Safe Online Exam
Connect Canvas

Install the external app

Install the registered app by client ID at the right account scope, record the deployment ID, and choose between strict and self-service deployment-ID policy.

With the LTI key enabled, install the external app so it appears in Canvas navigation.

Add the app by client ID

At the root account (or the desired account scope), open the external-app configuration area and add the app by client ID. Paste the LTI_CLIENT_ID from the LTI key step and approve the registration.

Record the deployment ID

Canvas assigns a deployment ID on installation. Record it — it becomes LTI_DEPLOYMENT_ID.

Deploy a revision with the real IDs

Set LTI_DEPLOYMENT_ID (and the real LTI_CLIENT_ID) and finalize the installer before testing. The Cloud Run release bundle creates numbered Secret Manager versions for the LTI values, stages a candidate revision, and cuts traffic only after readiness. The Compose bundle updates the protected environment and recreates the app through its migration gate.

By default, the service rejects launches from a deployment ID that is not explicitly configured.

Choose the deployment-ID policy

Strict (default)

LTI_DEPLOYMENT_ID_CHECKING_ENABLED=true. Only the deployment ID(s) you configure are accepted. Use this for controlled, admin-installed rollouts. Supports a comma/newline allowlist for multiple installs.

Controlled self-service

LTI_DEPLOYMENT_ID_CHECKING_ENABLED=false. Accepts any non-empty deployment ID in a signed launch from the configured issuer and client ID — for letting instructors add this exact app to their own courses.

Only relax checking if the installers are trusted

Self-service mode still enforces token signatures, issuer/audience, nonce, target-link, and browser/state validation — it removes only the preconfigured allowlist. Use it only if everyone who can install this client ID in Canvas is trusted to grant access to the tool.

Choose the account scope

ScopeUse it for
Root-account installationA broad rollout and the school administrator dashboard. Recommended.
Course-level installationAn isolated instructor/student pilot only. Does not provide the root-account navigation surface.

Do not install the same registration both account-wide and course-local in the same course unless you intend duplicate navigation entries.

Hiding the student navigation tab

You may hide the Safe Online Exam course-navigation placement from students without breaking protected Classic Quiz or New Quiz launches. Keep the external app installed in the course or inherited from its account. On an assessment page where the tab is not rendered, the detector uses the student's same-origin Canvas session to find the installed LTI 1.3 tool that matches the configured client and deployment IDs, then starts the signed assessment launch.

On a sharded Canvas instance, the External Tools list can return the same Developer Key as a shard-local ID while LTI_CLIENT_ID remains globally qualified. The detector recognizes that corresponding form; do not replace the configured client ID with another local or unrelated Developer Key ID.

This remains subject to the deployment-ID policy above: strict mode requires a matching configured deployment ID, while controlled self-service mode accepts a signed launch for the configured client ID. Test the hidden-tab path before a real exam; the acceptance sequence is in Roll out & operate.

If the tool does not launch, or the admin dashboard is missing, see Troubleshooting → Canvas launch.

Next: Load the detector script.

On this page