Developer Guide
Quickstart
Mango Power Open API uses the OAuth 2.0 Client Credentials Grant. Your backend authenticates with its Client ID and Client Secret and exchanges those credentials for a short-lived access token.
Before you begin
Section titled “Before you begin”Complete these steps before integrating with the Open API:
- Create a Mango Power account. Register in the Mango Power app or create an account at account.mangopower.com.
- Set up your organization. Contact a Mango Power administrator to create an organization for you in the appropriate region. Your sites and devices will be managed under this organization and made available to its Application Clients through the Open API.
- Create an Application Client. Sign in to the Mango Power ISP Portal, open Open API → Application Clients, and create a Client ID and Client Secret for your organization.
- Get your regional base URL. On the ISP Portal’s Open API → Application Clients page, copy the Open API Base URL shown for the current region. If you switch regions, use the URL shown after switching.
Keep the Client Secret on your server. Do not embed it in browser or mobile application code.
Request an access token
Section titled “Request an access token”Before calling a protected endpoint, send an OAuth 2.0 token request to POST /openapi/auth. Authenticate the Application Client with HTTP Basic and set grant_type=client_credentials in the form body. Use the returned short-lived Bearer token for subsequent requests.
For the complete request format, token lifecycle, and error handling, see Authentication.
Set OPEN_API_BASE_URL to the Open API Base URL shown on the ISP Portal’s Application Clients page, without a trailing slash.
Endpoint
POST {OPEN_API_BASE_URL}/openapi/authHeaders
Authorization: Basic <encoded_client_credentials>Content-Type: application/x-www-form-urlencodedAccept: application/jsonForm body
grant_type=client_credentials&scope=openapi.readUse an OAuth library or mature HTTP client to construct the HTTP Basic header from your Client ID and Client Secret.
A successful response contains a Bearer token that expires after one hour (3,600 seconds):
{ "access_token": "eyJhbGciOi...", "token_type": "Bearer", "expires_in": 3600}Tokens expire after one hour. Refresh the token proactively before it expires and use the new token for subsequent requests. Requesting a new token for every API call adds latency and unnecessary authentication traffic.
Call protected endpoints
Section titled “Call protected endpoints”Send the token in the Authorization header:
Authorization: Bearer eyJhbGciOi...The Application Client token is separate from Mango Power user login tokens and cannot be used with the IoT Admin or installer user APIs.
Open the API reference for the complete endpoint contract.
Continue with Device endpoints for the recommended discovery flow and guidance on product-specific Realtime metrics and energy History data.