chat. Rejects a PAT belonging to a different saved browser account.

ParametersJSON Schema
NameRequiredDescriptionDefault
patYesFigma Personal Access Token

Output Schema

ParametersJSON Schema
NameRequiredDescription
errorNo
resultNo

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations indicate readOnlyHint=false and destructiveHint=false, which are consistent with the description's 'save' action. The description adds behavioral context beyond annotations: it validates the PAT, saves it, and rejects mismatched accounts. This provides useful operational details that an agent needs to know.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences with no filler. It front-loads the core action, then provides an important security-relevant alternative and a rejection condition. Every sentence adds value, making it efficient and well-structured.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a single-parameter tool with an output schema present, the description covers the essential purpose, usage guidance, and a behavioral constraint. It doesn't explain the output format (covered by the output schema) or prerequisites like having a saved browser account, but those are either implicit or handled elsewhere. Overall, it is complete enough for an agent to call correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema covers 100% of the parameter 'pat' with a clear description ('Figma Personal Access Token'). The description adds minimal extra meaning—only that it is 'already supplied by the user,' which is more about usage context than parameter semantics. Since schema coverage is high, the baseline of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's action: 'Validate and save a PAT already supplied by the user.' It specifies the resource (PAT) and includes a rejection condition ('Rejects a PAT belonging to a different saved browser account'), making the purpose unambiguous and distinct from sibling tools like setup_status or setup_select_account.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly advises an alternative method: 'Prefer local figmanage login --pat-only to keep tokens out of chat.' This gives a clear when-not-to-use instruction. However, it does not explicitly contrast with the sibling tools (setup_status, setup_extract_cookies, setup_select_account), but those are not competing alternatives for saving a PAT, so the guidance is sufficient.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

setup_select_accountA

Validate and save a browser session after setup_extract_cookies. Use its recommended account without another question; ask when selection is ambiguous or changes the existing account. Preserves the PAT for the same account.

ParametersJSON Schema
NameRequiredDescriptionDefault
account_indexYesAccount number returned by setup_extract_cookies

Output Schema

ParametersJSON Schema
NameRequiredDescription
errorNo
resultNo

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations (readOnlyHint=false, destructiveHint=false, openWorldHint=true), the description discloses specific behaviors: it validates and saves a session, preserves the PAT for the same account, and may prompt the user when selection is ambiguous or changes the existing account. This adds meaningful context about side effects and user interaction without contradicting the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is three short sentences, front-loading the core action first, then providing decision rules and a key note on PAT preservation. Every sentence adds value with no fluff.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple tool with one parameter and an output schema, the description covers the action, the precondition (after setup_extract_cookies), the decision rule for asking vs. proceeding, and the PAT preservation behavior. It lacks explicit error handling details, but the output schema likely covers return values, making it sufficiently complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The single parameter account_index is fully described in the schema with its source (returned by setup_extract_cookies). The tool description does not add additional meaning beyond that, so it meets the baseline for full schema coverage.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's action: validate and save a browser session after setup_extract_cookies. It identifies the resource (browser session) and the sequencing relative to a sibling, making its purpose unambiguous and distinct from setup_status, setup_extract_cookies, and setup_save_pat.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives explicit guidance on when to use it: after setup_extract_cookies, and includes a decision rule for when to ask the user (ambiguous selection or account change) versus using the recommended account silently. It does not explicitly contrast with setup_save_pat, though it mentions PAT preservation, which could overlap, so it is not fully exhaustive.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

setup_statusA
Read-only

Check live authentication, retry admin access detection, and get structured next actions. Use before setup, after an authentication error, or when expected tools are missing. Does not read browser credentials or change settings.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

Output Schema

ParametersJSON Schema
NameRequiredDescription
errorNo
resultNo

TDQS

A4.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, but the description adds meaningful behavioral context: it explicitly states the tool does not read browser credentials or change settings, and mentions a retry behavior for admin access detection. This goes beyond what annotations alone convey, helping the agent understand side-effect boundaries.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, each earning its place: the first states the core function, the second gives usage timing, and the third clarifies limitations. The most important information is front-loaded, and there is no redundant or filler language.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a parameterless tool with a readOnly hint, an output schema, and three clear usage triggers, the description is complete. It covers purpose, when to use it, and what it avoids doing. The existence of an output schema means detailed return values do not need to be spelled out in the description.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool has zero parameters and the schema fully covers this by defining an empty properties object. Per the baseline for 0-param tools, the description need not explain parameters. It instead focuses on purpose and behavior, which is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb and resource: 'Check live authentication, retry admin access detection, and get structured next actions.' This clearly identifies the tool as a diagnostic/status tool and differentiates it from siblings like setup_extract_cookies or setup_save_pat, which perform credential operations rather than status checks.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit usage triggers are given: 'Use before setup, after an authentication error, or when expected tools are missing.' This gives clear context for when to invoke the tool. It does not explicitly list sibling alternatives, but the closing disclaimer about not reading credentials or changing settings implies when other tools would be appropriate.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 4 tool updatesv1.5.0
    • Changedsetup_extract_cookies2 fields changed
      • removedInput schema / $schema
        Removed value: -"http://json-schema.org/draft-07/schema#"
      • changedOutput schema / (root)
        Previous value: -nullNew value: +{
        +  "$schema": "http://json-schema.org/draft-07/schema#",
        +  "additionalProperties": false,
        +  "properties": {
        +    "error": {
        +      "additionalProperties": false,
        +      "properties": {
        +        "code": {
        +          "type": "string"
        +        },
        +        "message": {
        +          "type": "string"
        +        }
        +      },
        +      "required": [
        +        "code",
        +        "message"
        +      ],
        +      "type": "object"
        +    },
        +    "result": {}
        +  },
        +  "type": "object"
        +}
    • Changedsetup_save_pat2 fields changed
      • changedInput schema / properties / pat / description
        Previous value: -"Figma Personal Access Token (starts with figd_)"New value: +"Figma Personal Access Token"
      • changedOutput schema / (root)
        Previous value: -nullNew value: +{
        +  "$schema": "http://json-schema.org/draft-07/schema#",
        +  "additionalProperties": false,
        +  "properties": {
        +    "error": {
        +      "additionalProperties": false,
        +      "properties": {
        +        "code": {
        +          "type": "string"
        +        },
        +        "message": {
        +          "type": "string"
        +        }
        +      },
        +      "required": [
        +        "code",
        +        "message"
        +      ],
        +      "type": "object"
        +    },
        +    "result": {}
        +  },
        +  "type": "object"
        +}
    • Changedsetup_select_account2 fields changed
      • changedInput schema / properties / account_index / description
        Previous value: -"Account number from the list returned by setup_extract_cookies"New value: +"Account number returned by setup_extract_cookies"
      • changedOutput schema / (root)
        Previous value: -nullNew value: +{
        +  "$schema": "http://json-schema.org/draft-07/schema#",
        +  "additionalProperties": false,
        +  "properties": {
        +    "error": {
        +      "additionalProperties": false,
        +      "properties": {
        +        "code": {
        +          "type": "string"
        +        },
        +        "message": {
        +          "type": "string"
        +        }
        +      },
        +      "required": [
        +        "code",
        +        "message"
        +      ],
        +      "type": "object"
        +    },
        +    "result": {}
        +  },
        +  "type": "object"
        +}
    • Changedsetup_status2 fields changed
      • removedInput schema / $schema
        Removed value: -"http://json-schema.org/draft-07/schema#"
      • changedOutput schema / (root)
        Previous value: -nullNew value: +{
        +  "$schema": "http://json-schema.org/draft-07/schema#",
        +  "additionalProperties": false,
        +  "properties": {
        +    "error": {
        +      "additionalProperties": false,
        +      "properties": {
        +        "code": {
        +          "type": "string"
        +        },
        +        "message": {
        +          "type": "string"
        +        }
        +      },
        +      "required": [
        +        "code",
        +        "message"
        +      ],
        +      "type": "object"
        +    },
        +    "result": {}
        +  },
        +  "type": "object"
        +}
  2. 4 tool updatesv1.4.2
    • First observedsetup_extract_cookies
    • First observedsetup_save_pat
    • First observedsetup_select_account
    • First observedsetup_status

TDQS

A4.2/5.0

Scored across 4 tools

Disambiguation4/5

All four tools are setup-related but have distinct roles: status check, cookie extraction, account selection, and PAT saving. The only minor ambiguity is between setup_extract_cookies and setup_select_account, but their descriptions clearly separate extraction from validation/saving.

Naming Consistency4/5

All tools share a consistent setup_ prefix and use verb_noun naming (setup_status, setup_extract_cookies, setup_select_account, setup_save_pat). Minor deviation: setup_status is a noun phrase rather than verb_noun, but the pattern is otherwise uniform.

Tool Count4/5

Four tools is slightly thin for a setup workflow, but each tool covers a distinct step in the authentication/setup lifecycle. The count is appropriate for a focused setup-only server, though it may feel minimal if the server is expected to manage Figma resources beyond setup.

Completeness4/5

The setup flow is well covered: check status, extract cookies, select account, and save PAT. A minor gap is the lack of an explicit teardown/logout or re-authentication tool, but the status tool's 'next actions' guidance helps mitigate dead ends.

Maintenance

ActivityNo data
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to create, modify, and manage Figma designs through natural language commands via a specialized MCP server and plugin bridge. It supports a wide range of operations including element creation, property modification, component management, and accessibility checks.
    8 npm
    106
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    MCP server that connects AI clients to Figma, enabling real-time reading, creation, and modification of designs using natural language.
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    An MCP server that provides write access to Figma through the Plugin API, enabling AI agents to create, modify, and manage Figma designs programmatically.
    23
    -