Create a launch link
The hosted mint route isPOST /launch/api/mint. Use the full endpoint URL from onboarding.
Every request includes the X-Mint-Secret header and a JSON body:
Request fields
The server chooses membership from your access policy. Premium lab access requires
membership: "premium". An absent or unrecognized value becomes free.
The mint route normalizes displayName and removes control characters. It does not derive a public name from learnerId.
memberId accepts 1–64 letters, numbers, underscores, or hyphens. Invalid values are ignored. This field does not replace learnerId.
Learner identity
A supplied learner ID stays the same across launches. It can identify a signed-in learner or a guest session managed by your platform. Without an ID, Cybr generates a newanon: identity for that mint request. The response includes the generated ID.
Completion is recorded against that anonymous ID. A later mint without an ID creates a different learner identity and does not retain the previous completion.
Automatically generated anonymous identities cannot post or delete discussion comments.
Response
A successful request returns HTTP200:
A signed URL grants access to the associated learner’s lab session. Return it only to that learner.
Server example
mintEndpoint and mintSecret come from secure server configuration. learnerId and membership come from your server session and access policy.
Mint errors
A rate-limit response includes
retryAfter in the JSON body and a Retry-After header. Named learners and generated anonymous identities use separate mint limits.
Mint limits are separate from deployment launch limits. A successful mint does not reserve a deployment slot or guarantee a successful launch.
Show a link or launch card
Direct link
Set the link target tourl from the mint response:
Embedded card
Set an iframe source toembedUrl:
https://learn.example.com, without a page path.
The iframe height is an example. Your page can adjust it to fit the card’s content.
Dark card
The compact card acceptstheme=dark:
Completion notifications
The embedded card sends this message to an allowed parent origin:expectedLabId and showLessonCompleted belong to your application. If the hosted origin differs from the example, use the origin from onboarding.
The message is a browser notification, not a server webhook. Your server can read learner completion through the organization API before it updates trusted records.
That API request uses an organization API key, not the mint secret.
A direct link does not provide the embedded-card relay. Direct-link integrations can read completion through the API instead.
Link expiration and reuse
A launch token expires after two hours by default. Hosted configuration can change that duration. The response’sexpiresAt is the exact deadline.
Each signed link can start at most one deployment. A reload can restore the existing session, but a new deployment requires a new link.
A second launch with a spent link returns 409 with code: "link_used". A failed launch releases the link reservation for another attempt.
After the lab ends, obtain a fresh link for a new attempt. After token expiration, obtain a fresh link before opening the lab page again.
End notification
The embedded card can relay an end event:destroyed, timeUp, expired, linkUsed, and failed after a deployment spent the link.
Your page can obtain a fresh link after this event. Use the same origin, iframe-source, and lab-ID checks as the completion listener.
End-event delivery is best effort. Your interface must also offer a way to request a fresh link without that event.
Ending or expiring a lab does not itself record learner completion.
Before going live
Complete these checks:- Store the mint secret in secure server configuration.
- Check your lab IDs and learner access policy.
- Send Cybr the exact origins that will embed the card.
- Launch a lab with both free and premium access where applicable.
- If your platform supports guests, check guest identity behavior.
- Complete a lab and check your platform’s progress update.
- End a lab and obtain a fresh link for another attempt.
