Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To connect an application to Canvas LMS on behalf of a user, register a developer key, send the user through Canvas’s OAuth 2.0 authorization-code flow, exchange the returned code for a token, and call the API with a bearer token over HTTPS. The setup depends on the Canvas host, administrator-enabled key and scopes, and whether your app is a confidential server or a public client such as a SPA or mobile app.

Choose the OAuth flow that matches the job

For an application acting on behalf of an individual Canvas user, use Canvas API OAuth authorization. The user authorizes access through their Canvas installation; the resulting token represents that authorization.

Do not confuse this with LTI Advantage service authentication. LTI services use a separate client-credentials flow with a signed JWT assertion, and the resulting service access is limited to resources associated with a deployed tool. Choose that flow for an LTI service, not as a substitute for a user-authorized API integration. Canvas OAuth documentation

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Register and configure a developer key

A Canvas developer key supplies the OAuth client identity and, for confidential clients, its secret. On Canvas Cloud, an institution administrator issues and enables the key. An open-source Canvas installation can create credentials through site administration. A key created in a root account applies to that account and its subaccounts; globally created keys can function in accounts where enabled. Ask the administrator responsible for the target account to confirm the right key and enablement.

Configure the key with only the API endpoint scopes the integration needs. Scopes are expressed as an HTTP method and Canvas endpoint path. Requested scopes must be allowed by the key; a call outside the granted scope can return 401 Unauthorized. Disabling a key can block authorization or API requests, and removing a scope invalidates tokens derived from that key. Canvas Developer Keys documentation

If your service supports multiple institutions, treat each Canvas host and its key configuration as institution-specific rather than assuming one key works everywhere. Canvas specifically advises LTI providers to store and look up the appropriate institution-scoped key using launch information such as custom_canvas_api_domain. Canvas OAuth documentation

Authorize a user and exchange the code

  1. Redirect the user to the authorization endpoint on their own Canvas host: https://<canvas-host>/login/oauth2/auth. Include client_id, response_type=code, your registered redirect_uri, a unique state value, and the scopes needed. Canvas documents code as the supported response type.

    Free tools Windows power users keep installed

    One-click scans. No signup required.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. When Canvas redirects back, validate the returned state against the value stored for that authorization attempt before using the response. A successful response includes an authorization code; a denied request or other authorization error returns an error parameter instead. Handle that error rather than attempting a token exchange. Canvas OAuth documentation

  3. Send the code to POST https://<canvas-host>/login/oauth2/token with grant_type=authorization_code, the client credentials appropriate to the client type, the code, and the same redirect URI if one was supplied in the authorization request.

  4. Store the token response securely and continue with the API request. Canvas invalidates the authorization code after exchange, so if a later part of the exchange fails and the code cannot be used again, restart authorization. Never place a confidential client’s secret in public application code. Canvas OAuth documentation

Make API requests and manage token expiry

Send the access token in the HTTP authorization header over HTTPS:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Authorization: Bearer <access-token>

Canvas supports tokens in query strings or POST parameters but discourages those methods because URLs and request data may be logged or exposed. Store tokens securely, avoid logging them, and do not ask users to create personal access tokens for a multi-user application; Canvas says that practice violates its API policy. Canvas OAuth documentation

The general Canvas OAuth guide says access tokens have a one-hour lifespan. Its documented confidential-client refresh flow uses grant_type=refresh_token; the response provides a new access token and the same refresh token is reused. Read the response’s expires_in value rather than relying only on a locally assumed expiry time. Handle authorization and refresh errors without writing credentials or tokens to logs. Canvas OAuth documentation

Apply the public-client rules where relevant

Canvas’s Developer Keys API reference describes a client_type setting. Public clients, including single-page applications and mobile apps, require PKCE in the authorization-code flow, cannot use client credentials, and receive short-lived access tokens with rotating refresh tokens. This differs from the general guide’s confidential-client refresh description, so do not reuse that refresh-token assumption for a public client. Verify that the target Canvas version and key configuration support the specific flow you intend to deploy. Canvas Developer Keys API reference

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Diagnose common integration failures

Plan around scopes and documentation changes

Canvas’s Developer Keys documentation states an 8,000-character maximum HTTP header size, which limits how many scopes a client can request in a single token request. Keep the requested scope set focused on the endpoints the integration actually uses. Canvas Developer Keys documentation

Canvas documentation indicates that it is moving to the Instructure Developer Documentation Portal after July 1, 2026. Because key configuration, scope behavior, and public-client support can vary with deployment and change over time, confirm current guidance in that portal and with the administrator of the target Canvas installation before release. Canvas OAuth documentation

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.