Skip to main content
Glama

eClass MCP Server

An MCP server for interacting with the Open eClass platform, with support for UoA's SSO authentication.

Features

  • SSO Authentication: Log in through UoA's CAS SSO system

  • Course Retrieval: Get list of enrolled courses

  • Session Management: Persistent sessions between tool calls

  • Status Checking: Verify authentication status

Related MCP server: mcpUPB

Quick Start

Prerequisites

  • Python 3.10+

  • uv (recommended) or pip

Installation

git clone https://github.com/sdi2200262/eclass-mcp-server.git
cd eclass-mcp-server
uv sync --dev --all-extras

Configuration

Create a .env file (or copy example.env):

ECLASS_USERNAME=your_username
ECLASS_PASSWORD=your_password

Optional settings:

ECLASS_URL=https://eclass.uoa.gr          # Default
ECLASS_SSO_DOMAIN=sso.uoa.gr              # Default
ECLASS_SSO_PROTOCOL=https                 # Default

Running

# Using the entry point script
python run_server.py

# Or as a module
python -m src.eclass_mcp_server.server

MCP Client Configuration

To use this MCP server with Claude Desktop, VS Code, Cursor, or any MCP-compatible client, configure your client to run:

python3 /absolute/path/to/eclass-mcp-server/run_server.py

Set the following environment variables in your client's MCP configuration:

{
  "env": {
    "ECLASS_USERNAME": "your_username",
    "ECLASS_PASSWORD": "your_password"
  }
}

Optional environment variables:

  • ECLASS_URL - OpenEclass instance URL (default: https://eclass.uoa.gr)

  • ECLASS_SSO_DOMAIN - SSO domain (default: sso.uoa.gr)

  • ECLASS_SSO_PROTOCOL - SSO protocol (default: https)

Refer to your specific client's documentation for how to add MCP servers to your configuration.

Available Tools

Tool

Description

login

Authenticate using credentials from .env

get_courses

Retrieve enrolled courses (requires login)

logout

End the current session

authstatus

Check authentication status

All tools use a dummy random_string parameter (MCP protocol requirement).

Standalone Client

For non-MCP usage, a standalone client is included:

python eclass_client.py

This demonstrates the core functionality without MCP integration. See docs/architecture.md for details.

Documentation

Project Structure

eclass-mcp-server/
├── run_server.py               # Entry point
├── eclass_client.py            # Standalone client (non-MCP)
├── src/eclass_mcp_server/      # Main package
│   ├── server.py               # MCP server and tool handlers
│   ├── authentication.py       # SSO authentication
│   ├── course_management.py    # Course operations
│   └── html_parsing.py         # HTML parsing utilities
└── docs/                       # Documentation

Security

  • Credentials are stored locally in .env only

  • Never passed as tool parameters (preventing AI provider exposure)

  • Sessions maintained in-memory only

  • No cloud services or remote storage

License

GNU GPL v3.0 - This ensures transparency in credential handling.

Acknowledgments

Available Tools

4 tools
authstatusB

Check authentication status with eClass

ParametersJSON Schema
NameRequiredDescriptionDefault
random_stringYesDummy parameter for no-parameter tools

TDQS

B3.1/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden. It only states the purpose without disclosing behavioral traits such as whether it requires authentication, what the response format is, or any rate limits. For a tool with zero annotation coverage, this is inadequate.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, clear sentence with no wasted words. It's appropriately sized and front-loaded, making it easy to understand immediately.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the lack of annotations and output schema, the description is incomplete. It doesn't explain what the tool returns (e.g., success/failure, user details) or any behavioral context, which is necessary for an authentication-related tool with no structured data support.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema description coverage is 100%, so the schema fully documents the single parameter. The description doesn't add any parameter information, which is acceptable since the schema handles it. With 0 parameters of real semantic weight (the parameter is a dummy), a baseline of 4 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose as 'Check authentication status with eClass', which is a specific verb ('Check') and resource ('authentication status') combination. It doesn't explicitly distinguish from siblings like 'login' or 'logout', but the purpose is unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No guidance is provided on when to use this tool versus alternatives like 'login' or 'logout'. The description states what it does but offers no context about when it should be invoked or what scenarios it addresses.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get_coursesB

Get list of enrolled courses from eClass

ParametersJSON Schema
NameRequiredDescriptionDefault
random_stringYesDummy parameter for no-parameter tools

TDQS

B3.1/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden of behavioral disclosure. It mentions retrieving a list but doesn't specify whether this requires authentication, what format the list is in, if there are rate limits, or any error conditions. For a read operation with zero annotation coverage, this leaves significant gaps in understanding the tool's behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, efficient sentence with no wasted words. It's front-loaded with the core purpose ('Get list of enrolled courses from eClass'), making it easy to understand immediately. Every word earns its place without redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no annotations, no output schema, and a simple read operation, the description is incomplete. It lacks details on authentication requirements, return format, error handling, or any behavioral context. For a tool that likely interacts with an eClass system, this leaves too many unknowns for effective agent use.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has one parameter (random_string) with 100% description coverage, indicating it's a dummy parameter for no-parameter tools. The description doesn't add any parameter details beyond the schema, but since this is effectively a zero-parameter tool (with a dummy parameter), the baseline is 4 as it doesn't need to compensate for schema gaps.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the action ('Get list') and target resource ('enrolled courses from eClass'), providing a specific verb+resource combination. However, it doesn't differentiate from sibling tools (authstatus, login, logout) which are unrelated authentication tools, so this distinction isn't needed but the purpose remains clear.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool versus alternatives. While the sibling tools are unrelated (authentication vs. data retrieval), there's no explicit mention of prerequisites like needing to be logged in or any context for usage. It simply states what it does without usage instructions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

loginB

Log in to eClass using username/password from your .env file through UoA's SSO. Configure ECLASS_USERNAME and ECLASS_PASSWORD in your .env file.

ParametersJSON Schema
NameRequiredDescriptionDefault
random_stringYesDummy parameter for no-parameter tools

TDQS

B3.3/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden of behavioral disclosure. It mentions authentication via SSO and .env file usage, but lacks details on what the tool actually does (e.g., establishes a session, returns tokens, handles errors) or behavioral traits like rate limits, side effects, or response format. For a login tool with zero annotation coverage, this is a significant gap.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two concise sentences that efficiently convey the core functionality and configuration requirement. It's front-loaded with the main action and wastes no words, making it easy to parse quickly.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the complexity of a login operation (authentication, session management) with no annotations and no output schema, the description is incomplete. It doesn't explain what happens after login (e.g., session persistence, return values, error handling), leaving gaps in understanding the tool's behavior and outcomes.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has 1 parameter with 100% coverage, describing it as a 'Dummy parameter for no-parameter tools.' The description doesn't add any parameter-specific information, which is appropriate since the tool likely doesn't require user-provided inputs. With high schema coverage and no meaningful parameters, a baseline of 4 is justified as the description doesn't need to compensate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose: 'Log in to eClass using username/password from your .env file through UoA's SSO.' It specifies the action (log in), target system (eClass), and authentication method (SSO with .env credentials). However, it doesn't explicitly differentiate from sibling tools like 'authstatus' or 'logout' beyond the obvious login/logout distinction.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage context: it should be used to authenticate with eClass via SSO when credentials are stored in .env. However, it doesn't provide explicit guidance on when to use this vs. alternatives like 'authstatus' (which might check login state) or prerequisites beyond .env configuration. The guidance is somewhat implied but not comprehensive.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

logoutB

Log out from eClass

ParametersJSON Schema
NameRequiredDescriptionDefault
random_stringYesDummy parameter for no-parameter tools

TDQS

B3.1/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries full burden for behavioral disclosure. While 'Log out' implies session termination, it doesn't specify what gets invalidated, whether this affects other tools, if re-authentication is required afterward, or what happens on failure. The description lacks important behavioral context for a security-sensitive operation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is maximally concise with just three words that directly convey the tool's purpose. There's zero waste or unnecessary elaboration, and it's perfectly front-loaded with the essential information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a security operation like logout with no annotations and no output schema, the description is insufficient. It doesn't explain what happens after logout, whether the operation can fail, what state changes occur, or how this affects subsequent tool calls. The minimal description leaves critical behavioral questions unanswered.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has 100% description coverage, with the single parameter clearly documented as a 'Dummy parameter for no-parameter tools.' The description doesn't need to add parameter semantics since the tool conceptually requires no real parameters, and the schema adequately explains the dummy parameter requirement.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the action ('Log out') and target system ('from eClass'), providing a specific verb+resource combination. However, it doesn't differentiate from sibling tools like 'login' or 'authstatus' beyond the obvious action difference.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool versus alternatives like 'authstatus' to check login state, or whether logout should follow certain workflows. It simply states what the tool does without context about appropriate usage scenarios.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 4 tool updates
    • First observedauthstatus
    • First observedget_courses
    • First observedlogin
    • First observedlogout

TDQS

B3.4/5.0

Scored across 4 tools

Disambiguation5/5

Each tool has a distinct purpose with no overlap: authstatus checks authentication state, get_courses retrieves course data, login handles authentication, and logout terminates sessions. The descriptions clearly differentiate these functions, making tool selection straightforward for an agent.

Naming Consistency4/5

Three tools follow a consistent verb_noun pattern (get_courses, login, logout), while authstatus uses a compound noun. This minor deviation slightly reduces consistency, but the naming remains readable and intuitive overall.

Tool Count4/5

Four tools are reasonable for an eClass server focused on authentication and basic course access. It covers core authentication workflows and data retrieval, though it could be slightly expanded for a more comprehensive eClass integration.

Completeness3/5

The tools cover authentication and course listing well, but there are notable gaps for typical eClass functionality such as accessing course content, assignments, grades, or announcements. This limits the server's ability to support full eClass workflows.

Maintenance

ActivityInactive
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers