Canvas deploys contain code changes that are intended to fix bugs, improve performance, and prepare for new features. These deploys take place every two weeks and can be tested in the beta environment before the production deploy date indicated in the title of this document.
- New to deploy notes? Visit Understanding Release Notes for a guide on how to read and use this document.
- Visit the Canvas Collaborative Roadmap to explore upcoming work and share feedback. Your input helps guide future product development.
- For Canvas Platform Service changes (API, GraphQL, Canvas Data), please see the appropriate page in the Change Log.
- Institutions are responsible for conducting thorough evaluations of their custom CSS/JS with each release and deploy to assess potential impacts.
Unless otherwise stated, all features in this deploy are available in the Beta environment on 2026-07-30 and the Production environment on 2026-08-12.
Updated Features
Account Settings
Configure Trusted Proxy IPs for MFA Session Binding- Admin
Feature Option Name to Enable | N/A |
|---|
Enable Feature Option Location & Default Status | N/A |
Subaccount Configuration | N/A |
Account/Course Setting to Enable | None |
Permissions | Inherent to user Role |
Affects User Interface | Yes |
Affected Areas | Account Settings |
Summary
Institutions using a Content Delivery Network (CDN) or proxy in front of their network can see repeated Multi-Factor Authentication (MFA) prompts, since Canvas ties an MFA session to the single IP address used at validation. Admins can enter a list of IP addresses that Canvas treats as equivalent for MFA session binding, reducing repeat prompts for users behind a shared CDN or proxy.
Change Benefit
- Consistent Authentication: Admins on proxied custom domains complete Multi-Factor Authentication once and move through Canvas without repeated verification prompts, across CDN and proxy providers including Cloudflare, CloudFront, Akamai, and Fastly. Accounts that had session fingerprinting disabled as a temporary workaround regain full MFA protection with no loop.
Feature Workflow
In Root Account Settings, enter IP addresses to treat as equivalent for MFA session binding.
Developer Keys
Google Apps LTI Requires Opt-In- Admin
Feature Option Name to Enable | N/A |
|---|
Enable Feature Option Location & Default Status | N/A |
Subaccount Configuration | N/A |
Account/Course Setting to Enable | None |
Permissions | Developer Keys-manage |
Affects User Interface | No |
Affected Areas | Developer Keys |
Summary
Instructure updates the security model for the Google Apps LTI (LTI 1.1) integration. New users must opt in to enable the tool's API key on the Developer Keys page. Existing users who have used the tool in the last 6 months see no change and keep their current setup.
Change Benefit
- Improved Security: Reduces the tool's default security exposure and moves Instructure toward a more mature API management model. New users gain clearer control over which integrations have API access from the start.
Feature Workflow
In Developer Keys, toggle on the desired key.
Developer Keys
Paste Scopes- Admin
Feature Option Name to Enable | N/A |
|---|
Enable Feature Option Location & Default Status | N/A |
Subaccount Configuration | N/A |
Account/Course Setting to Enable | None |
Permissions | Developer Keys-manage |
Affects User Interface | Yes |
Affected Areas | API Key Settings |
Summary
In the Developer Key add API key page, admins can paste scopes.
Note: Upon saving, if a scope is invalid it is automatically removed.
Change Benefit
- Simplified Scoping: Admins paste a list of scopes directly from the tool provider instead of manually finding and selecting each one, cutting the time and troubleshooting needed to scope a developer key correctly.
Feature Workflow
Click the Method field [1], then click the Paste Scopes option [2].
Paste the desired content into the Paste Scopes field.
Developer Keys
Token Count Relabeled- Admin
Feature Option Name to Enable | N/A |
|---|
Enable Feature Option Location & Default Status | N/A |
Subaccount Configuration | N/A |
Account/Course Setting to Enable | None |
Permissions | Developer Keys-manage |
Affects User Interface | Yes |
Affected Areas | Developer Keys |
Summary
In Developer Keys, the Access Token Count text is changed to Lifetime Token Count for API keys. Additionally, the Access Token Count and Last Used data is removed for LTI tools, which do not use access tokens.
The Lifetime Token Count includes all tokens, not only currently active ones.
Change Benefit
- Improved Clarity: Lifetime Token Count in Developer Keys, makes clear the number includes all tokens issued, not only currently active ones. The token information for LTI keys is also removed, since it is not relevent for LTI keys.
Feature Workflow
In Developer Keys, Lifetime token count text displays.
Settings
Academic Integrity Pledge- Admin, Student
Feature Option Name to Enable | N/A |
|---|
Enable Feature Option Location & Default Status | N/A |
Subaccount Configuration | N/A |
Account/Course Setting to Enable | None |
Permissions | Inherent to user role |
Affects User Interface | Yes |
Affected Areas | Account-level setting, Assignments |
Summary
In Account-level Settings, admins can enable an Academic Integrity Pledge that requires students to acknowledge it before submitting assignments. The feature is disabled by default. Once enabled, admins can use the default pledge text or write their own.
When enabled, students see the pledge text and a checkbox on the submission page for every assignment type except external tool assignments. Students must check the box before they can submit.
Note: If admins enable both the Similarity Pledge and the Academic Integrity Pledge, students must check both boxes on assignments that use an LTI 2 Canvas Plagiarism Framework tool.
Change Benefit
- Academic Integrity: Reinforces honest submission practices by requiring students to actively acknowledge an integrity pledge before submitting an assignment. Admins control when and where the pledge applies, using the default text or their own wording to match institutional policy.
Feature Workflow
Check the Require pledge for submission checkbox [1]. Use the default pledge text or enter custom pledge text in the field [2].
Students must select the checkbox before submitting their assignment.
Note: The checkbox is unchecked by default.
User Navigation
Mandatory Token Expiration for Non-Admin Roles.- Instructors
Beta and Production Environment Availability | 2026-07-30 Note: This date falls outside the regular deploy cadence. |
|---|
Affects User Interface | Yes |
Affected Feature Areas | User-generated tokens |
Previous Feature Mention | Canvas Deploy Notes (2026-07-01) |
Summary
Expiration dates for user-generated tokens for all non-admin roles, meaning any user without an account level role, are mandatory. Instructor tokens have an expiration date set to 90 days after creation. Student token expiration remains 30 days.
Change Benefit
- Stronger account security: Mandatory expiration dates for non-admin tokens reduce the risk of long-lived, forgotten, or stolen tokens being used to access Canvas without detection.
Feature Workflow
For new Instructor access tokens, the maximum expiration is 90 days.
Other Updates
Authentication
Admins on Custom Domains Skip Repeat MFA Prompts- Admin
Affects User Interface | No |
|---|
Affected Feature Areas | Authentication |
Summary
Canvas identifies the actual client IP address for admins who access Canvas through a custom domain routed through their institution's own Content Delivery Network (CDN) or proxy. Previously, Canvas saw the proxy's rotating edge IP instead of the admin's actual IP.
Change Benefit
- Consistent Authentication: Admins on proxied custom domains complete Multi-Factor Authentication once and move through Canvas without repeated verification prompts, across CDN and proxy providers including Cloudflare, CloudFront, Akamai, and Fastly. Accounts that had session fingerprinting disabled as a temporary workaround regain full MFA protection with no loop.
Dashboard
Color Overlay Default Status Update- All Users
Affects User Interface | Yes |
|---|
Affected Areas | Dashboard Course Cards |
Summary
In the Dashboard, course card color overlay is disabled by default. Previously, this was enabled by default. Users that already changed this setting keep their current configuration.
Change Benefit
- Improved Visibility: Course cards display their images and colors clearly by default, with the option to add a color overlay for accounts that prefer it. Accounts with a customized setting keep their current configuration.
Reports
LTI Reports Include LTI Version- Admin
Affects User Interface | No |
|---|
Affected Feature Areas | LTI Report |
Summary
The LTI Report's CSV export includes the LTI version number.
Change Benefit
- Clearer Reporting: The LTI Report's CSV export includes the LTI version number, giving admins version details for each tool without needing to check each one individually.
Change Log
Date | Description |
|---|
2026-08-04 | Updated - Developer Keys: Token Count Relabeled
- Settings: Academic Integrity Pledge
- Account/Course Setting to Enable
|