Skip to main content
Each implementation uses credentials to authorize access to your organization’s labs.

Hosted Lab Pages

Your server sends the mint secret to Cybr to generate a signed launch link. The hosted service uses your organization’s configured API key to manage labs. Your learner receives the signed link, not either secret. The Hosted Lab Pages integration guide explains this setup.

SDK and REST API

The SDK and REST API use the same organization API key. An organization administrator manages these keys in the Cybr Labs portal. The API key is separate from a learner ID. Public SDK package availability is described in the SDK quickstart.

Create an API key

  1. Open the Cybr Labs portal as an organization administrator.
  2. Create a key with a label for its environment.
  3. Copy the full value.
  4. Store that value in secure server configuration.
Keys start with cybr_.

Use the API key

Pass the configured value to the server SDK:
Direct REST requests use the X-API-Key header. Both methods keep the key on the server.

Manage API keys

Rotation requires a coordinated update to server configuration.

Protect your credentials

Apply these rules:
  • Use a separate key for each environment.
  • Keep keys out of source control, browser code, and logs.
  • Rotate a key after suspected exposure.
  • Remove access that staff no longer require.
The security guide covers SDK and REST learner sessions and terminal credentials. Hosted launch links use the rules in the hosted guide. For access questions, contact support@cybr.com.