Claude drives FreeCAD over MCP: what the CAD agent builds and what it must not touch
CAD by spoken instruction is one of the agent use cases that lands directly in a machine shop or a design office. The video „I Connected Claude AI to FreeCAD (And It Models Parts Like an Engineer)" by the Make Form channel has been showing since 15 July 2026 how Claude Desktop builds parts in FreeCAD over the Model Context Protocol (MCP), in a little under 20 minutes. On 4 October 2026 it stood at roughly 283,000 views. What matters for a workshop is more than the show: what happens underneath, how fragile is the bridge, and which parts are allowed in at all?
How the bridge actually works
The video title suggests a Claude feature. Nobody at Anthropic built it. It is a single community project: the repository freecad-mcp by neka-nat, standing at 2,654 stars on 4 October 2026, MIT licence, last change on 24 September 2026. It consists of two pieces that talk over a plain XML-RPC connection.
The first piece is an addon that runs inside FreeCAD: copy it into the addon directory (on Windows with FreeCAD 1.1 that is %APPDATA%\FreeCAD\v1-1\Mod\), restart FreeCAD, click „Start RPC Server" in the MCP workbench. An RPC server then listens on port 9875. The second piece is the MCP server itself, a PyPI package (as of 4 October 2026: version 0.1.25, Python 3.12 or newer) that Claude Desktop launches through uvx. Registering it in Claude Desktop's claude_desktop_config.json is a JSON block with uvx freecad-mcp as the command, nothing more. The tutorial walks through the whole thing on Windows; FreeCAD 1.1.4 was released on 28 September 2026.
The real mechanism sits in the return channel. After every execution FreeCAD sends a viewport screenshot back, Claude reads the image and issues the next command. That loop of prompt, execution, image, correction is what separates this from macro-driven CAD.
What the demo proves
The parts shown are simple; the interaction is not. A 50 × 30 × 20 mm box appears on request. Told to „fillet all edges" without a radius, Claude asks back and recommends staying under 10 mm to avoid geometry errors; with the chosen 2 mm it fillets cleanly across all twelve edges. Asked to „make four holes on top", it fills the missing dimensions through questions (4 mm diameter, through all) and picks the placement itself: 10 mm and 8 mm inset from the edges so the fillets stay clear. That is dimensioning with a stated reason.
The two later cases are the interesting ones. A hand-drawn sketch of a stepped block, three views with dimensions, becomes a 3D part in about 20 seconds according to the video, and the built-in measurement tool confirms the sizes afterwards. And when Claude is asked for a spur gear (20 teeth, module 2, 20 mm face width, 10 mm bore), it notices the gear workbench is missing and constructs the involute gear from primitive geometry and its own calculations. Both are demonstrations of judgement, observed in a video rather than on a test bench. That caveat belongs in the sentence.
A third observation works as a warning: told to „close all the documents", Claude closes every open document without asking. The note that unsaved work was lost arrives afterwards. CAD agents belong in the same risk class as any production agent with write rights: it acts first and raises concerns second.
Security of the RPC bridge
The project documentation is more candid here than the video. Quote: „Any program that can reach the port from an allowed address can call every tool, including execute_code, which runs arbitrary Python inside FreeCAD with your user's permissions." By default the RPC server listens on localhost only, remote connections are off, and requests from web browsers are refused outright. Anyone who opens the bridge binds to all interfaces and maintains an IP allowlist; for that case the docs prescribe an auth token, narrow address grants or an SSH tunnel.
For company use the consequence is concrete: the machine on which Claude may drive FreeCAD is a machine on which a language model can execute arbitrary Python code with the signed-in user's rights. It therefore gets the same treatment as every MCP server we write ourselves: least privilege, its own device or VM, a clear decision about which data may live there. How we harden infrastructure agents and what self-built MCP servers bring are two earlier posts on this site.
Token cost: the screenshot is the price
The image feedback is not free. Every step hands Claude a picture, and pictures count as tokens. For long sessions the docs offer the --only-text-feedback switch, which skips screenshots and returns only object names, dimensions and error messages. The video's author still recommends the image mode for starters, because without the picture Claude no longer sees whether the part stands up. Regular users should turn image mode on for control steps and leave it off otherwise.
What this means for a design office
The demo shows single parts: box, flange, gear, stepped block. It shows no assembly, no drawing generation with tolerances, no standard-parts library. Via the addon, FEM calculations can be started according to the project description; responsibility for strength and manufacturing annotations still sits with a human. Whoever needs a shaft with fits or a welded frame with inspection marks gets a model from the agent, not an approval.
Where the approach reaches today is the parts that quietly burn design hours: guards, covers, brackets, gauges, jigs. Everything nobody wants to fully detail and the workshop needs anyway. In shops that work from sketch to DXF for the plasma cutter, that is exactly the niche the demo shows: photograph the sketch, build the part, export the contour. The dimensions are valid only as far as the model read them correctly. Every part still gets measured, and the data question gets settled before the first prompt, because every prompt sends geometry to the Claude cloud. Customer-bound designs go in only with clearance, or through the same MCP interface with a local model.
The bridge remains a community project. It hangs on FreeCAD's Python API and on Claude Desktop's willingness to launch local MCP servers. For a one-off demo that is fine. For a workflow meant to produce drawings it would be a dependency on a single maintainer, and nobody builds that in without an exit plan.
Further sources
- Repository neka-nat/freecad-mcp: project description, 2,654 stars, MIT licence, as of 4 Oct 2026
- Configuration docs:
--only-text-feedback, remote mode, auth token, theexecute_codequote - Installation docs: addon directories per platform, Python versions
- PyPI package freecad-mcp: version 0.1.25, Python 3.12+, as of 4 Oct 2026
- The video „I Connected Claude AI to FreeCAD“: Make Form channel, published 15 Jul 2026
- FreeCAD releases on GitHub: version 1.1.4 of 28 Sep 2026, LGPL-2.1
- uv installation for Windows: the official
irm https://astral.sh/uv/install.ps1line - Model Context Protocol: protocol reference
Does setting up Claude with FreeCAD over MCP cost money?+
The software is free: FreeCAD is licensed under LGPL 2.1, the freecad-mcp server under MIT, and uv as well. You still need a Claude account for the desktop app. Running costs come from tokens, because Claude receives a screenshot of the FreeCAD viewport after every step. The project docs list an --only-text-feedback switch that drops the images and cuts tokens per operation noticeably.
Does the agent replace the design engineer?+
No. The demo shows single parts with no assembly, no drawing generation and no tolerance management: a box, a flange, a gear, a stepped block from a hand sketch. The agent's clarifying questions about fillet radius and hole diameter show engineering-like judgement in choosing dimensions, but responsibility for material, strength and manufacturing annotations stays with the human. What the agent is useful for today are aids, jigs and covers, the parts nobody wants to fully detail.
Which data leaves the building with this setup?+
Everything you type into the chat, dimensions and sketches included, goes to the Claude service in the cloud. In the default mode FreeCAD additionally sends a viewport screenshot to the same model after every operation. The local bridge itself stays shut by default: the RPC server listens on localhost only, remote access is an explicit switch with an IP allowlist. Geometry under a confidentiality obligation therefore does not belong in this experiment.
senn-tech