Enables AI assistants to read, create, and modify Figma designs, synchronize design tokens bidirectionally, and auto-document component-variant sets via Obra Autodocs integration.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
Wrangler affected by OS Command Injection in `wrangler pages deploy`
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
Vite's server.fs.deny bypassed with /. for files under project root
process.env. You'll be asked to provide them before it can run.APP_NAMEENABLE_MCP_APPS— e FIGMA_ACCESS_TOKEN=figd_YOUR_TOKEN_HERE -e =true \FIGMA_ACCESS_TOKEN— e =figd_YOUR_TOKEN_HERE -e ENABLE_MCP_APPS=true \FIGMA_CONSOLE_CONFIGFIGMA_MCP_MODEFIGMA_WS_HOST— Override the WebSocket server bind address (default: localhost). Set to 0.0.0.0 when running inside Docker so the host machine can reach the MCP server.FIGMA_WS_PORT— Override the preferred WebSocket port (default: 9223). The server will fall back through a 10-port range starting from this value if the preferred port is occupied.LOG_LEVEL[](https://m8ven.ai/mcp/obra-studio-figma-console-mcp-autodocs-z3pdrg)