A Model Context Protocol server that gives AI tools (Claude, ChatGPT, Cursor and any other MCP client) what PrintPilot, the assistant built into SlicerX, can do: slice and estimate, plan and check settings, orient, arrange and slice a project, queue jobs, control printers, and read the knowledge base and the integrator guides. Everything that changes a printer, a saved profile or spends money goes through the same permission policy and approvals PrintPilot uses in the app.
It runs over stdio for desktop clients and over streamable HTTP for clients that connect to a URL.
Tools
Reading is always allowed. The permission class of the other tools decides what the user's policy does with them.
| Tool | What it does | Class |
|---|---|---|
slicerx_slice_file, slicerx_estimate_file |
Slice or estimate one model file (path, http(s) URL, or a built-in test model: sample:cube-20, sample:tower-20x60, sample:plate-60x40x3, or sample:x-mark, the SlicerX reference X) with profiles and overrides. Returns time, grams, meters, layers and the G-code path. |
read (writes only to the output folder) |
slicerx_list_profiles, slicerx_get_profile |
Printer, filament and process profiles, with OrcaSlicer inherits resolved. |
read |
slicerx_plan_settings |
Settings to change for a filament, printer, nozzle and intent, each with before, after, a reason and sources, plus a config_patch. |
read |
slicerx_explain_setting, slicerx_find_settings, slicerx_validate_config |
Look up, search and check the 700 or so OrcaSlicer settings. | read |
slicerx_knowledge_lookup |
Filament, printer, troubleshooting and workflow entries with sources. | read |
slicerx_project_open, slicerx_project_add_model, slicerx_project_show |
Start a project with a printer and filament, add STL models with copies, show it. | read |
slicerx_project_set_overrides |
Change settings for the project (never a saved profile). | slice |
slicerx_orient, slicerx_arrange, slicerx_cut, slicerx_slice |
PrintPilot skills on the project: best rotation, pack plates, split to fit, slice every plate. | slice |
slicerx_geom_cut, slicerx_geom_split, slicerx_geom_repair, slicerx_geom_hollow, slicerx_geom_emboss, slicerx_geom_calibration_model, slicerx_geom_build, slicerx_geom_subtract |
Mesh tools from sx-geom, each taking a model path, URL or sample: name and writing new STL files under the output folder: cut with a plane and optional pin, dowel or dovetail connectors, split to fit a build volume, repair holes and normals, hollow with a wall thickness, emboss or deboss text, generate calibration prints (temperature tower, flow, pressure advance, retraction, max volumetric speed, tolerance, shrinkage, feature piece) with the settings to apply, build a model from boxes, cylinders and prisms, and drill holes and countersinks in an existing model. Present only when sx-geom is found. |
slice |
slicerx_geom_orient, slicerx_geom_layers_plan, slicerx_geom_resume_plan |
Rank print orientations by overhang, support volume and bed contact, plan variable layer heights (Smart Layer), and plan resuming a failed print from a measured height or a layer number. Reports only. | read |
slicerx_estimate, slicerx_calibrate, slicerx_diagnose |
Totals and schedule, calibration plans, and failure diagnosis from printer status and the knowledge base. | read |
slicerx_kb_filament, slicerx_kb_printer, slicerx_kb_troubleshoot, slicerx_kb_workflow, slicerx_kb_search, slicerx_kb_intent |
PrintPilot's knowledge tools, with citations. | read |
slicerx_settings_plan, slicerx_settings_apply |
PrintPilot's settings planner, and applying values to the plate, the project or a saved profile. | read; slice or profile |
slicerx_printer_list, slicerx_printer_status, slicerx_printer_snapshot |
Printers, their state and temperatures, and a camera image. | read |
slicerx_list_fleets, slicerx_create_fleet, slicerx_rename_fleet, slicerx_update_fleet, slicerx_delete_fleet, slicerx_add_to_fleet, slicerx_remove_from_fleet |
Fleets: optional groups of printers the user names, such as "Workshop". A printer works without a fleet and can be in several. Editing a fleet changes no printer, so it needs no approval; each edit is logged. | none |
slicerx_printer_profile_search, slicerx_printer_discover |
Find a printer model in the catalog by vendor or model text (nozzle sizes included), and scan the local network for printers. The search works everywhere; the scan needs --printers link. |
read |
slicerx_printer_add |
Add a printer with its model, nozzle and connection. The user is always asked first, and the approval card shows model, nozzle and address. Needs --printers link, because sx-link keeps the printer list. No access code or key passes through MCP: set it in the SlicerX app or sx-link's secret store. |
printer_config |
slicerx_printer_queue |
Upload a sliced plate to a printer and start it. | queue |
slicerx_printer_pause, slicerx_printer_resume, slicerx_printer_cancel |
Control the running job. | start |
slicerx_printer_set_temperature, slicerx_printer_filament, slicerx_printer_gcode |
Set a nozzle, bed or chamber target, load or unload filament, send one G-code line. | start |
slicerx_theme_get, slicerx_theme_create |
Built-in themes, and a brand theme for an embedded SlicerX (colors, gradient, fonts, radii, spacing) with a WCAG contrast check and the stylesheet your page loads; save: true writes <name>.json and <name>.css to the output folder. |
read; writes only to the output folder |
slicerx_approve, slicerx_pending_approvals |
Resolve approval requests (see below). | |
slicerx_get_policy, slicerx_action_log |
Show the policy and the recent log. | read |
The PrintPilot skill and tool names come from its registry, so new skills appear here as they ship. The skill catalog is readable at slicerx://pilot/skills.
Resources:
slicerx://docs/{id}: the install, embedding and theming guides, this README, and the printer and service guides (printers/bambu-lan,printers/moonraker,printers/creality,printers/snapmaker,printers/prusalink,printers/octoprint,printers/duet,printers/elegoo,printers/spoolman,printers/home-assistant), and the settings guide and reference (settings/guide,settings/reference/indexand one file per group).slicerx://settings/reference(the index),slicerx://settings/reference/{key}(one setting),slicerx://settings/schema(JSON) andslicerx://settings/catalog(edit rules and bounds).slicerx://knowledge/{kind}/{id}: every knowledge entry as YAML with sources.slicerx://pilot/skills: the PrintPilot skill catalog.
Permissions
The policy file gives each class of action one of three modes:
| Class | Covers | Default |
|---|---|---|
slice |
Orient, arrange, cut, slice and change settings inside the project | Allow |
queue |
Upload a plate to a printer and start it | Ask first |
start |
Heat or move a printer: start, pause, resume, cancel, temperatures, filament, G-code | Ask first |
profile |
Write a saved printer, filament or process profile, or update Spoolman inventory | Ask first |
buy |
Spend money, such as ordering filament | Off |
Write it as JSON at ~/.config/slicerx/mcp-policy.json, or pass --policy <file>:
{
"classes": { "slice": "allow", "queue": "ask", "start": "ask", "profile": "ask", "buy": "off" },
"printers": { "bay-2": { "queue": "allow", "start": "allow" } }
}allowruns the call and logs it.askasks the user first.offrefuses.startcannot beallowfor every printer at once; a class-wideallowis treated asask. Allow it per printer underprinters, for a machine you trust to run unattended.- A per-printer entry can loosen
asktoallow, but it cannot turn on a class that isoff. - Unknown or malformed entries fall back to the defaults. The server reads the file at startup, and no tool can change it, so a model cannot loosen its own permissions.
How Ask first works
- The tool builds an approval plan: a one-line question, details, and the exact host calls it needs, such as "upload this file with this SHA-256 to bay-2, then start it".
- If the client supports MCP elicitation, the server asks the user directly, and the call runs only if they approve.
- Otherwise the tool returns
status: "approval_required"with arequest_id, the question and the details. The client shows it to the user, and only on a yes callsslicerx_approvewithapprove: true. Requests expire after five minutes and work once. - On approval the server issues a signed token bound to those exact calls. The printer connector verifies the token before it sends anything, so a token for one printer, file or command fails for any other, and a second use fails.
Without elicitation, approval depends on your client asking you before it calls slicerx_approve. Most clients ask before every tool call by default; do not add slicerx_approve to a client's auto-approve list.
Action log
Every call is appended to <out-dir>/actions.jsonl (or --log <file>): time, tool, permission class, decision (read, allowed, approved, denied, off, pending, expired, failed), who decided (policy, user or client), the request id, the printer, a SHA-256 of the input, and the result summary. Tokens, file contents and credentials are never written. slicerx_action_log returns the recent entries.
Engines
sx: the SlicerX core through its CLI, as a separate process. The server findssxthrough--sx-bin,SLICERX_SX_BINorPATH. Build it withcargo build -p sx-cli --release(the binary istarget/release/sx).stub: a rough estimate from mesh volume and surface area (STL only). Results say so, its G-code holds only comments, and printers refuse it.
The mesh tools use sx-geom, found through --sx-geom-bin, SLICERX_SX_GEOM_BIN, the folder of sx, or PATH. Build it with cargo build -p sx-geom --release. Without it the slicerx_geom_* tools are not offered.
--engine auto (the default) uses sx when it is found and the stub otherwise. Project plates are sliced as one combined model; the core centers it on the bed.
Printers
--printers demo(default): five simulated printers. Nothing reaches real hardware, and approvals work exactly as they do for real printers.--printers link --link-code <code>: real printers throughsx-link, the SlicerX bridge on this machine. Startsx-link, add your printers to it, and pass the pairing code it prints. Setup for each printer is in the guides atslicerx://docs/printers/.... Approvals for printer actions are registered with and granted by sx-link's own broker, because sx-link verifies every token before it sends anything to a printer; project and profile approvals stay with the server's broker. Tested against sx-link and the mock printers; not yet on physical printers.--printers off: no printer tools.
Install
With npm (once @slicerx/mcp is published), no clone needed:
npx -y @slicerx/mcp@0.1.0 --allow-dir ~/printsFrom a clone:
pnpm install
pnpm --filter @slicerx/mcp build # writes packages/mcp/dist/cli.js and packages/mcp/data/
cargo build -p sx-cli --release # optional: the real slicer instead of the stubThe commands below use /path/to/slicerx; replace it with your clone.
Claude Desktop
Settings, Developer, Edit Config, then add the server to claude_desktop_config.json:
{
"mcpServers": {
"slicerx": {
"command": "node",
"args": [
"/path/to/slicerx/packages/mcp/dist/cli.js",
"--allow-dir", "/Users/you/prints",
"--sx-bin", "/path/to/slicerx/target/release/sx"
]
}
}
}Restart Claude Desktop. Clients that support elicitation show Ask first actions as an approval prompt; others get an approval request in the conversation.
Claude Code
claude mcp add slicerx -- node /path/to/slicerx/packages/mcp/dist/cli.js --allow-dir ~/printsOver HTTP instead, with the server already running (see below):
claude mcp add --transport http slicerx http://127.0.0.1:3977/mcp --header "Authorization: Bearer $SLICERX_MCP_TOKEN"Claude Code plugin
The SlicerX plugin for Claude Code bundles this server with skills and slash commands; see packages/claude-plugin.
Cursor
~/.cursor/mcp.json (all projects) or .cursor/mcp.json (one project) takes the same mcpServers block as Claude Desktop.
Other clients
Any client that launches a stdio server can run node /path/to/slicerx/packages/mcp/dist/cli.js. Clients that connect to a URL use streamable HTTP:
export SLICERX_MCP_TOKEN="$(openssl rand -hex 24)"
node packages/mcp/dist/cli.js --http --port 3977 --allow-dir ~/printsThe endpoint is http://127.0.0.1:3977/mcp, stateless, POST only. In HTTP mode approvals always use slicerx_approve, since a stateless server cannot hold an elicitation open. ChatGPT and other hosted assistants connect only to remote HTTPS servers, so they cannot reach a loopback address; you need a reverse proxy or tunnel you control, with --token set and --allowed-host <public name>. Keep printer classes on Ask first or Off for any server reachable from outside your machine.
Options
| Flag | Environment | Default |
|---|---|---|
--http |
SLICERX_MCP_HTTP=1 |
stdio |
--host, --port |
SLICERX_MCP_HOST, SLICERX_MCP_PORT |
127.0.0.1, 3977 |
--token <secret> |
SLICERX_MCP_TOKEN |
none; required off loopback |
--allowed-host <name> |
SLICERX_MCP_ALLOWED_HOST (comma list) |
loopback names only |
--allow-dir <dir> (repeat) |
SLICERX_MCP_ALLOW_DIR (colon list) |
stdio: any readable path; HTTP: none |
--out-dir <dir> |
SLICERX_MCP_OUT_DIR |
<tmp>/slicerx-mcp |
--no-urls |
SLICERX_MCP_NO_URLS=1 |
URLs allowed, 256 MB limit |
--engine auto|sx|stub |
SLICERX_MCP_ENGINE |
auto |
--sx-geom-bin <path> |
SLICERX_MCP_SX_GEOM_BIN or SLICERX_SX_GEOM_BIN |
next to sx, then PATH |
--sx-bin <path> |
SLICERX_MCP_SX_BIN or SLICERX_SX_BIN |
sx on PATH |
--printers demo|link|off |
SLICERX_MCP_PRINTERS |
demo |
--link-url, --link-code |
SLICERX_MCP_LINK_URL, SLICERX_MCP_LINK_CODE |
ws://127.0.0.1:47615, none |
--policy <file> |
SLICERX_MCP_POLICY |
~/.config/slicerx/mcp-policy.json if present, else the defaults |
--log <file> |
SLICERX_MCP_LOG |
<out-dir>/actions.jsonl |
--profiles-dir <dir> |
SLICERX_MCP_PROFILES_DIR |
~/.config/slicerx/profiles |
--data-dir <dir> |
SLICERX_MCP_DATA_DIR or SLICERX_DATA_DIR |
bundled data/, else the clone |
Adding tools
An edition or another host can start the server in-process and add its own tools, written as PrintPilot tools, without the base package importing them. They go through the same permission policy and approvals:
import { createContext, createSlicerxServer } from '@slicerx/mcp'
const ctx = await createContext({ extraTools: [cloudSlice, cloudJobs] })
await createSlicerxServer(ctx).connect(transport)Security
- Model paths must be inside
--allow-dirwhen it is set. HTTP mode reads no local path until you add one. - HTTP mode binds to 127.0.0.1, checks the Host and Origin headers against loopback names (against DNS rebinding), and refuses to bind elsewhere without a bearer token. Each request gets a new server instance.
- The server never reads credentials. Printer credentials stay in the operating system keychain behind
sx-link. - Knowledge text, model metadata, profile names and printer replies are data. Tool output marks printer and file text as untrusted, and none of it can approve an action.
Licensing
MPL-2.0, like the rest of the SlicerX base kit. The package bundles no OrcaSlicer code or data. MCP clients talk to the server over stdio or HTTP, so connecting a client places no license terms on it.
Development
pnpm --filter @slicerx/mcp test # tools, permissions and approvals, resources, HTTP, both engines
pnpm --filter @slicerx/mcp typecheck
pnpm --filter @slicerx/mcp dev -- --engine stub # run from source
npx @modelcontextprotocol/inspector node packages/mcp/dist/cli.jsTests that need the real core run when target/release/sx exists and are skipped otherwise.
Dependencies:
@modelcontextprotocol/sdk1.31.0: the MCP server, stdio and streamable HTTP transports (MIT).zod4.6.5: tool input schemas (MIT).yaml2.9.1: reads the knowledge base (ISC).- Development only:
esbuild0.28.2 bundles the workspace packages intodist/cli.js,tsx4.23.15 runs from source,vitest5.0.2 runs the tests, and@types/node24.19.0.
Status
Working: stdio and HTTP transports, the permission policy with elicitation and approval requests, the action log, file slicing with the sx engine or the stub, the MCP project with PrintPilot's skills, the simulated printers, and every resource listed above. Theming tools build and check themes; applying one happens in your page with applyTheme() or <ThemeProvider>. Printer actions on real printers go through sx-link's broker (tested with the mock printers). Planned: publishing @slicerx/mcp to npm, and testing on physical printers.