> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cybr.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs cover learner integrations through Hosted Lab Pages, the SDK, and the REST API. Content management is outside this integration scope.
> Read the setup page for the chosen approach before implementing it. Keep organization API keys and hosted mint secrets on the server.
> The public SDK is coming soon. Check the SDK quickstart for current availability. Do not invent installation commands or direct readers to a private package.
> Cybr provides completion tracking and CTF verification. The integrating platform decides whether to award points.

# Submit flag

> Grades the flag. A correct result records completion. Incorrect verdicts also use HTTP 200. SDK: `labs.submitFlag()`.

SDK: `labs.submitFlag()`.


## OpenAPI

````yaml assets/openapi.json POST /api/v2/labs/{labId}/flag
openapi: 3.1.0
info:
  title: Cybr Labs public integration API
  version: 0.0.15
  description: SDK and REST integration contract. Organization keys remain on the server.
  contact:
    email: support@cybr.com
servers:
  - url: https://api.cybr.com
security:
  - OrganizationKey: []
tags:
  - name: Labs
    description: Content, progress, discussions, and resource links.
  - name: Deployments
    description: Lab environments and terminal sessions.
paths:
  /api/v2/labs/{labId}/flag:
    post:
      tags:
        - Labs
      summary: Submit flag
      description: >-
        Grades the flag. A correct result records completion. Incorrect verdicts
        also use HTTP 200. SDK: `labs.submitFlag()`.
      operationId: submit_flag
      parameters:
        - name: labId
          in: path
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/FlagRequest'
            example:
              learnerId: academy:user:uuid
              flag: example-flag
      responses:
        '200':
          description: Successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/FlagResponse'
              example:
                message: CORRECT_FLAG
        '400':
          description: Invalid request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Missing or invalid API key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Lab not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: COMPLETION_RECORD_FAILED or server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        default:
          description: Other API error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    FlagRequest:
      type: object
      properties:
        learnerId:
          type: string
        flag:
          type: string
      required:
        - learnerId
        - flag
    FlagResponse:
      type: object
      properties:
        message:
          enum:
            - CORRECT_FLAG
            - INCORRECT_FLAG
            - NOT_CTF
      required:
        - message
    Error:
      type: object
      properties:
        message:
          type: string
        retryAfter:
          type: number
        activeCount:
          type: integer
        limit:
          type: integer
        errors:
          type: array
          items:
            type: string
      required:
        - message
  securitySchemes:
    OrganizationKey:
      type: apiKey
      in: header
      name: X-API-Key

````