Canvas Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Canvas Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Python MCP server that exposes Canvas LMS academic data as callable tools for AI agents.
Model Context Protocol (MCP) is an open standard developed by Anthropic that defines how AI models communicate with external tools and data sources. Instead of embedding all logic inside a prompt, an AI agent discovers available tools at runtime and calls them by name with typed arguments — just like a function call.
MCP separates concerns cleanly:
AI Agent ──(tool call)──► MCP Server ──(HTTP)──► Canvas LMS API
◄──(result)──── ◄──(JSON)────The agent never knows or cares how Canvas authentication works; it only calls get_courses() and receives structured data.
canvas-mcp/
├── main.py # MCP server — registers tools and starts the server
├── canvas_client.py # Canvas API client — authentication, pagination, retries
├── requirements.txt
├── .env.example
└── README.mdcanvas_client.py — CanvasClientThe CanvasClient class centralises all HTTP communication with Canvas:
| Concern | Implementation |
|---|---|
| Authentication | Authorization: Bearer <token> header on every request |
| Pagination | Parses Link: <url>; rel="next" headers and accumulates pages automatically |
| Retries | urllib3.Retry with 3 attempts, exponential backoff, on 429/5xx responses |
| Error surface | All failures raise CanvasAPIError with the HTTP status and body |
main.py — FastMCP ServerUses FastMCP from the mcp package to register Python functions as MCP tools. Each tool:
CanvasClient methods.list[dict] or dict — always JSON-serialisable.Canvas uses Personal Access Tokens for API authentication. Once generated in Canvas Settings, the token is sent as a Bearer token on every request:
Authorization: Bearer <CANVAS_API_TOKEN>| MCP Tool | Canvas Endpoint |
|---|---|
get_courses | GET /api/v1/courses |
get_assignments | GET /api/v1/courses/{id}/assignments |
get_upcoming_events | GET /api/v1/planner/items |
get_course_grades | GET /api/v1/courses/{id}/enrollments |
get_course_summary | Combines courses + assignments + enrollments |
Canvas paginates results via Link response headers:
Link: <https://canvas.example.com/api/v1/courses?page=2>; rel="next"CanvasClient._get() follows these automatically, collecting every page into a single list before returning.
# 1. Clone / enter the project
cd canvas-mcp
# 2. Create and activate a virtual environment
python3 -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
# 3. Install dependencies
pip install -r requirements.txt
# 4. Configure environment variables
cp .env.example .env
# Edit .env with your Canvas URL and tokenCopy .env.example to .env and fill in your values:
# Your institution's Canvas domain
CANVAS_BASE_URL=https://canvas.example.edu
# Personal Access Token from Canvas Account → Settings → New Access Token
CANVAS_API_TOKEN=your_token_hereThe server validates both variables at startup and exits with a clear error message if either is missing.
# Activate venv if not already active
source .venv/bin/activate
# Start the server (communicates over stdio)
python main.pyThe server speaks the MCP stdio transport. To wire it into Claude Code, add it to your .claude/settings.json:
{
"mcpServers": {
"canvas": {
"command": "python",
"args": ["/absolute/path/to/canvas-mcp/main.py"],
"env": {
"CANVAS_BASE_URL": "https://canvas.example.edu",
"CANVAS_API_TOKEN": "your_token_here"
}
}
}
}Or set CANVAS_BASE_URL / CANVAS_API_TOKEN in your shell environment and omit the env block.
get_courses()Returns all active courses for the authenticated user.
get_assignments(course_id)Returns all assignments for the specified course.
get_upcoming_events()Returns upcoming items from the Canvas Planner (assignments, calendar events, etc.).
get_course_grades(course_id)Returns current score and letter grade for every enrolled student in the course.
get_course_summary(course_id)Aggregates course info, assignments, and grades into a single summary including:
List my available courses.Show assignments for course 123.What deadlines do I have this week?Show grade information for course 123.Generate a summary of course 123.CanvasAPIError and return {"error": "..."} rather than raising, so the agent can surface the message gracefully.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.