# How to disable MCP

**URL:** <https://community.penpot.app/t/how-to-disable-mcp/10574>\
**Category:** Self-host\
**Tags:** mcp\
**Created:** [May 12, 2026, 12:16pm UTC](https://community.penpot.app/t/how-to-disable-mcp/10574 "2026-05-12T12:16:36Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ryuno-Ki](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/ryuno-ki/32/240_2.png) [@Ryuno-Ki](https://community.penpot.app/u/Ryuno-Ki)\
**Post date:** [May 12, 2026, 12:16pm UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/1 "2026-05-12T12:16:36Z")

</div>

Edit: Moved the personal views to [my blog](https://jaenis.ch/en/blog/2026/how-to-disable-mcp-in-penpot/) because this post got flagged as inappropriate.

PenPot 2.15.0 [dropped](https://github.com/penpot/penpot/releases/tag/2.15.0). If you want to upgrade your self-hosted PenPot instance, the Frontend won’t come up. (I’m not using docker-compose but rootless Podman with SystemD files).

That’s because the host „penpot-mcp" is not found in upstream of NginX.

What’s needed is an update of the environment variable „PENPOT\_FLAGS" to contain „disable-mcp" as well as „PENPOT\_MCP\_URI" to point to something like „[http://127.0.0.1](http://127.0.0.1)". (Note that there is another environment variable in the thread below for 2.15.2).

The help page is useless without a Frontend:

> **[Penpot MCP server](https://help.penpot.app/mcp/)**
>
> Installing and using the Penpot MCP server with any AI agent or LLM you trust.

I eventually figured it out by reading the (I think is) offending PR:

> <https://github.com/penpot/penpot/pull/9299/files#diff-1742a1dc2cf8ac170ed6e6679079b798c6774b227d5ab98b8e032ec581aaae22>
>
> \## Relevant Issues
> 
> \* #9212 
> \* #9213 
> \* #9300
> \* #9218
> \* #9315 
> \* #9217 
> …\* #9214 
> 
> \## Description
> 
> This PR adds a new "agentic" DevEnv mode, which supports the AI-based self-improvement of Penpot.
> 
> \* Agentic DevEnv:
> \* The agentic DevEnv is started via \`./manage.sh run-devenv-agentic\`.  
> This spawns two additional processes (via tmux):
> \* Penpot MCP server (extended for self-improvement, see below)
> \* Serena MCP server (local server for code intelligence, which operates directly on the codebase in the container)
> \* Detailed usage instructions are provided in new documentation: \`docs/technical-guide/developer/agentic-devenv.md\` (not linked from index)
> \* New software installations in the \`main\` container: 
> \* \`serena\` 
> \* \`uv\` (package manager, needed by Serena)
> \* Structured agent instructions via focused memories (to be extended, #9215)  
> Particular instructions on:
> \* Critical information (bootstrap insutrctions)
> \* Crash detection/analysis/recovery
> \* Development tasks (commits, PRs)
> \* ClojureScript REPL usage
> \* Relationship between TypeScript API and ClojureScript implementation
> \* Penpot MCP server extensions (only active in agentic DevEnv)
> \* ClojureScript REPL tool (accesses the existing nREPL server)
> \* Penpot file import tool (to facilitate reproductions involving 
> \* Tool for the retrieval of ClojureScript compiler errors
> \* Tool for pinpointing syntax errors in Clojure code (unbalanced parentheses)
> 
> \## Note to Reviewer
> 
> You can test this by checking out the branch and following the instructions that were added here: \`docs/technical-guide/developer/agentic-devenv.md\`
> 
> Please do not squash the commits when merging.

---

<div class="post-metadata">

**Author:** ![Alpetrus](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/alpetrus/32/10077_2.png) [@Alpetrus](https://community.penpot.app/u/Alpetrus)\
**Post date:** [May 12, 2026, 7:52pm UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/2 "2026-05-12T19:52:18Z")

</div>

The same problem with self-hosted penpot with docker and my .yaml.  
_penpot-frontend_ was restarting.

> [@Ryuno-Ki](#):
>
> What’s needed is an update of the environment variable „PENPOT\_FLAGS" to contain „disable-mcp" as well as „PENPOT\_MCP\_URI" to point to something like „[http://127.0.0.1](http://127.0.0.1)".

It works. Thanks!

---

<div class="post-metadata">

**Author:** ![Ryuno-Ki](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/ryuno-ki/32/240_2.png) [@Ryuno-Ki](https://community.penpot.app/u/Ryuno-Ki)\
**Post date:** [May 13, 2026, 12:42pm UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/3 "2026-05-13T12:42:35Z")

</div>

You’re welcome.

Update: Starting with [2.15.2](https://github.com/penpot/penpot/releases/tag/2.15.2) another environment variable is [required](https://github.com/penpot/penpot/pull/9565/changes): PENPOT\_MCP\_URI\_WS (for WebSocket communication).

---

<div class="post-metadata">

**Author:** ![system](https://europe1.discourse-cdn.com/flex017/uploads/penpot/original/2X/d/d4d155e990eb22835864435d02174f56ac44f323.png) [@system](https://community.penpot.app/u/system)\
**Post date:** [May 14, 2026, 1:35pm UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/4 "2026-05-14T13:35:42Z")

</div>



---

<div class="post-metadata">

**Author:** ![Alpetrus](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/alpetrus/32/10077_2.png) [@Alpetrus](https://community.penpot.app/u/Alpetrus)\
**Post date:** [May 14, 2026, 3:47pm UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/5 "2026-05-14T15:47:15Z")

</div>

PENPOT\_MCP\_URI\_WS: [https://127.0.0.1](https://127.0.0.1) works perfectly!

---

<div class="post-metadata">

**Author:** ![system](https://europe1.discourse-cdn.com/flex017/uploads/penpot/original/2X/d/d4d155e990eb22835864435d02174f56ac44f323.png) [@system](https://community.penpot.app/u/system)\
**Post date:** [May 15, 2026, 11:07am UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/6 "2026-05-15T11:07:41Z")

</div>



---

<div class="post-metadata">

**Author:** ![Sebastien\_QUEROL](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/sebastien_querol/32/10478_2.png) [@Sebastien\_QUEROL](https://community.penpot.app/u/Sebastien_QUEROL)\
**Post date:** [May 20, 2026, 9:57am UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/7 "2026-05-20T09:57:59Z")

</div>

Nothing works on my end : where do you put that env variable exactly ? Under the frontend or the backend ? Can’t penpot just interpret the lack of MCP-related env variables as “don’t enable that feature” ? What a pain…

---

<div class="post-metadata">

**Author:** ![milieu](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/milieu/32/7297_2.png) [@milieu](https://community.penpot.app/u/milieu)\
**Post date:** [May 20, 2026, 3:41pm UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/8 "2026-05-20T15:41:11Z")

</div>

Perhaps we should have the discussion, if MCP is unsafe for agents, how might those interfaces be shored up for all of us? It seems we are mixing more than one concern here. I see three and suspect there may be more:

1. The MCP feature contribution caused issues with self-install
2. MCP is not feature flagged (is this actually true though?)
3. Interfaces that the MCP feature accessed may not be safe (this requires verification)

What else am i missing? The linked blog post is aggressive. While i sympathise, we have more than one user’s needs to consider here.

---

<div class="post-metadata">

**Author:** ![Ryuno-Ki](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/ryuno-ki/32/240_2.png) [@Ryuno-Ki](https://community.penpot.app/u/Ryuno-Ki)\
**Post date:** [May 20, 2026, 4:57pm UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/9 "2026-05-20T16:57:42Z")

</div>

> where do you put that env variable exactly ?

In the container definition for penpot-frontend. It was the only container not coming back online.

> Can’t penpot just interpret the lack of MCP-related env variables as “don’t enable that feature” ?

That would be ideal. Or have a default value in case it isn’t defined. At the very least I would have preferred to find a note in the release notes / CHANGES.md. It mentions that this service was added („MCP server integration") but not that it could have an impact on the configuration.

> What a pain…

The first version of this thread OP got unlisted because I felt pain …

---

<div class="post-metadata">

**Author:** ![Ryuno-Ki](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/ryuno-ki/32/240_2.png) [@Ryuno-Ki](https://community.penpot.app/u/Ryuno-Ki)\
**Post date:** [May 20, 2026, 4:59pm UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/10 "2026-05-20T16:59:04Z")

</div>

@milieu Would you mind to break out your questions into a new thread?

---

<div class="post-metadata">

**Author:** ![davidbarragan](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/davidbarragan/32/51_2.png) [@davidbarragan](https://community.penpot.app/u/davidbarragan)\
**Post date:** [May 26, 2026, 11:40am UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/11 "2026-05-26T11:40:10Z")

</div>

I hope [this change](https://github.com/penpot/penpot/pull/9874/) will solve the problem.

---

<div class="post-metadata">

**Author:** ![Ryuno-Ki](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/ryuno-ki/32/240_2.png) [@Ryuno-Ki](https://community.penpot.app/u/Ryuno-Ki)\
**Post date:** [May 26, 2026, 12:55pm UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/12 "2026-05-26T12:55:50Z")

</div>

How would it? I mean, you’re telling the Frontend to wait for MCP, whereas the question here is how to get PenPot operating _without_ running a MCP server.

---

<div class="post-metadata">

**Author:** ![davidbarragan](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/davidbarragan/32/51_2.png) [@davidbarragan](https://community.penpot.app/u/davidbarragan)\
**Post date:** [May 26, 2026, 2:06pm UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/13 "2026-05-26T14:06:41Z")

</div>

I understand what you’re saying @Ryuno-Ki; the PR simply ensures that the default implementation provided by the `docker-compose.yml` file in the repository doesn’t throw any errors.

Your proposal is to completely disable the MCP.

---

<div class="post-metadata">

**Author:** ![davidbarragan](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/davidbarragan/32/51_2.png) [@davidbarragan](https://community.penpot.app/u/davidbarragan)\
**Post date:** [May 26, 2026, 3:12pm UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/14 "2026-05-26T15:12:29Z")

</div>

I have a new [proposal](https://github.com/penpot/penpot/pull/9879).

---

<div class="post-metadata">

**Author:** ![Ryuno-Ki](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/ryuno-ki/32/240_2.png) [@Ryuno-Ki](https://community.penpot.app/u/Ryuno-Ki)\
**Post date:** [May 26, 2026, 4:12pm UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/15 "2026-05-26T16:12:33Z")

</div>

I can get behind this one. Thank you.

---

<div class="post-metadata">

**Author:** ![davidbarragan](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/davidbarragan/32/51_2.png) [@davidbarragan](https://community.penpot.app/u/davidbarragan)\
**Post date:** [May 27, 2026, 10:38am UTC](https://community.penpot.app/t/how-to-disable-mcp/10574/16 "2026-05-27T10:38:02Z")

</div>

It will be available in the upcoming 2.15.4 release
