> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cybr.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs cover learner integrations through Hosted Lab Pages, the SDK, and the REST API. Content management is outside this integration scope.
> Read the setup page for the chosen approach before implementing it. Keep organization API keys and hosted mint secrets on the server.
> The public SDK is coming soon. Check the SDK quickstart for current availability. Do not invent installation commands or direct readers to a private package.
> Cybr provides completion tracking and CTF verification. The integrating platform decides whether to award points.

# Keys and access

> Understand the credentials for Hosted Lab Pages, the SDK, and the REST API.

Each implementation uses credentials to authorize access to your organization's labs.

| Implementation | Credential your integration sends | Purpose |
| - | - | - |
| Hosted Lab Pages | Mint secret | Generates signed launch links for learners |
| SDK | Organization API key | Calls the Cybr Labs API through the SDK |
| REST API | Organization API key | Calls the Cybr Labs API directly |

## Hosted Lab Pages

Your server sends the mint secret to Cybr to generate a signed launch link. The hosted service uses your organization's configured API key to manage labs.

Your learner receives the signed link, not either secret. The [Hosted Lab Pages integration guide](/hosted/integration) explains this setup.

## SDK and REST API

The SDK and REST API use the same organization API key. An organization administrator manages these keys in the Cybr Labs portal.

The API key is separate from a learner ID. Public SDK package availability is described in the [SDK quickstart](/getting-started/quickstart#install-the-sdk).

### Create an API key

1. Open the Cybr Labs portal as an organization administrator.
2. Create a key with a label for its environment.
3. Copy the full value.
4. Store that value in secure server configuration.

Keys start with `cybr_`.

### Use the API key

Pass the configured value to the server SDK:

```ts theme={null}
import { CybrLabs } from '@cybr/labs-sdk'

const cybr = CybrLabs.init({ key: apiKey })
```

Direct REST requests use the `X-API-Key` header. Both methods keep the key on the server.

### Manage API keys

| Action | Result |
| - | - |
| Create | Generates a new organization API key |
| Rotate | Replaces the key immediately and invalidates the old value |
| Disable | Stops the key from authenticating |
| Re-enable | Restores a disabled key |
| Archive | Permanently retires a key |

Rotation requires a coordinated update to server configuration.

## Protect your credentials

Apply these rules:

* Use a separate key for each environment.
* Keep keys out of source control, browser code, and logs.
* Rotate a key after suspected exposure.
* Remove access that staff no longer require.

The [security guide](/guides/security) covers SDK and REST learner sessions and terminal credentials. Hosted launch links use the rules in the [hosted guide](/hosted/integration).

For access questions, contact [support@cybr.com](mailto:support@cybr.com).
