Summary
This article reviews the API User token access for Canvas users at USNH.
Content
Canvas user API token access
ET&S centrally controls and reviews any requests for individual Canvas Application Programming Interface (API) user tokens. In most cases alternative solutions to using an API user token will be provided. In limited circumstances and with ET&S approval, faculty or staff may be issued an API user token for a defined period, with the option to request renewal. Students will not be approved for tokens.
What is a Canvas API token?
An API token is a generated string of letters and numbers but it is not a standard password. It is a credential that is intended to grant programmatic access to Canvas. The token could allow software or applications, including AI agents, to read, write, and modify any data, enrollments, courses, and grades to which the associated user has access.
Why do we limit use of API tokens?
Limiting the issuance of user tokens is a critical security and stability requirement for maintaining our LMS environment. These risks include:
-
Data security: Granting API access increases the risk of a potential data breach. If an unmanaged or improperly secured application gains access, sensitive student and institutional data could be compromised. In addition, user tokens circumvent multi-factor authentication and university SSO authentication requirements.
-
Increasing risk from AI and third party services: Many AI tools and browser extensions now request Canvas API tokens to analyze coursework, generate summaries or feedback, automate downloads, grading insights, or submissions. These tools often are hosted externally, store tokens insecurely, have unclear data retention policies, are not contractually vetted by the institution. In effect, users are being asked to delegate full account access to unvetted third parties, creating unacceptable risk to student records and institutional systems. The downstream impact of a compromised token can exceed that of a stolen password, especially since MFA provides no protection. DeepThought and CoPilot while using your University SSO to sign in are the only licensed, approved AI tools for Tier 3 (FERPA data).
-
User accountability: any actions taken using the token are the responsibility of the token holder.
-
System instability: Improperly coded or potentially abusive tools such as AI agents can use the token to run extensive numbers of API calls and overload the Canvas system, leading to performance issues, lag, or even system-wide outages for all users. We must safeguard the system's stability.
-
Compliance: Restricting access helps us comply with privacy regulations (such as FERPA) by ensuring only authorized, vetted systems can process educational records. It also helps us comply with Instructure's API policy. Instructure is the parent company of Canvas.
Clarification on API usage
API access is not prohibited, but must be:
- Provisioned centrally with a managed lifecycle
- Used for approved integrations only
- Secured appropriately
- In support of a legitimate and justified business or academic need
Most institutional needs can still be supported using:
If you have questions, you may send a message through our Canvas Service Request.
Further Readings
USNH AI Tools: Understanding Data Tiers
Instructure API Policy
Canvas: Integrating External Apps (LTI Tools) in a course
Need additional help?
Submit a Canvas (myCourses) support request or visit the Technology Help Desk Support page to locate your local campus contact information or to submit an online technology support request. For password issues you must call or visit the Help Desk in person.