
Security News
White House Authorizes Private Companies to Conduct Offensive Cyber Operations
A new federal program will let vetted U.S. cybersecurity firms help investigate and disrupt foreign cybercrime groups under government direction.
canvas-api-mcp
Advanced tools
Ask your AI what's due and it reads the answer straight from Canvas:
real deadlines, real submission status, no copying anything across.
An MCP server for Canvas LMS. 16 curated tools for everyday student work, plus a gateway that reaches every endpoint your Canvas instance exposes.
📖 Documentation: mcp.johannsenlum.com/canvas-lms · install guide · tool reference · skills · compliance
Personal-use software. Canvas's API Policy requires OAuth for applications used by multiple people, and Canvas OAuth cannot be implemented safely by locally installed software (no PKCE, and
client_secretcannot be shipped in a package). Use this with your own token on your own account. See Compliance.
Real prompts, and which tool answers them.
You: What's due this week? Claude: (calls
whats_due): You have 3 things due: Problem Set 4 (Thu, CS3230), a discussion reply (Fri, IS4302), and the Milestone 2 report (Sun, EE2211).
You: How am I doing in my databases course, and what's on the syllabus for week 6? Claude: (calls
my_grades, thenget_syllabus, thencourse_contentfor the week 6 module): You're at 87% overall. Week 6 covers normalization and has a reading plus a lab file due Friday.
You: Summarize the PDF lecture notes for lecture 8 and pull up my submission for the essay so I can see the feedback. Claude: (calls
list_files+read_filefor the PDF, thenmy_submissionfor the essay): ...
You: Reply to the "Project teams" discussion and say I'm free after 3pm for the group meeting. Claude: (calls
post_discussion_reply✏️): Posted to the thread.
You: Has Canvas ever given me quiz statistics broken down by question, across the whole semester? Claude: (calls
search_canvas_apito find the right endpoint, thencanvas_requestto call it): ...
The last example is the point of the gateway tools: if an endpoint exists on your
Canvas instance, search_canvas_api can find it and canvas_request can call it,
even though only 16 tools are hand-curated.
Python 3.11+
A Canvas personal access token. Your institution must allow students to create them: check Canvas → Account → Settings → Approved Integrations for a "+ New access token" button. Full walkthrough with screenshots: mcp.johannsenlum.com/canvas-lms/install.
Note that the token expires. Since Instructure's October 2025 security update,
accounts holding only student roles must set an expiry no more than 120 days out,
and institutions often cap it lower (NUS allows 90). Write the date down: an expired
token makes every tool return 401 at once, which looks like a broken install rather
than a credential that simply ran out.
canvas-api-mcp is published on PyPI. Run it with:
uvx canvas-api-mcp
Install from source (contributors / unreleased main). Not part of the
normal install path above, only needed if you want the latest unreleased
code instead of the published PyPI release:
uvx --from git+https://github.com/JohannsenLum/canvas-api-mcp canvas-api-mcp
Or run from a local clone:
git clone https://github.com/JohannsenLum/canvas-api-mcp
cd canvas-api-mcp
uv sync
One-click deeplinks exist for Cursor, VS Code, and LM Studio only. No other
client has a documented install-link format. These prefill the config below but
still need CANVAS_BASE_URL and CANVAS_TOKEN filled in afterward.
Your token stays on your machine, in your own config file. It is never transmitted anywhere except directly to your Canvas instance.
| Client | Deeplink? |
|---|---|
| Claude Code | no |
| Claude Desktop | no |
| Cursor | yes, above |
| VS Code | yes, above |
| LM Studio | yes, above |
| Zed | no |
| Windsurf | no (Windsurf only resolves servers in its own registry) |
~/.claude.json{
"mcpServers": {
"canvas": {
"command": "uvx",
"args": ["canvas-api-mcp"],
"env": {
"CANVAS_BASE_URL": "https://canvas.yourschool.edu",
"CANVAS_TOKEN": "your-token-here"
}
}
}
}
claude_desktop_config.jsonmacOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json
No one-click install exists for Claude Desktop (it installs .mcpb bundles, not
deeplinks). Copy this JSON in via Settings → Developer → Edit Config:
{
"mcpServers": {
"canvas": {
"command": "uvx",
"args": ["canvas-api-mcp"],
"env": {
"CANVAS_BASE_URL": "https://canvas.yourschool.edu",
"CANVAS_TOKEN": "your-token-here"
}
}
}
}
~/.cursor/mcp.jsonFallback for the button above, or if you'd rather paste it directly:
{
"mcpServers": {
"canvas": {
"command": "uvx",
"args": ["canvas-api-mcp"],
"env": {
"CANVAS_BASE_URL": "https://canvas.yourschool.edu",
"CANVAS_TOKEN": "your-token-here"
}
}
}
}
.vscode/mcp.jsonFallback for the button above, or if you'd rather paste it directly. Note VS
Code uses a servers key, not mcpServers:
{
"servers": {
"canvas": {
"type": "stdio",
"command": "uvx",
"args": ["canvas-api-mcp"],
"env": {
"CANVAS_BASE_URL": "https://canvas.yourschool.edu",
"CANVAS_TOKEN": "your-token-here"
}
}
}
}
mcp.json (Program → Install → Edit mcp.json)Fallback for the button above, or if you'd rather paste it directly:
{
"mcpServers": {
"canvas": {
"command": "uvx",
"args": ["canvas-api-mcp"],
"env": {
"CANVAS_BASE_URL": "https://canvas.yourschool.edu",
"CANVAS_TOKEN": "your-token-here"
}
}
}
}
settings.jsonNo deeplink exists for Zed. Add this under context_servers in your Zed
settings:
{
"context_servers": {
"canvas": {
"source": "custom",
"command": "uvx",
"args": ["canvas-api-mcp"],
"env": {
"CANVAS_BASE_URL": "https://canvas.yourschool.edu",
"CANVAS_TOKEN": "your-token-here"
}
}
}
}
~/.codeium/windsurf/mcp_config.jsonNo deeplink exists for Windsurf. It only resolves servers from its own registry, so this has to be pasted in manually via Windsurf Settings → MCP Servers → Edit raw config:
{
"mcpServers": {
"canvas": {
"command": "uvx",
"args": ["canvas-api-mcp"],
"env": {
"CANVAS_BASE_URL": "https://canvas.yourschool.edu",
"CANVAS_TOKEN": "your-token-here"
}
}
}
}
| Tool | What it does |
|---|---|
whoami | Identity and your role in each course |
get_calendar_feed_url | Your private calendar .ics link (only when you ask for it) |
my_courses | Active courses with code, term, role |
whats_due | Everything due, soonest first |
my_grades | Current score per course |
list_assignments | A course's assignments and submission state |
get_assignment | One assignment in full, with rubric |
my_submission | Your submission, score, and feedback |
submit_assignment ✏️ | Submit work |
course_announcements | Recent announcements |
course_content | Modules and their contents |
list_files | Files in a course |
read_file | Extract text from PDF/DOCX/PPTX/text |
get_page | A Canvas wiki page by slug |
get_syllabus | A course's syllabus |
read_discussion | Topics, or one topic's replies |
post_discussion_reply ✏️ | Post to a discussion |
search_canvas_api | Find any endpoint by keyword (gateway) |
canvas_request ✏️ | Execute any endpoint (gateway) |
✏️ writes to Canvas. That's 3 write tools total: submit_assignment,
post_discussion_reply, and canvas_request when called with a non-GET method
(GET calls through canvas_request are read-only).
search_canvas_api + canvas_request reach all ~1,116 endpoints your instance
exposes. What they may do is decided by Canvas from your token's permissions: a
teacher token unlocks educator endpoints with no change to this server.
week_ahead, study_pack, grade_check.
canvas://me, canvas://courses, canvas://api/catalog.
If your client supports the skills convention:
npx skills add JohannsenLum/canvas-api-mcp
Works with any Canvas instance: set CANVAS_BASE_URL. The catalog of ~1,116
endpoints ships inside the package at
canvas_api_mcp/data/catalog.json. To match your deployment's exact feature
set, regenerate it:
python scripts/build_catalog.py https://canvas.yourschool.edu -o data/catalog.json
submit_assignment can submit anything, including
AI-generated work. Submitting work that is not your own breaches the academic
integrity rules of essentially every institution, and Canvas's API Policy
explicitly prohibits use that violates them. That is on you.read_file fetches materials for your own study. Do not
redistribute them.uv sync
uv run pytest -v
# Live tests against your real account (read-only)
CANVAS_LIVE_TESTS=1 uv run pytest tests/test_live.py -v
Environment variables: CANVAS_BASE_URL, CANVAS_TOKEN, optional
CANVAS_MAX_PAGES (default 10) and CANVAS_TIMEOUT (seconds, default 30).
See env.template.
Issues and pull requests are welcome: see CONTRIBUTING.md for setup, the architectural rules worth knowing before you change anything, and the bar for adding a new curated tool.
Found a security problem? Do not open a public issue. See SECURITY.md for private reporting, particularly important here, since this project handles password-equivalent Canvas tokens.
Changes are recorded in CHANGELOG.md.
MIT © 2026 Johannsen Lum.
Use it, change it, redistribute it, build something commercial on it: the only condition is that you keep the copyright notice and licence text. It comes with no warranty of any kind.
Contributions are accepted under the same licence.
FAQs
MCP server for Canvas LMS: student tools plus full API gateway
We found that canvas-api-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
A new federal program will let vetted U.S. cybersecurity firms help investigate and disrupt foreign cybercrime groups under government direction.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.