‹ BackHN Continuity

Thread

Figma restricts MCP access to whitelisted clients, excluding Pi

187 points · 106 comments · thdr

  1. SkyPuncher · · focus · HN ↗
    I do security review for my company. I suspect this is a means of containing OAuth redirect vulnerabilities. We basically needed to do the same thing with our MCP server.

    The security problem is two fold: (1) companies want control over where their data goes. Figma allowing any MCP creates problems (2) open redirects can create phishing issues. If your using Pi, you’re probably thinking of this. Most users aren’t.

    For us, we decided to do an allowlist pattern because it was a reasonable tradeoff. The solution is allowing per-tenant client configuration, but that comes with its own set of issues (dev time, support, maintenance, etc). When nearly all of the money is flowing through a handful of well-known MCPs there’s little reason to out effort into supporting every MCP.

    1. hparadiz · · focus · HN ↗
      We need OIDC tokens generated at the SSO placed on the dev environment upon user authentication and then have those OIDCs reusable among multiple mcps. People don't wanna login to 10 different mcps every morning.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.