Back to Omniroute

SKILL

skills/omni-auth/SKILL.md

3.8.496.7 KB
Original Source
<!-- generated by src/lib/agentSkills/generator.ts; manual edits will be overwritten -->

Overview

Manage API key authentication and session tokens. Start here to authenticate requests via Bearer token, obtain session cookies, and configure login requirements for the OmniRoute API.

Authentication

All requests require a valid Bearer token or session cookie. Obtain a token via POST /api/auth/login or configure REQUIRE_API_KEY=false for local development.

Endpoints

POST /api/auth/login

Authenticate user

bash
curl -X POST https://localhost:20128/api/auth/login \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"
  -H "Content-Type: application/json" \
  -d '{}'

POST /api/auth/logout

Log out

bash
curl -X POST https://localhost:20128/api/auth/logout \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"
  -H "Content-Type: application/json" \
  -d '{}'

GET /api/auth/oidc/login

Start OIDC login for the dashboard admin gate

Builds an authorization URL from the configured OIDC issuer/client (discovered via {issuer}/.well-known/openid-configuration, falling back to {issuer}/authorize), sets a short-lived oidc_state cookie, and redirects the browser. Password login remains available as a fallback while OIDC is enabled.

bash
curl https://localhost:20128/api/auth/oidc/login \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

GET /api/auth/oidc/callback

Complete OIDC login for the dashboard admin gate

Validates the state cookie, exchanges the authorization code for tokens, verifies the ID token against the issuer's JWKS (audience = client id), and — if oidcAllowedSubjects is configured — checks the token's sub/email against that allowlist. On success it mints the same 30-day auth_token dashboard-session JWT used by password login and redirects to /dashboard.

bash
curl https://localhost:20128/api/auth/oidc/callback \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

Payloads

See the full OpenAPI specification at GET /api/openapi/spec or docs/openapi.yaml for detailed request/response schemas.

<!-- skill:custom-start --> <!-- Migrated from skills/omniroute/SKILL.md (preserved curated content) -->

OmniRoute

Local/remote AI gateway exposing OpenAI-compatible REST. One key, 327 providers, auto-fallback, RTK token saver, MCP server, A2A agents.

Setup

bash
export OMNIROUTE_URL="http://localhost:20128"      # or VPS / tunnel URL
export OMNIROUTE_KEY="sk-..."                       # from Dashboard → API Keys

All requests: ${OMNIROUTE_URL}/v1/... with Authorization: Bearer ${OMNIROUTE_KEY}.

Verify: curl $OMNIROUTE_URL/api/health{"ok":true}

Discover models

bash
curl $OMNIROUTE_URL/v1/models                  # chat/LLM (default)
curl $OMNIROUTE_URL/v1/models/image            # image-gen
curl $OMNIROUTE_URL/v1/models/tts              # text-to-speech
curl $OMNIROUTE_URL/v1/models/embedding        # embeddings
curl $OMNIROUTE_URL/v1/models/web              # web search + fetch
curl $OMNIROUTE_URL/v1/models/stt              # speech-to-text

Use data[].id as model field in requests. Combos appear with owned_by:"combo".

Capability skills

CapabilityRaw URL
Chat / code-genhttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-chat/SKILL.md
Image generationhttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-image/SKILL.md
Text-to-speechhttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-tts/SKILL.md
Speech-to-texthttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-stt/SKILL.md
Embeddingshttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-embeddings/SKILL.md
Web searchhttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-web-search/SKILL.md
Web fetchhttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-web-fetch/SKILL.md
MCP server (107 tools)https://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omni-mcp/SKILL.md
A2A protocolhttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-a2a/SKILL.md
Routing & comboshttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-routing/SKILL.md
Token compressionhttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-compression/SKILL.md
Monitoring & healthhttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-monitoring/SKILL.md

CLI skills (omniroute binary)

CapabilityRaw URL
CLI entry pointhttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-cli/SKILL.md
CLI admin & lifecyclehttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-cli-admin/SKILL.md
CLI providers & keyshttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-cli-providers/SKILL.md
CLI cloud agentshttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-cli-cloud/SKILL.md
CLI evals & benchmarkshttps://raw.githubusercontent.com/diegosouzapw/OmniRoute/main/skills/omniroute-cli-eval/SKILL.md

Errors

  • 401 → set/refresh OMNIROUTE_KEY (Dashboard → API Keys)
  • 400 Invalid model format → check model exists in /v1/models/<kind>
  • 503 Provider circuit open → upstream provider down; retry after Retry-After seconds
  • 429 → rate limited; honor Retry-After

Differentiators vs OpenAI direct

  • Auto-fallback combos (19 strategies): never stop coding even if a provider rate-limits
  • RTK token saver: tool_result compressed via 47 specialized filters (git-diff, test-jest, terraform-plan, docker-logs…) — 20-40% token reduction
  • Caveman mode: optional terse system prompt injection (LITE/FULL/ULTRA) — 15-25% completion reduction
  • MCP + A2A servers built-in (this is the only AI router that exposes both protocols)
  • Memory with FTS5 + Qdrant for persistent agent context
  • Guardrails for PII masking, prompt injection detection, vision policies
<!-- skill:custom-end -->