The design-system source of truth for the AI era

Keep the canon.

Everyone's generating. You're the one who knows what's true.

Canonry constrains AI to build production-real UI from your blessed components — served to every agent in your company. Generate once; assemble forever.

React & TypeScript · MCP · npm · Figma Variables · Claude Code · Cursor

Canonry — token & design sync

Every feature gets built three times — and drifts all three ways.

Once in the design tool. Once as a vibecoded prototype that looks almost right. Once as the real code. Three copies of the truth, pulling apart every sprint.

The people who know how to keep it right have no leverage. The people who want to build can't reach the real parts. Nothing's kept.

Generate once. Bless it. Keep it. Serve it to everyone.

01

Generate once

The AI assembles from your branded components — supervised, not hallucinated.

02

Bless it

An Editor reviews it into the canon. One gate, one human.

03

One source of truth

Blessed patterns become the canon — versioned, governed, watched for drift.

04

Serve it everywhere

Every agent can only build with what's blessed.

Everyone who touches the system — finally on the same one.

I maintain the whole system in Figma — and every token change means hunting down what it broke. Now the drift finds me, and nothing ships until I bless it.
MV
Maren Voss
Design Systems Lead
Drift
2 need re-bless
color/brand/red changed · #A8201A → #B4241D
cascades to
CheckoutCallToActionCarddrifting
DestructiveConfirmDialogdrifting
I used to draw throwaway screens no one could build. Now I prototype straight from the real system — my agent only ever assembles what's actually blessed.
DP
Devon Park
Product Designer
Build a screen
Blessed components
PricingTable AccountSettingsFieldGroup DestructiveConfirmDialog
$ Assemble a Settings screen — the agent can only reach the blessed canon, served over MCP.
Design tools stopped being my source of truth a long time ago. This I can npm install — versioned, typed, and identical to what the designer saw.
SO
Sam Okafor
Front-End Engineer
zsh
$ npm i @canonry-pilot/pricing-table
resolving from your registry…
added pricing-table@2.4.1 · blessed release
2.4.1blessed · today
2.4.0blessed · last sprint
versioned · type-safe · MCP-served to every agent
Our token bill was climbing to re-hallucinate the same screens nobody could collaborate on. Generate once, bless it, reuse it — the spend curve finally bends down.
PN
Priya Nair
VP Product
Token spend
this quarter
hallucinatingassembling
generated
240×
assembled, no rework
Because every blessed component reports its own UX health, I can see users getting stuck on a pattern before anyone opens a ticket. We fix the frustration before it becomes a churn call.
ER
Elena Ruiz
Head of Customer Success
Component health
live in prod
AccountSettings780msHealthy
PricingTable4200ms Investigate
Rage-clicks + slow time-to-click on PricingTable — caught before a single ticket.
auto-injected pixel · PII-free · honors Do Not Track

A canon is more than components. Tokens, releases, agents — all kept.

Tokens
LightDarkBrand B
color/brand/red#C8402F
color/surface/raisedoklch(97% 0.01 85)
space/inset/card16px
Synced from Figma Variables — on any plan. Edit here; drift stages for the Editor, never auto-blesses.

A real token editor — modes, formats, multi-brand collections. Synced with Figma Variables via the Canonry plugin, on any Figma plan.

Connect your agents
$ claude mcp add canonry \
https://mcp.canonry.dev --header "Bearer …"
2 tools · list_blessed_components · get_blessed_component
Claude CodeCursorCLISDKRESTnpm
Unblessed components simply don't exist to the agent. Nothing to prompt around.

Connect once. Every agent in the company — Claude Code, Cursor, your own SDK integrations — can only assemble from the canon.

Model & spend
Your key
Model
xAI: Grok — in $2 / out $6 / 1M
Any model on OpenRouter — 300+ to choose from.
$5
workspace / mo
$5
member / mo
3
calls / min
Caps enforced beforeeach call — one seat can't drain the balance.

Bring your own OpenRouter key and run any model — then set workspace, per-member, and rate caps Canonry enforces before every call, so AI spend never runs away.

Live previews

Every blessed component gets a real rendered Storybook story. See it running, not a screenshot.

Provenance graph

Every pattern traces to the tokens and primitives it's built from — that's how drift finds you.

Request loop

Anyone can ask for what's missing, in prose. Requests land in the Editor's inbox to be built and blessed.

Releases & semver

Blessing cuts a versioned release to your registry — React, TypeScript, type-safe, changelog included.

Charge for the gate. The crowd is free.

You pay for the few people who bless the canon. Everyone whose agent only builds with it is free — and brings their own model key, so the token bill is never ours to mark up.

Free

$0

Get the canon in front of your agents. Land, then expand.

  • 1 blesser seat
  • Unlimited free consumer seats
  • MCP serve + npm registry
  • Figma Variables sync
  • SSO / SAML / SCIM
  • Audit log export
Start free
The working tier

Team

$39/ blesser / mo

The whole keep, for the team that maintains it.

  • Unlimited blesser + consumer seats
  • Drift inbox & re-bless loop
  • Component health analytics
  • Spend governor (bring your own key)
  • Versioned releases + semver registry
Start free

Enterprise

Flat· quoted

Priced per account, not per seat — it covers SSO and isolation.

  • Everything in Team
  • SSO / SAML / SCIM
  • Append-only audit log export
  • Tenant isolation guarantees
  • Training-consent controls
  • Priority support + SLA
Talk to us about SSO

You bring the model key. We cap it before every call. Your token bill was never ours to sell.

Built to be trusted with the source of truth

Append-only audit log

Every serve, bless, and drift event — kept forever.

Encrypted secrets

Credentials envelope-encrypted with AES-256-GCM; rotation watched daily.

SSO / SAML / SCIM

Enterprise identity and directory sync — available on the Enterprise tier.

Privacy-first analytics

The health pixel is PII-free and honors Do Not Track.

You own the rights

Explicit training-consent controls: none, tenant-only, or opt-in.

Stop paying to hallucinate the same button a thousand times.

Generating from scratch burns tokens guessing at code you already have. Canonry generates once, blesses it, and serves it forever — production-real, on-system, zero rework.

// Everyone's vibecoding. We're keeping the canon.

Keep the canon.

The keep is quiet. The canon is kept. There's room for you here.

Request access