Canvas Access Tokens API

The Access Tokens API from Canvas — 3 operation(s) for access tokens.

Operations 5

GET /v1/users/{user_id}/user_generated_tokens List access tokens for a user #
GET /v1/users/{user_id}/tokens/{id} Show an access token #
PUT /v1/users/{user_id}/tokens/{id} Update an access token #
DELETE /v1/users/{user_id}/tokens/{id} Delete an access token #
POST /v1/users/{user_id}/tokens Create an access token #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/canvas-access-tokens-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

canvas-access-tokens-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Canvas LMS REST Access Tokens API
  version: v1
  summary: The complete Canvas LMS REST API, converted from the Swagger 1.2 documents Instructure publishes under https://canvas.instructure.com/doc/api/.
  description: The Canvas LMS REST API covers courses, assignments, quizzes, grades, users, enrollments, accounts, files, modules, rubrics, submissions, SIS imports, LTI, analytics and account administration.
  contact:
    name: Instructure Canvas
    url: https://canvas.instructure.com/doc/api/
  license:
    name: AGPL-3.0
    url: https://github.com/instructure/canvas-lms/blob/master/LICENSE
servers:
- url: https://canvas.instructure.com/api
  description: Instructure-hosted Canvas (canvas.instructure.com)
- url: https://{canvas_host}/api
  description: Any Canvas instance; Canvas is multi-tenant and self-hostable, so the host is the institution's Canvas domain.
  variables:
    canvas_host:
      default: canvas.instructure.com
      description: Your institution's Canvas hostname, e.g. school.instructure.com
security:
- bearerAuth: []
- oauth2: []
tags:
- name: Access Tokens
  x-resource: access_tokens
  externalDocs:
    url: https://canvas.instructure.com/doc/api/access_tokens.html
paths:
  /v1/users/{user_id}/user_generated_tokens:
    get:
      tags:
      - Access Tokens
      operationId: list_access_tokens_for_user
      summary: List access tokens for a user
      description: 'Returns a list of manually generated access tokens for the specified user.

        Note that the actual token values are only returned when the token is first created.'
      parameters:
      - name: user_id
        in: path
        schema:
          type: string
        required: true
        description: ID
      - name: per_page
        in: query
        schema:
          type: integer
          format: int64
        required: false
        description: The number of results to return per page. Defaults to 10. Maximum of 100.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/Token'
      externalDocs:
        url: https://canvas.instructure.com/doc/api/access_tokens.html
  /v1/users/{user_id}/tokens/{id}:
    get:
      tags:
      - Access Tokens
      operationId: show_access_token
      summary: Show an access token
      description: The ID can be the actual database ID of the token, or the 'token_hint' value.
      parameters:
      - name: user_id
        in: path
        schema:
          type: string
        required: true
        description: ID
      - name: id
        in: path
        schema:
          type: string
        required: true
        description: ID
      responses:
        '200':
          description: Success, no content returned
      externalDocs:
        url: https://canvas.instructure.com/doc/api/access_tokens.html
    put:
      tags:
      - Access Tokens
      operationId: update_access_token
      summary: Update an access token
      description: 'Update an existing access token.


        The ID can be the actual database ID of the token, or the ''token_hint'' value.


        Regenerating an expired token requires a new expiration date.'
      parameters:
      - name: user_id
        in: path
        schema:
          type: string
        required: true
        description: ID
      - name: id
        in: path
        schema:
          type: string
        required: true
        description: ID
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                token[purpose]:
                  type: string
                  description: The purpose of the token.
                token[expires_at]:
                  type: string
                  format: date-time
                  description: The time at which the token will expire.
                token[scopes]:
                  type: array
                  items:
                    type: array
                    items: {}
                  description: The scopes to associate with the token.
                token[regenerate]:
                  type: boolean
                  description: Regenerate the actual token.
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                token[purpose]:
                  type: string
                  description: The purpose of the token.
                token[expires_at]:
                  type: string
                  format: date-time
                  description: The time at which the token will expire.
                token[scopes]:
                  type: array
                  items:
                    type: array
                    items: {}
                  description: The scopes to associate with the token.
                token[regenerate]:
                  type: boolean
                  description: Regenerate the actual token.
      responses:
        '200':
          description: Success, no content returned
      externalDocs:
        url: https://canvas.instructure.com/doc/api/access_tokens.html
    delete:
      tags:
      - Access Tokens
      operationId: delete_access_token
      summary: Delete an access token
      description: The ID can be the actual database ID of the token, or the 'token_hint' value.
      parameters:
      - name: user_id
        in: path
        schema:
          type: string
        required: true
        description: ID
      - name: id
        in: path
        schema:
          type: string
        required: true
        description: ID
      responses:
        '200':
          description: Success, no content returned
      externalDocs:
        url: https://canvas.instructure.com/doc/api/access_tokens.html
  /v1/users/{user_id}/tokens:
    post:
      tags:
      - Access Tokens
      operationId: create_access_token
      summary: Create an access token
      description: 'Create a new access token for the specified user.

        If the user is not the current user, the token will be created as "pending",

        and must be activated by the user before it can be used.'
      parameters:
      - name: user_id
        in: path
        schema:
          type: string
        required: true
        description: ID
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                token[purpose]:
                  type: string
                  description: The purpose of the token.
                token[expires_at]:
                  type: string
                  format: date-time
                  description: The time at which the token will expire.
                token[scopes]:
                  type: array
                  items:
                    type: array
                    items: {}
                  description: 'The scopes to associate with the token.

                    Ignored if the default developer key does not have the "enable scopes" option enabled.

                    In such cases, the token will inherit the user''s permissions instead.'
              required:
              - token[purpose]
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                token[purpose]:
                  type: string
                  description: The purpose of the token.
                token[expires_at]:
                  type: string
                  format: date-time
                  description: The time at which the token will expire.
                token[scopes]:
                  type: array
                  items:
                    type: array
                    items: {}
                  description: 'The scopes to associate with the token.

                    Ignored if the default developer key does not have the "enable scopes" option enabled.

                    In such cases, the token will inherit the user''s permissions instead.'
              required:
              - token[purpose]
      responses:
        '200':
          description: Success, no content returned
      externalDocs:
        url: https://canvas.instructure.com/doc/api/access_tokens.html
components:
  schemas:
    Token:
      type: object
      properties:
        id:
          type: integer
          description: The internal database ID of the token.
        created_at:
          type: string
          description: The time the token was created.
        expires_at:
          type: array
          items:
            type: string
            x-canvas-declared-type: '''string'', ''null'''
          description: The time the token will permanently expire, or null if it does not permanently expire.
        workflow_state:
          type: string
          description: The current state of the token. One of 'active', 'pending', 'disabled', or 'deleted'.
        remember_access:
          type: boolean
          description: Whether the token should be remembered across sessions. Only applicable for OAuth tokens.
        scopes:
          type: array
          items:
            type: string
          description: The scopes associated with the token. If empty, there are no scope limitations.
        real_user_id:
          type: array
          items:
            type: string
            x-canvas-declared-type: '''integer'', ''null'''
          description: If the token was created while masquerading, this is the ID of the real user. Otherwise, null.
        token:
          type: string
          description: The actual access token. Only included when the token is first created.
        token_hint:
          type: string
          description: A short, unique string that can be used to look up the token.
        user_id:
          type: integer
          description: The ID of the user the token belongs to.
        purpose:
          type: string
          description: The purpose of the token.
        app_name:
          type: array
          items:
            type: string
            x-canvas-declared-type: '''string'', ''null'''
          description: If the token was created by an OAuth application, this is the name of that application. Otherwise, null.
        can_manually_regenerate:
          type: boolean
          description: Whether the current user can manually regenerate this token.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'Canvas OAuth2 access token sent as "Authorization: Bearer <token>". See https://canvas.instructure.com/doc/api/file.oauth.html'
    oauth2:
      type: oauth2
      description: Canvas OAuth2. See https://canvas.instructure.com/doc/api/file.oauth.html and https://canvas.instructure.com/doc/api/file.oauth_endpoints.html
      flows:
        authorizationCode:
          authorizationUrl: https://canvas.instructure.com/login/oauth2/auth
          tokenUrl: https://canvas.instructure.com/login/oauth2/token
          refreshUrl: https://canvas.instructure.com/login/oauth2/token
          scopes: {}
externalDocs:
  description: Canvas LMS REST API Documentation
  url: https://canvas.instructure.com/doc/api/
x-generated-from: https://canvas.instructure.com/doc/api/api-docs.json
x-provenance:
  method: derived
  derived_by: API Evangelist enrichment pipeline (Swagger 1.2 -> OpenAPI 3.1 conversion)
  source: openapi/_original/swagger-1.2/*.json (144 verbatim first-party Swagger 1.2 documents)
  source_url: https://canvas.instructure.com/doc/api/api-docs.json
  fetched: '2026-09-05'
  http_status: 200