Is Figma safe?

Clean risk

Figma embeds an OAuth client secret and uses it when refreshing tokens with api.figma.com.

After login, the extension reads a stored refresh token and sends it to api.figma.com/v1/oauth/refresh with a Basic Authorization header built from an embedded client ID and client secret. It stores the returned access token locally and uses bearer tokens for Figma API requests such as recent files, search, file metadata, file creation, and account details.

Figmav1.3.25Chrome Web Store
0Risk
Who publishes it

Figma, Inc. - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Figma
Declared legal entity
Figma, Inc.
Registered address
760 Market St Floor 10, San Francisco, CA 94102-2300, US
Registered contact
Figma, Inc.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.3.8. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 1.3.25, which we have not unpacked yet.

  • Read and change your data on t-boweisvde9h9.us-west-2.experiments.sagemaker.aws

    *://t-boweisvde9h9.us-west-2.experiments.sagemaker.aws/*

  • Store data in your browser

    storage

  • Sign you in with your Google account

    identity

  • See the address and title of every tab you have open

    tabs

  • Run its own code inside the pages you visit

    scripting

Where it sends data

Destinations our analysis observed Figma contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • api.figma.com

    Figma sends data to api.figma.com. No other extension we have analysed sends data here.

Updated 30 September 2026fkmaohpngenfoccdgceedjkfhkdcohmg