Canvas MCP Server

by dmontgomery40

30 494 downloads Not rated yet

About

An MCP server for Canvas LMS, providing full functionality for both students and instructors.

Details

Repository
DMontgomery40/mcp-canvas-lms

Explore

- Student features: course management, assignment submission, grade tracking.
-

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Canvas MCP Server
    Command (node, npx, python, etc.) npx
    Arguments
    • Argument 1 -y
    • Argument 2 canvas-mcp-server
    Environment
    • CANVAS_DOMAIN your_school.instructure.com
    • CANVAS_API_TOKEN your_token_here

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

export CANVAS_API_TOKEN="your_token_here"
export CANVAS_DOMAIN="your_school.instructure.com"

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "canvas-mcp-server": {
      "command": "npx",
      "args": ["-y", "canvas-mcp-server"],
      "env": {
        "CANVAS_API_TOKEN": "your_token_here",
        "CANVAS_DOMAIN": "your_school.instructure.com"
      }
    }
  }
}

npm install -g canvas-mcp-server


1. Log into Canvas → Account → Settings
2. Scroll to "Approved Integrations"
3. Click "+ New Access Token"
4. Enter description: "Claude MCP Integration"
5. Copy the generated token Save securely!

⚠️ Account Admin Note: For account-level operations, ensure your API token has administrative privileges.

git clone https://github.com/DMontgomery40/mcp-canvas-lms.git
cd mcp-canvas-lms
npm install

bash
git clone https://github.com/DMontgomery40/mcp-canvas-lms.git
cd mcp-canvas-lms
npm install
npm run dev:watch

For lower-noise, repeatable MCP usage, start with codemode-oriented routing:
- codemode-mcp (jx-codes)
- UTCP

Even with strong setup, model behavior can be hit-or-miss across providers and versions. Keep retries and deterministic fallbacks.

canvas_health_check

Check API connectivity.

canvas_list_courses

List all your courses.

canvas_get_course

Get detailed course info.

canvas_list_assignments

List course assignments.

canvas_get_assignment

Get assignment details.

canvas_submit_assignment

Submit assignment work.

canvas_get_submission

Check submission status.

canvas_list_modules

List course modules.

canvas_get_module

Get module details.

canvas_list_module_items

List items in a module.

canvas_mark_module_item_complete

Mark items complete.

canvas_list_discussion_topics

List discussion topics.

canvas_get_discussion_topic

Get discussion details.

canvas_post_to_discussion

Post to discussions.

canvas_list_announcements

List course announcements.

canvas_get_user_grades

Get your grades.

canvas_get_course_grades

Get course-specific grades.

canvas_get_dashboard

Get dashboard info.

canvas_get_dashboard_cards

Get course cards.

canvas_get_upcoming_assignments

Get due dates.

canvas_list_calendar_events

List calendar events.

canvas_list_files

List course files.

canvas_get_file

Get file details.

canvas_list_folders

List course folders.

canvas_list_pages

List course pages.

canvas_get_page

Get page content.

canvas_list_conversations

List messages.

canvas_get_conversation

Get conversation details.

canvas_create_conversation

Send messages.

canvas_list_notifications

List notifications.

canvas_get_syllabus

Get course syllabus.

canvas_get_user_profile

Get user profile.

canvas_update_user_profile

Update profile.

canvas_create_course

Create new courses.

canvas_update_course

Update course settings.

canvas_create_assignment

Create assignments.

canvas_update_assignment

Update assignments.

canvas_list_assignment_groups

List assignment groups.

canvas_submit_grade

Grade submissions.

canvas_enroll_user

Enroll students.

canvas_list_quizzes

List course quizzes.

canvas_get_quiz

Get quiz details.

canvas_create_quiz

Create quizzes.

canvas_start_quiz_attempt

Start quiz attempts.

canvas_list_rubrics

List course rubrics.

canvas_get_rubric

Get rubric details.

canvas_get_account

Get account details.

canvas_list_account_courses

List courses in an account.

canvas_list_account_users

List users in an account.

canvas_create_user

Create new users in accounts.

canvas_list_sub_accounts

List sub-accounts.

canvas_get_account_reports

List available reports.

canvas_create_account_report

Generate account reports.

<details>
<summary><strong>🎓 Core Student Tools (Click to expand)</strong></summary>

- canvas_health_check - Check API connectivity
- canvas_list_courses - List all your courses
- canvas_get_course - Get detailed course info
- canvas_list_assignments - List course assignments
- canvas_get_assignment - Get assignment details
- canvas_submit_assignment - Submit assignment work
- canvas_get_submission - Check submission status
- canvas_list_modules - List course modules
- canvas_get_module - Get module details
- canvas_list_module_items - List items in a module
- canvas_mark_module_item_complete - Mark items complete
- canvas_list_discussion_topics - List discussion topics
- canvas_get_discussion_topic - Get discussion details
- canvas_post_to_discussion - Post to discussions
- canvas_list_announcements - List course announcements
- canvas_get_user_grades - Get your grades
- canvas_get_course_grades - Get course-specific grades
- canvas_get_dashboard - Get dashboard info
- canvas_get_dashboard_cards - Get course cards
- canvas_get_upcoming_assignments - Get due dates
- canvas_list_calendar_events - List calendar events
- canvas_list_files - List course files
- canvas_get_file - Get file details
- canvas_list_folders - List course folders
- canvas_list_pages - List course pages
- canvas_get_page - Get page content
- canvas_list_conversations - List messages
- canvas_get_conversation - Get conversation details
- canvas_create_conversation - Send messages
- canvas_list_notifications - List notifications
- canvas_get_syllabus - Get course syllabus
- canvas_get_user_profile - Get user profile
- canvas_update_user_profile - Update profile

</details>

<details>
<summary><strong>👨‍🏫 Instructor Tools (Click to expand)</strong></summary>

- canvas_create_course - Create new courses (FIXED: now requires account_id)
- canvas_update_course - Update course settings
- canvas_create_assignment - Create assignments
- canvas_update_assignment - Update assignments
- canvas_list_assignment_groups - List assignment groups
- canvas_submit_grade - Grade submissions
- canvas_enroll_user - Enroll students
- canvas_list_quizzes - List course quizzes
- canvas_get_quiz - Get quiz details
- canvas_create_quiz - Create quizzes
- canvas_start_quiz_attempt - Start quiz attempts
- canvas_list_rubrics - List course rubrics
- canvas_get_rubric - Get rubric details

</details>

<details>
<summary><strong>👨‍💼 Account Management Tools (NEW!)</strong></summary>

- canvas_get_account - Get account details
- canvas_list_account_courses - List courses in an account
- canvas_list_account_users - List users in an account
- canvas_create_user - Create new users in accounts
- canvas_list_sub_accounts - List sub-accounts
- canvas_get_account_reports - List available reports
- canvas_create_account_report - Generate account reports

</details>

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "canvas mcp server": {
            "env": {
                "CANVAS_DOMAIN": "your_school.instructure.com",
                "CANVAS_API_TOKEN": "your_token_here"
            },
            "args": [
                "-y",
                "canvas-mcp-server"
            ],
            "command": "npx"
        }
    }
}

Linux

{
    "env": {
        "CANVAS_DOMAIN": "your_school.instructure.com",
        "CANVAS_API_TOKEN": "your_token_here"
    },
    "args": [
        "-y",
        "canvas-mcp-server"
    ],
    "command": "npx"
}

Macos

{
    "env": {
        "CANVAS_DOMAIN": "your_school.instructure.com",
        "CANVAS_API_TOKEN": "your_token_here"
    },
    "args": [
        "-y",
        "canvas-mcp-server"
    ],
    "command": "npx"
}

Windows

{
    "env": {
        "CANVAS_DOMAIN": "your_school.instructure.com",
        "CANVAS_API_TOKEN": "your_token_here"
    },
    "args": [
        "/c",
        "npx",
        "-y",
        "canvas-mcp-server"
    ],
    "command": "cmd"
}

Security and disclosure history

This project is an independent MCP server for Canvas LMS APIs. It is not affiliated with, endorsed by, or maintained by Instructure or Canvas.

In June 2025, during development of this MCP, I identified a Broken Access Control issue in the Canvas environment at bootcampspot.instructure.com. The issue exposed personally identifiable information for other students enrolled in my course.

I reported the issue through Bugcrowd on June 5, 2025, and also contacted Instructure / Canvas security channels directly. The Bugcrowd report was later closed as "Not Applicable." In subsequent correspondence, Instructure stated that the bootcampspot.instructure.com environment was outside its control.

Public references:

- Disclosure thread: https://www.reddit.com/r/cybersecurity/comments/1t6wmkw/reported_a_broken_access_control_bug_to/
- Bugcrowd activity timeline: https://imgur.com/gallery/canvas-vuln-declared-n-11-months-ago-zYfHnBs
- Later Instructure / BootcampSpot correspondence: https://imgur.com/a/BnhgXme

This repository does not publish exploit steps, affected tenant details beyond what is already public, live URLs, screenshots containing student data, or proof-of-concept abuse flows.

Separately, Instructure publicly disclosed a Canvas security incident in May 2026, and public reporting has linked the incident to ShinyHunters claims. This repository makes no claim that the June 2025 report caused, enabled, predicted, or is technically connected to the May 2026 incident.

This disclosure is documented here for project history and transparency only.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.

Videos about Canvas MCP Server

Relevant YouTube tutorials, setups, and demos