Manage API key authentication and session tokens. Start here to authenticate requests via Bearer token, obtain session cookies, and configure login requirements for the OmniRoute API.
52
58%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Fix and improve this skill with Tessl
tessl review fix ./skills/omni-auth/SKILL.mdManage API key authentication and session tokens. Start here to authenticate requests via Bearer token, obtain session cookies, and configure login requirements for the OmniRoute API.
All requests require a valid Bearer token or session cookie. Obtain a token via POST /api/auth/login or configure REQUIRE_API_KEY=false for local development.
Authenticate user
curl -X POST https://localhost:20128/api/auth/login \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
-H "Content-Type: application/json" \
-d '{}'Log out
curl -X POST https://localhost:20128/api/auth/logout \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"
-H "Content-Type: application/json" \
-d '{}'Start OIDC login for the dashboard admin gate
Builds an authorization URL from the configured OIDC issuer/client (discovered
via {issuer}/.well-known/openid-configuration, falling back to {issuer}/authorize),
sets a short-lived oidc_state cookie, and redirects the browser. Password login
remains available as a fallback while OIDC is enabled.
curl https://localhost:20128/api/auth/oidc/login \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"Complete OIDC login for the dashboard admin gate
Validates the state cookie, exchanges the authorization code for tokens,
verifies the ID token against the issuer's JWKS (audience = client id), and —
if oidcAllowedSubjects is configured — checks the token's sub/email against
that allowlist. On success it mints the same 30-day auth_token dashboard-session
JWT used by password login and redirects to /dashboard.
curl https://localhost:20128/api/auth/oidc/callback \
-H "Authorization: Bearer $OMNIROUTE_TOKEN"See the full OpenAPI specification at GET /api/openapi/spec or docs/openapi.yaml for detailed request/response schemas.
Local/remote AI gateway exposing OpenAI-compatible REST. One key, 327 providers, auto-fallback, RTK token saver, MCP server, A2A agents.
export OMNIROUTE_URL="http://localhost:20128" # or VPS / tunnel URL
export OMNIROUTE_KEY="sk-..." # from Dashboard → API KeysAll requests: ${OMNIROUTE_URL}/v1/... with Authorization: Bearer ${OMNIROUTE_KEY}.
Verify: curl $OMNIROUTE_URL/api/health → {"ok":true}
curl $OMNIROUTE_URL/v1/models # chat/LLM (default)
curl $OMNIROUTE_URL/v1/models/image # image-gen
curl $OMNIROUTE_URL/v1/models/tts # text-to-speech
curl $OMNIROUTE_URL/v1/models/embedding # embeddings
curl $OMNIROUTE_URL/v1/models/web # web search + fetch
curl $OMNIROUTE_URL/v1/models/stt # speech-to-textUse data[].id as model field in requests. Combos appear with owned_by:"combo".
401 → set/refresh OMNIROUTE_KEY (Dashboard → API Keys)400 Invalid model format → check model exists in /v1/models/<kind>503 Provider circuit open → upstream provider down; retry after Retry-After seconds429 → rate limited; honor Retry-Afterea0cdc5
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.