| name | omni-api-keys |
| description | Create, list, rotate, and revoke OmniRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints. |
Overview
Create, list, rotate, and revoke OmniRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints.
Authentication
All requests require a valid Bearer token or session cookie. Obtain a token via POST /api/auth/login or configure REQUIRE_API_KEY=false for local development.
Endpoints
GET /api/keys
List API keys
curl https://localhost:20128/api/keys \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
POST /api/keys
Create API key
curl -X POST https://localhost:20128/api/keys \
-H "Authorization: Bearer $OMNIROUTE_TOKEN" \
-H "Content-Type: application/json" \
-d '{}'
GET /api/keys/{id}
Get API key
curl https://localhost:20128/api/keys/{id} \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
PATCH /api/keys/{id}
Update API key
curl -X PATCH https://localhost:20128/api/keys/{id} \
-H "Authorization: Bearer $OMNIROUTE_TOKEN" \
-H "Content-Type: application/json" \
-d '{}'
DELETE /api/keys/{id}
Delete API key
curl -X DELETE https://localhost:20128/api/keys/{id} \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
GET /api/keys/{id}/devices
List devices for an API key
Lists the distinct devices (masked IP + User-Agent fingerprints) tracked for an API key by the in-memory device tracker. IPs are masked before storage; the route never sees the raw client IP.
curl https://localhost:20128/api/keys/{id}/devices \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
POST /api/keys/{id}/regenerate
POST keys › › regenerate
curl -X POST https://localhost:20128/api/keys/{id}/regenerate \
-H "Authorization: Bearer $OMNIROUTE_TOKEN" \
-H "Content-Type: application/json" \
-d '{}'
GET /api/keys/{id}/reveal
GET keys › › reveal
curl https://localhost:20128/api/keys/{id}/reveal \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
GET /api/keys/{id}/usage-limits
GET keys › › usage limits
curl https://localhost:20128/api/keys/{id}/usage-limits \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
GET /api/keys/groups
GET keys › groups
curl https://localhost:20128/api/keys/groups \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
POST /api/keys/groups
POST keys › groups
curl -X POST https://localhost:20128/api/keys/groups \
-H "Authorization: Bearer $OMNIROUTE_TOKEN" \
-H "Content-Type: application/json" \
-d '{}'
GET /api/keys/groups/{id}
GET keys › groups ›
curl https://localhost:20128/api/keys/groups/{id} \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
PUT /api/keys/groups/{id}
PUT keys › groups ›
curl -X PUT https://localhost:20128/api/keys/groups/{id} \
-H "Authorization: Bearer $OMNIROUTE_TOKEN" \
-H "Content-Type: application/json" \
-d '{}'
DELETE /api/keys/groups/{id}
DELETE keys › groups ›
curl -X DELETE https://localhost:20128/api/keys/groups/{id} \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
GET /api/keys/groups/{id}/keys
GET keys › groups › › keys
curl https://localhost:20128/api/keys/groups/{id}/keys \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
POST /api/keys/groups/{id}/keys
POST keys › groups › › keys
curl -X POST https://localhost:20128/api/keys/groups/{id}/keys \
-H "Authorization: Bearer $OMNIROUTE_TOKEN" \
-H "Content-Type: application/json" \
-d '{}'
DELETE /api/keys/groups/{id}/keys
DELETE keys › groups › › keys
curl -X DELETE https://localhost:20128/api/keys/groups/{id}/keys \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
GET /api/keys/groups/{id}/permissions
GET keys › groups › › permissions
curl https://localhost:20128/api/keys/groups/{id}/permissions \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
POST /api/keys/groups/{id}/permissions
POST keys › groups › › permissions
curl -X POST https://localhost:20128/api/keys/groups/{id}/permissions \
-H "Authorization: Bearer $OMNIROUTE_TOKEN" \
-H "Content-Type: application/json" \
-d '{}'
DELETE /api/keys/groups/{id}/permissions
DELETE keys › groups › › permissions
curl -X DELETE https://localhost:20128/api/keys/groups/{id}/permissions \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
Payloads
See the full OpenAPI specification at GET /api/openapi/spec or docs/openapi.yaml for detailed request/response schemas.