Skip to content
Skillv1.0.0

figma-prod-checklist

Production readiness checklist for Figma REST API integrations. Use when deploying Figma integrations to production, preparing for launch, or auditing an existing integration for production fitness. T

by jeremylongshore(0) 0 installs
Free
Sign in to install

Free account. Installing gives you the manifest plus copy-paste snippets.

See reviews

About

Imported from jeremylongshore/tons-of-skills-marketplace (skills/.curated/figma-prod-checklist/SKILL.md). Install upstream with npx skills add jeremylongshore/tons-of-skills-marketplace --skill figma-prod-checklist. Copyright stays with the author (MIT).

Figma Production Checklist

Overview

Complete checklist for deploying Figma API integrations to production, covering authentication, error handling, rate limits, monitoring, and rollback.

Prerequisites

  • Staging environment tested and verified
  • Production PAT or OAuth credentials ready
  • Monitoring infrastructure available

Instructions

Step 1: Authentication & Secrets

  • Production PAT stored in secret manager (not env files)
  • PAT uses minimum required scopes (file_content:read, not files:read)
  • PAT expiry tracked (max 90 days) with rotation reminder
  • OAuth refresh token flow tested (if using OAuth)
  • Separate tokens for dev/staging/prod
  • No tokens in client-side code or git history

Step 2: Error Handling

  • All HTTP status codes handled (400, 403, 404, 429, 500)
  • Retry-After header honored on 429 responses
  • Exponential backoff with jitter for transient errors
  • Max retry limit to prevent infinite loops
  • Graceful degradation when Figma is unavailable
  • Error responses do not leak token values in logs

Step 3: Rate Limiting

  • Request queue with concurrency control (max 3-5 concurrent)
  • Batch node IDs in single requests (up to 50 per call)
  • Response caching for frequently accessed files (TTL: 60-300s)
  • Rate limit monitor with proactive throttling
  • No tight loops calling Figma API without delays

Step 4: Monitoring & Health

// Health check endpoint
async function figmaHealthCheck() {
  const start = Date.now();
  try {
    const res = await fetch('https://api.figma.com/v1/me', {
      headers: { 'X-Figma-Token': process.env.FIGMA_PAT! },
      signal: AbortSignal.timeout(5000),
    });
    return {
      status: res.ok ? 'healthy' : 'degraded',
      latencyMs: Date.now() - start,
      httpStatus: res.status,
    };
  } catch (error) {
    return {
      status: 'unhealthy',
      latencyMs: Date.now() - start,
      error: error instanceof Error ? error.message : 'Unknown',
    };
  }
}
  • Health endpoint includes Figma connectivity check
  • Alerts on sustained 429 errors (>5/min)
  • Alerts on 403 errors (token expiry)
  • Alerts on response latency >5s (P95)
  • Dashboard tracks requests/min, error rate, latency

Step 5: Data Handling

  • Image export URLs treated as temporary (expire after 30 days)
  • No PII from Figma stored without user consent
  • File data cached with appropriate TTL
  • Large file responses streamed, not buffered entirely in memory

Step 6: Webhook Production Setup

  • HTTPS endpoint (Figma requires TLS)
  • Passcode verification on every incoming webhook
  • Idempotency handling for duplicate deliveries
  • Quick response (200 within 5s) with async processing
  • Dead letter queue for failed webhook processing

Step 7: Pre-Flight Verification

#!/bin/bash
echo "=== Figma Production Pre-Flight ==="

# 1. Token valid?
STATUS=$(curl -s -o /dev/null -w "%{http_code}" \
  -H "X-Figma-Token: ${FIGMA_PAT}" \
  https://api.figma.com/v1/me)
echo "Auth: $STATUS (expect 200)"

# 2. File accessible?
STATUS=$(curl -s -o /dev/null -w "%{http_code}" \
  -H "X-Figma-Token: ${FIGMA_PAT}" \
  "https://api.figma.com/v1/files/${FIGMA_FILE_KEY}?depth=1")
echo "File: $STATUS (expect 200)"

# 3. Figma status page
echo -n "Figma Status: "
curl -s https://www.figmastatus.com/api/v2/status.json 2>/dev/null \
  | jq -r '.status.description // "Unable to check"'

echo "=== Pre-flight complete ==="

Output

  • All checklist items verified
  • Health check endpoint deployed
  • Monitoring and alerting configured
  • Pre-flight script passing

Error Handling

Alert Condition Severity Action
Auth Failure 403 errors > 0 P1 Rotate PAT immediately
Rate Limited 429 errors > 5/min P2 Reduce request rate; check plan tier
High Latency P95 > 5000ms P2 Check Figma status; add caching
API Down 5xx errors > 10/min P1 Enable fallback; check status.figma.com

Examples

Run the Step 7 pre-flight before the go-live cut:

./scripts/figma-preflight.sh
✓ FIGMA_PAT present, not in repo (gitleaks clean)
✓ /v1/me → 200 (token valid, acting as design-infra@example.com)
✓ File probe ?depth=1 → 200 in 240ms
✓ 429 handler: Retry-After honored (simulated)
✓ Webhook passcode verification: forged POST → 401
✗ Alerting: no alert rule for figma_api_requests_total{status="429"}
1 failure — fix before ship

Each line maps to a checklist step in this skill (auth → errors → rate limits → monitoring → data → webhooks). A red pre-flight is the checklist telling you which section to reopen — here, Step 4 (references/monitoring-health.md).

Resources

Next Steps

For version upgrades, see figma-upgrade-migration.

Use it

Copy one of these into your project. Installing also returns the manifest and these snippets.

yaml
targets:
  - https://api.opensmartroute.ai/api/v1/registry/jeremylongshore-tons-of-skills-marketplace-figma-prod-checklist/manifest   # or paste the manifest below

Manifest

An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.

jeremylongshore-tons-of-skills-marketplace-figma-prod-checklist.ocm.jsonjson
{
  "ocm": "1",
  "id": "jeremylongshore-tons-of-skills-marketplace-figma-prod-checklist",
  "kind": "skill",
  "name": "figma-prod-checklist",
  "description": "Production readiness checklist for Figma REST API integrations. Use when deploying Figma integrations to production, preparing for launch, or auditing an existing integration for production fitness. Trigger with phrases like \"figma production\", \"deploy figma\", \"figma go-live\", \"figma launch checklist\".",
  "publisher": "jeremylongshore",
  "version": "1.0.0",
  "capabilities": {
    "domains": [
      "coding"
    ],
    "tags": [
      "skill-md",
      "saas",
      "figma",
      "skills-sh"
    ],
    "languages": [
      "en"
    ]
  },
  "quality_prior": 0.6,
  "examples": [
    "Production readiness checklist for Figma REST API integrations. Use when deploying Figma integrations to production, preparing for launch, or auditing an existing integration for production fitness. Trigger with phrases like \"figma production\", \"deploy figma\", \"figma go-live\", \"figma launch checklist\"."
  ],
  "primary": false,
  "metadata": {
    "source": {
      "provider": "skills.sh",
      "repository": "https://github.com/jeremylongshore/tons-of-skills-marketplace",
      "path": "skills/.curated/figma-prod-checklist/SKILL.md",
      "ref": "HEAD",
      "url": "https://github.com/jeremylongshore/tons-of-skills-marketplace/blob/HEAD/skills/.curated/figma-prod-checklist/SKILL.md",
      "key": "jeremylongshore/tons-of-skills-marketplace/skills/.curated/figma-prod-checklist/SKILL.md"
    },
    "compatibility": "Designed for Claude Code",
    "allowed_tools": [
      "Read,",
      "Bash(curl:*),",
      "Grep"
    ],
    "license": "MIT"
  },
  "instructions": "# Figma Production Checklist\n\n## Overview\n\nComplete checklist for deploying Figma API integrations to production, covering authentication, error handling, rate limits, monitoring, and rollback.\n\n## Prerequisites\n\n- Staging environment tested and verified\n- Production PAT or OAuth credentials ready\n- Monitoring infrastructure available\n\n## Instructions\n\n### Step 1: Authentication & Secrets\n\n- [ ] Production PAT stored in secret manager (not env files)\n- [ ] PAT uses minimum required scopes (`file_content:read`, not `files:read`)\n- [ ] PAT expiry tracked (max 90 days) with rotation reminder\n- [ ",
  "cost": {
    "context_tokens": 1270
  }
}

Fetch it by URL: GET /api/v1/registry/jeremylongshore-tons-of-skills-marketplace-figma-prod-checklist/manifest?version=1.0.0

Reviews

Star ratings from people who tried it. One review per account; edit yours any time.

No reviews yet. Install it, try it, and be the first to rate it.