Skip to main content

canvas-api-mcp

Never miss an assignment deadline again.

Ask your AI what's due and it reads the answer straight from Canvas:
real deadlines, real submission status, no copying anything across.

An MCP server for Canvas LMS. 16 curated tools for everyday student work, plus a gateway that reaches every endpoint your Canvas instance exposes.

Terminal. Question one: 'what mods am I taking this sem?' Answered instantly by the curated my_courses tool (CS3230, CS2040S, MA2001, GEA1000). Question two: 'what groups am I in?' No curated tool covers it, so search_canvas_api finds GET /v1/users/self/groups among 1,116 Canvas endpoints and canvas_request executes it. 18 tools · 1,116 endpoints reachable · 149 tests · MIT.

📖 Documentation: mcp.johannsenlum.com/canvas-lms · install guide · tool reference · skills · compliance

PyPI Python 3.11+ License: MIT MCP Registry GitHub stars

Personal-use software. Canvas's API Policy requires OAuth for applications used by multiple people, and Canvas OAuth cannot be implemented safely by locally installed software (no PKCE, and client_secret cannot be shipped in a package). Use this with your own token on your own account. See Compliance.

What you can ask it

Real prompts, and which tool answers them.

You: What's due this week? Claude: (calls whats_due): You have 3 things due: Problem Set 4 (Thu, CS3230), a discussion reply (Fri, IS4302), and the Milestone 2 report (Sun, EE2211).

You: How am I doing in my databases course, and what's on the syllabus for week 6? Claude: (calls my_grades, then get_syllabus, then course_content for the week 6 module): You're at 87% overall. Week 6 covers normalization and has a reading plus a lab file due Friday.

You: Summarize the PDF lecture notes for lecture 8 and pull up my submission for the essay so I can see the feedback. Claude: (calls list_files + read_file for the PDF, then my_submission for the essay): ...

You: Reply to the "Project teams" discussion and say I'm free after 3pm for the group meeting. Claude: (calls post_discussion_reply ✏️): Posted to the thread.

You: Has Canvas ever given me quiz statistics broken down by question, across the whole semester? Claude: (calls search_canvas_api to find the right endpoint, then canvas_request to call it): ...

The last example is the point of the gateway tools: if an endpoint exists on your Canvas instance, search_canvas_api can find it and canvas_request can call it, even though only 16 tools are hand-curated.

Install

Prerequisites

  • Python 3.11+
  • A Canvas personal access token. Your institution must allow students to create them: check Canvas → Account → Settings → Approved Integrations for a "+ New access token" button. Full walkthrough with screenshots: mcp.johannsenlum.com/canvas-lms/install.

Running the server

canvas-api-mcp is published on PyPI. Run it with:

uvx canvas-api-mcp

Install from source (contributors / unreleased main). Not part of the normal install path above, only needed if you want the latest unreleased code instead of the published PyPI release:

uvx --from git+https://github.com/JohannsenLum/canvas-api-mcp canvas-api-mcp

Or run from a local clone:

git clone https://github.com/JohannsenLum/canvas-api-mcp
cd canvas-api-mcp
uv sync

Quick install (one-click)

One-click deeplinks exist for Cursor, VS Code, and LM Studio only. No other client has a documented install-link format. These prefill the config below but still need CANVAS_BASE_URL and CANVAS_TOKEN filled in afterward.

Add to Cursor Add to VS Code Add to LM Studio

All clients (manual config)

Your token stays on your machine, in your own config file. It is never transmitted anywhere except directly to your Canvas instance.

Client Deeplink?
Claude Code no
Claude Desktop no
Cursor yes, above
VS Code yes, above
LM Studio yes, above
Zed no
Windsurf no (Windsurf only resolves servers in its own registry)

Claude Code: ~/.claude.json
{
  "mcpServers": {
    "canvas": {
      "command": "uvx",
      "args": ["canvas-api-mcp"],
      "env": {
        "CANVAS_BASE_URL": "https://canvas.yourschool.edu",
        "CANVAS_TOKEN": "your-token-here"
      }
    }
  }
}

Claude Desktop: claude_desktop_config.json

macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json

No one-click install exists for Claude Desktop (it installs .mcpb bundles, not deeplinks). Copy this JSON in via Settings → Developer → Edit Config:

{
  "mcpServers": {
    "canvas": {
      "command": "uvx",
      "args": ["canvas-api-mcp"],
      "env": {
        "CANVAS_BASE_URL": "https://canvas.yourschool.edu",
        "CANVAS_TOKEN": "your-token-here"
      }
    }
  }
}

Cursor: ~/.cursor/mcp.json

Fallback for the button above, or if you'd rather paste it directly:

{
  "mcpServers": {
    "canvas": {
      "command": "uvx",
      "args": ["canvas-api-mcp"],
      "env": {
        "CANVAS_BASE_URL": "https://canvas.yourschool.edu",
        "CANVAS_TOKEN": "your-token-here"
      }
    }
  }
}

VS Code: .vscode/mcp.json

Fallback for the button above, or if you'd rather paste it directly. Note VS Code uses a servers key, not mcpServers:

{
  "servers": {
    "canvas": {
      "type": "stdio",
      "command": "uvx",
      "args": ["canvas-api-mcp"],
      "env": {
        "CANVAS_BASE_URL": "https://canvas.yourschool.edu",
        "CANVAS_TOKEN": "your-token-here"
      }
    }
  }
}

LM Studio: mcp.json (Program → Install → Edit mcp.json)

Fallback for the button above, or if you'd rather paste it directly:

{
  "mcpServers": {
    "canvas": {
      "command": "uvx",
      "args": ["canvas-api-mcp"],
      "env": {
        "CANVAS_BASE_URL": "https://canvas.yourschool.edu",
        "CANVAS_TOKEN": "your-token-here"
      }
    }
  }
}

Zed: settings.json

No deeplink exists for Zed. Add this under context_servers in your Zed settings:

{
  "context_servers": {
    "canvas": {
      "source": "custom",
      "command": "uvx",
      "args": ["canvas-api-mcp"],
      "env": {
        "CANVAS_BASE_URL": "https://canvas.yourschool.edu",
        "CANVAS_TOKEN": "your-token-here"
      }
    }
  }
}

Windsurf: ~/.codeium/windsurf/mcp_config.json

No deeplink exists for Windsurf. It only resolves servers from its own registry, so this has to be pasted in manually via Windsurf Settings → MCP Servers → Edit raw config:

{
  "mcpServers": {
    "canvas": {
      "command": "uvx",
      "args": ["canvas-api-mcp"],
      "env": {
        "CANVAS_BASE_URL": "https://canvas.yourschool.edu",
        "CANVAS_TOKEN": "your-token-here"
      }
    }
  }
}

Tools

Tool What it does
whoami Identity and your role in each course
get_calendar_feed_url Your private calendar .ics link (only when you ask for it)
my_courses Active courses with code, term, role
whats_due Everything due, soonest first
my_grades Current score per course
list_assignments A course's assignments and submission state
get_assignment One assignment in full, with rubric
my_submission Your submission, score, and feedback
submit_assignment ✏️ Submit work
course_announcements Recent announcements
course_content Modules and their contents
list_files Files in a course
read_file Extract text from PDF/DOCX/PPTX/text
get_page A Canvas wiki page by slug
get_syllabus A course's syllabus
read_discussion Topics, or one topic's replies
post_discussion_reply ✏️ Post to a discussion
search_canvas_api Find any endpoint by keyword (gateway)
canvas_request ✏️ Execute any endpoint (gateway)

✏️ writes to Canvas. That's 3 write tools total: submit_assignment, post_discussion_reply, and canvas_request when called with a non-GET method (GET calls through canvas_request are read-only).

search_canvas_api + canvas_request reach all ~1,116 endpoints your instance exposes. What they may do is decided by Canvas from your token's permissions: a teacher token unlocks educator endpoints with no change to this server.

Prompts

week_ahead, study_pack, grade_check.

Resources

canvas://me, canvas://courses, canvas://api/catalog.

Skills

If your client supports the skills convention:

npx skills add JohannsenLum/canvas-api-mcp

Other institutions

Works with any Canvas instance: set CANVAS_BASE_URL. The catalog of ~1,116 endpoints ships inside the package at canvas_api_mcp/data/catalog.json. To match your deployment's exact feature set, regenerate it:

python scripts/build_catalog.py https://canvas.yourschool.edu -o data/catalog.json

Compliance

  • Academic integrity. submit_assignment can submit anything, including AI-generated work. Submitting work that is not your own breaches the academic integrity rules of essentially every institution, and Canvas's API Policy explicitly prohibits use that violates them. That is on you.
  • Rate limiting. The client throttles against Canvas's published quota. Do not remove it: overloading the API is prohibited.
  • Course material. read_file fetches materials for your own study. Do not redistribute them.
  • Your token is password-equivalent. It can read your grades and submit work as you. Set an expiry. Never commit it.
  • Personal-use scope. Phase 1 targets a single student using their own token. There are no curated educator tools; Canvas's OAuth flow has no PKCE, so this locally-installed server cannot implement the multi-user OAuth that Canvas's API Policy requires for anything broader. Do not repackage this as a multi-tenant service.

Development

uv sync
uv run pytest -v

# Live tests against your real account (read-only)
CANVAS_LIVE_TESTS=1 uv run pytest tests/test_live.py -v

Environment variables: CANVAS_BASE_URL, CANVAS_TOKEN, optional CANVAS_MAX_PAGES (default 10) and CANVAS_TIMEOUT (seconds, default 30). See env.template.

Contributing

Issues and pull requests are welcome: see CONTRIBUTING.md for setup, the architectural rules worth knowing before you change anything, and the bar for adding a new curated tool.

Found a security problem? Do not open a public issue. See SECURITY.md for private reporting, particularly important here, since this project handles password-equivalent Canvas tokens.

Changes are recorded in CHANGELOG.md.

Licence

MIT © 2026 Johannsen Lum.

Use it, change it, redistribute it, build something commercial on it: the only condition is that you keep the copyright notice and licence text. It comes with no warranty of any kind.

Contributions are accepted under the same licence.

Release files for canvas-api-mcp 0.0.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for canvas-api-mcp 0.0.5
File Size Uploaded
canvas_api_mcp-0.0.5.tar.gz 214.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for canvas-api-mcp 0.0.5
File Interpreter ABI Platform
canvas_api_mcp-0.0.5-py3-none-any.whl Python 3 none any Details

Total release size: 286.4 kB

Release files / canvas_api_mcp-0.0.5.tar.gz

Download URL canvas_api_mcp-0.0.5.tar.gz
Size 214.8 kB
Tags Source
SHA-256 checksum
How to use checksums
00ed5c394ff7717c33ea6463bf0cdc9a3e0c23488f7561223efce0b80113640b
BLAKE2b-256 checksum
How to use checksums
3a999f953e34fde2b399f67c2f5028b8c74d1df332ae1cf64a379e12570c4f86
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.

Transparency log

Release files / canvas_api_mcp-0.0.5-py3-none-any.whl

Download URL canvas_api_mcp-0.0.5-py3-none-any.whl
Size 71.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a8850e9ff3e9f82994f626d8daf2df566b8401a8af1d168a104ea6812f4edfaa
BLAKE2b-256 checksum
How to use checksums
320d12afba6c1e533eee4888b1ad649b33887d24a34df2fceed490c64ab76bf8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.

Transparency log

Release history Release notifications | RSS feed

1.1.0

2 release files

1.0.0

2 release files

This release

0.0.5 This release

2 release files

0.0.4

2 release files

0.0.3

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page