> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cybr.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs cover learner integrations through Hosted Lab Pages, the SDK, and the REST API. Content management is outside this integration scope.
> Read the setup page for the chosen approach before implementing it. Keep organization API keys and hosted mint secrets on the server.
> The public SDK is coming soon. Check the SDK quickstart for current availability. Do not invent installation commands or direct readers to a private package.
> Cybr provides completion tracking and CTF verification. The integrating platform decides whether to award points.

# Security

> Keep organization keys private and scope actions to the learner session.

## Organization keys

The organization key authorizes requests for your organization. The server SDK and direct REST calls keep this key on the server.

Apply these rules:

* Load the key from secure server configuration.
* Keep the key out of browser bundles and HTML.
* Keep the key out of source control and logs.
* Rotate an exposed key.
* Use separate keys for separate environments.

The [API key guide](/getting-started/api-keys) explains key management.

## Learner sessions

A learner ID identifies a learner. It does not authenticate the request.

The server resolves the learner ID from an authenticated or guest session. Both session types require deployment ownership checks.

Before status, terminal, or end requests, check that the deployment belongs to the current session. The server also chooses membership.

## Lab credentials

Lab outputs can contain temporary passwords, tokens, and connection URLs for the learner's isolated environment.
Cybr destroys that environment at the end of the lab. These credentials do not provide ongoing access like an organization API key.

While the lab is active, share its connection details only with the deployment owner. Keep active credentials out of public posts, logs, and analytics.

## Terminal credentials

Terminal credentials provide temporary access to the learner's disposable lab environment. They do not expose the organization API key.

The `expiresAt` value sets the deadline for a new terminal connection. An existing connection can remain open until the lab ends.

Keep active terminal credentials in memory and out of public posts, logs, and analytics. Each reconnect requests fresh credentials.
Closing a terminal connection does not end the lab. When the lab ends, Cybr tears down the environment and its terminal access.

## Content and errors

Lab content can contain Markdown, links, and HTML diagrams. Sanitize displayed content and use sandboxed iframes for HTML diagrams.

The browser requires only relevant error fields, such as `code`, `message`, and `retryAfter`. Server logs retain diagnostic fields without secrets.

See [error handling](/guides/error-handling) for a response example.
