Connect in three steps
- In Polyform, open Agent in the bottom bar (or the Agent menu) and press Start endpoint. Nothing listens until you do.
- Copy the connect command it shows and run it once in a terminal:
claude mcp add --transport http polyform http://127.0.0.1:<port>/mcp \ --header "Authorization: Bearer <token>" - Ask your agent to do something. You see its cursor, its current step, and every change as it lands.
The port and the token are new each time the endpoint starts, so a saved configuration stops working after a restart. That is deliberate. The endpoint listens on 127.0.0.1 only, so nothing outside your computer can reach it.
Permissions, one capability at a time
There are 19 tools, grouped into capabilities you switch on and off while the agent is connected. Editing starts off in every session.
| Capability | What it allows | Default |
|---|---|---|
| Document | Read the document and its layers | On |
| Selection | See what you have selected | On |
| Render | Look at the canvas and at layers as images | On |
| Changes | Follow what changed since it last looked | On |
| Attention | Select layers and bring them into view | On |
| Edit | Change the document, import images and SVG, remove backgrounds | Off |
You stay in charge
- Hold. Press Hold and the agent's next step waits until you resume. You can leave it a one-line note about why.
- One undo per edit. Each agent batch is one labelled entry in history, marked AGENT. Step back through it like your own work.
- Visible presence. A frame around the canvas and a chip with the agent's current step, so it never works out of sight.
Without a window
For scripts and CI, the same binary runs headless: polyform mcp serve path/to/Project.poly serves a file at rest, and polyform export renders it, pixel-identical to the app.
Agents never sign in to anything. The agent endpoint is local to your machine and separate from your account.