MCP server
The EduRails MCP server wraps the API so an agent (Claude, Claude Code or another MCP client) can look up courses, progress and cohorts on your behalf. Tools come from the same contract as the API: they do nothing you cannot do.
Before you start
Whoever manages your institution has to turn on “Assistants and MCP” in Institution → Features (it is off by default). Your tokens and connections live in Settings → Connections.
Connecting
Remote server (Streamable HTTP): https://app.edurails.com/mcp. Without a credential it returns 401 and starts the OAuth flow; a client that does not support it can send your personal access token:
{
"mcpServers": {
"edurails": {
"type": "http",
"url": "https://app.edurails.com/mcp",
"headers": { "Authorization": "Bearer edr_live_…" }
}
}
}Profiles
core(default): the essentials to learn, teach and administer.all(…/mcp?tools=all): every tool.- By domain (
…/mcp?tools=learning,teaching): those domains plusorg, which is always in.
Tools
| Tool | Domain | Profile |
|---|---|---|
whoami | org | core |
list_my_organizations | learning | core |
list_courses | learning | core |
get_course | learning | core |
list_course_lessons | learning | core |
get_course_lesson | learning | core |
list_my_courses | learning | core |
get_my_progress | learning | core |
get_my_course_progress | learning | core |
list_my_certificates | learning | core |
list_my_notes | learning | core |
search_content | learning | core |
list_teacher_cohorts | teaching | core |
get_cohort_progress | teaching | core |
get_organization | admin | core |
get_organization_usage | admin | core |
list_organization_members | admin | core |
list_organization_invites | admin | core |
invite_organization_member | admin | core |
get_my_gamification | learning | core |
list_my_badges | learning | core |
verify_certificate | learning | core |
assign_course | teaching | core |
assign_course_to_student | teaching | core |
get_cohort_report | teaching | core |
list_cohorts | teaching | core |
start_course | learning | all |
complete_lesson | learning | all |
save_note | learning | all |
list_due_flashcards | learning | all |
list_learning_paths | learning | all |
get_org_report_overview | teaching | all |
get_org_report_courses | teaching | all |
confirm_quiz_proposal | teaching | all |
propose_quiz | teaching | all |
Security
Every connection is tied to one institution and to your role there. Every change is shown first and only happens if you confirm it. A token or a connection never opens your account settings or creates other tokens. Course content is treated as data, not as instructions.
Good practice
- Use one token or OAuth grant per agent, so you can revoke it on its own.
- Start with
coreand open domains when needed: fewer tools, less context and less risk. - Review what the agent is about to write (inviting, completing) before confirming it.