SchoolPass for Claude — students, arrival/dismissal calendar, pickup changes, and school info
About
SchoolPass for Claude — students, arrival/dismissal calendar, pickup changes, and school info
Security Report
This is a well-architected MCP server for SchoolPass parent account management with strong authentication, proper credential handling, and thoughtful security design. The server implements session caching, token refresh logic, CDN/WAF edge case handling, and confirm-gated write operations. Minor code quality observations exist around error handling breadth and logging, but these do not represent security vulnerabilities. Permissions are appropriate for the server's purpose. Supply chain analysis found 2 known vulnerabilities in dependencies (0 critical, 1 high severity). Package verification found 1 issue.
4 files analyzed · 6 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: SCHOOLPASS_EMAIL
Environment variable: SCHOOLPASS_PASSWORD
Environment variable: SCHOOLPASS_SCHOOL_CODE
Environment variable: SCHOOLPASS_API_HOST
Environment variable: SCHOOLPASS_SESSION_CACHE
Environment variable: SCHOOLPASS_SESSION_FILE
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-chrischall-schoolpass-mcp": {
"env": {
"SCHOOLPASS_EMAIL": "your-schoolpass-email-here",
"SCHOOLPASS_API_HOST": "your-schoolpass-api-host-here",
"SCHOOLPASS_PASSWORD": "your-schoolpass-password-here",
"SCHOOLPASS_SCHOOL_CODE": "your-schoolpass-school-code-here",
"SCHOOLPASS_SESSION_FILE": "your-schoolpass-session-file-here",
"SCHOOLPASS_SESSION_CACHE": "your-schoolpass-session-cache-here"
},
"args": [
"-y",
"schoolpass-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
schoolpass-mcp
MCP server for SchoolPass — read AND change your child's school arrival & dismissal from a parent account. Talks to the SchoolPass REST API used by the SchoolPass web and mobile apps, authenticating server-side with your own parent email and password (no browser, no extension).
Developed and maintained by AI (Claude Code). Use at your own discretion.
Parent-scoped: read tools plus a confirm-gated dismissal-change write/cancel.
Tools
| Tool | What it does |
|---|---|
schoolpass_healthcheck | Reachability + authentication, reported separately. |
schoolpass_whoami | The parent identity the server signed in as. |
schoolpass_list_students | Your linked students — name, grade, home dismissal location, aftercare. |
schoolpass_get_profile | The parent account profile. |
schoolpass_list_drivers | Authorized pickup drivers; include_carpool: true adds their carpools (other families' contact/vehicle fields dropped unless view: "full"). |
schoolpass_get_calendar | A student's arrival/dismissal calendar over a date range. |
schoolpass_list_pickup_changes | Pickup/dismissal changes for a student on a date. |
schoolpass_list_dismissal_locations | The school's dismissal locations, with ids. |
schoolpass_get_school_info | Basic school info and per-school config. |
schoolpass_submit_dismissal_change | Submit a dismissal/arrival change (confirm-gated: preview + single-use confirmToken). |
schoolpass_cancel_dismissal_change | Cancel a change, back to default (confirm-gated: preview + confirmToken). |
Configuration
| Env var | Required | Notes |
|---|---|---|
SCHOOLPASS_EMAIL | yes | Your SchoolPass parent account email. |
SCHOOLPASS_PASSWORD | yes | Your SchoolPass password. |
SCHOOLPASS_SCHOOL_CODE | yes | The numeric school id (the AppCode / appCode value; e.g. 1183). |
SCHOOLPASS_API_HOST | no | Regional API host override (default busapi-east16-ss.school-pass.net). |
MCP_CONFIRM_MODE | no | How the two writes confirm on a client that cannot show a prompt: ask-user (default — preview + token, the user approves in chat), auto (the model may use the token after reviewing the preview), or refuse. |
MCP_CONFIRM_ELICITATION | no | off never shows a confirmation prompt, so every client gets the MCP_CONFIRM_MODE behaviour. Set it for a client that says it can show prompts but never does (the write hangs — opencode 2.0.x). Default on; any other value is treated as on, with a warning on stderr. |
MCP_CONFIRM_TTL_SECONDS | no | How long a confirm token stays valid (default 600). |
MCP_CONFIRM_SECRET | no | HMAC key for confirm tokens; set only if tokens must survive a restart. On mcp-host the host supplies a stable per-child key (MCP_HOST_CONFIRM_SECRET) and spent tokens are recorded under MCP_DATA_DIR, so an approval survives an idle restart. |
Finding your school id and region host: sign into your school's
<school>.school-pass.net portal, open the new SchoolPass app, and read
appCode (the id) and apiUrl (the host) from its browser localStorage.
Install
{
"mcpServers": {
"schoolpass": {
"command": "npx",
"args": ["-y", "schoolpass-mcp"],
"env": {
"SCHOOLPASS_EMAIL": "you@example.com",
"SCHOOLPASS_PASSWORD": "your-password",
"SCHOOLPASS_SCHOOL_CODE": "1183"
}
}
}
}
Notes
- Parent scope only. A parent token cannot reach admin routes (visitor
management, carline operations, reports, bus routing); those return
403. - Never retry a rejected login. SchoolPass fronts its login with reCAPTCHA; repeated failures can get the account challenged. A password SchoolPass refuses (400/401) is tried once per process: later calls return the same error without contacting SchoolPass until the configured credentials change or the server restarts. A CDN/WAF block page (CloudFront, Cloudflare, …) is not a refusal: it is reported as an edge block, never latched, and never spends or discards the stored session.
- No credentials, still boots. The server starts without configuration and
answers
tools/list; the config error surfaces on the first tool call.
Without the server: curl
The SchoolPass API is reachable server-side, so a one-off shell read needs no
MCP process — see the bundled schoolpass-curl skill
(skills/schoolpass-curl/) for a curl + jq recipe set.
Development
npm install
npm test # tsc typecheck + unit + boot tests
npm run build # tsc + esbuild bundle
node --env-file=.env scripts/live-check.mjs # live read-only check (needs .env)
License
MIT
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Worldmonitor
Freeby Koala73 · Developer Tools
Live markets, conflicts, country risk, chokepoints, energy, and China decision signals. 90 tools.
Paperclip
Freeby Paperclipai · Developer Tools
Trending hip-hop artist momentum scores across four cultural dimensions.
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.