New Your team’s decisions, in one playbook every coding agent works from. Never answer your agent twice

3dassets

20 tools. 5 can modify or destroy data without limits.

1 destructive tool with no built-in limits. Policy required.

Last updated:

5 can modify or destroy data
15 read-only
20 tools total

Community server · catalogue entry checked 21/09/2026 · full schemas captured for 14 of 20 tools

How to control 3dassets ↓

What 3dassets exposes to your agents

Read (15) Write / Execute (4) Destructive / Financial (1)

What 3dassets costs in tokens

3,605 tokens of tool definitions, loaded on every request
1.8% of a 200k context window
517 heaviest tool: submit_asset_from_url
Critical Risk

The most dangerous 3dassets tools

5 of 3dassets's 20 tools can modify, destroy, or commit something on every call — and an agent calls them with no built-in limits.

How to control 3dassets

PolicyLayer is an MCP gateway — it sits between your AI agents and 3dassets, and nothing reaches the server without passing your rules. These are the rules we recommend:

Block financial tools by default
{
  "finalize_upload": {
    "deny_if": [
      {
        "conditions": [],
        "on_deny": "Requires human approval."
      }
    ]
  }
}

Financial tools should be explicitly enabled per use case, not open by default.

Rate limit write operations
{
  "create_account": {
    "limits": [
      {
        "counter": "create_account_per_hour",
        "window": "hour",
        "max": 30,
        "scope": "grant"
      }
    ]
  }
}

Prevents bulk unintended modifications from agents caught in loops.

Cap read operations
{
  "get_asset": {
    "limits": [
      {
        "counter": "get_asset_per_minute",
        "window": "minute",
        "max": 60,
        "scope": "grant"
      }
    ]
  }
}

Controls API costs and prevents retry loops from exhausting upstream rate limits.

  1. Create a free account and register 3dassets — nothing to install.
  2. Add these rules — paste them, or build them visually. Tune the limits to your setup.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
ENFORCE POLICY ON 3DASSETS →

Instant setup, no code required.

All 20 3dassets tools

READ 15 tools
Read get_asset Full details for one asset by slug: CDN URL, licence + attribution text, stats, bounding box, animations, and Read get_asset_usage Code or steps to load an asset in three.js, React Three Fiber, <model-viewer>, Blender, Godot or Unity. Read get_demo Get one demo: the pack, the spawn point, the walkable bounds, the points of interest, and every placement (pub Read get_pack Get a free pack manifest with direct CDN URLs, licences, geometry budgets, loader snippets and its assembled s Read get_upload_url For clients that can upload bytes: returns a presigned PUT URL for a .glb (and optionally a PNG preview). Then Read list_ai_models Search model suggestions from OpenRouter, refreshed hourly. Custom model/tool names are accepted; the list is Read list_categories List categories available on 3dassets.dev (slugs are what other tools accept). Read list_demos List the walkable demo scenes staff have built from single packs. Each is a small environment a person can wal Read list_licenses Returns the sole accepted submission dedication: CC0 1.0 Universal. No licence selection is needed. Read list_tags List tags available on 3dassets.dev (slugs are what other tools accept). Read my_assets List the user’s submissions with status (processing, pending review, published, rejected + reason, failed + re Read my_packs List the user’s pack proposals with status (submitted, approved + pack URL, rejected + reason) and the status Read search_assets Search the free GLB catalogue on 3dassets.dev (three.js, Blender, Godot, Unity) by text, category (what it is) Read search_packs Find cohesive free GLB game kits by text, theme or style. Returns file counts, total bytes and starter scene U Read verify_account Exchange the emailed 6-digit code for the account’s API key. Show the key to the user and tell them to configu

Related servers

Other MCP servers with similar tools — same risk classification, starter policies for each.

Questions about 3dassets

Can an AI agent move money through the 3dassets MCP server? +

Yes. The 3dassets server exposes 1 financial tools including finalize_upload. Without a policy, an autonomous agent can call these with no spend caps, no rate limits, and no approval flow. PolicyLayer lets you block financial tools by default, require human approval, or set per-tool rate limits — enforced on every call.

How do I prevent bulk modifications through 3dassets? +

The 3dassets server has 4 write tools including create_account, submit_asset_from_url, submit_pack. Set a rate limit in your policy -- for example, 10 calls per hour prevents an agent from making more than 10 modifications per hour. PolicyLayer enforces this at the gateway, before calls reach 3dassets.

How many tools does the 3dassets MCP server expose? +

20 tools across 3 categories: Financial, Read, Write. 15 are read-only. 5 can modify, create, or delete data.

How do I enforce a policy on 3dassets? +

Register the 3dassets MCP server in PolicyLayer, apply the suggested rules above (adjust the limits to your use case), and point your AI client at the PolicyLayer proxy URL instead of the server directly. Your agents keep the same tools; PolicyLayer evaluates every call against policy before it executes. Nothing to install, live in minutes.

Enforce policy on every 3dassets tool call.

Deterministic rules across all 20 3dassets tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Instant setup, no code required.

20 3dassets tools catalogued and risk-classified — across an index of 46,500+ MCP servers.

// WHERE THIS COMES FROM

These policies come from 3dassets's registry record.

The record behind this page: verified identity, auth posture, risk grade, every tool classified, recommended policy — re-checked continuously.

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.