Skip to main content
mcpSource-backed

Curio MCP Server for Claude

Curio is a design-style library for AI: hundreds of real design styles — movements, brands, and cultural traditions — packaged as token-complete, machine-readable specs.

by Curio · submitted by voltwake·added 2026-06-11·
Review first review before installing

Open the source and read safety notes before installing.

Citation facts

Source-backed facts for citing this resource, derived directly from the registry — also available as plain text for AI assistants.

Source URLs
https://designbycurio.com/docs, https://github.com/JSONbored/awesome-claude/blob/main/content/mcp/curio-mcp-server.mdx, https://designbycurio.com/
Safety notes
Remote HTTP MCP server — it runs no local commands and touches no local files. All tools are read-only lookups against the Curio style catalog; the server cannot modify anything on the user's machine., get_style_spec consumes one quota credit on the signed-in account, the same metering as a website download. search_styles, list_styles, get_style, and get_quota never charge.
Privacy notes
Sign-in is OAuth only (PKCE); the client holds scoped tokens, never passwords., The server receives only tool arguments (search queries, style ids) and the account id for quota accounting — no prompts, files, or other local context leave the client., Access can be revoked anytime from the account's Connected apps page, which invalidates the authorization's tokens immediately.
Author
Curio
Submitted by
voltwake
Claim status
unclaimed
Last verified
2026-06-11

Decision playbook

Review trust signals before you adopt

Signals are present but mixed. Use the checklist below to confirm the source and operational safety for your environment.

Compare context
Selected

0

Current score

63

Baseline

Delta

No baseline selected

No major trust-signal divergence detected in the current selection.

Source and provenance checks

Needs review

Confirm ownership and provenance before trusting install instructions.

  • Source link availableRequired

    Open the canonical repository and verify ownership.

    Done
  • Source provenance statusRequired

    Marked as source-backed.

    Done
  • Metadata reviewed

    No reviewed flag detected in metadata.

    Pending

Safety and privacy checks

Complete

Validate risk disclosures before installation or API wiring.

  • Safety notes presentRequired

    Review the listed safety guidance before running commands.

    Done
  • Privacy notes presentRequired

    Review data handling notes before connecting accounts or secrets.

    Done
  • Trust level risk gateRequired

    Trust level does not block evaluation.

    Done

Package and install checks

Needs review

Check package metadata and artifact integrity signals.

  • Install payload available

    Install or copy payload is available for review.

    Done
  • Package verification flag

    No package verification flag provided.

    Pending
  • Checksum metadata

    No checksum provided for downloaded artifact.

    Pending

Compare-driven decision checks

Needs review

Use compare context to validate trade-offs before adoption.

  • Compare tray has multiple entries

    Add at least one more entry to compare trust differences.

    Pending
  • Baseline comparison available

    No baseline peer selected yet.

    Pending
  • Diverging trust signals identified

    No major trust-signal divergence found.

    Pending

Setup at a glance

CLI install

Copy-ready — paste the snippet to get started.

5 minutes

Adoption plan

Balanced adoption plan

Current risk score 24/100. Use staged verification before broader rollout.

Risk 24

Pre-adoption checks

Validate source and review signals before any execution.

  • Confirm source provenanceRequired

    Source URL/provenance metadata is present.

    Done
  • Confirm metadata review state

    No review metadata found; increase manual validation.

    Pending
  • Verify install payload

    Install/config payload exists and can be inspected.

    Done

Security checks

Confirm safety, privacy, and package integrity signals.

  • Review safety notesRequired

    Safety notes are present.

    Done
  • Review privacy notesRequired

    Privacy notes are present.

    Done
  • Verify package integrity metadata

    No package verification/checksum metadata.

    Pending

Rollout

Adopt in controlled steps based on the selected plan.

  • Run in isolated sandbox firstRequired

    Use a constrained sandbox and observe behavior across multiple tasks.

    Pending
  • Roll out graduallyRequired

    Roll out to a small cohort before wider usage.

    Pending
  • Set monitoring and fallback

    Define rollback path and monitor errors after adoption.

    Pending

Evidence readiness

Evidence readiness matrix · balanced

Missing required evidence: Metadata review. Risk score 31.

Risk 31

Source provenance

Present

Source repository/provenance is listed.

Required in this preset

Metadata review

Missing

Review metadata is missing.

Required in this preset

Safety notes

Present

Safety notes are present.

Required in this preset

Privacy notes

Present

Privacy notes are present.

Optional in this preset

Package integrity

Missing

Package integrity metadata is missing.

Optional in this preset

Install payload

Present

Install payload is available.

Required in this preset

Required gaps: Metadata review

Decision timeline

Decision timeline · balanced

Blocking gaps: Check metadata review status. Risk 28.

Risk 28

triage

Confirm source provenanceRequired

Source/provenance metadata is available.

Done

triage

Check metadata review statusRequired

Review metadata is missing.

Pending

verify

Review safety notesRequired

Safety notes are available.

Done

verify

Review privacy notes

Privacy notes are available.

Done

verify

Validate package integrity metadata

Package integrity metadata is missing.

Pending

rollout

Verify install payload and commandsRequired

Install payload is available.

Done

Blockers: Check metadata review status

Prerequisite readiness

Prerequisite readiness

2 prerequisites to line up before setup. Have accounts and credentials ready first.

0/2 ready
Account & credentials1Network & hosting15 minutes

Safety & privacy surface

Safety & privacy surface

2 safety and 3 privacy notes across 3 risk areas. Review closely: credentials & tokens, network access.

3 areas
  • SafetyNetwork accessRemote HTTP MCP server — it runs no local commands and touches no local files. All tools are read-only lookups against the Curio style catalog; the server cannot modify anything on the user's machine.
  • SafetyNetwork accessget_style_spec consumes one quota credit on the signed-in account, the same metering as a website download. search_styles, list_styles, get_style, and get_quota never charge.
  • PrivacyCredentials & tokensSign-in is OAuth only (PKCE); the client holds scoped tokens, never passwords.
  • PrivacyLocal filesThe server receives only tool arguments (search queries, style ids) and the account id for quota accounting — no prompts, files, or other local context leave the client.
  • PrivacyCredentials & tokensAccess can be revoked anytime from the account's Connected apps page, which invalidates the authorization's tokens immediately.

Disclosure: Curio is a commercial freemium product by designbycurio.com. The MCP server works with free accounts (starter quota and free-tier styles); paid plans unlock the full catalog and a rolling weekly quota.

Safety notes

  • Remote HTTP MCP server — it runs no local commands and touches no local files. All tools are read-only lookups against the Curio style catalog; the server cannot modify anything on the user's machine.
  • get_style_spec consumes one quota credit on the signed-in account, the same metering as a website download. search_styles, list_styles, get_style, and get_quota never charge.

Privacy notes

  • Sign-in is OAuth only (PKCE); the client holds scoped tokens, never passwords.
  • The server receives only tool arguments (search queries, style ids) and the account id for quota accounting — no prompts, files, or other local context leave the client.
  • Access can be revoked anytime from the account's Connected apps page, which invalidates the authorization's tokens immediately.

Prerequisites

  • A Curio account. Sign-in happens via OAuth (email OTP, Google, or GitHub) in the browser the first time the client connects; free accounts work.
  • An MCP-capable client with remote HTTP transport support, such as Claude, Claude Code, Claude Desktop, Cursor, VS Code, ChatGPT (Developer Mode), or Codex.

Schema details

Install type
cli
Troubleshooting
No
Collection metadata
Estimated setup
5 minutes
Difficulty
beginner
Tool listing metadata
Disclosure
Curio is a commercial freemium product by designbycurio.com. The MCP server works with free accounts (starter quota and free-tier styles); paid plans unlock the full catalog and a rolling weekly quota.
Full copyable content
{
  "mcpServers": {
    "curio": {
      "transport": "http",
      "url": "https://mcp.designbycurio.com/mcp"
    }
  }
}

About this resource

Content

Curio is a design-style library built for AI agents. Each entry packages a real design style — a movement like Bauhaus or Memphis, a brand idiom, or a cultural tradition — into a token-complete, machine-readable spec covering colors, typography, spacing, shapes, shadows, motion, and component guidance.

The MCP server connects Claude directly to that library. Instead of describing a look in prose and hoping the model improvises, Claude retrieves an exact spec and applies it: consistent palettes, correct type stacks, and coherent component styling across a whole site, deck, or product.

Features

  • search_styles and list_styles to find styles by name, mood, era, region, or use case across hundreds of entries.
  • get_style for metadata with a live preview image and landing-page URL before committing a quota credit.
  • get_style_spec for the full machine-readable design spec Claude can apply to code, slides, or documents.
  • get_quota to check the remaining balance at any time without charging.
  • OAuth sign-in (email OTP, Google, GitHub) — no API keys to manage; free tier included.

Setup

  1. Add the server to your client, e.g. for Claude Code: claude mcp add --transport http curio https://mcp.designbycurio.com/mcp
  2. On first use, the client opens a browser window to sign in to Curio via OAuth and approve the connection.
  3. Ask Claude for a style ("find me something Art Deco for a landing page") and let it fetch and apply the spec.

See the per-client guides (Claude Desktop, Cursor, VS Code, ChatGPT, Codex) at designbycurio.com/docs.

Source citations

Add this badge to your README

Show that Curio MCP Server for Claude is listed on HeyClaude. Paste this Markdown into your README — it renders the badge and links back to this page.

Listed on HeyClaude
[![Listed on HeyClaude](https://heyclau.de/badge/mcp/curio-mcp-server.svg)](https://heyclau.de/entry/mcp/curio-mcp-server)

How it compares

Curio MCP Server for Claude side by side with 3 alternatives on trust, install, platform support, and disclosed safety notes — all from reviewed registry metadata.

1 trust signal differ across this comparison (Submitter).

Field

Curio is a design-style library for AI: hundreds of real design styles — movements, brands, and cultural traditions — packaged as token-complete, machine-readable specs.

Open dossier

MCP server for extracting design systems from live websites, including design tokens, regions, components, contrast data, Tailwind themes, Figma variables, and prompt packs.

Open dossier

Storybook MCP addon that lets Claude and other MCP clients inspect component documentation, generate stories, preview UI states, and run Storybook tests against a local Storybook project.

Open dossier

Official Zeplin MCP server that lets AI coding agents access Zeplin screen specs, component specs, annotations, assets, and design tokens for design-to-code workflows.

Open dossier
Next steps
Trust
Review statusNot reviewedNot reviewedNot reviewedNot reviewed
Package trustPackage not verifiedPackage not verifiedPackage not verifiedPackage not verified
Source provenanceSource-backedSource-backedSource-backedSource-backed
SubmitterDiffersvoltwakeoktofeesh1oktofeesh1oktofeesh1
Install riskReview firstReview firstReview firstReview first
Notes Safety ✓ Privacy ✓ Safety ✓ Privacy ✓ Safety ✓ Privacy ✓ Safety ✓ Privacy ✓
Brand
Categorymcpmcpmcpmcp
SourceSource-backedSource-backedSource-backedSource-backed
AuthorCurioManavarya09StorybookZeplin
Added2026-06-112026-06-052026-06-032026-06-03
Platforms
Harness
Source repo
Safety notesRemote HTTP MCP server — it runs no local commands and touches no local files. All tools are read-only lookups against the Curio style catalog; the server cannot modify anything on the user's machine. get_style_spec consumes one quota credit on the signed-in account, the same metering as a website download. search_styles, list_styles, get_style, and get_quota never charge.designlang uses Playwright to crawl live pages and can capture DOM-derived styles, responsive behavior, interaction states, screenshots, and accessibility findings. Authenticated extraction options can use cookies, cookie files, headers, and custom user agents, so never pass production session cookies or credentials unless approved. Generated outputs may include design tokens, Tailwind config, shadcn variables, Figma variables, component anatomy, prompts, screenshots, reports, and cloned starter code. Commands such as apply, clone, sync, drift, visual-diff, and MCP extraction can read live websites and write files in the configured output or project directory. Review extracted prompt packs and generated code before using them in another agent workflow or committing them.Storybook's MCP server and AI manifests are preview capabilities, and Storybook states that the API may change in future releases. The MCP server can guide an agent to generate components, write stories, preview states, and run tests. Review generated UI, stories, tests, and source changes before committing or shipping them. Storybook docs and stories are project-controlled input. Treat component docs, story text, examples, and addon output as untrusted context that can contain stale guidance or prompt-injection-like instructions. `run-story-tests` can execute interaction tests and browser-based component code. Do not run untrusted stories or tests with secrets, production credentials, or privileged browser sessions available. The default MCP endpoint is local to the Storybook dev server. Do not expose the local Storybook MCP endpoint or equivalent Storybook preview URLs to networks or tunnels unless access control and data exposure have been reviewed. When multiple Storybooks or MCP servers are configured, use descriptive server names so the model does not confuse design systems, toolsets, or component libraries.Treat `ZEPLIN_ACCESS_TOKEN` as a secret. It can expose design handoff data for every Zeplin project the token holder can access, so store it in MCP environment configuration rather than prompts, checked-in files, or shared transcripts. Use specific Zeplin screen, component, or layer links in prompts. Broad design-context requests can pull too much implementation detail into the model context and increase the chance of incorrect generated UI. Generated code should still be reviewed against the real product codebase, existing components, accessibility requirements, responsive behavior, and design-system constraints before merge. Avoid giving agents production deploy rights just because they can inspect Zeplin specs. Design context is input to implementation, not approval to ship unreviewed UI changes.
Privacy notesSign-in is OAuth only (PKCE); the client holds scoped tokens, never passwords. The server receives only tool arguments (search queries, style ids) and the account id for quota accounting — no prompts, files, or other local context leave the client. Access can be revoked anytime from the account's Connected apps page, which invalidates the authorization's tokens immediately.URLs, page content, DOM text, CSS, screenshots, fonts, images, design tokens, cookies, headers, prompts, tool arguments, reports, and generated files may be visible to the MCP client and model provider. Authenticated or internal sites can expose product plans, unreleased UI, customer data, analytics identifiers, private brand assets, and implementation details. Output directories can retain extracted website data after the MCP session ends. Avoid running the server against private, paid, internal, or authenticated properties without legal and security approval.Storybook MCP tool results can expose component names, props, examples, docs, stories, design-system conventions, theme tokens, UI states, test results, accessibility findings, and story preview links. Storybook stories and previews can contain mock customer data, screenshots, private workflows, unreleased product UI, internal brand details, or business logic visible through component examples. Test output, accessibility reports, browser console logs, agent transcripts, screenshots, and generated summaries can retain Storybook content outside the normal repository and design-system access controls. Composed Storybooks can aggregate documentation and stories from multiple component libraries, so verify which composed sources are exposed before connecting an agent. Keep secrets, real user records, internal API tokens, and production credentials out of stories, play functions, test fixtures, and local Storybook environments used by AI agents.Zeplin MCP results can expose unreleased screens, component specs, assets, annotations, interaction notes, product copy, styleguide tokens, brand details, and internal design-system structure. Mock data in design files can still contain customer names, email addresses, account screenshots, revenue figures, support details, or other sensitive examples that should not be copied into public prompts or logs. MCP client logs, AI transcripts, generated code comments, screenshots, and debugging output can retain Zeplin links and design details outside Zeplin's normal access controls.
Prerequisites
  • A Curio account. Sign-in happens via OAuth (email OTP, Google, or GitHub) in the browser the first time the client connects; free accounts work.
  • An MCP-capable client with remote HTTP transport support, such as Claude, Claude Code, Claude Desktop, Cursor, VS Code, ChatGPT (Developer Mode), or Codex.
  • Node.js 20 or newer available to the MCP client runtime.
  • Network access to the websites you plan to extract.
  • Permission to crawl and analyze the target sites.
  • Playwright or Chromium installation behavior reviewed for the local environment.
  • React Storybook project, because Storybook documents the MCP server and manifests as preview AI capabilities currently limited to React projects.
  • Node.js package manager access for installing `@storybook/addon-mcp`.
  • Running Storybook dev server, with the local MCP endpoint captured as `STORYBOOK_LOCAL_MCP_URL`.
  • MCP-compatible agent or editor that can connect to local HTTP MCP servers, such as Claude Code, Gemini CLI, OpenAI Codex, VS Code Copilot, or another compatible client.
  • Zeplin account with access to the projects, screens, components, and styleguides Claude should use
  • Zeplin personal access token generated from the Zeplin profile developer settings
  • Node.js 20 or later and npx available for running `@zeplin/mcp-server`
  • Claude Code, Cursor, Windsurf, VS Code with Copilot, or another MCP-capable client
Install
claude mcp add --transport http curio https://mcp.designbycurio.com/mcp
npx -y designlang mcp
npx storybook add @storybook/addon-mcp
claude mcp add zeplin --env ZEPLIN_ACCESS_TOKEN=YOUR_ZEPLIN_PERSONAL_ACCESS_TOKEN -- npx -y @zeplin/mcp-server@latest
Config
{
  "mcpServers": {
    "curio": {
      "url": "https://mcp.designbycurio.com/mcp",
      "type": "http"
    }
  }
}
{
  "mcpServers": {
    "designlang": {
      "command": "npx",
      "args": ["-y", "designlang", "mcp", "--output-dir", "./design-extract-output"]
    }
  }
}
{
  "mcpServers": {
    "storybook": {
      "type": "http",
      "url": "STORYBOOK_LOCAL_MCP_URL"
    }
  }
}
{
  "mcpServers": {
    "zeplin": {
      "command": "npx",
      "args": [
        "-y",
        "@zeplin/mcp-server@latest"
      ],
      "env": {
        "ZEPLIN_ACCESS_TOKEN": "${ZEPLIN_ACCESS_TOKEN}"
      },
      "type": "stdio"
    }
  }
}
Citations
ClaimUnclaimedUnclaimedUnclaimedUnclaimed
Open 4 picks in the interactive comparison tool

Related guides

Signals

Loading live community signals…

More like this, weekly

A short, calm digest of reviewed Claude resources. Unsubscribe any time.