Reference
The HTTP API
Everything the interface does, it does over this API. Scripts use the same routes with a token instead of a cookie.
The web UI is a client of this API and has no privileged back channel. Anything you can do in the interface, you can do from a script, with the same role check applied.
Authenticating a script
curl -H 'Authorization: Bearer mgdk_…' \
https://docker.example.com/api/environmentsAPI tokens are created under Settings and travel as a bearer header rather than a cookie — nothing about a scripted client should need cookie handling. Each token records when it was last used, so a token nothing uses any more is visible as such.
Why tokens start with mgdk_
Partly so a person can tell what kind of secret they are looking at in a list of environment variables, and partly because a recognisable prefix is exactly what automated secret scanners — GitHub's included — key off to flag a token that has leaked into a public repository. A bare 64 hex characters would be invisible to them. Tokens are stored as a SHA-256 lookup hash, not in the clear.
Route families
| Prefix | What lives there |
|---|---|
| /api/auth/* | Sign-in, sign-out, password change, TOTP enrol/confirm/disable, recovery codes, and the SSO and LDAP configuration and test endpoints. |
| /api/environments | The hosts themselves — add, edit, test, discover, reconnect, and per-host info and status. |
| /api/environments/:id/containers | List, inspect, act, top, update, and the in-container file operations. |
| /api/environments/:id/compose | Stack up and down, plus stack definitions, drift, expiry and limits. |
| /api/environments/:id/swarm/* | Swarm init, join, leave, nodes, services, scale, image update, configs and secrets. |
| /api/environments/:id/backup/* | Init, check, snapshots, restore, restore-service, swap, forget, and volume and stack backup. |
| /api/scans, /api/scanner-db | Image scans and their findings, SARIF export, and the vulnerability databases. |
| /api/gitops | Git targets, their files, manual sync, and the public webhook endpoint. |
| /api/schedules, /api/notifications | Scheduled jobs including on-demand runs, and notification channels with a test endpoint. |
| /api/users, /api/tokens | Accounts, roles, password resets, per-user TOTP disable, and API tokens. |
| /api/health, /api/metrics, /api/features | Liveness, Prometheus-style metrics, and which optional features this install has on. |
Streams
Logs, stats, events and scan progress are Server-Sent Events rather than polled endpoints; the container terminal is a WebSocket. A proxy in front of MangoDock has to leave both alone — see Behind a reverse proxy.
One transport cannot do all of this
A host connected over SSH-with-exec drives the docker CLI rather than the Engine API. Deploying a stack needs the API, and MangoDock says so rather than half-working: “deploying a stack needs the Engine API; this host is on the docker-CLI transport. Allow socket forwarding on it, or use a TCP endpoint.”
Air-gapped
- The API is served by the same container as the UI. Nothing about it reaches outside your network.