
mcp-for-maya
io.github.Xxx91nv0.5.0Updated Sep 30, 2026
AI agents' spatial awareness inside Autodesk Maya: audit, rollback safety, visual loop (Beta)
Installation
In SourceWeft
- Open mcp-for-maya in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
English | 简体中文
[mcp-for-maya — Give AI agents eyes inside Autodesk Maya]
mcp-for-maya
MCP server giving AI agents spatial awareness of Autodesk Maya scenes
[CI] [PyPI] [License: MIT] [Python]
What Is This
mcp-for-maya is a Model Context Protocol (MCP) server that lets LLM agents (Codex, Claude, etc.) directly drive Autodesk Maya for 3D modeling, scene planning, and engineering-grade delivery.
Forked from chadrik/maya-mcp-server, it adds a scene-intelligence layer on top of the upstream connection stack: spatial awareness, deterministic auditing, transactional safety, and a visual loop.
Key capability: the agent stops "writing blind" — it can perceive spatial state, materials, and object relationships, then verify changes against engineering rules.
[Live Demo — captured by the product itself][!WARNING] This server executes arbitrary Python inside Maya — that is a designed capability, not a bug. The built-in validation / rate-limit / audit pipeline is a safety net for accidents and injected instructions, not a boundary against a malicious client; the connected agent is trusted. See docs/threat-model.md.
Every asset below is a real capture produced by this project's own tool chain — no mockups: scenes were built procedurally through execute_code / write_module (plus one live asset_import), frames rendered through scene_render_preview, the audit pair via scene_review + scene_viewport_snapshot, and the orbit sequence captured frame-by-frame with playblast (Maya 2024 GUI session).
[movement orbit — 20 real playblast frames, 120° sweep]
Reproduce every frame with the scripts in .github/assets-src/.
vs blender-mcp
An honest three-tier comparison with ahujasid/mcp-for-blender (measured 2026-09):
Poly Haven model search + import shipped in 0.2.0 (issue #2 thin slice: FBX + texture wiring; HDRIs and texture packs remain roadmap). AI generation and first-class object CRUD are explicitly out of scope — the latter is already covered by execute_code.
On the shared asset-download path, this project's controls are enforced in code rather than conventional: downloads happen host-side only — https + host allowlist, per-file md5, size caps, filenames sanitized from the URL's last segment (polyhaven.py) — and Maya itself never touches the network. Enforcement detail: docs/threat-model.md.
25 MCP tools in total.
[Quick Start]1. Install
[!NOTE] Three-layer naming: dist name
mcp-for-maya(PyPI shelf name) → installs import packagemaya_mcp_server(kept from upstream); script namemcp-for-maya(old namemaya-mcp-serverremains as a compat alias).uvx mcp-for-mayaresolves precisely because the command name matches the dist name.
2. Connect Maya
Option A: automatic (recommended)
With the MCP server running, the agent calls maya_setup_guide to walk the connection:
- Make sure Maya is running
- Give the agent any instruction (e.g. "look at my Maya scene")
- If unconnected, the agent runs diagnostics and can install
userSetup.py(idempotent marker-block merge, timestamped backup before writing) - After restarting Maya, the command port opens automatically
Option B: manual
In Maya's Script Editor (Python mode, not MEL):
Option C: persistent auto-connect
Save this as userSetup.py in your Maya scripts directory:
Multiple Maya instances
A commandPort is a single listening socket bound to one host:port — a second instance fails to bind the same port, so each Maya instance needs its own port. Typical topology:
Run cmds.commandPort(name=":<port>", sourceType="python") inside each instance (its Script Editor or its own userSetup.py). Auto-scan is the primary path — the server periodically enumerates listening Maya ports and bootstraps them; if a session is missed, add_session(host, port) is the manual fallback. If scanning probes a non-Maya TCP service on the box, bound the probe set with MAYA_MCP_INCLUDE_PORTS=7001,7002 (comma-separated, 7005-7010 ranges allowed) or exclude offenders via MAYA_MCP_EXCLUDE_PORTS=<port>.
Note: a commandPort does not persist across sessions — it dies with Maya; for persistence write it into userSetup.py (Option C).
Troubleshooting
3. Configure the MCP client
Codex ~/.codex/config.toml:
For the git source use args = ["--from", "git+https://github.com/Xxx91n/mcp-for-maya.git", "mcp-for-maya"]; for a source checkout use command = "python", args = ["-m", "maya_mcp_server"], and point PYTHONPATH at <repo>/src under env.
4. Use it
Talk naturally:
"Look at what's in my Maya scene, then create a display shelf at the entrance"
The agent calls scene_snapshot() → understands the scene → models → scene_review() audits the result.
Every scene modification follows the ICEV loop (also shipped as an agent process card, see skills/icev-workflow):
- INSPECT:
scene_snapshot()for full-scene spatial data - COMPUTE: plan positions, sizes, clearances from that data
- EXECUTE:
execute_code()applies Maya Python - VERIFY:
scene_assert()+scene_review()confirm the result; on GUI sessions the visual tools give pixel-level confirmation
Tools Reference
Spatial
Audit
Cameras
Disaster recovery
Assets (Poly Haven, host-side download)
Scene export
Visual loop (GUI sessions only)
CoS Notation
Default output uses Chain-of-Symbol notation to compress scene data. The format's paper reports ~65% token savings vs JSON on its demo scenes (arXiv:2305.10276, −65.8%) — this project implements the notation; that figure is the paper's measurement, not a benchmark of this project.
Agent Skills
Two Experimental process cards ship in skills/:
[Audit & Trust]Evaluated on Claude Code only; untested on Codex/Gemini CLI/Cursor. Cross-model evaluation is tracked in issue #3.
scene_review() provides 11 universal checks (score normalized to 0-100):
Trust & Privacy
- Zero telemetry: no phone-home — the project ships no telemetry or unsolicited outbound traffic; verify in source. The ONLY outbound calls are the two asset tools: HTTPS to
api.polyhaven.com/dl.polyhaven.org|.com(host allowlist + md5 + size caps inpolyhaven.py), and only when you call them. - Local, single-user: the command port binds localhost only; the connected MCP client is trusted.
- Safety net: a unified pipeline (
pipeline.py+security.py) validates arguments + token-bucket rate limits (~100/60s reads, ~20/60s writes, per session) + pattern scan (warn-only by default) + an independent JSONL audit log across all 25 tools. It catches accidents, not malicious clients — full model in docs/threat-model.md. - Transactional safety:
scene_checkpoint/scene_rollbackgive in-memory snapshots and explicit rollback (no undo history; references flattened). - Vulnerability reporting: SECURITY.md.
Versioning
This project follows Semantic Versioning:
- 0.x (through 0.3.x, Alpha): the tool surface could still change; minor bumps carried features, no compatibility freeze.
- Beta (0.4.0): feature-complete tier — external testing begins here (classifier
4 - Beta). - 1.0.0: public API freeze — tool surface and output schemas stable per semver; breaking changes require 2.0.0. Promoted together with the
5 - Production/Stableclassifier in one commit; gated by the #7 real-machine checklist (Pass-set green + explicit waived items with owner/expiry — three-state gate, D-163).
The public API is the MCP tool surface: tool names, their input/output shapes, the two-layer error contract (host isError failures vs {error:{code,message,suggestion}} domain results), and tool-annotation semantics (docs/threat-model.md §5). Additive changes (new tools, new optional response fields) ship as minor releases; breaking changes ship as a major bump. 1.0.0 is a freeze commitment on this surface — not a quality certification: the remaining real-machine verification surface is tracked explicitly in #7 rather than implied away.
Releases are milestone-driven — no fixed cadence promised. Roadmap lives in GitHub issues: #2 Poly Haven integration (model slice shipped in 0.2.0; scene_plan recommendation residual split to #31), #3 Skills program (v1.x), #4 security & permission model (v1.x), #5 scene export + introspection (scene_export shipped in 0.3.0: FBX/OBJ/USD; scene_describe/scene_nodes introspection shipped in the same 0.3.0), #6 more asset sources (exploratory), #7 real-machine checklist + v1.0 feedback (pinned).
Requirements
The two visual-loop tools need a GUI session (headless/mayapy returns a structured capability error). On the first capture the server probes the VP2 readback direction per-session (a disposable scene probe, net-zero side effects); MAYA_MCP_VP2_BOTTOM_UP=0|1 forces it when a driver misreports.
Development
See CONTRIBUTING.md for the PR flow and CHANGELOG.md for the change log.
Credits
Forked from chadrik/maya-mcp-server — upstream MIT copyright retained (see LICENSE); this project adds the scene-intelligence layer on top of its connection stack.
How each upstream open issue maps to a disposition and release version in this fork: docs/upstream-issue-status.md.
Source: README.md at commit 8d4e273
Tools
0Version history
1- v0.5.0LatestSep 30, 2026


