Agent Skills

omni-api-keys

Create, list, rotate, and revoke OmniRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints.

Install

npx skills add https://github.com/diegosouzapw/omniroute --skill omni-api-keys
SKILL.md

Overview

Create, list, rotate, and revoke OmniRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints.

Authentication

All requests require a valid Bearer token or session cookie. Obtain a token via POST /api/auth/login or configure REQUIRE_API_KEY=false for local development.

Endpoints

GET /api/keys

List API keys

curl https://localhost:20128/api/keys \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

POST /api/keys

Create API key

curl -X POST https://localhost:20128/api/keys \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

GET /api/keys/{id}

Get API key

curl https://localhost:20128/api/keys/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

PATCH /api/keys/{id}

Update API key

curl -X PATCH https://localhost:20128/api/keys/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

DELETE /api/keys/{id}

Delete API key

curl -X DELETE https://localhost:20128/api/keys/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

GET /api/keys/{id}/devices

List devices for an API key

Lists the distinct devices (masked IP + User-Agent fingerprints) tracked for an API key by the in-memory device tracker. IPs are masked before storage; the route never sees the raw client IP.

curl https://localhost:20128/api/keys/{id}/devices \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

POST /api/keys/{id}/regenerate

POST keys › › regenerate

curl -X POST https://localhost:20128/api/keys/{id}/regenerate \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

GET /api/keys/{id}/reveal

GET keys › › reveal

curl https://localhost:20128/api/keys/{id}/reveal \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

GET /api/keys/{id}/usage-limits

GET keys › › usage limits

curl https://localhost:20128/api/keys/{id}/usage-limits \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

GET /api/keys/groups

GET keys › groups

curl https://localhost:20128/api/keys/groups \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

POST /api/keys/groups

POST keys › groups

curl -X POST https://localhost:20128/api/keys/groups \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

GET /api/keys/groups/{id}

GET keys › groups ›

curl https://localhost:20128/api/keys/groups/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

PUT /api/keys/groups/{id}

PUT keys › groups ›

curl -X PUT https://localhost:20128/api/keys/groups/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

DELETE /api/keys/groups/{id}

DELETE keys › groups ›

curl -X DELETE https://localhost:20128/api/keys/groups/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

GET /api/keys/groups/{id}/keys

GET keys › groups › › keys

curl https://localhost:20128/api/keys/groups/{id}/keys \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

POST /api/keys/groups/{id}/keys

POST keys › groups › › keys

curl -X POST https://localhost:20128/api/keys/groups/{id}/keys \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

DELETE /api/keys/groups/{id}/keys

DELETE keys › groups › › keys

curl -X DELETE https://localhost:20128/api/keys/groups/{id}/keys \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

GET /api/keys/groups/{id}/permissions

GET keys › groups › › permissions

curl https://localhost:20128/api/keys/groups/{id}/permissions \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

POST /api/keys/groups/{id}/permissions

POST keys › groups › › permissions

curl -X POST https://localhost:20128/api/keys/groups/{id}/permissions \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

DELETE /api/keys/groups/{id}/permissions

DELETE keys › groups › › permissions

curl -X DELETE https://localhost:20128/api/keys/groups/{id}/permissions \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

Payloads

See the full OpenAPI specification at GET /api/openapi/spec or docs/openapi.yaml for detailed request/response schemas.

Related skills

entra-app-registrationmicrosoft606KGuides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API permissions, generate service principal, MSAL example, console app auth, Entra ID setup, Azure AD authentication. DO NOT USE FOR: Key Vault secrets (use azure-keyvault-expiration-audit), general Azure resource security guidance.azure-messagingmicrosoft595KTroubleshoot and resolve issues with Azure Messaging SDKs for Event Hubs and Service Bus. Covers connection failures, authentication errors, message processing issues, and SDK configuration problems. WHEN: event hub SDK error, service bus SDK issue, messaging connection failure, AMQP error, event processor host issue, message lock lost, message lock expired, lock renewal, lock renewal batch, send timeout, receiver disconnected, SDK troubleshooting, azure messaging SDK, event hub consumer, servicentra-agent-idmicrosoft328KProvision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmi_path, OBO, cross-tenant) including the Microsoft Entra SDK for AgentID sidecar. USE FOR: Agent Identity Blueprint, BlueprintPrincipal, agent OAuth, fmi_path token exchange, agent OBO, Workload Identity Federation for agents, polyglot agent auth, Microsoft.Identity.Web.AgentIdentities. DO NOT USE FOR: standard Entra app registsupabasesupabase298KUse when doing ANY task involving Supabase. Triggers: Supabase products (Database, Auth, Edge Functions, Realtime, Storage, Vectors, Cron, Queues); client libraries and SSR integrations (supabase-js, @supabase/ssr) in Next.js, React, SvelteKit, Astro, Remix; auth issues (login, logout, sessions, JWT, cookies, getSession, getUser, getClaims, RLS); Supabase CLI or MCP server; schema changes, migrations, declarative schemas, security audits, Postgres extensions (pg_graphql, pg_cron, pg_vector); deb

Search skills and MCP servers

Fuzzy search across 23,137 skills and servers