For Companies & Schools
Announcing Network Firewalls to help secure your integrations
Over the past couple of weeks we've shipped Network Firewall so you can restrict traffic by IP and geography at three scopes: team-level policies for dashboard access, application-level policies for server-side API requests, and district-level policies for SSO and widget requests.
We also added ManageBac SSO via the Faria Accounts Portal, SAML NameID matching by email or person external ID, and a round of LMS/SIS sync fixes.
API Updates
- Data Feeds: Integration
created,updated, andmarked_for_deletionevents now includestate.statusis deprecated and equivalent tostate. See the Events guide. - LTI: Brightspace grade return now includes
scoreGiven/scoreMaximum. Launches that cannot download the issuer keyset returnINVALID_KEYSETinstead of a generic auth error. - Error Messages: Missing sharing rules, invitations, and uploads now return 404; inviting an existing team member or supplying an invalid CSV file URL returns 400; creating a duplicate integration override returns 409. Invalid integration access tokens return 401. Listing submissions no longer fails when an enrollment is temporarily missing a person external ID.
Dashboard Updates
- Network Firewall: Configure origin policies (known IPs, blocklists, VPN/Tor, and geographic rules) in three places. On a developer team, Team Settings → Network Firewall controls who can sign in to the Edlink dashboard. On an application, Network Firewall applies to server-side API requests authenticated with that application's credentials. On a district team, Network Firewall applies to SSO and widget traffic for integrations connected through Edlink.
- Integrations: Fixed an issue with provider names on the team integrations list.
- CSV sources: Custom CSV and SFTP sources can auto-map columns instead of running the old profiling sync.
- Onboarding: Developer teams can add sample integrations without an Integration Gateway invitation. Canvas Advanced Options and scopes selection are clearer. Institution search during onboarding is improved. Restored team admin identity-provider settings.
- Reliability: A banner appears when a new dashboard deploy is available so you can refresh. Fixed Transformations Save Changes being unclickable behind the preview list, blank Attendance State chips in Browse Data, and cramped Billing Plan edit-drawer fields.
Pipeline Updates
- ManageBac: Added ManageBac SSO through the Faria Accounts Portal, with a region step (Global, China, or US) during source setup. See Connecting ManageBac.
- SAML: Sources can match NameID to email or person external ID; AuthnRequest signing follows the IdP's advertised algorithms; a missing SSO redirect endpoint now returns
INVALID_CONFIGURATION. See Connecting SAML. - Toddle: Assignment and grade passback is supported (list, get, create, and update assignments; grade submissions). See Toddle functionality.
- Veracross: Classes ingest
school_level(with a source toggle) so you can share by school. Flow no longer creates completed historical classes in the destination LMS. - Qmlativ: Improved source validation during onboarding.
- Infinite Campus: Fixed a teacher enrollment sync bug.
- Canvas: Clearer errors when administrator OAuth credentials are rejected during source create.
- Aeries: Optional permission to expose a staff member's primary school code.
- Bromcom: Email priority now treats lower numeric values as higher priority, matching Bromcom's ordering.
- Blackbaud: Invalid OAuth grants on source create or update return a clear 400.
- Flow: New permission to pause student enrollment creation (useful before the school year starts). Sharing people and classes from school rules no longer blocks enrollments that were already shared via meetings.
