Skip to main content
Version: 2026-08-19 (archived)

Launch claims reference

After verification, the launch_data JWT decodes to a flat set of claims:

{
"iat": 1751470000,
"exp": 1751477200,
"iss": "https://canvas.instructure.com",
"launch_id": "I9gbX9ExUrt6",
"time": "2026-07-27T18:03:00+00:00",
"app": "I4ppXy",
"user": {
"id": "In4kDp7yZq",
"role": "student"
},
"course": {
"id": "IcT91mBxze",
"name": "Intro to Computing",
"label": "CS101"
},
"organization": {
"id": "Id3pL0yMnt",
"title": "Example University",
"issuer": "I1ssUr",
"client": "IcL13nt",
"deployment": "Id3pL0yMnt"
},
"resource_link_id": "Ir3sLnk42",
"location": {
"id": "Il0c8n",
"type": "assessment",
"label": "Quiz 1",
"params": {
"guid": "42"
}
},
"grade_passback": true,
"storage": {
"context": "https://link.voshi.com/lti13/v1/contexts/IcT91mBxze/apps/I4ppXy/data",
"location": "https://link.voshi.com/lti13/v1/contexts/IcT91mBxze/apps/I4ppXy/locations/Il0c8n/data",
"member": "https://link.voshi.com/lti13/v1/contexts/IcT91mBxze/members/In4kDp7yZq/apps/I4ppXy/data",
"member_location": "https://link.voshi.com/lti13/v1/contexts/IcT91mBxze/members/In4kDp7yZq/apps/I4ppXy/locations/Il0c8n/data"
},
"api": {
"domain": "api.link.voshi.com",
"token": "8f14e45fceea167a5a36dedd4bea2543"
}
}
note

All IDs are Voshi's own IDs — stable across launches, but never the LMS's internal IDs. The raw LMS user identifier is not available to your app. No PII: name and email are omitted. Recognize a returning user by user.id, not by anything else.

Claims​

iatinteger

Standard JWT "issued at" — Unix epoch seconds (UTC) when the token was signed. Use the time claim, not iat, if you want a human-readable launch timestamp.

expinteger

Standard JWT expiry — Unix epoch seconds. Currently iat + 2 hours. Your JWT library checks this during verification and rejects an expired token.

issstring

The LMS's issuer URL (e.g. https://canvas.instructure.com) — the LTI platform this launch originated from. Note this identifies the LMS, not Voshi; the token's signature is Voshi's.

launch_idstring

The ID of this launch. Required to send a grade later — store it.

timestring

When the launch happened, as an ISO 8601 timestamp.

appstring

Your app's ID.

userobject

Who launched.

user fields
idstring

The user's stable Voshi ID — the same across every launch by this person, in any course at the same school.

rolestring

Exactly one of student, instructor, or admin, derived from the user's role in the LMS. Instructors, TAs, content developers, and faculty map to instructor; institution and system administrators map to admin; everything else — including unrecognized roles — maps to student.

courseobject

The course the launch came from.

course fields
idstring

The course's stable Voshi ID.

namestring

The course title, e.g. Intro to Computing.

labelstring

The course's short label, e.g. CS101.

organizationobject

The school.

organization fields
idstring

The school's Voshi ID (identical to deployment below).

titlestring

The school's display name, e.g. Example University.

issuerstring

Voshi's ID for the LMS platform (e.g. one Canvas cloud). Most apps can ignore this.

clientstring

Voshi's ID for the LMS registration under that platform. Most apps can ignore this.

deploymentstring

Voshi's ID for the school's deployment — the most specific of the three, and the value duplicated in id. Use id.

resource_link_idstring

Voshi's ID for the specific placement (resource link) in the course, or "" if the placement was never deep-linked. Two placements of the same location in the same course have different resource_link_ids.

locationobject

Which of your locations was launched.

location fields
idstring

The location's ID, assigned when you created it. Store it in your app if you want to switch on it directly.

typestring

One of assessment, practice, content, or setup. Only assessment locations can pass grades back.

labelstring

The friendly name you gave the location, e.g. Quiz 1.

paramsobject

The static key-value pairs configured on the location. Values are always strings ("3", never 3).

grade_passbackboolean

true only when this launch can accept a grade: the location is of type assessment and the LMS created a gradebook line item for the placement. If false, any grade you submit for this launch is rejected. Note that an assessment location can still launch with false — typically when the placement was created without deep linking, so no line item exists.

storageobject

URLs of your four storage rows for this launch — read and write them through the App Data API. Each value is the row's full URL: call it exactly as given, and treat it as opaque — don't parse it or construct these URLs yourself.

storage fields
contextstring

Data row for this course.

locationstring

Data row for this placement (this location in this course).

memberstring

Data row for this user within the course.

member_locationstring

Data row for this user on this placement — e.g. their submission state.

apiobject

The credential for calling the App Data API as the launching user.

api fields
domainstring

The API host to call, e.g. api.link.voshi.com.

tokenstring

A bearer token tied to the launching user's session: send it as Authorization: Bearer <token>. It expires with the session (about a week), so treat it as per-launch — get a fresh one from the next launch rather than storing it long-term. Keep it server-side; it acts as that user.

What is deliberately absent​

  • Name and email — no PII is forwarded.
  • The LMS's user ID — not available to your app.
  • LTI custom parameters from the LMS placement — not forwarded. Use location params for static per-placement configuration instead.