openapi: 3.2.0 info: title: Canvas LMS REST Access Tokens API version: v1 summary: The complete Canvas LMS REST API, converted from the Swagger 1.2 documents Instructure publishes under https://canvas.instructure.com/doc/api/. description: The Canvas LMS REST API covers courses, assignments, quizzes, grades, users, enrollments, accounts, files, modules, rubrics, submissions, SIS imports, LTI, analytics and account administration. contact: name: Instructure Canvas url: https://canvas.instructure.com/doc/api/ license: name: AGPL-3.0 url: https://github.com/instructure/canvas-lms/blob/master/LICENSE servers: - url: https://canvas.instructure.com/api description: Instructure-hosted Canvas (canvas.instructure.com) - url: https://{canvas_host}/api description: Any Canvas instance; Canvas is multi-tenant and self-hostable, so the host is the institution's Canvas domain. variables: canvas_host: default: canvas.instructure.com description: Your institution's Canvas hostname, e.g. school.instructure.com security: - bearerAuth: [] - oauth2: [] tags: - name: Access Tokens x-resource: access_tokens externalDocs: url: https://canvas.instructure.com/doc/api/access_tokens.html paths: /v1/users/{user_id}/user_generated_tokens: get: tags: - Access Tokens operationId: list_access_tokens_for_user summary: List access tokens for a user description: 'Returns a list of manually generated access tokens for the specified user. Note that the actual token values are only returned when the token is first created.' parameters: - name: user_id in: path schema: type: string required: true description: ID - name: per_page in: query schema: type: integer format: int64 required: false description: The number of results to return per page. Defaults to 10. Maximum of 100. responses: '200': description: Success content: application/json: schema: type: array items: $ref: '#/components/schemas/Token' externalDocs: url: https://canvas.instructure.com/doc/api/access_tokens.html /v1/users/{user_id}/tokens/{id}: get: tags: - Access Tokens operationId: show_access_token summary: Show an access token description: The ID can be the actual database ID of the token, or the 'token_hint' value. parameters: - name: user_id in: path schema: type: string required: true description: ID - name: id in: path schema: type: string required: true description: ID responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/access_tokens.html put: tags: - Access Tokens operationId: update_access_token summary: Update an access token description: 'Update an existing access token. The ID can be the actual database ID of the token, or the ''token_hint'' value. Regenerating an expired token requires a new expiration date.' parameters: - name: user_id in: path schema: type: string required: true description: ID - name: id in: path schema: type: string required: true description: ID requestBody: required: false content: application/json: schema: type: object properties: token[purpose]: type: string description: The purpose of the token. token[expires_at]: type: string format: date-time description: The time at which the token will expire. token[scopes]: type: array items: type: array items: {} description: The scopes to associate with the token. token[regenerate]: type: boolean description: Regenerate the actual token. application/x-www-form-urlencoded: schema: type: object properties: token[purpose]: type: string description: The purpose of the token. token[expires_at]: type: string format: date-time description: The time at which the token will expire. token[scopes]: type: array items: type: array items: {} description: The scopes to associate with the token. token[regenerate]: type: boolean description: Regenerate the actual token. responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/access_tokens.html delete: tags: - Access Tokens operationId: delete_access_token summary: Delete an access token description: The ID can be the actual database ID of the token, or the 'token_hint' value. parameters: - name: user_id in: path schema: type: string required: true description: ID - name: id in: path schema: type: string required: true description: ID responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/access_tokens.html /v1/users/{user_id}/tokens: post: tags: - Access Tokens operationId: create_access_token summary: Create an access token description: 'Create a new access token for the specified user. If the user is not the current user, the token will be created as "pending", and must be activated by the user before it can be used.' parameters: - name: user_id in: path schema: type: string required: true description: ID requestBody: required: false content: application/json: schema: type: object properties: token[purpose]: type: string description: The purpose of the token. token[expires_at]: type: string format: date-time description: The time at which the token will expire. token[scopes]: type: array items: type: array items: {} description: 'The scopes to associate with the token. Ignored if the default developer key does not have the "enable scopes" option enabled. In such cases, the token will inherit the user''s permissions instead.' required: - token[purpose] application/x-www-form-urlencoded: schema: type: object properties: token[purpose]: type: string description: The purpose of the token. token[expires_at]: type: string format: date-time description: The time at which the token will expire. token[scopes]: type: array items: type: array items: {} description: 'The scopes to associate with the token. Ignored if the default developer key does not have the "enable scopes" option enabled. In such cases, the token will inherit the user''s permissions instead.' required: - token[purpose] responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/access_tokens.html components: schemas: Token: type: object properties: id: type: integer description: The internal database ID of the token. created_at: type: string description: The time the token was created. expires_at: type: array items: type: string x-canvas-declared-type: '''string'', ''null''' description: The time the token will permanently expire, or null if it does not permanently expire. workflow_state: type: string description: The current state of the token. One of 'active', 'pending', 'disabled', or 'deleted'. remember_access: type: boolean description: Whether the token should be remembered across sessions. Only applicable for OAuth tokens. scopes: type: array items: type: string description: The scopes associated with the token. If empty, there are no scope limitations. real_user_id: type: array items: type: string x-canvas-declared-type: '''integer'', ''null''' description: If the token was created while masquerading, this is the ID of the real user. Otherwise, null. token: type: string description: The actual access token. Only included when the token is first created. token_hint: type: string description: A short, unique string that can be used to look up the token. user_id: type: integer description: The ID of the user the token belongs to. purpose: type: string description: The purpose of the token. app_name: type: array items: type: string x-canvas-declared-type: '''string'', ''null''' description: If the token was created by an OAuth application, this is the name of that application. Otherwise, null. can_manually_regenerate: type: boolean description: Whether the current user can manually regenerate this token. securitySchemes: bearerAuth: type: http scheme: bearer description: 'Canvas OAuth2 access token sent as "Authorization: Bearer ". See https://canvas.instructure.com/doc/api/file.oauth.html' oauth2: type: oauth2 description: Canvas OAuth2. See https://canvas.instructure.com/doc/api/file.oauth.html and https://canvas.instructure.com/doc/api/file.oauth_endpoints.html flows: authorizationCode: authorizationUrl: https://canvas.instructure.com/login/oauth2/auth tokenUrl: https://canvas.instructure.com/login/oauth2/token refreshUrl: https://canvas.instructure.com/login/oauth2/token scopes: {} externalDocs: description: Canvas LMS REST API Documentation url: https://canvas.instructure.com/doc/api/ x-generated-from: https://canvas.instructure.com/doc/api/api-docs.json x-provenance: method: derived derived_by: API Evangelist enrichment pipeline (Swagger 1.2 -> OpenAPI 3.1 conversion) source: openapi/_original/swagger-1.2/*.json (144 verbatim first-party Swagger 1.2 documents) source_url: https://canvas.instructure.com/doc/api/api-docs.json fetched: '2026-09-05' http_status: 200