> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cybr.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs cover learner integrations through Hosted Lab Pages, the SDK, and the REST API. Content management is outside this integration scope.
> Read the setup page for the chosen approach before implementing it. Keep organization API keys and hosted mint secrets on the server.
> The public SDK is coming soon. Check the SDK quickstart for current availability. Do not invent installation commands or direct readers to a private package.
> Cybr provides completion tracking and CTF verification. The integrating platform decides whether to award points.

# Create terminal session

> Creates temporary WebSocket credentials. Keep the response private and request fresh credentials for each reconnect. SDK: `deployments.createTerminalSession()`.

SDK: `deployments.createTerminalSession()`.


## OpenAPI

````yaml assets/openapi.json POST /api/v2/deployments/{deploymentId}/terminal-session
openapi: 3.1.0
info:
  title: Cybr Labs public integration API
  version: 0.0.15
  description: SDK and REST integration contract. Organization keys remain on the server.
  contact:
    email: support@cybr.com
servers:
  - url: https://api.cybr.com
security:
  - OrganizationKey: []
tags:
  - name: Labs
    description: Content, progress, discussions, and resource links.
  - name: Deployments
    description: Lab environments and terminal sessions.
paths:
  /api/v2/deployments/{deploymentId}/terminal-session:
    post:
      tags:
        - Deployments
      summary: Create terminal session
      description: >-
        Creates temporary WebSocket credentials. Keep the response private and
        request fresh credentials for each reconnect. SDK:
        `deployments.createTerminalSession()`.
      operationId: create_terminal_session
      parameters:
        - name: deploymentId
          in: path
          required: true
          schema:
            type: string
      responses:
        '200':
          description: Successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TerminalSession'
              example:
                wsUrl: wss://terminal.example.com/session
                protocols:
                  - cybr-terminal
                  - example-token
                expiresAt: '2026-01-01T00:30:00Z'
        '400':
          description: INVALID_DEPLOYMENT_ID or NO_TERMINAL_CREDENTIALS.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Missing or invalid API key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: DEPLOYMENT_NOT_FOUND.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: >-
            INVALID_DEPLOYMENT_STATUS, TERMINAL_NOT_ENABLED,
            TERMINAL_NOT_SUPPORTED, LAB_ENDED, NO_TERMINAL_ROLE, or
            TERMINAL_ENDED.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: >-
            CONTAINER_STARTING, TERMINAL_NOT_CONFIGURED, or
            TERMINAL_UNAVAILABLE. Only CONTAINER_STARTING uses the SDK startup
            retry loop.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        default:
          description: Other API error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    TerminalSession:
      type: object
      properties:
        wsUrl:
          type: string
          format: uri
        protocols:
          type: array
          items:
            type: string
        expiresAt:
          type: string
          format: date-time
          description: >-
            Deadline for connection authorization. It is not the shell lifetime
            or deployment deadline.
      required:
        - wsUrl
        - expiresAt
    Error:
      type: object
      properties:
        message:
          type: string
        retryAfter:
          type: number
        activeCount:
          type: integer
        limit:
          type: integer
        errors:
          type: array
          items:
            type: string
      required:
        - message
  securitySchemes:
    OrganizationKey:
      type: apiKey
      in: header
      name: X-API-Key

````