LTI 1.3 — Launch EmbayLMS from another LMS
Who this guide is for: Tenant administrators who want learners to open EmbayLMS content from inside Canvas, Moodle, Blackboard, Brightspace or any other LTI 1.3 Advantage platform — with single sign-on and no second login.
Plan availability: LTI registrations are part of the developer surface and require the Growth plan or higher (same gate as API keys and webhooks).
Overview
LTI’s vocabulary is inverted from what a reader expects, so here it is once:
| Term | Who | In this guide |
|---|---|---|
| Platform | The LMS that launches content — Canvas, Moodle, Blackboard… | your other LMS |
| Tool | The application being launched — EmbayLMS | us |
| Deployment | One placement of the tool inside the platform (Canvas issues one per account or course) | a row under the platform |
Registration is symmetric. You tell the platform our endpoints (login, launch, JWKS); you tell us the platform’s identity and endpoints (issuer, client ID, OIDC login URL, JWKS URL). Both sides then verify each other’s signed messages with public keys — there is no shared secret in LTI 1.3.
Prerequisites
- The Owner role, or a custom role holding
integration.lti:manage. - Administrator access to the platform to add an external tool / developer key.
- A course published in EmbayLMS to launch into (a deployment can be pinned to one, or left open so the platform’s deep-link picker chooses).
Step 1 — Copy our endpoints
Settings → Integrations → LTI 1.3. The Our endpoints panel lists what the platform’s “add external tool” form asks for, each with a copy button:
| Field on the platform | Value |
|---|---|
| OIDC login / initiation URL | https://<your-tenant>.embaylms.com/api/v1/lti/login |
| Target link / launch URL | https://<your-tenant>.embaylms.com/api/v1/lti/launch |
| Deep linking URL | https://<your-tenant>.embaylms.com/api/v1/lti/deep-link |
| Public JWK URL | https://<your-tenant>.embaylms.com/api/v1/lti/.well-known/jwks.json |
| Redirect URIs | the launch URL and the deep-link URL |
The origin is your tenant’s own subdomain — launches resolve the tenant from the host, so a URL from another tenant’s page will not work for yours.
Step 2 — Register the platform with EmbayLMS
Once the platform has issued a client ID for the tool, click Register a platform and fill in:
| Field | Where to find it | Notes |
|---|---|---|
| Name | — | Your label, e.g. Canvas Production |
| Issuer | Platform documentation | The iss claim the platform sends. Canvas: https://canvas.instructure.com; Moodle: your Moodle site URL |
| Client ID | Developer key / tool registration | Issued by the platform. Must be unique across your registrations — it is what a launch is matched on |
| OIDC login URL | Platform documentation | Canvas: https://<canvas>/api/lti/authorize_redirect; Moodle: https://<moodle>/mod/lti/auth.php |
| Token URL | Platform documentation | Canvas: https://<canvas>/login/oauth2/token; Moodle: https://<moodle>/mod/lti/token.php |
| JWKS URL | Platform documentation | Canvas: https://<canvas>/api/lti/security/jwks; Moodle: https://<moodle>/mod/lti/certs.php |
| Deep linking enabled | — | On by default; lets instructors pick a course from inside the platform |
| Active | — | Off pauses launches from this platform without deleting the registration |
All URLs must be https://.
Step 3 — Add the deployment
After the platform has deployed the tool (Canvas: Apps → +App; Moodle: Site administration → Plugins → External tool → Manage tools), it shows a deployment ID. Under the platform row, enter it and optionally pin it to a course: a pinned deployment always launches that course; an unpinned one relies on the link’s target (deep linking) instead.
A platform can have several deployments (one per Canvas sub-account, say); each deployment ID must be unique within its platform.
Step 4 — Test the launch
From the platform, open the placement as a learner. The first launch creates the learner’s EmbayLMS account (matched on email) and lands in the course player; later launches sign them straight in.
Configuration reference
| Field | Required | Description |
|---|---|---|
| Name | Yes | Label shown in the list |
| Issuer | Yes | The platform’s OIDC issuer (iss) |
| Client ID | Yes | Platform-issued; unique per tenant |
| OIDC login URL | Yes | Where we send the login initiation |
| Token URL | Yes | Stored for LTI Advantage services |
| JWKS URL | Yes | Where we fetch the platform’s public keys |
| Deep linking enabled | — | Default on |
| Active | — | Default on |
| Deployment ID | Yes (per deployment) | From the platform; unique per platform |
| Pinned course | No (per deployment) | Published courses only |
Every create, edit and delete writes an audit-log entry (lti_tool,
lti_deployment). Deleting a platform deletes its deployments and refuses its
next launch immediately.
Troubleshooting
| Symptom | Likely cause / fix |
|---|---|
| ”A platform with this client ID is already registered” | Each client ID can be registered once. Edit the existing row instead, or delete it first. |
| Launch fails with “tool not found” | The client ID in the launch does not match a registration, or the registration is inactive. Check the client ID the platform shows against the row. |
| Launch fails with a signature error | The JWKS URL is wrong or unreachable from our side, or the platform is using a key it has since rotated — re-check the URL and retry. |
| Deep linking shows no picker | Deep linking enabled is off on the registration, or the platform placement is not a deep-link placement. |
| The LTI tab is missing | Your plan is below Growth, or your role lacks integration.lti:view. If the permission was just granted, sign out and back in. |