Registering your app
Register your app to tell Voshi it exists and to get your API key.
The three endpoints you register
Voshi reaches your app at three URLs. All three must be public HTTPS, and all three receive a form POST with a single signed launch_data field that you verify the same way.
| URL | Called when | Docs |
|---|---|---|
| Callback URL | Someone opens your app from a course. Arrives through their browser. | Receiving launches |
| Provision URL | A course, or a location in it, needs setting up in your app. Server to server. | Receiving provision requests |
| Locations URL | An instructor is placing your app and Voshi needs your list of destinations. Server to server. | Serving your locations |
Only the Callback URL is strictly required to receive a launch — but an app without a Locations URL can't be placed in a course, and an app without a Provision URL can't finish course setup, so a live app needs all three.
Register in the dashboard
Go to zen.voshi.com/app/ltiaas/s/ and sign in. If you don't have builder access yet, contact the MyEducator team.
Fill in the form:
- App Name — shown to instructors when they add your app to a course.
- Callback URL — your launch receiver. See the rules below.
- Description / Logo URL — optional.
The response shows your API key exactly once — copy it now and store it securely, like you would a password. It authenticates the grades API and the management API.
Open Apps → your app → Profile and fill in Provisioning URL and Locations URL. Both are optional in the form — leave the Provision URL blank if your app needs no course setup — but an app with no Locations URL can't be placed in a course.
You can edit the name, all three URLs, the description, and the logo later in Apps → your app → Profile, or via the management API. Configuration changes apply immediately — including to placements instructors have already made.
There's nothing to define for your locations at registration time. Voshi asks your Locations URL for them whenever an instructor is placing content, so your catalog lives in your app. See Locations.
Endpoint URL rules
Each of the three URLs is validated when you set it and re-checked every time Voshi calls it:
- Must be an absolute
https://URL (nohttp://, no relative paths). - Must point at a publicly-routable host — URLs that resolve to private, loopback, or link-local addresses are rejected. Your local machine can't receive launches; use a tunnel with a public HTTPS hostname or a deployed environment during development.
App status
| Status | Meaning |
|---|---|
draft | The initial status. The app cannot be placed in courses or launched — it's invisible to instructors. |
active | Live: instructors can place it, launches are forwarded to your callback URL. |
suspended | Disabled by the platform team. Launches and API calls are rejected. |
Only the Voshi platform team can change your app's status. The path to testing end-to-end is:
- Build your three endpoints and your grade flow against these docs.
- Contact the MyEducator team to activate your app.
- Test from a real LMS course — place a location, launch as an instructor and as a student, and verify grades land in the gradebook.
The dashboard's Test tab (Apps → your app → Test) exercises all three of those against your real endpoints before any of it. It asks your Locations URL what you offer, sends your Callback URL a signed launch to one of the locations you answered with, and shows you the result of a grade you submit against that launch. The claims are fabricated and carry test: true; nothing is recorded, and the trial launch_id is accepted by the real POST /grades endpoint without writing a grade or touching the gradebook.
Your API key
The key has the form:
ltiaas_<app-id>_<secret>
- It's shown once at registration. Voshi stores it encrypted and cannot show it again — the dashboard displays only a hint (
ltiaas_…last4). - Keep it server-side only. It authorizes grade submission and app configuration changes for your app.
- It is not involved in launch verification — launches are verified against Voshi's public keys. And it is not what your provisioning calls use; those authenticate with the request's own
api.token.
Rotating or replacing your API key
POST /ltiaas/v1/apps/me/rotate-key issues a new key and invalidates the current one immediately — see Rotate your API key. That call needs the current key, so if you've lost it entirely, contact the MyEducator team instead.
Team members
Apps are managed by their members, and membership is flat: every member has full management rights over the app, and an app always retains at least one member.
The builder dashboard has no Members screen yet — ask the MyEducator team to add or remove teammates on your app.