IntegrationsLTI 1.3 — Launch from Canvas / Moodle

LTI 1.3 — Launch EmbayLMS from another LMS

Who this guide is for: Tenant administrators who want learners to open EmbayLMS content from inside Canvas, Moodle, Blackboard, Brightspace or any other LTI 1.3 Advantage platform — with single sign-on and no second login.

Plan availability: LTI registrations are part of the developer surface and require the Growth plan or higher (same gate as API keys and webhooks).

Overview

LTI’s vocabulary is inverted from what a reader expects, so here it is once:

TermWhoIn this guide
PlatformThe LMS that launches content — Canvas, Moodle, Blackboard…your other LMS
ToolThe application being launched — EmbayLMSus
DeploymentOne placement of the tool inside the platform (Canvas issues one per account or course)a row under the platform

Registration is symmetric. You tell the platform our endpoints (login, launch, JWKS); you tell us the platform’s identity and endpoints (issuer, client ID, OIDC login URL, JWKS URL). Both sides then verify each other’s signed messages with public keys — there is no shared secret in LTI 1.3.

Prerequisites

  • The Owner role, or a custom role holding integration.lti:manage.
  • Administrator access to the platform to add an external tool / developer key.
  • A course published in EmbayLMS to launch into (a deployment can be pinned to one, or left open so the platform’s deep-link picker chooses).

Step 1 — Copy our endpoints

Settings → Integrations → LTI 1.3. The Our endpoints panel lists what the platform’s “add external tool” form asks for, each with a copy button:

Field on the platformValue
OIDC login / initiation URLhttps://<your-tenant>.embaylms.com/api/v1/lti/login
Target link / launch URLhttps://<your-tenant>.embaylms.com/api/v1/lti/launch
Deep linking URLhttps://<your-tenant>.embaylms.com/api/v1/lti/deep-link
Public JWK URLhttps://<your-tenant>.embaylms.com/api/v1/lti/.well-known/jwks.json
Redirect URIsthe launch URL and the deep-link URL

The origin is your tenant’s own subdomain — launches resolve the tenant from the host, so a URL from another tenant’s page will not work for yours.

Step 2 — Register the platform with EmbayLMS

Once the platform has issued a client ID for the tool, click Register a platform and fill in:

FieldWhere to find itNotes
Name—Your label, e.g. Canvas Production
IssuerPlatform documentationThe iss claim the platform sends. Canvas: https://canvas.instructure.com; Moodle: your Moodle site URL
Client IDDeveloper key / tool registrationIssued by the platform. Must be unique across your registrations — it is what a launch is matched on
OIDC login URLPlatform documentationCanvas: https://<canvas>/api/lti/authorize_redirect; Moodle: https://<moodle>/mod/lti/auth.php
Token URLPlatform documentationCanvas: https://<canvas>/login/oauth2/token; Moodle: https://<moodle>/mod/lti/token.php
JWKS URLPlatform documentationCanvas: https://<canvas>/api/lti/security/jwks; Moodle: https://<moodle>/mod/lti/certs.php
Deep linking enabled—On by default; lets instructors pick a course from inside the platform
Active—Off pauses launches from this platform without deleting the registration

All URLs must be https://.

Step 3 — Add the deployment

After the platform has deployed the tool (Canvas: Apps → +App; Moodle: Site administration → Plugins → External tool → Manage tools), it shows a deployment ID. Under the platform row, enter it and optionally pin it to a course: a pinned deployment always launches that course; an unpinned one relies on the link’s target (deep linking) instead.

A platform can have several deployments (one per Canvas sub-account, say); each deployment ID must be unique within its platform.

Step 4 — Test the launch

From the platform, open the placement as a learner. The first launch creates the learner’s EmbayLMS account (matched on email) and lands in the course player; later launches sign them straight in.

Configuration reference

FieldRequiredDescription
NameYesLabel shown in the list
IssuerYesThe platform’s OIDC issuer (iss)
Client IDYesPlatform-issued; unique per tenant
OIDC login URLYesWhere we send the login initiation
Token URLYesStored for LTI Advantage services
JWKS URLYesWhere we fetch the platform’s public keys
Deep linking enabled—Default on
Active—Default on
Deployment IDYes (per deployment)From the platform; unique per platform
Pinned courseNo (per deployment)Published courses only

Every create, edit and delete writes an audit-log entry (lti_tool, lti_deployment). Deleting a platform deletes its deployments and refuses its next launch immediately.

Troubleshooting

SymptomLikely cause / fix
”A platform with this client ID is already registered”Each client ID can be registered once. Edit the existing row instead, or delete it first.
Launch fails with “tool not found”The client ID in the launch does not match a registration, or the registration is inactive. Check the client ID the platform shows against the row.
Launch fails with a signature errorThe JWKS URL is wrong or unreachable from our side, or the platform is using a key it has since rotated — re-check the URL and retry.
Deep linking shows no pickerDeep linking enabled is off on the registration, or the platform placement is not a deep-link placement.
The LTI tab is missingYour plan is below Growth, or your role lacks integration.lti:view. If the permission was just granted, sign out and back in.