Figma (Gayani) has confirmed its remote MCP server only accepts clients on a supported whitelist, excluding third-party agent clients like Pi pending a review form; whether other MCP providers adopt client-identity gating โ or Figma reopens access โ settles whether MCP ecosystems are moving to approved-client control over agent access.
state: corroboratedheat: highuncertainty: mediumconvergesscott: highmcp-governance agentic-security agent-harnessesFigmaGayani
Surfaced 2026-10-03T06:04:16Z โ "our remote MCP server only accepts clients on our supported list, and Pi isn't on it yet. You can see the current list in our MCP catalog" โ Meaning shifted from single-vendor precedent to a likely emergent pattern: HN testimony cites Slack's MCP server as partner-gated per Slack's own help docs and a security reviewer reports implementing the same gating for OAuth containment, while a purpose-built CDP bypass shows the gate rests on a spoofable self-reported client string rather than cryptographic identity. The attention burst is spent (~0 pts/h vs 49 peak, 39th percentile at 86h) โ the magnitude-valve spread reading reflects the consumed HN+X spike, not an expanding periphery (the newest derivative, the bypass Show HN, launched to 2 points) โ so heat prices low while the imitation question carries forward at corroborated.
What is this?
Figma's remote MCP server โ the official OAuth-gated endpoint for giving coding agents design context from Figma files โ only accepts clients listed in its published MCP Catalog (Claude, Claude Code, Codex, VS Code, Cursor, Zed, OpenHands, ServiceNow Build Agent), and a Figma support reply on the official forum confirms new client integrations are paused while Figma builds a 'scalable foundation for all partners,' with a request form / account-team route for consideration. The forum reply stresses that speaking MCP and being authorized to connect are separate: custom OAuth apps can't obtain the mcp:connect scope, dynamic client registration returns 403, and personal access tokens are rejected at the MCP endpoint โ so third-party agent clients like Pi are shut out at the identity layer even with valid Figma file permissions. Notably, Pi's own package docs describe registering with Figma's OAuth endpoint under another client's display name, implying the gate keys on a self-reported client string rather than a strong cryptographic identity. Caveats: the supplied snippets never name 'Gayani' (the confirmation is attributed only to Figma support/forum staff), and the material contains no evidence on whether other MCP providers will imitate or reject this gating.
Why it matters to Scott
A major platform vendor independently implementing client-identity gating for agent access is a dated receipt for the Agent Provenance Stack's Identity layer โ while the reported mechanism (a self-asserted client string, which Pi's own docs spoof under another client's display name) demonstrates exactly the asserted-vs-cryptographic identity gap that framework and his Chat-Era Trust Model critique diagnose. It also bears directly on Scott's own mcp-ip-wiki remote server's client-admission design and hands him a publishable position on whether other MCP providers imitate Figma's whitelist or hold the protocol open.
ip:framework.agent-provenance-stackip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookip:concept.cryptographic-trustdev:project.mcp-ip-wikiradar:amazon-blocks-meta-muse-shoppingradar:gitlab-19-4-governed-mcpradar:honeylabs-spoofed-ai-crawlersradar:ietf-ai-agent-auth-draft
queries asked of Scott's wikis
- MCP client whitelisting and governance
- agent identity OAuth non-human authentication
- spoofable client identity agentic security
- open protocol vs platform gatekeeping precedent
- agent harness dependent on first-party MCP servers
- Figma design context in coding agents
Measured heat
now 0 pts/hpeak 49 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 290h
points/hour across evidence ยท reading as of 2026-10-12 02:59:37.977291+11:00 ยท deterministic, not a model opinion
How the heat travelled
pace: p78 vs 1188 stories at the 168h mark (now 290h old) โ ahead of gpt-synopsys-partnership (1.0x), behind llama-cpp-hot-swappable-ple-memory (1.0x)
Evidence (3) โ โญ canonical anchor
Interpretation history
2026-10-03T05:15:40Z
magnitude valve eligible (multi-platform, top-decile engagement) and never alerted; deterministic escalation to deliver
2026-10-02T21:29:13Z
evidence attached: hn.story.49938648 โ A community CDP bypass built specifically in response to Figma's MCP client gating materially contextualizes whether approved-client control holds, so re-judging the open case needs it.
2026-10-01T16:48:55Z
grounded: converges/high โ A major platform vendor independently implementing client-identity gating for agent access is a dated receipt for the Agent Provenance Stack's Identity layer โ
2026-10-01T16:42:09Z
case created โ First-party vendor confirmation of client-identity gating on a major MCP server is a concrete governance precedent, and imitation by other providers is the resolvable question.
Decision trace
- 10-10 23:34review_dormantscheduled targets exhausted or 28 quiet days
- 10-10 23:34drop_targetsquiet through full ladder or over cap 8
- 10-03 16:04push"our remote MCP server only accepts clients on our supported list, and Pi isn't on it yet. You can see the current list in our MCP catalog" โ Meaning shifted from single-vendor preceden
- 10-03 15:15repriceMeaning shifted from single-vendor precedent to a likely emergent pattern: HN testimony cites Slack's MCP server as partner-gated per Slack's own help docs and a security reviewer reports im
- 10-03 15:15alert_held"our remote MCP server only accepts clients on our supported list, and Pi isn't on it yet. You can see the current list in our MCP catalog" โ Meaning shifted from single-vendor preceden
- 10-03 15:15alert_route"our remote MCP server only accepts clients on our supported list, and Pi isn't on it yet. You can see the current list in our MCP catalog" โ Meaning shifted from single-vendor preceden
- 10-03 07:29attachA community CDP bypass built specifically in response to Figma's MCP client gating materially contextualizes whether approved-client control holds, so re-judging the open case needs it.
- 10-03 07:27propose_attachA community CDP bypass built specifically in response to Figma's MCP client gating materially contextualizes whether approved-client control holds, so re-judging the open case needs it.
- 10-02 06:21sensor_dirtyvelocity_spike
- 10-02 04:22sensor_dirtycomment_update
- 10-02 02:48groundA major platform vendor independently implementing client-identity gating for agent access is a dated receipt for the Agent Provenance Stack's Identity layer โ while the reported mechanism (a sel
- 10-02 02:42createFirst-party vendor confirmation of client-identity gating on a major MCP server is a concrete governance precedent, and imitation by other providers is the resolvable question.