Skip to main content
The REST API provides the same integration features as the SDK. It works with server-side HTTP clients in any language. The base URL is https://api.cybr.com. Customer integration routes use /api/v2.

API contract

Download the OpenAPI 3.1 specification: The file works with Swagger-compatible tools and client generators. The endpoint pages use that same specification. The reference does not enable live requests against production. The specification covers learner integrations. It includes lab content reads, deployments, terminals, answers, completion, and discussions. Lab authoring, content management, internal runner, and administration routes are outside this contract.

SDK and REST differences

The SDK supplies polling, retry rules, and typed errors. Direct HTTP clients implement those behaviors themselves. Flag and guide-answer responses contain a message verdict. The SDK converts that field into { correct, verdict }. The SDK defaults launch membership to free. A direct launch request must include membership.

Authentication

Every request includes an organization key:
The key stays in secure server configuration. Learner identity is separate from organization authentication. Discussion requests also require x-cybr-learner-id. Other operations use the learner fields listed in their schemas.

Errors

An error response generally contains a message code. HTTP status distinguishes invalid input, missing access, conflicts, limits, and server errors. A timeout after a write can leave its outcome unknown. The error guide describes safe recovery.

Start with HTTP

The REST quickstart covers launch, status, and teardown. The terminal protocol covers the WebSocket connection.