Skip to main content

Organization keys

The organization key authorizes requests for your organization. The server SDK and direct REST calls keep this key on the server. Apply these rules:
  • Load the key from secure server configuration.
  • Keep the key out of browser bundles and HTML.
  • Keep the key out of source control and logs.
  • Rotate an exposed key.
  • Use separate keys for separate environments.
The API key guide explains key management.

Learner sessions

A learner ID identifies a learner. It does not authenticate the request. The server resolves the learner ID from an authenticated or guest session. Both session types require deployment ownership checks. Before status, terminal, or end requests, check that the deployment belongs to the current session. The server also chooses membership.

Lab credentials

Lab outputs can contain temporary passwords, tokens, and connection URLs for the learner’s isolated environment. Cybr destroys that environment at the end of the lab. These credentials do not provide ongoing access like an organization API key. While the lab is active, share its connection details only with the deployment owner. Keep active credentials out of public posts, logs, and analytics.

Terminal credentials

Terminal credentials provide temporary access to the learner’s disposable lab environment. They do not expose the organization API key. The expiresAt value sets the deadline for a new terminal connection. An existing connection can remain open until the lab ends. Keep active terminal credentials in memory and out of public posts, logs, and analytics. Each reconnect requests fresh credentials. Closing a terminal connection does not end the lab. When the lab ends, Cybr tears down the environment and its terminal access.

Content and errors

Lab content can contain Markdown, links, and HTML diagrams. Sanitize displayed content and use sandboxed iframes for HTML diagrams. The browser requires only relevant error fields, such as code, message, and retryAfter. Server logs retain diagnostic fields without secrets. See error handling for a response example.