> ## Documentation Index
> Fetch the complete documentation index at: https://docs.praxis-ai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Complete the Canvas LMS API authorization handoff

> Canvas redirects the user's browser here after they authorize Pria to call the
Canvas API on their behalf (Canvas OAuth2 authorization-code flow). The handler
exchanges the supplied `code` for a Canvas API access token, stores it on the
caller's `UserInstitution.canvasApiToken`, writes a history entry recording the
successful authentication, and returns a small HTML page that closes the popup
and signals the parent window to retry the request that triggered the auth.

This is **not** a Pria login flow — the user is already signed in with a valid
Pria JWT before being sent to Canvas. The `state` parameter carries the Pria
user's `_id` so the backend can look up which user to attach the Canvas token
to without relying on the session.

**Configuration requirements:** the user's institution (or its parent account)
must have `canvasClientId` and `canvasClientSecret` set, and a derivable Canvas
API domain (an instructure.com URL or a `.edu` vanity URL in
`publicAuthorizedUrls`).




## OpenAPI

````yaml /mdx/api-reference/admin/admin-api.json get /api/auth/token_complete
openapi: 3.0.0
info:
  title: Pria Admin API
  version: 2.0.1
  description: >-
    Pria API Documentation Praxis's developer platform is a core part of our
    mission to empower organizations to grow better. Our APIs are designed to
    enable teams of any shape or size to build robust integrations that help
    them customize and get the most value out of Pria. All Pria APIs are built
    using REST conventions and designed to have a predictable URL structure.
    <br/>  <br/>They use many standard HTTP features, including methods (POST,
    GET, PUT, DELETE) and error response codes.  <br/> <br/>All API calls are
    made under https://hiimpria.ai/api and all responses return standard JSON.
    In these docs, you'll find lists of all available endpoints for a given API,
    along with interactive code blocks for building requests. For walkthroughs
    of basic usage for these APIs, check out the API guides.
servers:
  - url: https://pria.praxislxp.com
    description: Pria API Server
security: []
tags:
  - name: Authentication
    description: User authentication, registration, and password management (/api/auth)
  - name: OAuth
    description: OAuth authentication providers - Google, GitHub, SSO (/api/auth/oauth)
  - name: User
    description: User profile management and account operations (/api/user)
  - name: User Institutions
    description: User institution memberships and switching (/api/user/institution)
  - name: User Tools
    description: Available tools for authenticated users (/api/user/tools)
  - name: Institutions
    description: Institution settings and configuration (/api/user/institution)
  - name: Conversation
    description: AI conversation and Q&A endpoints (/api/ai)
  - name: Realtime
    description: Real-time voice AI and WebRTC sessions (/api/ai/rt)
  - name: Assistant
    description: AI assistant configuration and management (/api/user/assistant)
  - name: History
    description: Conversation history and favorites (/api/user/history)
  - name: RAG
    description: >-
      Document upload, embedding, and retrieval-augmented generation
      (/api/user/files, /api/user/rag)
  - name: Setting
    description: Instance variables and settings management (/api/user/setting)
  - name: Branding
    description: Digital twin branding and customization (/api/agent/branding)
  - name: Agent
    description: Agent engagement and session management (/api/agent)
  - name: SDK Launch
    description: >-
      SDK launch token signing and verification for secure iframe embedding
      (/api/auth/sdk-sign, /api/auth/sdk-verify)
  - name: Testing
    description: Health checks, diagnostics, and test endpoints (/api/test)
  - name: Admin Accounts
    description: Account management for super admins (/api/admin/account)
  - name: Admin Institutions
    description: Institution management for admins (/api/admin/institution)
  - name: Admin Users
    description: User management for admins (/api/admin/user)
  - name: Admin Entitlements
    description: >-
      User-institution relationships and permissions
      (/api/admin/userInstitution)
  - name: Admin Sessions
    description: Session management for admins (/api/admin/session)
  - name: Admin Histories
    description: Conversation history management and analytics (/api/admin/history)
  - name: Admin Assistants
    description: AI assistant management for admins (/api/admin/assistant)
  - name: Admin Questions
    description: Institution question and prompt management (/api/admin/question)
  - name: Admin Tools
    description: Tool configuration management (/api/admin/tool)
  - name: Admin AI Models
    description: AI model configuration (/api/admin/aimodel)
  - name: Admin MCP Servers
    description: Model Context Protocol server management (/api/admin/mcpserver)
  - name: Admin Feedbacks
    description: User feedback management (/api/admin/feedback)
  - name: Admin Uploads
    description: Upload management (/api/admin/upload)
  - name: Admin Charts
    description: Analytics and visualization chart management (/api/admin/chart)
  - name: Admin Memory
    description: Admin inspection and editing of user/instance memory parameters.
  - name: Admin Usage Limits
    description: Per-user usage-vs-cap reporting and account-wide at-limit counts.
paths:
  /api/auth/token_complete:
    get:
      tags:
        - OAuth
      summary: Complete the Canvas LMS API authorization handoff
      description: >
        Canvas redirects the user's browser here after they authorize Pria to
        call the

        Canvas API on their behalf (Canvas OAuth2 authorization-code flow). The
        handler

        exchanges the supplied `code` for a Canvas API access token, stores it
        on the

        caller's `UserInstitution.canvasApiToken`, writes a history entry
        recording the

        successful authentication, and returns a small HTML page that closes the
        popup

        and signals the parent window to retry the request that triggered the
        auth.


        This is **not** a Pria login flow — the user is already signed in with a
        valid

        Pria JWT before being sent to Canvas. The `state` parameter carries the
        Pria

        user's `_id` so the backend can look up which user to attach the Canvas
        token

        to without relying on the session.


        **Configuration requirements:** the user's institution (or its parent
        account)

        must have `canvasClientId` and `canvasClientSecret` set, and a derivable
        Canvas

        API domain (an instructure.com URL or a `.edu` vanity URL in

        `publicAuthorizedUrls`).
      parameters:
        - in: query
          name: code
          schema:
            type: string
          required: true
          description: Canvas OAuth authorization code to exchange for an access token.
        - in: query
          name: state
          schema:
            type: string
          required: true
          description: >
            Pria user `_id` — set during the original `consentUrl` generation so
            this

            callback can find which Pria user to attach the Canvas token to.
        - in: query
          name: error
          schema:
            type: string
          description: Set by Canvas when the user denies the consent screen.
        - in: query
          name: error_description
          schema:
            type: string
          description: Human-readable failure reason that accompanies `error`.
      responses:
        '200':
          description: >
            Canvas token stored successfully. Returns an HTML page
            (`TOKEN_SUCCESS_HTML`)

            that closes the popup window and signals the opener to retry.
          content:
            text/html:
              schema:
                type: string
        '400':
          description: >
            Canvas returned an OAuth error, required query parameters are
            missing,

            the institution is misconfigured (no Canvas API URL / client id /
            secret),

            or the Canvas token exchange itself failed.
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Parameter code is required
                  error:
                    type: string
                    description: >-
                      Present on Canvas exchange failures (instead of
                      `message`).
                    example: Unknown error (3) <upstream>
        '404':
          description: >
            User identified by `state` was not found, or the required
            UserInstitution

            entitlement row is missing.
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: User not found
        '500':
          description: Database error while loading the UserInstitution entitlement.
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Error - can't find the user's entitlement

````