Safe Online Exam
Connect Canvas

Create the LTI 1.3 key

Create the separate Canvas LTI 1.3 Developer Key from the service's JSON configuration URL, then record the client ID.

Create a separate LTI 1.3 Developer Key (distinct from the API OAuth key). Use the service's JSON configuration URL so the deployed service remains the registration source of truth. This Canvas workflow is not the separate OpenID Dynamic Registration protocol.

Use Canvas's JSON configuration URL

In Canvas, select the JSON configuration URL option and enter:

${TOOL_URL}/lti/config

The document supplies the title, the course-navigation and root-account-navigation placements, the OIDC initiation URL, the target link URI, the public JWKS URL, and the signed course/account/user/role custom fields.

About the account placement

The account placement is marked root-account-only and administrator-visible. The server still independently requires the signed LTI Administrator role, Canvas's signed root-admin substitution, numeric account identifiers, and a matching account-admin OAuth grant before the dashboard does anything — the placement visibility is not the security boundary.

If Canvas requires manual fields

If your Canvas cannot use the configuration URL, these are the fields:

Canvas fieldValue
JSON configuration URL${TOOL_URL}/lti/config
OIDC initiation URL${TOOL_URL}/lti/login
Target link URI${TOOL_URL}/lti/launch
Redirect URI${TOOL_URL}/lti/launch
Public JWK URL${TOOL_URL}/.well-known/jwks.json

Enable and record

Enable the key and record its client ID as LTI_CLIENT_ID. You will place this into your secret store during the pass-2 redeploy, together with the deployment ID from the next step.

This client ID is not the same as CANVAS_API_CLIENT_ID. Keep the two clearly labeled — mixing them is a common cause of launch or authorization failures.

Next: Install the external app.

On this page