API Tokens and Canvas
Canvas API Token Policy
Since the widespread public availability of LLM tools, we have seen a significant increase in the number of users requesting API tokens and in third-party applications asking users to give them a Canvas API token. This is an insecure and unsafe way of accessing Canvas that violates both Emory IT policies (Information Technology Conditions of Use and Enterprise Password Policy) as well as Canvas API policies. For these reasons, we do not allow any users to generate their own Canvas API tokens.Faculty members who have a demonstrated research or teaching need that cannot be met through Canvas’s native interface may request an API token by e-mailing classes@emory.edu. Please explain why an API token is necessary for your use case and how you intend to use it. If accepted, we will provide you with an API token for up to 90 days at a time.
Background
An Application Programming Interface (API) is a standardized protocol that allows two computer systems to interact with one another. An API token is a way of authorizing access to an API that is analogous to a username and password. With a Canvas API token, for example, a user can do anything through the Canvas API that they can do through the web interface: create course content or post grades in courses where they are an instructor, download course content from any course that they are enrolled in, post in discussions, and so on. And because an API enables programmatic access, all of these actions can be automated at scale: download every file from every course, change all students’ grades at once, post one thousand discussion replies instantly, etc. API tokens thus create significant data privacy and security concerns.In the pre-LLM world, making use of an API required a certain level of coding skill, time, and effort invested into developing an application. These barriers to entry also functioned as signals that a person knew what they were doing when they had an API token that provided them access to a system like Canvas. As in many other domains, LLMs have removed this barrier to entry and thus also removed a proxy signal for competence and trust. This is one among several reasons that we do not allow users to generate their own Canvas API tokens and instead administer them for allowed use cases.
For more information about Canvas API tokens, please e-mail the Canvas team at classes@emory.edu.