The Model Context Protocol is the plug most AI coding agents now use to reach tools: your design file, your issue tracker, your database. This week three stories about it trended at once, and together they say something a frontend developer should know before building a workflow on top of it. An open protocol does not mean open access. The server decides who gets in.
What happened
The loudest story came from Figma. The pi-mcp-adapter project, which connects the Pi coding agent to MCP servers, merged a pull request (https://github.com/nicobailon/pi-mcp-adapter/pull/750) after Figma's remote MCP server started rejecting Pi at sign-in. The error is blunt: "Dynamic Client Registration rejected (HTTP 403): Forbidden". The PR states that Figma has paused approving new clients, and the adapter now sends Pi users to Figma's desktop app instead. The story reached the Hacker News front page as "Figma restricts MCP access to whitelisted clients, excluding Pi", with 172 points and 98 comments (https://news.ycombinator.com/item?id=49922729).
Figma's own documentation is the primary source here, and it says it plainly: "Only clients listed in the Figma MCP Catalog like VS Code, Cursor, or Claude Code can connect to the Figma MCP Server" (https://developers.figma.com/docs/figma-mcp-server/remote-server-installation/). The page names Claude Code, Codex by OpenAI, Cursor, VS Code and Xcode. A developer with a new client can "join the waitlist". There is no date on that page, and no mention of a pause; that part comes only from the PR.
The irony is in the timing. The day before the PR merged, Earendil, the company behind Pi, published "You said no MCP" (https://earendil.com/posts/you-said-no-mcp/), reversing its earlier stance against MCP and moving it into Pi's core. That post reached 669 points on Hacker News. Its demo ran Linear's MCP server alongside Jev inside Pi, and worked through 167 open issues with 331 tool calls across 4 parallel workers. So Pi committed to MCP and, within a day, met a server that would not let it connect.
The third story is quieter. context-mode (https://github.com/mksglu/context-mode), an MCP server plus hooks that sandboxes tool output for coding agents, was on GitHub trending. It exists for a reason that has nothing to do with access and everything to do with cost: MCP tool output fills the context window.
How it works
MCP servers come in two shapes. A local server runs on your machine and your agent talks to it directly. A remote server runs on the vendor's infrastructure, and your agent must authenticate first, usually through OAuth.
OAuth has a step most people never see: client registration. Before an app can ask you to log in, the server has to know the app. MCP allows Dynamic Client Registration, where a new client registers itself on the fly. That is what makes MCP feel open: any agent can show up and ask. But registration is also the server's checkpoint. If the server only accepts registrations from clients on its list, everyone else gets a 403 before a single tool is called. That is exactly what Pi hit.
Figma's desktop app is the other path. It runs a local MCP server at http://127.0.0.1:3845/mcp with no OAuth at all, and the adapter now checks that port with a 1.5 second timeout before falling back to it. No registration, so no gatekeeper. The trade is that you need the desktop app open, and the remote server is the one Figma documents with write access: "create and modify native Figma content directly".
Why someone building web apps with AI should care
Figma-to-code is the frontend use of MCP. If your workflow is "agent reads the design, writes the component", the Figma server is the first tool in the chain. Three practical things follow.
First, check the client before the workflow. If you are building a design-to-code pipeline, the agent you pick decides whether the remote server will talk to you at all. The listed clients will work today. Anything else is a waitlist.
Second, know your fallback. The local desktop server is still there, and for reading designs it may be all you need. It is worth knowing which one your setup uses, because a pipeline that silently depends on the remote server breaks the day your client changes.
Third, measure context before adding servers. context-mode claims a 98% cut in tool-output size, with its own example going from 315 KB to 5.4 KB, across 17 platforms including Claude Code, Cursor, Codex CLI, Gemini CLI and Pi. That is the project's own claim on its own examples. But the fact that a tool like this exists, and trends, tells you the problem is real: every MCP server you connect costs tokens on every call.
What is not known yet
Whether Figma will reopen new-client approvals, and when. Only the PR says "paused"; Figma's page says "waitlist" and gives no date.
Whether reading and writing really split along desktop versus remote. Hacker News commenters say so. Figma's documentation lists write access on the remote server but does not compare the two.
One commenter says Pi connected after setting its client name to "Codex". That is unconfirmed, and it is spoofing another product's identity to get past a vendor's check. I would not build on it, and I would not recommend it.
And context-mode's 98% has no independent measurement yet.
My take
This is Amar. I build most of my own automation on MCP: my social, email and blog tools run as one MCP server that my agent calls every day. So I read this story as a builder, and my view is that Figma is not doing anything strange. A remote server with write access to someone's design files should know who is writing. I would want the same for mine.
What bothers me is the shape of the lock, not the lock. A 403 at registration, a "paused" in a PR and a "waitlist" in the docs is three different messages for one decision. If you are a vendor gating an MCP server, publish the list, the criteria and a date. If you are a frontend developer, treat the remote server as a dependency someone else controls, keep the local path working, and pick the agent after you have checked which servers it can actually reach. The protocol is open. The doors are not, and that is fine, as long as they are labelled.
