Body
An access token in Canvas is a digital key that lets outside programs connect to your account through the Canvas API. Because these access tokens potentially expose FERPA-protected student information both Instructure (the parent company of Canvas) and IET have some guidelines for their use.
User-Generated Access Token Guidelines
- API tokens may only be generated by Canvas administrators and Instructors (Teacher role in Canvas).
- All user-generated Access Tokens created by Teachers have a mandatory expiration date set to no more than 90 days after creation.
- Students are not allowed to generate tokens.
- Applications integrated with Canvas may generate access tokens because they have been vetted for security.
- IET can revoke API tokens at any given time (e.g., for security concerns).
Limiting the issuance of user tokens is an important security and stability requirement for maintaining our LMS environment. Risks include:
- Data security: Granting API access increases the risk of a potential data breach. If an unmanaged or improperly secured application gains access, sensitive student and institutional data could be compromised. In addition, user tokens circumvent multi-factor authentication and university SSO authentication requirements.
- Increased risk from AI and third party services: Many AI tools and browser extensions now request Canvas API tokens to analyze coursework, generate summaries or feedback, automate downloads, grading insights, or submissions. These tools often are hosted externally, store tokens insecurely, have unclear data retention policies, and are not contractually vetted by the institution. In effect, users are being asked to delegate full account access to unvetted third parties, creating a risk to student records and institutional systems.
- System instability: Improperly coded or potentially abusive tools such as AI agents can use the token to run extensive numbers of API calls and overload the Canvas system, leading to performance issues, lag, or even system-wide outages for all users.
- Compliance: Restricting access helps us comply with privacy regulations (such as FERPA) by ensuring only authorized systems can process educational records. It also helps us comply with Instructure's API policy.