openapi: 3.2.0 info: title: Canvas LMS REST Content Security Policy Settings API version: v1 summary: The complete Canvas LMS REST API, converted from the Swagger 1.2 documents Instructure publishes under https://canvas.instructure.com/doc/api/. description: The Canvas LMS REST API covers courses, assignments, quizzes, grades, users, enrollments, accounts, files, modules, rubrics, submissions, SIS imports, LTI, analytics and account administration. contact: name: Instructure Canvas url: https://canvas.instructure.com/doc/api/ license: name: AGPL-3.0 url: https://github.com/instructure/canvas-lms/blob/master/LICENSE servers: - url: https://canvas.instructure.com/api description: Instructure-hosted Canvas (canvas.instructure.com) - url: https://{canvas_host}/api description: Any Canvas instance; Canvas is multi-tenant and self-hostable, so the host is the institution's Canvas domain. variables: canvas_host: default: canvas.instructure.com description: Your institution's Canvas hostname, e.g. school.instructure.com security: - bearerAuth: [] - oauth2: [] tags: - name: Content Security Policy Settings x-resource: content_security_policy_settings externalDocs: url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html paths: /v1/courses/{course_id}/csp_settings: get: tags: - Content Security Policy Settings operationId: get_current_settings_for_account_or_course_courses summary: Get current settings for account or course description: Update multiple modules in an account. parameters: - name: course_id in: path schema: type: string required: true description: ID responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html put: tags: - Content Security Policy Settings operationId: enable_disable_or_clear_explicit_csp_setting_courses summary: Enable, disable, or clear explicit CSP setting description: 'Either explicitly sets CSP to be on or off for courses and sub-accounts, or clear the explicit settings to default to those set by a parent account Note: If "inherited" and "settings_locked" are both true for this account or course, then the CSP setting cannot be modified.' parameters: - name: course_id in: path schema: type: string required: true description: ID requestBody: required: false content: application/json: schema: type: object properties: status: type: string enum: - enabled - disabled - inherited description: 'If set to "enabled" for an account, CSP will be enabled for all its courses and sub-accounts (that have not explicitly enabled or disabled it), using the allowed domains set on this account. If set to "disabled", CSP will be disabled for this account or course and for all sub-accounts that have not explicitly re-enabled it. If set to "inherited", this account or course will reset to the default state where CSP settings are inherited from the first parent account to have them explicitly set.' required: - status application/x-www-form-urlencoded: schema: type: object properties: status: type: string enum: - enabled - disabled - inherited description: 'If set to "enabled" for an account, CSP will be enabled for all its courses and sub-accounts (that have not explicitly enabled or disabled it), using the allowed domains set on this account. If set to "disabled", CSP will be disabled for this account or course and for all sub-accounts that have not explicitly re-enabled it. If set to "inherited", this account or course will reset to the default state where CSP settings are inherited from the first parent account to have them explicitly set.' required: - status responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html /v1/accounts/{account_id}/csp_settings: get: tags: - Content Security Policy Settings operationId: get_current_settings_for_account_or_course_accounts summary: Get current settings for account or course description: Update multiple modules in an account. parameters: - name: account_id in: path schema: type: string required: true description: ID responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html put: tags: - Content Security Policy Settings operationId: enable_disable_or_clear_explicit_csp_setting_accounts summary: Enable, disable, or clear explicit CSP setting description: 'Either explicitly sets CSP to be on or off for courses and sub-accounts, or clear the explicit settings to default to those set by a parent account Note: If "inherited" and "settings_locked" are both true for this account or course, then the CSP setting cannot be modified.' parameters: - name: account_id in: path schema: type: string required: true description: ID requestBody: required: false content: application/json: schema: type: object properties: status: type: string enum: - enabled - disabled - inherited description: 'If set to "enabled" for an account, CSP will be enabled for all its courses and sub-accounts (that have not explicitly enabled or disabled it), using the allowed domains set on this account. If set to "disabled", CSP will be disabled for this account or course and for all sub-accounts that have not explicitly re-enabled it. If set to "inherited", this account or course will reset to the default state where CSP settings are inherited from the first parent account to have them explicitly set.' required: - status application/x-www-form-urlencoded: schema: type: object properties: status: type: string enum: - enabled - disabled - inherited description: 'If set to "enabled" for an account, CSP will be enabled for all its courses and sub-accounts (that have not explicitly enabled or disabled it), using the allowed domains set on this account. If set to "disabled", CSP will be disabled for this account or course and for all sub-accounts that have not explicitly re-enabled it. If set to "inherited", this account or course will reset to the default state where CSP settings are inherited from the first parent account to have them explicitly set.' required: - status responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html /v1/accounts/{account_id}/csp_settings/lock: put: tags: - Content Security Policy Settings operationId: lock_or_unlock_current_csp_settings_for_sub_accounts_and_courses summary: Lock or unlock current CSP settings for sub-accounts and courses description: Can only be set if CSP is explicitly enabled or disabled on this account (i.e. "inherited" is false). parameters: - name: account_id in: path schema: type: string required: true description: ID requestBody: required: false content: application/json: schema: type: object properties: settings_locked: type: boolean description: Whether sub-accounts and courses will be prevented from overriding settings inherited from this account. required: - settings_locked application/x-www-form-urlencoded: schema: type: object properties: settings_locked: type: boolean description: Whether sub-accounts and courses will be prevented from overriding settings inherited from this account. required: - settings_locked responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html /v1/accounts/{account_id}/csp_settings/domains: post: tags: - Content Security Policy Settings operationId: add_allowed_domain_to_account summary: Add an allowed domain to account description: 'Adds an allowed domain for the current account. Note: this will not take effect unless CSP is explicitly enabled on this account.' parameters: - name: account_id in: path schema: type: string required: true description: ID requestBody: required: false content: application/json: schema: type: object properties: domain: type: string description: no description required: - domain application/x-www-form-urlencoded: schema: type: object properties: domain: type: string description: no description required: - domain responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html delete: tags: - Content Security Policy Settings operationId: remove_domain_from_account summary: Remove a domain from account description: Removes an allowed domain from the current account. parameters: - name: account_id in: path schema: type: string required: true description: ID - name: domain in: query schema: type: string required: true description: no description responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html /v1/accounts/{account_id}/csp_settings/domains/batch_create: post: tags: - Content Security Policy Settings operationId: add_multiple_allowed_domains_to_account summary: Add multiple allowed domains to an account description: 'Adds multiple allowed domains for the current account. Note: this will not take effect unless CSP is explicitly enabled on this account.' parameters: - name: account_id in: path schema: type: string required: true description: ID requestBody: required: false content: application/json: schema: type: object properties: domains: type: array items: {} description: no description required: - domains application/x-www-form-urlencoded: schema: type: object properties: domains: type: array items: {} description: no description required: - domains responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/content_security_policy_settings.html components: securitySchemes: bearerAuth: type: http scheme: bearer description: 'Canvas OAuth2 access token sent as "Authorization: Bearer ". See https://canvas.instructure.com/doc/api/file.oauth.html' oauth2: type: oauth2 description: Canvas OAuth2. See https://canvas.instructure.com/doc/api/file.oauth.html and https://canvas.instructure.com/doc/api/file.oauth_endpoints.html flows: authorizationCode: authorizationUrl: https://canvas.instructure.com/login/oauth2/auth tokenUrl: https://canvas.instructure.com/login/oauth2/token refreshUrl: https://canvas.instructure.com/login/oauth2/token scopes: {} externalDocs: description: Canvas LMS REST API Documentation url: https://canvas.instructure.com/doc/api/ x-generated-from: https://canvas.instructure.com/doc/api/api-docs.json x-provenance: method: derived derived_by: API Evangelist enrichment pipeline (Swagger 1.2 -> OpenAPI 3.1 conversion) source: openapi/_original/swagger-1.2/*.json (144 verbatim first-party Swagger 1.2 documents) source_url: https://canvas.instructure.com/doc/api/api-docs.json fetched: '2026-09-05' http_status: 200