mcp-canvas-lms
Version 2.2 - 54 tools available - an MCP server for interacting with the Canvas LMS API. This server allows you to manage courses, assignments, enrollments, and grades within Canvas.
Documentation
Canvas MCP Server v2.3.0
Security and disclosure history
This project is an independent MCP server for Canvas LMS APIs. It is not affiliated with, endorsed by, or maintained by Instructure or Canvas.
In June 2025, during development of this MCP, I identified a Broken Access Control issue in the Canvas environment at bootcampspot.instructure.com. The issue exposed personally identifiable information for other students enrolled in my course.
I reported the issue through Bugcrowd on June 5, 2025, and also contacted Instructure / Canvas security channels directly. The Bugcrowd report was later closed as "Not Applicable." In subsequent correspondence, Instructure stated that the bootcampspot.instructure.com environment was outside its control.
Public references:
- Disclosure thread: https://www.reddit.com/r/cybersecurity/comments/1t6wmkw/reported_a_broken_access_control_bug_to/
- Bugcrowd activity timeline: https://imgur.com/gallery/canvas-vuln-declared-n-11-months-ago-zYfHnBs
- Later Instructure / BootcampSpot correspondence: https://imgur.com/a/BnhgXme
This repository does not publish exploit steps, affected tenant details beyond what is already public, live URLs, screenshots containing student data, or proof-of-concept abuse flows.
Separately, Instructure publicly disclosed a Canvas security incident in May 2026, and public reporting has linked the incident to ShinyHunters claims. This repository makes no claim that the June 2025 report caused, enabled, predicted, or is technically connected to the May 2026 incident.
This disclosure is documented here for project history and transparency only.
What this is
> A comprehensive Model Context Protocol (MCP) server for Canvas LMS with complete student, instructor, and account administration functionality
๐ What's New in v2.3.0
- ๐ NEW: Streamable HTTP transport support (`MCP_TRANSPORT=streamable-http`)
- ๐ฅ๏ธ Preserved: First-class stdio transport for local MCP clients
- ๐งช Added: Behavior tests for lifecycle, transports, and structured failure-path errors
- ๐งฑ Improved: Stricter tool schemas and codemode-oriented tool descriptions
- ๐ง FIXED: Course creation "page not found" error (missing `account_id` parameter)
- ๐จโ๐ผ Account Management: Complete account-level administration tools
- ๐ Reports & Analytics: Generate and access Canvas account reports
- ๐ฅ User Management: Create and manage users at the account level
- ๐ข Multi-Account Support: Handle account hierarchies and sub-accounts
- โ API Compliance: All endpoints now follow proper Canvas API patterns
๐ฏ Key Features
๐ For Students
- Course Management: Access all courses, syllabi, and course materials
- Assignment Workflow: View, submit (text/URL/files), and track assignments
- Communication: Participate in discussions, read announcements, send messages
- Progress Tracking: Monitor grades, module completion, and calendar events
- Quizzes: Take quizzes, view results and feedback
- File Access: Browse and download course files and resources
๐จโ๐ซ For Instructors
- Course Creation: Create and manage course structure *(now with proper account support)*
- Grading: Grade submissions, provide feedback, manage rubrics
- User Management: Enroll students, manage permissions
- Content Management: Create assignments, quizzes, discussions
๐จโ๐ผ For Account Administrators (NEW!)
- Account Management: Manage institutional Canvas accounts
- User Administration: Create and manage users across accounts
- Course Oversight: List and manage all courses within accounts
- Reporting: Generate enrollment, grade, and activity reports
- Sub-Account Management: Handle account hierarchies and structures
๐ ๏ธ Technical Excellence
- Robust API: Automatic retries, pagination, comprehensive error handling
- Cloud Ready: Docker containers, Kubernetes manifests, health checks
- Well Tested: Unit tests, integration tests, mocking, coverage reports
- Type Safe: Full TypeScript implementation with strict types
- 50+ Tools: Comprehensive coverage of Canvas LMS functionality
Quick Start
Option 1: Claude Desktop Integration (Recommended MCP Setup)
Add to `claude_desktop_config.json`:
{
"mcpServers": {
"canvas-mcp-server": {
"command": "npx",
"args": ["-y", "canvas-mcp-server"],
"env": {
"CANVAS_API_TOKEN": "your_token_here",
"CANVAS_DOMAIN": "your_school.instructure.com"
}
}
}
}Option 2: NPM Package
# Install globally
npm install -g canvas-mcp-server
# Configure
export CANVAS_API_TOKEN="your_token_here"
export CANVAS_DOMAIN="your_school.instructure.com"
# Run
canvas-mcp-serverOption 3: Docker
docker run -d \
--name canvas-mcp \
-p 3000:3000 \
-e CANVAS_API_TOKEN="your_token" \
-e CANVAS_DOMAIN="school.instructure.com" \
-e MCP_TRANSPORT="streamable-http" \
-e MCP_HTTP_HOST="0.0.0.0" \
-e MCP_HTTP_PORT="3000" \
-e MCP_HTTP_PATH="/mcp" \
ghcr.io/dmontgomery40/mcp-canvas-lms:latestTransport Modes
The server supports two explicit transport modes:
- `stdio` (default): best for Claude Desktop/Codex/Cursor local MCP wiring.
- `streamable-http`: best for local HTTP integrations and containerized workflows.
Transport environment variables
# Required Canvas auth
CANVAS_API_TOKEN=your_token
CANVAS_DOMAIN=your_school.instructure.com
# Transport selection
MCP_TRANSPORT=stdio # or streamable-http
# Streamable HTTP settings
MCP_HTTP_HOST=127.0.0.1
MCP_HTTP_PORT=3000
MCP_HTTP_PATH=/mcp
MCP_HTTP_STATEFUL=true
MCP_HTTP_JSON_RESPONSE=true
MCP_HTTP_ALLOWED_ORIGINS=๐ผ Account Admin Workflow Examples
Create a New Course (FIXED!)
"Create a new course called 'Advanced Biology' in account 123"Now properly creates courses with required account_id parameter
Manage Users
"Create a new student user John Doe with email john.doe@school.edu in our main account"Creates user accounts with proper pseudonym and enrollment setup
Generate Reports
"Generate an enrollment report for account 456 for the current term"Initiates Canvas reporting system for institutional analytics
List Account Courses
"Show me all published Computer Science courses in our Engineering account"Advanced filtering and searching across account course catalogs
๐ Student Workflow Examples
Check Today's Assignments
"What assignments do I have due this week?"Lists upcoming assignments with due dates, points, and submission status
Submit an Assignment
"Help me submit my essay for English 101 Assignment 3"Guides through text submission with formatting options
Check Grades
"What's my current grade in Biology?"Shows current scores, grades, and assignment feedback
Participate in Discussions
"Show me the latest discussion posts in my Philosophy class"Displays recent discussion topics and enables posting responses
Track Progress
"What modules do I need to complete in Math 200?"Shows module completion status and next items to complete
Getting Canvas API Token
1. Log into Canvas โ Account โ Settings
2. Scroll to "Approved Integrations"
3. Click "+ New Access Token"
4. Enter description: "Claude MCP Integration"
5. Copy the generated token Save securely!
โ ๏ธ Account Admin Note: For account-level operations, ensure your API token has administrative privileges.
Production Deployment
Docker Compose
git clone https://github.com/DMontgomery40/mcp-canvas-lms.git
cd mcp-canvas-lms
cp .env.example .env
# Edit .env with your Canvas credentials
docker-compose up -dKubernetes
kubectl create secret generic canvas-mcp-secrets \
--from-literal=CANVAS_API_TOKEN="your_token" \
--from-literal=CANVAS_DOMAIN="school.instructure.com"
kubectl apply -f k8s/Health Monitoring
# Check application health
curl http://localhost:3000/health
# Or use the built-in health check
npm run health-checkDevelopment
# Setup development environment
git clone https://github.com/DMontgomery40/mcp-canvas-lms.git
cd mcp-canvas-lms
npm install
# Start development with hot reload
npm run dev:watch
# Run tests
npm run test
npm run coverage
# Code quality
npm run lint
npm run type-check๐ Available Tools (50+ Tools)
๐ Core Student Tools (Click to expand)
- `canvas_health_check` - Check API connectivity
- `canvas_list_courses` - List all your courses
- `canvas_get_course` - Get detailed course info
- `canvas_list_assignments` - List course assignments
- `canvas_get_assignment` - Get assignment details
- `canvas_submit_assignment` - Submit assignment work
- `canvas_get_submission` - Check submission status
- `canvas_list_modules` - List course modules
- `canvas_get_module` - Get module details
- `canvas_list_module_items` - List items in a module
- `canvas_mark_module_item_complete` - Mark items complete
- `canvas_list_discussion_topics` - List discussion topics
- `canvas_get_discussion_topic` - Get discussion details
- `canvas_post_to_discussion` - Post to discussions
- `canvas_list_announcements` - List course announcements
- `canvas_get_user_grades` - Get your grades
- `canvas_get_course_grades` - Get course-specific grades
- `canvas_get_dashboard` - Get dashboard info
- `canvas_get_dashboard_cards` - Get course cards
- `canvas_get_upcoming_assignments` - Get due dates
- `canvas_list_calendar_events` - List calendar events
- `canvas_list_files` - List course files
- `canvas_get_file` - Get file details
- `canvas_list_folders` - List course folders
- `canvas_list_pages` - List course pages
- `canvas_get_page` - Get page content
- `canvas_list_conversations` - List messages
- `canvas_get_conversation` - Get conversation details
- `canvas_create_conversation` - Send messages
- `canvas_list_notifications` - List notifications
- `canvas_get_syllabus` - Get course syllabus
- `canvas_get_user_profile` - Get user profile
- `canvas_update_user_profile` - Update profile
๐จโ๐ซ Instructor Tools (Click to expand)
- `canvas_create_course` - Create new courses *(FIXED: now requires account_id)*
- `canvas_update_course` - Update course settings
- `canvas_create_assignment` - Create assignments
- `canvas_update_assignment` - Update assignments
- `canvas_list_assignment_groups` - List assignment groups
- `canvas_submit_grade` - Grade submissions
- `canvas_enroll_user` - Enroll students
- `canvas_list_quizzes` - List course quizzes
- `canvas_get_quiz` - Get quiz details
- `canvas_create_quiz` - Create quizzes
- `canvas_start_quiz_attempt` - Start quiz attempts
- `canvas_list_rubrics` - List course rubrics
- `canvas_get_rubric` - Get rubric details
๐จโ๐ผ Account Management Tools (NEW!)
- `canvas_get_account` - Get account details
- `canvas_list_account_courses` - List courses in an account
- `canvas_list_account_users` - List users in an account
- `canvas_create_user` - Create new users in accounts
- `canvas_list_sub_accounts` - List sub-accounts
- `canvas_get_account_reports` - List available reports
- `canvas_create_account_report` - Generate account reports
๐ง Breaking Changes in v2.2.0
Course Creation Fix
BEFORE (Broken):
{
"tool": "canvas_create_course",
"arguments": {
"name": "My Course" // โ Missing account_id - caused "page not found"
}
}AFTER (Fixed):
{
"tool": "canvas_create_course",
"arguments": {
"account_id": 123, // โ
Required account_id
"name": "My Course",
"course_code": "CS-101"
}
}๐ Example Claude Conversations
Student: *"I need to check my upcoming assignments and submit my English essay"*
Claude: *I'll help you check your upcoming assignments and then assist with submitting your English essay. Let me start by getting your upcoming assignments...*
[Claude uses `canvas_get_upcoming_assignments` then helps with `canvas_submit_assignment`]
Instructor: *"Create a new Advanced Physics course in the Science department and enroll my teaching assistant"*
Claude: *I'll help you create the Advanced Physics course in your Science department account and then enroll your TA...*
[Claude uses `canvas_create_course` with proper account_id, then `canvas_enroll_user`]
Administrator: *"Generate an enrollment report for all Computer Science courses this semester"*
Claude: *I'll generate a comprehensive enrollment report for your CS courses...*
[Claude uses `canvas_list_account_courses` with filters, then `canvas_create_account_report`]
๐ Troubleshooting
Common Issues:
- โ 401 Unauthorized: Check your API token and permissions
- โ 404 Not Found: Verify course/assignment IDs and access rights
- โ "Page not found" on course creation: Update to v2.2.0 for account_id fix
- โ Timeout: Increase `CANVAS_TIMEOUT` or check network connectivity
Debug Mode:
export LOG_LEVEL=debug
npm startHealth Check:
npm run health-check๐ค Contributing
We welcome contributions! See CONTRIBUTING.md for guidelines.
Quick Contribution Setup
git clone https://github.com/DMontgomery40/mcp-canvas-lms.git
cd mcp-canvas-lms
npm install
npm run dev:watch
# Make changes, add tests, submit PR๐ Roadmap
- v2.3: Enhanced reporting, bulk operations, advanced search
- v2.4: Mobile support, offline capability, analytics dashboard
- v3.0: Multi-tenant, GraphQL API, AI-powered insights
๐ Support & Community
- ๐ Bug Reports: GitHub Issues
- ๐ฌ Questions: GitHub Discussions
- ๐ Documentation: Wiki
Appendix: MCP in Practice (Code Execution, Tool Scale, and Safety)
Last updated: 2026-03-23
Why This Appendix Exists
MCP is still one of the most useful interoperability layers for agentic tooling. The tradeoff is that large MCP servers can expose dozens of tools, and naive tool-calling can flood context windows with tool schemas, call traces, and low-signal chatter.
In practice, larger tool surfaces only help when orchestration stays token-efficient and execution behavior is constrained.
The Shift to Code Execution / Code Mode
Recent production workflows move orchestration out of conversational turns and into executable loops. This keeps context overhead lower, improves determinism, and makes runs auditable.
Core reading:
Recommended Setup for Power Users
For lower-noise, repeatable MCP usage, start with codemode-oriented routing:
Even with strong setup, model behavior can be hit-or-miss across providers and versions. Keep retries and deterministic fallbacks.
Peter Steinberger Workflow Pattern
A high-leverage pattern is turning broad MCP tool surfaces into narrower CLI/task interfaces:
What Works Best With Which MCP Clients
- Claude Code / Codex / Cursor agent workflows: usually strong for direct MCP + code-execution loops.
- Thin hosted chat clients: often safer with wrapped CLIs/gateways instead of full raw tool exposure.
- High-tool-count servers: usually better when split into narrow task gateways.
This ecosystem changes quickly. If you are reading this now, parts of this section may already be out of date.
Prompt Injection: Risks, Consequences, and Mitigations
Prompt injection remains an open problem for tool-using agents. It is manageable, but not solved.
Primary risks:
- Hidden instructions in retrieved content or tool output.
- Secret/token exfiltration through unintended calls.
- Unauthorized state changes in systems or data.
Mitigation baseline:
- Least-privilege credentials and scoped tokens.
- Destination/action allowlists and strict schema validation.
- Human confirmation for destructive operations.
- Sandboxed execution and resource limits.
- Structured logging and replayable execution traces.
Treat every tool output as untrusted input unless explicitly verified.
๐ License
MIT License - see LICENSE file for details.
Frequently asked questions
What is mcp-canvas-lms?
mcp-canvas-lms is Version 2.2 - 54 tools available - an MCP server for interacting with the Canvas LMS API. This server allows you to manage courses, assignments, enrollments, and grades within Canvas.
How do I install mcp-canvas-lms?
Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.
Is mcp-canvas-lms open source?
Yes โ it is hosted on GitHub at https://github.com/dmontgomery40/mcp-canvas-lms and has 61 stars.
Related MCP tools
Add Obsidian integrations like semantic search and custom Templater prompts to Claude or any MCP client. TypeScript-based implementation.
AI Agents & MCPs & AI Workflow Automation โข (~400 MCP servers for AI agents) โข AI Automation / AI Agent with MCPs โข AI Workflows & AI Agents โข MCPs for AI Ag...
Mcp-use is the easiest way to interact with mcp servers with custom agents TypeScript-based implementation. Trusted by 8100+ developers.
5ire is a cross-platform desktop AI assistant, MCP client. It compatible with major service providers, supports local knowledge base and tools via model co...
๐ค A visualization mcp contains 25+ visual charts using @antvis. Using for chart generation and data analysis. TypeScript-based implementation.
A Model Context Protocol server for converting almost anything to Markdown TypeScript-based implementation. Trusted by 2200+ developers.
Run your own MCP server? See who uses it and what to fix.
Measure it with TrackMCP