openapi: 3.2.0 info: title: Canvas LMS REST Logins API version: v1 summary: The complete Canvas LMS REST API, converted from the Swagger 1.2 documents Instructure publishes under https://canvas.instructure.com/doc/api/. description: The Canvas LMS REST API covers courses, assignments, quizzes, grades, users, enrollments, accounts, files, modules, rubrics, submissions, SIS imports, LTI, analytics and account administration. contact: name: Instructure Canvas url: https://canvas.instructure.com/doc/api/ license: name: AGPL-3.0 url: https://github.com/instructure/canvas-lms/blob/master/LICENSE servers: - url: https://canvas.instructure.com/api description: Instructure-hosted Canvas (canvas.instructure.com) - url: https://{canvas_host}/api description: Any Canvas instance; Canvas is multi-tenant and self-hostable, so the host is the institution's Canvas domain. variables: canvas_host: default: canvas.instructure.com description: Your institution's Canvas hostname, e.g. school.instructure.com security: - bearerAuth: [] - oauth2: [] tags: - name: Logins x-resource: logins externalDocs: url: https://canvas.instructure.com/doc/api/logins.html paths: /v1/accounts/{account_id}/logins: get: tags: - Logins operationId: list_user_logins_accounts summary: List user logins description: Given a user ID, return a paginated list of that user's logins for the given account. parameters: - name: account_id in: path schema: type: string required: true description: ID responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/logins.html post: tags: - Logins operationId: create_user_login summary: Create a user login description: Create a new login for an existing user in the given account. parameters: - name: account_id in: path schema: type: string required: true description: ID requestBody: required: false content: application/json: schema: type: object properties: user[id]: type: string description: The ID of the user to create the login for. login[unique_id]: type: string description: The unique ID for the new login. login[password]: type: string description: The new login's password. login[sis_user_id]: type: string description: 'SIS ID for the login. To set this parameter, the caller must be able to manage SIS permissions on the account.' login[integration_id]: type: string description: 'Integration ID for the login. To set this parameter, the caller must be able to manage SIS permissions on the account. The Integration ID is a secondary identifier useful for more complex SIS integrations.' login[authentication_provider_id]: type: string description: 'The authentication provider this login is associated with. Logins associated with a specific provider can only be used with that provider. Legacy providers (LDAP, CAS, SAML) will search for logins associated with them, or unassociated logins. New providers will only search for logins explicitly associated with them. This can be the integer ID of the provider, or the type of the provider (in which case, it will find the first matching provider).' login[declared_user_type]: type: string description: "The declared intention of the user type. This can be set, but does\nnot change any Canvas functionality with respect to their access.\nA user can still be a teacher, admin, student, etc. in any particular\ncontext without regard to this setting. This can be used for\nadministrative purposes for integrations to be able to more easily\nidentify why the user was created.\nValid values are:\n * administrative\n * observer\n * staff\n * student\n * student_other\n * teacher" login[must_reset_password]: type: boolean description: 'If true, the user will be required to change their password the next time they sign in with this login. Only valid for logins that support Canvas passwords.' user[existing_user_id]: type: string description: 'A Canvas User ID to identify a user in a trusted account (alternative to `id`, `existing_sis_user_id`, or `existing_integration_id`). This parameter is not available in OSS Canvas.' user[existing_integration_id]: type: string description: 'An Integration ID to identify a user in a trusted account (alternative to `id`, `existing_user_id`, or `existing_sis_user_id`). This parameter is not available in OSS Canvas.' user[existing_sis_user_id]: type: string description: 'An SIS User ID to identify a user in a trusted account (alternative to `id`, `existing_integration_id`, or `existing_user_id`). This parameter is not available in OSS Canvas.' user[trusted_account]: type: string description: 'The domain of the account to search for the user. This field is required when identifying a user in a trusted account. This parameter is not available in OSS Canvas.' required: - user[id] - login[unique_id] application/x-www-form-urlencoded: schema: type: object properties: user[id]: type: string description: The ID of the user to create the login for. login[unique_id]: type: string description: The unique ID for the new login. login[password]: type: string description: The new login's password. login[sis_user_id]: type: string description: 'SIS ID for the login. To set this parameter, the caller must be able to manage SIS permissions on the account.' login[integration_id]: type: string description: 'Integration ID for the login. To set this parameter, the caller must be able to manage SIS permissions on the account. The Integration ID is a secondary identifier useful for more complex SIS integrations.' login[authentication_provider_id]: type: string description: 'The authentication provider this login is associated with. Logins associated with a specific provider can only be used with that provider. Legacy providers (LDAP, CAS, SAML) will search for logins associated with them, or unassociated logins. New providers will only search for logins explicitly associated with them. This can be the integer ID of the provider, or the type of the provider (in which case, it will find the first matching provider).' login[declared_user_type]: type: string description: "The declared intention of the user type. This can be set, but does\nnot change any Canvas functionality with respect to their access.\nA user can still be a teacher, admin, student, etc. in any particular\ncontext without regard to this setting. This can be used for\nadministrative purposes for integrations to be able to more easily\nidentify why the user was created.\nValid values are:\n * administrative\n * observer\n * staff\n * student\n * student_other\n * teacher" login[must_reset_password]: type: boolean description: 'If true, the user will be required to change their password the next time they sign in with this login. Only valid for logins that support Canvas passwords.' user[existing_user_id]: type: string description: 'A Canvas User ID to identify a user in a trusted account (alternative to `id`, `existing_sis_user_id`, or `existing_integration_id`). This parameter is not available in OSS Canvas.' user[existing_integration_id]: type: string description: 'An Integration ID to identify a user in a trusted account (alternative to `id`, `existing_user_id`, or `existing_sis_user_id`). This parameter is not available in OSS Canvas.' user[existing_sis_user_id]: type: string description: 'An SIS User ID to identify a user in a trusted account (alternative to `id`, `existing_integration_id`, or `existing_user_id`). This parameter is not available in OSS Canvas.' user[trusted_account]: type: string description: 'The domain of the account to search for the user. This field is required when identifying a user in a trusted account. This parameter is not available in OSS Canvas.' required: - user[id] - login[unique_id] responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/logins.html /v1/users/{user_id}/logins: get: tags: - Logins operationId: list_user_logins_users summary: List user logins description: Given a user ID, return a paginated list of that user's logins for the given account. parameters: - name: user_id in: path schema: type: string required: true description: ID responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/logins.html /v1/users/reset_password: post: tags: - Logins operationId: kickoff_password_recovery_flow summary: Kickoff password recovery flow description: Given a user email, generate a nonce and email it to the user responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/logins.html /v1/accounts/{account_id}/logins/{id}: put: tags: - Logins operationId: edit_user_login summary: Edit a user login description: Update an existing login for a user in the given account. parameters: - name: account_id in: path schema: type: string required: true description: ID - name: id in: path schema: type: string required: true description: ID requestBody: required: false content: application/json: schema: type: object properties: login[unique_id]: type: string description: The new unique ID for the login. login[password]: type: string description: 'The new password for the login. Admins can only set a password for another user if the "Password setting by admins" account setting is enabled.' login[old_password]: type: string description: 'The prior password for the login. Required if the caller is changing their own password.' login[sis_user_id]: type: string description: 'SIS ID for the login. To set this parameter, the caller must be able to manage SIS permissions on the account.' login[integration_id]: type: string description: 'Integration ID for the login. To set this parameter, the caller must be able to manage SIS permissions on the account. The Integration ID is a secondary identifier useful for more complex SIS integrations.' login[authentication_provider_id]: type: string description: 'The authentication provider this login is associated with. Logins associated with a specific provider can only be used with that provider. Legacy providers (LDAP, CAS, SAML) will search for logins associated with them, or unassociated logins. New providers will only search for logins explicitly associated with them. This can be the integer ID of the provider, or the type of the provider (in which case, it will find the first matching provider). To unassociate from a known provider, specify null or an empty string.' login[workflow_state]: type: string enum: - active - suspended description: Used to suspend or re-activate a login. login[declared_user_type]: type: string description: "The declared intention of the user type. This can be set, but does\nnot change any Canvas functionality with respect to their access.\nA user can still be a teacher, admin, student, etc. in any particular\ncontext without regard to this setting. This can be used for\nadministrative purposes for integrations to be able to more easily\nidentify why the user was created.\nValid values are:\n * administrative\n * observer\n * staff\n * student\n * student_other\n * teacher" login[must_reset_password]: type: boolean description: 'If true, the user will be required to change their password the next time they sign in with this login. Cleared automatically when the password is changed. Only valid for logins that support Canvas passwords.' override_sis_stickiness: type: boolean description: 'Default is true. If false, any fields containing “sticky” changes will not be updated. See SIS CSV Format documentation for information on which fields can have SIS stickiness' application/x-www-form-urlencoded: schema: type: object properties: login[unique_id]: type: string description: The new unique ID for the login. login[password]: type: string description: 'The new password for the login. Admins can only set a password for another user if the "Password setting by admins" account setting is enabled.' login[old_password]: type: string description: 'The prior password for the login. Required if the caller is changing their own password.' login[sis_user_id]: type: string description: 'SIS ID for the login. To set this parameter, the caller must be able to manage SIS permissions on the account.' login[integration_id]: type: string description: 'Integration ID for the login. To set this parameter, the caller must be able to manage SIS permissions on the account. The Integration ID is a secondary identifier useful for more complex SIS integrations.' login[authentication_provider_id]: type: string description: 'The authentication provider this login is associated with. Logins associated with a specific provider can only be used with that provider. Legacy providers (LDAP, CAS, SAML) will search for logins associated with them, or unassociated logins. New providers will only search for logins explicitly associated with them. This can be the integer ID of the provider, or the type of the provider (in which case, it will find the first matching provider). To unassociate from a known provider, specify null or an empty string.' login[workflow_state]: type: string enum: - active - suspended description: Used to suspend or re-activate a login. login[declared_user_type]: type: string description: "The declared intention of the user type. This can be set, but does\nnot change any Canvas functionality with respect to their access.\nA user can still be a teacher, admin, student, etc. in any particular\ncontext without regard to this setting. This can be used for\nadministrative purposes for integrations to be able to more easily\nidentify why the user was created.\nValid values are:\n * administrative\n * observer\n * staff\n * student\n * student_other\n * teacher" login[must_reset_password]: type: boolean description: 'If true, the user will be required to change their password the next time they sign in with this login. Cleared automatically when the password is changed. Only valid for logins that support Canvas passwords.' override_sis_stickiness: type: boolean description: 'Default is true. If false, any fields containing “sticky” changes will not be updated. See SIS CSV Format documentation for information on which fields can have SIS stickiness' responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/logins.html /v1/users/{user_id}/logins/{id}: delete: tags: - Logins operationId: delete_user_login summary: Delete a user login description: Delete an existing login. parameters: - name: user_id in: path schema: type: string required: true description: ID - name: id in: path schema: type: string required: true description: ID responses: '200': description: Success, no content returned externalDocs: url: https://canvas.instructure.com/doc/api/logins.html components: securitySchemes: bearerAuth: type: http scheme: bearer description: 'Canvas OAuth2 access token sent as "Authorization: Bearer ". See https://canvas.instructure.com/doc/api/file.oauth.html' oauth2: type: oauth2 description: Canvas OAuth2. See https://canvas.instructure.com/doc/api/file.oauth.html and https://canvas.instructure.com/doc/api/file.oauth_endpoints.html flows: authorizationCode: authorizationUrl: https://canvas.instructure.com/login/oauth2/auth tokenUrl: https://canvas.instructure.com/login/oauth2/token refreshUrl: https://canvas.instructure.com/login/oauth2/token scopes: {} externalDocs: description: Canvas LMS REST API Documentation url: https://canvas.instructure.com/doc/api/ x-generated-from: https://canvas.instructure.com/doc/api/api-docs.json x-provenance: method: derived derived_by: API Evangelist enrichment pipeline (Swagger 1.2 -> OpenAPI 3.1 conversion) source: openapi/_original/swagger-1.2/*.json (144 verbatim first-party Swagger 1.2 documents) source_url: https://canvas.instructure.com/doc/api/api-docs.json fetched: '2026-09-05' http_status: 200