[ARCHIVED] Limitations of Access tokens
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
what are the limitations of an user generated Access token? if a student gets a teacher to share a token with them what access could they have ?
Thank you!
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Well, if the student knows what they are doing they will have the same access as the teacher to Canvas. They can view grades, post grades, create assignments, pretty much everything the teacher can do and for all of the teacher's courses. They would likely have to do it all through APIs, but for some people that incredibly easy to do (not me). There used to be a warning that said explained this but I don't see it listed now. It does say "Access tokens are what allow third-party applications to access Canvas resources on your behalf.", so accessing on your behalf does mean with your permissions.
Rick
This discussion post is outdated and has been archived. Please use the Community question forums and official documentation for the most current and accurate information.