Before you start
Who can use this feature
Available on the Organization and Enterprise plans.
Organization admins only.
Anthropic models only.
Normally, the Figma MCP server requires each user to follow an OAuth login flow to get access. However, you may want to manage this access centrally, so members sign in once through your identity provider and aren't interrupted by repeated login and consent prompts.
You can do this with Cross App Access (XAA). XAA enables enterprise-managed authorization, a way to centralize MCP access in Okta and remove sign-in friction. Instead of each member authorizing the Figma connector on their own, access is brokered by Okta: a member signs in once through Okta, and Claude can then work across approved MCP servers without asking that member to authorize again.
To set up enterprise-managed auth with Okta XAA:
- Set up SAML SSO with Okta for your organization.
- Follow Okta's guide to set up enterprise-managed auth.
- In Figma, from the file browser, click Admin.
- Select Settings in the left sidebar.
- In the Login and provisioning section, click OIDC Issuer URL.
- Enter your Okta base tenant URL.
- Click Save.
Note: For additional information about enterprise-managed auth and Claude, see Anthropic's guide about authorizing MCP connectors for your entire organization.