Install
Inside DeepSeek Harness, with dsh-market
dsh plugin --profile web add dshmarket
Or from the command line
dsh plugin --profile web add dsh-figma-mcp
Installing runs third-party code with your own permissions — it can read your files, use your credentials and reach the network. Review the source first, and pin a commit (github:owner/repo#sha) when you can.
README
Overview
The one-click Figma MCP connector for DSH, paste a Figma link into chat, and the Agent can read/write nodes, layers, variables, and styles, generate React/Vue code, secure OAuth login, token stored locally, auto-reminded before expiry, with a built-in Skill to guide the way.
Install
From npm
dsh plugin add dsh-figma-mcp
From GitHub
dsh plugin add github:lubanqihao9875/dsh-figma-mcp
Local development
Clone the repo and enter the directory first:
git clone https://github.com/lubanqihao9875/dsh-figma-mcp.git
cd dsh-figma-mcp
Then link the current directory into DSH:
# macOS / Linux
dsh plugin add link:$(pwd)
# Windows (PowerShell)
dsh plugin add link:"$PWD"
After installing, restart DSH. The "Settings → DSH Figma MCP" card appears — click "Connect Figma" to complete the authorization.
Card
The card has two sections: "Connection" (authorization state) and "Skill" (whether the Figma MCP usage is injected into the Agent skill list)
Connection
| Status chip | Meaning | Action |
|---|---|---|
| Not connected | Not yet authorized | Click "Connect Figma" to open the browser |
| Connected | Token is valid | Nothing to do |
| Expiring soon | Less than 24h left | Suggested: click "Refresh auth" |
| Expired | Token is no longer valid | Click "Reauthorize" |
After authorization the card switches from "Not connected" to "Connected" automatically.
Skill
The "Skill" toggle controls whether dsh-figma-mcp-skill is injected into the Agent's skill list. dsh-figma-mcp-skill tells DSH how to pick the mcp__figma__* tools. It is on by default.
Expiry and refresh
The token lifetime follows what Figma issues. As the token approaches expiry, the status chip turns yellow ("Expiring soon"). "Refresh auth" silently renews the token in the background without opening a browser; only when it is completely invalid do you need "Reauthorize" to go through the browser flow again.
Disconnect and uninstall
"Disconnect" only clears local data: the token and refresh credentials in the patch file are deleted immediately. Click Disconnect before uninstalling the plugin, otherwise a still-valid token will remain in the patch file.
Usage examples
After connecting, paste a Figma link directly into a DSH chat and tell the Agent what you want. The Agent automatically calls the mcp__figma__* tools to read content and run the task.
Read design content
Show me what's in this design file: your Figma file URL (e.g.
https://www.figma.com/design/<file-id>)
Extract copy and build an i18n table
Pull every button and heading label from the Figma file above and produce a Chinese/English i18n table
Generate code from the design
Convert the Figma page above into React code
Security
- The token is stored in
$DSH_HOME/figma-mcp/config.json, written atomically with0o600permissions. Do not share the config file, the token, or related screenshots.
Troubleshooting
- Clicking "Connect Figma" does not open a browser: check whether a popup blocker stopped the OAuth window.
Comments
Comments live in GitHub Discussions. Sign in with GitHub to post or react.