Canvas Content Security Policy Settings API

The Content Security Policy Settings API from Canvas — 5 operation(s) for content security policy settings.

Operations 8

GET /v1/courses/{course_id}/csp_settings Get current settings for account or course #
PUT /v1/courses/{course_id}/csp_settings Enable, disable, or clear explicit CSP setting #
GET /v1/accounts/{account_id}/csp_settings Get current settings for account or course #
PUT /v1/accounts/{account_id}/csp_settings Enable, disable, or clear explicit CSP setting #
PUT /v1/accounts/{account_id}/csp_settings/lock Lock or unlock current CSP settings for sub-accounts and courses #
POST /v1/accounts/{account_id}/csp_settings/domains Add an allowed domain to account #
DELETE /v1/accounts/{account_id}/csp_settings/domains Remove a domain from account #
POST /v1/accounts/{account_id}/csp_settings/domains/batch_create Add multiple allowed domains to an account #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/canvas-content-security-policy-settings-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

canvas-content-security-policy-settings-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Canvas LMS REST Content Security Policy Settings API
  version: v1
  summary: The complete Canvas LMS REST API, converted from the Swagger 1.2 documents Instructure publishes under https://canvas.instructure.com/doc/api/.
  description: The Canvas LMS REST API covers courses, assignments, quizzes, grades, users, enrollments, accounts, files, modules, rubrics, submissions, SIS imports, LTI, analytics and account administration.
  contact:
    name: Instructure Canvas
    url: https://canvas.instructure.com/doc/api/
  license:
    name: AGPL-3.0
    url: https://github.com/instructure/canvas-lms/blob/master/LICENSE
servers:
- url: https://canvas.instructure.com/api
  description: Instructure-hosted Canvas (canvas.instructure.com)
- url: https://{canvas_host}/api
  description: Any Canvas instance; Canvas is multi-tenant and self-hostable, so the host is the institution's Canvas domain.
  variables:
    canvas_host:
      default: canvas.instructure.com
      description: Your institution's Canvas hostname, e.g. school.instructure.com
security:
- bearerAuth: []
- oauth2: []
tags:
- name: Content Security Policy Settings
  x-resource: content_security_policy_settings
  externalDocs:
    url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html
paths:
  /v1/courses/{course_id}/csp_settings:
    get:
      tags:
      - Content Security Policy Settings
      operationId: get_current_settings_for_account_or_course_courses
      summary: Get current settings for account or course
      description: Update multiple modules in an account.
      parameters:
      - name: course_id
        in: path
        schema:
          type: string
        required: true
        description: ID
      responses:
        '200':
          description: Success, no content returned
      externalDocs:
        url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html
    put:
      tags:
      - Content Security Policy Settings
      operationId: enable_disable_or_clear_explicit_csp_setting_courses
      summary: Enable, disable, or clear explicit CSP setting
      description: 'Either explicitly sets CSP to be on or off for courses and sub-accounts,

        or clear the explicit settings to default to those set by a parent account


        Note: If "inherited" and "settings_locked" are both true for this account or course,

        then the CSP setting cannot be modified.'
      parameters:
      - name: course_id
        in: path
        schema:
          type: string
        required: true
        description: ID
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                status:
                  type: string
                  enum:
                  - enabled
                  - disabled
                  - inherited
                  description: 'If set to "enabled" for an account, CSP will be enabled for all its courses and sub-accounts (that

                    have not explicitly enabled or disabled it), using the allowed domains set on this account.

                    If set to "disabled", CSP will be disabled for this account or course and for all sub-accounts

                    that have not explicitly re-enabled it.

                    If set to "inherited", this account or course will reset to the default state where CSP settings

                    are inherited from the first parent account to have them explicitly set.'
              required:
              - status
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                status:
                  type: string
                  enum:
                  - enabled
                  - disabled
                  - inherited
                  description: 'If set to "enabled" for an account, CSP will be enabled for all its courses and sub-accounts (that

                    have not explicitly enabled or disabled it), using the allowed domains set on this account.

                    If set to "disabled", CSP will be disabled for this account or course and for all sub-accounts

                    that have not explicitly re-enabled it.

                    If set to "inherited", this account or course will reset to the default state where CSP settings

                    are inherited from the first parent account to have them explicitly set.'
              required:
              - status
      responses:
        '200':
          description: Success, no content returned
      externalDocs:
        url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html
  /v1/accounts/{account_id}/csp_settings:
    get:
      tags:
      - Content Security Policy Settings
      operationId: get_current_settings_for_account_or_course_accounts
      summary: Get current settings for account or course
      description: Update multiple modules in an account.
      parameters:
      - name: account_id
        in: path
        schema:
          type: string
        required: true
        description: ID
      responses:
        '200':
          description: Success, no content returned
      externalDocs:
        url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html
    put:
      tags:
      - Content Security Policy Settings
      operationId: enable_disable_or_clear_explicit_csp_setting_accounts
      summary: Enable, disable, or clear explicit CSP setting
      description: 'Either explicitly sets CSP to be on or off for courses and sub-accounts,

        or clear the explicit settings to default to those set by a parent account


        Note: If "inherited" and "settings_locked" are both true for this account or course,

        then the CSP setting cannot be modified.'
      parameters:
      - name: account_id
        in: path
        schema:
          type: string
        required: true
        description: ID
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                status:
                  type: string
                  enum:
                  - enabled
                  - disabled
                  - inherited
                  description: 'If set to "enabled" for an account, CSP will be enabled for all its courses and sub-accounts (that

                    have not explicitly enabled or disabled it), using the allowed domains set on this account.

                    If set to "disabled", CSP will be disabled for this account or course and for all sub-accounts

                    that have not explicitly re-enabled it.

                    If set to "inherited", this account or course will reset to the default state where CSP settings

                    are inherited from the first parent account to have them explicitly set.'
              required:
              - status
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                status:
                  type: string
                  enum:
                  - enabled
                  - disabled
                  - inherited
                  description: 'If set to "enabled" for an account, CSP will be enabled for all its courses and sub-accounts (that

                    have not explicitly enabled or disabled it), using the allowed domains set on this account.

                    If set to "disabled", CSP will be disabled for this account or course and for all sub-accounts

                    that have not explicitly re-enabled it.

                    If set to "inherited", this account or course will reset to the default state where CSP settings

                    are inherited from the first parent account to have them explicitly set.'
              required:
              - status
      responses:
        '200':
          description: Success, no content returned
      externalDocs:
        url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html
  /v1/accounts/{account_id}/csp_settings/lock:
    put:
      tags:
      - Content Security Policy Settings
      operationId: lock_or_unlock_current_csp_settings_for_sub_accounts_and_courses
      summary: Lock or unlock current CSP settings for sub-accounts and courses
      description: Can only be set if CSP is explicitly enabled or disabled on this account (i.e. "inherited" is false).
      parameters:
      - name: account_id
        in: path
        schema:
          type: string
        required: true
        description: ID
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                settings_locked:
                  type: boolean
                  description: Whether sub-accounts and courses will be prevented from overriding settings inherited from this account.
              required:
              - settings_locked
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                settings_locked:
                  type: boolean
                  description: Whether sub-accounts and courses will be prevented from overriding settings inherited from this account.
              required:
              - settings_locked
      responses:
        '200':
          description: Success, no content returned
      externalDocs:
        url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html
  /v1/accounts/{account_id}/csp_settings/domains:
    post:
      tags:
      - Content Security Policy Settings
      operationId: add_allowed_domain_to_account
      summary: Add an allowed domain to account
      description: 'Adds an allowed domain for the current account. Note: this will not take effect

        unless CSP is explicitly enabled on this account.'
      parameters:
      - name: account_id
        in: path
        schema:
          type: string
        required: true
        description: ID
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                domain:
                  type: string
                  description: no description
              required:
              - domain
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                domain:
                  type: string
                  description: no description
              required:
              - domain
      responses:
        '200':
          description: Success, no content returned
      externalDocs:
        url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html
    delete:
      tags:
      - Content Security Policy Settings
      operationId: remove_domain_from_account
      summary: Remove a domain from account
      description: Removes an allowed domain from the current account.
      parameters:
      - name: account_id
        in: path
        schema:
          type: string
        required: true
        description: ID
      - name: domain
        in: query
        schema:
          type: string
        required: true
        description: no description
      responses:
        '200':
          description: Success, no content returned
      externalDocs:
        url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html
  /v1/accounts/{account_id}/csp_settings/domains/batch_create:
    post:
      tags:
      - Content Security Policy Settings
      operationId: add_multiple_allowed_domains_to_account
      summary: Add multiple allowed domains to an account
      description: 'Adds multiple allowed domains for the current account. Note: this will not take effect

        unless CSP is explicitly enabled on this account.'
      parameters:
      - name: account_id
        in: path
        schema:
          type: string
        required: true
        description: ID
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                domains:
                  type: array
                  items: {}
                  description: no description
              required:
              - domains
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                domains:
                  type: array
                  items: {}
                  description: no description
              required:
              - domains
      responses:
        '200':
          description: Success, no content returned
      externalDocs:
        url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'Canvas OAuth2 access token sent as "Authorization: Bearer <token>". See https://canvas.instructure.com/doc/api/file.oauth.html'
    oauth2:
      type: oauth2
      description: Canvas OAuth2. See https://canvas.instructure.com/doc/api/file.oauth.html and https://canvas.instructure.com/doc/api/file.oauth_endpoints.html
      flows:
        authorizationCode:
          authorizationUrl: https://canvas.instructure.com/login/oauth2/auth
          tokenUrl: https://canvas.instructure.com/login/oauth2/token
          refreshUrl: https://canvas.instructure.com/login/oauth2/token
          scopes: {}
externalDocs:
  description: Canvas LMS REST API Documentation
  url: https://canvas.instructure.com/doc/api/
x-generated-from: https://canvas.instructure.com/doc/api/api-docs.json
x-provenance:
  method: derived
  derived_by: API Evangelist enrichment pipeline (Swagger 1.2 -> OpenAPI 3.1 conversion)
  source: openapi/_original/swagger-1.2/*.json (144 verbatim first-party Swagger 1.2 documents)
  source_url: https://canvas.instructure.com/doc/api/api-docs.json
  fetched: '2026-09-05'
  http_status: 200