Pimp My IDE / garage dispatch
Back to garage
October 1, 2026 | MCP / client admission / tool authority

A standard plug can still meet a locked door.

Figma's remote MCP server uses the protocol and OAuth, yet only cataloged clients may connect. Compatibility needs four receipts, not one logo.

Protocol support proves that two systems can speak the same language. It does not prove that the server admits this client, that the account can reach this file, or that the requested tool may change it.

MCP compatibility has more than one owner.

Figma recommends its hosted remote MCP server and says it has the broadest feature set. The server can return design context, generate code from selected frames, retrieve resources, and write native Figma content. It also draws a product boundary: only clients listed in the Figma MCP Catalog can connect.[1]

The current setup guide names Claude Code, Codex, Cursor, VS Code, and Xcode. Figma's write-to-canvas page names a larger but still explicit set of supported clients. Writing also needs a Full seat. Editing an existing file needs edit permission for that file.[2]

A shared connector is not an open guest list.

This is not a contradiction in the protocol. The MCP authorization specification defines how an HTTP client discovers authorization metadata, requests a token, and binds that token to the intended server. Authorization is optional. Dynamic client registration is a recommendation, not a requirement, and authorization servers may apply their own registration policies.[3]

Do not collapse the route into connected or broken.

A useful diagnosis starts with the layer that refused the request. The client may understand MCP while the server does not admit that client. An admitted client may complete OAuth while the signed-in account lacks the right seat. The account may open the file but lack edit permission. The route may read context while a specific write tool remains unavailable.

Those failures need different fixes. Reinstalling the client will not upgrade a seat. Repeating OAuth will not add an unlisted client to a server catalog. Granting file edit access will not add a missing tool. One red connection lamp sends operators toward the wrong wrench.

New clients make this distinction visible.

Pi 1.0 shipped with native MCP support through Codemode. Its launch also describes Pi as a minimal, extensible coding-agent harness and links its MIT-licensed code and documentation.[4] That proves a client-side capability. It does not grant admission to every remote MCP service.

A Hacker News thread linked to a Figma staff post and focused on Pi's absence from Figma's client list.[5] The discussion is evidence of developer friction, not evidence about Figma's private review process or Pi's implementation. The public Figma documentation is the authority for the current admission rule.

The practical lesson travels beyond either product. When a tool says it supports MCP, record the endpoint, transport, authentication path, admitted client, account entitlement, resource permission, requested tool, and observed result. That small receipt turns a vague compatibility claim into a route someone else can debug.

Interactive makeover / capability customs gantry

Inspect the route one gate at a time.

Traditional purpose replaced: one connection badge. Better version: four native selectors expose client admission, account access, resource permission, and requested action. The generated card remains a preflight plan until a real call and response are attached.

Build a route

This teaching rig models the public Figma rules read on October 1. It does not contact Figma, inspect an account, or test a client.

This model covers the documented route only. Product limits, organization policy, tool availability, and server changes still need a live check.

Admission line

Client to action

4 of 4 gates pass
Pass01 / ProtocolMCP over HTTP selected
Pass02 / ClientCatalog admission selected
Pass03 / ResourceAccount and file readable
Pass04 / ActionRead requirements selected

Read route fits the selected public rules.

Run a real read call and save the endpoint, account, tool name, response, and timestamp before marking the route tested.

Four receipts for remote tool compatibility

Give each decision its own line.

01 / WIRE

Can both sides speak the transport?

Record the endpoint, transport, protocol version, and discovery response.

02 / GUEST LIST

Does the service admit this client?

Use the service's current client catalog or registration process. Do not infer admission from the protocol logo.

03 / CREDENTIAL

What can this account reach?

Record the signed-in identity, seat, organization policy, and file permission without exposing the token.

04 / TOOL

Did the required action run?

Call the narrow tool, inspect the destination, and save the exact error or result.

Sources read

Source log and evidence boundary
  1. Figma Developer Docs, "Set up the remote server", read October 1, 2026. It recommends the remote server, lists supported setup paths, describes OAuth and remote capabilities, and states that only clients in the Figma MCP Catalog may connect.
  2. Figma Developer Docs, "Write to canvas", read October 1, 2026. It lists supported write clients and states that writing needs a Full seat and file edit permission. The related rate limits and access page separates seat limits, client support, and resource permission.
  3. Model Context Protocol specification, "Authorization", read October 1, 2026. It defines the HTTP authorization flow, optional authorization support, OAuth metadata discovery, resource binding, and recommended dynamic client registration. It also allows authorization servers to apply registration policies.
  4. Earendil, "Pi 1.0", published and read October 1, 2026. This first-party launch says Pi 1.0 adds native MCP support through Codemode and links its documentation, install route, and MIT-licensed source.
  5. Hacker News item 49922729, read October 1, 2026. The thread links to a Figma staff post and records developer discussion about client admission. Comments are not used as proof of product behavior.

Evidence boundary. Pimp My IDE did not authenticate to Figma, run Pi against the endpoint, or inspect either implementation. The article compares published interfaces and access rules. The customs gantry is a teaching model. Its status describes whether the selected inputs fit the documented rules, not whether a live integration works.