Skip to main content
Safe Online Exam guides students through a carefully sequenced launch flow that connects Canvas, delivers an encrypted Safe Exam Browser configuration, and releases the Canvas access code only after SEB proves it is running the current configuration. This page covers every student-facing step — from first-time Canvas authorization through post-assessment exit.

Connecting Canvas for the First Time

Canvas LTI identity and Canvas API authorization are separate. The first time a student needs Canvas API access, Safe Online Exam displays a Connect Canvas button.
1

Open Safe Online Exam

Select Safe Online Exam from the Canvas course-navigation menu. If this is the first time you’ve used the tool in any course, you’ll see a prompt to connect your Canvas account.
2

Select Connect Canvas

Choose Connect Canvas to begin the Canvas OAuth authorization flow.
3

Approve the Authorization

Review and approve the requested permissions. Safe Online Exam requests the same complete application scope set used by instructors — including the session-token permission required to obtain a one-time Canvas session URL for SEB, and the course-list permission needed when the same account is also a teacher in another course. Canvas still enforces your actual course permissions; scope possession is never treated as a role or course-authorization check. The authorization does not copy your browser’s cookies into the .seb file.
4

Return to the Course Tool

After approving, Canvas returns you to the Safe Online Exam course page. Your authorization is stored and will not need to be repeated unless your Canvas permissions change. Use Reconnect Canvas if you are ever prompted to refresh the connection.

Optional Setup Check

Safe Online Exam provides a Setup check that exercises your device’s readiness before a high-stakes assessment. Running it at least once per device is strongly recommended.
1

Confirm Your Canvas Connection

The setup check verifies that your Canvas OAuth grant is active.
2

Allow the Browser to Open SEB

When prompted by your browser’s native-protocol dialog, allow it to open Safe Exam Browser.
3

Wait for the Readiness Report

The check page tests certificate decryption, SEB runtime detection, connectivity, storage, and Config Key proof, then reports readiness.
4

Quit SEB and Return to Canvas

Once the check reports success, quit SEB and return to the Canvas course.
The setup check does not release an assessment access code, prove that your device is institution-managed, or guarantee that the network or assessment will be unchanged on exam day.
Until the setup check reminder is dismissed or the check is started, the launch page for protected quizzes shows Setup check (recommended) alongside Return to course and Open Safe Exam Browser. Selecting the button opens the reminder dialog — it never interrupts or blocks a normal assessment launch. After dismissal or starting the check, the standard Setup check action remains available without the recommendation. This preference is not a device-trust or setup-completion record.

Launching a Protected Assessment

1

Open the Assessment

Choose the assessment from the Safe Online Exam student list, or navigate directly to its Canvas quiz page.
2

Select Open Safe Exam Browser

On the SEB-required page, select Open Safe Exam Browser. Your browser will display a native-protocol confirmation dialog.
3

Approve the Protocol Prompt

Approve the dialog to allow your browser to hand off to SEB.
4

If SEB Does Not Open

If SEB does not launch, use the delayed recovery panel on the page to install or open SEB, then retry with a fresh launch. Do not reuse an old download URL or a previously downloaded .seb file — the configuration grant is one-time and short-lived.
5

Complete the Assessment Inside SEB

SEB opens Canvas within the controlled browser environment. The Safe Online Exam detector automatically requests the current Config Key from the SEB JavaScript API and submits proof to the service.Only valid, current Config Key proof can release the Canvas access code, approved exam tools, and an exit grant. The detector fills only an unambiguous Canvas access-code prompt — it does not fill other fields or treat DOM content as authorization.
The configuration grant that triggers your .seb download is a one-time capability valid for 120 seconds, bound to your LTI principal, course, content ID, and the current settings fingerprint. If the download or SEB launch fails, return to the Safe Online Exam launch page and start a fresh launch to obtain a new grant.

Finishing and Exiting

After completing the assessment, use the displayed quit action inside SEB to exit cleanly.
  • Classic Quiz: Safe Online Exam waits for Canvas’s completed-submission result before allowing exit.
  • New Quiz: The exit flow waits for the New Quiz authoritative result interface to confirm completion.
Cancelling a Canvas submission confirmation dialog does not start the exit flow — you must actually complete the submission. Native early quit remains protected by the effective exit password configured for the course. If you need to exit early for an approved reason, contact your instructor or the approved support channel. Do not attempt to bypass the client policy.

What You Should Never Share

Never share the following with anyone — including support staff, classmates, or over email and chat. Sharing these items can compromise exam integrity and your own academic standing.
  • Canvas access codes
  • One-time session URLs
  • .seb configuration files from a live assessment
  • .p12 identity files or private keys
Sensitive responses from the service are short-lived, served with no-store headers, and are bound to your current session. They cannot be reused by another person even if forwarded.

Troubleshooting Tips

If Safe Online Exam shows a Connect Canvas or Reconnect Canvas prompt unexpectedly, your OAuth grant may have expired or Canvas permissions may have changed. Select Reconnect Canvas to re-authorize. If the problem persists, contact your institution’s Canvas administrator.
Ensure Safe Exam Browser is installed on your device. If it is installed but does not open, check that your browser is permitted to open the sebs:// or seb:// protocol. Use the delayed recovery panel on the launch page to open SEB directly, then retry with a fresh launch from the Safe Online Exam page — do not reuse the previous download link.
The detector fills the Canvas access-code prompt only when it can unambiguously identify the correct field and valid Config Key proof has been returned by the service. If the access code does not fill:
  • Confirm you opened the assessment through Safe Online Exam, not directly from the Canvas quiz URL.
  • Ensure SEB is running the current .seb configuration, not a cached or outdated one.
  • If the quiz was recently updated by the instructor, the configuration fingerprint may have changed — return to the launch page and download a fresh .seb file.
  • Contact your instructor if the problem persists; do not attempt to enter an access code manually from memory or external sources.
A failed setup check may indicate a certificate decryption problem, a network connectivity issue, or that SEB is not installed or is running an incompatible version. Note the specific error reported on the check page and share it with your institution’s support channel along with your SEB version, operating system, and approximate time.

Instructor Workflow

See how instructors enable SEB, set passwords, and configure exam tools for your assessments.

Troubleshooting

Full diagnostic guidance for launch, OAuth, detector, and SEB issues.

Operations Testing

Understand the acceptance test flow used to validate SEB configurations before deployment.

Architecture

Learn how the protection flow works end-to-end, from LTI launch through Config Key proof.