curl --request POST \
--url https://pria.praxislxp.com/api/auth/sdk-hide \
--header 'Content-Type: application/json' \
--data '
{
"params": {},
"launch_token": "<string>",
"nonce": "<string>",
"timestamp": 123,
"ticket": "<string>",
"hidden": true
}
'import requests
url = "https://pria.praxislxp.com/api/auth/sdk-hide"
payload = {
"params": {},
"launch_token": "<string>",
"nonce": "<string>",
"timestamp": 123,
"ticket": "<string>",
"hidden": True
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
params: {},
launch_token: '<string>',
nonce: '<string>',
timestamp: 123,
ticket: '<string>',
hidden: true
})
};
fetch('https://pria.praxislxp.com/api/auth/sdk-hide', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://pria.praxislxp.com/api/auth/sdk-hide",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'params' => [
],
'launch_token' => '<string>',
'nonce' => '<string>',
'timestamp' => 123,
'ticket' => '<string>',
'hidden' => true
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://pria.praxislxp.com/api/auth/sdk-hide"
payload := strings.NewReader("{\n \"params\": {},\n \"launch_token\": \"<string>\",\n \"nonce\": \"<string>\",\n \"timestamp\": 123,\n \"ticket\": \"<string>\",\n \"hidden\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://pria.praxislxp.com/api/auth/sdk-hide")
.header("Content-Type", "application/json")
.body("{\n \"params\": {},\n \"launch_token\": \"<string>\",\n \"nonce\": \"<string>\",\n \"timestamp\": 123,\n \"ticket\": \"<string>\",\n \"hidden\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://pria.praxislxp.com/api/auth/sdk-hide")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"params\": {},\n \"launch_token\": \"<string>\",\n \"nonce\": \"<string>\",\n \"timestamp\": 123,\n \"ticket\": \"<string>\",\n \"hidden\": true\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"hidden": true,
"ticket": "<string>"
}Course-wide Hide Pria for everyone toggle
Hides (or restores) Pria for an entire Canvas course. Teacher-gated both ways: students can neither hide a course nor show it again. Identity and course come from the VERIFIED launch or the ticket — never free body fields.
A course already connected to a USABLE Digital Twin cannot be hidden (409). A course whose only holder is a DISABLED Digital Twin stays connected to it (it is freed only by a teacher’s Disconnect or an administrator’s edit); hiding it still works, because only a USABLE holder blocks the hide.
curl --request POST \
--url https://pria.praxislxp.com/api/auth/sdk-hide \
--header 'Content-Type: application/json' \
--data '
{
"params": {},
"launch_token": "<string>",
"nonce": "<string>",
"timestamp": 123,
"ticket": "<string>",
"hidden": true
}
'import requests
url = "https://pria.praxislxp.com/api/auth/sdk-hide"
payload = {
"params": {},
"launch_token": "<string>",
"nonce": "<string>",
"timestamp": 123,
"ticket": "<string>",
"hidden": True
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
params: {},
launch_token: '<string>',
nonce: '<string>',
timestamp: 123,
ticket: '<string>',
hidden: true
})
};
fetch('https://pria.praxislxp.com/api/auth/sdk-hide', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://pria.praxislxp.com/api/auth/sdk-hide",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'params' => [
],
'launch_token' => '<string>',
'nonce' => '<string>',
'timestamp' => 123,
'ticket' => '<string>',
'hidden' => true
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://pria.praxislxp.com/api/auth/sdk-hide"
payload := strings.NewReader("{\n \"params\": {},\n \"launch_token\": \"<string>\",\n \"nonce\": \"<string>\",\n \"timestamp\": 123,\n \"ticket\": \"<string>\",\n \"hidden\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://pria.praxislxp.com/api/auth/sdk-hide")
.header("Content-Type", "application/json")
.body("{\n \"params\": {},\n \"launch_token\": \"<string>\",\n \"nonce\": \"<string>\",\n \"timestamp\": 123,\n \"ticket\": \"<string>\",\n \"hidden\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://pria.praxislxp.com/api/auth/sdk-hide")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"params\": {},\n \"launch_token\": \"<string>\",\n \"nonce\": \"<string>\",\n \"timestamp\": 123,\n \"ticket\": \"<string>\",\n \"hidden\": true\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"hidden": true,
"ticket": "<string>"
}Body
Either a fresh signed launch (params/launch_token/nonce/timestamp, as verified by
/api/auth/sdk-verify) OR a ticket minted earlier by this same endpoint or by
POST /api/auth/getInstitutionsForContextid — never both required. When both a ticket
and a launch proof are sent, the ticket wins and the launch proof is ignored. A ticket
carries the same identity/course facts as the launch it came from for up to 4 hours
(design 2026-09-28 D4/D7), so a teacher can return to the panel after the 10-minute
launch signature has expired.
Launch parameters, when authenticating by fresh launch (see SdkVerifyRequest).
HMAC-SHA256 token returned from sdk-sign, when authenticating by fresh launch.
The nonce returned from sdk-sign, when authenticating by fresh launch.
The timestamp returned from sdk-sign, when authenticating by fresh launch.
A course ticket, when authenticating by ticket instead of a fresh launch.
Set the course-wide hide (default). false shows Pria again.
Response
Preference saved
true
By ticket: the SAME ticket handed back unchanged (a ticket never renews itself). By a
fresh launch: a freshly minted 4-hour course ticket, so the caller can act again
without re-launching. null in the rare case no ticket could be minted (for example,
an over-long course id); the caller keeps using its launch proof.
Was this page helpful?