SchoolPass for Claude — students, arrival/dismissal calendar, pickup changes, and school info
About
SchoolPass for Claude — students, arrival/dismissal calendar, pickup changes, and school info
Security Report
SchoolPass MCP server is well-designed with proper authentication, consent-gated write operations, and reasonable scope limitations. Core security practices are sound: credentials are stored in environment variables, API calls are authenticated, and dangerous operations require explicit confirmation. Minor code quality observations around error handling breadth do not materially impact security. Supply chain analysis found 2 known vulnerabilities in dependencies (0 critical, 1 high severity). Package verification found 1 issue.
7 files analyzed · 6 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: SCHOOLPASS_EMAIL
Environment variable: SCHOOLPASS_PASSWORD
Environment variable: SCHOOLPASS_SCHOOL_CODE
Environment variable: SCHOOLPASS_API_HOST
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-chrischall-schoolpass-mcp": {
"env": {
"SCHOOLPASS_EMAIL": "your-schoolpass-email-here",
"SCHOOLPASS_API_HOST": "your-schoolpass-api-host-here",
"SCHOOLPASS_PASSWORD": "your-schoolpass-password-here",
"SCHOOLPASS_SCHOOL_CODE": "your-schoolpass-school-code-here"
},
"args": [
"-y",
"schoolpass-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
schoolpass-mcp
MCP server for SchoolPass — read AND change your child's school arrival & dismissal from a parent account. Talks to the SchoolPass REST API used by the SchoolPass web and mobile apps, authenticating server-side with your own parent email and password (no browser, no extension).
Developed and maintained by AI (Claude Code). Use at your own discretion.
Parent-scoped: read tools plus a confirm-gated dismissal-change write/cancel.
Tools
| Tool | What it does |
|---|---|
schoolpass_healthcheck | Reachability + authentication, reported separately. |
schoolpass_whoami | The parent identity the server signed in as. |
schoolpass_list_students | Your linked students — name, grade, home dismissal location, aftercare. |
schoolpass_get_profile | The parent account profile. |
schoolpass_list_drivers | Authorized pickup drivers, with their carpools. |
schoolpass_get_calendar | A student's arrival/dismissal calendar over a date range. |
schoolpass_list_pickup_changes | Pickup/dismissal changes for a student on a date. |
schoolpass_list_dismissal_locations | The school's dismissal locations, with ids. |
schoolpass_get_school_info | Basic school info and per-school config. |
schoolpass_submit_dismissal_change | Submit a dismissal/arrival change (confirm-gated, dry-run preview). |
schoolpass_cancel_dismissal_change | Cancel a change, back to default (confirm-gated). |
Configuration
| Env var | Required | Notes |
|---|---|---|
SCHOOLPASS_EMAIL | yes | Your SchoolPass parent account email. |
SCHOOLPASS_PASSWORD | yes | Your SchoolPass password. |
SCHOOLPASS_SCHOOL_CODE | yes | The numeric school id (the AppCode / appCode value; e.g. 1183). |
SCHOOLPASS_API_HOST | no | Regional API host override (default busapi-east16-ss.school-pass.net). |
Finding your school id and region host: sign into your school's
<school>.school-pass.net portal, open the new SchoolPass app, and read
appCode (the id) and apiUrl (the host) from its browser localStorage.
Install
{
"mcpServers": {
"schoolpass": {
"command": "npx",
"args": ["-y", "schoolpass-mcp"],
"env": {
"SCHOOLPASS_EMAIL": "you@example.com",
"SCHOOLPASS_PASSWORD": "your-password",
"SCHOOLPASS_SCHOOL_CODE": "1183"
}
}
}
}
Notes
- Parent scope only. A parent token cannot reach admin routes (visitor
management, carline operations, reports, bus routing); those return
403. - Never retry a rejected login. SchoolPass fronts its login with reCAPTCHA; repeated failures can get the account challenged.
- No credentials, still boots. The server starts without configuration and
answers
tools/list; the config error surfaces on the first tool call.
Without the server: curl
The SchoolPass API is reachable server-side, so a one-off shell read needs no
MCP process — see the bundled schoolpass-curl skill
(skills/schoolpass-curl/) for a curl + jq recipe set.
Development
npm install
npm test # unit + boot tests
npm run build # tsc + esbuild bundle
node --env-file=.env scripts/live-check.mjs # live read-only check (needs .env)
License
MIT
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.