A local Model Context Protocol server for read-only D2L Brightspace academic data. It runs over stdio and is written in Go with mark3labs/mcp-go.
Important
D2L MCP is unofficial. It is not affiliated with or endorsed by D2L Corporation or any educational institution.
- Courses, identity, grades, assignments, quizzes, discussions, and announcements
- Calendar, due and overdue work, recent updates, and course snapshots
- Course-content browsing by root, table of contents, or module
- Individual and recursive downloads for course materials
- Assignment-attachment downloads
- Public SimpleSyllabus retrieval
- Browser-assisted Brightspace login and silent token refresh
- Typed MCP inputs, structured outputs, guidance resources, and workflow prompts
Brightspace academic access is GET-only. Authentication performs a token-exchange POST inside the user's authenticated browser session. Downloads write only to a managed local directory.
The project is pre-1.0 and currently targets behavioral compatibility with d2l-cli v0.2.2. Interfaces may change before v1.0, but tagged releases follow semantic versioning.
See docs/PARITY.md for the complete command mapping, deliberate MCP interface differences, and upstream source citations.
Download the archive for your platform from GitHub Releases:
darwin_arm64for Apple silicondarwin_amd64for Intel Macslinux_arm64orlinux_amd64for Linuxwindows_arm64orwindows_amd64for Windows
Each release includes platform archives and checksums.txt. Verify the archive checksum, extract the binary, and place d2l-mcp (or d2l-mcp.exe) somewhere on PATH.
Release binaries are not currently code-signed or notarized. Your operating system may require confirmation before first launch.
Building requires Go 1.25.5 or newer:
git clone https://github.com/RobertLMcCrary/D2L-MCP.git
cd D2L-MCP
go build -trimpath -o d2l-mcp ./cmd/d2l-mcpConfirm the installation:
./d2l-mcp version
./d2l-mcp --helpSource builds report dev; tagged release binaries report their release version. Move the built executable to a directory on PATH before continuing.
Runtime requirements:
- A Brightspace account
- Google Chrome, Chromium, or another Chrome-compatible executable discoverable by
chromedp
Use a known school preset:
d2l-mcp setup --school ksu
d2l-mcp setup --school gsuOr configure any Brightspace host:
d2l-mcp setup \
--host https://your-school.brightspace.example \
--syllabus-host https://your-school.simplesyllabus.comAuthenticate and verify the setup:
d2l-mcp login
d2l-mcp doctorState remains compatible with d2l-cli under ~/.d2l/:
config.jsontoken.jsonbrowser_profile/
Tokens and browser state are secrets. Never commit or share them.
Configure your MCP client with the binary's absolute path:
{
"mcpServers": {
"d2l": {
"command": "/absolute/path/to/d2l-mcp",
"args": ["serve"]
}
}
}The server uses stdout exclusively for MCP JSON-RPC. Diagnostics and command errors go to stderr.
Read-only query tools:
d2l_statusd2l_whoamid2l_list_coursesd2l_get_gradesd2l_list_assignmentsd2l_list_quizzesd2l_get_discussionsd2l_get_contentd2l_get_announcementsd2l_get_calendard2l_get_dued2l_get_overdued2l_get_updatesd2l_get_syllabusd2l_get_snapshot
Local-writing download tools:
d2l_download_assignmentd2l_download_moduled2l_download_topic
Downloads default to ~/.d2l/downloads. Set D2L_DOWNLOAD_DIR or download_dir in config.json to use another managed root. Existing files are never overwritten.
- Academic API calls are GET-only.
- HTTPS Brightspace hosts are required.
- Bearer credentials are not forwarded across host redirects.
- Tokens use mode
0600; state directories use0700on supported systems. - Browser refresh is cancellable and serialized with a lock file.
- Requests have deadlines, bounded pagination, and context-aware rate-limit retries.
- Downloads have a 256 MiB per-file limit and reject traversal, symlink roots, and overwrites.
- LMS text and files are treated as untrusted data, not agent instructions.
Read SECURITY.md before reporting a vulnerability or sharing diagnostics.
go test ./...
go test -race ./...
go vet ./...
go test ./internal/d2l -run '^$' -fuzz FuzzSafeFilename -fuzztime=10sValidate the complete cross-platform release locally with GoReleaser:
goreleaser check
goreleaser release --snapshot --cleanThe test suite covers fixture-backed API behavior, pagination, retries, cancellation, authentication-state compatibility, path security, in-process MCP negotiation, and a true stdio subprocess.
Contributions are welcome. Read CONTRIBUTING.md for safety requirements, development checks, and fixture-sanitization rules.
D2L MCP is a native Go adaptation of Aaryan Kapoor's d2l-cli. Aaryan designed and implemented the original CLI, endpoint coverage, authentication flow, course resolution, SimpleSyllabus integration, downloads, snapshot workflow, and agent guidance that made this port possible.
Detailed derivation and source citations are preserved in NOTICE and docs/PARITY.md.
D2L MCP and its upstream-derived portions are available under the MIT License. The original d2l-cli copyright and permission notice are retained.