mirror of
https://github.com/penpot/penpot.git
synced 2026-09-25 21:36:15 +00:00
The plugin WebSocket bridge ignored PENPOT_MCP_SERVER_HOST and bound all interfaces, exposing unauthenticated task dispatch to the network in single-user mode. Pass mcpServer.host into WebSocketServer, mirroring the ReplServer fix, so the bridge binds localhost by default and 0.0.0.0 only on explicit opt-in. Closes #11603. AI-assisted-by: muse-spark-1.3-contributor
Penpot MCP Server
A Model Context Protocol (MCP) server that provides Penpot integration capabilities for AI clients supporting the model context protocol (MCP).
Setup
-
Install Dependencies
pnpm install -
Build the Project
pnpm run build -
Run the Server
pnpm run start
Penpot Plugin API REPL
The MCP server includes a REPL interface for testing Penpot Plugin API calls. To use it, connect to the URL reported at startup.