Releases: ctxrs/figma-server
Release list
v0.2.0: JavaScript evaluation and full CDP
v0.2.0 adds arbitrary JavaScript evaluation and arbitrary Chrome DevTools Protocol commands over MCP and JSON HTTP.
The new tools are figma.evaluate, figma.cdp, figma.cdp_events and figma.cdp_close. Connections keep enabled domains, remote objects and bounded event queues across calls. Raw requests run concurrently, so paused evaluation can receive resume commands and event reads.
This interface is for trusted local agents. Acquiring a managed handle requires authentication and an owned writer lease. Browser commands can affect other agents and bypass file locks; raw-created targets require caller cleanup. Raw authority persists for the worker generation. Protocol completion is not a saved-design or destructive-effect guarantee. Chromium sandboxing remains enabled; launch still blocks service workers and initially disables downloads.
The qualified runtime passed twelve independent Chromium/MCP/HTTP fixtures and seventeen installed native Linux checks, including ordinary reopening after raw access, Ctrl+C cleanup and authenticated-profile restart. Source evidence includes earlier154-test Node22/24 baselines and focused checks for subsequent changes; the final signal and CLI files passed together25/25 on each node. Fresh production installation and installed CLI/MCP/HTTP smoke passed. These results do not claim new v0.2 native macOS/Windows qualification or cloud durability.
Install from the GitHub tarball after publication. v0.1.0 remains unchanged. See qualification.json and SHA256SUMS for artifact and scope details.
figma-server v0.1.0 prerelease
v0.1.0 prerelease
Run a dedicated Figma browser, sign in once, and connect MCP agents or JSON HTTP clients. Agents inspect the visible editor, capture screenshots and send browser inputs. There is no model-provider allowlist.
Each file lease has its own tab. Different files can proceed in parallel; one server writer at a time holds the same file. Another writer waits up to 30 seconds before file_busy. Human collaborators and other clients remain outside that lock.
The qualified Design lane is native property editing on Linux. Frame and Rectangle fields were read back after normal reopening and one browser restart. Independent public MCP on macOS read the same Linux-edited properties and verified them after normal reopening, without editing. Actual same-file MCP/JSON writer handoff and overlapping operations on different files were also observed within their recorded runtime scope.
Save UI state remains unknown. These observations do not establish a save transaction, independent cloud durability or a guarantee for future calls. macOS editing, ordinary-user Windows, other editor types, native text-content readback, image insertion/save and component/style workflows remain unqualified.
Use plain Design file URLs for dashboard opening. Unsupported node-id or page-id selections must be removed. The fallback requires the exact rendered Recents/Drafts card. Tools operate visible controls; they do not expose a complete native node API.
The source suite passed 139 tests with zero failures/skips on both Node 22.22.2 and 24.21.0, including headed fixtures, build and typechecking. See the README for installation/login/MCP setup and TESTING.md for archive and platform evidence. Installation uses the GitHub npm-format archive; this release does not imply an npm registry publication.