Authentication
API keys for the API, proxy users for the gateway.
There are two credentials, and they are not interchangeable.
| Credential | Used for | Where it comes from |
|---|---|---|
| API key | Calls to https://api.boxafox.com/v1 | Dashboard → API keys |
| Proxy user (username and password) | Connections to the gateway gw.boxafox.com:8000 | Dashboard → Proxy users, or POST /v1/proxy-users |
API keys
Send the key in the X-API-Key header on every request:
curl https://api.boxafox.com/v1/me -H "X-API-Key: prx_live_…"- A key looks like
prx_live_followed by 40 letters and digits. - The full key is shown once, when you create it. Afterwards the dashboard shows only its first 12 characters.
- An account can have up to 10 active keys. Give each integration its own key, so you can revoke one without touching the others.
- There are no test keys and no sandbox: every key acts on your real account.
GET /v1/products is the one endpoint that needs no key.
When a key is refused
| Status | error | Meaning |
|---|---|---|
| 401 | unauthorized | The header is missing or the key is not valid. |
| 401 | key_revoked | The key was revoked. Create a new one. |
| 403 | account_suspended | The account is suspended. Only GET /v1/me still answers, with the reason in suspend_reason. |
Proxy users
A proxy user is a username and password for the gateway. Every account has a default proxy user; create more to separate projects, set a data limit per user, or rotate one password without affecting the rest.
curl -X POST https://api.boxafox.com/v1/proxy-users \
-H "X-API-Key: $BOXAFOX_KEY" \
-H "Content-Type: application/json" \
-d '{ "username": "acme_scraper1", "residential_bytes_limit": 5368709120 }'usernameandpasswordare optional; both are generated when left out.- A username is unique, cannot be changed and is never reused, also after the user is deleted.
- Limits are in bytes per network;
nullmeans no limit other than the account's balance. POST /v1/proxy-users/{id}/reset-passwordrotates the password. The old one stops working within a second.
At the gateway, a wrong username or password answers 407 with X-Proxy-Error: auth_failed.