TL;DR
Instructure is evolving Canvas API integrations to strengthen platform security, scalability, and sustainability while preserving an open ecosystem. Upcoming Canvas Apps enhancements will give institutions a simpler, more transparent way to install and manage API-based integrations, while Partners will adopt standardized configurations and contribute to infrastructure costs when usage exceeds monthly allotments. Some customers may need to update or reinstall specific tools, but Instructure and its Partners will communicate required actions in advance and prioritize academic continuity throughout the transition. LTI integrations remain available at no additional cost, and Instructure currently has no plans to charge customers separately for Canvas API access.
As AI continues to transform education technology, institutions are relying on more integrated tools than ever before to deliver engaging, personalized learning experiences. At the same time, the evolving cybersecurity landscape has accelerated our focus on strengthening how applications securely access the Canvas platform.
At Instructure, we're committed to ensuring our platform remains secure, scalable, and sustainable while continuing to support the open ecosystem that has made Canvas the connected learning platform trusted by thousands of institutions. This work is ongoing, and you can expect to hear about additional initiatives and updates in the coming months. However, we wanted to take time with this blog to dive deeper into the series of enhancements released throughout the first half of 2026 that improve API security, modernize integration management, and strengthen the long-term health of our developer ecosystem.
These updates are designed to benefit both institutions and third-party developers by making integrations easier to manage, more transparent, and more secure.
A Security-First Experience for Institutions
As the number and sophistication of integrated applications continue to grow, institutions need better visibility into the tools connecting with Canvas and greater confidence that those integrations are following modern security best practices.
Last year, we introduced Canvas Apps to make it easier for administrators to discover, install, and manage LTI integration applications through a centralized experience. Soon, we’ll be releasing enhancements to support API integrations as well. These improvements include standardized access via scoped developer keys, clearer visibility into requested permissions, and more consistent governance of third-party applications.
For institutions, this means:
- A simpler, more streamlined application installation experience for LTI and API integrations.
- Greater transparency into the permissions applications request.
- Improved security through standardized API authentication methods.
- Continued confidence in an open ecosystem built on modern security practices.
These changes, targeted for release by the end of 2026, are designed to improve the administration experience without disrupting existing integrations. Institutions will continue to have the flexibility to build and adopt the tools that best support their teaching and learning goals. Institution administrators interested in early adopter opportunities should refer to the Canvas Collaborative Roadmap.
A Scalable Platform for our API Integration Partners
Supporting one of the largest educational technology ecosystems in the world requires continuous investment in the infrastructure that powers millions of API requests every day. As AI-enabled applications and increasingly data-intensive integrations continue to drive significant growth in API usage, we're evolving how we support commercial API access to ensure our platform remains reliable, secure, and scalable for everyone.
To support that investment, API-enabled third-party applications will participate in a more standardized integration framework. Partners using Canvas APIs will:
- Register their API configurations with Instructure.
- Transition to standardized developer key authentication through Canvas Apps.
- Participate in the Instructure Platform Integration Partner Program for commercial API access.
As part of this updated model, API-enabled partners receive a monthly allocation of API transactions through their Partner tier. Applications whose usage exceeds those included allocations will contribute toward the infrastructure costs associated with supporting high-volume API traffic.
We recognize this may increase operating costs for a subset of partners with the highest API usage. That's why we're making significant investments alongside these changes—not only in strengthening the security and scalability of our platform, but also in improving the efficiency of our API infrastructure itself. At the same time, we're working closely with partners to identify opportunities to optimize existing integrations; continue support and adoption of open standards like LTI, OneRoster, Edu-API, and leverage more efficient integration services like Instructure's Data Services (Live Events) and Data Access Platform (DAP/CD2). Ultimately the goal is to reduce unnecessary API traffic without compromising functionality or customer experience.
Our goal is not simply to recover infrastructure costs; it is to build APIs that are more efficient, more secure, and more resilient so partners can continue creating exceptional integration experiences for years to come.
What Customers Can Expect
Our goal throughout this transition is simple: strengthen the security and sustainability of the Canvas ecosystem while maintaining the seamless experience institutions rely on every day.
As these platform enhancements roll out, some third-party partners may choose to update how their integrations authenticate with Canvas or take advantage of new capabilities available through Canvas Apps. In some cases, this may require institutions to reinstall or update specific integrated tools, activate Data Services (Live Events), or grant access to DAP (CD2). When customer action is required, Instructure and our partners will communicate those changes in advance and provide clear guidance throughout the process.
Most importantly, academic continuity remains our highest priority. We recognize that institutions depend on integrated tools to support teaching and learning, particularly during the busy back-to-school season. As we implement these enhancements, we're working closely with our partner community to minimize disruption, preserve existing workflows whenever possible, and ensure transitions occur in a thoughtful, coordinated manner.
- Institutions will continue to build and deploy their own custom applications using Canvas APIs.
- LTI-based integrations remain fully supported and continue to be available at no additional cost.
- At this time, Instructure has no plans to charge customers for Canvas API access. Customer API usage continues to be included as part of annual Canvas licensing.
- Existing integrations will continue to function while partners transition to the updated framework.
- Canvas will remain an open platform that supports innovation through standards-based integrations and robust APIs.
Looking Ahead
Education technology continues to evolve rapidly, creating new opportunities to improve teaching and learning while also raising expectations around security, reliability, and operational excellence.
These updates reflect Instructure's ongoing commitment to investing in the platform, strengthening our integration ecosystem, and ensuring that institutions can confidently adopt innovative technologies—today and well into the future. Our priority is to ensure Canvas remains an open, trusted platform where institutions, partners, and learners can continue to innovate together.
To stay up-to-date on the latest releases to this work, including Canvas Apps improvements, check out the Collaborative Roadmap, and watch for additional updates on our work around platform security, scalability, and sustainability in the coming months..