Skip to content

Connect Figma SCIM to Claude: Control Group Membership & Roles

Learn how to connect Figma SCIM to Claude via a managed MCP server to automate user provisioning, audit seat roles, and control group memberships securely.

Roopendra Talekar Roopendra Talekar · · 9 min read

If your IT or DevOps team needs to connect Figma SCIM to Claude to automate user provisioning, audit seat roles, or control group memberships, you need a Model Context Protocol (MCP) server. This server acts as the translation layer between Claude's tool calls and Figma's SCIM (System for Cross-domain Identity Management) REST APIs. You can either build and maintain this infrastructure yourself, or use a managed integration platform like Truto to dynamically generate a secure, authenticated MCP server URL. If your team uses ChatGPT, check out our guide on connecting Figma SCIM to ChatGPT or explore our broader architectural overview on connecting Figma SCIM to AI Agents.

Giving a Large Language Model (LLM) read and write access to your organization's identity management ecosystem is a serious engineering challenge. You have to handle API token lifecycles, map massive, nested SCIM JSON schemas to MCP tool definitions, and deal with Figma's strict API quotas. Every time an endpoint shifts or a schema requirement changes, you have to update your server code, redeploy, and test the integration.

This guide breaks down exactly how to use Truto to generate a secure, managed MCP server for Figma SCIM, connect it natively to Claude Desktop, and execute complex identity management workflows using natural language.

The Engineering Reality of the Figma SCIM API

A custom MCP server is a self-hosted integration layer. While the open MCP standard provides a predictable way for models to discover tools, the reality of implementing it against a specific vendor's SCIM API is painful. SCIM is an IETF standard (RFC 7643 and 7644), but every vendor implements it with slight variations.

If you decide to build a custom MCP server for Figma SCIM, here are the specific integration challenges you will face:

The Complexity of SCIM Patch Operations Figma SCIM supports both full updates (PUT) and partial updates (PATCH). The PATCH endpoint (/scim/v2/{tenant}/Users/{id}) requires the standard SCIM PatchOp syntax. For example, replacing a user's seat role requires a payload like [{"type":"seatType","value":"Dev"}]. This nested array-of-objects structure is notoriously difficult for LLMs to construct correctly without strict JSON Schema enforcement. A managed MCP server exposes tools like figma_scim_users_partial_update with exact schema definitions that force Claude to generate the correct PatchOp arrays, preventing hallucinated payload structures.

Account Binding and State Transitions Figma SCIM has unique behavior when provisioning users. If you send a POST /scim/v2/{tenant}/Users request to create a user, and a Figma account with that email already exists, Figma does not return a 409 Conflict. Instead, it silently binds the existing account to SCIM and updates its attributes. An LLM needs explicit instructions in the tool description to understand this state transition so it can accurately interpret the API response and report back to the user.

Rate Limits and 429 Handling Figma enforces rate limits on its SCIM API to protect infrastructure. When building an MCP server, you cannot assume every request will succeed. It is important to note that Truto does not retry, throttle, or apply backoff on rate limit errors automatically. When the Figma SCIM API returns an HTTP 429 Too Many Requests, Truto passes that error directly to the caller. Truto normalizes the upstream rate limit information into standardized headers (ratelimit-limit, ratelimit-remaining, ratelimit-reset) per the IETF specification. The LLM or the agent orchestration framework is responsible for reading these headers and executing the retry/backoff logic.

Tenant Validation Every SCIM request to Figma requires a numeric tenant ID in the path (/scim/v2/{tenant_id}/...). If this ID is malformed or the provided Bearer token lacks access to it, the API will reject the request. Building a pre-flight validation check into your MCP server is critical to prevent cascading failures during bulk provisioning tasks.

Generating the Figma SCIM MCP Server

Truto's MCP servers feature turns your connected Figma SCIM integration into an MCP-compatible tool server instantly. The tool generation is dynamic and documentation-driven. Rather than hand-coding tool definitions, Truto derives them from the integration's defined resources and human-readable documentation records.

You can generate the MCP server in two ways: via the Truto UI or programmatically via the API.

Method 1: Via the Truto UI

This is the fastest method for internal IT teams and administrators setting up Claude Desktop.

  1. Log into your Truto dashboard.
  2. Navigate to the Integrated Accounts page and select your connected Figma SCIM account.
  3. Click the MCP Servers tab.
  4. Click Create MCP Server.
  5. Select your desired configuration. You can restrict the server to specific methods (e.g., read-only) or tag groups.
  6. Click Generate and copy the resulting MCP server URL (e.g., https://api.truto.one/mcp/abc123xyz...).

Method 2: Via the Truto API

For platform engineers building multi-tenant AI agents, you can generate MCP servers programmatically. Make a POST request to the /integrated-account/:id/mcp endpoint.

// Example: Generating a read-only Figma SCIM MCP Server
const response = await fetch('https://api.truto.one/integrated-account/YOUR_ACCOUNT_ID/mcp', {
  method: 'POST',
  headers: {
    'Authorization': 'Bearer YOUR_TRUTO_API_TOKEN',
    'Content-Type': 'application/json'
  },
  body: JSON.stringify({
    name: "Figma SCIM - Read Only Audit",
    config: { 
      methods: ["read", "list", "get"]
    },
    expires_at: "2026-12-31T23:59:59Z"
  })
});
 
const data = await response.json();
console.log(data.url); // The MCP server URL to pass to Claude

The resulting URL contains a cryptographic token that securely identifies the integrated account and enforces the requested configuration.

Connecting the MCP Server to Claude

Once you have your Truto MCP server URL, you need to register it with your AI client. The standard MCP JSON-RPC 2.0 protocol allows Claude to send an initialize request, discover the available tools via tools/list, and execute them via tools/call.

Method A: Via the Claude UI (Desktop/Web)

If you are using Claude Desktop or an enterprise workspace, connecting the server is entirely UI-driven.

  1. Open Claude and navigate to Settings.
  2. Go to Integrations -> Add MCP Server (or Connectors -> Add custom connector depending on your tier).
  3. Paste the Truto MCP Server URL.
  4. Click Add.

Claude will immediately perform a handshake with the server and load the Figma SCIM tools into its context window. No additional authentication is required unless you configured the server to require an API token.

Method B: Via Manual Config File

If you are running Claude Desktop locally and prefer file-based configuration, or if you are using Cursor, you can edit your claude_desktop_config.json file to use the Server-Sent Events (SSE) transport.

{
  "mcpServers": {
    "figma-scim-prod": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-sse",
        "--url",
        "https://api.truto.one/mcp/YOUR_SECURE_TOKEN"
      ]
    }
  }
}

Restart Claude Desktop. The tools will now be available in your chat interface.

Hero Tools for Figma SCIM

When Claude calls tools/list, Truto dynamically generates the tool schemas. All arguments arrive in a flat input namespace, and Truto automatically routes them to the correct query parameters or HTTP body based on the integration's schema.

Here are the most critical Figma SCIM tools available to your AI agent.

figma_scim_tenant_validate

This tool checks whether the connected Figma SCIM tenant ID and bearer token are valid. It is a critical first step before attempting to provision users. A successful response means the tenant ID is valid and accessible. A 400 means the tenant ID is malformed (it must be numeric), and a 404 means it is unknown.

"Claude, before we run the bulk provisioning script, please validate our Figma SCIM tenant connection to ensure our API token and tenant ID are correct."

list_all_figma_scim_users

Retrieves SCIM-provisioned users in the Figma organization. It returns full SCIM user resources including id, userName (email), active status, seat role, and enterprise attributes like department and costCenter. Claude can use the userName eq "email" filter to find specific users.

"Can you list all active Figma SCIM users in the Engineering department? Please filter the results and show me their current seat roles."

create_a_figma_scim_user

Provisions a new user in Figma via SCIM. If a Figma account with the requested email already exists, Figma automatically binds it to SCIM and updates the attributes. It requires the user's email and active status, and accepts optional parameters for seat role (on Enterprise plans) and figmaAdmin flags.

"We have a new hire starting today. Please create a Figma SCIM user for alex.chen@company.com, set them to active, assign them a 'Dev' seat role, and set their cost center to 'R&D'."

figma_scim_users_partial_update

Executes a PATCH request to change selected attributes of a user without overwriting the entire resource. This is the preferred method for deactivating users (replacing active with false) or upgrading seat types, utilizing standard SCIM PatchOp syntax.

"Alex Chen is leaving the company. Please locate his Figma SCIM user ID by his email, and then perform a partial update to set his active status to false. Do not delete his account, just revoke access."

list_all_figma_scim_groups

Lists SCIM-managed groups in the Figma organization. Each group includes an id, displayName, and a list of members. Groups whose display names perfectly match an existing Figma workspace or billing group are automatically linked to it.

"Can you list all Figma SCIM groups and find the one named 'Product Design Workspace'? I need to see how many members currently belong to it."

create_a_figma_scim_group

Creates a new SCIM group in Figma. If the displayName matches an existing Figma workspace (case sensitive), the group is linked, and any members added to this group will inherit access to that workspace.

"Create a new Figma SCIM group called 'External Contractors'. Once created, add the user ID 109348 to this group as its first member."

To view the complete inventory of available Figma SCIM tools and their exact JSON Schema definitions, visit the Figma SCIM integration page.

Workflows in Action

MCP tools become incredibly powerful when Claude chains them together to solve multi-step IT support tickets or compliance tasks.

Scenario 1: Onboarding a New Product Designer

IT administrators frequently receive requests to provision new employees with the exact same access as their peers.

"We just hired Sarah for the design team (sarah.j@company.com). Please provision her a Figma account with a full design seat. Then, figure out which SCIM group the rest of the 'Product Design' team is in, and add her to that group so she inherits the right workspaces."

How Claude executes this:

  1. Calls create_a_figma_scim_user with userName: "sarah.j@company.com", active: true, and the seat role set to the design tier.
  2. Calls list_all_figma_scim_groups filtering by displayName eq "Product Design" to retrieve the group ID.
  3. Calls figma_scim_groups_partial_update targeting the retrieved group ID, passing a SCIM PatchOp to add Sarah's newly created Figma user ID to the members array.
sequenceDiagram
    participant User as IT Admin
    participant Claude as Claude
    participant Figma as Figma SCIM
    User->>Claude: Provision Sarah & add to Design group
    Claude->>Figma: POST /scim/v2/{tenant}/Users (Sarah)
    Figma-->>Claude: Returns User ID (12345)
    Claude->>Figma: GET /scim/v2/{tenant}/Groups?filter=displayName eq "Product Design"
    Figma-->>Claude: Returns Group ID (67890)
    Claude->>Figma: PATCH /scim/v2/{tenant}/Groups/67890 (Add member 12345)
    Figma-->>Claude: 200 OK
    Claude-->>User: Setup complete.

Scenario 2: Offboarding and License Reclamation

When an employee leaves, security compliance dictates that access must be revoked immediately, but their historical assets should remain intact.

"Marcus (marcus.w@company.com) is offboarding today. Please revoke his access to Figma, but do not permanently delete his account. Just deactivate him so we free up the license."

How Claude executes this:

  1. Calls list_all_figma_scim_users with the filter userName eq "marcus.w@company.com" to retrieve Marcus's internal Figma user ID.
  2. Calls figma_scim_users_partial_update using Marcus's ID, sending a PatchOp to replace the active attribute with false.
  3. Claude confirms to the user that the account has been deactivated, ensuring the seat license is reclaimed without destroying Marcus's design files.

Security and Access Control

Providing an LLM with write access to your corporate identity provider requires strict guardrails. Truto's MCP architecture provides multiple layers of access control that are enforced at the server level, preventing Claude from executing unauthorized operations.

  • Method Filtering: When generating the MCP server, you can restrict it to specific operations via config.methods. Setting this to ["read"] ensures Claude can only call list and get operations, making the server strictly read-only for audit tasks.
  • Tag Filtering: You can restrict the server to only expose tools related to specific resource tags. For example, you could expose users tools but hide groups tools entirely.
  • Extra Authentication (require_api_token_auth): By default, possessing the MCP URL is enough to connect. For high-security environments, enabling require_api_token_auth forces the client to also provide a valid Truto API Bearer token in the headers, adding a secondary identity check.
  • Automatic Expiration: Setting an expires_at timestamp creates a short-lived MCP server. This is ideal for giving a temporary contractor or an automated CI/CD pipeline access to SCIM tools for a limited window, after which the server automatically deletes itself.

Rethink How You Build Agentic Integrations

Connecting Figma SCIM to Claude transforms identity management from a series of manual clicks in an admin portal into a conversational, automated workflow. However, building the required MCP infrastructure from scratch - parsing SCIM schemas, handling PatchOp formatting, and managing token refreshes - is a massive distraction from building your core AI product.

By utilizing a managed integration platform, you offload the entire API lifecycle. You get dynamic, documentation-driven tools that update automatically when schemas change, complete with enterprise-grade access controls.

Stop wrestling with identity APIs and start shipping agentic workflows. Let your LLMs do the heavy lifting while your managed MCP server handles the protocol.

FAQ

Does Truto automatically handle Figma SCIM rate limits for Claude?
No. Truto passes HTTP 429 Too Many Requests errors directly back to the caller. Truto normalizes the upstream rate limit information into standard headers (ratelimit-limit, ratelimit-remaining, ratelimit-reset), and the AI agent is responsible for executing retry and backoff logic.
How do I restrict Claude to only reading Figma SCIM data?
When creating the MCP server in Truto, you can use method filtering by setting config.methods to ["read"]. This ensures only safe operations like 'list' and 'get' are exposed as tools to the LLM.
Can I use the Figma SCIM tools to bind existing accounts?
Yes. When you use the create_a_figma_scim_user tool and provide an email that already exists in Figma, the API silently binds that existing account to SCIM and updates its attributes rather than throwing a conflict error.
Is it secure to share the Truto MCP Server URL?
The URL contains a cryptographic token for authentication. However, for maximum security, you can configure the server with require_api_token_auth: true, which forces the client to also supply a valid Truto API Bearer token in the connection headers.

More from our Blog