Skip to main content
Cybr verifies CTF flags and records learner completion. Your server receives these results directly from the API. Cybr does not calculate scores or maintain your leaderboard. Those features belong to your platform.

What each result means

Explicit completion is self-reported by your application. It is not proof that a learner solved a flag or passed every question.

Verify a CTF flag

A successful correct-flag response means that Cybr recorded completion. An incorrect flag does not record completion. The result contains correct and verdict. Possible verdicts are CORRECT_FLAG, INCORRECT_FLAG, and NOT_CTF.

Record explicit completion

When your completion policy permits it, call markCompleted():
An existing completion returns the same success response. A repeated response does not identify a new completion event.

Read completion status

The completed field describes the specified learner. It does not distinguish a correct flag from explicit completion. Your platform can store the verification result separately. This retains the reason that your application recorded completion.

Update your own platform

Your application can use completion results to unlock lessons or show progress. It controls those decisions. If your platform awards points or badges, deduplicate those awards in your database. A unique learner-and-lab key is one possible policy. Use one transaction for an award and its score update. Concurrent requests or repeated submissions must not create duplicate awards. Cybr does not return point values or unique completion-event IDs.

Errors and recovery

A completion persistence error returns HTTP 500 with COMPLETION_RECORD_FAILED. The SDK reports server_error and retains that backendCode. After a timeout, the request outcome can be unknown. Read the learner-specific completion status to help reconcile your records. A successful response can arrive more than once. Your platform retains its deduplication rule during recovery.

No callback endpoint required

This response-based flow requires no endpoint for Cybr to call on your platform. Cybr also requires no customer GET endpoint. The integration sends identity and membership in its requests. These docs do not define an outbound completion webhook.