Integrating Gamified Learning with Moodle, Canvas and Blackboard: LTI 1.3, SCORM, xAPI and Open Badges
A gamified tool earns its place in a course only if it launches cleanly from the LMS, returns grades the gradebook accepts, keeps personal data to a minimum and survives a course copy. This report sets out how to do that with each platform, at the level of fields, scopes and failure modes.
Who it is for
Learning technologists and LMS administrators evaluating gamified tools, and engineers building them. It assumes familiarity with OAuth 2.0 and JSON Web Tokens, and quotes field names and scopes exactly as the specifications define them.
Key findings
- LTI 1.3 with LTI Advantage is the route all three platforms share. Moodle 5.2 and 5.3 and Blackboard hold active 1EdTech LTI Advantage Complete certifications; Canvas's most recent one, from July 2025, is listed as out of date. Certification must be renewed every year.[8][9][10][11]
- Grade passback is where gamified tools break. Post a bounded mastery score marked
FullyGraded, not raw points, with strictly increasing timestamps: Moodle drops the score from any other update and rejects two updates in the same second, and Canvas ignores pending scores.[4][27][33] - SCORM support is uneven. Moodle supports SCORM 1.2 but not 2004; Canvas plays both through a SCORM tool that must be enabled and does not run in beta or test environments; Blackboard plays both through its SCORM Engine.[26][36][42]
- Saved game state can outgrow SCORM 1.2. Its
cmi.suspend_dataholds 4,096 characters; SCORM 2004 has guaranteed at least 64,000 since its 3rd Edition.[18][19] - None of the three LMSs is a learning record store. Fine-grained game events need your own or an institutional LRS, fed with xAPI.[29][42]
- Open Badges 3.0 comes from partner products today. Parchment Digital Badges (for Canvas) and Milestone (for Blackboard) are certified 3.0 issuers; Moodle core issues 2.0.[9][12][13]
- Data protection turns on role. A provider that uses pupils' data for its own product development becomes a controller; misjudging this was the most common problem in the edtech audits the ICO reported in June 2026.[44][45]
Dates to plan around
- 5 October 2026
- Moodle 5.3, the next long-term support release, is due.[24]
- 6 October 2026
- Canvas Free-for-Teacher closes; its replacement, Canvas Lite, has no API access tokens.[37]
- 13 November 2026
- Blackboard's current developer image (4000.19.0) expires.[39]
- 1 January and 30 September 2027
- Blackboard stops new LTI 1.0 and 1.1 registrations, then switches all of them off.[40]
Choosing an integration route
Each standard carries something different. Most gamified tools need more than one: LTI to launch and return grades, xAPI for detailed events, and Open Badges for achievements that learners keep.
| Route | Carries | Best for | Watch for |
|---|---|---|---|
| LTI 1.3 and LTI Advantage | Launch and minimal identity; content placement (Deep Linking); grades (AGS); rosters (NRPS) | Live tools and games you host | Registration differs per LMS; strict grade rules |
| SCORM 1.2 and 2004 | Packaged content; completion, success and score; saved state | Content that must run inside the LMS | No SCORM 2004 in Moodle; small state limits; settings fixed at import |
| cmi5 | Packaged content launched by the LMS, reporting xAPI to an LRS | Modern packaged content with rich data | Little native LMS support |
| xAPI | Detailed learning events as statements | Analytics and research on game play | Needs an LRS; identity must be pseudonymous |
| Open Badges 3.0 | Verifiable, portable achievements | Credentials learners keep | Issued by partner products today |
| Caliper and LMS event streams | Activity events from the LMS | Institution-level analytics | Version 1.1 in practice; availability varies |
How an LTI 1.3 launch works
LTI 1.3 builds on OpenID Connect. The core specification and the 1EdTech Security Framework
define a third-party-initiated login in which the LMS (the platform) and your tool exchange a
signed JSON Web Token, the id_token.[1][2]
LTI 1.3 resource link launch, step by step
- LMS to toolLogin initiationThe LMS calls the tool's login URL with
iss,login_hintandtarget_link_uri, which are required, and optionallylti_message_hint,lti_deployment_idandclient_id. - Tool to LMSAuthentication requestThe tool redirects to the platform's authorisation endpoint with
scope=openid,response_type=id_token,response_mode=form_post,prompt=none, itsclient_id, its registeredredirect_uri, thelogin_hint, anonceand astate, echoinglti_message_hintunaltered. - LMS to toolSigned id_tokenThe platform form-posts the signed
id_tokenand thestateto the redirect URI. - ToolValidateCheck the signature against the platform's key set using the
kid;iss,audandazp;expandiatwith no more than a few minutes of leeway; nonce reuse; thestate; the deployment; and version1.3.0. - ToolLaunchRead the claims, find or create the user from
sub, and redirect to the signedtarget_link_uriclaim rather than the unsigned login parameter. - Tool to LMSService callsFor grades or rosters, request an access token with a client-credentials grant and a signed JWT assertion whose
issandsubare yourclient_id, then call the services with the scopes granted. Tokens are recommended to last 3,600 seconds and cannot be refreshed.
The claims that matter
Claims sit under https://purl.imsglobal.org/spec/lti/claim/. A resource link launch
must carry message_type (LtiResourceLinkRequest), version
(1.3.0), deployment_id, target_link_uri,
resource_link and roles, which may be an empty array, plus
sub except in anonymous launches.[1]
Two details are often missed. The context claim is optional, so a tool must not
assume a course; and the resource_link id must change when a link is
copied, which matters for any per-link game state. Values in the custom claim must
be strings, and a value starting with $ asks the platform to substitute data such as
$Context.id.[1]
Only sub is a required user claim. Name, email and locale are optional, and a
platform may launch anonymously, leaving out sub and every identity claim. The
certification suite tests both cases, so a tool should handle them by design.[1][8]
Keys and rotation
Sign with RSA keys of at least SHA-256 (RS256), publish them in a JSON Web Key Set, give every
key a kid even when there is only one, and never reuse a kid for a
different key. To rotate, add the new key under a new kid and keep the old one in
the set while both are in use.[2] Rotate keys
inside a stable key-set URL: a 2021 Blackboard developer post notes that changing the URL
itself forced institutions to redeploy the tool.[39]
The LTI Advantage services
Deep Linking 2.0: placing content and creating the grade column
In an LtiDeepLinkingRequest, the platform sends
deep_linking_settings with a deep_link_return_url,
accept_types and accept_presentation_document_targets, and optionally
accept_multiple, accept_lineitem and auto_create. The tool
answers by form-posting a signed LtiDeepLinkingResponse in a parameter named
JWT, with content_items of type ltiResourceLink,
link, file, html or image.[3]
An ltiResourceLink can carry a lineItem with a label,
scoreMaximum, resourceId and tag, so the gradebook column
is created with the link. The specification calls this the declarative approach and prefers it
where it fits.[3][4]
Assignment and Grade Services 2.0
The launch carries an endpoint claim with the granted scopes and the line item URLs. The four
scopes are https://purl.imsglobal.org/spec/lti-ags/scope/lineitem,
…/lineitem.readonly, …/result.readonly and …/score.
Scores are posted to the line item URL with /scores appended, as
application/vnd.ims.lis.v1.score+json.[4]
A score carries userId, timestamp, activityProgress
(Initialized, Started, InProgress, Submitted,
Completed) and gradingProgress (FullyGraded,
Pending, PendingManual, Failed, NotReady),
with scoreGiven and scoreMaximum when there is a score. Four rules
decide whether gamified tools behave: platforms may ignore anything not FullyGraded;
a missing scoreGiven clears any previous score; timestamps must strictly increase
and never repeat for the same learner and line item; and a platform must not apply an update
older than the one it holds.[4]
Names and Role Provisioning Services 2.0
With the contextmembership.readonly scope, a tool can read a course roster. Each
member carries at least a user_id, matching the launch sub, and
roles; anything more depends on the platform's consent, so tools should not rely
on it. Results are paged through Link headers.[5]
For gamification, the roster is useful for team challenges; most tools can avoid it and create
users at launch.
Dynamic Registration
LTI Dynamic Registration 1.0 automates the exchange of configuration between tool and platform,
though an administrator still reviews and activates the result. It remains a candidate final
specification, yet all three platforms support it in some form. Its claims array is
also a privacy control: a tool can ask for sub alone.[6][7]
What each LMS does with LTI 1.3
Moodle
Administrators register a tool dynamically by pasting its registration URL and choosing "Add
LTI Advantage", available since Moodle 3.10, or manually with a key set URL, login URL and
redirect URIs.[25][28]
Moodle's iss is the site address, its key set is at /mod/lti/certs.php
and its token endpoint at /mod/lti/token.php. Sharing the launcher's name and email
with the tool defaults to never.[27]
Moodle's grade handling is stricter than the specification. Its 5.2 code rejects a score
without userId, timestamp, gradingProgress or
activityProgress, sets scoreGiven to null unless the score is
FullyGraded, rescales scores to the grade item's maximum, and returns HTTP 409 when
the stored grade is as new as or newer than the incoming timestamp, compared to the whole
second. Two updates
within the same second therefore clash.[27]
Moodle can also publish its own courses and activities to other platforms as an LTI Advantage
tool, synchronising grades and members every 30 minutes by default.[25]
Canvas
LTI 1.3 tools are configured as developer keys, entered manually or from JSON, and installed in
an account or course by client ID; disabling or deleting the key removes every installation.
Canvas supports dynamic registration, where the default privacy level is anonymous and
administrators can remove requested scopes.[31][36]
The privacy_level setting takes anonymous, name_only,
email_only or public, but sub is always sent. Hosted Canvas
uses https://canvas.instructure.com as its issuer, with authentication and key-set
endpoints on sso.canvaslms.com.[31]
A Deep Linking content item with a lineItem creates an assignment, from three
placements: assignment selection, the course assignments menu and the module index menu. A line
item created without a resource link creates a placeholder assignment.[32][33]
Canvas returns HTTP 400 for a score timestamp earlier than the stored result and 422 for a user
who is not a student in the course, and ignores scoreGiven when progress is
NotReady, Failed or Pending. Roster requests
return 50 members per page by default.[33]
Canvas notifies tools of course imports through its Platform Notification Service, without
retrying failed deliveries, and supports LTI platform storage for browsers that block
third-party cookies.[31][32]
Its REST API is throttled by a cost per request, returning HTTP 429, and since June 2026
rejects requests without a User-Agent header with HTTP 403.[34]
Blackboard
The tool vendor registers once in the Blackboard Developer Portal and receives an application
(client) ID, the issuer https://blackboard.com and the platform endpoints;
institutions then deploy the tool by client ID, and Blackboard generates a deployment ID.
Dynamic registration happens in the Developer Portal. Blackboard accepts RS256 and RS512
signatures.[38]
Administrators choose which user fields to send (role, name and email address are preselected)
and whether each tool may read rosters and grades, and grade services only expose columns the
tool created. LTI must be enabled in three places, and deleting a tool's domain or placement
breaks existing links permanently.[41]
Some Blackboard developer pages differ from the specification on details such as the scores
path, so build to the specification and test.[38]
Its Developer Portal limits REST calls to 10,000 per 24 hours per developer group by default,
returning HTTP 429 with a Retry-After header; whether this also covers LTI
service calls is not documented.[39]
| Capability | Moodle | Canvas | Blackboard (Ultra) |
|---|---|---|---|
| LTI Advantage certification | Active 5.2 and 5.3 | Out of date July 2025 | Active April 2026 |
| Dynamic Registration | Yes since 3.10 | Yes anonymous by default | Yes via Developer Portal |
| Deep Linking 2.0 | Yes multiple links since 3.10 | Yes a line item creates an assignment | Yes |
| Grade services (AGS) | Yes FullyGraded only | Yes placeholder assignments | Yes tool-created columns only |
| Identity sent by default | Name and email: never | Depends on privacy level; sub always | Role, name, email preselected |
| Cookie-less launch support | Unverified | Yes | Yes |
| Legacy LTI 1.1 | Still selectable | No end date found | Switched off by 30 Sep 2027 |
Designing grade passback for gamified tools
Points, streaks and levels belong in the tool. The gradebook should receive something an assessor would recognise. In practice:
- Post mastery, not raw points. Unbounded points fit badly in a gradebook, and Moodle and Canvas rescale to the column maximum. Keep points in the tool and post a bounded score, such as a mastery percentage with
scoreMaximumof 100.[4][27][33] - Send scores only when final. Post
scoreGivenwithgradingProgressofFullyGraded, and never send a progress-only update after a score exists, because a missingscoreGivenclears it.[4] - Create columns declaratively. Return a
lineItemthrough Deep Linking, and before creating any line item programmatically, look up existing ones byresource_link_id,resource_idortag.[3][4] - Use time carefully. Send ISO 8601 timestamps with sub-second precision from clock-synchronised servers, and no more than one score per learner and line item per second.[4][27]
- Recover without duplicates. The grade service has no idempotency key. After an ambiguous failure, read the current result, then re-post with a later timestamp.[4]
- Survive course copies. Resource link IDs change on copy while
resourceIdandtagsurvive; Canvas also offers$Context.id.historyand copy notices.[1][4][32]
SCORM: portable, with sharp edges
SCORM remains the most portable way to put content inside an LMS, and the usual choice where tools cannot be hosted externally. The limits that matter for game-like content are these:[18][19]
| Element | SCORM 1.2 | SCORM 2004 (4th Edition) |
|---|---|---|
| Saved state | cmi.suspend_data: 4,096 characters | At least 64,000 characters (raised from 4,000 in the 3rd Edition) |
| Status | cmi.core.lesson_status: one combined value | Separate completion_status and success_status |
| Score | cmi.core.score.raw, normalised 0 to 100 | cmi.score.scaled from −1 to 1, plus raw, min and max |
| Bookmark | 255 characters | At least 1,000 characters |
| Interactions | Optional for the LMS | At least 250 |
Moodle supports SCORM 1.2, passing the ADL conformance test suite, but not SCORM 2004: some 2004 packages may appear to work, but development has stopped. Its "SCORM standards mode" is off by default, which lets SCORM 1.2 packages store up to 64,000 characters of state, so a package that relies on this may fail elsewhere.[26][27] Canvas needs its SCORM tool enabled at account level. It plays SCORM 1.2 and SCORM 2004 2nd to 4th Editions as a graded assignment, ungraded assignment or page, a choice that cannot be changed after import; uploads default to 100 points, and SCORM is not available in Canvas beta or test environments.[36] Blackboard plays SCORM 1.2, SCORM 2004 4th Edition, AICC and xAPI packages through its SCORM Engine, grading the whole package or individual SCOs. With multiple attempts it uses the last graded attempt, and the grade schema and maximum cannot be changed after import.[42]
For gamified content, that means shipping SCORM 1.2 where Moodle is involved, keeping saved state within 4,096 characters (compress it, or keep state on a server), and testing in SCORM Cloud, which plays and debugs packages but does not certify them.[43]
xAPI and cmi5
An xAPI statement needs an actor, a verb and an object, and
may carry a result with a score scaled from −1 to 1, success, completion and
duration. Where personal data is a concern, the specification recommends identifying the actor
by an opaque account name.[20] IEEE
9274.1.1-2023, which IEEE describes as standardising xAPI 1.0.3, was adopted in 2025 as
ISO/IEC/IEEE 39274-1-1, and ADL's specification repository lists xAPI 2.0 as the current
version.[20][21]
cmi5 adds the missing LMS launch. The LMS launches an assignable unit with
endpoint, fetch, actor, registration and
activityId; the unit exchanges the one-time fetch URL for an
authorisation token, reads launch data including the moveOn rule, and must send
"initialized" first and "terminated" last.[22]
None of the three platforms is a learning record store. Moodle's core xAPI library, added for
H5P, is not meant to be a full LRS, but the logstore_xapi plugin forwards Moodle
events to an external LRS and ADL publishes a cmi5 launch plugin.[23][29]
We found no native xAPI, LRS or cmi5 support documented for Canvas. Blackboard plays xAPI
packages without an LRS, and its SCORM Engine can forward SCORM activity data to an external
LRS.[42]
Open Badges 3.0 and portable credentials
Open Badges 3.0 aligns badges with the W3C Verifiable Credentials Data Model 2.0, a W3C
Recommendation since May 2025. Credentials are OpenBadgeCredential or
AchievementCredential, signed as VC-JWT or with a Data Integrity proof, with issuer
keys found at an HTTP URL or a DID, and can be bundled into a Comprehensive Learner Record
2.0.[14][15][17]
Moodle core issues certified Open Badges 2.0, with 3.0 in development. In Canvas, Parchment
Digital Badges issues 3.0 for paid organisations that opt in, and those badges are private by
default. In Blackboard, the Achievements tool links to Milestone, which moved to 3.0 in July
2025 and holds an active 3.0 issuer certification.[9][12][13][49][50]
For gamified tools, the practical choice is to issue credentials for meaningful achievements
through one of these issuers, or as a certified issuer yourself, rather than pushing badge counts
into the gradebook.
Analytics events
Caliper 1.2, published in 2020, defines event envelopes and metric profiles, but Canvas and Blackboard use 1.1 in practice.[16] Canvas Live Events can be delivered in Caliper 1.1 format to a queue or a signed webhook, with monthly key rotation and up to three retries; Canvas Data 2 provides bulk snapshots and incremental queries.[35] Blackboard holds an active Caliper 1.1 certification and can stream events to an external store.[11][39] Moodle has no native Caliper; its options are web services and log store plugins.[28][29]
Privacy, security and UK law
Role first. Under the ICO's edtech guidance, whether a provider is a controller or a processor depends on who actually controls the processing, whatever the contract says. A provider that only follows an institution's instructions is likely a processor, but one that uses pupils' data for its own purposes, such as product development, becomes a controller and may bring the Children's code into scope.[44] In June 2026 the ICO reported on its audits of 28 edtech providers, whose products included learning management systems. Misjudging this role was the most common problem, especially where data fed product development or analytics, alongside thin contracts, incomplete data-flow maps and weak impact assessments.[45]
Minimise at launch. Request only sub and roles, using the
registration claims array and anonymous launches where possible. In Moodle, leave
name and email sharing at never; in Canvas, set privacy_level to anonymous; in
Blackboard, untick name and email and turn off roster access a tool does not need. Use opaque
identifiers in xAPI.[6][27][31][41][46]
Mind transfers and the 2026 changes. Restricted international transfers need adequacy regulations, approved safeguards or an exception.[46] Since 19 June 2026, organisations must run a data protection complaints process under the Data (Use and Access) Act, and on 30 September 2026 the ICO formally became the Information Commission.[47]
Be ready to rotate. In May 2026 the US Department of Education warned of a cybersecurity incident involving Canvas, carried out through Free-for-Teacher accounts, and advised institutions to rotate LTI tools, single sign-on connectors and API keys.[48] Every integration should have a documented key rotation procedure.
Testing and certification
1EdTech certification means passing its test suite, which deliberately sends malformed launches,
and renewing every year as a member; platforms must pass the core and all three services.
Development tools include the LTI reference implementation and build.1edtech.org.[8]
SCORM Cloud plays and debugs SCORM, xAPI, cmi5 and LTI content and includes an LRS, and ADL's
CATAPULT provides cmi5 test suites for content and for LMSs, with a reference player.[23][43]
For platforms: Moodle's public sandbox resets hourly and moodle-docker runs locally;
Canvas is open source and runs locally under Docker, though a self-hosted instance uses its
own issuer; and Blackboard publishes
a developer image, the current one expiring on 13 November 2026.[30][37][39]
A reference architecture
Putting these constraints together, a gamified tool that integrates with all three platforms needs four parts of its own: an LTI service, a game engine, a grade policy and a privacy layer. The diagram reads from top to bottom.
LMS
Your tool
Outputs
Failure modes to design for
- Clock skew breaks token validation and grade ordering: synchronise clocks and allow only a few minutes of leeway.[2][4]
- Key rotation breaks launches if old keys disappear early or the key-set URL changes.[2][39]
- Duplicate line items appear when tools post before looking up existing columns; Canvas turns each into a placeholder assignment.[4][33]
- Course copies change resource link IDs, orphaning per-link state unless the tool maps history.[1][32]
- Rate limits return HTTP 429 in Canvas and Blackboard: back off and spread synchronisation.[34][39]
- Blocked third-party cookies break the login state: use LTI platform storage where the LMS supports it, with a fallback.[31][38]
- Destructive admin actions, such as deleting a Canvas developer key or a Blackboard tool domain, remove installs or break links: put them in runbooks.[36][41]
Implementation checklist
- Validate
iss,audandazp,expandiat, nonce reuse,state, deployment and version on every launch - Publish a key set with a
kidon every key, and sign with RS256 (Blackboard also accepts RS512) - Store registrations by issuer, client ID and deployment ID
- Support Dynamic Registration and request only the claims you need
- Create grade columns through Deep Linking; look up before creating line items; store their IDs
- Post bounded,
FullyGradedscores with sub-second, strictly increasing timestamps - Handle Moodle's 409 and Canvas's 400 and 422 responses, and back off on 429
- Use roster services only when the design needs them, and follow paging links exactly
- Fall back to LTI platform storage when cookies are blocked
- Send a descriptive
User-Agenton every Canvas API call - Keep SCORM 1.2 saved state within 4,096 characters, and ship SCORM 1.2 for Moodle
- Send xAPI with opaque actors to an LRS with a defined retention period
- Decide and document your controller or processor role, and complete a DPIA
- Plan for Blackboard's LTI 1.1 retirement and keep certification current
- Test against the 1EdTech suite, local Moodle and Canvas, the Blackboard developer image, and SCORM Cloud or CATAPULT
Where EdTechLab stands
We hold ourselves to the standard this report describes. Our platforms intle, EngagedLab and interacty export SCORM 1.2 and SCORM 2004 (4th Edition) packages. In July 2026, intle's packages passed all 124 SCORM Cloud checks, run across both versions combined. Because Moodle does not support SCORM 2004, Moodle sites should use the SCORM 1.2 export.
LTI 1.3, the LTI Advantage services and live xAPI are not features of our products today. When a client project needs them, we scope and build the integration against the checklist above. Sky, our research and development programme for module-level learning design, is being designed to install into Blackboard Ultra and Canvas through LTI 1.3, with Moodle and Brightspace planned to follow. 1EdTech LTI 1.3 conformance certification is planned before general availability.
Limits of this report
- Specification and platform details reflect documents and directory entries on 4 October 2026; certification status and platform behaviour change.
- Moodle behaviour is taken from its 5.2 source code; Canvas and Blackboard behaviour from their documentation, which sometimes differs from the specifications.
- We did not run live integrations against production instances for this report.
- Some points could not be verified, including the engine behind Canvas's SCORM tool, native xAPI or cmi5 in Canvas, and Moodle support for LTI platform storage.
References
Accessed 4 October 2026.
- 1EdTech. Learning Tools Interoperability Core Specification 1.3. Source
- 1EdTech. Security Framework 1.0 (2019) and 1.1 (2021). Source
- 1EdTech. LTI Deep Linking 2.0. Source
- 1EdTech. LTI Assignment and Grade Services 2.0. Source
- 1EdTech. LTI Names and Role Provisioning Services 2.0. Source
- 1EdTech. LTI Dynamic Registration 1.0 (Candidate Final). Source
- 1EdTech. Learning Tools Interoperability standard page and LTI deprecation schedule. Source
- 1EdTech. LTI Advantage Conformance Certification Guide, Get your product certified, the LTI Reference Implementation and build.1edtech.org. Source
- 1EdTech TrustEd Apps Directory: Moodle. Source
- 1EdTech TrustEd Apps Directory: Canvas. Source
- 1EdTech TrustEd Apps Directory: Blackboard. Source
- 1EdTech TrustEd Apps Directory: Parchment Digital Badges. Source
- 1EdTech TrustEd Apps Directory: Milestone. Source
- 1EdTech. Open Badges 3.0 (and Open Badges 2.0). Source
- 1EdTech. Comprehensive Learner Record 2.0. Source
- 1EdTech. Caliper Analytics 1.2. Source
- W3C. Verifiable Credentials Data Model v2.0, Recommendation, 15 May 2025. Source
- ADL. SCORM 1.2 Run-Time Environment (2001). Source
- ADL. SCORM 2004 4th Edition Testing Requirements (2009) and SCORM 2004 3rd Edition Impact Summary (2006). Source
- ADL. xAPI specification repository (xAPI 1.0.3 data model; current version noted as 2.0). Source
- IEEE. IEEE 9274.1.1-2023; ISO/IEC/IEEE 39274-1-1:2025. Source
- AICC/ADL. cmi5 specification (Quartz). Source
- ADL. CATAPULT cmi5 test tools; Moodle-mod_cmi5launch. Source
- Moodle HQ. Releases. Source
- MoodleDocs 5.2. LTI External tools and Publish as LTI tool. Source
- MoodleDocs. SCORM FAQ and SCORM settings. Source
- Moodle source code, MOODLE_502_STABLE: mod_lti, the grade services scores handler and mod_scorm settings. Source
- Moodle Tracker: LTI 1.3 (MDL-62599), dynamic registration (MDL-67301), Caliper (MDL-55106) and related issues. Source
- Moodle developer documentation, xAPI subsystem, web services and log store plugins; xAPI-vle, moodle-logstore_xapi. Source
- Moodle sandbox and moodle-docker. Source
- Instructure developer documentation: Manually configuring LTI Advantage tools, LTI launch overview and Registration. Source
- Instructure developer documentation: Placements, Deep Linking, Platform Notification Service and Variable substitutions. Source
- Instructure developer documentation: Line Items, Score and Names and Role APIs. Source
- Instructure: Throttling; Enforcing User-Agent header for Canvas API requests; Upcoming API changes (13 April 2026). Source
- Instructure developer documentation: Live Events and Data Access Platform. Source
- Instructure Community: How do I configure an LTI key for an account? and How do I import SCORM files as an assignment? Source
- Instructure: Canvas Lite announcement (September 2026); canvas-lms repository. Source
- Blackboard developer documentation: Getting started with LTI, Registering a new LTI application, Best practices, Authenticating using OIDC, Assignment and Grade Services and Registering a REST or LTI application. Source
- Blackboard developer documentation: rate limits, sandbox environments, Caliper, and LTI 1.3 tools must generate their own keys and JWKS URL (2021). Source
- Blackboard Community. Retirement of LTI 1.1 support in Blackboard LMS (28 August 2026). Source
- Blackboard Help. Set up LTIs (updated 19 September 2026). Source
- Blackboard Help. SCORM Engine (administrator) and SCORM packages (Ultra instructor). Source
- Rustici Software. SCORM Cloud. Source
- Information Commissioner's Office. The Children's code and education technologies (edtech) (updated 30 May 2023). Source
- Information Commissioner's Office. Statement on the Edtech examined report (24 June 2026). Source
- Information Commissioner's Office. What are controllers and processors?, Data minimisation and International transfers. Source
- Information Commissioner's Office. Statements on the Data (Use and Access) Act: commencement, complaints, and governance changes for 30 September 2026. Source
- US Department of Education, Federal Student Aid. Technology security alert: ongoing cybersecurity incident involving Canvas (12 May 2026, updated 29 May 2026). Source
- Instructure. Canvas Badges/Credentials release notes (2 June 2025) and FAQ: Rebranding Canvas Credentials to Parchment Digital Badges. Source
- Blackboard Help, Anthology Milestone and Blackboard (14 July 2026); Blackboard blog, A new era for digital credentials: Open Badges 3.0 is here (31 July 2025). Source
Next step
Planning a gamified tool for your LMS?
We can review an integration plan against this checklist, or scope and build one with you.