mcp-canvas-lms

MCP.Pizza Chef: DMontgomery40

Fifty-four tools cover Canvas, the course site most colleges use: courses and syllabi, assignments and due dates, grades and feedback, discussions, files, quizzes, and messages. Instructors can grade work and enroll students; administrators can create accounts and run reports. You supply an access token from your Canvas settings plus your school's web address. It is an independent project with no license file attached, which makes workplace or institutional use legally murky, and it has no connection to Instructure.

Calendar
Communication
Files/PDF

Use This MCP server To

See everything due this week across all my courses Check my current grade and read the feedback Submit an essay to the right assignment Catch up on announcements and discussions I missed Download the readings for a module Grade a batch of submissions and leave comments Pull an enrollment report for a whole department

README

Canvas MCP Server v2.3.0

Security and disclosure history

This project is an independent MCP server for Canvas LMS APIs. It is not affiliated with, endorsed by, or maintained by Instructure or Canvas.

In June 2025, during development of this MCP, I identified a Broken Access Control issue in the Canvas environment at bootcampspot.instructure.com. The issue exposed personally identifiable information for other students enrolled in my course.

I reported the issue through Bugcrowd on June 5, 2025, and also contacted Instructure / Canvas security channels directly. The Bugcrowd report was later closed as "Not Applicable." In subsequent correspondence, Instructure stated that the bootcampspot.instructure.com environment was outside its control.

Public references:

This repository does not publish exploit steps, affected tenant details beyond what is already public, live URLs, screenshots containing student data, or proof-of-concept abuse flows.

Separately, Instructure publicly disclosed a Canvas security incident in May 2026, and public reporting has linked the incident to ShinyHunters claims. This repository makes no claim that the June 2025 report caused, enabled, predicted, or is technically connected to the May 2026 incident.

This disclosure is documented here for project history and transparency only.

What this is

A comprehensive Model Context Protocol (MCP) server for Canvas LMS with complete student, instructor, and account administration functionality

๐Ÿš€ What's New in v2.3.0

  • ๐ŸŒ NEW: Streamable HTTP transport support (MCP_TRANSPORT=streamable-http)
  • ๐Ÿ–ฅ๏ธ Preserved: First-class stdio transport for local MCP clients
  • ๐Ÿงช Added: Behavior tests for lifecycle, transports, and structured failure-path errors
  • ๐Ÿงฑ Improved: Stricter tool schemas and codemode-oriented tool descriptions
  • ๐Ÿ”ง FIXED: Course creation "page not found" error (missing account_id parameter)
  • ๐Ÿ‘จโ€๐Ÿ’ผ Account Management: Complete account-level administration tools
  • ๐Ÿ“Š Reports & Analytics: Generate and access Canvas account reports
  • ๐Ÿ‘ฅ User Management: Create and manage users at the account level
  • ๐Ÿข Multi-Account Support: Handle account hierarchies and sub-accounts
  • โœ… API Compliance: All endpoints now follow proper Canvas API patterns

๐ŸŽฏ Key Features

mcp-canvas-lms FAQ

What do I need to get started?
An access token you generate in your Canvas account settings, plus your school's Canvas web address such as yourschool.instructure.com. Both go into your assistant's settings file.
Can I use this to stay on top of deadlines?
Yes, and it is the most common use. Asking what is due this week returns dates, points, and whether you have already submitted.
Which apps does it work in?
Claude Desktop, Cursor, and other apps that read the same settings file. A container version exists for people who prefer that.
Can it submit work or start quizzes for me?
Yes โ€” it can submit assignments, post to discussions, and open a quiz attempt. Your school's academic honesty rules still apply, so think carefully about what you let it do unsupervised.
Is it official?
No. It is an independent project, not affiliated with or endorsed by Instructure, the company behind Canvas.
Can I install it on a work or school machine?
Legally that is unclear. The project ships no license file, so nobody has been granted formal permission to use, copy, or modify it. Check with whoever handles software approvals first.
Is the container version safe to leave running?
Only on your own machine. The documented container setup listens on every network address with no password and, by default, accepts requests from any website, so anyone who can reach that port gets your Canvas access.
Can it see other students' details?
It sees only what your own account can see. Separately, the author reported a Canvas flaw in 2025 that exposed other students' details on one bootcamp site; that was a Canvas problem, not this tool's.