API keys¶
API keys authenticate your requests to the Mango Inference API. Every request must include a valid key.
Create a key¶
Keys are managed in the console, not through the API.
- Sign in at https://inference.mangoboost.io.
- Open Keys (https://inference.mangoboost.io/keys).
- Create a key and give it a name you will recognize later. Use one key per application or environment, so you can revoke one without breaking the rest.
- Copy the key and store it securely. It is shown only once.
If you lose a key, you cannot recover it. Create a new one and retire the old.
Use a key¶
The same key works for both endpoint families; only the header differs.
curl https://api.mangoboost.io/v1/chat/completions \
-H "Authorization: Bearer $MANGOINFERENCE_API_KEY" \
-H "Content-Type: application/json" \
-d '{"model": "zai-org/GLM-5.3", "messages": [{"role": "user", "content": "Hi"}]}'
curl https://api.mangoboost.io/v1/messages \
-H "x-api-key: $MANGOINFERENCE_API_KEY" \
-H "Content-Type: application/json" \
-d '{"model": "zai-org/GLM-5.3", "max_tokens": 64, "messages": [{"role": "user", "content": "Hi"}]}'
A missing, malformed, or unknown key returns HTTP 401 before the request
reaches a model, so a 401 is always the key, never the payload. See
Authentication.
Store keys in environment variables or a secrets manager. Never commit them to source control.
Manage keys¶
| Action | How |
|---|---|
| Revoke | Delete the key in the console. Requests using it fail with 401 from then on. |
| Rotate | Create the replacement first, deploy it, confirm traffic has moved, then delete the old key. There is no overlap or grace period built in: deleting first means downtime. |
| Scope / permissions | Not available. A key is not restricted to particular models or operations, so isolate by issuing separate keys rather than by scoping one. |
Because keys are unscoped, the blast radius of a leaked key is the whole account's inference. Rotate on any suspicion rather than investigating first. Creating a key costs nothing.