Canvas LMS · OAuth Scopes

Canvas LMS OAuth Scopes

OAuth 2.0 searched

Canvas LMS publishes 3 OAuth 2.0 scopes via the authorizationCode flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the Canvas LMS API on a user’s behalf.

Tokens are issued from https://canvas.instructure.com/login/oauth2/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

Learning ManagementEducationEdTechLMSLTIHigher EducationK-12Open SourceAGPLCanvas
Scopes: 3 Flows: authorizationCode Method: searched

OAuth endpoints

Authorization URL
https://canvas.instructure.com/login/oauth2/auth
Token URL
https://canvas.instructure.com/login/oauth2/token
Flows
authorizationCode

Scopes (3)

ScopeDescriptionFlows
url:GET|/api/v1/accounts Read accounts authorizationCode
url:GET|/api/v1/courses Read courses authorizationCode
url:GET|/api/v1/users/{user_id} Read a user authorizationCode

Source

OAuth Scopes

Raw ↑
generated: '2026-06-20'
method: searched
source: openapi/canvas-lms-rest-api-openapi.yml
docs: https://developerdocs.instructure.com/services/canvas/resources/api_token_scopes.md
scope_format: "url:{VERB}|{path}  e.g. url:GET|/api/v1/courses"
scope_notes: >-
  Canvas scopes are per-endpoint and dynamic: each is url:VERB|/api/v1/<path>.
  Developer keys are configured with the subset of scopes a token may request;
  when a developer key is set to "enforce scopes", tokens are restricted to the
  listed scopes. The full live list is enumerable via
  GET /api/v1/accounts/:account_id/scopes (group_by=resource_name). The scopes
  below are those the captured OpenAPI operations map to; the docs reference is
  the authoritative, install-specific source.
schemes:
- name: OAuth2
  source: openapi/canvas-lms-rest-api-openapi.yml
  flows:
  - flow: authorizationCode
    authorizationUrl: https://canvas.instructure.com/login/oauth2/auth
    tokenUrl: https://canvas.instructure.com/login/oauth2/token
  description: Canvas OAuth2 (RFC 6749) authorization code grant. Register a Developer Key in
    the target Canvas account to obtain a client_id and client_secret.
scopes:
- scope: url:GET|/api/v1/accounts
  description: Read accounts
  flows:
  - authorizationCode
  sources:
  - openapi/canvas-lms-rest-api-openapi.yml
- scope: url:GET|/api/v1/courses
  description: Read courses
  flows:
  - authorizationCode
  sources:
  - openapi/canvas-lms-rest-api-openapi.yml
- scope: url:GET|/api/v1/users/{user_id}
  description: Read a user
  flows:
  - authorizationCode
  sources:
  - openapi/canvas-lms-rest-api-openapi.yml