io.usefulapi/learnworlds
REMOTE · LEARNWORLDS.USEFULAPI.IO · SCANNED OCT 3
Check LearnWorlds courses, learners, progress, grades and payments, and enroll or tag users.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security89
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability77
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2416 tokens (~120/item across 20 items; 20 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management10
- Stability observed for 3 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage96
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 89% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 20 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 20 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the io.usefulapi/learnworlds MCP server?
io.usefulapi/learnworlds is a hosted endpoint at https://learnworlds.usefulapi.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · learnworlds.usefulapi.io
claude mcp add --transport http io-usefulapi-learnworlds 'https://learnworlds.usefulapi.io/mcp'
{
"mcpServers": {
"io-usefulapi-learnworlds": {
"url": "https://learnworlds.usefulapi.io/mcp"
}
}
} {
"servers": {
"io-usefulapi-learnworlds": {
"type": "http",
"url": "https://learnworlds.usefulapi.io/mcp"
}
}
} [mcp_servers.io-usefulapi-learnworlds] url = "https://learnworlds.usefulapi.io/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"io-usefulapi-learnworlds": {
"type": "remote",
"url": "https://learnworlds.usefulapi.io/mcp",
"enabled": true
}
}
} openclaw mcp add io-usefulapi-learnworlds --url 'https://learnworlds.usefulapi.io/mcp' --transport streamable-http
mcp_servers:
io-usefulapi-learnworlds:
url: "https://learnworlds.usefulapi.io/mcp" {
"McpServers": {
"io-usefulapi-learnworlds": {
"Transport": "http",
"Url": "https://learnworlds.usefulapi.io/mcp"
}
}
} assistant mcp add io-usefulapi-learnworlds -t streamable-http -u 'https://learnworlds.usefulapi.io/mcp'
{
"mcpServers": {
"io-usefulapi-learnworlds": {
"type": "http",
"url": "https://learnworlds.usefulapi.io/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Oct 26 +1
- Server version: 1.3.0 → 1.5.1 functional
- 1 Oct 26 +5
- HTTPS: unverified → pass ▲ security
- Stability: unverified → 0.03 ▲ functional
- Server version: 1.0.0 → 1.3.0 functional
- 30 Sept 26 +53
- Authorization: unverified → pass ▲ security
- Injection markers: unverified → pass ▲ security
- Transport: fail → pass ▲ security
- First check of Judged manipulation: pass security
- First check of Authorization: partial security
- MCP protocol: unverified → fail ▼ functional
- Tool coverage: unverified → 100 ▲ functional
- First check of Schema quality: fail functional
- First check of Tool coverage: 89 functional
- First check of Schema quality: excellent functional
- First check of Destructive annotations: pass functional
- First check of Schema quality: fail functional
- 29 Sept 26 18
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Oct 2026 · Probed https://learnworlds.usefulapi.io/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=usefulapi.io | CN=WE1,O=Google Trust Services,C=US | 13 Sept 2026 | 12 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | d9be3287b0fde9630e825ba1f79bff3f |
| SANs: usefulapi.io, *.usefulapi.io | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of learnworlds.usefulapi.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| usefulapi.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer realm="OAuth", resource_metadata="https://learnworlds.usefulapi.io/.well-known/oauth-protected-resource/mcp"
Bearer realm="OAuth", resource_metadata="https://learnworlds.usefulapi.io/.well-known/oauth-protected-resource/mcp" Protected resource metadata
| Document | https://learnworlds.usefulapi.io/.well-known/oauth-protected-resource/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://learnworlds.usefulapi.io/mcp |
| Authorisation server | https://learnworlds.usefulapi.io |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://learnworlds.usefulapi.io/mcp | Verified | 200 | |
| http (plaintext) | http://learnworlds.usefulapi.io/mcp | HTTPS enforced | 301 | https://learnworlds.usefulapi.io/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
learnworlds_add_user_to_group Add a user to a user group ~85
WRITE: add an existing user to a user group (which may enroll them in the group's products). LearnWorlds: POST /v2/user_groups/{id}/users/{uid}.
| Name | Type | Req | Description |
|---|---|---|---|
| group_id | string | yes | The user group id (from learnworlds_list_user_groups). |
| user | string | yes | The user's id, or their email address. |
No output schema declared.
No examples provided.
learnworlds_create_user Create a user ~213
WRITE: create a learner account. Deliberately no password or admin flag — set send_registration_email so the learner sets their own password. LearnWorlds: POST /v2/users.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | The user's email. | |
| fields | object | – | Sign-up fields to set, e.g. {"company": "Acme", "phone": "+1..."}. Built-in keys include bio, location, url, phone, address, country, birthday, company, company_size, university, graduation_year and… |
| send_registration_email | boolean | – | Send LearnWorlds' registration email to the user. |
| signup_validation_rules | boolean | – | Apply the school's sign-up validation rules (default false). |
| subscribed_for_marketing_emails | boolean | – | Marketing-email consent. |
| tags | array | – | Tags to attach to the new user. |
| username | string | yes | The user's username (display name). |
No output schema declared.
No examples provided.
learnworlds_enroll_user Enroll a user in a product ~199
WRITE: manually enroll a user in a course, bundle or subscription. This grants access and records a manual enrollment at the given price (use 0 for a free grant) — it does not charge the learner's card. Optionally emails the learner. LearnWorlds: POST /v2/users/{id}/enrollment.
| Name | Type | Req | Description |
|---|---|---|---|
| duration | integer | – | Subscriptions only: how many duration_type units. |
| duration_type | string | – | Subscriptions only. |
| justification | string | – | A note, e.g. "Added by admin". |
| price | number | yes | Price recorded for this enrollment; 0 for a free grant. |
| product_id | string | yes | The product id (for a course, its slug). |
| product_type | string | yes | – |
| send_enrollment_email | boolean | – | Send the enrollment email to the learner. |
| user | string | yes | The user's id, or their email address. |
No output schema declared.
No examples provided.
learnworlds_get_course Get a course ~56
Fetch one course by id (its slug). LearnWorlds: GET /v2/courses/{id}.
| Name | Type | Req | Description |
|---|---|---|---|
| course_id | string | yes | The course id — the course slug, e.g. "my-first-course". |
No output schema declared.
No examples provided.
learnworlds_get_course_analytics Get course analytics ~81
Course-level analytics: students, learning units, average score and success rate, total study time, average time to finish, social interactions and certificates issued. LearnWorlds: GET /v2/courses/{id}/analytics.
| Name | Type | Req | Description |
|---|---|---|---|
| course_id | string | yes | The course id — the course slug, e.g. "my-first-course". |
No output schema declared.
No examples provided.
learnworlds_get_course_contents Get course contents ~85
The course outline: its sections (with drip-feed settings) and the learning activities (videos, PDFs, SCORM, assessments, certificates...) in each, with their ids. LearnWorlds: GET /v2/courses/{id}/contents.
| Name | Type | Req | Description |
|---|---|---|---|
| course_id | string | yes | The course id — the course slug, e.g. "my-first-course". |
No output schema declared.
No examples provided.
learnworlds_get_course_grades Get course grades ~162
Assessment grades of the users enrolled in a course — per user and learning unit, with submission time. LearnWorlds: GET /v2/courses/{id}/grades.
| Name | Type | Req | Description |
|---|---|---|---|
| course_id | string | yes | The course id — the course slug, e.g. "my-first-course". |
| items_per_page | integer | – | Items per page, 1-200. |
| learning_units | string | – | Comma-separated learning-unit ids to filter by (from learnworlds_get_course_contents). |
| order | string | – | Sort direction. |
| page | integer | – | Page number, starting at 1. |
| sort | string | – | Field to sort by. |
| users | string | – | Comma-separated user ids to filter by. |
No output schema declared.
No examples provided.
learnworlds_get_payment Get a payment ~49
Fetch one payment by payment id or transaction id. LearnWorlds: GET /v2/payments/{id}.
| Name | Type | Req | Description |
|---|---|---|---|
| payment_id | string | yes | The payment id or the transaction id. |
No output schema declared.
No examples provided.
learnworlds_get_user Get a user ~77
Fetch one user by id or email — profile, role, tags, sign-up fields, UTMs and last login. LearnWorlds: GET /v2/users/{id}.
| Name | Type | Req | Description |
|---|---|---|---|
| include_suspended | boolean | – | Also return the user if suspended. |
| user | string | yes | The user's id, or their email address. |
No output schema declared.
No examples provided.
learnworlds_get_user_course_progress Get a user's progress in a course ~101
A user's progress in one course — status, progress rate, average score, time on course, completed units, and a per-section / per-activity breakdown. LearnWorlds: GET /v2/users/{id}/courses/{cid}/progress.
| Name | Type | Req | Description |
|---|---|---|---|
| course_id | string | yes | The course id — the course slug, e.g. "my-first-course". |
| user | string | yes | The user's id, or their email address. |
No output schema declared.
No examples provided.
learnworlds_list_certificates List certificates ~99
Certificates awarded, newest first (20 per page), for a course and/or a user — at least one of course_id or user_id is required. LearnWorlds: GET /v2/certificates.
| Name | Type | Req | Description |
|---|---|---|---|
| course_id | string | – | Only certificates for this course id. |
| page | integer | – | Page number, starting at 1. |
| user_id | string | – | Only certificates of this user (id or email). |
No output schema declared.
No examples provided.
learnworlds_list_course_users List users enrolled in a course ~97
The users enrolled in one course, newest first (20 per page by default). LearnWorlds: GET /v2/courses/{id}/users.
| Name | Type | Req | Description |
|---|---|---|---|
| course_id | string | yes | The course id — the course slug, e.g. "my-first-course". |
| items_per_page | integer | – | Items per page, 1-200. |
| page | integer | – | Page number, starting at 1. |
No output schema declared.
No examples provided.
learnworlds_list_courses List courses ~104
List the school's courses, newest first, 50 per page — title, price fields, access (paid/free/draft...), categories and author. A cheap way to confirm the credentials work. LearnWorlds: GET /v2/courses.
| Name | Type | Req | Description |
|---|---|---|---|
| access | array | – | Only courses with one of these access values. |
| categories | string | – | Comma-separated category names to filter by. |
| page | integer | – | Page number, starting at 1. |
No output schema declared.
No examples provided.
learnworlds_list_event_logs List event logs ~168
The school's activity log (50 per page) — registrations, logins, purchases, enrollments, course completions, certificates, subscription changes and more, filterable by user, activity and time. LearnWorlds: GET /v2/event-logs.
| Name | Type | Req | Description |
|---|---|---|---|
| activity | string | – | Only this kind of event. |
| created_after | number | – | Created after (Unix timestamp in seconds, e.g. 1626088013). |
| created_before | number | – | Created before (Unix timestamp in seconds, e.g. 1626088013). |
| page | integer | – | Page number, starting at 1. |
| sort | string | – | By creation time; default desc. |
| user_id | string | – | Only events of this user (id or email). |
No output schema declared.
No examples provided.
learnworlds_list_payments List payments ~195
List payments, newest first (50 per page by default) — product, price, discount, tax, coupon, affiliate, gateway and billing info. All filters are ANDed. LearnWorlds: GET /v2/payments.
| Name | Type | Req | Description |
|---|---|---|---|
| affiliate_id | string | – | Only payments referred by this affiliate (id or email). |
| created_after | number | – | Created after (Unix timestamp in seconds, e.g. 1626088013). |
| created_before | number | – | Created before (Unix timestamp in seconds, e.g. 1626088013). |
| items_per_page | integer | – | Items per page, 1-200. |
| page | integer | – | Page number, starting at 1. |
| product_id | string | – | Only payments for this product id. |
| product_type | string | – | – |
| user_id | string | – | Only payments by this user (id or email). |
No output schema declared.
No examples provided.
learnworlds_list_user_courses List a user's course enrollments ~73
The courses a user is enrolled in, with enrollment and expiry dates (50 per page). LearnWorlds: GET /v2/users/{id}/courses.
| Name | Type | Req | Description |
|---|---|---|---|
| page | integer | – | Page number, starting at 1. |
| user | string | yes | The user's id, or their email address. |
No output schema declared.
No examples provided.
learnworlds_list_user_groups List user groups ~66
List the school's user groups (cohorts / B2B seats), newest first — title, products, group managers, capacity and tags. LearnWorlds: GET /v2/user_groups.
| Name | Type | Req | Description |
|---|---|---|---|
| page | integer | – | Page number, starting at 1. |
No output schema declared.
No examples provided.
learnworlds_list_users List users ~211
List the school's users, newest first (20 per page by default), filterable by status, role, tags, registration date and custom fields. All filters are ANDed. LearnWorlds: GET /v2/users.
| Name | Type | Req | Description |
|---|---|---|---|
| custom_fields | object | – | Custom-field filters, e.g. {"cf_skill": "Excel"}. The cf_ prefix is added if missing. |
| include_suspended | boolean | – | Include suspended users (default false). |
| items_per_page | integer | – | Items per page, 1-200. |
| page | integer | – | Page number, starting at 1. |
| registration_after | number | – | Registered after (Unix timestamp in seconds, e.g. 1626088013). |
| registration_before | number | – | Registered before (Unix timestamp in seconds, e.g. 1626088013). |
| role | string | – | – |
| status | string | – | – |
| tags | string | – | Comma-separated tags; users with these tags. |
No output schema declared.
No examples provided.
learnworlds_update_user Update a user ~205
WRITE: update a user's email, username, marketing consent, sign-up fields or tags. Only the fields you pass are sent. Passing `tags` REPLACES the tag list — use learnworlds_update_user_tags to add/remove individual tags. LearnWorlds: PUT /v2/users/{id}.
| Name | Type | Req | Description |
|---|---|---|---|
| string | – | – | |
| fields | object | – | Sign-up fields to set, e.g. {"company": "Acme", "phone": "+1..."}. Built-in keys include bio, location, url, phone, address, country, birthday, company, company_size, university, graduation_year and… |
| subscribed_for_marketing_emails | boolean | – | – |
| tags | array | – | The complete new tag list (replaces existing tags). |
| user | string | yes | The user's id, or their email address. |
| username | string | – | – |
No output schema declared.
No examples provided.
learnworlds_update_user_tags Attach or detach user tags ~90
WRITE: add (attach) or remove (detach) tags on a user, leaving their other tags untouched. Reversible with the opposite action. LearnWorlds: PUT /v2/users/{id}/tags.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | – |
| tags | array | yes | The tags to attach or detach. |
| user | string | yes | The user's id, or their email address. |
No output schema declared.
No examples provided.
What is the io.usefulapi/learnworlds MCP server?
io.usefulapi/learnworlds is an MCP server listed in the public MCP registry as io.usefulapi/learnworlds. Check LearnWorlds courses, learners, progress, grades and payments, and enroll or tag users. This page covers its hosted endpoint (https://learnworlds.usefulapi.io/mcp).
Is the io.usefulapi/learnworlds MCP server safe to use?
io.usefulapi/learnworlds scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.usefulapi/learnworlds MCP server expose?
io.usefulapi/learnworlds exposes 20 tools: learnworlds_list_courses, learnworlds_get_course, learnworlds_get_course_contents, learnworlds_get_course_analytics, learnworlds_list_course_users, and 15 more. Their descriptions and schemas cost roughly 2,416 tokens of context every time the server is loaded.
Does the io.usefulapi/learnworlds MCP server require authentication?
Yes. io.usefulapi/learnworlds asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the io.usefulapi/learnworlds MCP server still maintained?
io.usefulapi/learnworlds is still listed as active in the MCP registry. We last reached this channel on 3 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.