For context: Figma has two MCPs. The local "dev" MCP that works through the Desktop app, and the remote MCP that requires a connection to Figma. Companies need to be whitelisted to use the remote MCP, which is the only one that allows agents edit access to Figma documents.
I only found out about Figma's limitation when I was trying to add the remote MCP server to GitHub Copilot Desktop and kept running into errors. Turns out they only whitelisted GitHub Copilot CLI and had put a pause on enabling any more vendors. Eventually someone (not sure which side) got it working.
Kind of strange to limit edit access only to the Remote MCP when their competitors like Pen[1] and Paper[2] allow any local agent to edit.
This was always a possibility, when my team dug into the concentration of MCP server usage a year ago we found that the top 10 servers had half of all GitHub stars (the Figma server was in 10th at the time).
I think we'll see more of this. Of course SAAS companies like Figma, and soon Adobe and ... will see that their tools are still useful. And they are useful to LLMs like they are useful to humans.
The obvious play to "extract value" from that is to restrict access to bots and offer LLM integration themselves, for a fee.
We're talking about client request headers, right? Why even bother with such a thing? Malicious users will just spoof those, you're only going to annoy legitimate users.
Another thing they do that I find equally frustrating is their MCP can do things you cannot do via API so you are forced to use theirs and cannot implement your own
> Open MCP basically kills your product in my opinion, you can't charge for any feature the LLM can do itself.
For products for which this is true resorting to whitelisting clients simply accelerates your obsolescence by creating a temporary market for products that are MCP, and open agent, friendly.
Welcome to where this was inevitably all going to go eventually. The entirety of commercial personal computing is going this direction: locking down APIs to make sure you’re not only doing what the company wants, but also the way the company wants. Mobile phones provide countless examples already; applying those examples to LLM world isn’t far fetched - and Anthropic already started down the road of “any old agent isn’t OUR agent” months ago.
I only found out about Figma's limitation when I was trying to add the remote MCP server to GitHub Copilot Desktop and kept running into errors. Turns out they only whitelisted GitHub Copilot CLI and had put a pause on enabling any more vendors. Eventually someone (not sure which side) got it working.
Kind of strange to limit edit access only to the Remote MCP when their competitors like Pen[1] and Paper[2] allow any local agent to edit.
[1] https://www.pen.dev/
[2] https://paper.design/
https://www.oreilly.com/radar/mcp-in-practice/
MCP is only as useful as the servers people use are open.
The obvious play to "extract value" from that is to restrict access to bots and offer LLM integration themselves, for a fee.
It's probably good news for users and open source though, why would you pay for something if a free tool with an MCP can do it.
For products for which this is true resorting to whitelisting clients simply accelerates your obsolescence by creating a temporary market for products that are MCP, and open agent, friendly.