Skip to content
← Back to documentation
Technical Reference

Figma

Collaborative interface design tool

CategoryOther
AuthenticationOAuth 2.0
Version0.6.0
Published scopes4 published scopes
Last updatedSeptember 19, 2026

Overview

Connect Figma with Flows360

Collaborative interface design tool

Use the Figma connector to include its declared actions and events in Flows360 workflows without duplicating the integration logic inside each consuming system. This pinned connector version currently exposes 4 actions and 1 trigger.

Available actions

  • Get File
  • Get File Comments
  • Post File Comment
  • Custom API Call

Available triggers

  • New Comment (Figma Professional plan only)

The capability list above is generated from the exact reviewed connector package so the public description stays aligned with the version Flows360 operates.

Technical guide

Technical reference

Package identity

  • Connector: Figma
  • Package: @activepieces/piece-figma@0.6.0
  • Exact artifact digest: sha256:c07d9dc79e77d588e583e3413f55fc9e3b0740e8aae49bc709a4847c36f5ae5b
  • Runtime: Activepieces-compatible deterministic worker
  • Source: the exact reviewed Activepieces source

Authentication

OAUTH2. Connection values are tenant-specific and remain in the consuming Studio instance; CDK stores definitions and field metadata, not customer credential values.

Action contracts

  • Get File (get_file), Get file Classification: read.
  • Get File Comments (get_comments), Get file comments Classification: read.
  • Post File Comment (post_comment), Post file comment Classification: read.
  • Custom API Call (custom_api_call), Make a custom API call to a specific endpoint Classification: read.

Trigger contracts

  • New Comment (Figma Professional plan only), webhook.

Verification

Deterministic execution evidence is recorded for the pinned artifact, including 1 exercised action entrypoint and 0 exercised trigger entrypoints.

Capability summary

AuthenticationOAuth 2.0
Supported objects5
Supported actions4
Triggers1

Authentication

Authentication method: OAuth 2.0

Required scopes

file_content:readfile_metadata:readfile_comments:readfile_comments:write

Authentication profiles

connection · oauth2

OAuth scopes: file_content:read, file_metadata:read, file_comments:read, file_comments:write

Supported objects

ObjectReadWriteNotes
Get File Yes No Get file
Get File Comments Yes No Get file comments
Post File Comment Yes No Post file comment
Custom API Call Yes No Make a custom API call to a specific endpoint
New Comment (Figma Professional plan only) Yes No webhook trigger declared by the pinned package.

Supported actions

Get File · Read

Get file

get_file · Risk: low · Retry: safe

Inputs

  • file_key · string · Required, The Figma file key (copy from Figma file URL)
Get File Comments · Read

Get file comments

get_comments · Risk: low · Retry: safe

Inputs

  • file_key · string · Required, The Figma file key (copy from Figma file URL)
Post File Comment · Read

Post file comment

post_comment · Risk: low · Retry: safe

Inputs

  • file_key · string · Required, The Figma file key (copy from Figma file URL)
  • message · string · Required, Your comment
Custom API Call · Read

Make a custom API call to a specific endpoint

custom_api_call · Risk: low · Retry: safe

Inputs

  • url · object · Required
  • method · string · Required
  • headers · object · Optional, Authorization headers are injected automatically from your connection.
  • queryParams · object · Optional, Appended to the URL as ?key=value.
  • body_type · string · Optional
  • body · object · Optional
  • response_is_binary · boolean · Optional, Enable for files like PDFs, images, etc.
  • failsafe · boolean · Optional, On a failed request, output the error instead of failing the step.
  • timeout · number · Optional, Seconds to wait for a response. Empty: up to the flow limit (10 min).
  • followRedirects · boolean · Optional, Follow 3xx redirects instead of returning them as the response.

Triggers

New Comment (Figma Professional plan only) · Webhook

Triggers when a new comment is posted

Inputs

  • team_id · string

Setup

Setup

  1. Add the Figma connector to the workflow in the target Flows360 Studio instance.
  2. Create or select the tenant-specific connection required by the connector. Connection secrets remain in the Studio connection boundary and are not copied into CDK documentation.
  3. Provide the connection fields declared by the pinned package:
  • No provider credential fields are declared by the pinned package.

OAuth scopes

  • file_content:read
  • file_metadata:read
  • file_comments:read
  • file_comments:write
  1. Select the required action or trigger and complete its declared input fields. Required and optional inputs are defined by the exact package schema.
  2. Test the workflow in the appropriate environment before enabling production scheduling or event delivery.

Limitations

Limitations and operational notes

  • This content describes @activepieces/piece-figma@0.6.0; provider behaviour can change independently and should be revalidated when the provider or connector version changes.
  • Only the 4 actions and 1 trigger declared by this pinned package are represented here.
  • Tenant credentials and connection values are not stored in the public connector record.
  • Provider-side permissions, account entitlements, quotas and rate limits remain subject to the connected provider account and are not inferred when the package does not declare them.
  • Deterministic execution evidence is recorded for the pinned artifact, including 1 exercised action entrypoint and 0 exercised trigger entrypoints.

Troubleshooting

Why canu2019t the connector authenticate?

Check the tenant connection in Studio and confirm every required Figma connection field is present. Re-authorise OAuth-based connections if the provider token or consent has expired. Do not place credential values in CDK content or logs.

Why is an action or trigger unavailable?

Confirm that the workflow is using @activepieces/piece-figma@0.6.0 and compare the requested capability with the declared action and trigger list for this version. A capability that is not declared by the pinned package should not be presented as supported.

What should I check after a provider-side change?

Revalidate authentication, required fields, action/trigger behaviour and provider documentation before publishing refreshed connector content or moving a new package version into production.