Security
Some more complex tasks are only available when Cinema 4D is controlled via Python scripts. These include, for example, the creation of nodes for configuring materials or specialized scene node graphs. Since Python scripts can also be used, for example, to manipulate files and allow direct access to your network, you should always exercise extreme caution when using them. You can therefore generally improve security by allowing the use of Python only in specific cases and monitoring it closely. This is especially true if you grant others access to the MCP interface via Remote Access.
The MCP Server integrated into Cinema 4D already offers a wide range of commands, so that many objects and functions within Cinema 4D can be used without resorting to Python.
These directly supported actions are:
- Scene inspection: List objects, tags, materials and hierarchies; read selections, parameters and document settings.
- Entity management: Create, duplicate, rename and delete objects, tags, materials and shaders.
- Hierarchies and transforms: Reparent and reorder objects; set local or global position, rotation and scale.
- Parameters: Inspect parameter descriptions and IDs; read and write supported values and object links.
- Selection: Select objects, tags, materials, points, edges and polygons.
- Geometry: Read mesh and spline geometry; write points and polygons on editable meshes.
- Modeling: Execute modeling operations, including subdivision, optimization, connection and Current State to Object.
- Materials: Configure surface properties, inspect shaders, and build or modify material node graphs.
- XPresso: Create graphs, add and connect nodes, modify port values and remove nodes.
- Animation: Inspect animation tracks and keyframes; create, update and remove keys; evaluate object transforms at specified frames.
- MoGraph: Read individual clone transforms and modify exposed generator and effector parameters.
- User Data: List, create and remove User Data entries; modify their values through parameter tools.
- Layers and Takes: Create and assign layers, modify layer flags, create or update Takes, and set parameter overrides.
- Assets and import: Search the asset library, insert scene assets and merge external scene files.
- Viewport and rendering: Capture the viewport, generate preview renders, configure render settings, and start, monitor or stop rendering.
- Document management: List, create, open, activate, save and close documents; read and modify document settings.
- Commands and undo: Invoke Cinema 4D commands, group supported operations into a single undo step and undo document changes.
This option activates the exec_python tool: any Python code executed in Cinema 4D’s main thread, with c4d and doc in the namespace—essentially the Script Manager, but remotely controlled. This allows the MCP Client to do everything the Python API supports, including things for which there is no typed tool: setting the editor camera, evaluating scenes, and performing bulk operations all at once. The adapter logs every call along with the code text.
Allow Python-Bearing Operations
This is a separate restriction for entity types that contain Python themselves, such as the Python tag, Python generator, Python effector, Python field. If this box is not checked, create_entity and set_parameters will reject these types.
The difference is more significant than it seems:
With Allow exec_python Command, once the call is complete, nothing remains.
Allow Python-Bearing Operations on the other hand places code in the scene that will execute automatically every time the scene is rendered. Such nodes survive the MCP session, are saved with the .c4d file, and run whenever anyone opens the file.
Both effectively mean code execution on your computer with Cinema 4D’s permissions. For a local workstation, this is a reasonable trade-off; on a production or render node — and especially in conjunction with the Remote Access tab, if you open the server there beyond 127.0.0.1 — you should be more selective and activate Allow Python-Bearing Operations only when necessary.
