Skip to main content

What is a Proxy?

A proxy is a server that acts as an intermediary between your application and another server. In the context of SCANOSS, a reverse proxy sits between your tools and the SCANOSS API, forwarding requests on your behalf.

Why Use a Proxy with SCANOSS?

Centralised API Key Management

The proxy automatically injects the SCANOSS API key into outgoing requests, eliminating the need to distribute it to individual developer machines. This ensures centralised control over API access.

Security & Access Control

  • Enforce corporate policies with centralised traffic monitoring and filtering
  • Restrict access to authorised internal systems
  • Maintain full visibility into all API interactions

Usage Tracking & Logging

  • Monitor scan activity by team or project
  • Analyse API usage patterns
  • Preserve detailed audit logs for compliance

Network Architecture Requirements

Supports enterprise network policies requiring:
  • Centralised outbound traffic control
  • Internal certificate-based communication
  • Deep packet inspection and filtering

Prerequisites

Before you begin, you will need:
  • Caddy: A reverse proxy server used to inject your SCANOSS API key into outgoing API requests.
  • SCANOSS API key: Required to authenticate requests to the SCANOSS API.

Basic Proxy Configuration

Follow the steps below to configure Caddy as a reverse proxy that injects your SCANOSS API key into outgoing requests. Windows / macOS / Linux
  1. Create a new folder to store Caddy and its configuration.
  2. Inside that folder, create a new file named Caddyfile.
  3. Add the following configuration:
  1. Replace YOUR_API_KEY_HERE with your actual SCANOSS API key. If you do not yet have a key, refer to the Prerequisites section above.
  2. Save and close the file.
You can change port 1980 to any available port (e.g. 8080 or 8888).
Ensure the chosen port is not already in use by another service.

Running Caddy

Once the Caddyfile is configured, you can start the proxy in either interactive or background mode.

Interactive Mode

Run Caddy in the foreground to verify your configuration and observe logs in real time. Windows
macOS / Linux

Background Mode

Run Caddy as a background process so it continues running after you close the terminal. Windows
macOS / Linux

Stopping Caddy

Running as a systemd Service (Linux only)

Note: systemd is a Linux-specific init system and is not available on macOS by default. macOS users should use launchd or run Caddy in background mode instead.
Run Caddy as a systemd service to ensure it starts automatically on boot and restarts if it crashes.
  1. Create a systemd service file:
  1. Add the following configuration:
Update /etc/caddy/Caddyfile to match the actual path to your Caddyfile.
Update /usr/bin/caddy if Caddy is installed in a different location (verify with which caddy).
  1. Enable and start the service:
  1. Check the service status:

Running as a Windows Service

Run Caddy as a Windows service to ensure it starts automatically on boot and restarts if it crashes.
  1. Download and install NSSM (Non-Sucking Service Manager).
  2. Open PowerShell as Administrator and change directory to the folder where NSSM is installed.
  3. Install Caddy as a service:
Replace C:\path\to\caddy.exe with the actual path to your Caddy executable.
Replace C:\path\to\Caddyfile with the actual path to your Caddyfile.
  1. Configure the service (optional):
  1. Start the service:
  1. Verify the service is running:
Managing the Windows service:
You can also manage the service through the Windows Services manager (services.msc).

Troubleshooting

Port Conflicts

If Caddy fails to start, Caddy’s built-in admin API (which listens on a separate port by default) may be conflicting with another process. Disable the admin API by adding the following global block at the top of your Caddyfile, before any site definitions:

Stopping Existing Caddy Instances

If the conflict persists, check for running Caddy processes and stop them. Windows:
Linux / macOS: