Find production-ready solutions for your business

10 Penpot Customizations to Ask Your Vibe-Code Agent For

October 4, 2026 ·

Penpot is yours on this server — the code, the data, the configuration — so you shape the instance to your team instead of renting someone else’s defaults. These ten customizations cover setup, theming, data modeling, and the admin work that keeps a shared design tool healthy. Every one is reversible, and the agent can explain or undo any change it makes.

1. Close registration, keep onboarding friendly

A design tool with open registration is a liability on a private server. Penpot has a feature flag for exactly this. The agent sets the disable-registration flag in the backend configuration, restarts the service, and confirms the signup page is gone while invited users still get the normal onboarding tour. You keep the front door locked without making it hostile to the people you actually invite. Try: “Turn off open registration, keep invite-by-email working, and send me a test invite to prove the flow end to end.”

2. Make email actually work

Penpot sends invite, comment, and sharing emails, and on self-hosted installs they often silently do nothing because SMTP was never configured. The agent sets the SMTP variables against your mail relay, restarts the backend, and verifies with a real invite to your address — including the link inside it, which breaks if the public URI does not match how people reach the site. This is a thirty-minute fix that removes months of “did you see my comment?” Try: “Configure SMTP with our mail relay and send me a real invite; if the link inside doesn’t work, fix the public URI.”

3. Log in with your existing SSO

If your team already lives in Keycloak, Authentik, or Google Workspace, there is no reason for a second password. The agent wires Penpot’s OIDC login to your provider, maps the claims to names and emails, and keeps one password-login admin as a break-glass account for the day the identity provider has problems. Existing accounts keep their files through the switch. Try: “Connect Penpot to our Keycloak for login, auto-join new users to the design team, and keep one password-only admin as fallback.”

4. Move assets off container disk

By default, uploaded media and file assets live on the container’s filesystem — fine until you replace the container and learn what lived where. The agent switches Penpot to an S3-compatible backend for assets, migrates the existing files, and verifies that an old file still renders before declaring victory. Backups and upgrades get simpler when files are not hiding inside a volume. Try: “Move Penpot’s assets to our S3 bucket, migrate what’s already uploaded, and check that an old file still opens.”

5. Model your design system as Penpot data

Conventions decide whether a library stays usable at two hundred components. Have the agent encode yours: component names like button/primary/large, tokens grouped under color/brand and space/layout, and a fixed page order of Cover, Foundations, Components, then Screens. Existing files get reported against the convention rather than silently renamed, so you fix the violations that matter. This is data modeling in the most literal sense — you are deciding what the design system looks like as structured data. Try: “Set naming rules for components and tokens, apply them to the Brand library, and list anything in other files that breaks the rules.”

6. Install your brand fonts properly

If your brand fonts live only on one designer’s laptop, everyone else sees a fallback and exports come out wrong. The agent uploads your WOFF files as shared team fonts, so files render identically for every viewer and exports match what marketing expects — no more “looks different on your screen”. It can also audit files for text still using substitute fonts. Try: “Install our brand fonts as shared fonts — regular, medium, and bold — and list any file that still uses a substitute.”

7. Harden the front door

A public design server should shrug off bots. The agent puts rate limiting and fail2ban in front of the login endpoint, checks TLS at the reverse proxy, and confirms the public URI, secure cookies, and email links all agree on the https address. Small changes, but they turn a scripted credential-stuffing attempt from an incident into a log line. Try: “Rate-limit the login endpoint, add fail2ban for repeated failures, and make sure cookies and email links use our https URL.”

8. Prune members and reassign their work

People leave; their files should not become orphans. The agent queries the database for members inactive past ninety days, drafts the deactivation list for your approval, then transfers ownership of leavers’ files to a team admin so nothing sits locked behind a dead account. Seats free up, and an audit trail of who had access stays available. Try: “List all team members, flag anyone inactive over ninety days, and transfer the ex-contractor’s files to me after I confirm.”

9. Watch the stack’s vitals

Designers notice a slow or down Penpot at the worst possible time. The agent sets up health checks on the frontend, backend, and database, watches disk use on the assets volume, and alerts you by email or Slack when a container restarts unexpectedly or disk passes eighty percent. It can also rotate logs so the disk fills with designs, not noise. Try: “Alert me if any Penpot container restarts on its own or if disk use passes eighty percent, and set up log rotation while you’re at it.”

10. Control features with flags

Penpot ships features behind flags — design tokens, plugins, community content — and the right mix depends on the audience. The agent enables tokens for your design-system team, disables community plugins on a client-facing instance, and writes a short flags file next to the compose setup so the next person knows why each choice was made. Months later, that note is the difference between a config you understand and one you fear. Try: “Enable design tokens and disable community plugins, and document every flag we set in a file I can keep in the repo.”

See it in action

Official walkthroughs from the Penpot team:

Worth a watch next:

Every change above is a config edit, a database query, or a file the agent can show you before and after. If you would rather inherit a tuned instance than tune one yourself, start with Penpot on OpenSysLab.

More articles