CanvasCAUTION
Canvas LMS MCP server — up to 102 tools and 8 agent skills for students & educators. Works with Claude, Cursor, Codex, and 40+ agents.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/MIT) [](https://skills.sh)
MCP server for Canvas LMS with up to 103 tools and 8 agent skills. Designed for Claude Desktop, Cursor, Codex, Windsurf, and 40+ other agents; setup and capabilities vary by client.
Quick Start
1. Install the MCP server (everything else, including the skills, needs it running):
- Claude Desktop: download
canvas-mcp.mcpbfrom the latest release and double-click it. It prompts for your Canvas URL and token; no terminal needed. Details. - Cursor, Zed, Windsurf, Continue, Claude Code and other clients:
pip installinto a virtualenv, add your token to.env, and point your client at thecanvas-mcp-serverbinary. Local Installation has the per-client config blocks.
2. Verify: canvas-mcp-server --test should report a successful Canvas connection. Then restart your client.
3. Optional: add the workflow skills. These teach your agent the multi-step recipes (weekly plan, morning check, bulk grading, peer review, course QC) on top of the tools:
npx skills add vishalsachdev/canvas-mcp
See Agent Skills for the list. If your agent is Claude Code, the same recipes are also available as slash commands.
For AI Agents
6854fde7094cOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add canvas-mcp -- None canvas-mcp==1.13.0
Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
brand_new_tool | read | return |
Trust audit
CAUTIONgrade B · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
console.log(`✓ ~/.claude.json canvas X-Canvas-Token header updated -> ${mask(t)} (backup: ~/.claude.json.bak-${stamp})`);proxy_pass http://127.0.0.1:8819;
stripped = text.lstrip(" \n\t\r ").mcpbignore
.assetsignore
.nojekyll
return importlib.import_module(MODULE_NAME)
module = importlib.import_module(self.module)
import { fetchAllPaginated } from "../../client.js";import { canvasPost } from "../../client.js";import { canvasGet } from "../../client.js";import { fetchAllPaginated } from "../../client.js";import { createBatchRunner } from "../../batching.js";(b"x-canvas-url", b"http://169.254.169.254/latest/meta-data/"),
initializeCanvasClient(`http://127.0.0.1:${address.port}`, 'synthetic');initializeCanvasClient(`http://127.0.0.1:${address.port}`, 'synthetic');"http://127.0.0.1:3000",
"HTTPS_PROXY": "http://127.0.0.1:9", "https_proxy": "http://127.0.0.1:9"}
payload = json.loads(base64.b64decode(raw))
content = base64.b64decode(encoded, validate=True)
JPEG_BYTES = bytes.fromhex(
@types/node, tsx, typescript
share a token ([issue 318](https://github.com/vishalsachdev/canvas-mcp/issues/318)).
- **Covered the email-bearing keys the anonymizer missed:** `primary_email`, `unconfirmed_email`, and `contact_info` are now pseudonymised; `pronunciation` is nulled; `communication_channels[].address
**Confirmed by reading the code, higher confidence than the others here** — `student_tools.py:323-324` and `:337` both silently swallow any non-list response from Canvas: assignment-listing errors jus
Gates applied: no_behavioural_pass.
6854fde7094cfull audit observations/trust-audit/mcp-server/vishalsachdev__canvas.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 6854fde7094c | CAUTION | B | 80 | first audit |
Questions
What is the Canvas MCP server?
Canvas LMS MCP server — up to 102 tools and 8 agent skills for students & educators. Works with Claude, Cursor, Codex, and 40+ agents.
What tools does Canvas expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Canvas safe to connect to an agent?
With care. The audit graded it B (80/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Canvas need?
It reads ACCESS_TOKEN_SECRET, CANVAS_API_TOKEN, GH_TOKEN, GITHUB_TOKEN, MCP_ACCESS_KEYS and NEW_CANVAS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Canvas run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as canvas-mcp-code-api at 1.0.6.
How current is this page?
The grade is for one exact copy of the source (6854fde7094c), read on 2026-10-06. The repository is watched and re-audited when it changes.