Launch claims reference
After verification, the launch_data JWT decodes to a flat set of claims:
{
"iat": 1751470000,
"exp": 1751477200,
"iss": "https://canvas.instructure.com",
"launch_id": "I9gbX9ExUrt6",
"time": "2026-07-27T18:03:00+00:00",
"app": "I4ppXy",
"user": {
"id": "In4kDp7yZq",
"role": "student"
},
"course": {
"id": "IcT91mBxze",
"name": "Intro to Computing",
"label": "CS101"
},
"organization": {
"id": "Id3pL0yMnt",
"title": "Example University",
"issuer": "I1ssUr",
"client": "IcL13nt",
"deployment": "Id3pL0yMnt"
},
"resource_link_id": "Ir3sLnk42",
"location": {
"id": "Il0c8n",
"type": "assessment",
"label": "Quiz 1",
"params": {
"guid": "42"
}
},
"grade_passback": true,
"storage": {
"context": "https://link.voshi.com/lti13/v1/contexts/IcT91mBxze/apps/I4ppXy/data",
"location": "https://link.voshi.com/lti13/v1/contexts/IcT91mBxze/apps/I4ppXy/locations/Il0c8n/data",
"member": "https://link.voshi.com/lti13/v1/contexts/IcT91mBxze/members/In4kDp7yZq/apps/I4ppXy/data",
"member_location": "https://link.voshi.com/lti13/v1/contexts/IcT91mBxze/members/In4kDp7yZq/apps/I4ppXy/locations/Il0c8n/data"
},
"api": {
"domain": "api.link.voshi.com",
"token": "8f14e45fceea167a5a36dedd4bea2543"
}
}
All IDs are Voshi's own IDs — stable across launches, but never the LMS's internal IDs. The raw LMS user identifier is not available to your app. No PII: name and email are omitted. Recognize a returning user by user.id, not by anything else.
Claims
iatintegerStandard JWT "issued at" — Unix epoch seconds (UTC) when the token was signed. Use the time claim, not iat, if you want a human-readable launch timestamp.
expintegerStandard JWT expiry — Unix epoch seconds. Currently iat + 2 hours. Your JWT library checks this during verification and rejects an expired token.
issstringThe LMS's issuer URL (e.g. https://canvas.instructure.com) — the LTI platform this launch originated from. Note this identifies the LMS, not Voshi; the token's signature is Voshi's.
launch_idstringThe ID of this launch. Required to send a grade later — store it.
timestringWhen the launch happened, as an ISO 8601 timestamp.
appstringYour app's ID.
userobjectWho launched.
courseobjectThe course the launch came from.
organizationobjectThe school.
resource_link_idstringVoshi's ID for the specific placement (resource link) in the course, or "" if the placement was never deep-linked. Two placements of the same location in the same course have different resource_link_ids.
locationobjectWhich of your locations was launched.
grade_passbackbooleantrue only when this launch can accept a grade: the location is of type assessment and the LMS created a gradebook line item for the placement. If false, any grade you submit for this launch is rejected. Note that an assessment location can still launch with false — typically when the placement was created without deep linking, so no line item exists.
storageobjectURLs of your four storage rows for this launch — read and write them through the App Data API. Each value is the row's full URL: call it exactly as given, and treat it as opaque — don't parse it or construct these URLs yourself.
apiobjectThe credential for calling the App Data API as the launching user.
What is deliberately absent
- Name and email — no PII is forwarded.
- The LMS's user ID — not available to your app.
- LTI custom parameters from the LMS placement — not forwarded. Use location params for static per-placement configuration instead.