# Penpot 2.18 release: Born this way

**URL:** <https://community.penpot.app/t/penpot-2-18-release-born-this-way/10884>\
**Category:** Product updates\
**Created:** [September 11, 2026, 9:00am UTC](https://community.penpot.app/t/penpot-2-18-release-born-this-way/10884 "2026-09-11T09:00:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![myfunnyandy](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/myfunnyandy/32/54_2.png) [@myfunnyandy](https://community.penpot.app/u/myfunnyandy)\
**Post date:** [September 11, 2026, 9:00am UTC](https://community.penpot.app/t/penpot-2-18-release-born-this-way/10884/1 "2026-09-11T09:00:26Z")

</div>

![2.18 release cover](https://europe1.discourse-cdn.com/flex017/uploads/penpot/original/2X/1/112077bf1b7119c8826d941cbb701f6968f69f65.jpeg)

Penpot **2.18** introduces **Penpot Enterprise** , our new paid plan, shipping alongside the most requested **Outline stroke** (stroke to path) and a fresh batch of features and fixes. **Penpot stays free, unlimited, and open source.** Enterprise is for organizations that need to govern people, workflows, or content.

**WebGL rendering** and **MCP** keep getting more reliable, with regrouped drawing tools, font previews, tokens that stay tokens when you copy, **performance improvements** , and plenty of quality-of-life polish. Community contributors shipped alongside the core team again. Thank you to everyone who filed, reviewed, and merged.

Let’s dive in!

* * *

## Introducing Penpot Enterprise

As an open source product, Penpot brings the most advanced features to everyone for free. **Penpot Enterprise** is a paid layer that overrides, tweaks, or restricts how those features can be used at scale.

 ![2.18-enterprise](https://europe1.discourse-cdn.com/flex017/uploads/penpot/original/2X/7/7eb22fbfea08e6b78d5821dbfd511f83749b3382.webp)

A dedicated **Admin Console** lets authorized users create independent organizations and apply rules to them. We are starting with something straightforward: per-organization **SSO** , and **advanced permissions** across every team. [Penpot Enterprise](https://help.penpot.app/user-guide/account-teams/enterprise-plan/) is the plan that unlocks this.

### One sign-in for everyone

Let the whole organization sign in through your corporate identity provider: a generic **OpenID Connect** provider, **Azure Active Directory** , or **Google**. One consistent way into your organization’s teams and files, governed by the directory you already run. From the Admin Console you can connect that identity provider in a few steps.

### Advanced permissions

Decide who can do what across every team at once: who can create, edit, or administer teams, projects, and files, who can invite people in, and who can be invited (a typical use case is limiting invites only to people within your organization). Those rules sit on top of each person’s normal role, so the whole organization stays aligned with how you want to work, and changes take effect as soon as you make them.

* * *

## Outline stroke: from line to shape

A path is the geometry: points and segments. A stroke is the visible line drawn along it (width, color, dashes, caps, joins). Until now that outline was a style sitting on the path, not a shape you could grab.

 ![2.18-outline-stroke](https://europe1.discourse-cdn.com/flex017/uploads/penpot/original/2X/0/0a7a50d6c4a0d4a31882fe3ee179d81be2900a47.webp)

**Outline stroke** converts that outline into a separate, editable path, usually a closed shape that follows the visible edges of the stroke. Right-click a shape that has a stroke and choose **Outline stroke**. You can then reshape or restyle the outline on its own, run boolean operations, and export SVG where the outline is real vector geometry, not just a painted line. ([#9961](https://github.com/penpot/penpot/issues/9961))

This one is available **only with WebGL rendering turned on**. One more reason to [switch to WebGL rendering](https://community.penpot.app/t/whats-next-for-the-penpot-webgl-renderer/10627).

* * *

## Drawing tools, regrouped

The workspace toolbar was running out of room. Drawing tools now sit in two flyouts: **shapes** (rectangle, ellipse, line, arrow) and **free-draw** (path, pencil). Hover a slot to pick a tool; the icon remembers the last one you used. ([#9316](https://github.com/penpot/penpot/issues/9316))

 ![2.18-drawing-tools](https://europe1.discourse-cdn.com/flex017/uploads/penpot/original/2X/9/9af5b634dab15f68623f1cc2b3e0111f5edc5206.webp)

This release also adds dedicated **Line** and **Arrow** tools (by [@davidv399](https://github.com/davidv399)), so those staples are no longer a path-plus-caps workaround. ([#9145](https://github.com/penpot/penpot/issues/9145))

* * *

## Fonts you can actually see

A long-standing request lands: the font selector now **previews font families** , so you can scan the list and recognize a face before you commit. ([#10403](https://github.com/penpot/penpot/issues/10403))

 ![2.18-font-preview](https://europe1.discourse-cdn.com/flex017/uploads/penpot/original/2X/8/8a28d7ed80cc2d8338086db1a0a193d8eea5babd.webp)

* * *

## Tokens that stay tokens

Copy and paste used to resolve token references into raw values. Now **token references are preserved** when you copy and paste properties (by [@AKnassa](https://github.com/AKnassa)), so design-system links survive the trip. ([#9582](https://github.com/penpot/penpot/issues/9582))

The color tokens picker is easier to scan as palettes grow:

• Token sets appear in **reverse order by default** (by [@rhinocap](https://github.com/rhinocap)). ([#10552](https://github.com/penpot/penpot/issues/10552))  
• Expanded and collapsed set state is **remembered for the session**. ([#10551](https://github.com/penpot/penpot/issues/10551))

* * *

## Dashboard and pages

Files on the dashboard can switch between **grid and list** views, so you can scan by thumbnail or by name. ([#10691](https://github.com/penpot/penpot/issues/10691))

 ![2.18-dashboard-view](https://europe1.discourse-cdn.com/flex017/uploads/penpot/original/2X/2/25dcd1db6fbfb99635aaba95a5bf4431a58cc5ef.webp)

Pages in the workspace sitemap support **multi-selection and bulk delete**. Less clicking when you are cleaning house. ([#10484](https://github.com/penpot/penpot/issues/10484), [#10580](https://github.com/penpot/penpot/issues/10580))

* * *

## MCP: simpler setup, steadier sessions

If you connect AI clients to Penpot, configuration is simpler for the **common MCP clients**. The key-generated modal no longer shows a misleading client JSON snippet (by [@Shlok1729](https://github.com/Shlok1729)). ([#10355](https://github.com/penpot/penpot/issues/10355), [#10399](https://github.com/penpot/penpot/issues/10399))

Reliability work continues: MCP no longer hangs when the Penpot tab is backgrounded, and session timeouts and reconnects are more trustworthy after leaving a file or restarting the MCP container.

MCP Setup: [Penpot MCP server](https://help.penpot.app/mcp/).

* * *

## Community contributions

Community bylines keep growing. Highlights from this cycle:

• **Line and Arrow drawing tools** (by [@davidv399](https://github.com/davidv399))  
• **Preserve token references** on copy and paste (by [@AKnassa](https://github.com/AKnassa))  
• **Highlight the first matching font** in search (by [@ai-mountain](https://github.com/ai-mountain))  
• **Token sets reverse order** in the color tokens picker (by [@rhinocap](https://github.com/rhinocap))  
• **MCP client JSON snippet** cleanup (by [@Shlok1729](https://github.com/Shlok1729))  
• **SVG option** in image-fill file filters (by [@LuBoys](https://github.com/LuBoys))  
• **Spacebar while typing a comment** (by [@Krishcode264](https://github.com/Krishcode264))  
• **Custom fonts** moving between teams, **config.js cache** for self-host flags, and **comment avatars** vs rulers (by [@filipsajdak](https://github.com/filipsajdak))  
• **MCP WebSocket proxy** after container restart (by [@780Farva](https://github.com/780Farva))  
• **Numeric formulas** , **radial gradient handles** , and several plugin and UI fixes (by [@AKnassa](https://github.com/AKnassa))

Thank you to everyone credited in the changelog and to all who reported bugs.

* * *

## Performance, fixes and polish

This cycle also includes a large set of **bug fixes** and **performance** work across WebGL rendering, tokens, variants, comments, plugins, export, and MCP. Patch releases since 2.17 folded in crash fixes, more dependable variant overrides, and MCP timeout reliability.

We will not list every line item here. See [CHANGES.md](https://github.com/penpot/penpot/blob/staging/CHANGES.md) for the full breakdown.

* * *

## More to explore

If you need to govern people, workflows, or content, look at [Penpot Enterprise](https://help.penpot.app/user-guide/account-teams/enterprise-plan/). For everyone else, turn on **WebGL rendering** and try **Outline stroke** on a fat path, pick a font by preview, and copy a token-backed property to see the reference survive. If you use **MCP** , this is a good week to reconnect and send feedback.

• [Penpot Enterprise](https://help.penpot.app/user-guide/account-teams/enterprise-plan/)  
• [User Guide](https://help.penpot.app/)  
• [MCP server](https://help.penpot.app/mcp/)  
• [CHANGES.md](https://github.com/penpot/penpot/blob/staging/CHANGES.md)

---

<div class="post-metadata">

**Author:** ![Arthurium](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/arthurium/32/11216_2.png) [@Arthurium](https://community.penpot.app/u/Arthurium)\
**Post date:** [September 11, 2026, 3:01pm UTC](https://community.penpot.app/t/penpot-2-18-release-born-this-way/10884/2 "2026-09-11T15:01:55Z")

</div>

Thank you all, both the Penpot staff and the community for the work that you do to make Penpot better, more usable, and adjustable for various usecases. Gotta raise world equality somehow. Because that’s what open source does, it raises the floor, by making highly needed tooling openly available for those end-users who need it, not just stakeholders. And y’all take a step further and make the tools more accessible for non-technical people. That’s something the GNUs and the Linuxians can still learn from : )

---

<div class="post-metadata">

**Author:** ![andyfitz](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/andyfitz/32/415_2.png) [@andyfitz](https://community.penpot.app/u/andyfitz)\
**Post date:** [September 11, 2026, 6:38pm UTC](https://community.penpot.app/t/penpot-2-18-release-born-this-way/10884/3 "2026-09-11T18:38:34Z")

</div>

This release is AMAZING!!! congratulations to the Penpot team and all the community contributors

---

<div class="post-metadata">

**Author:** ![parkerreno](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/parkerreno/32/11325_2.png) [@parkerreno](https://community.penpot.app/u/parkerreno)\
**Post date:** [October 1, 2026, 6:34am UTC](https://community.penpot.app/t/penpot-2-18-release-born-this-way/10884/4 "2026-10-01T06:34:53Z")

</div>

> ### **One sign-in for everyone**
> 
> Let the whole organization sign in through your corporate identity provider: a generic **OpenID Connect** provider, **Azure Active Directory** , or **Google**. One consistent way into your organization’s teams and files, governed by the directory you already run. From the Admin Console you can connect that identity provider in a few steps.

SSO via OIDC, LDAP, etc has been a thing for a while in PenPot - is this becoming an Enterprise only feature? Or is just setting it up from Admin Console the enterprise feature?

---

<div class="post-metadata">

**Author:** ![myfunnyandy](https://dub1.discourse-cdn.com/flex017/user_avatar/community.penpot.app/myfunnyandy/32/54_2.png) [@myfunnyandy](https://community.penpot.app/u/myfunnyandy)\
**Post date:** [October 2, 2026, 5:46am UTC](https://community.penpot.app/t/penpot-2-18-release-born-this-way/10884/5 "2026-10-02T05:46:13Z")

</div>

Hi @parkerreno! Nothing changes for the existing setup. OIDC, LDAP and the rest are still configured the usual way on self-hosted instances, and that stays free.

The Enterprise part is org-level SSO managed from the Admin Console: you connect your identity provider in a few clicks and it applies to the whole organization’s teams and files, with no env vars or config files involved.
