# Figma SCIM MCP connector

The Figma SCIM connector brings Figma user accounts and groups into Elaichi, so Claude, ChatGPT, Cursor, and the Elaichi Agent can list, create, update, and remove Figma members and groups within each person's own access, with every change logged.

Source: https://elaichi.ai/connectors/figmascim/

## Facts

| | |
| --- | --- |
| Application | Figma SCIM |
| Category | Design |
| AI tools | 14 |
| Authentication | Connects with an API key |
| Bring your own OAuth app | No |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. Connected tools are never listed one by one, however few there are. The endpoint advertises `search_tools` and `execute_tool` instead |

## What you can ask once Figma SCIM is connected

- List every Figma user who is not in a group yet
- Add the new designers to the Brand group in Figma
- Remove Priya's Figma account, she left on Friday

## Connect Figma SCIM in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Figma SCIM.
2. Optionally set Share with, then press Connect.
3. Paste a Figma SCIM API key. One person generates a token in Figma SCIM and pastes it once. Everyone else works through Share with, and never sees it.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Figma SCIM tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Figma SCIM MCP connector for Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Figma SCIM MCP connector for ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Figma SCIM MCP connector for Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Figma SCIM to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Every scope the client asks for starts ticked except "Delete data and remove access", which you tick yourself. Calling a Figma SCIM tool needs "Run your connected tools". Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Figma SCIM through Elaichi

### Provision a new hire's Figma account

IT. Create the Figma user on day one and drop them into the right groups, without opening the admin console or waiting for a ticket to move.

### Remove a leaver from Figma the same day

People ops. Ask for someone's Figma account to be removed as part of offboarding, and confirm it is gone before the day ends.

### Run a Figma access review in minutes

Security. Pull every Figma user and group, spot accounts that should not be there, and tidy group membership while the list is in front of you.

### Keep Figma groups matched to project teams

Design ops. Add a contractor to the Brand group for a launch, then take them out when the work wraps, with the change recorded.

### Check who is actually holding a Figma seat

Finance. List Figma users by status to see which seats are in use, so license renewals are based on real headcount rather than a guess.

### Answer who changed what in Figma

Compliance. Every user created, updated or removed through the connector is in the audit log with a name and a time, ready for the next audit request.

## Elaichi vs Zapier MCP vs Composio for Figma SCIM

All three can connect Figma SCIM to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

| What to check | Elaichi | Zapier MCP | Composio |
| --- | --- | --- | --- |
| Where the AI connects | One address for the whole organization. Endpoint: https://api.elaichi.ai/mcp | A server per member, created at sign-in. | An MCP endpoint per team, or an SDK. |
| Control over Figma SCIM tools | Allow or restrict single Figma SCIM tools, per role or user. | App and action restrictions on the account. | Role permissions, down to the action. |
| Record of calls | One audit entry per Figma SCIM call. | A History tab of tool calls. | A log of every tool call. |
| Single sign-on | SAML or OIDC, plus SCIM, on Gold. | SAML on Enterprise. | SAML and OIDC on Enterprise. |
| Price | $15 per user per month. | 2 tasks per successful call. | Billed per tool call. |

Sources: Zapier MCP [docs](https://docs.zapier.com/mcp/get-started/quickstart), [security](https://docs.zapier.com/mcp/manage/security), [usage](https://docs.zapier.com/mcp/features/usage); Composio [docs](https://docs.composio.dev/docs/composio-connect), [gateway](https://composio.dev/mcp-gateway), [enterprise](https://composio.dev/enterprise), [pricing](https://composio.dev/pricing). Checked September 2026.

Longer take: [Zapier MCP alternative](/blog/zapier-mcp-alternative/) and [when you don't need an MCP gateway](/blog/when-you-dont-need-an-mcp-gateway/).

## Frequently asked questions

### How do I connect Figma SCIM to Claude?

Connect Figma SCIM in Elaichi by pasting the Figma SCIM API key from your Figma organization settings, with no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste the endpoint https://api.elaichi.ai/mcp. Sign in to Elaichi as yourself and Figma SCIM is available in the conversation.

### Does Figma SCIM work with ChatGPT and Cursor as well as Claude?

Yes. Figma SCIM is connected once in Elaichi, and the same endpoint, https://api.elaichi.ai/mcp, is pasted into Claude, ChatGPT, Cursor, any other MCP client, and the Elaichi Agent. Each person signs in as themselves in every client.

### What can an AI agent actually do with my Figma SCIM data?

With Figma SCIM connected, an agent can list the Figma users and groups in your organization, look up a single person, create a new user, update their details, add them to or remove them from groups, and delete an account when someone leaves. It can also check the provisioning configuration. Short, concrete asks such as "remove Priya's Figma account" work better than long sentences.

### Does connecting Figma SCIM give the AI control of my whole Figma organization?

No. Figma SCIM in Elaichi runs within the scope of the API key that was connected and the access of the person who signed in, and Elaichi can narrow that further by team or by action. Elaichi never widens what Figma allows, and provisioning actions never touch design files.

### Can my team share one Figma SCIM connection?

Yes. One admin connects Figma SCIM in Elaichi and shares it with a team, and nobody else ever handles the API key. Each teammate still signs in to Elaichi as themselves, so every Figma user or group change in the audit log carries their own name.

### Can I stop an agent from deleting or changing things in Figma SCIM?

Yes. Restrictions in Elaichi apply per action, so you can allow listing Figma users and groups while blocking deletes or updates. A restricted action is left out of the AI client's tool list entirely and cannot be called, whatever the prompt says.

### What happens to a Figma SCIM connection when someone leaves?

Offboarding that person in Elaichi ends their access to Figma SCIM at once, across every client they used. A shared Figma SCIM connection keeps working for everyone else on the team. Disconnecting Figma SCIM once in Elaichi removes it from Claude, ChatGPT, Cursor, and every other client at the same time.

### Does the Figma SCIM MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Figma SCIM is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

### Is Elaichi an alternative to Zapier MCP for Figma SCIM?

Yes. Both let Claude, ChatGPT or Cursor use Figma SCIM. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Figma SCIM call.

### How is Elaichi different from Composio for Figma SCIM?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Figma SCIM: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

## All 14 Figma SCIM tools

Every tool below is callable through https://api.elaichi.ai/mcp once Figma SCIM is connected, subject to the toolbox it is in and the restrictions on the caller.

- **List all Figma SCIM users** (List). List SCIM-provisioned users in the Figma organization (GET /scim/v2/{tenant}/Users). Returns SCIM user resources with id, userName (email), displayName, active, seat role, name, externalId, enterprise attributes (department, cost center, organization) and the figmaAdmin flag. Filter with userName eq "email" or externalId eq "value"; pages with count (max 3000) and startIndex. Calling this also binds existing Figma accounts to SCIM.

- **Get single Figma SCIM user by ID** (Get). Get one SCIM user in Figma by Figma user id (GET /scim/v2/{tenant}/Users/{id}). Returns the full SCIM user resource. Required: id. To find an id, list users with a userName filter.

- **Delete a Figma SCIM user by ID** (Delete). Permanently delete a user from Figma and from the SCIM provisioning log (DELETE /scim/v2/{tenant}/Users/{id}). To keep the account but revoke access, deactivate instead with partial_update (active=false). Required: id. Returns 204 with no body.

- **Create a Figma SCIM user** (Create). Provision a user in Figma via SCIM (POST /scim/v2/{tenant}/Users). If a Figma account with that email already exists it is bound to SCIM and updated. Required: schemas, userName (email) and active; optional seat role (Enterprise plan), display name, title, name, externalId, enterprise attributes and figmaAdmin. Returns the created user with its Figma id.

- **Update a Figma SCIM user by ID** (Update). Overwrite all attributes of a SCIM user in Figma (PUT /scim/v2/{tenant}/Users/{id}). Send the complete user; attributes omitted are cleared. Common uses: change email (userName), display name, seat role, cost center. Required: id, schemas, userName, active. Returns the updated user.

- **Figma SCIM users partial update** (Update). Change selected attributes of a SCIM user in Figma without resending everything (PATCH /scim/v2/{tenant}/Users/{id}, SCIM PatchOp). Example: replace roles with [{"type":"seatType","value":"Dev"}] to change the seat, or replace active with false to deactivate. Required: id (query) and Operations. Returns the updated user.

- **List all Figma SCIM groups** (List). List SCIM-managed groups in the Figma organization (GET /scim/v2/{tenant}/Groups). Each group has id, displayName, external_id and members (Figma user ids with display emails). Groups whose displayName matches a Figma workspace or billing group are linked to it. Filter with displayName eq "name" or externalId eq "value"; pages with count and startIndex.

- **Get single Figma SCIM group by ID** (Get). Get one SCIM group in Figma by group id (GET /scim/v2/{tenant}/Groups/{id}). Returns displayName, external_id and the member list. Required: id.

- **Create a Figma SCIM group** (Create). Create a SCIM group in Figma (POST /scim/v2/{tenant}/Groups). If displayName matches an existing Figma workspace or billing group (case sensitive) the group is linked to it and members inherit it. Required: schemas and displayName; optional externalId and members (Figma user ids). Returns the group with its id.

- **Update a Figma SCIM group by ID** (Update). Overwrite a SCIM group in Figma (PUT /scim/v2/{tenant}/Groups/{id}): display name, externalId and the full member list. Members added inherit the linked workspace or billing group; members omitted lose it. Required: id, schemas, displayName. Returns the updated group.

- **Figma SCIM groups partial update** (Update). Change selected attributes or membership of a SCIM group in Figma (PATCH /scim/v2/{tenant}/Groups/{id}, SCIM PatchOp). Example: replace value {"displayName": "New name"}, or add path members value [{"value": "&lt;user id&gt;"}]. Required: id (query) and Operations. Returns the updated group.

- **Delete a Figma SCIM group by ID** (Delete). Permanently delete a SCIM group from Figma and the SCIM provisioning log (DELETE /scim/v2/{tenant}/Groups/{id}). Members are not deleted. Required: id. Returns 204 with no body.

- **List all Figma SCIM service provider config** (List). Get Figma's SCIM service provider configuration (GET /scim/v2/{tenant}/ServiceProviderConfig): which SCIM features are supported (patch yes, filter yes with max 200 results, bulk no, sort no, change password no) and the bearer token authentication scheme. Useful to verify the tenant id and token before provisioning. No parameters.

- **Figma SCIM tenant validate** (Validate). Check whether the connected Figma SCIM tenant ID is valid (GET /scim/v2/{tenant_id}). Takes no inputs: the tenant ID and API token come from the connection. A successful (HTTP 200) response means the tenant ID is valid for this token. An error means it is not: 400 when the tenant ID is malformed (it must be numeric), 404 when it is well-formed but unknown or not accessible with this token. Use it as a connection health check before provisioning users or groups.
