Is Figma safe?
Figma embeds an OAuth client secret and uses it when refreshing tokens with api.figma.com.
After login, the extension reads a stored refresh token and sends it to api.figma.com/v1/oauth/refresh with a Basic Authorization header built from an embedded client ID and client secret. It stores the returned access token locally and uses bearer tokens for Figma API requests such as recent files, search, file metadata, file creation, and account details.
Who publishes itFigma, Inc. - no other listings under this identity
Figma, Inc. - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.3.8. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 1.3.25, which we have not unpacked yet.
Read and change your data on t-boweisvde9h9.us-west-2.experiments.sagemaker.aws
*://t-boweisvde9h9.us-west-2.experiments.sagemaker.aws/*
Store data in your browser
storage
Sign you in with your Google account
identity
See the address and title of every tab you have open
tabs
Run its own code inside the pages you visit
scripting
Where it sends data
Destinations our analysis observed Figma contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- api.figma.com
Figma sends data to api.figma.com. No other extension we have analysed sends data here.