
mxHeadless
REST API gateway for headless frontends on MODX 3. Resources, objects, OpenAPI, API keys, and OAuth
- MODX 3
- PHP 8.1


Setting mxheadless_trusted_proxies holds a comma-separated list of IPs. Newlines and CIDR are not parsed.
If REMOTE_ADDR is in the list, client IP comes from the first address in X-Forwarded-For. Otherwise the package uses only REMOTE_ADDR.
IP affects rate limit and the audit log. An empty list is safe for direct connections.
X-Forwarded-Proto for URL building. Configure HTTPS on the reverse proxy203.0.113.10,203.0.113.11