openapi: 3.2.0 info: title: Canvas LMS REST Api Token Scopes API version: v1 summary: The complete Canvas LMS REST API, converted from the Swagger 1.2 documents Instructure publishes under https://canvas.instructure.com/doc/api/. description: The Canvas LMS REST API covers courses, assignments, quizzes, grades, users, enrollments, accounts, files, modules, rubrics, submissions, SIS imports, LTI, analytics and account administration. contact: name: Instructure Canvas url: https://canvas.instructure.com/doc/api/ license: name: AGPL-3.0 url: https://github.com/instructure/canvas-lms/blob/master/LICENSE servers: - url: https://canvas.instructure.com/api description: Instructure-hosted Canvas (canvas.instructure.com) - url: https://{canvas_host}/api description: Any Canvas instance; Canvas is multi-tenant and self-hostable, so the host is the institution's Canvas domain. variables: canvas_host: default: canvas.instructure.com description: Your institution's Canvas hostname, e.g. school.instructure.com security: - bearerAuth: [] - oauth2: [] tags: - name: Api Token Scopes x-resource: api_token_scopes externalDocs: url: https://canvas.instructure.com/doc/api/api_token_scopes.html paths: /v1/accounts/{account_id}/scopes: get: tags: - Api Token Scopes operationId: list_scopes summary: List scopes description: A list of scopes that can be applied to developer keys and access tokens. parameters: - name: account_id in: path schema: type: string required: true description: ID - name: group_by in: query schema: type: string enum: - resource_name required: false description: The attribute to group the scopes by. By default no grouping is done. responses: '200': description: Success content: application/json: schema: type: array items: $ref: '#/components/schemas/Scope' externalDocs: url: https://canvas.instructure.com/doc/api/api_token_scopes.html components: schemas: Scope: type: object properties: resource: type: string example: courses description: The resource the scope is associated with resource_name: type: string example: Courses description: The localized resource name controller: type: string example: courses description: The controller the scope is associated to action: type: string example: index description: The controller action the scope is associated to verb: type: string example: GET description: The HTTP verb for the scope scope: type: string example: url:GET|/api/v1/courses description: The identifier for the scope securitySchemes: bearerAuth: type: http scheme: bearer description: 'Canvas OAuth2 access token sent as "Authorization: Bearer ". See https://canvas.instructure.com/doc/api/file.oauth.html' oauth2: type: oauth2 description: Canvas OAuth2. See https://canvas.instructure.com/doc/api/file.oauth.html and https://canvas.instructure.com/doc/api/file.oauth_endpoints.html flows: authorizationCode: authorizationUrl: https://canvas.instructure.com/login/oauth2/auth tokenUrl: https://canvas.instructure.com/login/oauth2/token refreshUrl: https://canvas.instructure.com/login/oauth2/token scopes: {} externalDocs: description: Canvas LMS REST API Documentation url: https://canvas.instructure.com/doc/api/ x-generated-from: https://canvas.instructure.com/doc/api/api-docs.json x-provenance: method: derived derived_by: API Evangelist enrichment pipeline (Swagger 1.2 -> OpenAPI 3.1 conversion) source: openapi/_original/swagger-1.2/*.json (144 verbatim first-party Swagger 1.2 documents) source_url: https://canvas.instructure.com/doc/api/api-docs.json fetched: '2026-09-05' http_status: 200