Canvas MCP Server
About
An MCP server for Canvas LMS, providing full functionality for both students and instructors.
Details
- Repository
- DMontgomery40/mcp-canvas-lms
Explore
- Student features: course management, assignment submission, grade tracking.
-
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
Canvas MCP ServerCommand (node, npx, python, etc.)npxArguments-
Argument 1
-y -
Argument 2
canvas-mcp-server
Environment-
CANVAS_DOMAIN
your_school.instructure.com -
CANVAS_API_TOKEN
your_token_here
Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
-
Argument 1
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
export CANVAS_API_TOKEN="your_token_here"
export CANVAS_DOMAIN="your_school.instructure.com"
Add to claude_desktop_config.json:
{
"mcpServers": {
"canvas-mcp-server": {
"command": "npx",
"args": ["-y", "canvas-mcp-server"],
"env": {
"CANVAS_API_TOKEN": "your_token_here",
"CANVAS_DOMAIN": "your_school.instructure.com"
}
}
}
}
npm install -g canvas-mcp-server
1. Log into Canvas → Account → Settings
2. Scroll to "Approved Integrations"
3. Click "+ New Access Token"
4. Enter description: "Claude MCP Integration"
5. Copy the generated token Save securely!
⚠️ Account Admin Note: For account-level operations, ensure your API token has administrative privileges.
git clone https://github.com/DMontgomery40/mcp-canvas-lms.git
cd mcp-canvas-lms
npm install
bashgit clone https://github.com/DMontgomery40/mcp-canvas-lms.git
cd mcp-canvas-lms
npm install
npm run dev:watch
For lower-noise, repeatable MCP usage, start with codemode-oriented routing:
- codemode-mcp (jx-codes)
- UTCP
Even with strong setup, model behavior can be hit-or-miss across providers and versions. Keep retries and deterministic fallbacks.
canvas_health_check
Check API connectivity.
canvas_list_courses
List all your courses.
canvas_get_course
Get detailed course info.
canvas_list_assignments
List course assignments.
canvas_get_assignment
Get assignment details.
canvas_submit_assignment
Submit assignment work.
canvas_get_submission
Check submission status.
canvas_list_modules
List course modules.
canvas_get_module
Get module details.
canvas_list_module_items
List items in a module.
canvas_mark_module_item_complete
Mark items complete.
canvas_list_discussion_topics
List discussion topics.
canvas_get_discussion_topic
Get discussion details.
canvas_post_to_discussion
Post to discussions.
canvas_list_announcements
List course announcements.
canvas_get_user_grades
Get your grades.
canvas_get_course_grades
Get course-specific grades.
canvas_get_dashboard
Get dashboard info.
canvas_get_dashboard_cards
Get course cards.
canvas_get_upcoming_assignments
Get due dates.
canvas_list_calendar_events
List calendar events.
canvas_list_files
List course files.
canvas_get_file
Get file details.
canvas_list_folders
List course folders.
canvas_list_pages
List course pages.
canvas_get_page
Get page content.
canvas_list_conversations
List messages.
canvas_get_conversation
Get conversation details.
canvas_create_conversation
Send messages.
canvas_list_notifications
List notifications.
canvas_get_syllabus
Get course syllabus.
canvas_get_user_profile
Get user profile.
canvas_update_user_profile
Update profile.
canvas_create_course
Create new courses.
canvas_update_course
Update course settings.
canvas_create_assignment
Create assignments.
canvas_update_assignment
Update assignments.
canvas_list_assignment_groups
List assignment groups.
canvas_submit_grade
Grade submissions.
canvas_enroll_user
Enroll students.
canvas_list_quizzes
List course quizzes.
canvas_get_quiz
Get quiz details.
canvas_create_quiz
Create quizzes.
canvas_start_quiz_attempt
Start quiz attempts.
canvas_list_rubrics
List course rubrics.
canvas_get_rubric
Get rubric details.
canvas_get_account
Get account details.
canvas_list_account_courses
List courses in an account.
canvas_list_account_users
List users in an account.
canvas_create_user
Create new users in accounts.
canvas_list_sub_accounts
List sub-accounts.
canvas_get_account_reports
List available reports.
canvas_create_account_report
Generate account reports.
<details>
<summary><strong>🎓 Core Student Tools (Click to expand)</strong></summary>
- canvas_health_check - Check API connectivity
- canvas_list_courses - List all your courses
- canvas_get_course - Get detailed course info
- canvas_list_assignments - List course assignments
- canvas_get_assignment - Get assignment details
- canvas_submit_assignment - Submit assignment work
- canvas_get_submission - Check submission status
- canvas_list_modules - List course modules
- canvas_get_module - Get module details
- canvas_list_module_items - List items in a module
- canvas_mark_module_item_complete - Mark items complete
- canvas_list_discussion_topics - List discussion topics
- canvas_get_discussion_topic - Get discussion details
- canvas_post_to_discussion - Post to discussions
- canvas_list_announcements - List course announcements
- canvas_get_user_grades - Get your grades
- canvas_get_course_grades - Get course-specific grades
- canvas_get_dashboard - Get dashboard info
- canvas_get_dashboard_cards - Get course cards
- canvas_get_upcoming_assignments - Get due dates
- canvas_list_calendar_events - List calendar events
- canvas_list_files - List course files
- canvas_get_file - Get file details
- canvas_list_folders - List course folders
- canvas_list_pages - List course pages
- canvas_get_page - Get page content
- canvas_list_conversations - List messages
- canvas_get_conversation - Get conversation details
- canvas_create_conversation - Send messages
- canvas_list_notifications - List notifications
- canvas_get_syllabus - Get course syllabus
- canvas_get_user_profile - Get user profile
- canvas_update_user_profile - Update profile
</details>
<details>
<summary><strong>👨🏫 Instructor Tools (Click to expand)</strong></summary>
- canvas_create_course - Create new courses (FIXED: now requires account_id)
- canvas_update_course - Update course settings
- canvas_create_assignment - Create assignments
- canvas_update_assignment - Update assignments
- canvas_list_assignment_groups - List assignment groups
- canvas_submit_grade - Grade submissions
- canvas_enroll_user - Enroll students
- canvas_list_quizzes - List course quizzes
- canvas_get_quiz - Get quiz details
- canvas_create_quiz - Create quizzes
- canvas_start_quiz_attempt - Start quiz attempts
- canvas_list_rubrics - List course rubrics
- canvas_get_rubric - Get rubric details
</details>
<details>
<summary><strong>👨💼 Account Management Tools (NEW!)</strong></summary>
- canvas_get_account - Get account details
- canvas_list_account_courses - List courses in an account
- canvas_list_account_users - List users in an account
- canvas_create_user - Create new users in accounts
- canvas_list_sub_accounts - List sub-accounts
- canvas_get_account_reports - List available reports
- canvas_create_account_report - Generate account reports
</details>
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"canvas mcp server": {
"env": {
"CANVAS_DOMAIN": "your_school.instructure.com",
"CANVAS_API_TOKEN": "your_token_here"
},
"args": [
"-y",
"canvas-mcp-server"
],
"command": "npx"
}
}
}
Linux
{
"env": {
"CANVAS_DOMAIN": "your_school.instructure.com",
"CANVAS_API_TOKEN": "your_token_here"
},
"args": [
"-y",
"canvas-mcp-server"
],
"command": "npx"
}
Macos
{
"env": {
"CANVAS_DOMAIN": "your_school.instructure.com",
"CANVAS_API_TOKEN": "your_token_here"
},
"args": [
"-y",
"canvas-mcp-server"
],
"command": "npx"
}
Windows
{
"env": {
"CANVAS_DOMAIN": "your_school.instructure.com",
"CANVAS_API_TOKEN": "your_token_here"
},
"args": [
"/c",
"npx",
"-y",
"canvas-mcp-server"
],
"command": "cmd"
}
Security and disclosure history
This project is an independent MCP server for Canvas LMS APIs. It is not affiliated with, endorsed by, or maintained by Instructure or Canvas.
In June 2025, during development of this MCP, I identified a Broken Access Control issue in the Canvas environment at bootcampspot.instructure.com. The issue exposed personally identifiable information for other students enrolled in my course.
I reported the issue through Bugcrowd on June 5, 2025, and also contacted Instructure / Canvas security channels directly. The Bugcrowd report was later closed as "Not Applicable." In subsequent correspondence, Instructure stated that the bootcampspot.instructure.com environment was outside its control.
Public references:
- Disclosure thread: https://www.reddit.com/r/cybersecurity/comments/1t6wmkw/reported_a_broken_access_control_bug_to/
- Bugcrowd activity timeline: https://imgur.com/gallery/canvas-vuln-declared-n-11-months-ago-zYfHnBs
- Later Instructure / BootcampSpot correspondence: https://imgur.com/a/BnhgXme
This repository does not publish exploit steps, affected tenant details beyond what is already public, live URLs, screenshots containing student data, or proof-of-concept abuse flows.
Separately, Instructure publicly disclosed a Canvas security incident in May 2026, and public reporting has linked the incident to ShinyHunters claims. This repository makes no claim that the June 2025 report caused, enabled, predicted, or is technically connected to the May 2026 incident.
This disclosure is documented here for project history and transparency only.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



