Summary
This procedure establishes a university standard for requesting, issuing, and managing Canvas Learning Management System (LMS) API access tokens. The objectives of this standard are to:
- Ensure secure and appropriate access to Canvas data through API tokens
- Protect institutional and user data from unauthorized access or misuse
- Provide a consistent and auditable process for requesting and approving API access
- Increase awareness of data security responsibilities among faculty, staff, and students
- Support appropriate academic, instructional, and administrative uses of Canvas data
Purpose
This procedure applies to all users of the Canvas LMS, including faculty, staff, students, and affiliated partners, who request or use API access tokens. The use of API tokens introduces potential risks related to unauthorized access, data exposure, and misuse of institutional information. This procedure establishes safeguards to ensure tokens are issued, used, and managed in a manner consistent with university data security standards and applicable policies.
Student Requests
Students may be granted access to Canvas API tokens under the following conditions:
- A completed access token request form is required prior to issuance.
- Each request must include a faculty sponsor who approves and oversees the intended use.
- API token usage must be directly related to coursework or academic projects.
- Requests for non-course-related use may be considered on an exceptional basis, subject to additional review and approval.
- All student-issued tokens must include an expiration date, not to exceed 30 days from the date of issuance.
- Students are responsible for ensuring their use of the token aligns with university data security and acceptable use policies.
Failure to comply with this procedure may result in revocation of access and further disciplinary action as described in the Acceptable Use of Information Technology Policy.
Faculty and Staff Requests
Faculty and staff may request Canvas API tokens under the following conditions:
- A completed access token request form is required prior to issuance.
- Requests must clearly state the intended use and demonstrate alignment with job responsibilities, instructional duties, or institutional operations.
- API token usage must be directly related to official university business or coursework support.
- All faculty and staff-issued tokens must include an expiration date, not to exceed 90 days from the date of issuance.
Faculty and staff are expected to maintain appropriate stewardship of API tokens and ensure they are not shared, exposed, or used outside their approved purpose. Failure to comply with this procedure may result in revocation of access and further disciplinary action as described in the Acceptable Use of Information Technology Policy.
Use Guidelines
The following guidelines apply to all Canvas API access token usage:
- API tokens are considered sensitive credentials and must be stored securely at all times.
- Tokens must not be shared, transferred, or embedded in publicly accessible code repositories or applications.
- All users must ensure that data accessed via API tokens is handled in accordance with university data classification and security policies.
- Tokens must be deleted immediately if they are no longer needed, compromised, or used outside the approved scope.
- The university reserves the right to audit API token usage to ensure compliance with this procedure.
- Any suspected security incident, misuse, or unauthorized access involving API tokens must be reported promptly to the Office of Information Security.
- Violations of this procedure may result in suspension of access, disciplinary action, and/or escalation in accordance with the Acceptable Use of Information Technology Policy.