# Safe Online Exam - [Safe Online Exam: Canvas LTI App for Safe Exam Browser](https://docs.safeonlineexam.com/introduction.md): What Safe Online Exam does, who it serves, Version 1 features, the SEB protection flow, technology stack, stable routes, and PolyForm license terms. - [Architecture and Security Model — Safe Online Exam](https://docs.safeonlineexam.com/architecture.md): Safe Online Exam runtime shape, code ownership, LTI and OAuth trust model, SEB lifecycle, certificate encryption boundary, and all ten persistence tables. - [Safe Online Exam Deployment: Choosing Your Platform](https://docs.safeonlineexam.com/deployment/overview.md): Compare Cloud Run, Docker Compose, and container modes, understand image pinning and release trust, and review operational requirements before starting. - [Docker Compose Deployment: Safe Online Exam on Linux](https://docs.safeonlineexam.com/deployment/docker-compose.md): Install Safe Online Exam on a Linux host with Docker Compose, covering bundle verification, guided setup, TLS proxy, backups, and the upgrade helper. - [Cloud Run and Cloud SQL Deployment: Safe Online Exam](https://docs.safeonlineexam.com/deployment/cloud-run.md): Deploy Safe Online Exam on Cloud Run with Cloud SQL via the versioned bundle — covering installer stages, Cloud SQL profiles, IAM setup, and upgrades. - [Registering Safe Online Exam as a Canvas LTI 1.3 App](https://docs.safeonlineexam.com/deployment/canvas-setup.md): Create the Canvas API OAuth key and LTI 1.3 Developer Key, install the external app, and load the SEB detector script through the Canvas account theme. - [SEB Config Certificate: Generation, Rotation, and Trust](https://docs.safeonlineexam.com/deployment/certificate-management.md): Generate the X.509 identity that encrypts Safe Online Exam .seb files, deploy it to clients, rotate it safely, and review the trust model and fallback. - [Environment Variable Reference for Safe Online Exam](https://docs.safeonlineexam.com/configuration/reference.md): Safe Online Exam env var reference: profile resolution, hardened startup validation, PostgreSQL settings, required app values, and file-based secrets. - [Secret Management and File-Based Configuration Guide](https://docs.safeonlineexam.com/configuration/secrets.md): File-based secret alternatives, OAuth token keyring format, Compose secrets profile, and rotation procedures for Safe Online Exam production credentials. - [Canvas LTI 1.3 Endpoint and Deployment ID Settings](https://docs.safeonlineexam.com/configuration/lti-settings.md): Reference for Safe Online Exam LTI 1.3 issuer, JWKS, auth URL, deployment-ID policy, Canvas API base settings, and self-hosted Canvas considerations. - [Root-Account Administrator Workflow in Safe Online Exam](https://docs.safeonlineexam.com/user-guide/administrators.md): Manage the root-account dashboard, connect courses, run recovery actions, and configure school exam tool presets for institution-wide rollout. - [Instructor Course Setup and SEB Management Workflow](https://docs.safeonlineexam.com/user-guide/instructors.md): Connect Canvas, discover Classic and New Quizzes, configure SEB policy, manage exam tools, and enable or disable SEB protection per assessment. - [Student Launch and Assessment Workflow in Safe Online Exam](https://docs.safeonlineexam.com/user-guide/students.md): Connect Canvas once, run the optional setup check, download a signed SEB configuration, prove the Config Key, and complete a protected assessment securely. - [Testing and Acceptance for Safe Online Exam Deployments](https://docs.safeonlineexam.com/operations/testing.md): Test gates, local verification commands, and the Canvas and SEB role-based acceptance sequence required before Safe Online Exam goes to production. - [Diagnosing Safe Online Exam Launch and Configuration Issues](https://docs.safeonlineexam.com/operations/troubleshooting.md): Symptom-driven diagnosis for Safe Online Exam service, LTI launch, Canvas OAuth, SEB configuration, detector loading, and certificate failure categories. - [Upgrading and Rolling Back Safe Online Exam Deployments](https://docs.safeonlineexam.com/operations/upgrading.md): Upgrade procedure for Docker Compose and Cloud Run, covering the mandatory migration job, staged candidate revision checks, and schema-aware rollback. - [LTI 1.3 Routes and Public Endpoints — Safe Online Exam](https://docs.safeonlineexam.com/api/lti-routes.md): Reference for Safe Online Exam's public status, health, JWKS, LTI config, OIDC initiation, and signed LTI 1.3 launch endpoints used by Canvas. - [Canvas OAuth Authorization Routes — Safe Online Exam API](https://docs.safeonlineexam.com/api/oauth-routes.md): Reference for Safe Online Exam's Canvas OAuth endpoints — instructor, student, and admin authorization flows, the shared callback, and the status check. - [SEB Student Config Grant, Access-Code, and Exit Routes](https://docs.safeonlineexam.com/api/seb-student-routes.md): One-time grants, encrypted .seb download, Config Key proof, access-code release, session readiness, launch handoff, and exit flows for Safe Online Exam. - [Canvas SEB Detector, Theme Loader, and Diagnostics Routes](https://docs.safeonlineexam.com/api/seb-detector-routes.md): Stable detector URL, Canvas theme loader, compatibility alias, debug trace endpoint, and the server-owned YouTube player page for Safe Online Exam. - [Instructor Assessment Management Routes — Safe Online Exam](https://docs.safeonlineexam.com/api/instructor-routes.md): Reference for /api/quizzes: discovery, SEB enable/disable, course defaults, exam-tool copy, and session-bound password reveal for verified instructors. - [Root-Account Administrator Routes — Safe Online Exam API](https://docs.safeonlineexam.com/api/admin-routes.md): Reference for /api/admin: account summary, course connection and reset, password reveal, quit-password rotation, SEB toggles, and preset rollout batches.