Figma Production Checklist
Overview
Complete checklist for deploying Figma API integrations to production, covering authentication, error handling, rate limits, monitoring, and rollback.
Prerequisites
- Staging environment tested and verified
- Production PAT or OAuth credentials ready
- Monitoring infrastructure available
Instructions
Step 1: Authentication & Secrets
Step 2: Error Handling
Step 3: Rate Limiting
Step 4: Monitoring & Health
async function figmaHealthCheck() {
const start = Date.now();
try {
const res = await fetch('https://api.figma.com/v1/me', {
headers: { 'X-Figma-Token': process.env.FIGMA_PAT! },
signal: AbortSignal.timeout(5000),
});
return {
status: res.ok ? 'healthy' : 'degraded',
latencyMs: Date.now() - start,
httpStatus: res.status,
};
} catch (error) {
return {
status: 'unhealthy',
latencyMs: Date.now() - start,
error: error instanceof Error ? error.message : 'Unknown',
};
}
}
Step 5: Data Handling
Step 6: Webhook Production Setup
Step 7: Pre-Flight Verification
#!/bin/bash
echo "=== Figma Production Pre-Flight ==="
STATUS=$(curl -s -o /dev/null -w "%{http_code}" \
-H "X-Figma-Token: ${FIGMA_PAT}" \
https://api.figma.com/v1/me)
echo "Auth: $STATUS (expect 200)"
STATUS=$(curl -s -o /dev/null -w "%{http_code}" \
-H "X-Figma-Token: ${FIGMA_PAT}" \
"https://api.figma.com/v1/files/${FIGMA_FILE_KEY}?depth=1")
echo "File: $STATUS (expect 200)"
echo -n "Figma Status: "
curl -s https://www.figmastatus.com/api/v2/status.json 2>/dev/null \
| jq -r '.status.description // "Unable to check"'
echo "=== Pre-flight complete ==="
Output
- All checklist items verified
- Health check endpoint deployed
- Monitoring and alerting configured
- Pre-flight script passing
Error Handling
| Alert | Condition | Severity | Action |
|---|
| Auth Failure | 403 errors > 0 | P1 | Rotate PAT immediately |
| Rate Limited | 429 errors > 5/min | P2 | Reduce request rate; check plan tier |
| High Latency | P95 > 5000ms | P2 | Check Figma status; add caching |
| API Down | 5xx errors > 10/min | P1 | Enable fallback; check status.figma.com |
Examples
Run the Step 7 pre-flight before the go-live cut:
./scripts/figma-preflight.sh
✓ FIGMA_PAT present, not in repo (gitleaks clean)
✓ /v1/me → 200 (token valid, acting as design-infra@example.com)
✓ File probe ?depth=1 → 200 in 240ms
✓ 429 handler: Retry-After honored (simulated)
✓ Webhook passcode verification: forged POST → 401
✗ Alerting: no alert rule for figma_api_requests_total{status="429"}
1 failure — fix before ship
Each line maps to a checklist step in this skill (auth → errors → rate limits → monitoring → data → webhooks). A red pre-flight is the checklist telling you which section to reopen — here, Step 4 (references/monitoring-health.md).
Resources
Next Steps
For version upgrades, see figma-upgrade-migration.