How do external tool sessionless launch URLs work?

Question asked by Erik Scull on Jan 24, 2017
I'm having a tough time finding documentation on how sessionless launch URLs work. The API docs describe how to retrieve them (External Tools - Canvas LMS REST API Documentation ) but it's a bit unclear to me how they are used. They seem to permit a single-use launch of the tool, but how is authentication handled without the HTTP POST of a typical LTI 1.x tool launch?


To help me wrap my mind around it, I would be very grateful if someone could sketch out a use-case or two --even in super broad strokes-- outlining how and in what scenarios sessionless URLs are best used.


Many thanks!