EdTechLab
Back to Lab Notes
Technical report · Series part 2 of 2 25 min read

Integrating Gamified Learning with Moodle, Canvas and Blackboard: LTI 1.3, SCORM, xAPI and Open Badges

A gamified tool earns its place in a course only if it launches cleanly from the LMS, returns grades the gradebook accepts, keeps personal data to a minimum and survives a course copy. This report sets out how to do that with each platform, at the level of fields, scopes and failure modes.

Who it is for

Learning technologists and LMS administrators evaluating gamified tools, and engineers building them. It assumes familiarity with OAuth 2.0 and JSON Web Tokens, and quotes field names and scopes exactly as the specifications define them.

Author
EdTechLab team
Standards
LTI 1.3 and Advantage, SCORM, xAPI, cmi5, Open Badges 3.0, Caliper
Status as of
4 October 2026

Key findings

  1. LTI 1.3 with LTI Advantage is the route all three platforms share. Moodle 5.2 and 5.3 and Blackboard hold active 1EdTech LTI Advantage Complete certifications; Canvas's most recent one, from July 2025, is listed as out of date. Certification must be renewed every year.[8][9][10][11]
  2. Grade passback is where gamified tools break. Post a bounded mastery score marked FullyGraded, not raw points, with strictly increasing timestamps: Moodle drops the score from any other update and rejects two updates in the same second, and Canvas ignores pending scores.[4][27][33]
  3. SCORM support is uneven. Moodle supports SCORM 1.2 but not 2004; Canvas plays both through a SCORM tool that must be enabled and does not run in beta or test environments; Blackboard plays both through its SCORM Engine.[26][36][42]
  4. Saved game state can outgrow SCORM 1.2. Its cmi.suspend_data holds 4,096 characters; SCORM 2004 has guaranteed at least 64,000 since its 3rd Edition.[18][19]
  5. None of the three LMSs is a learning record store. Fine-grained game events need your own or an institutional LRS, fed with xAPI.[29][42]
  6. Open Badges 3.0 comes from partner products today. Parchment Digital Badges (for Canvas) and Milestone (for Blackboard) are certified 3.0 issuers; Moodle core issues 2.0.[9][12][13]
  7. Data protection turns on role. A provider that uses pupils' data for its own product development becomes a controller; misjudging this was the most common problem in the edtech audits the ICO reported in June 2026.[44][45]

Dates to plan around

5 October 2026
Moodle 5.3, the next long-term support release, is due.[24]
6 October 2026
Canvas Free-for-Teacher closes; its replacement, Canvas Lite, has no API access tokens.[37]
13 November 2026
Blackboard's current developer image (4000.19.0) expires.[39]
1 January and 30 September 2027
Blackboard stops new LTI 1.0 and 1.1 registrations, then switches all of them off.[40]

Choosing an integration route

Each standard carries something different. Most gamified tools need more than one: LTI to launch and return grades, xAPI for detailed events, and Open Badges for achievements that learners keep.

Integration standards for gamified learning tools and what each carries
RouteCarriesBest forWatch for
LTI 1.3 and LTI AdvantageLaunch and minimal identity; content placement (Deep Linking); grades (AGS); rosters (NRPS)Live tools and games you hostRegistration differs per LMS; strict grade rules
SCORM 1.2 and 2004Packaged content; completion, success and score; saved stateContent that must run inside the LMSNo SCORM 2004 in Moodle; small state limits; settings fixed at import
cmi5Packaged content launched by the LMS, reporting xAPI to an LRSModern packaged content with rich dataLittle native LMS support
xAPIDetailed learning events as statementsAnalytics and research on game playNeeds an LRS; identity must be pseudonymous
Open Badges 3.0Verifiable, portable achievementsCredentials learners keepIssued by partner products today
Caliper and LMS event streamsActivity events from the LMSInstitution-level analyticsVersion 1.1 in practice; availability varies

How an LTI 1.3 launch works

LTI 1.3 builds on OpenID Connect. The core specification and the 1EdTech Security Framework define a third-party-initiated login in which the LMS (the platform) and your tool exchange a signed JSON Web Token, the id_token.[1][2]

LTI 1.3 resource link launch, step by step

  1. LMS to toolLogin initiationThe LMS calls the tool's login URL with iss, login_hint and target_link_uri, which are required, and optionally lti_message_hint, lti_deployment_id and client_id.
  2. Tool to LMSAuthentication requestThe tool redirects to the platform's authorisation endpoint with scope=openid, response_type=id_token, response_mode=form_post, prompt=none, its client_id, its registered redirect_uri, the login_hint, a nonce and a state, echoing lti_message_hint unaltered.
  3. LMS to toolSigned id_tokenThe platform form-posts the signed id_token and the state to the redirect URI.
  4. ToolValidateCheck the signature against the platform's key set using the kid; iss, aud and azp; exp and iat with no more than a few minutes of leeway; nonce reuse; the state; the deployment; and version 1.3.0.
  5. ToolLaunchRead the claims, find or create the user from sub, and redirect to the signed target_link_uri claim rather than the unsigned login parameter.
  6. Tool to LMSService callsFor grades or rosters, request an access token with a client-credentials grant and a signed JWT assertion whose iss and sub are your client_id, then call the services with the scopes granted. Tokens are recommended to last 3,600 seconds and cannot be refreshed.
Sources: LTI Core 1.3 and the 1EdTech Security Framework.[1][2]

The claims that matter

Claims sit under https://purl.imsglobal.org/spec/lti/claim/. A resource link launch must carry message_type (LtiResourceLinkRequest), version (1.3.0), deployment_id, target_link_uri, resource_link and roles, which may be an empty array, plus sub except in anonymous launches.[1] Two details are often missed. The context claim is optional, so a tool must not assume a course; and the resource_link id must change when a link is copied, which matters for any per-link game state. Values in the custom claim must be strings, and a value starting with $ asks the platform to substitute data such as $Context.id.[1]

Only sub is a required user claim. Name, email and locale are optional, and a platform may launch anonymously, leaving out sub and every identity claim. The certification suite tests both cases, so a tool should handle them by design.[1][8]

Keys and rotation

Sign with RSA keys of at least SHA-256 (RS256), publish them in a JSON Web Key Set, give every key a kid even when there is only one, and never reuse a kid for a different key. To rotate, add the new key under a new kid and keep the old one in the set while both are in use.[2] Rotate keys inside a stable key-set URL: a 2021 Blackboard developer post notes that changing the URL itself forced institutions to redeploy the tool.[39]

The LTI Advantage services

Deep Linking 2.0: placing content and creating the grade column

In an LtiDeepLinkingRequest, the platform sends deep_linking_settings with a deep_link_return_url, accept_types and accept_presentation_document_targets, and optionally accept_multiple, accept_lineitem and auto_create. The tool answers by form-posting a signed LtiDeepLinkingResponse in a parameter named JWT, with content_items of type ltiResourceLink, link, file, html or image.[3] An ltiResourceLink can carry a lineItem with a label, scoreMaximum, resourceId and tag, so the gradebook column is created with the link. The specification calls this the declarative approach and prefers it where it fits.[3][4]

Assignment and Grade Services 2.0

The launch carries an endpoint claim with the granted scopes and the line item URLs. The four scopes are https://purl.imsglobal.org/spec/lti-ags/scope/lineitem, …/lineitem.readonly, …/result.readonly and …/score. Scores are posted to the line item URL with /scores appended, as application/vnd.ims.lis.v1.score+json.[4]

A score carries userId, timestamp, activityProgress (Initialized, Started, InProgress, Submitted, Completed) and gradingProgress (FullyGraded, Pending, PendingManual, Failed, NotReady), with scoreGiven and scoreMaximum when there is a score. Four rules decide whether gamified tools behave: platforms may ignore anything not FullyGraded; a missing scoreGiven clears any previous score; timestamps must strictly increase and never repeat for the same learner and line item; and a platform must not apply an update older than the one it holds.[4]

Names and Role Provisioning Services 2.0

With the contextmembership.readonly scope, a tool can read a course roster. Each member carries at least a user_id, matching the launch sub, and roles; anything more depends on the platform's consent, so tools should not rely on it. Results are paged through Link headers.[5] For gamification, the roster is useful for team challenges; most tools can avoid it and create users at launch.

Dynamic Registration

LTI Dynamic Registration 1.0 automates the exchange of configuration between tool and platform, though an administrator still reviews and activates the result. It remains a candidate final specification, yet all three platforms support it in some form. Its claims array is also a privacy control: a tool can ask for sub alone.[6][7]

What each LMS does with LTI 1.3

Moodle

Administrators register a tool dynamically by pasting its registration URL and choosing "Add LTI Advantage", available since Moodle 3.10, or manually with a key set URL, login URL and redirect URIs.[25][28] Moodle's iss is the site address, its key set is at /mod/lti/certs.php and its token endpoint at /mod/lti/token.php. Sharing the launcher's name and email with the tool defaults to never.[27]

Moodle's grade handling is stricter than the specification. Its 5.2 code rejects a score without userId, timestamp, gradingProgress or activityProgress, sets scoreGiven to null unless the score is FullyGraded, rescales scores to the grade item's maximum, and returns HTTP 409 when the stored grade is as new as or newer than the incoming timestamp, compared to the whole second. Two updates within the same second therefore clash.[27] Moodle can also publish its own courses and activities to other platforms as an LTI Advantage tool, synchronising grades and members every 30 minutes by default.[25]

Canvas

LTI 1.3 tools are configured as developer keys, entered manually or from JSON, and installed in an account or course by client ID; disabling or deleting the key removes every installation. Canvas supports dynamic registration, where the default privacy level is anonymous and administrators can remove requested scopes.[31][36] The privacy_level setting takes anonymous, name_only, email_only or public, but sub is always sent. Hosted Canvas uses https://canvas.instructure.com as its issuer, with authentication and key-set endpoints on sso.canvaslms.com.[31]

A Deep Linking content item with a lineItem creates an assignment, from three placements: assignment selection, the course assignments menu and the module index menu. A line item created without a resource link creates a placeholder assignment.[32][33] Canvas returns HTTP 400 for a score timestamp earlier than the stored result and 422 for a user who is not a student in the course, and ignores scoreGiven when progress is NotReady, Failed or Pending. Roster requests return 50 members per page by default.[33] Canvas notifies tools of course imports through its Platform Notification Service, without retrying failed deliveries, and supports LTI platform storage for browsers that block third-party cookies.[31][32] Its REST API is throttled by a cost per request, returning HTTP 429, and since June 2026 rejects requests without a User-Agent header with HTTP 403.[34]

Blackboard

The tool vendor registers once in the Blackboard Developer Portal and receives an application (client) ID, the issuer https://blackboard.com and the platform endpoints; institutions then deploy the tool by client ID, and Blackboard generates a deployment ID. Dynamic registration happens in the Developer Portal. Blackboard accepts RS256 and RS512 signatures.[38] Administrators choose which user fields to send (role, name and email address are preselected) and whether each tool may read rosters and grades, and grade services only expose columns the tool created. LTI must be enabled in three places, and deleting a tool's domain or placement breaks existing links permanently.[41] Some Blackboard developer pages differ from the specification on details such as the scores path, so build to the specification and test.[38] Its Developer Portal limits REST calls to 10,000 per 24 hours per developer group by default, returning HTTP 429 with a Retry-After header; whether this also covers LTI service calls is not documented.[39]

LTI 1.3 support in Moodle, Canvas and Blackboard, October 2026
CapabilityMoodleCanvasBlackboard (Ultra)
LTI Advantage certificationActive 5.2 and 5.3Out of date July 2025Active April 2026
Dynamic RegistrationYes since 3.10Yes anonymous by defaultYes via Developer Portal
Deep Linking 2.0Yes multiple links since 3.10Yes a line item creates an assignmentYes
Grade services (AGS)Yes FullyGraded onlyYes placeholder assignmentsYes tool-created columns only
Identity sent by defaultName and email: neverDepends on privacy level; sub alwaysRole, name, email preselected
Cookie-less launch supportUnverifiedYesYes
Legacy LTI 1.1Still selectableNo end date foundSwitched off by 30 Sep 2027

Designing grade passback for gamified tools

Points, streaks and levels belong in the tool. The gradebook should receive something an assessor would recognise. In practice:

  • Post mastery, not raw points. Unbounded points fit badly in a gradebook, and Moodle and Canvas rescale to the column maximum. Keep points in the tool and post a bounded score, such as a mastery percentage with scoreMaximum of 100.[4][27][33]
  • Send scores only when final. Post scoreGiven with gradingProgress of FullyGraded, and never send a progress-only update after a score exists, because a missing scoreGiven clears it.[4]
  • Create columns declaratively. Return a lineItem through Deep Linking, and before creating any line item programmatically, look up existing ones by resource_link_id, resource_id or tag.[3][4]
  • Use time carefully. Send ISO 8601 timestamps with sub-second precision from clock-synchronised servers, and no more than one score per learner and line item per second.[4][27]
  • Recover without duplicates. The grade service has no idempotency key. After an ambiguous failure, read the current result, then re-post with a later timestamp.[4]
  • Survive course copies. Resource link IDs change on copy while resourceId and tag survive; Canvas also offers $Context.id.history and copy notices.[1][4][32]

SCORM: portable, with sharp edges

SCORM remains the most portable way to put content inside an LMS, and the usual choice where tools cannot be hosted externally. The limits that matter for game-like content are these:[18][19]

SCORM 1.2 and SCORM 2004 data model elements that matter for gamified content
ElementSCORM 1.2SCORM 2004 (4th Edition)
Saved statecmi.suspend_data: 4,096 charactersAt least 64,000 characters (raised from 4,000 in the 3rd Edition)
Statuscmi.core.lesson_status: one combined valueSeparate completion_status and success_status
Scorecmi.core.score.raw, normalised 0 to 100cmi.score.scaled from −1 to 1, plus raw, min and max
Bookmark255 charactersAt least 1,000 characters
InteractionsOptional for the LMSAt least 250

Moodle supports SCORM 1.2, passing the ADL conformance test suite, but not SCORM 2004: some 2004 packages may appear to work, but development has stopped. Its "SCORM standards mode" is off by default, which lets SCORM 1.2 packages store up to 64,000 characters of state, so a package that relies on this may fail elsewhere.[26][27] Canvas needs its SCORM tool enabled at account level. It plays SCORM 1.2 and SCORM 2004 2nd to 4th Editions as a graded assignment, ungraded assignment or page, a choice that cannot be changed after import; uploads default to 100 points, and SCORM is not available in Canvas beta or test environments.[36] Blackboard plays SCORM 1.2, SCORM 2004 4th Edition, AICC and xAPI packages through its SCORM Engine, grading the whole package or individual SCOs. With multiple attempts it uses the last graded attempt, and the grade schema and maximum cannot be changed after import.[42]

For gamified content, that means shipping SCORM 1.2 where Moodle is involved, keeping saved state within 4,096 characters (compress it, or keep state on a server), and testing in SCORM Cloud, which plays and debugs packages but does not certify them.[43]

xAPI and cmi5

An xAPI statement needs an actor, a verb and an object, and may carry a result with a score scaled from −1 to 1, success, completion and duration. Where personal data is a concern, the specification recommends identifying the actor by an opaque account name.[20] IEEE 9274.1.1-2023, which IEEE describes as standardising xAPI 1.0.3, was adopted in 2025 as ISO/IEC/IEEE 39274-1-1, and ADL's specification repository lists xAPI 2.0 as the current version.[20][21]

cmi5 adds the missing LMS launch. The LMS launches an assignable unit with endpoint, fetch, actor, registration and activityId; the unit exchanges the one-time fetch URL for an authorisation token, reads launch data including the moveOn rule, and must send "initialized" first and "terminated" last.[22]

None of the three platforms is a learning record store. Moodle's core xAPI library, added for H5P, is not meant to be a full LRS, but the logstore_xapi plugin forwards Moodle events to an external LRS and ADL publishes a cmi5 launch plugin.[23][29] We found no native xAPI, LRS or cmi5 support documented for Canvas. Blackboard plays xAPI packages without an LRS, and its SCORM Engine can forward SCORM activity data to an external LRS.[42]

Open Badges 3.0 and portable credentials

Open Badges 3.0 aligns badges with the W3C Verifiable Credentials Data Model 2.0, a W3C Recommendation since May 2025. Credentials are OpenBadgeCredential or AchievementCredential, signed as VC-JWT or with a Data Integrity proof, with issuer keys found at an HTTP URL or a DID, and can be bundled into a Comprehensive Learner Record 2.0.[14][15][17] Moodle core issues certified Open Badges 2.0, with 3.0 in development. In Canvas, Parchment Digital Badges issues 3.0 for paid organisations that opt in, and those badges are private by default. In Blackboard, the Achievements tool links to Milestone, which moved to 3.0 in July 2025 and holds an active 3.0 issuer certification.[9][12][13][49][50] For gamified tools, the practical choice is to issue credentials for meaningful achievements through one of these issuers, or as a certified issuer yourself, rather than pushing badge counts into the gradebook.

Analytics events

Caliper 1.2, published in 2020, defines event envelopes and metric profiles, but Canvas and Blackboard use 1.1 in practice.[16] Canvas Live Events can be delivered in Caliper 1.1 format to a queue or a signed webhook, with monthly key rotation and up to three retries; Canvas Data 2 provides bulk snapshots and incremental queries.[35] Blackboard holds an active Caliper 1.1 certification and can stream events to an external store.[11][39] Moodle has no native Caliper; its options are web services and log store plugins.[28][29]

Privacy, security and UK law

Role first. Under the ICO's edtech guidance, whether a provider is a controller or a processor depends on who actually controls the processing, whatever the contract says. A provider that only follows an institution's instructions is likely a processor, but one that uses pupils' data for its own purposes, such as product development, becomes a controller and may bring the Children's code into scope.[44] In June 2026 the ICO reported on its audits of 28 edtech providers, whose products included learning management systems. Misjudging this role was the most common problem, especially where data fed product development or analytics, alongside thin contracts, incomplete data-flow maps and weak impact assessments.[45]

Minimise at launch. Request only sub and roles, using the registration claims array and anonymous launches where possible. In Moodle, leave name and email sharing at never; in Canvas, set privacy_level to anonymous; in Blackboard, untick name and email and turn off roster access a tool does not need. Use opaque identifiers in xAPI.[6][27][31][41][46]

Mind transfers and the 2026 changes. Restricted international transfers need adequacy regulations, approved safeguards or an exception.[46] Since 19 June 2026, organisations must run a data protection complaints process under the Data (Use and Access) Act, and on 30 September 2026 the ICO formally became the Information Commission.[47]

Be ready to rotate. In May 2026 the US Department of Education warned of a cybersecurity incident involving Canvas, carried out through Free-for-Teacher accounts, and advised institutions to rotate LTI tools, single sign-on connectors and API keys.[48] Every integration should have a documented key rotation procedure.

Testing and certification

1EdTech certification means passing its test suite, which deliberately sends malformed launches, and renewing every year as a member; platforms must pass the core and all three services. Development tools include the LTI reference implementation and build.1edtech.org.[8] SCORM Cloud plays and debugs SCORM, xAPI, cmi5 and LTI content and includes an LRS, and ADL's CATAPULT provides cmi5 test suites for content and for LMSs, with a reference player.[23][43] For platforms: Moodle's public sandbox resets hourly and moodle-docker runs locally; Canvas is open source and runs locally under Docker, though a self-hosted instance uses its own issuer; and Blackboard publishes a developer image, the current one expiring on 13 November 2026.[30][37][39]

A reference architecture

Putting these constraints together, a gamified tool that integrates with all three platforms needs four parts of its own: an LTI service, a game engine, a grade policy and a privacy layer. The diagram reads from top to bottom.

LMS

MoodleDynamic registration; name and email off by default
CanvasDeveloper key by client ID; privacy level
BlackboardDeveloper Portal; deploy by client ID
Launch and servicesLTI 1.3, Deep Linking, AGS, NRPS

Your tool

LTI serviceLogin, launch, key set, token client; registrations keyed by issuer, client and deployment
Game enginePoints, levels, streaks and saved state stay here
Grade policyBounded mastery score, FullyGraded, increasing timestamps
Privacy layersub-only identity; pseudonymous leaderboards

Outputs

GradebookMastery score through AGS
Learning record storexAPI with opaque actors
CredentialsOpen Badges 3.0 for real achievements
AnalyticsReports from LRS data, plus LMS event streams where available

Failure modes to design for

  • Clock skew breaks token validation and grade ordering: synchronise clocks and allow only a few minutes of leeway.[2][4]
  • Key rotation breaks launches if old keys disappear early or the key-set URL changes.[2][39]
  • Duplicate line items appear when tools post before looking up existing columns; Canvas turns each into a placeholder assignment.[4][33]
  • Course copies change resource link IDs, orphaning per-link state unless the tool maps history.[1][32]
  • Rate limits return HTTP 429 in Canvas and Blackboard: back off and spread synchronisation.[34][39]
  • Blocked third-party cookies break the login state: use LTI platform storage where the LMS supports it, with a fallback.[31][38]
  • Destructive admin actions, such as deleting a Canvas developer key or a Blackboard tool domain, remove installs or break links: put them in runbooks.[36][41]

Implementation checklist

  • Validate iss, aud and azp, exp and iat, nonce reuse, state, deployment and version on every launch
  • Publish a key set with a kid on every key, and sign with RS256 (Blackboard also accepts RS512)
  • Store registrations by issuer, client ID and deployment ID
  • Support Dynamic Registration and request only the claims you need
  • Create grade columns through Deep Linking; look up before creating line items; store their IDs
  • Post bounded, FullyGraded scores with sub-second, strictly increasing timestamps
  • Handle Moodle's 409 and Canvas's 400 and 422 responses, and back off on 429
  • Use roster services only when the design needs them, and follow paging links exactly
  • Fall back to LTI platform storage when cookies are blocked
  • Send a descriptive User-Agent on every Canvas API call
  • Keep SCORM 1.2 saved state within 4,096 characters, and ship SCORM 1.2 for Moodle
  • Send xAPI with opaque actors to an LRS with a defined retention period
  • Decide and document your controller or processor role, and complete a DPIA
  • Plan for Blackboard's LTI 1.1 retirement and keep certification current
  • Test against the 1EdTech suite, local Moodle and Canvas, the Blackboard developer image, and SCORM Cloud or CATAPULT

Where EdTechLab stands

We hold ourselves to the standard this report describes. Our platforms intle, EngagedLab and interacty export SCORM 1.2 and SCORM 2004 (4th Edition) packages. In July 2026, intle's packages passed all 124 SCORM Cloud checks, run across both versions combined. Because Moodle does not support SCORM 2004, Moodle sites should use the SCORM 1.2 export.

LTI 1.3, the LTI Advantage services and live xAPI are not features of our products today. When a client project needs them, we scope and build the integration against the checklist above. Sky, our research and development programme for module-level learning design, is being designed to install into Blackboard Ultra and Canvas through LTI 1.3, with Moodle and Brightspace planned to follow. 1EdTech LTI 1.3 conformance certification is planned before general availability.

Limits of this report

  • Specification and platform details reflect documents and directory entries on 4 October 2026; certification status and platform behaviour change.
  • Moodle behaviour is taken from its 5.2 source code; Canvas and Blackboard behaviour from their documentation, which sometimes differs from the specifications.
  • We did not run live integrations against production instances for this report.
  • Some points could not be verified, including the engine behind Canvas's SCORM tool, native xAPI or cmi5 in Canvas, and Moodle support for LTI platform storage.

References

Accessed 4 October 2026.

  1. 1EdTech. Learning Tools Interoperability Core Specification 1.3. Source
  2. 1EdTech. Security Framework 1.0 (2019) and 1.1 (2021). Source
  3. 1EdTech. LTI Deep Linking 2.0. Source
  4. 1EdTech. LTI Assignment and Grade Services 2.0. Source
  5. 1EdTech. LTI Names and Role Provisioning Services 2.0. Source
  6. 1EdTech. LTI Dynamic Registration 1.0 (Candidate Final). Source
  7. 1EdTech. Learning Tools Interoperability standard page and LTI deprecation schedule. Source
  8. 1EdTech. LTI Advantage Conformance Certification Guide, Get your product certified, the LTI Reference Implementation and build.1edtech.org. Source
  9. 1EdTech TrustEd Apps Directory: Moodle. Source
  10. 1EdTech TrustEd Apps Directory: Canvas. Source
  11. 1EdTech TrustEd Apps Directory: Blackboard. Source
  12. 1EdTech TrustEd Apps Directory: Parchment Digital Badges. Source
  13. 1EdTech TrustEd Apps Directory: Milestone. Source
  14. 1EdTech. Open Badges 3.0 (and Open Badges 2.0). Source
  15. 1EdTech. Comprehensive Learner Record 2.0. Source
  16. 1EdTech. Caliper Analytics 1.2. Source
  17. W3C. Verifiable Credentials Data Model v2.0, Recommendation, 15 May 2025. Source
  18. ADL. SCORM 1.2 Run-Time Environment (2001). Source
  19. ADL. SCORM 2004 4th Edition Testing Requirements (2009) and SCORM 2004 3rd Edition Impact Summary (2006). Source
  20. ADL. xAPI specification repository (xAPI 1.0.3 data model; current version noted as 2.0). Source
  21. IEEE. IEEE 9274.1.1-2023; ISO/IEC/IEEE 39274-1-1:2025. Source
  22. AICC/ADL. cmi5 specification (Quartz). Source
  23. ADL. CATAPULT cmi5 test tools; Moodle-mod_cmi5launch. Source
  24. Moodle HQ. Releases. Source
  25. MoodleDocs 5.2. LTI External tools and Publish as LTI tool. Source
  26. MoodleDocs. SCORM FAQ and SCORM settings. Source
  27. Moodle source code, MOODLE_502_STABLE: mod_lti, the grade services scores handler and mod_scorm settings. Source
  28. Moodle Tracker: LTI 1.3 (MDL-62599), dynamic registration (MDL-67301), Caliper (MDL-55106) and related issues. Source
  29. Moodle developer documentation, xAPI subsystem, web services and log store plugins; xAPI-vle, moodle-logstore_xapi. Source
  30. Moodle sandbox and moodle-docker. Source
  31. Instructure developer documentation: Manually configuring LTI Advantage tools, LTI launch overview and Registration. Source
  32. Instructure developer documentation: Placements, Deep Linking, Platform Notification Service and Variable substitutions. Source
  33. Instructure developer documentation: Line Items, Score and Names and Role APIs. Source
  34. Instructure: Throttling; Enforcing User-Agent header for Canvas API requests; Upcoming API changes (13 April 2026). Source
  35. Instructure developer documentation: Live Events and Data Access Platform. Source
  36. Instructure Community: How do I configure an LTI key for an account? and How do I import SCORM files as an assignment? Source
  37. Instructure: Canvas Lite announcement (September 2026); canvas-lms repository. Source
  38. Blackboard developer documentation: Getting started with LTI, Registering a new LTI application, Best practices, Authenticating using OIDC, Assignment and Grade Services and Registering a REST or LTI application. Source
  39. Blackboard developer documentation: rate limits, sandbox environments, Caliper, and LTI 1.3 tools must generate their own keys and JWKS URL (2021). Source
  40. Blackboard Community. Retirement of LTI 1.1 support in Blackboard LMS (28 August 2026). Source
  41. Blackboard Help. Set up LTIs (updated 19 September 2026). Source
  42. Blackboard Help. SCORM Engine (administrator) and SCORM packages (Ultra instructor). Source
  43. Rustici Software. SCORM Cloud. Source
  44. Information Commissioner's Office. The Children's code and education technologies (edtech) (updated 30 May 2023). Source
  45. Information Commissioner's Office. Statement on the Edtech examined report (24 June 2026). Source
  46. Information Commissioner's Office. What are controllers and processors?, Data minimisation and International transfers. Source
  47. Information Commissioner's Office. Statements on the Data (Use and Access) Act: commencement, complaints, and governance changes for 30 September 2026. Source
  48. US Department of Education, Federal Student Aid. Technology security alert: ongoing cybersecurity incident involving Canvas (12 May 2026, updated 29 May 2026). Source
  49. Instructure. Canvas Badges/Credentials release notes (2 June 2025) and FAQ: Rebranding Canvas Credentials to Parchment Digital Badges. Source
  50. Blackboard Help, Anthology Milestone and Blackboard (14 July 2026); Blackboard blog, A new era for digital credentials: Open Badges 3.0 is here (31 July 2025). Source

Next step

Planning a gamified tool for your LMS?

We can review an integration plan against this checklist, or scope and build one with you.

Series

Gamification in the LMS

  1. Part 1: What the platforms do natively
  2. Part 2: Integration with LTI 1.3, SCORM, xAPI and Open Badges (this report)

Core finding

Keep the game in the tool and send the LMS what an assessor would recognise: a bounded, final mastery score, minimal identity, and credentials learners can keep.

In this report