Skip to main content
figma-data-handling Handle Figma API data correctly: comments, versions, user data, and privacy compliance.
Use when working with Figma comments API, version history,
or ensuring GDPR compliance for Figma user data.
Trigger with phrases like "figma data", "figma comments",
"figma versions", "figma GDPR", "figma user data".
跳到安装 Skills Marketplace 发现并探索由社区构建的 Agent Skills
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/jeremylongshore/claude-code-plugins-plus-skills --skill figma-data-handling命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
下载 Zip 下载中... jeremylongshore
jeremylongshore/claude-code-plugins-plus-skills
打开 GitHub 仓库 name figma-data-handling description Handle Figma API data correctly: comments, versions, user data, and privacy compliance.
Use when working with Figma comments API, version history,
or ensuring GDPR compliance for Figma user data.
Trigger with phrases like "figma data", "figma comments",
"figma versions", "figma GDPR", "figma user data".
allowed-tools Read, Write, Edit version 1.6.0 license MIT author Jeremy Longshore <jeremy@intentsolutions.io> tags ["saas","figma"] compatibility Designed for Claude Code
Figma Data Handling
Overview
Work with Figma's data APIs: comments, version history, and user information. Handle sensitive data correctly with redaction and privacy compliance.
Prerequisites
FIGMA_PAT with appropriate scopes (file_comments:read/write, file_versions:read)
Understanding of GDPR/CCPA basics
Instructions
Step 1: Comments API
const PAT = process.env .FIGMA_PAT !;
const FILE_KEY = process.env .FIGMA_FILE_KEY !;
async function getComments (fileKey : string ) {
const res = await fetch (
`https://api.figma.com/v1/files/${fileKey} /comments` ,
{ headers : { 'X-Figma-Token' : PAT } }
);
const data = await res.json ();
return data.comments ;
}
async function getCommentsAsMarkdown (fileKey : string ) {
const res = (
,
{ : { : } }
);
( res. ()). ;
}
( ) {
: = { message };
(nodeId) {
body. = { : nodeId };
}
res = (
,
{
: ,
: {
: ,
: ,
},
: . (body),
}
);
res. ();
}
( ) {
(
,
{
: ,
: {
: ,
: ,
},
: . ({ emoji }),
}
). ( r. ());
}
await
fetch
`https://api.figma.com/v1/files/${fileKey} /comments?as_md=true`
headers
'X-Figma-Token'
PAT
return
await
json
comments
async
function
postComment
fileKey : string , message : string , nodeId ?: string
const
body
any
if
client_meta
node_id
const
await
fetch
`https://api.figma.com/v1/files/${fileKey} /comments`
method
'POST'
headers
'X-Figma-Token'
PAT
'Content-Type'
'application/json'
body
JSON
stringify
return
json
async
function
reactToComment
fileKey : string , commentId : string , emoji : string
return
fetch
`https://api.figma.com/v1/files/${fileKey} /comments/${commentId} /reactions`
method
'POST'
headers
'X-Figma-Token'
PAT
'Content-Type'
'application/json'
body
JSON
stringify
then
r =>
json
Step 2: Version History API
async function getVersionHistory (fileKey : string ) {
const res = await fetch (
`https://api.figma.com/v1/files/${fileKey} /versions` ,
{ headers : { 'X-Figma-Token' : PAT } }
);
const data = await res.json ();
return data.versions ;
}
async function getAllVersions (fileKey : string ) {
const versions : any [] = [];
let url : string | null = `https://api.figma.com/v1/files/${fileKey} /versions` ;
while (url) {
const res = await fetch (url, { headers : { 'X-Figma-Token' : PAT } });
const data = await res.json ();
versions.push (...data.versions );
url = data.pagination ?.next_page
? `https://api.figma.com/v1/files/${fileKey} /versions?before=${data.pagination.next_page} `
: null ;
}
return versions;
}
Step 3: User Data and Privacy
interface FigmaUser {
id : string ;
handle : string ;
img_url : string ;
email : string ;
}
function redactFigmaUser (user : FigmaUser ): Omit <FigmaUser , 'email' > & { email : string } {
return {
...user,
email : '[REDACTED]' ,
img_url : '[REDACTED]' ,
};
}
interface DataClassification {
field : string ;
sensitivity : 'public' | 'internal' | 'pii' ;
handling : string ;
}
const figmaDataClassification : DataClassification [] = [
{ field : 'user.email' , sensitivity : 'pii' , handling : 'Encrypt at rest, redact in logs' },
{ field : 'user.handle' , sensitivity : 'internal' , handling : 'Do not expose to unauthorized users' },
{ field : 'user.img_url' , sensitivity : 'pii' , handling : 'Do not cache without consent' },
{ field : 'file.name' , sensitivity : 'internal' , handling : 'Standard handling' },
{ field : 'comment.message' , sensitivity : 'internal' , handling : 'May contain PII -- scan before storing' },
{ field : 'PAT token' , sensitivity : 'pii' , handling : 'Never log, never store in code' },
];
Step 4: Data Retention
interface CachedFigmaData {
data : any ;
fetchedAt : Date ;
expiresAt : Date ;
}
function createCacheEntry (data : any , ttlMs : number ): CachedFigmaData {
const now = new Date ();
return {
data,
fetchedAt : now,
expiresAt : new Date (now.getTime () + ttlMs),
};
}
async function cleanupExpiredData (db : any ) {
const now = new Date ();
const deleted = await db.figmaCache .deleteMany ({
expiresAt : { $lt : now },
});
console .log (`Cleaned up ${deleted.count} expired Figma cache entries` );
}
Step 5: Safe Logging
const REDACT_FIELDS = ['email' , 'img_url' , 'access_token' , 'refresh_token' ];
function safeFigmaLog (label : string , data : any ) {
const safe = JSON .parse (JSON .stringify (data));
function redact (obj : any ) {
for (const key of Object .keys (obj)) {
if (REDACT_FIELDS .includes (key)) {
obj[key] = '[REDACTED]' ;
} else if (typeof obj[key] === 'object' && obj[key] !== null ) {
redact (obj[key]);
}
}
}
redact (safe);
console .log (`[figma] ${label} :` , JSON .stringify (safe));
}
Output
Comments fetched and posted via REST API
Version history retrieved with pagination
PII redacted before logging and storage
Data retention policies applied
Error Handling Error Cause Solution 403 on comments Missing file_comments:read scope Regenerate PAT with scope Empty version history New file with no saved versions Create a named version in Figma first PII in logs Missing redaction Apply safeFigmaLog wrapper Stale image URLs URLs older than 30 days Re-export images; do not cache URLs long-term
Examples Pull the latest comments as Markdown and post a reaction (Step 1 Comments API):
curl -s -H "X-Figma-Token: ${FIGMA_PAT} " \
"https://api.figma.com/v1/files/${FIGMA_FILE_KEY} /comments?as_md=true" \
| jq -r '.comments[0] | "\(.user.handle): \(.message)"'
Walk version history with pagination (Step 2):
curl -s -H "X-Figma-Token: ${FIGMA_PAT} " \
"https://api.figma.com/v1/files/${FIGMA_FILE_KEY} /versions" \
| jq '{versions: [.versions[] | {id, created_at, label}], next: .pagination.next_page}'
PII rules for what you may persist from these payloads (user handles, avatars, emails): references/user-data-and-privacy.md and references/safe-logging.md.
Resources
Next Steps For enterprise access control, see figma-enterprise-rbac.