trackmcp
Back to directory
dmontgomery40

mcp-canvas-lms

View on GitHub

Version 2.2 - 54 tools available - an MCP server for interacting with the Canvas LMS API. This server allows you to manage courses, assignments, enrollments, and grades within Canvas.

61 stars TypeScriptAI & Machine Learning Updated Oct 14, 2025
canvas-lmscanvas-lms-apicanvas-lms-gradesmcpmcp-education-toolmcp-servermodel-context-protocolschool-education

Documentation

Canvas MCP Server v2.3.0

Security and disclosure history

This project is an independent MCP server for Canvas LMS APIs. It is not affiliated with, endorsed by, or maintained by Instructure or Canvas.

In June 2025, during development of this MCP, I identified a Broken Access Control issue in the Canvas environment at bootcampspot.instructure.com. The issue exposed personally identifiable information for other students enrolled in my course.

I reported the issue through Bugcrowd on June 5, 2025, and also contacted Instructure / Canvas security channels directly. The Bugcrowd report was later closed as "Not Applicable." In subsequent correspondence, Instructure stated that the bootcampspot.instructure.com environment was outside its control.

Public references:

  • Disclosure thread: https://www.reddit.com/r/cybersecurity/comments/1t6wmkw/reported_a_broken_access_control_bug_to/
  • Bugcrowd activity timeline: https://imgur.com/gallery/canvas-vuln-declared-n-11-months-ago-zYfHnBs
  • Later Instructure / BootcampSpot correspondence: https://imgur.com/a/BnhgXme

This repository does not publish exploit steps, affected tenant details beyond what is already public, live URLs, screenshots containing student data, or proof-of-concept abuse flows.

Separately, Instructure publicly disclosed a Canvas security incident in May 2026, and public reporting has linked the incident to ShinyHunters claims. This repository makes no claim that the June 2025 report caused, enabled, predicted, or is technically connected to the May 2026 incident.

This disclosure is documented here for project history and transparency only.

What this is

> A comprehensive Model Context Protocol (MCP) server for Canvas LMS with complete student, instructor, and account administration functionality

๐Ÿš€ What's New in v2.3.0

  • ๐ŸŒ NEW: Streamable HTTP transport support (`MCP_TRANSPORT=streamable-http`)
  • ๐Ÿ–ฅ๏ธ Preserved: First-class stdio transport for local MCP clients
  • ๐Ÿงช Added: Behavior tests for lifecycle, transports, and structured failure-path errors
  • ๐Ÿงฑ Improved: Stricter tool schemas and codemode-oriented tool descriptions
  • ๐Ÿ”ง FIXED: Course creation "page not found" error (missing `account_id` parameter)
  • ๐Ÿ‘จโ€๐Ÿ’ผ Account Management: Complete account-level administration tools
  • ๐Ÿ“Š Reports & Analytics: Generate and access Canvas account reports
  • ๐Ÿ‘ฅ User Management: Create and manage users at the account level
  • ๐Ÿข Multi-Account Support: Handle account hierarchies and sub-accounts
  • โœ… API Compliance: All endpoints now follow proper Canvas API patterns

๐ŸŽฏ Key Features

๐ŸŽ“ For Students

  • Course Management: Access all courses, syllabi, and course materials
  • Assignment Workflow: View, submit (text/URL/files), and track assignments
  • Communication: Participate in discussions, read announcements, send messages
  • Progress Tracking: Monitor grades, module completion, and calendar events
  • Quizzes: Take quizzes, view results and feedback
  • File Access: Browse and download course files and resources

๐Ÿ‘จโ€๐Ÿซ For Instructors

  • Course Creation: Create and manage course structure *(now with proper account support)*
  • Grading: Grade submissions, provide feedback, manage rubrics
  • User Management: Enroll students, manage permissions
  • Content Management: Create assignments, quizzes, discussions

๐Ÿ‘จโ€๐Ÿ’ผ For Account Administrators (NEW!)

  • Account Management: Manage institutional Canvas accounts
  • User Administration: Create and manage users across accounts
  • Course Oversight: List and manage all courses within accounts
  • Reporting: Generate enrollment, grade, and activity reports
  • Sub-Account Management: Handle account hierarchies and structures

๐Ÿ› ๏ธ Technical Excellence

  • Robust API: Automatic retries, pagination, comprehensive error handling
  • Cloud Ready: Docker containers, Kubernetes manifests, health checks
  • Well Tested: Unit tests, integration tests, mocking, coverage reports
  • Type Safe: Full TypeScript implementation with strict types
  • 50+ Tools: Comprehensive coverage of Canvas LMS functionality

Quick Start

Add to `claude_desktop_config.json`:

json
{
  "mcpServers": {
    "canvas-mcp-server": {
      "command": "npx",
      "args": ["-y", "canvas-mcp-server"],
      "env": {
        "CANVAS_API_TOKEN": "your_token_here",
        "CANVAS_DOMAIN": "your_school.instructure.com"
      }
    }
  }
}

Option 2: NPM Package

bash
# Install globally
npm install -g canvas-mcp-server

# Configure
export CANVAS_API_TOKEN="your_token_here"
export CANVAS_DOMAIN="your_school.instructure.com"

# Run
canvas-mcp-server

Option 3: Docker

bash
docker run -d \
  --name canvas-mcp \
  -p 3000:3000 \
  -e CANVAS_API_TOKEN="your_token" \
  -e CANVAS_DOMAIN="school.instructure.com" \
  -e MCP_TRANSPORT="streamable-http" \
  -e MCP_HTTP_HOST="0.0.0.0" \
  -e MCP_HTTP_PORT="3000" \
  -e MCP_HTTP_PATH="/mcp" \
  ghcr.io/dmontgomery40/mcp-canvas-lms:latest

Transport Modes

The server supports two explicit transport modes:

  • `stdio` (default): best for Claude Desktop/Codex/Cursor local MCP wiring.
  • `streamable-http`: best for local HTTP integrations and containerized workflows.

Transport environment variables

bash
# Required Canvas auth
CANVAS_API_TOKEN=your_token
CANVAS_DOMAIN=your_school.instructure.com

# Transport selection
MCP_TRANSPORT=stdio # or streamable-http

# Streamable HTTP settings
MCP_HTTP_HOST=127.0.0.1
MCP_HTTP_PORT=3000
MCP_HTTP_PATH=/mcp
MCP_HTTP_STATEFUL=true
MCP_HTTP_JSON_RESPONSE=true
MCP_HTTP_ALLOWED_ORIGINS=

๐Ÿ’ผ Account Admin Workflow Examples

Create a New Course (FIXED!)

code
"Create a new course called 'Advanced Biology' in account 123"

Now properly creates courses with required account_id parameter

Manage Users

code
"Create a new student user John Doe with email john.doe@school.edu in our main account"

Creates user accounts with proper pseudonym and enrollment setup

Generate Reports

code
"Generate an enrollment report for account 456 for the current term"

Initiates Canvas reporting system for institutional analytics

List Account Courses

code
"Show me all published Computer Science courses in our Engineering account"

Advanced filtering and searching across account course catalogs

๐ŸŽ“ Student Workflow Examples

Check Today's Assignments

code
"What assignments do I have due this week?"

Lists upcoming assignments with due dates, points, and submission status

Submit an Assignment

code
"Help me submit my essay for English 101 Assignment 3"

Guides through text submission with formatting options

Check Grades

code
"What's my current grade in Biology?"

Shows current scores, grades, and assignment feedback

Participate in Discussions

code
"Show me the latest discussion posts in my Philosophy class"

Displays recent discussion topics and enables posting responses

Track Progress

code
"What modules do I need to complete in Math 200?"

Shows module completion status and next items to complete

Getting Canvas API Token

1. Log into Canvas โ†’ Account โ†’ Settings

2. Scroll to "Approved Integrations"

3. Click "+ New Access Token"

4. Enter description: "Claude MCP Integration"

5. Copy the generated token Save securely!

โš ๏ธ Account Admin Note: For account-level operations, ensure your API token has administrative privileges.

Production Deployment

Docker Compose

bash
git clone https://github.com/DMontgomery40/mcp-canvas-lms.git
cd mcp-canvas-lms
cp .env.example .env
# Edit .env with your Canvas credentials
docker-compose up -d

Kubernetes

bash
kubectl create secret generic canvas-mcp-secrets \
  --from-literal=CANVAS_API_TOKEN="your_token" \
  --from-literal=CANVAS_DOMAIN="school.instructure.com"

kubectl apply -f k8s/

Health Monitoring

bash
# Check application health
curl http://localhost:3000/health

# Or use the built-in health check
npm run health-check

Development

bash
# Setup development environment
git clone https://github.com/DMontgomery40/mcp-canvas-lms.git
cd mcp-canvas-lms
npm install

# Start development with hot reload
npm run dev:watch

# Run tests
npm run test
npm run coverage

# Code quality
npm run lint
npm run type-check

๐Ÿ“š Available Tools (50+ Tools)

๐ŸŽ“ Core Student Tools (Click to expand)

  • `canvas_health_check` - Check API connectivity
  • `canvas_list_courses` - List all your courses
  • `canvas_get_course` - Get detailed course info
  • `canvas_list_assignments` - List course assignments
  • `canvas_get_assignment` - Get assignment details
  • `canvas_submit_assignment` - Submit assignment work
  • `canvas_get_submission` - Check submission status
  • `canvas_list_modules` - List course modules
  • `canvas_get_module` - Get module details
  • `canvas_list_module_items` - List items in a module
  • `canvas_mark_module_item_complete` - Mark items complete
  • `canvas_list_discussion_topics` - List discussion topics
  • `canvas_get_discussion_topic` - Get discussion details
  • `canvas_post_to_discussion` - Post to discussions
  • `canvas_list_announcements` - List course announcements
  • `canvas_get_user_grades` - Get your grades
  • `canvas_get_course_grades` - Get course-specific grades
  • `canvas_get_dashboard` - Get dashboard info
  • `canvas_get_dashboard_cards` - Get course cards
  • `canvas_get_upcoming_assignments` - Get due dates
  • `canvas_list_calendar_events` - List calendar events
  • `canvas_list_files` - List course files
  • `canvas_get_file` - Get file details
  • `canvas_list_folders` - List course folders
  • `canvas_list_pages` - List course pages
  • `canvas_get_page` - Get page content
  • `canvas_list_conversations` - List messages
  • `canvas_get_conversation` - Get conversation details
  • `canvas_create_conversation` - Send messages
  • `canvas_list_notifications` - List notifications
  • `canvas_get_syllabus` - Get course syllabus
  • `canvas_get_user_profile` - Get user profile
  • `canvas_update_user_profile` - Update profile

๐Ÿ‘จโ€๐Ÿซ Instructor Tools (Click to expand)

  • `canvas_create_course` - Create new courses *(FIXED: now requires account_id)*
  • `canvas_update_course` - Update course settings
  • `canvas_create_assignment` - Create assignments
  • `canvas_update_assignment` - Update assignments
  • `canvas_list_assignment_groups` - List assignment groups
  • `canvas_submit_grade` - Grade submissions
  • `canvas_enroll_user` - Enroll students
  • `canvas_list_quizzes` - List course quizzes
  • `canvas_get_quiz` - Get quiz details
  • `canvas_create_quiz` - Create quizzes
  • `canvas_start_quiz_attempt` - Start quiz attempts
  • `canvas_list_rubrics` - List course rubrics
  • `canvas_get_rubric` - Get rubric details

๐Ÿ‘จโ€๐Ÿ’ผ Account Management Tools (NEW!)

  • `canvas_get_account` - Get account details
  • `canvas_list_account_courses` - List courses in an account
  • `canvas_list_account_users` - List users in an account
  • `canvas_create_user` - Create new users in accounts
  • `canvas_list_sub_accounts` - List sub-accounts
  • `canvas_get_account_reports` - List available reports
  • `canvas_create_account_report` - Generate account reports

๐Ÿ”ง Breaking Changes in v2.2.0

Course Creation Fix

BEFORE (Broken):

javascript
{
  "tool": "canvas_create_course",
  "arguments": {
    "name": "My Course"  // โŒ Missing account_id - caused "page not found"
  }
}

AFTER (Fixed):

javascript
{
  "tool": "canvas_create_course", 
  "arguments": {
    "account_id": 123,              // โœ… Required account_id
    "name": "My Course",
    "course_code": "CS-101"
  }
}

๐ŸŒŸ Example Claude Conversations

Student: *"I need to check my upcoming assignments and submit my English essay"*

Claude: *I'll help you check your upcoming assignments and then assist with submitting your English essay. Let me start by getting your upcoming assignments...*

[Claude uses `canvas_get_upcoming_assignments` then helps with `canvas_submit_assignment`]


Instructor: *"Create a new Advanced Physics course in the Science department and enroll my teaching assistant"*

Claude: *I'll help you create the Advanced Physics course in your Science department account and then enroll your TA...*

[Claude uses `canvas_create_course` with proper account_id, then `canvas_enroll_user`]


Administrator: *"Generate an enrollment report for all Computer Science courses this semester"*

Claude: *I'll generate a comprehensive enrollment report for your CS courses...*

[Claude uses `canvas_list_account_courses` with filters, then `canvas_create_account_report`]

๐Ÿ” Troubleshooting

Common Issues:

  • โŒ 401 Unauthorized: Check your API token and permissions
  • โŒ 404 Not Found: Verify course/assignment IDs and access rights
  • โŒ "Page not found" on course creation: Update to v2.2.0 for account_id fix
  • โŒ Timeout: Increase `CANVAS_TIMEOUT` or check network connectivity

Debug Mode:

bash
export LOG_LEVEL=debug
npm start

Health Check:

bash
npm run health-check

๐Ÿค Contributing

We welcome contributions! See CONTRIBUTING.md for guidelines.

Quick Contribution Setup

bash
git clone https://github.com/DMontgomery40/mcp-canvas-lms.git
cd mcp-canvas-lms
npm install
npm run dev:watch
# Make changes, add tests, submit PR

๐Ÿ“ˆ Roadmap

  • v2.3: Enhanced reporting, bulk operations, advanced search
  • v2.4: Mobile support, offline capability, analytics dashboard
  • v3.0: Multi-tenant, GraphQL API, AI-powered insights

๐Ÿ™‹ Support & Community

Appendix: MCP in Practice (Code Execution, Tool Scale, and Safety)

Last updated: 2026-03-23

Why This Appendix Exists

MCP is still one of the most useful interoperability layers for agentic tooling. The tradeoff is that large MCP servers can expose dozens of tools, and naive tool-calling can flood context windows with tool schemas, call traces, and low-signal chatter.

In practice, larger tool surfaces only help when orchestration stays token-efficient and execution behavior is constrained.

The Shift to Code Execution / Code Mode

Recent production workflows move orchestration out of conversational turns and into executable loops. This keeps context overhead lower, improves determinism, and makes runs auditable.

Core reading:

For lower-noise, repeatable MCP usage, start with codemode-oriented routing:

Even with strong setup, model behavior can be hit-or-miss across providers and versions. Keep retries and deterministic fallbacks.

Peter Steinberger Workflow Pattern

A high-leverage pattern is turning broad MCP tool surfaces into narrower CLI/task interfaces:

What Works Best With Which MCP Clients

  • Claude Code / Codex / Cursor agent workflows: usually strong for direct MCP + code-execution loops.
  • Thin hosted chat clients: often safer with wrapped CLIs/gateways instead of full raw tool exposure.
  • High-tool-count servers: usually better when split into narrow task gateways.

This ecosystem changes quickly. If you are reading this now, parts of this section may already be out of date.

Prompt Injection: Risks, Consequences, and Mitigations

Prompt injection remains an open problem for tool-using agents. It is manageable, but not solved.

Primary risks:

  • Hidden instructions in retrieved content or tool output.
  • Secret/token exfiltration through unintended calls.
  • Unauthorized state changes in systems or data.

Mitigation baseline:

  • Least-privilege credentials and scoped tokens.
  • Destination/action allowlists and strict schema validation.
  • Human confirmation for destructive operations.
  • Sandboxed execution and resource limits.
  • Structured logging and replayable execution traces.

Treat every tool output as untrusted input unless explicitly verified.

๐Ÿ“„ License

MIT License - see LICENSE file for details.


Frequently asked questions

What is mcp-canvas-lms?

mcp-canvas-lms is Version 2.2 - 54 tools available - an MCP server for interacting with the Canvas LMS API. This server allows you to manage courses, assignments, enrollments, and grades within Canvas.

How do I install mcp-canvas-lms?

Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.

Is mcp-canvas-lms open source?

Yes โ€” it is hosted on GitHub at https://github.com/dmontgomery40/mcp-canvas-lms and has 61 stars.

Related MCP tools

Run your own MCP server? See who uses it and what to fix.

Measure it with TrackMCP