LMS SSO: SAML vs OpenID Connect for Your Learning Platform
A practical guide to single sign-on for your LMS: choosing SAML or OpenID Connect, provisioning users with JIT or SCIM, mapping roles and cohorts, an…
Canvas LMS integration specialists
Engineers who extend Canvas the supported way: LTI 1.3 tools, the Canvas REST and GraphQL APIs, SIS and HR integrations and data pipelines. Built for institutions and companies that need Canvas to work with everything else.
Get a free Canvas LMS estimate
Takes 2 minutes. A senior engineer replies - not a salesperson.
Common Canvas problems we solve
Canvas is usually hosted by Instructure, so you cannot change its code. Almost everything is solved through LTI tools, APIs and good data plumbing.
We rebuild the launch flow on LTI 1.3 with OIDC login and signed JWTs, add Deep Linking, Names and Role Provisioning and Assignment and Grade Services, then migrate existing placements.
Automatic sync from your SIS or HR system using SIS imports or the API, with error reports instead of silent failures.
Grade passback through LTI Advantage or scheduled API exports to your SIS, with an audit trail.
Data pipelines from Canvas Data 2 or the API into your warehouse and BI tool, refreshed automatically.
Paginated, throttled and retry-safe integrations that respect Canvas rate limiting and run in the background.
Course content, users, enrolments and grade history migrated with scripts and checks, not copy and paste.
What our Canvas developers do
Tools that launch inside Canvas with deep linking, roster access and grade passback.
REST and GraphQL integrations for courses, enrolments, submissions and outcomes.
Automatic account, section and enrolment management from your system of record.
Pipelines from Canvas Data 2 and the API to your warehouse and dashboards.
SAML, OIDC and Azure AD or Google sign-in alongside your other systems.
From Moodle, Blackboard or a WordPress LMS into Canvas, or out of Canvas.
Branding, custom CSS and JavaScript where your Canvas account allows it.
LTI key handling, token scopes, data minimisation and privacy documentation.
Monitoring, fixes when Canvas changes, and on-call help during term starts.
Code-level expertise
Because Canvas is a shared hosted service, integrations have to be polite: paginate every list, respect rate limits, use narrowly scoped tokens and never block a teacher waiting for an external system.
This example reads every student enrolment in a course, following Canvas pagination.
import os
import time
import requests
BASE = os.environ["CANVAS_URL"] # e.g. https://school.instructure.com
TOKEN = os.environ["CANVAS_TOKEN"] # scoped developer key token
def student_enrollments(course_id: int):
url = f"{BASE}/api/v1/courses/{course_id}/enrollments"
params = {"type[]": "StudentEnrollment", "per_page": 100}
session = requests.Session()
session.headers["Authorization"] = f"Bearer {TOKEN}"
while url:
resp = session.get(url, params=params, timeout=30)
if resp.status_code == 403 and "Rate Limit Exceeded" in resp.text:
time.sleep(5) # back off, then retry the same page
continue
resp.raise_for_status()
yield from resp.json()
url = resp.links.get("next", {}).get("url")
params = None # the next URL already has the query
Skills
Engagement models
Pick the model that fits today and switch when your needs change. Every model includes a senior engineer, code review and a staging site.
Bug fixes, small changes, audits and urgent issues.
from $45/hour
Steady roadmap work and ongoing maintenance.
from 2500/month
Large roadmaps, platform teams and agencies.
from 4500/month
Well-defined features, migrations and new builds.
from 3000 minimum
Every engagement starts with a free technical call and an NDA. Prices exclude applicable taxes.
How it works
2 minutes
Use the short form: platform, what is wrong or what you want built, and how you prefer to work. Two minutes is enough.
30 minutes
A senior engineer reviews your site or requirements, asks the awkward questions early and suggests the simplest approach that will last.
1-3 business days
You get a written plan: fixed price and timeline, or the developer profile and monthly plan for dedicated work. NDA signed before any access.
Weekly demos
We set up staging and version control, ship in small reviewed increments and demo every change before it reaches your live site.
Compare
| Criterion | All-in-One LMS | Freelance marketplace | In-house hire |
|---|---|---|---|
| Engineers who work only on learning platforms | Yes | Partial | Partial |
| One team for WordPress LMS, Moodle, Open edX, Canvas and custom LMS | Yes | No | No |
| Cover when your developer is ill or on leave | Yes | No | Partial |
| Code review and QA before every release | Yes | Varies | Partial |
| NDA and IP assignment in the contract | Yes | Varies | Yes |
| No recruitment, payroll or notice periods | Yes | Yes | No |
| Scale hours up or down month to month | Yes | Partial | No |
| One accountable point of contact | Yes | No | Yes |
A general comparison of how each model usually works. Individual freelancers and in-house teams vary.
Canvas is open source, but most institutions and companies use the version hosted by Instructure, where you cannot change the application code. That shapes every project:
LTI 1.3, with the LTI Advantage services, is the current standard. It replaces shared-secret LTI 1.1 launches with OIDC and signed tokens, and adds standard services for deep linking, rosters and grade passback. If your tools still use LTI 1.1, plan the move now.
A Canvas specialist will talk about the OIDC launch, platform and tool keys, deployment IDs, Deep Linking and Assignment and Grade Services without prompting.
Integrations that ignore them work in testing and fail on the first day of term.
The answer should be a secrets store or environment configuration with narrow scopes, never a spreadsheet or the code.
Canvas integrations often handle student records. Your developer should help you minimise the data you copy and document where it goes.
Comparing platforms? Read Moodle vs Canvas and our guide to SCORM, xAPI and cmi5, or see our Canvas integration services.
Integrations and LTI tools are usually fixed-price projects once the scope is clear; ongoing integration support fits a part-time dedicated plan. You get a written estimate after the free technical call.
Yes, including OIDC launch, Deep Linking for content selection, Names and Role Provisioning for rosters and Assignment and Grade Services for passing scores back to the gradebook.
Yes. We rebuild the launch and security layer, keep your existing features, and plan the switch of course placements so teachers are not disrupted mid-term.
Yes, using SIS imports for bulk changes and the API for real-time updates, with error reporting so mismatched records are fixed rather than lost.
On hosted Canvas, changes to the core application are not possible; customization happens through LTI tools, APIs and the theming your account allows. For self-hosted Canvas, more is possible, but we still recommend extensions over code changes.
Yes. Course content, users, enrolments and, where the source allows it, grade history can be migrated with scripted checks. See our LMS migration services.
Yes. We build pipelines from Canvas Data 2 and the API into your data warehouse and dashboards, refreshed on a schedule.
Free estimate
Tell us whether you use hosted or self-hosted Canvas, what needs to connect, and your timeline. A senior engineer will reply with questions or a first estimate.
A practical guide to single sign-on for your LMS: choosing SAML or OpenID Connect, provisioning users with JIT or SCIM, mapping roles and cohorts, an…
Moodle is open source software you run; Canvas is open-source code most institutions rent as a hosted service. Here is how that shapes cost, integrat…
SCORM, xAPI and cmi5 solve different tracking problems, and LTI 1.3 solves a different one again. Here is how they compare and which to choose for yo…