Agisoft Metashape Firewall Configuration: Complete Network Guide

Agisoft Metashape Firewall Configuration: Complete Network Guide

Configuring a corporate firewall for Agisoft Metashape is usually straightforward because normal photogrammetric processing does not require a permanent Internet connection.

Metashape performs its core processing operations locally on the workstation. This means tasks such as photo alignment, point cloud generation, mesh reconstruction, DEM creation and orthomosaic processing can be performed without providing the software with unrestricted Internet access.

However, several optional Metashape features communicate with external online services. If your organization operates behind a restrictive firewall, proxy or closed corporate network, these connections may need to be explicitly allowed.

This guide explains the official Agisoft Metashape firewall configuration requirements for Agisoft Cloud, online base maps and supported publishing platforms.

Does Agisoft Metashape Require Internet Access?

No. Metashape does not require Internet access for normal local photogrammetric processing.

This is particularly important for organizations working in:

  • Government environments
  • Secure corporate networks
  • Research laboratories
  • Air-gapped workstations
  • Restricted infrastructure environments
  • Remote field locations
  • Networks with strict outbound firewall policies

Images and project files can remain on the local workstation or internal storage infrastructure while Metashape performs the processing locally.

Internet connectivity becomes necessary only when you choose to use certain online services integrated with Metashape.

Which Metashape Features Require Internet Access?

According to Agisoft’s official firewall configuration documentation, Internet access may be required for three main categories of optional functionality:

  1. Agisoft Cloud processing
  2. Online base map layers
  3. Online publishing services

If your organization does not use one of these functions, you generally do not need to allow access to the servers associated exclusively with that feature.

Agisoft Metashape Firewall Requirements at a Glance

Metashape Feature Required Server / Host Special Port
Agisoft Cloud account.agisoft.com Standard HTTPS connection
Agisoft Cloud api.agisoft.com 8086
Base Maps www.agisoft.com Web access
Base Maps tiles.agisoft.com Web access
Base Maps s3-eu-west-1.amazonaws.com Web access
Base Maps s3.amazonaws.com Web access
Base Maps a-c.tile.openstreetmap.org HTTP access
Sketchfab Publishing api.sketchfab.com Web access
Cesium ion Publishing api.cesium.com Web access
Cesium ion Publishing s3.us-east-1.amazonaws.com Web access
Mapbox Publishing api.mapbox.com Web access
Mapbox Publishing s3.us-east-1.amazonaws.com Web access
4DMapper Publishing app.4dmapper.com Web access
Picterra Publishing app.picterra.ch Web access
PointBox Publishing www.pointbox.xyz Web access
Pointscene Publishing pointscene.com Web access

Firewall Configuration for Agisoft Cloud

Agisoft Cloud allows Metashape users to perform photogrammetric processing using cloud resources rather than relying entirely on the CPU, GPU and RAM available on the local workstation.

This can be particularly useful for large datasets or computers with limited processing resources.

If your firewall blocks external Internet traffic, Metashape must be able to reach the following Agisoft services:

https://account.agisoft.com

and:

https://api.agisoft.com:8086

The second address is particularly important because Agisoft explicitly specifies port 8086.

If a corporate firewall allows normal browser traffic but blocks non-standard outbound ports, Agisoft Cloud may therefore fail even though account.agisoft.com can be opened successfully in a web browser.

Port 8086 and Agisoft Cloud

When troubleshooting Agisoft Cloud connectivity, verify that the workstation running Metashape can communicate with:

api.agisoft.com:8086

A firewall rule that only permits conventional web browsing may not automatically permit this connection.

Network administrators should therefore check whether outbound communication from the Metashape workstation to this host and port is permitted according to the organization’s security policy.

If local photogrammetric processing works but Agisoft Cloud does not, blocked access to one of the required cloud endpoints should be included in the troubleshooting process.

Firewall Configuration for Metashape Base Maps

Metashape can display online base map layers as geographic context for a project.

These maps can be displayed as:

  • A globe or geographic background in Model view
  • A background layer in Ortho view

The photogrammetric project itself does not depend on these online maps for normal processing.

However, if the required Internet services are blocked, the base map may fail to load even though the project, cameras, point cloud, DEM and orthomosaic continue to work normally.

Agisoft identifies the following servers as required for base map functionality:

https://www.agisoft.com

https://tiles.agisoft.com

https://s3-eu-west-1.amazonaws.com

https://s3.amazonaws.com

and OpenStreetMap tile servers:

http://{a-c}.tile.openstreetmap.org

Why Is the Metashape Base Map Not Loading?

If the base map area remains blank while the rest of Metashape operates normally, the problem may be related to network access rather than the photogrammetric project.

Check whether your organization’s firewall, web filtering system or network security policy allows the Metashape workstation to access the required map servers.

A useful troubleshooting distinction is:

  • Project processing works, but background map does not load: investigate access to base map servers.
  • Metashape works locally, but cloud processing fails: investigate Agisoft Cloud endpoints.
  • Local outputs work, but online publishing fails: investigate the servers required by the selected publishing service.

Firewall Configuration for Online Publishing

Metashape supports direct upload of processing results to several third-party online platforms.

Each publishing platform communicates with its own servers, so the required firewall configuration depends on which service you intend to use.

Sketchfab

To publish Metashape results to Sketchfab, allow access to:

https://api.sketchfab.com

Cesium ion

For Cesium ion publishing, Agisoft lists:

https://api.cesium.com

and:

https://s3.us-east-1.amazonaws.com

Mapbox

For Mapbox uploads, allow access to:

https://api.mapbox.com

and:

https://s3.us-east-1.amazonaws.com

4DMapper

For 4DMapper:

https://app.4dmapper.com

Picterra

For Picterra:

https://app.picterra.ch

PointBox

For PointBox:

https://www.pointbox.xyz

Pointscene

For Pointscene:

https://pointscene.com

If one particular publishing service fails while other online Metashape features work correctly, verify the firewall rules for that specific platform rather than assuming that Metashape has a general Internet connectivity problem.

Do You Need to Allow Every Server?

No.

A security-conscious organization can allow only the Internet services required by its actual Metashape workflow.

For example, a company that processes projects locally and never uses online publishing may not need to provide Metashape with access to Sketchfab, Cesium ion, Mapbox or the other publishing platforms.

Similarly, an organization that does not use Agisoft Cloud does not need cloud-processing connectivity simply to run local photogrammetric reconstruction.

This makes it possible to configure network access according to the principle of allowing only the functionality required by the organization.

Can Metashape Work on a Closed Network?

Yes.

Core Metashape processing can be performed locally without Internet access, making the software suitable for closed or restricted networks.

In such an environment, features that depend on external services will naturally be unavailable unless specific firewall exceptions are configured.

For example, an isolated workstation can still be used for:

  • Photo alignment
  • Camera optimization
  • Point cloud generation
  • Point cloud classification
  • Mesh reconstruction
  • DEM / DTM generation
  • Orthomosaic creation
  • Measurements
  • Local data export

while online maps, cloud processing and direct Internet publishing remain disabled.

Firewall Configuration for Secure Organizations

For organizations with strict IT policies, a practical approach is to determine which optional Metashape features employees actually require.

A typical workflow could be:

  1. Install Metashape on the approved workstation.
  2. Keep normal photogrammetric processing local.
  3. Identify whether Agisoft Cloud is required.
  4. Determine whether online base maps are required.
  5. Identify which, if any, online publishing platforms are required.
  6. Allow only the corresponding destinations through the firewall.
  7. Test each required Metashape online function.
  8. Keep unnecessary external services blocked according to organizational security policy.

This is particularly useful for enterprise, governmental and research environments where unrestricted Internet access is not permitted.

How to Troubleshoot Metashape Firewall Problems

If an online feature does not work, first determine whether the failure affects Metashape itself or only an optional Internet service.

Metashape Processes Images Normally

If Align Photos, Build Point Cloud, Build DEM and other local operations work correctly, the core application is operating normally.

A failure limited to cloud processing, base maps or publishing is more likely to involve connectivity to the relevant external service.

Agisoft Cloud Cannot Connect

Check access to:

account.agisoft.com

and especially:

api.agisoft.com:8086

Base Maps Are Blank

Check access to the Agisoft map servers, Amazon S3 endpoints and OpenStreetMap tile services listed above.

Publishing Fails

Identify which publishing platform is being used and verify connectivity to that platform’s required server or servers.

Recommended Firewall Checklist for Metashape

Before contacting technical support about an online connectivity issue, verify the following:

  • Metashape local processing works correctly.
  • The required online feature has been identified.
  • The corresponding server is permitted by the firewall.
  • Agisoft Cloud access includes api.agisoft.com on port 8086.
  • Base map servers are permitted if online maps are required.
  • The selected third-party publishing endpoint is permitted.
  • Corporate web filtering is not blocking the required service.
  • The same security rules apply to the user account and workstation running Metashape.

Agisoft Metashape Firewall Configuration: Final Recommendations

The most important point is that Agisoft Metashape does not require unrestricted Internet access for normal photogrammetric processing.

Core processing takes place locally.

Firewall exceptions are mainly required when using optional online functionality such as:

  • Agisoft Cloud
  • Online base maps
  • Sketchfab publishing
  • Cesium ion publishing
  • Mapbox publishing
  • 4DMapper
  • Picterra
  • PointBox
  • Pointscene

For organizations with restricted networks, this makes it possible to maintain tight security controls while allowing only the specific Metashape Internet services required by the workflow.

When Agisoft Cloud is required, pay particular attention to api.agisoft.com on port 8086, since this connection can be blocked even on networks where ordinary web browsing works normally.

Frequently Asked Questions

Does Agisoft Metashape need Internet access?

No. Core photogrammetric processing is performed locally and does not require Internet access. Certain optional features such as Agisoft Cloud, online base maps and online publishing require connectivity.

What port does Agisoft Cloud use?

Agisoft’s official firewall documentation lists api.agisoft.com:8086 as one of the required Agisoft Cloud endpoints.

Why is my Metashape base map not loading?

If local processing works normally but the base map does not appear, your firewall or network filtering may be preventing access to one or more required map servers.

Can Metashape work on an air-gapped computer?

Core photogrammetric processing can operate without Internet access. Online cloud processing, Internet base maps and direct publishing services will not be available unless connectivity is provided.

Do I need to allow Sketchfab if I do not use it?

No. Access to the Sketchfab API is required specifically for the corresponding online publishing workflow.

Which servers are required for Agisoft Cloud?

Agisoft lists account.agisoft.com and api.agisoft.com:8086 for Agisoft Cloud functionality.

Can I use Metashape behind a corporate firewall?

Yes. Local processing can be performed normally. If optional online features are required, the corresponding external services need to be accessible according to your organization’s network policy.

Why does Metashape work but cloud processing does not?

This can happen because local processing does not depend on Internet access. Cloud processing requires connectivity to the specific Agisoft Cloud servers, including the API endpoint on port 8086.