Connecting Canvas for the First Time
Canvas LTI identity and Canvas API authorization are separate. The first time a student needs Canvas API access, Safe Online Exam displays a Connect Canvas button.1
Open Safe Online Exam
Select Safe Online Exam from the Canvas course-navigation menu. If this is the first time you’ve used the tool in any course, you’ll see a prompt to connect your Canvas account.
2
Select Connect Canvas
Choose Connect Canvas to begin the Canvas OAuth authorization flow.
3
Approve the Authorization
Review and approve the requested permissions. Safe Online Exam requests the same complete application scope set used by instructors — including the session-token permission required to obtain a one-time Canvas session URL for SEB, and the course-list permission needed when the same account is also a teacher in another course. Canvas still enforces your actual course permissions; scope possession is never treated as a role or course-authorization check. The authorization does not copy your browser’s cookies into the
.seb file.4
Return to the Course Tool
After approving, Canvas returns you to the Safe Online Exam course page. Your authorization is stored and will not need to be repeated unless your Canvas permissions change. Use Reconnect Canvas if you are ever prompted to refresh the connection.
Optional Setup Check
Safe Online Exam provides a Setup check that exercises your device’s readiness before a high-stakes assessment. Running it at least once per device is strongly recommended.1
Confirm Your Canvas Connection
The setup check verifies that your Canvas OAuth grant is active.
2
Allow the Browser to Open SEB
When prompted by your browser’s native-protocol dialog, allow it to open Safe Exam Browser.
3
Wait for the Readiness Report
The check page tests certificate decryption, SEB runtime detection, connectivity, storage, and Config Key proof, then reports readiness.
4
Quit SEB and Return to Canvas
Once the check reports success, quit SEB and return to the Canvas course.
Until the setup check reminder is dismissed or the check is started, the launch page for protected quizzes shows Setup check (recommended) alongside Return to course and Open Safe Exam Browser. Selecting the button opens the reminder dialog — it never interrupts or blocks a normal assessment launch. After dismissal or starting the check, the standard Setup check action remains available without the recommendation. This preference is not a device-trust or setup-completion record.
Launching a Protected Assessment
1
Open the Assessment
Choose the assessment from the Safe Online Exam student list, or navigate directly to its Canvas quiz page.
2
Select Open Safe Exam Browser
On the SEB-required page, select Open Safe Exam Browser. Your browser will display a native-protocol confirmation dialog.
3
Approve the Protocol Prompt
Approve the dialog to allow your browser to hand off to SEB.
4
If SEB Does Not Open
If SEB does not launch, use the delayed recovery panel on the page to install or open SEB, then retry with a fresh launch. Do not reuse an old download URL or a previously downloaded
.seb file — the configuration grant is one-time and short-lived.5
Complete the Assessment Inside SEB
SEB opens Canvas within the controlled browser environment. The Safe Online Exam detector automatically requests the current Config Key from the SEB JavaScript API and submits proof to the service.Only valid, current Config Key proof can release the Canvas access code, approved exam tools, and an exit grant. The detector fills only an unambiguous Canvas access-code prompt — it does not fill other fields or treat DOM content as authorization.
The configuration grant that triggers your
.seb download is a one-time capability valid for 120 seconds, bound to your LTI principal, course, content ID, and the current settings fingerprint. If the download or SEB launch fails, return to the Safe Online Exam launch page and start a fresh launch to obtain a new grant.Finishing and Exiting
After completing the assessment, use the displayed quit action inside SEB to exit cleanly.- Classic Quiz: Safe Online Exam waits for Canvas’s completed-submission result before allowing exit.
- New Quiz: The exit flow waits for the New Quiz authoritative result interface to confirm completion.
What You Should Never Share
Troubleshooting Tips
Canvas connection issues
Canvas connection issues
If Safe Online Exam shows a Connect Canvas or Reconnect Canvas prompt unexpectedly, your OAuth grant may have expired or Canvas permissions may have changed. Select Reconnect Canvas to re-authorize. If the problem persists, contact your institution’s Canvas administrator.
Access code is not filling automatically
Access code is not filling automatically
The detector fills the Canvas access-code prompt only when it can unambiguously identify the correct field and valid Config Key proof has been returned by the service. If the access code does not fill:
- Confirm you opened the assessment through Safe Online Exam, not directly from the Canvas quiz URL.
- Ensure SEB is running the current
.sebconfiguration, not a cached or outdated one. - If the quiz was recently updated by the instructor, the configuration fingerprint may have changed — return to the launch page and download a fresh
.sebfile. - Contact your instructor if the problem persists; do not attempt to enter an access code manually from memory or external sources.
The setup check reports a failure
The setup check reports a failure
A failed setup check may indicate a certificate decryption problem, a network connectivity issue, or that SEB is not installed or is running an incompatible version. Note the specific error reported on the check page and share it with your institution’s support channel along with your SEB version, operating system, and approximate time.
Related Pages
Instructor Workflow
See how instructors enable SEB, set passwords, and configure exam tools for your assessments.
Troubleshooting
Full diagnostic guidance for launch, OAuth, detector, and SEB issues.
Operations Testing
Understand the acceptance test flow used to validate SEB configurations before deployment.
Architecture
Learn how the protection flow works end-to-end, from LTI launch through Config Key proof.