canvas-session-mcp
GitHub

Let your AI read Canvas.
No access token.

让 AI 直接读你的 Canvas,
不用 Access Token。

An MCP server for Claude, Cursor, Codex and other assistants. Sign in once with your school's normal login, then ask about deadlines, lecture slides, assignments and grades.

给 Claude、Cursor、Codex 等 AI 用的 MCP 服务器。用学校的正常登录方式登录一次,之后就能直接问 AI 截止日期、讲义、作业要求和成绩。

No token needed不需要 token Read-only只读 Runs on your computer数据留在本机 MIT

One command sets everything up:

一条命令装好所有东西:

npx -y https://github.com/CorCvusRamboChen/canvas-session-mcp/archive/refs/heads/main.tar.gz setup

Why

为什么做这个

Tokens are often switched off

很多学校关掉了 token

Most Canvas integrations need a personal access token. Many universities no longer let students create one.

现有的 Canvas 工具基本都要个人 Access Token,但很多大学已经不让学生自己生成了。

Your login already works

你的登录本来就能用

The Canvas website calls its own API with your session. This tool does the same, from a browser profile on your computer.

Canvas 网页版本身就是用你的登录会话调 API 的,这个工具也这么做,登录态保存在你电脑上的浏览器 profile 里。

Safe by design

设计上就是安全的

Only GET requests: it cannot submit, post or change anything. Nothing leaves your machine except requests to your school's Canvas.

只发 GET 请求,不会提交、发帖或修改任何东西;除了访问学校的 Canvas,不会把数据发到任何地方。

What it looks like

用起来是这样

Give me the Assignment 3 questions for Linear Algebra.
把线性代数 Assignment 3 的题目给我。
canvas_list_files(course_id: MATH1012) → canvas_read_file(file_id: 1234567) The Files tab is hidden in this course, and the sheet was uploaded as “Assing3-26.pdf” (sic), attached to the 11 Sep announcement. It has 3 questions (9 parts): subspaces, linear dependence and column space, and the matrix of a linear transformation. Due 20 Sep, worth 3.75%. Want them one by one? 这门课的 Files 页面是隐藏的,题目文件被上传成了 “Assing3-26.pdf”(文件名拼错了),挂在 9 月 11 日那条公告的附件里。一共 3 题 9 小问:子空间、线性相关与列空间、线性变换的矩阵。9 月 20 日截止,占 3.75%。要一题一题看吗?
What else is due this week? Have I submitted?
这周还有什么要交?我交了没?
canvas_upcoming(days: 7) Assignment 4 — Sunday 11:59pm, not submitted. Week 9 quiz — Monday, not submitted. Assessed quiz — Wednesday. Want me to save all of this course's files to your Canvas folder? Assignment 4:周日 23:59,还没交。Week 9 quiz:周一,还没交。计分测验:周三。要不要把这门课的文件都存到你的 Canvas 文件夹?

Based on a real conversation; course codes and IDs changed.

根据一次真实对话整理,课程代码和 id 已替换。

Real requests from one semester

一个学期里真实问过的

“Download everything for this course”

“把这门课的文件全部下载下来”

12 files found across modules, announcements and assignment pages; 8 unique PDFs saved into Canvas/MATH1012/…, questions and solutions. Byte-identical re-uploads were kept once. Running it again took 2 s.

从模块、公告、作业页面里找到 12 个文件,存下 8 份不重复的 PDF 到 Canvas/MATH1012/…,题目和答案都有。字节完全相同的重复上传只存一份,再跑一次只要 2 秒。

“I had an extension — what's still outstanding?”

“延期之后,我还有哪些没交?”

Overdue and missing work next to what's coming up, from every course at once.

所有课程里逾期没交的和接下来要交的,一次看全。

“Every marking criterion for my lab report”

“lab report 的所有评分要求”

Instructions, the rubric and the linked brief and sample-essay PDFs, read together and turned into one checklist.

作业说明、评分标准,以及链接的 brief 和 sample essay PDF 一起读完,整理成一张清单。

“Check my SQL against the spec”

“对照要求检查我的 SQL”

The assignment PDF is read as text, so column order, banned keywords and formatting rules can be checked line by line.

作业说明 PDF 转成文字,列的顺序、禁止使用的语法、格式规范都能逐条检查。

Get started

开始使用

You need Node.js 20+ and Chrome or Edge.

需要 Node.js 20+,以及 Chrome 或 Edge。

1

Run setup

运行 setup

npx -y https://github.com/CorCvusRamboChen/canvas-session-mcp/archive/refs/heads/main.tar.gz setup
2

Answer three questions

回答三个问题

Canvas address (e.g. https://canvas.lms.unimelb.edu.au) · where to save course files (default Documents/Canvas, any folder works) · sign in in the window that opens. SSO and MFA work as usual; the window closes by itself.

Canvas 地址(如 https://canvas.lms.unimelb.edu.au)· 课件存到哪里(默认 文档/Canvas,可以换成任何文件夹)· 在弹出的窗口里登录。SSO、MFA 照常,登录完窗口自动关闭。

3

Your AI apps are connected

自动接入你的 AI

Setup finds Claude Desktop, Claude Code, Cursor, Windsurf and Codex and asks before connecting each one. Existing settings are kept and backed up. Restart the app and ask “What's due this week on Canvas?”

setup 会找到 Claude Desktop、Claude Code、Cursor、Windsurf、Codex,每个都先问你再接入。原有配置会保留并备份。重启应用后问一句:“Canvas 上这周有什么要交?”

Manual configuration手动配置
claude mcp add canvas -- npx -y https://github.com/CorCvusRamboChen/canvas-session-mcp/archive/refs/heads/main.tar.gz

Staying signed in — measured

持续登录(实测)

On a real university Canvas with Okta SSO behind a Cloudflare bot check.

在一所大学的真实 Canvas 上测得(Okta SSO,前面有 Cloudflare 人机验证)。

Normal use平时使用Saved cookies go straight to Canvas, no browser直接带保存的 cookie 访问,不开浏览器0.7 s
Cookie lifetimecookie 能用多久Checked every 15 min with no renewal: still accepted after 2 h 6 min (longer idle gaps not measured yet)每 15 分钟检查一次、全程不续期,2 小时 6 分钟后仍然有效(长时间完全闲置还没测)≥ 2 h
Canvas session expiredCanvas 会话过期A sign-in window opens at your SSO, finishes without typing, and closes弹出窗口去学校 SSO,什么都不用输就自动完成并关闭4–10 s
SSO expired tooSSO 也过期The window waits for you to sign in, as any browser would窗口留着等你登录,和平时用浏览器一样—

Bot checks are never automated or bypassed. Where one blocks a hidden renewal, a visible window is used instead. Set CANVAS_MCP_RENEW=hidden if you never want a pop-up.

本工具从不自动完成或绕过任何人机验证。如果后台续期被人机验证拦下,就改用可见窗口。完全不想要弹窗的话,设置 CANVAS_MCP_RENEW=hidden。

How it was verified

怎么验证的

18

automated tests against a fake Canvas and a real MCP client, including a check that only GET requests are ever sent

个自动测试:假的 Canvas 服务器加真实的 MCP 客户端,其中一项专门确认只会发 GET 请求

60/60

live checks on a real account across 13 courses: modules, files, assignments, pages, announcements, grades, inbox, calendar, PDF to text

项真机检查:真实账号、13 门课,覆盖模块、文件、作业、页面、公告、成绩、站内信、日历和 PDF 转文字

4

problems found by live testing and fixed: attachments on announcements, last term counted as current, timetable noise, duplicate uploads

个真机测试中发现并修好的问题:公告附件漏抓、上学期的课算成当前、课表事件刷屏、重复上传存两份

Tools

工具

Tool工具What it does作用
canvas_upcomingEverything due soon across all courses, with submission status所有课近期要交的东西,以及是否已提交
canvas_list_coursesYour courses and terms课程列表
canvas_get_assignmentFull instructions, rubric, your submission and score作业完整要求、评分标准、提交状态和分数
canvas_read_fileLecture slides, PDFs and Word documents as text讲义、PDF、Word 转成文字
canvas_save_course_filesSave a whole course into your folder; unchanged files skipped, duplicates kept once把整门课存到你的文件夹,没变的跳过,重复的只存一份
canvas_list_modulesCourse structure: modules, pages, files课程模块结构
canvas_list_announcementsRecent announcements最近的公告
canvas_gradesGrades, scores and teacher comments成绩和老师评语
canvas_get_discussionDiscussion threads and replies讨论区帖子和回复
canvas_inboxCanvas Inbox messagesCanvas 站内信
canvas_calendarClasses, exams, consultation times课程、考试、答疑时间
canvas_api_getAny other Canvas API endpoint, read-only其他任意 Canvas API(只读)

Plus canvas_list_assignments, canvas_get_page, canvas_list_files, canvas_list_discussions and canvas_whoami.

另外还有 canvas_list_assignments、canvas_get_page、canvas_list_files、canvas_list_discussions、canvas_whoami。

How it works

原理

1 · login

Opens Chrome/Edge with its own profile and waits until Canvas recognises you. Remembers your SSO entry point.

用专用 profile 打开 Chrome/Edge,等 Canvas 认出你,并记下你学校的 SSO 入口。

2 · refresh

Session cookies are kept locally. If Canvas ever rejects them, a browser renews the session through your SSO — hidden when possible, otherwise a window that closes itself.

会话 cookie 保存在本机。Canvas 不认了就通过学校 SSO 自动续期:能在后台完成就后台完成,不行就弹一个会自己关闭的窗口。

3 · read

Requests go straight to /api/v1 with your session cookie, just like the Canvas website does.

带着会话 cookie 直接请求 /api/v1,跟 Canvas 网页版一样。

Please use responsibly. This is an unofficial tool, not affiliated with or endorsed by Instructure. It only reads what you can already see in your browser. Check your institution's IT policy, keep course materials private, and follow your subjects' rules on AI use. 使用须知:本项目是非官方工具,与 Instructure 无关,只读取你在浏览器里本来就能看到的内容。请遵守学校的 IT 政策,不要外传课程资料,并遵守各科关于 AI 使用的规定。