Re: https://community.canvaslms.com/t5/Canvas-Releases/Canvas-Release-Notes-2024-09-21/ta-p/612521#toc-h...
Please make the following an Admin Guide; I always have trouble finding this information / sending it to other admins because it only lives tucked away at the bottom of Release Notes.
If an admin has both the Users - Manage Access Tokens permission and the Users - act as permission, they can masquerade as a user to generate a token on the user's behalf. This updates the status as Pending to prevent unauthorized token generation without the user’s knowledge.The access token should then be securely shared with the user by the admin. Additionally, an admin can masquerade as a user to delete that user's existing access tokens and regenerate tokens.
Notes:
- Regenerating an existing access token on behalf of a user will place the token in a pending state, similar to newly generated tokens. The user must activate the token before it can be used. The access token should be securely shared with the user by the admin.
- Tokens generated by an admin on behalf of a user will remain in a pending state until the user navigates to their user settings and activates the token.
- Users will receive an email notification if an access token has been generated on their behalf.