Skip to main content

Krita Codex MCP Server

Control Krita from OpenAI Codex through a secure local Model Context Protocol (MCP) server for Windows.

PyPI package · GitHub releases · Windows installation guide

A Windows-first local MCP server that lets Codex inspect and control Krita through a small, authenticated bridge. The MCP process uses STDIO. The Krita Python plugin listens only on 127.0.0.1, validates a shared bearer token, and dispatches every Krita API call to Qt's main thread.

This repository is a Windows-first integration with a capability-based runtime compatibility check. Krita 5.3.2.1 is a tested build, not a hard version requirement. The server deliberately exposes a small set of cohesive tools instead of a large collection of micro-tools:

Tool Purpose
krita_state Active document, canvas/color space, recursive layer tree with UUIDs, active layer and current painting state
krita_preview Whole-canvas or pixel-precise cropped PNG returned directly as MCP image content
krita_canvas Sample colors; resize, scale, crop, rotate or flip; import editable raster layers
krita_edit Create/refine/move selections; native copy, cut, paste, selection-to-layer, fill and clear
krita_document Inspect runtime compatibility; list, create, open, activate, save and close documents
krita_layers Read/edit the layer tree, safely reparent, and transform layers by stable UUID
krita_history Read undo/redo state and execute bounded undo or redo steps
krita_brush Read/set native brush state and search installed Krita presets
krita_paint_path Pressure-aware line segments through Krita's native Node.paintLine API and active brush preset
krita_draw Native preset-backed lines, open/closed paths, polygons, rectangles and ellipses
krita_color KRA-backed project palettes, Krita palette swatches, color replacement and safe correction filters
krita_asset Export layer PNGs plus Unity-oriented animation, tileset and named-region packages with direct previews
krita_save_export Save KRA and export PNG beneath configured roots only
Codex -> local STDIO MCP process -> authenticated 127.0.0.1 HTTP bridge
      -> queued, timeout-aware Qt main-thread dispatch -> Krita Python API

The bridge has no arbitrary Python execution tool and no direct pixel painting fallback. Actual painting, shapes, replacement fills and correction filters go through native Krita actions or stroke APIs. If the running Krita build lacks a feature, krita_state and krita_document(action="compatibility") report the affected tools. Calling that feature returns a structured error; the bridge never silently switches to a different rendering backend.

Quick start

This requires a Windows Krita build that passes the live compatibility check and uv/uvx on PATH. Close Krita, make sure the allowed directory already exists, and install the current release from PyPI:

uvx --from "krita-codex-mcp==0.2.0" `
  krita-codex-install install `
  --allowed-root "C:\Krita Work"

Then use this order for a real Krita session:

  1. Enable Krita Codex Bridge in Krita's Python Plugin Manager.
  2. Restart Krita so the installed plugin and shared protocol package are loaded together.
  3. Run the same version's krita-codex-install check and require either Ready for productive use. or the explicit limited-mode success message.
  4. Preview the checkout-free, exactly version-pinned uvx Codex block with krita-codex-install codex-config.
  5. Apply it only after explicit confirmation, restart Codex, verify krita_state and krita_preview, and only then start normal work.

Install and update never close Krita. If the authenticated bridge is running, replacement is rejected before any installed files are changed and Krita must be closed manually. A busy local bridge port also stops the installer before replacement begins.

For a personal installation, use the user-level C:\Users\<you>\.codex\config.toml. This is the recommended option because the server is then available to all local Codex tasks and Git worktrees. The generated block uses uvx, has no checkout cwd, and pins the same exact distribution version as the installed plugin. The installer only changes that file after showing the full preview and receiving explicit confirmation. Unmarked or conflicting Krita entries are never overwritten. Never commit personal configuration. See the Windows installation guide for details.

The preflight checks local configuration, the complete installed hash manifest, wheel/plugin/ protocol versions, loopback port, authentication and the running Krita capability profile. The running plugin reports the distribution, protocol and Krita versions without adding an MCP tool. The check creates a disposable document, verifies a new paint layer, native drawing, Undo/Redo, transactional reparenting, direct PNG preview bytes and temporary KRA/PNG output beneath an allowed root. It restores the previously active document and removes every temporary file.

An unknown Krita version is accepted when all critical capabilities pass. Missing optional features produce limited warnings naming the affected MCP tools; missing projection, persistence, stable layer-tree or document-lifecycle APIs remain critical. The same structured report is available to Codex through krita_state, so it can avoid unavailable operations.

Capabilities and Krita limits

The current release supports native preset-backed painting and shapes, persistent document and layer editing, selections, color operations, KRA/PNG output, and Unity-oriented animation, tileset and named-region packages. Preview and asset operations return PNG images directly to the MCP caller. Re-export preserves Unity .meta sidecars for stable generated filenames.

The tested Krita 5.3.2.1 build imposes several safety limits. Other builds are evaluated at runtime and may report different available features:

  • Free layer scale, rotate, shear and crop operations are not native Undo commands. The bridge creates a hidden backup layer and blocks a second direct transform until the KRA is saved, closed and reopened. checkpoint_reopen=true can perform that round trip automatically.
  • Transform masks are limited to three per open document. Same-session mask mutation/removal and mixing mask and direct transform backends are blocked until Krita restarts.
  • Node.paintLine requires integer QPoint values, so incoming canvas coordinates are rounded at the native API boundary.
  • PNG export temporarily enables Krita batch mode so no format dialog can block the local bridge.

Timeouts and production guardrails

Timeouts are operation-specific across Codex, the MCP BridgeClient, the local HTTP bridge and Qt's main-thread dispatcher:

Operation class Dispatcher timeout
Reads and normal edits 30 seconds
Document open and checkpoint save 120 seconds
KRA/PNG, layer, animation, tileset and region exports 180 seconds

The recommended Codex tool_timeout_sec is 210 seconds so the MCP client can receive the bridge's structured result. If a timed-out Qt operation is already running, operation_may_complete=true is preserved and later calls receive BRIDGE_BUSY until Krita actually finishes.

Keep allowed_roots as narrow as practical, keep ordinary versioned or manual KRA backups, and do not treat the bridge timeout as cancellation. The bridge is local-only and binds exactly to 127.0.0.1.

See Windows installation, tool behavior and limits, security, and the GitHub releases.

License

Released under the MIT License. Copyright (c) 2026 Nicklas Desens.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

krita_codex_mcp-0.2.0.tar.gz (206.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

krita_codex_mcp-0.2.0-py3-none-any.whl (130.1 kB view details)

Uploaded Python 3

File details

Details for the file krita_codex_mcp-0.2.0.tar.gz.

File metadata

  • Download URL: krita_codex_mcp-0.2.0.tar.gz
  • Upload date:
  • Size: 206.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for krita_codex_mcp-0.2.0.tar.gz
Algorithm Hash digest
SHA256 225711a0e0bc9bbaa9bfd3033964d3706228a5ab418ae6aaf18e9b631f3540a4
MD5 f5d21ae762dea7c8f804afe8ac10313d
BLAKE2b-256 86ccf5326a51ec3d04d7b5b47e4be1e5f7801e4691017d9f8b048798e5615e5d

See more details on using hashes here.

Provenance

The following attestation bundles were made for krita_codex_mcp-0.2.0.tar.gz:

Publisher: release.yml on cyyprezz/krita-codex-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file krita_codex_mcp-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: krita_codex_mcp-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 130.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for krita_codex_mcp-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 6ffa38bc53049dcc82ab6db159b54eedfa6c01ef390b3aa52bdcdf21e84930a9
MD5 c58bf80ed4525efaa31f7bebe5ebfaf2
BLAKE2b-256 d5edf0b1e8a734f5559e939a797d5cbc858f6479ec259b1d79f8a2aeca4c180b

See more details on using hashes here.

Provenance

The following attestation bundles were made for krita_codex_mcp-0.2.0-py3-none-any.whl:

Publisher: release.yml on cyyprezz/krita-codex-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page