Canvas

by vishalsachdev

Not rated yet

About

Integrates with the Canvas Learning Management System (LMS), supporting FERPA-compliant anonymization and privacy controls.

Explore

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Canvas
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

If you useClaude Desktop, you can install Canvas MCP with one click — no terminal, no config-file editing:
- Downloadcanvas-mcp.mcpbfrom the](https://www.microsoft.com/microsoft-copilot/microsoft-copilot-studio)latest release.
- Double-click the file (or drag it into Claude Desktop → Settings → Extensions).
- When prompted, enter yourCanvas API URL— this must include the/api/v1path (e.g.https://canvas.youruniversity.edu/api/v1) — and yourCanvas API token(Canvas → Account → Settings → New Access Token). The token is stored in your OS keychain.

The extension runs the server locally and calls Canvas withyour owntoken, so requests use that token's Canvas permissions. Canvas and your AI client may retain their own activity records. Requires Python 3.10+ (the bundled runtime manages dependencies automatically). For other clients, or to run from source, use the manual setup below.

# (Recommended) Use a dedicated virtualenv so the MCP binary is in a stable location python3 -m venv .venv . .venv/bin/activate # Install the package editable pip install -e .
# Copy environment template cp env.template .env # Edit with your Canvas credentials # Required: CANVAS_API_TOKEN, CANVAS_API_URL

Get your Canvas API token from:Canvas → Account → Settings → New Access Token

Note for Students: Some educational institutions restrict API token creation for students. If you see an error like "There is a limit to the number of access tokens you can create" or cannot find the token creation option, contact your institution's Canvas administrator or IT support department to request API access or assistance in creating a token.

Canvas MCP is designed for MCP-compatible clients. Below are configuration examples for popular clients; exact setup and capabilities vary by client:

- macOS:~/Library/Application Support/Claude/claude_desktop_config.json
- Windows:%APPDATA%\Claude\claude_desktop_config.json

{ "mcpServers": { "canvas-api": { "command": "/absolute/path/to/canvas-mcp/.venv/bin/canvas-mcp-server" } } }

Note: Use the absolute path to your virtualenv binary to avoid issues with shell-specific PATH entries (e.g., pyenv shims).

- macOS/Linux:~/.cursor/mcp_config.json
- Windows:%USERPROFILE%\.cursor\mcp_config.json

{ "mcpServers": { "canvas-api": { "command": "/absolute/path/to/canvas-mcp/.venv/bin/canvas-mcp-server" } } }

Configuration:Add to Zed'ssettings.json(accessible via Settings menu)

{ "context_servers": { "canvas-api": { "command": { "path": "/absolute/path/to/canvas-mcp/.venv/bin/canvas-mcp-server", "args": [] } } } }

- macOS:~/Library/Application Support/Windsurf/mcp_config.json
- Windows:%APPDATA%\Windsurf\mcp_config.json

{ "mcpServers": { "canvas-api": { "command": "/absolute/path/to/canvas-mcp/.venv/bin/canvas-mcp-server" } } }

Configuration:Add to Continue'sconfig.json(accessible via Continue settings)

{ "mcpServers": { "canvas-api": { "command": "/absolute/path/to/canvas-mcp/.venv/bin/canvas-mcp-server" } } }

For other MCP-compatible clients, the general pattern is:
- Locate your client's MCP configuration file
- Add a server entry with:

- Server name:canvas-api(or any name you prefer)
- Command: Full path tocanvas-mcp-serverbinary
- Optional args: Additional arguments if needed

Consult your client's MCP documentation for specific configuration format and file locations.

Windows users: Replace forward slashes with backslashes in paths (e.g.,C:\Users\YourName\canvas-mcp\.venv\Scripts\canvas-mcp-server.exe)

# Test Canvas API connection canvas-mcp-server --test # View configuration canvas-mcp-server --config # Start server (for manual testing) canvas-mcp-server

The Canvas MCP Server provides a set of tools for interacting with the Canvas LMS API. These tools are organized into logical categories for better discoverability and maintainability.

- Personal assignment tracking and deadline management
- Grade monitoring across all courses
- TODO list and peer review management
- Submission status tracking

Shared Tools(Both Students & Educators)
- Course Tools- List and manage courses, get detailed information, generate summaries with syllabus content
- Discussion & Announcement Tools- Manage discussions, announcements, and replies
- Page & Content Tools- Access pages, modules, and course content

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "canvas": {
            "server": {
                "command": "uvx",
                "args": [
                    "canvas-mcp"
                ]
            }
        }
    }
}

McpServers

{
    "server": {
        "command": "uvx",
        "args": [
            "canvas-mcp"
        ]
    }
}

Transport

"stdio"

Package

"canvas-mcp"

Registry

"pypi"

MCP server for Canvas LMS withup to 101 toolsand8 agent skills. Designed for Claude Desktop, Cursor, Codex, Windsurf, and40+ other agents; setup and capabilities vary by client.

Canvas MCP providesup to 101 toolsfor interacting with Canvas LMS; the default profile registers fewer, and optional feature-gated tools can raise the total to 101. Tools are organized by user type:

Skills:canvas-course-qc(pre-semester audit),canvas-accessibility-auditor(WCAG-oriented review),canvas-course-builder(scaffold courses from specs/templates).

Decision tree:Simple query → MCP tools. Batch grading (10+) →bulk_grade_submissions. Complex bulk (30+) →execute_typescript.

Course identifiers:Canvas ID (12345), course code (badm_350_120251_246794), or SIS ID

Cannot do:Create/delete courses, modify course settings, access other users' data

Rate limits:~700 requests/10 min. Usemax_concurrent=5for bulk operations.

Full documentation:AGENTS.md|tools/TOOL_MANIFEST.json|tools/README.md

The Canvas MCP Server bridges the gap between AI assistants and Canvas Learning Management System, providing role-specific workflows for students, educators, learning designers, and developers. Built on the Model Context Protocol (MCP), it is designed for MCP-compatible clients; setup and supported capabilities vary by client.

Released:August 2026 |Full Changelog|All Releases

A protocol-correctness release. Every change here is about a client being able to tell what actually happened when it calls a tool.One change is breaking and one alters response shape— read both before upgrading.

- Breaking:send_peer_review_remindersis nowsend_peer_review_inbox_messages(#303). The old name implied it invoked Canvas's native reminder action; it does not, it sends ordinary Canvas Inbox messages, and the name now says so. The tool also resolves the course and requiresmanage_gradesbefore previewing or sending, failing closed when the permission cannot be verified. Thanks@jonespmfor catching the mismatch
- Tool failures now set MCPisError: true(
#270). Previously a Canvas error and an empty-but-successful result were indistinguishable to a client: both came back as an ordinary result. Errors keep their existing text or structured payload, they are simply flagged correctly now
- Response-shape change: string-returning tools no longer duplicate their payload(
#271). 91 of the registered tools were emitting the same value twice, once as text content and again under an information-freestructuredContent.result. Dictionary-returning tools keep their structured schemas.If a client readsstructuredContent.resultfor a string-returning tool, switch it to the text content
- FastMCP dependency floor raised to 3.4.7(
#293), picking up upstream fixes for Azure scope fallback, deterministic transformed-tool schemas, trusted OAuth metadata/JWKS proxies, andprivate_key_jwtaudience validation

v1.10.0— A community bug-fix release driven by live reporter testing — thanks@khagyard,@zqian,@jonespm,@bruchris, and@SHIL0018(our second outside code contribution). Included a breakingsearch_canvas_toolsresponse-shape change.

- Breaking:search_canvas_toolsresponse shape v2(#281). The tool now actually searches the ~99 registered MCP tools alongside the TypeScript code-API files (it previously searched only the latter, so "peer review" found nothing despite ~10 peer-review tools existing). Responses carryschema_version: 2with labeledmcp_tools/code_execution_apisections; the old flattoolskey is gone. Full-detail code-API content is now also capped at 2,000 characters (#287)
- Students can find their peer reviews(
#275):get_my_peer_reviews_todogained a direct per-assignment lookup and a Planner-feed discovery path — the same data source Canvas's own student UI uses — validated against a real production payload from the reporter
- create_announcementfails safely on student tokens(
#283): Canvas silently downgrades the create to a regular discussion topic; the tool now pre-checks course permissions and refuses before creating anything, auto-deletes the unintended topic if a downgrade still slips through, and steers AI clients away from posting the content via discussion tools as a fallback
- Security:stricter URL validation (code-scanning fix), Docker base bumped topython:3.14-slim, CI actions updated

v1.9.0— Prompt-injection hardening (#239): Canvas-authored text arrives provenance-fenced as data-not-instructions; multi-recipient sends became two-step preview→confirm (breaking); write tools refuse fence markers; OSSF Scorecard published, CI actions SHA-pinned,.mcpbships SLSA provenance; npm wizard retired (#249). Eleven adversarial review rounds pre-merge

v1.8.0— Security-scan remediation: 11 of 12 findings fixed, three breaking (HTTPS-only Canvas URLs, stdio-only file transfer tools, no-overwrite downloads), a measured submissions authorization bypass closed centrally, CSV formula-injection protection, code execution fails closed, dependency floors raised (PR #251, #255)

v1.7.0— Correctness release from instructor bug reports: writes no longer report success when Canvas quietly did less than asked (#219–#221), Planner-API upcoming assignments (#222),check_enrollmentAMBIGUOUS answers (#199), wire-format fixes for pages/inbox (#207,#208), MCP-spec tool annotations (#204), CSV rubric format fix (#190), anonymization consolidated to the client layer (#179). Thanks@khagyardand@zqian

v1.6.0— Tier 1 student write tools behind an explicit allowlist (#170),get_my_enrollments/get_my_profile(#171), three-tier anonymization (#166,#179), rubric association fixes (#180,#181),execute_typescriptbecame opt-in (#178), ruff gating CI ([@w3lld1, PR #186)

…

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.