Skip to content
Back to skills

Omni Api Keys

ASecurity

Create, list, rotate, and revoke OmniRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints.

  • 72,229 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added August 31, 2026
ai-agentsbashapi

Works with

  • cli
  • api

Security analysis

A96/100
  • mediumUses curl or wget to download content

Pro shows the line behind each finding and how to fix it

Scanned August 31, 2026

npx -y skills add diegosouzapw/OmniRoute --skill omni-api-keys --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Omni Api Keys?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Omni Api Keys
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/diegosouzapw-omni-api-keys/badge)](https://www.skillsdirectory.com/skills/diegosouzapw-omni-api-keys)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: omni-api-keys
description: Create, list, rotate, and revoke OmniRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints.
---
<!-- generated by src/lib/agentSkills/generator.ts; manual edits will be overwritten -->

## Overview

Create, list, rotate, and revoke OmniRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints.

## Authentication

All requests require a valid Bearer token or session cookie. Obtain a token via `POST /api/auth/login` or configure `REQUIRE_API_KEY=false` for local development.

## Endpoints

### GET /api/keys

List API keys

```bash
curl https://localhost:20128/api/keys \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"
```

### POST /api/keys

Create API key

```bash
curl -X POST https://localhost:20128/api/keys \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'
```

### GET /api/keys/{id}

Get API key

```bash
curl https://localhost:20128/api/keys/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"
```

### PATCH /api/keys/{id}

Update API key

```bash
curl -X PATCH https://localhost:20128/api/keys/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'
```

### DELETE /api/keys/{id}

Delete API key

```bash
curl -X DELETE https://localhost:20128/api/keys/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"
```

### GET /api/keys/{id}/devices

List devices for an API key

Lists the distinct devices (masked IP + User-Agent fingerprints) tracked for an API key by the in-memory device tracker. IPs are masked before storage; the route never sees the raw client IP.

```bash
curl https://localhost:20128/api/keys/{id}/devices \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"
```

## Payloads

See the full OpenAPI specification at `GET /api/openapi/spec` or `docs/openapi.yaml` for detailed request/response schemas.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…