> ## Documentation Index
> Fetch the complete documentation index at: https://docs.safeonlineexam.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Student Launch and Assessment Workflow in Safe Online Exam

> Connect Canvas once, run the optional setup check, download a signed SEB configuration, prove the Config Key, and complete a protected assessment securely.

Safe Online Exam guides students through a carefully sequenced launch flow that connects Canvas, delivers an encrypted Safe Exam Browser configuration, and releases the Canvas access code only after SEB proves it is running the current configuration. This page covers every student-facing step — from first-time Canvas authorization through post-assessment exit.

***

## Connecting Canvas for the First Time

Canvas LTI identity and Canvas API authorization are separate. The first time a student needs Canvas API access, Safe Online Exam displays a **Connect Canvas** button.

<Steps>
  <Step title="Open Safe Online Exam">
    Select **Safe Online Exam** from the Canvas course-navigation menu. If this is the first time you've used the tool in any course, you'll see a prompt to connect your Canvas account.
  </Step>

  <Step title="Select Connect Canvas">
    Choose **Connect Canvas** to begin the Canvas OAuth authorization flow.
  </Step>

  <Step title="Approve the Authorization">
    Review and approve the requested permissions. Safe Online Exam requests the same complete application scope set used by instructors — including the session-token permission required to obtain a one-time Canvas session URL for SEB, and the course-list permission needed when the same account is also a teacher in another course. Canvas still enforces your actual course permissions; scope possession is never treated as a role or course-authorization check. The authorization does not copy your browser's cookies into the `.seb` file.
  </Step>

  <Step title="Return to the Course Tool">
    After approving, Canvas returns you to the Safe Online Exam course page. Your authorization is stored and will not need to be repeated unless your Canvas permissions change. Use **Reconnect Canvas** if you are ever prompted to refresh the connection.
  </Step>
</Steps>

***

## Optional Setup Check

Safe Online Exam provides a **Setup check** that exercises your device's readiness before a high-stakes assessment. Running it at least once per device is strongly recommended.

<Steps>
  <Step title="Confirm Your Canvas Connection">
    The setup check verifies that your Canvas OAuth grant is active.
  </Step>

  <Step title="Allow the Browser to Open SEB">
    When prompted by your browser's native-protocol dialog, allow it to open Safe Exam Browser.
  </Step>

  <Step title="Wait for the Readiness Report">
    The check page tests certificate decryption, SEB runtime detection, connectivity, storage, and Config Key proof, then reports readiness.
  </Step>

  <Step title="Quit SEB and Return to Canvas">
    Once the check reports success, quit SEB and return to the Canvas course.
  </Step>
</Steps>

The setup check does **not** release an assessment access code, prove that your device is institution-managed, or guarantee that the network or assessment will be unchanged on exam day.

<Info>
  Until the setup check reminder is dismissed or the check is started, the launch page for protected quizzes shows **Setup check (recommended)** alongside **Return to course** and **Open Safe Exam Browser**. Selecting the button opens the reminder dialog — it never interrupts or blocks a normal assessment launch. After dismissal or starting the check, the standard **Setup check** action remains available without the recommendation. This preference is not a device-trust or setup-completion record.
</Info>

***

## Launching a Protected Assessment

<Steps>
  <Step title="Open the Assessment">
    Choose the assessment from the Safe Online Exam student list, or navigate directly to its Canvas quiz page.
  </Step>

  <Step title="Select Open Safe Exam Browser">
    On the SEB-required page, select **Open Safe Exam Browser**. Your browser will display a native-protocol confirmation dialog.
  </Step>

  <Step title="Approve the Protocol Prompt">
    Approve the dialog to allow your browser to hand off to SEB.
  </Step>

  <Step title="If SEB Does Not Open">
    If SEB does not launch, use the delayed recovery panel on the page to install or open SEB, then retry with a fresh launch. Do not reuse an old download URL or a previously downloaded `.seb` file — the configuration grant is one-time and short-lived.
  </Step>

  <Step title="Complete the Assessment Inside SEB">
    SEB opens Canvas within the controlled browser environment. The Safe Online Exam detector automatically requests the current Config Key from the SEB JavaScript API and submits proof to the service.

    Only valid, current Config Key proof can release the Canvas access code, approved exam tools, and an exit grant. The detector fills only an unambiguous Canvas access-code prompt — it does not fill other fields or treat DOM content as authorization.
  </Step>
</Steps>

<Note>
  The configuration grant that triggers your `.seb` download is a one-time capability valid for 120 seconds, bound to your LTI principal, course, content ID, and the current settings fingerprint. If the download or SEB launch fails, return to the Safe Online Exam launch page and start a fresh launch to obtain a new grant.
</Note>

***

## Finishing and Exiting

After completing the assessment, use the displayed quit action inside SEB to exit cleanly.

* **Classic Quiz:** Safe Online Exam waits for Canvas's completed-submission result before allowing exit.
* **New Quiz:** The exit flow waits for the New Quiz authoritative result interface to confirm completion.

Cancelling a Canvas submission confirmation dialog does not start the exit flow — you must actually complete the submission.

Native early quit remains protected by the effective exit password configured for the course. If you need to exit early for an approved reason, contact your instructor or the approved support channel. Do not attempt to bypass the client policy.

***

## What You Should Never Share

<Warning>
  Never share the following with anyone — including support staff, classmates, or over email and chat. Sharing these items can compromise exam integrity and your own academic standing.

  * Canvas access codes
  * One-time session URLs
  * `.seb` configuration files from a live assessment
  * `.p12` identity files or private keys

  Sensitive responses from the service are short-lived, served with `no-store` headers, and are bound to your current session. They cannot be reused by another person even if forwarded.
</Warning>

***

## Troubleshooting Tips

<Accordion title="Canvas connection issues">
  If Safe Online Exam shows a **Connect Canvas** or **Reconnect Canvas** prompt unexpectedly, your OAuth grant may have expired or Canvas permissions may have changed. Select **Reconnect Canvas** to re-authorize. If the problem persists, contact your institution's Canvas administrator.
</Accordion>

<Accordion title="SEB does not open after selecting the button">
  Ensure Safe Exam Browser is installed on your device. If it is installed but does not open, check that your browser is permitted to open the `sebs://` or `seb://` protocol. Use the delayed recovery panel on the launch page to open SEB directly, then retry with a fresh launch from the Safe Online Exam page — do not reuse the previous download link.
</Accordion>

<Accordion title="Access code is not filling automatically">
  The detector fills the Canvas access-code prompt only when it can unambiguously identify the correct field and valid Config Key proof has been returned by the service. If the access code does not fill:

  * Confirm you opened the assessment through Safe Online Exam, not directly from the Canvas quiz URL.
  * Ensure SEB is running the current `.seb` configuration, not a cached or outdated one.
  * If the quiz was recently updated by the instructor, the configuration fingerprint may have changed — return to the launch page and download a fresh `.seb` file.
  * Contact your instructor if the problem persists; do not attempt to enter an access code manually from memory or external sources.
</Accordion>

<Accordion title="The setup check reports a failure">
  A failed setup check may indicate a certificate decryption problem, a network connectivity issue, or that SEB is not installed or is running an incompatible version. Note the specific error reported on the check page and share it with your institution's support channel along with your SEB version, operating system, and approximate time.
</Accordion>

***

## Related Pages

<CardGroup cols={2}>
  <Card title="Instructor Workflow" icon="chalkboard-teacher" href="/user-guide/instructors">
    See how instructors enable SEB, set passwords, and configure exam tools for your assessments.
  </Card>

  <Card title="Troubleshooting" icon="wrench" href="/operations/troubleshooting">
    Full diagnostic guidance for launch, OAuth, detector, and SEB issues.
  </Card>

  <Card title="Operations Testing" icon="flask" href="/operations/testing">
    Understand the acceptance test flow used to validate SEB configurations before deployment.
  </Card>

  <Card title="Architecture" icon="diagram-project" href="/architecture">
    Learn how the protection flow works end-to-end, from LTI launch through Config Key proof.
  </Card>
</CardGroup>
