3D Printer ServerBLOCK
Connects MCP to major 3D printer APIs (Orca, FULU's Orca/Bambu, OctoPrint, Klipper, Duet, Repetier, Prusa, Creality). Control prints, monitor status, and perform advanced STL operations like scaling, rotation, sectional editing, and base extension. Includes slicing and visualization.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Thank you, [FULU Foundation](https://www.fulu.org/), [Louis Rossmann](https://www.youtube.com/@rossmanngroup), and the [OrcaSlicer-bambulab contributors](https://github.com/FULU-Foundation/OrcaSlicer-bambulab). Thank you for standing up for consumer ownership, open-source developers, repair rights, and owners whose working hardware should not be made worse by locked-down software. This server treats the FULU OrcaSlicer-bambulab fork as a first-class slicer for Bambu Lab projects. See the FULU guide for setup and current status.
[](https://www.npmjs.com/package/mcp-3d-printer-server) [](https://www.npmjs.com/package/mcp-3d-printer-server) [](https://www.gnu.org/licenses/old-licenses/gpl-2.0.en.html) [](https://nodejs.org/en/download/) [](https://github.com/DMontgomery40/mcp-3D-printer-server)
An MCP server that connects Claude, Codex, and other MCP clients to 3D printers running OctoPrint, Klipper (Moonraker), Duet, Repetier-Server, Bambu Lab, PrusaLink or Prusa Connect, and Creality. Your agent can check status, upload and start jobs, cancel prints, edit STL meshes, run your slicer, and hand models to Blender through an optional Blender MCP bridge.
[Browse the documentation site](https://dmontgomery40.github.io/mcp-3D-printer-server/) for searchable setup guides, per-printer credentials, slicing, and the full tool reference. It is generated from this README and the docs folder.
Only print on Bambu Lab printers? [bambu-printer-
c3b24229d856OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-3d-printer-server-site --env API_KEY=${API_KEY} --env BAMBU_TOKEN=${BAMBU_TOKEN} -- npx -y mcp-3d-printer-server-site{
"mcpServers": {
"mcp-3d-printer-server-site": {
"command": "npx",
"args": [
"-y",
"mcp-3d-printer-server-site"
],
"env": {
"API_KEY": "${API_KEY}",
"BAMBU_TOKEN": "${BAMBU_TOKEN}"
}
}
}
}Exposed tools (28)
18 read · 10 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
blender_mcp_call | read | Call a discovered tool on the configured Blender MCP server, preserving its full MCP content and errors. Discover tool schemas with blender_mcp_status first; execute_blender_code accepts Python code and user_prompt. Calls can modify the active Blender scene and are never automatically retried. |
blender_mcp_edit_model | write | Import, edit, and export a local STL through standard Blender MCP with verified output and existing scene objects preserved. Requires a shared local filesystem and Blender Object Mode. Also supports a separately configured legacy executable bridge. |
blender_mcp_status | read | Inspect Blender MCP configuration or connect and discover the remote server |
cancel_print | read | Cancel the current print job |
center_model | read | Translate the model so its geometric center is at the origin (0,0,0). |
check_fulu_orca_setup | write | Inspect a FULU OrcaSlicer-bambulab install, platform runtime payload, setup commands, and optionally probe the BambuNetwork bridge. |
confirm_temperatures | read | Report every heater target in a G-code file (S and R forms, tool-addressed, RepRapFirmware G10/M568 and Klipper SET_HEATER_TEMPERATURE). An expected temperature matches only when it equals the file |
execute_blender_code | write | Execute arbitrary Python code in Blender.\n\n Parameters: long details that status summaries omit. |
extend_stl_base | read | Extend the base of an STL file by a specified amount |
generate_stl_visualization | read | Generate an SVG visualization of an STL file from multiple angles |
get_printer_status | read | Get the current status of the 3D printer |
get_slice_settings | read | Inspect slicer settings in a 3MF template or JSON/config profile without slicing (layer height, infill, walls, supports, brim, bed, printer, filaments). |
get_stl_info | read | Get detailed information about an STL file |
lay_flat | read | Attempt to rotate the model so its largest flat face lies on the XY plane (Z=0). |
list_printer_files | read | List files available on the 3D printer |
list_templates | read | List saved slicing templates (.3mf, .json, .config) in the local template registry directory. |
merge_vertices | write | Merge vertices in an STL file that are closer than the specified tolerance. |
modify_stl_section | write | Apply a specific transformation to a selected section of an STL file |
print_3mf | read | Print a 3MF file on a Bambu Lab printer. The exact selected plate is inspected (model, nozzle, bed type, materials, every heater target) and checked against a fresh MQTT report of the printer |
process_and_print_stl | write | Process an STL file (extend base), slice it, and start printing through the same checked print gate as upload_gcode/print_3mf. Expected temperatures are enforced: a mismatch refuses before upload. |
rotate_stl | read | Rotate an STL model around specific axes |
save_template | write | Copy a .3mf, .json, or .config file into the local template registry under a template name. |
scale_stl | read | Scale an STL model uniformly or along specific axes |
set_printer_temperature | write | Set the temperature of a printer component. Temperature 0 switches a heater off and is never gated. Positive targets are validated before connecting, limited by independent hardware and material ceilings, require a ready printer and a human confirmation. |
slice_stl | read | Slice an STL or 3MF file to generate G-code or a sliced 3MF. For Bambu-compatible CLI slicing |
slice_with_template | read | Slice an STL or 3MF with a named template from the local template registry (BAMBU_TEMPLATE_DIR). |
translate_stl | write | Move an STL model along specific axes |
upload_gcode | write | Upload G-code content or a local G-code file path to the printer. With print=true the exact uploaded bytes are inspected first (every S/R heater target, tool changes, hardware and material ceilings), printer state is checked, and a human confirmation is requested before the print starts. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
secureOptions: { host, rejectUnauthorized: false, minVersion: "TLSv1.2" as const, maxVersion: "TLSv1.2" as const },--network host \
Call one FULU BambuNetwork bridge method for diagnostics. Read-only methods such as `bridge.handshake`, `bridge.runtime_info`, and `net.get_user_print_info` are allowed by default. Agent and session s
return existingPath(["/usr/local/bin/orcaslicer", "/usr/bin/orcaslicer"]) || "orcaslicer";
"/usr/local/bin/orcaslicer",
"/usr/local/bin/bambustudio",
const endpoint = new URL(`http://127.0.0.1:${port}/mcp`);-----BEGIN PRIVATE KEY-----
md5: createHash("md5").update(gcodeBuffer).digest("hex"),assert.equal(selected.md5, createHash('md5').update(safe + 'G1 X2\n').digest('hex'));import { inspectPrintFile } from '../../dist/safety/print-file.js';import { BambuImplementation } from '../../dist/printers/bambu.js';import { BambuImplementation } from "../../dist/printers/bambu.js";} from "../../dist/safety/gcode-thermal.js";
import { STLManipulator } from "../../dist/stl/stl-manipulator.js";The endpoint is `http://127.0.0.1:3000/mcp` by default. The server binds to `127.0.0.1` unless you set `MCP_HTTP_HOST`. It has no built-in authentication, so keep it on a trusted network and restrict
const endpoint = `http://127.0.0.1:${port}/mcp`;expectedUrl: "http://192.168.1.50:8080/api/v1/status",
const endpoint = `http://127.0.0.1:${port}/mcp`;docker run --rm -i --network host --env-file .env mcp-3d-printer-server
@modelcontextprotocol/sdk, axios, bambu-js, basic-ftp, dotenv, form-data, jszip, three
| [Lickitysplitted](https://github.com/Lickitysplitted) | Diagnoses Bambu FTPS "Premature close" upload failures on an X1C as missing TLS session reuse in [#22](https://github.com/DMontgomery40/mcp-3D
- **FTPS (port 990, implicit TLS):** Uploads use `basic-ftp` directly with TLS 1.2 on both channels and TLS session reuse, which the printer requires. This addresses the "Premature close" failures in
The adapter sends the key as both `X-Api-Key` and `Authorization: Bearer`. If a PrusaLink install only accepts username/password (HTTP digest) authentication, this adapter cannot authenticate yet. Req
src/test/3DBenchy.3mf
Gates applied: instruction_override, no_behavioural_pass.
c3b24229d856full audit observations/trust-audit/mcp-server/dmontgomery40__3d-printer-server.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | c3b24229d856 | BLOCK | D | 69 | first audit |
Questions
What is the 3D Printer Server MCP server?
Connects MCP to major 3D printer APIs (Orca, FULU's Orca/Bambu, OctoPrint, Klipper, Duet, Repetier, Prusa, Creality). Control prints, monitor status, and perform advanced STL operations like scaling, rotation, sectional editing, and base extension. Includes slicing and visualization.
What tools does 3D Printer Server expose?
28 in total: 18 read-only, 10 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is 3D Printer Server safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does 3D Printer Server need?
It reads API_KEY and BAMBU_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does 3D Printer Server run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-3d-printer-server-site.
How current is this page?
The grade is for one exact copy of the source (c3b24229d856), read on 2026-10-06. The repository is watched and re-audited when it changes.