Skip to main content
Glama
README.md
<img src="https://static.edubase.net/media/brand/title/color.png" alt="EduBase logo" height="150" />

# EduBase MCP server

[![pre-commit.ci status](https://results.pre-commit.ci/badge/github/EduBase/MCP/main.svg)](https://results.pre-commit.ci/latest/github/EduBase/MCP/main)
[![Publish to MCP Registry](https://github.com/EduBase/MCP/actions/workflows/publish-mcp.yml/badge.svg)](https://github.com/EduBase/MCP/actions/workflows/publish-mcp.yml)

This repository contains the **implementation of the Model Context Protocol** (MCP) server **for the EduBase platform**. It allows MCP clients (for example Claude Desktop) and LLMs to interact with your EduBase account and perform tasks on your behalf. It supports stdio, SSE and streamable HTTP transport protocols.

![EduBase MCP demo GIF: Claude uploads math questions](https://shared.edubase.net/mcp/EduBaseMCPdemomath.gif)

## What is EduBase?

EduBase is an innovative, modular, online educational platform that makes learning more enjoyable, simpler and interactive, suitable for educational institutions or enterprises.

### Why choose EduBase?

EduBase revolutionizes digital learning with its unique combination of features:

* **Advanced Quiz System** with parametrization allowing infinite variations of the same question, real-time cheating detection, beautiful LaTeX typesetting, advanced STEM-support and automatic grading
* **Unified Learning Environment** that centralizes all your educational content — videos, exams, documents, and SCORM modules — in one intuitive system
* **Enterprise-Grade Security** with features like SSO integration, fine-grained access controls, comprehensive auditing, and GDPR compliance
* **Integration** with your existing systems through LTI, comprehensive API, and custom integration options
* **AI-Assisted Tools**, such as EduBase Assistant, that can instantly transform your existing content into interactive quizzes and assessments, or translate your materials from one language to another

From higher education institutions to corporate training departments, EduBase scales to meet your specific needs while maintaining an intuitive user experience across all devices.

### Demo video

Collaboratively creating and uploading questions, scheduling exams and analyzing user results with Claude:

<a href="https://www.youtube.com/watch?v=jvGP-5NzRPs">
  <img src="https://img.youtube.com/vi/jvGP-5NzRPs/maxresdefault.jpg" alt="Demonstrating EduBase's MCP server to collaboratively create and upload questions, schedule exams and analyze results." width="600"/>
</a>

### Obtaining your API credentials

Once logged in, on your Dashboard, search for the Integrations menu, click "add integration" and choose the type "EduBase API".

**If you don't see this option**, enter the `MCPGITHUB` activation code or feel free to contact us to request access at [info@edubase.net](mailto:info@edubase.net).

<img src="https://shared.edubase.net/mcp/EduBase_Integration_page_with_API_credentials.png" alt="EduBase API credentials page" width="500" />

## Tools

Each documented API endpoint is available as a tool, named `edubase_<method>_<endpoint>`. For example, the tool for the `GET /user:me` endpoint is named `edubase_get_user_me`. The tag, permission and transfer endpoints work the same way for every content type, so they share a single tool per method with a `type` argument (e.g. `edubase_post_content_tag` for `POST /exam:tag`, `POST /quiz:tag`, etc.). See our [developer documentation](https://developer.edubase.net) for more information.

### Toolsets

Tools are grouped into toolsets, so you can expose only the tools you need. Fewer tools use less of the model's context and make it easier for the model to pick the right one. Every toolset is enabled by default.

| Toolset | Tools for |
|---|---|
| `files` | Temporary file uploads (always enabled) |
| `questions` | Questions |
| `quizzes` | Quiz sets, their questions, settings and grading presets |
| `exams` | Exams, their settings, users, certificates and branding |
| `results` | Quiz and exam results, certificate downloads |
| `users` | Users, their names, groups and login links |
| `classes` | Classes and class memberships |
| `organizations` | Organizations, members, departments, competencies and webhooks |
| `integrations` | Integrations and their keys |
| `tags` | Tags and tag attachments of contents |
| `permissions` | User permissions on contents and ownership transfers |
| `metrics` | Custom metrics |

Select toolsets with a comma-separated list in `EDUBASE_TOOLSETS` (e.g. `questions,quizzes,exams`). Set `EDUBASE_READONLY=true` to expose only the tools that read data (the `get` tools, and the tools that only generate download links, like `edubase_post_question_export`).

Set `EDUBASE_DYNAMIC_TOOLSETS=true` to enable toolsets on demand: sessions start with only the critical tools, and the model enables the toolsets it needs with the `edubase_enable_toolsets` tool (listed with `edubase_list_toolsets`). This keeps the initial tool list small for clients that load every tool upfront, but needs a client that refreshes the tool list when notified about changes.

When an HTTP transport is used, clients can narrow the configuration further for their own session with the `EduBase-Mcp-Toolsets`, `EduBase-Mcp-ReadOnly` and `EduBase-Mcp-Dynamic` headers, or the `toolsets`, `read_only` and `dynamic_toolsets` query parameters (e.g. `https://domain.edubase.net/mcp?toolsets=exams&read_only=true`). A session can never enable toolsets or write tools that the server configuration disables.

## Configuration

The MCP server can be configured using environment variables. The following variables are available:

| Variable | Description | Required | Default value |
|---|---|---|---|
| `EDUBASE_API_URL` | The base URL of the EduBase API, most probably `https://subdomain.edubase.net/api`. | **Yes** | `https://www.edubase.net/api` |
| `EDUBASE_API_APP` | The App ID of your integration app on EduBase, the `app` on the EduBase API. Find this in the integration details window on EduBase. | Not if HTTP transport is used with authentication, otherwise **Yes** | - |
| `EDUBASE_API_KEY` | The Secret key of your integration app on EduBase, the `secret` on the EduBase API. Find this along the App ID in the integration details window on EduBase. | Not if HTTP transport is used with authentication, otherwise **Yes** | - |
| `EDUBASE_SSE_MODE` | Start MCP server in HTTP mode with SSE transport. Value must be `true`. | No | `false` |
| `EDUBASE_STREAMABLE_HTTP_MODE` | Start MCP server in HTTP mode with streamable HTTP transport. Value must be `true`. | No | `false` |
| `EDUBASE_TOOLSETS` | Comma-separated list of the enabled [toolsets](#toolsets), or `all`. | No | `all` |
| `EDUBASE_READONLY` | Only expose the tools that read data. Value must be `true`. | No | `false` |
| `EDUBASE_OUTPUT_SCHEMAS` | Output schemas of the tools and structured tool results: `off` lists the tools without output schemas and returns the results as JSON text only, `on` includes the complete output schemas, `fields` includes the output schemas without the field descriptions (keeping the structured results, but saving most of the tokens of the schemas). | No | `fields` |
| `EDUBASE_CONFIG_PROVIDERS` | Comma-separated list of the hosting providers allowed to supply session configuration in the requests when an HTTP transport is used. Currently only `smithery` is supported (the base64-encoded `config` query parameter). | No | - |
| `EDUBASE_DYNAMIC_TOOLSETS` | Start sessions with only the file upload tools and let the model enable [toolsets](#toolsets) on demand. Value must be `true`. | No | `false` |
| `EDUBASE_HTTP_PORT` | HTTP server will listen on this port if SSE or streamable HTTP transport mode is used. | No | 3000 |
| `EDUBASE_OAUTH` | Enables OAuth 2.1 protected-resource behaviour: unauthenticated requests are rejected with `401 + WWW-Authenticate` pointing at `/.well-known/oauth-protected-resource`, and bearer tokens are forwarded to the EduBase API. | No | `false` |
| `EDUBASE_OAUTH_AUTHORIZATION_SERVER` | Public base URL of the EduBase deployment acting as the OAuth IdP. Used to advertise the authorization server in the protected-resource metadata document. | No | derived from `EDUBASE_API_URL` |
| `EDUBASE_OAUTH_RESOURCE_URL` | Public base URL of *this* MCP server (the OAuth resource indicator). Used in the `WWW-Authenticate` header and resource metadata. | No | derived from `EDUBASE_API_URL` |
| `EDUBASE_ALLOW_PRIVATE_NETWORK` | When an HTTP transport is used, the `edubase_filebin` tool blocks outbound requests to private, loopback, link-local and reserved addresses (SSRF protection) and refuses local file paths. Set to `true` to allow them, e.g. a self-hosted deployment on a trusted private network. Has no effect in stdio mode, where the local user is the only caller. | No | `false` |
| `EDUBASE_FILEBIN_ALLOWED_HOSTS` | Optional comma-separated allow-list of hostnames permitted as `edubase_filebin` upload targets (exact host or any subdomain, e.g. `edubase.net`). When empty, any public host is allowed (still subject to the address filtering above). | No | - |

## Use as a remote MCP server

You can use the **EduBase MCP server as a remote MCP server** for your MCP client. To do this, you need to host the MCP server where clients can access it, and then configure the client to connect to the server. Either start it with SSE or streamable HTTP transport mode and always use HTTPS when accessing the server remotely over the internet!

### Authentication with remote servers

You can use server in two modes:

* **Without client authentication**: In this mode, the server will not require any authentication from the client. This is useful for testing or development purposes, or in a closed network but it is not recommended for production use. For this, you have to configure the server with the `EDUBASE_API_APP` and `EDUBASE_API_KEY` as well!
* **With Bearer token authentication**: In this mode, the server will require a Bearer token to be sent with each request. This is the recommended way to use the server in production. You can obtain the Bearer token from your EduBase account by creating an integration app and providing the App ID and Secret key in the `{app}:{secret}` format, base64 encoded as a token. The server will then use this token to authenticate the client and authorize access to the API endpoints.
* **With OAuth 2.1 (EduBase as IdP)**: When `EDUBASE_OAUTH=true`, compatible clients (Claude Desktop, Claude.ai connectors, Cursor, ChatGPT connectors, etc.) discover the EduBase authorization server through `/.well-known/oauth-protected-resource`, register themselves dynamically (RFC 7591), walk the user through an EduBase consent screen, and exchange an authorization code (with PKCE S256) for an opaque access token. The MCP server forwards that token verbatim to the EduBase API, which resolves it to the auto-provisioned MCP integration, created on first consent. No App ID/Secret to copy — users just click "Connect EduBase" in their client.

## Usage with Claude Desktop

For a step-by-step walkthrough, see our blog post on how to [connect EduBase with Claude: The Complete MCP Integration Guide](https://edubase.blog/claude-mcp-integration-guide/).

### Using the provided EduBase MCP server

You can use the provided EduBase MCP server (if available) without any configuration, just by adding it as a remote server in your client with the URL `https://domain.edubase.net/mcp` (replace with the actual domain), if it supports OAuth authentication, or with the appropriate Bearer token in the `Authorization` header (`Authorization: Bearer ${BASE64_ENCODED_TOKEN}`).

**Recommended for www.edubase.net users**, as the server is maintained and updated by us, and you don't have to worry about hosting or configuring it. Just make sure to use the correct URL and authentication method when connecting your client.

### Installing manually

Add the following to your `claude_desktop_config.json`:

#### Using Node.js

Before running the MCP server, make sure you have **Node.js installed**. You can download it from [nodejs.org](https://nodejs.org/) or use a package manager like `brew`.

```json
{
  "mcpServers": {
    "edubase": {
      "command": "npx",
      "args": [
        "-y",
        "@edubase/mcp"
      ],
      "env": {
        "EDUBASE_API_URL": "https://domain.edubase.net/api",
        "EDUBASE_API_APP": "your_integration_app_id",
        "EDUBASE_API_KEY": "your_integration_secret_key"
      }
    }
  }
}
```

Or download EduBase MCP server release or clone the repository and run `npm run build` to build the server. Do not forget to adjust `/path/to/dist` to the actual directory and **configure the environmental variables**!

```json
{
  "mcpServers": {
    "edubase": {
      "command": "node",
      "args": [
        "/path/to/dist/index.js"
      ],
      "env": {
        "EDUBASE_API_URL": "https://domain.edubase.net/api",
        "EDUBASE_API_APP": "your_integration_app_id",
        "EDUBASE_API_KEY": "your_integration_secret_key"
      }
    }
  }
}
```

#### Using Docker

Before running the MCP server, make sure you have **Docker installed and is running**. You can download it from [docker.com](https://www.docker.com/) or use a package manager. Do not forget to **configure the environmental variables**!

```json
{
  "mcpServers": {
    "edubase": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "-e",
        "EDUBASE_API_URL",
        "-e",
        "EDUBASE_API_APP",
        "-e",
        "EDUBASE_API_KEY",
        "edubase/mcp"
      ],
      "env": {
        "EDUBASE_API_URL": "https://domain.edubase.net/api",
        "EDUBASE_API_APP": "your_integration_app_id",
        "EDUBASE_API_KEY": "your_integration_secret_key"
      }
    }
  }
}
```

### Installing via remote MCP server

You can use the provided EduBase MCP server (if available) as a remote server. We recommend Base64 encoding your `EDUBASE_API_APP` and `EDUBASE_API_KEY` and using it in as a Bearer token in the `Authorization` header (`Authorization: Bearer ${BASE64_ENCODED_TOKEN}`).

```json
{
  "mcpServers": {
    "edubase": {
      "command": "npx",
      "args": [
        "mcp-remote",
        "https://domain.edubase.net/mcp",
        "--header",
        "Authorization: Bearer ${EDUBASE_API_APP}:${EDUBASE_API_KEY}"
      ]
    }
  }
}
```

### Installing via Smithery

To install EduBase MCP server for Claude Desktop automatically via [Smithery](https://smithery.ai/server/@EduBase/MCP):

```bash
npx -y @smithery/cli install @EduBase/MCP --client claude
```

## Development

Run `npm test` to build the server and check the tool listing: the size budgets of the tool list and the server instructions, the tool descriptions, the toolset, read-only and dynamic toolsets modes, and the configuration handling of the HTTP transport. When new tools exceed a budget, shorten their schemas or raise the budget in `test/server.test.mjs` deliberately, as every client pays for the tool list in every session.

## Contact

Website: [www.edubase.net](www.edubase.net)  
Developer Documentation: [developer.edubase.net](developer.edubase.net)  
Email: [info@edubase.net](mailto:info@edubase.net)

TDQS

B3/5.0

Scored across 138 tools

Disambiguation2/5

There are direct duplicates/aliases such as edubase_post_class_members vs edubase_post_classes_members and edubase_post_organization_members vs edubase_post_organizations_members. Additionally, trios like post/patch/put_quiz_settings and get_question vs get_questions vs post_question_export have subtle boundaries that require careful reading to avoid misselection.

Naming Consistency3/5

The dominant edubase_<method>_<resource> pattern is readable, but it is broken by non-verb tools like edubase_filebin and edubase_mcp_server_version, the misspelled edubase_get_quizes, and duplicate singular/plural resource names. Most names are predictable, so it is not chaotic, but the deviations are more than minor.

Tool Count1/5

138 tools is far beyond the well-scoped 3-15 range; even for a broad LMS platform this creates a massive surface that is hard to navigate. The count alone makes the server unwieldy and argues for consolidation.

Completeness3/5

The toolset covers a huge amount of EduBase functionality—users, organizations, quizzes, exams, results, certificates, permissions, and webhooks—with mostly full CRUD. However, classes have no create/update/delete tools and tags cannot be created or removed, which are noticeable gaps for a platform this broad.

Maintenance

ActivityActive
ResponsivenessNo issues