---
name: OmniRoute API Keys
slug: omniroute-api-keys
category: DevOps
description: OmniRoute API Keys creates, lists, rotates, and revokes API keys for OmniRoute proxy and management endpoints, with control over scopes, spending limits, and expiration.
github: "https://github.com/diegosouzapw/OmniRoute/tree/release/v3.8.50/skills/omni-api-keys"
language: TypeScript
stars: 46795
forks: 6310
install: "npx degit https://github.com/diegosouzapw/OmniRoute/tree/release/v3.8.50/skills/omni-api-keys ~/.claude/skills/omni-api-keys"
installs_to: ~/.claude/skills/omni-api-keys
source_path: skills/omni-api-keys/SKILL.md
collection_size: 25
category_size: 798
collection_url: "https://dirskills.com/collections/diegosouzapw/OmniRoute"
added: 2026-08-13T07:36:53.686Z
last_synced: 2026-08-13T07:36:53.686Z
canonical_url: "https://dirskills.com/skills/omniroute-api-keys"
---

# OmniRoute API Keys

OmniRoute API Keys creates, lists, rotates, and revokes API keys for OmniRoute proxy and management endpoints, with control over scopes, spending limits, and expiration.

**Install:**

```bash
npx degit https://github.com/diegosouzapw/OmniRoute/tree/release/v3.8.50/skills/omni-api-keys ~/.claude/skills/omni-api-keys
```

## README

<!-- generated by src/lib/agentSkills/generator.ts; manual edits will be overwritten -->

## Overview

Create, list, rotate, and revoke OmniRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints.

## Authentication

All requests require a valid Bearer token or session cookie. Obtain a token via `POST /api/auth/login` or configure `REQUIRE_API_KEY=false` for local development.

## Endpoints

### GET /api/keys

List API keys

```bash
curl https://localhost:20128/api/keys \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"
```

### POST /api/keys

Create API key

```bash
curl -X POST https://localhost:20128/api/keys \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"
  -H "Content-Type: application/json" \
  -d '{}'
```

### GET /api/keys/{id}

Get API key

```bash
curl https://localhost:20128/api/keys/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"
```

### PATCH /api/keys/{id}

Update API key

```bash
curl -X PATCH https://localhost:20128/api/keys/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"
  -H "Content-Type: application/json" \
  -d '{}'
```

### DELETE /api/keys/{id}

Delete API key

```bash
curl -X DELETE https://localhost:20128/api/keys/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"
```

### GET /api/keys/{id}/devices

List devices for an API key

Lists the distinct devices (masked IP + User-Agent fingerprints) tracked for an API key by the in-memory device tracker. IPs are masked before storage; the route never sees the raw client IP.

```bash
curl https://localhost:20128/api/keys/{id}/devices \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"
```

## Payloads

See the full OpenAPI specification at `GET /api/openapi/spec` or `docs/openapi.yaml` for detailed request/response schemas.
