Canvas LMS · OAuth Scopes

Canvas LMS OAuth Scopes

OAuth 2.0 searched

Canvas LMS publishes 3 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Canvas LMS API on a user’s behalf.

Tokens are issued from https://canvas.instructure.com/login/oauth2/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

Learning ManagementEducationEdTechLMSLTIHigher EducationK-12Open-SourceAGPLCanvas
Scopes: 3 Flows: authorizationCode Method: searched

OAuth endpoints

Authorization URL
https://canvas.instructure.com/login/oauth2/auth
Token URL
https://canvas.instructure.com/login/oauth2/token
Flows
authorizationCode

Scopes (3)

ScopeDescriptionFlows
url:GET|/api/v1/accounts Read accounts authorizationCode
url:GET|/api/v1/courses Read courses authorizationCode
url:GET|/api/v1/users/{user_id} Read a user authorizationCode

Source

OAuth Scopes

Raw ↑
generated: '2026-06-20'
method: searched
source: openapi/canvas-lms-rest-api-openapi.yml
docs: https://developerdocs.instructure.com/services/canvas/resources/api_token_scopes.md
scope_format: "url:{VERB}|{path}  e.g. url:GET|/api/v1/courses"
scope_notes: >-
  Canvas scopes are per-endpoint and dynamic: each is url:VERB|/api/v1/<path>.
  Developer keys are configured with the subset of scopes a token may request;
  when a developer key is set to "enforce scopes", tokens are restricted to the
  listed scopes. The full live list is enumerable via
  GET /api/v1/accounts/:account_id/scopes (group_by=resource_name). The scopes
  below are those the captured OpenAPI operations map to; the docs reference is
  the authoritative, install-specific source.
schemes:
- name: OAuth2
  source: openapi/canvas-lms-rest-api-openapi.yml
  flows:
  - flow: authorizationCode
    authorizationUrl: https://canvas.instructure.com/login/oauth2/auth
    tokenUrl: https://canvas.instructure.com/login/oauth2/token
  description: Canvas OAuth2 (RFC 6749) authorization code grant. Register a Developer Key in
    the target Canvas account to obtain a client_id and client_secret.
scopes:
- scope: url:GET|/api/v1/accounts
  description: Read accounts
  flows:
  - authorizationCode
  sources:
  - openapi/canvas-lms-rest-api-openapi.yml
- scope: url:GET|/api/v1/courses
  description: Read courses
  flows:
  - authorizationCode
  sources:
  - openapi/canvas-lms-rest-api-openapi.yml
- scope: url:GET|/api/v1/users/{user_id}
  description: Read a user
  flows:
  - authorizationCode
  sources:
  - openapi/canvas-lms-rest-api-openapi.yml

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/canvas-lms-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.