GitHub - ctxrs/figma-server: Figma is hostile to your agents, so just run figma-server for full access over CDP

figma-server lets personal, coding, and enterprise agents operate Figma through Chromium using CDP, with MCP and HTTP API connections.

Visit Website
GitHub - ctxrs/figma-server: Figma is hostile to your agents, so just run figma-server for full access over CDP

Introduction

Overview

figma-server is a tool that gives an agent access to Figma by running the web application in Chromium and controlling it through the Chrome DevTools Protocol. It is intended for people who want to use their own personal, coding, or enterprise agent rather than depend on a specific built-in agent workflow.

The project packages browser control as a server that agents can connect to through MCP or an HTTP API.

Key Features

Through the controlled Chromium session, an agent can perform several browser-level actions:

  • Click and type in the Figma interface
  • Capture screenshots of the current browser state
  • Run JavaScript in the browser
  • Open multiple tabs to work across different files
  • Connect through either MCP or the HTTP API

This approach uses Figma as a web application and gives the connected agent browser-level tools instead of relying on Figma's official MCP client approval process.

How to Use

figma-server requires Node.js 22.16.0 or newer, npm, and access to a graphical desktop for the initial sign-in. The documented release is the v0.2.0 prerelease, installed globally through npm from the project's packaged release.

After installation, initialize the dedicated browser profile and install Chromium. Sign in once through the graphical browser, then connect the chosen agent using MCP or the HTTP API.

Session Behavior

Once sign-in is complete, Chromium can run headlessly. The Figma login is retained in a dedicated profile, so the same session can be reused until Figma requires authentication again.

Users who authenticate with Google or enterprise single sign-on need to configure the exact identity-provider origins before logging in.