Student experience
What a student does — connect Canvas once, run a setup check, download a fresh configuration, and take the exam in SEB — and what the tool does for them.
Students interact with the tool as little as possible by design. This page describes the experience so you can support it and write your own student-facing instructions.
The one-time setup
Connect Canvas
The student launches the course-navigation tool and completes a one-time Canvas connection. This authorizes the scoped session handoff the tool uses to place the student into Canvas inside SEB — without copying their normal browser cookies.
Run the setup check (recommended)
The optional setup check generates a separate configuration that tests certificate decryption, SEB detection, connectivity, storage, and Config Key proof. It never releases an assessment access code and does not establish device trust — it just catches a client or profile problem before exam day.
Taking an exam
Download a fresh configuration
From the assessment, the student downloads a .seb file. There is no reusable
link — each download is a one-time, 120-second capability tied to the student, the
assessment, and current settings. If settings changed, they download again.
Open it in Safe Exam Browser
The encrypted configuration opens only on a device with the managed private identity. SEB starts and reaches Canvas through the generated session URL.
The code is filled automatically
On the assessment page, the detector proves the running configuration. On success, the access code is filled into the Canvas prompt for the student — they never see or type it. Approved tools become available; disabled tools stay unavailable.
Submit and exit
The student takes and submits the exam. SEB is allowed to quit only after Canvas shows the authoritative completed state; a manual or early quit follows the configured password policy.
What students never do
By design
Students never see the access code, never receive a reusable download link, and never handle certificates or passwords. If a student is being asked for an access code value, something is wrong — see Troubleshooting → Detector and SEB configuration.
Supporting students
- If a download will not open in SEB, the device is missing the identity or the configuration is stale — have them download a fresh file and confirm the device profile is installed.
- If "Connect Canvas" keeps reappearing, the student may be authorizing a different Canvas environment than the launch, or a scope is missing — see OAuth & scopes.
- The setup check is the fastest way to confirm a student's device is ready before an exam.
Instructor workflow
What instructors do from the course-navigation tool — discover assessments, set SEB policy and tools, enable enforcement, and manage passwords.
Operations
Day-2 running of the service — cleanup, backups and restore drills, upgrades, application vs schema rollback, pool sizing, monitoring, and the dev database reset.