# MangoProxy API Authentication

How to authenticate to the MangoProxy proxy-management API and to MangoProxy
proxies. See also the machine-readable guide at https://mangoproxy.com/auth.md

## Summary

MangoProxy publishes Auth.md discovery:

- Protected Resource Metadata: https://mangoproxy.com/.well-known/oauth-protected-resource
- Authorization Server metadata (with `agent_auth`): https://mangoproxy.com/.well-known/oauth-authorization-server

Credentials are API keys. Today they are provisioned by a human through the
dashboard; `/agent/auth` returns a structured `registration_via_dashboard`
response until automated agent registration is enabled.

## Steps

1. Discover: fetch the PRM, then the AS metadata, and read `agent_auth`.
2. Sign up / generate keys: https://my.mangoproxy.com/
3. Call the Agent API with header `x-api-key: <api_key>`.
4. Docs: https://mangoproxy.com/dev/ and https://backend.mangoproxy.com/public-api/docs

## Credential types

- **API key** — for managing proxies, sub-users and integrations via the API.
  Keep it secret and never embed it in client-side code.
- **Proxy credentials** — `username:password` for HTTP/SOCKS proxy
  authentication, taken from the dashboard's connection-string generator.

## Free tools

The public network tools (IP lookup, proxy checker, port scanner, IP trace)
require no authentication. See the `mangoproxy-tools` skill and the OpenAPI
specification at https://mangoproxy.com/.well-known/openapi.json
