Installing EqualWeb PDF Accessibility on Canvas
Install EqualWeb into your Canvas and it appears in your course and account menus. It lists the PDF files in your courses, checks them for accessibility, and - with your EqualWeb credits - remediates them. A Canvas administrator does it in about five minutes, and there is nothing to download.
What you need
- A Canvas account administrator login on the root account, with the LTI Registrations - Manage permission. A sub-account administrator cannot complete the wizard.
- Your Canvas must be reachable from the internet over HTTPS. Instructure-hosted Canvas always is; a self-hosted Canvas behind a VPN or an IP allowlist cannot be used.
Two values you need from us: the registration URL and the callback URL. Both are the same strings for every institution, and neither is published here - your EqualWeb contact sends them to you when your institution is enabled for early access. Keep them to hand: you will paste the first in step 2 and the second in step 7. If you do not have them yet, contact us or book a short call.
Six steps inside Canvas
Open the app installer
- Go to Admin → your account → Apps → Manage → Install a New App
- Choose LTI 1.3, then Dynamic Registration.
Paste the registration URL
- Paste the value we sent you https://…/register into the registration URL field and continue.
Permissions - nothing to approve
EqualWeb requests no Canvas API permissions at this step. An empty permissions screen is exactly what you should see.
Data sharing - choose "All user data"
EqualWeb has to know who is opening the tool, so that only instructors and administrators can run checks against your files. Name and email are never stored - the identity is used only to decide what that person may do.
Placements - leave the defaults
EqualWeb installs into the course navigation and account navigation menus, visible to administrators and instructors only. Students never see the menu item, and a student who reaches the URL anyway gets an honest card instead of a session.
Review, then Install App
- Click Install App. You will see "EqualWeb is registered ✓" and the window closes by itself.
- Open any course, or your account menu, and click EqualWeb PDF Accessibility. The app opens inside Canvas - you are already signed in, and there is no separate EqualWeb password.
Let EqualWeb read your course files
An LTI install identifies people but grants no access to files at all - that is deliberate in the LTI standard. So the first screen says "One step left: let EqualWeb read your course files." A Canvas account administrator connects it with a second developer key and one Authorize click. Your course PDFs appear the moment the connection is verified.
The EqualWeb connection screen offers two ways to do it. Both end in the same place; pick one.
API developer key (OAuth2)
No secret to keep in sync, and access is renewed automatically. This is the path we ship and support.
In Canvas
- Go to Admin → Developer Keys → + Developer Key → + API Key - a separate, second key next to the LTI one from step 2.
- Key Name: EqualWeb API
- Redirect URIs - the top field, not "Redirect URI (Legacy)": paste the EqualWeb callback URL https://…/oauth/callback we sent you with the registration URL.
- Leave Enforce Scopes off. If your policy requires it on, tick every endpoint on the EqualWeb scope list plus Allow Include Parameters.
- Save, switch the key ON in the list, then copy its Client ID and secret (Show Key).
In EqualWeb
- Under Option 1 - API developer key, paste the Client ID and secret.
- Account ID: usually 1.
- Save platform credentials, then Authorize with Canvas.
- The Canvas approval screen opens in a new tab - approve it and close the tab. EqualWeb verifies the connection by itself.
Admin access token
The original method, still fully supported. Quickest to set up, and handy for a test - but the token is a long-lived secret you manage yourself.
In Canvas
- Go to Account → Settings → + New Access Token
- Purpose: EqualWeb. Leave the expiry date empty - a token that expires takes the connection down with it.
- Generate Token and copy it. Canvas shows it only once.
In EqualWeb
- Under Option 2 - access token, paste the token.
- Account ID: usually 1.
- Save platform credentials, then Test connection. It reports the identity the tool will act as - if that is not who you expect, correct it here.
Free checks from day one
Every institution gets 10 free accessibility checks per day, with no EqualWeb account required - reset daily, counted per institution. AI remediation, and any volume beyond the daily allowance, use your EqualWeb credits.
What each person sees
| Institution administrator | College administrator | Instructor | |
|---|---|---|---|
| Documents | Every course in the institution | Their own college only | Their own course only |
| Courses, Analytics, Permissions, Settings | Yes | Yes, scoped to their college | No |
| The Canvas connection (step 7-8) | Sets it up | Read-only - the connection belongs to the whole institution | Sees "Waiting for your Canvas administrator" |
| EqualWeb API key | Single billing: theirs · split billing: none | Single billing: none · split billing: theirs | Never |
The launch is accepted only for Instructor, Teaching Assistant, Content Developer or Administrator. A college administrator's scope is not a setting we apply - Canvas is asked who they administer at every launch, and the answer decides what they see.
Requirements on your own instance
Instructure-hosted customers need nothing here. A self-hosted Canvas must be reachable from the public internet over HTTPS with a publicly trusted certificate - we fetch your signing keys on every launch and call your REST API from our servers - and it must not sit behind an IP allowlist, because our calls come from Cloudflare's edge and there is no fixed address to allow. A Canvas that is only reachable internally cannot be connected.
Troubleshooting
Every entry here is a real failure we hit on a live Canvas and fixed.
I opened the install link and got an EqualWeb page telling me to paste it into my LMS
The install wizard says the configuration points at a different host
The EqualWeb area inside Canvas is blank, or says "refused to connect"
"Another EqualWeb session was open"
"Your browser blocked the sign-in"
"Canvas did not identify the launching user"
"For instructors and administrators"
The documents list is empty although the connection tested fine
It listed nothing, we fixed the connection, and it still lists nothing
"Waiting for your Canvas administrator"
The list stops with "Scan not finished - reload the page to continue"
"redirect_uri does not match client settings" after clicking Authorize
Authorize opens and immediately fails, or Canvas shows a 404
"The provided value is incorrect", or a warning about Site Admin keys (self-hosted only)
Every call fails with "Insufficient scopes on access token"
"The Canvas authorization has expired or was revoked"
Everything worked, then stopped (access-token option)
"This Canvas does not match the connection"
"Sign-in link already used" or "expired"
Still stuck? Open a support request · About the product: PDF Accessibility for Canvas LMS
Get your install details
Tell us about your Canvas and we will enable your institution and send the two values you need - then this guide takes about five minutes.