Red Flag ManiaIntegrations
⌘ K
Public documentation
LTI 1.3Controlled rollout

Core LTI 1.3 launch

A standards-based learner launch into one explicit, immutable published Red Flag course version.

Launch contract

The initial integration validates an LtiResourceLinkRequest, resolves the institution deployment, checks learner access, and issues a short-lived player handoff.

  • OIDC login initiation with expiring state and nonce.
  • Platform signature, issuer, audience, deployment, message, role, and resource-link validation.
  • An exact learner role and institution-scoped platform subject.
  • A resource link bound to one approved published course version.
  • A short-lived, single-use exchange before the player creates its session.
Flow
LMS → RFM login initiation → LMS authorization → RFM callback
RFM validation → published version → single-use player handoff

Failure boundary

Invalid signatures, replayed state, unknown deployments, unsupported roles, unavailable access, and unmapped resource links stop before player access. Raw LMS messages and learner claims are not returned to the browser as diagnostics.

Not in this release

The current public path does not offer generic LMS enablement, Names and Role Provisioning Services, or publicly available production setup. Approved staging pilots can use provider-supported Dynamic Registration and Deep Linking. RFM final-assessment grade return through Assignment and Grade Services has passed Canvas and Brightspace staging acceptance and remains unavailable in production.