> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cybr.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs cover learner integrations through Hosted Lab Pages, the SDK, and the REST API. Content management is outside this integration scope.
> Read the setup page for the chosen approach before implementing it. Keep organization API keys and hosted mint secrets on the server.
> Install the SDK with `npm install @cybr/labs-sdk`. It runs on the server; the `/terminal`, `/terminal/xterm`, `/video`, and `/hosted-browser` entry points run in the browser.
> Cybr provides completion tracking and CTF verification. The integrating platform decides whether to award points.

# REST API

> Use the same Cybr Labs API through direct HTTP requests.

The REST API provides the same integration features as the SDK. It works with server-side HTTP clients in any language.

The base URL is `https://api.cybr.com`. Customer integration routes use `/api/v2`.

## API contract

Download the OpenAPI 3.1 specification:

<a href="/assets/openapi.json" download="cybr-labs-openapi.json">Download OpenAPI JSON</a>

The file works with Swagger-compatible tools and client generators.

The endpoint pages use that same specification. The reference does not enable live requests against production.

The specification covers learner integrations. It includes lab content reads, deployments, terminals, answers, completion, and discussions.

This specification covers every operation available to organization API keys.

## SDK and REST differences

The SDK supplies polling, retry rules, and typed errors. Direct HTTP clients implement those behaviors themselves.

Flag and guide-answer responses contain a `message` verdict. The SDK converts that field into `{ correct, verdict }`.

The SDK defaults launch membership to `free`. A direct launch request must include `membership`.

## Authentication

Every request includes an organization key:

```http theme={null}
X-API-Key: cybr_your_api_key
```

The key stays in secure server configuration. Learner identity is separate from organization authentication.

Discussion requests also require `x-cybr-learner-id`. Other operations use the learner fields listed in their schemas.

## Errors

An error response generally contains a `message` code. HTTP status distinguishes invalid input, missing access, conflicts, limits, and server errors.

A timeout after a write can leave its outcome unknown. The [error guide](/guides/error-handling) describes safe recovery.

## Start with HTTP

The [REST quickstart](/api-reference/quickstart) covers launch, status, and teardown. The [terminal protocol](/api-reference/terminal-protocol) covers the WebSocket connection.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.