Skip to main content
Version: 2026-08-19 (archived)

How launches work

A launch is what happens when someone opens your app from inside an LMS course. Voshi sits between the LMS and your app: it handles the LMS integration and hands the user to your app with everything you need in a single signed token.

The lifecycle​

  1. Someone launches your app. An instructor or student clicks your app's placement in a course. The LMS hands the launch to Voshi — your app isn't involved yet.
  2. Voshi forwards the launch to you. Voshi sends the user's browser to your app's callback URL with a POST of a single field, launch_data: a signed JWT identifying the school, course, user, and which of your locations was launched.
  3. Your app takes over. You verify the JWT, create your own session, and render whatever the user should see. From here on, the user is simply navigating your app.

Nothing precedes step 1: Voshi doesn't announce a school, course, or student before they launch, so the launch is also where your app creates them. See just-in-time provisioning.

note

The launch POST arrives through the user's browser, not from a Voshi server. That has two consequences: the JWT's signature is the only thing standing between you and a forged launch (so verify it, always), and Voshi never sees your app's response — errors on your side are between your app and the user.

What arrives in the launch​

The JWT identifies the user (stable ID + role), the course, the school, your launched location with its params, whether grade passback is available, and URLs for your four app data storage rows. See the claims reference for every field.

Three properties worth knowing up front:

  • All IDs are Voshi's own IDs — stable across launches, but never the LMS's internal IDs.
  • No PII. Name and email are not included. Recognize a returning user by user.id.
  • One token, one session. Tokens expire after 2 hours, but you shouldn't rely on that — trade the token for your own session on first use and don't accept the same token twice.

How placements happen (deep linking)​

Instructors place your app into their course through a content picker that Voshi provides entirely — your app does not participate in deep linking at all. The instructor picks one of your locations, optionally renames the placement, and Voshi handles the rest (for assessment locations, a gradebook column is created as part of the placement).

Edits you make to a location's label, type, or params in the dashboard apply immediately to content instructors have already placed. See Locations.

Next​