Back to Browse

Schoolpass MCP Server

Developer ToolsModerate6.6Local
Free

SchoolPass for Claude — students, arrival/dismissal calendar, pickup changes, and school info

About

SchoolPass for Claude — students, arrival/dismissal calendar, pickup changes, and school info

Security Report

6.6
Moderate6.6Moderate Risk

This is a well-architected MCP server for SchoolPass parent account management with strong authentication, proper credential handling, and thoughtful security design. The server implements session caching, token refresh logic, CDN/WAF edge case handling, and confirm-gated write operations. Minor code quality observations exist around error handling breadth and logging, but these do not represent security vulnerabilities. Permissions are appropriate for the server's purpose. Supply chain analysis found 2 known vulnerabilities in dependencies (0 critical, 1 high severity). Package verification found 1 issue.

4 files analyzed · 6 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

What You'll Need

Set these up before or after installing:

Your SchoolPass parent account email address.Optional

Environment variable: SCHOOLPASS_EMAIL

Your SchoolPass parent account password.Required

Environment variable: SCHOOLPASS_PASSWORD

The numeric school id (AppCode) SchoolPass uses to select your school.Optional

Environment variable: SCHOOLPASS_SCHOOL_CODE

Optional regional API host override (default busapi-east16-ss.school-pass.net).Optional

Environment variable: SCHOOLPASS_API_HOST

Set to false to disable the on-disk session cache and re-authenticate on every process start. Defaults to enabled.Optional

Environment variable: SCHOOLPASS_SESSION_CACHE

Absolute path for the session cache file. Defaults to $MCP_DATA_DIR/.schoolpass-mcp/session.json.Optional

Environment variable: SCHOOLPASS_SESSION_FILE

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-chrischall-schoolpass-mcp": {
      "env": {
        "SCHOOLPASS_EMAIL": "your-schoolpass-email-here",
        "SCHOOLPASS_API_HOST": "your-schoolpass-api-host-here",
        "SCHOOLPASS_PASSWORD": "your-schoolpass-password-here",
        "SCHOOLPASS_SCHOOL_CODE": "your-schoolpass-school-code-here",
        "SCHOOLPASS_SESSION_FILE": "your-schoolpass-session-file-here",
        "SCHOOLPASS_SESSION_CACHE": "your-schoolpass-session-cache-here"
      },
      "args": [
        "-y",
        "schoolpass-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

schoolpass-mcp

MCP server for SchoolPass — read AND change your child's school arrival & dismissal from a parent account. Talks to the SchoolPass REST API used by the SchoolPass web and mobile apps, authenticating server-side with your own parent email and password (no browser, no extension).

Developed and maintained by AI (Claude Code). Use at your own discretion.

Parent-scoped: read tools plus a confirm-gated dismissal-change write/cancel.

Tools

ToolWhat it does
schoolpass_healthcheckReachability + authentication, reported separately.
schoolpass_whoamiThe parent identity the server signed in as.
schoolpass_list_studentsYour linked students — name, grade, home dismissal location, aftercare.
schoolpass_get_profileThe parent account profile.
schoolpass_list_driversAuthorized pickup drivers; include_carpool: true adds their carpools (other families' contact/vehicle fields dropped unless view: "full").
schoolpass_get_calendarA student's arrival/dismissal calendar over a date range.
schoolpass_list_pickup_changesPickup/dismissal changes for a student on a date.
schoolpass_list_dismissal_locationsThe school's dismissal locations, with ids.
schoolpass_get_school_infoBasic school info and per-school config.
schoolpass_submit_dismissal_changeSubmit a dismissal/arrival change (confirm-gated: preview + single-use confirmToken).
schoolpass_cancel_dismissal_changeCancel a change, back to default (confirm-gated: preview + confirmToken).

Configuration

Env varRequiredNotes
SCHOOLPASS_EMAILyesYour SchoolPass parent account email.
SCHOOLPASS_PASSWORDyesYour SchoolPass password.
SCHOOLPASS_SCHOOL_CODEyesThe numeric school id (the AppCode / appCode value; e.g. 1183).
SCHOOLPASS_API_HOSTnoRegional API host override (default busapi-east16-ss.school-pass.net).
MCP_CONFIRM_MODEnoHow the two writes confirm on a client that cannot show a prompt: ask-user (default — preview + token, the user approves in chat), auto (the model may use the token after reviewing the preview), or refuse.
MCP_CONFIRM_ELICITATIONnooff never shows a confirmation prompt, so every client gets the MCP_CONFIRM_MODE behaviour. Set it for a client that says it can show prompts but never does (the write hangs — opencode 2.0.x). Default on; any other value is treated as on, with a warning on stderr.
MCP_CONFIRM_TTL_SECONDSnoHow long a confirm token stays valid (default 600).
MCP_CONFIRM_SECRETnoHMAC key for confirm tokens; set only if tokens must survive a restart. On mcp-host the host supplies a stable per-child key (MCP_HOST_CONFIRM_SECRET) and spent tokens are recorded under MCP_DATA_DIR, so an approval survives an idle restart.

Finding your school id and region host: sign into your school's <school>.school-pass.net portal, open the new SchoolPass app, and read appCode (the id) and apiUrl (the host) from its browser localStorage.

Install

{
  "mcpServers": {
    "schoolpass": {
      "command": "npx",
      "args": ["-y", "schoolpass-mcp"],
      "env": {
        "SCHOOLPASS_EMAIL": "you@example.com",
        "SCHOOLPASS_PASSWORD": "your-password",
        "SCHOOLPASS_SCHOOL_CODE": "1183"
      }
    }
  }
}

Notes

  • Parent scope only. A parent token cannot reach admin routes (visitor management, carline operations, reports, bus routing); those return 403.
  • Never retry a rejected login. SchoolPass fronts its login with reCAPTCHA; repeated failures can get the account challenged. A password SchoolPass refuses (400/401) is tried once per process: later calls return the same error without contacting SchoolPass until the configured credentials change or the server restarts. A CDN/WAF block page (CloudFront, Cloudflare, …) is not a refusal: it is reported as an edge block, never latched, and never spends or discards the stored session.
  • No credentials, still boots. The server starts without configuration and answers tools/list; the config error surfaces on the first tool call.

Without the server: curl

The SchoolPass API is reachable server-side, so a one-off shell read needs no MCP process — see the bundled schoolpass-curl skill (skills/schoolpass-curl/) for a curl + jq recipe set.

Development

npm install
npm test            # tsc typecheck + unit + boot tests
npm run build       # tsc + esbuild bundle
node --env-file=.env scripts/live-check.mjs   # live read-only check (needs .env)

License

MIT

Reviews

No reviews yet

Be the first to review this server!