Every API here is available over the APIs.io API and to AI agents over MCP.
openapi: 3.2.0
info:
title: Canvas LMS REST Logins API
version: v1
summary: The complete Canvas LMS REST API, converted from the Swagger 1.2 documents Instructure publishes under https://canvas.instructure.com/doc/api/.
description: The Canvas LMS REST API covers courses, assignments, quizzes, grades, users, enrollments, accounts, files, modules, rubrics, submissions, SIS imports, LTI, analytics and account administration.
contact:
name: Instructure Canvas
url: https://canvas.instructure.com/doc/api/
license:
name: AGPL-3.0
url: https://github.com/instructure/canvas-lms/blob/master/LICENSE
servers:
- url: https://canvas.instructure.com/api
description: Instructure-hosted Canvas (canvas.instructure.com)
- url: https://{canvas_host}/api
description: Any Canvas instance; Canvas is multi-tenant and self-hostable, so the host is the institution's Canvas domain.
variables:
canvas_host:
default: canvas.instructure.com
description: Your institution's Canvas hostname, e.g. school.instructure.com
security:
- bearerAuth: []
- oauth2: []
tags:
- name: Logins
x-resource: logins
externalDocs:
url: https://canvas.instructure.com/doc/api/logins.html
paths:
/v1/accounts/{account_id}/logins:
get:
tags:
- Logins
operationId: list_user_logins_accounts
summary: List user logins
description: Given a user ID, return a paginated list of that user's logins for the given account.
parameters:
- name: account_id
in: path
schema:
type: string
required: true
description: ID
responses:
'200':
description: Success, no content returned
externalDocs:
url: https://canvas.instructure.com/doc/api/logins.html
post:
tags:
- Logins
operationId: create_user_login
summary: Create a user login
description: Create a new login for an existing user in the given account.
parameters:
- name: account_id
in: path
schema:
type: string
required: true
description: ID
requestBody:
required: false
content:
application/json:
schema:
type: object
properties:
user[id]:
type: string
description: The ID of the user to create the login for.
login[unique_id]:
type: string
description: The unique ID for the new login.
login[password]:
type: string
description: The new login's password.
login[sis_user_id]:
type: string
description: 'SIS ID for the login. To set this parameter, the caller must be able to
manage SIS permissions on the account.'
login[integration_id]:
type: string
description: 'Integration ID for the login. To set this parameter, the caller must be able to
manage SIS permissions on the account. The Integration ID is a secondary
identifier useful for more complex SIS integrations.'
login[authentication_provider_id]:
type: string
description: 'The authentication provider this login is associated with. Logins
associated with a specific provider can only be used with that provider.
Legacy providers (LDAP, CAS, SAML) will search for logins associated with
them, or unassociated logins. New providers will only search for logins
explicitly associated with them. This can be the integer ID of the
provider, or the type of the provider (in which case, it will find the
first matching provider).'
login[declared_user_type]:
type: string
description: "The declared intention of the user type. This can be set, but does\nnot change any Canvas functionality with respect to their access.\nA user can still be a teacher, admin, student, etc. in any particular\ncontext without regard to this setting. This can be used for\nadministrative purposes for integrations to be able to more easily\nidentify why the user was created.\nValid values are:\n * administrative\n * observer\n * staff\n * student\n * student_other\n * teacher"
login[must_reset_password]:
type: boolean
description: 'If true, the user will be required to change their password the next time
they sign in with this login. Only valid for logins that support Canvas
passwords.'
user[existing_user_id]:
type: string
description: 'A Canvas User ID to identify a user in a trusted account (alternative to `id`,
`existing_sis_user_id`, or `existing_integration_id`). This parameter is
not available in OSS Canvas.'
user[existing_integration_id]:
type: string
description: 'An Integration ID to identify a user in a trusted account (alternative to `id`,
`existing_user_id`, or `existing_sis_user_id`). This parameter is not
available in OSS Canvas.'
user[existing_sis_user_id]:
type: string
description: 'An SIS User ID to identify a user in a trusted account (alternative to `id`,
`existing_integration_id`, or `existing_user_id`). This parameter is not
available in OSS Canvas.'
user[trusted_account]:
type: string
description: 'The domain of the account to search for the user. This field is required when
identifying a user in a trusted account. This parameter is not available in OSS
Canvas.'
required:
- user[id]
- login[unique_id]
application/x-www-form-urlencoded:
schema:
type: object
properties:
user[id]:
type: string
description: The ID of the user to create the login for.
login[unique_id]:
type: string
description: The unique ID for the new login.
login[password]:
type: string
description: The new login's password.
login[sis_user_id]:
type: string
description: 'SIS ID for the login. To set this parameter, the caller must be able to
manage SIS permissions on the account.'
login[integration_id]:
type: string
description: 'Integration ID for the login. To set this parameter, the caller must be able to
manage SIS permissions on the account. The Integration ID is a secondary
identifier useful for more complex SIS integrations.'
login[authentication_provider_id]:
type: string
description: 'The authentication provider this login is associated with. Logins
associated with a specific provider can only be used with that provider.
Legacy providers (LDAP, CAS, SAML) will search for logins associated with
them, or unassociated logins. New providers will only search for logins
explicitly associated with them. This can be the integer ID of the
provider, or the type of the provider (in which case, it will find the
first matching provider).'
login[declared_user_type]:
type: string
description: "The declared intention of the user type. This can be set, but does\nnot change any Canvas functionality with respect to their access.\nA user can still be a teacher, admin, student, etc. in any particular\ncontext without regard to this setting. This can be used for\nadministrative purposes for integrations to be able to more easily\nidentify why the user was created.\nValid values are:\n * administrative\n * observer\n * staff\n * student\n * student_other\n * teacher"
login[must_reset_password]:
type: boolean
description: 'If true, the user will be required to change their password the next time
they sign in with this login. Only valid for logins that support Canvas
passwords.'
user[existing_user_id]:
type: string
description: 'A Canvas User ID to identify a user in a trusted account (alternative to `id`,
`existing_sis_user_id`, or `existing_integration_id`). This parameter is
not available in OSS Canvas.'
user[existing_integration_id]:
type: string
description: 'An Integration ID to identify a user in a trusted account (alternative to `id`,
`existing_user_id`, or `existing_sis_user_id`). This parameter is not
available in OSS Canvas.'
user[existing_sis_user_id]:
type: string
description: 'An SIS User ID to identify a user in a trusted account (alternative to `id`,
`existing_integration_id`, or `existing_user_id`). This parameter is not
available in OSS Canvas.'
user[trusted_account]:
type: string
description: 'The domain of the account to search for the user. This field is required when
identifying a user in a trusted account. This parameter is not available in OSS
Canvas.'
required:
- user[id]
- login[unique_id]
responses:
'200':
description: Success, no content returned
externalDocs:
url: https://canvas.instructure.com/doc/api/logins.html
/v1/users/{user_id}/logins:
get:
tags:
- Logins
operationId: list_user_logins_users
summary: List user logins
description: Given a user ID, return a paginated list of that user's logins for the given account.
parameters:
- name: user_id
in: path
schema:
type: string
required: true
description: ID
responses:
'200':
description: Success, no content returned
externalDocs:
url: https://canvas.instructure.com/doc/api/logins.html
/v1/users/reset_password:
post:
tags:
- Logins
operationId: kickoff_password_recovery_flow
summary: Kickoff password recovery flow
description: Given a user email, generate a nonce and email it to the user
responses:
'200':
description: Success, no content returned
externalDocs:
url: https://canvas.instructure.com/doc/api/logins.html
/v1/accounts/{account_id}/logins/{id}:
put:
tags:
- Logins
operationId: edit_user_login
summary: Edit a user login
description: Update an existing login for a user in the given account.
parameters:
- name: account_id
in: path
schema:
type: string
required: true
description: ID
- name: id
in: path
schema:
type: string
required: true
description: ID
requestBody:
required: false
content:
application/json:
schema:
type: object
properties:
login[unique_id]:
type: string
description: The new unique ID for the login.
login[password]:
type: string
description: 'The new password for the login. Admins can only set a password for another
user if the "Password setting by admins" account setting is enabled.'
login[old_password]:
type: string
description: 'The prior password for the login. Required if the caller is changing
their own password.'
login[sis_user_id]:
type: string
description: 'SIS ID for the login. To set this parameter, the caller must be able to
manage SIS permissions on the account.'
login[integration_id]:
type: string
description: 'Integration ID for the login. To set this parameter, the caller must be able to
manage SIS permissions on the account. The Integration ID is a secondary
identifier useful for more complex SIS integrations.'
login[authentication_provider_id]:
type: string
description: 'The authentication provider this login is associated with. Logins
associated with a specific provider can only be used with that provider.
Legacy providers (LDAP, CAS, SAML) will search for logins associated with
them, or unassociated logins. New providers will only search for logins
explicitly associated with them. This can be the integer ID of the
provider, or the type of the provider (in which case, it will find the
first matching provider). To unassociate from a known provider, specify
null or an empty string.'
login[workflow_state]:
type: string
enum:
- active
- suspended
description: Used to suspend or re-activate a login.
login[declared_user_type]:
type: string
description: "The declared intention of the user type. This can be set, but does\nnot change any Canvas functionality with respect to their access.\nA user can still be a teacher, admin, student, etc. in any particular\ncontext without regard to this setting. This can be used for\nadministrative purposes for integrations to be able to more easily\nidentify why the user was created.\nValid values are:\n * administrative\n * observer\n * staff\n * student\n * student_other\n * teacher"
login[must_reset_password]:
type: boolean
description: 'If true, the user will be required to change their password the next time
they sign in with this login. Cleared automatically when the password is
changed. Only valid for logins that support Canvas passwords.'
override_sis_stickiness:
type: boolean
description: 'Default is true. If false, any fields containing “sticky” changes will not be updated.
See SIS CSV Format documentation for information on which fields can have SIS stickiness'
application/x-www-form-urlencoded:
schema:
type: object
properties:
login[unique_id]:
type: string
description: The new unique ID for the login.
login[password]:
type: string
description: 'The new password for the login. Admins can only set a password for another
user if the "Password setting by admins" account setting is enabled.'
login[old_password]:
type: string
description: 'The prior password for the login. Required if the caller is changing
their own password.'
login[sis_user_id]:
type: string
description: 'SIS ID for the login. To set this parameter, the caller must be able to
manage SIS permissions on the account.'
login[integration_id]:
type: string
description: 'Integration ID for the login. To set this parameter, the caller must be able to
manage SIS permissions on the account. The Integration ID is a secondary
identifier useful for more complex SIS integrations.'
login[authentication_provider_id]:
type: string
description: 'The authentication provider this login is associated with. Logins
associated with a specific provider can only be used with that provider.
Legacy providers (LDAP, CAS, SAML) will search for logins associated with
them, or unassociated logins. New providers will only search for logins
explicitly associated with them. This can be the integer ID of the
provider, or the type of the provider (in which case, it will find the
first matching provider). To unassociate from a known provider, specify
null or an empty string.'
login[workflow_state]:
type: string
enum:
- active
- suspended
description: Used to suspend or re-activate a login.
login[declared_user_type]:
type: string
description: "The declared intention of the user type. This can be set, but does\nnot change any Canvas functionality with respect to their access.\nA user can still be a teacher, admin, student, etc. in any particular\ncontext without regard to this setting. This can be used for\nadministrative purposes for integrations to be able to more easily\nidentify why the user was created.\nValid values are:\n * administrative\n * observer\n * staff\n * student\n * student_other\n * teacher"
login[must_reset_password]:
type: boolean
description: 'If true, the user will be required to change their password the next time
they sign in with this login. Cleared automatically when the password is
changed. Only valid for logins that support Canvas passwords.'
override_sis_stickiness:
type: boolean
description: 'Default is true. If false, any fields containing “sticky” changes will not be updated.
See SIS CSV Format documentation for information on which fields can have SIS stickiness'
responses:
'200':
description: Success, no content returned
externalDocs:
url: https://canvas.instructure.com/doc/api/logins.html
/v1/users/{user_id}/logins/{id}:
delete:
tags:
- Logins
operationId: delete_user_login
summary: Delete a user login
description: Delete an existing login.
parameters:
- name: user_id
in: path
schema:
type: string
required: true
description: ID
- name: id
in: path
schema:
type: string
required: true
description: ID
responses:
'200':
description: Success, no content returned
externalDocs:
url: https://canvas.instructure.com/doc/api/logins.html
components:
securitySchemes:
bearerAuth:
type: http
scheme: bearer
description: 'Canvas OAuth2 access token sent as "Authorization: Bearer <token>". See https://canvas.instructure.com/doc/api/file.oauth.html'
oauth2:
type: oauth2
description: Canvas OAuth2. See https://canvas.instructure.com/doc/api/file.oauth.html and https://canvas.instructure.com/doc/api/file.oauth_endpoints.html
flows:
authorizationCode:
authorizationUrl: https://canvas.instructure.com/login/oauth2/auth
tokenUrl: https://canvas.instructure.com/login/oauth2/token
refreshUrl: https://canvas.instructure.com/login/oauth2/token
scopes: {}
externalDocs:
description: Canvas LMS REST API Documentation
url: https://canvas.instructure.com/doc/api/
x-generated-from: https://canvas.instructure.com/doc/api/api-docs.json
x-provenance:
method: derived
derived_by: API Evangelist enrichment pipeline (Swagger 1.2 -> OpenAPI 3.1 conversion)
source: openapi/_original/swagger-1.2/*.json (144 verbatim first-party Swagger 1.2 documents)
source_url: https://canvas.instructure.com/doc/api/api-docs.json
fetched: '2026-09-05'
http_status: 200