Skip to main content

Learner IDs

A learnerId identifies a learner in API requests. Cybr does not require that learner to have a Cybr account. Use these rules for IDs:
  • Use an opaque ID from your integration.
  • Keep the ID stable for the same learner.
  • Add an integration-specific namespace, such as academy:user:uuid.
  • Keep names and email addresses out of the ID.
  • Resolve the ID from a server session.
The namespace prevents accidental collisions with IDs from other integrations. A browser-supplied ID alone does not prove ownership.

Signed-in learners

The server maps its authenticated session to a stable learner ID. The same ID applies to launches, flags, completion, and discussions.

Guest learners

The server issues an opaque guest ID and associates it with a guest session. The learner does not require a login. The session retains its ID across requests. The server stores each deployment ID with the guest session that owns it.
A lost guest session can lose access to its previous deployments and progress. Guest-to-account linking belongs to your platform.

Membership

Each launch declares free or premium. The SDK defaults to free. Direct REST requests must include the field. These are default launch limits. The API response supplies the current wait time if a request reaches a limit. Login and membership are independent. Your server chooses membership from your access policy. The browser does not choose premium access.

Deployment ownership

Before each status, terminal, or end request, check the deployment association in your server session. The organization key authorizes organization access. It does not replace your checks for individual learners.

Read completion

The learnerId query scopes the completion result to that learner. Without it, the response does not describe an individual learner. See completion and CTF verification for recording progress.