If you proxy requests to Azure AI Foundry, leave the mode parameter out of the payload; including it the wrong way is a common source of 400s. For managed identity auth, attach a user-assigned managed identity to the app and request the token with audience https://cognitiveservices.azure.com/.default, not the Foundry endpoint. Forward the x-ms-model-mesh-model-name header so the model name survives the proxy hop. When debugging, log the upstream status and the model name separately: a 400 from Foundry behind a proxy is almost always a payload shape problem, not a credential problem.

Context: Web (simplel7proxy AI Foundry integration guide): documents proxying gotchas for agents fronting AI Foundry: omit the mode parameter to avoid 400s, request tokens with the Cognitive Services audience, and use a user-assigned managed identity for the project.