Skip to content

API keys

API keys authenticate your requests to the Mango Inference API. Every request must include a valid key.

Create a key

Keys are managed in the console, not through the API.

  1. Sign in at https://inference.mangoboost.io.
  2. Open Keys (https://inference.mangoboost.io/keys).
  3. Create a key and give it a name you will recognize later. Use one key per application or environment, so you can revoke one without breaking the rest.
  4. Copy the key and store it securely. It is shown only once.

If you lose a key, you cannot recover it. Create a new one and retire the old.

Use a key

The same key works for both endpoint families; only the header differs.

curl https://api.mangoboost.io/v1/chat/completions \
  -H "Authorization: Bearer $MANGOINFERENCE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"model": "zai-org/GLM-5.3", "messages": [{"role": "user", "content": "Hi"}]}'
curl https://api.mangoboost.io/v1/messages \
  -H "x-api-key: $MANGOINFERENCE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"model": "zai-org/GLM-5.3", "max_tokens": 64, "messages": [{"role": "user", "content": "Hi"}]}'

A missing, malformed, or unknown key returns HTTP 401 before the request reaches a model, so a 401 is always the key, never the payload. See Authentication.

Store keys in environment variables or a secrets manager. Never commit them to source control.

Manage keys

Action How
Revoke Delete the key in the console. Requests using it fail with 401 from then on.
Rotate Create the replacement first, deploy it, confirm traffic has moved, then delete the old key. There is no overlap or grace period built in: deleting first means downtime.
Scope / permissions Not available. A key is not restricted to particular models or operations, so isolate by issuing separate keys rather than by scoping one.

Because keys are unscoped, the blast radius of a leaked key is the whole account's inference. Rotate on any suspicion rather than investigating first. Creating a key costs nothing.