--- name: omni-api-keys description: Create, list, rotate, and revoke OmniRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints. --- ## Overview Create, list, rotate, and revoke OmniRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints. ## Authentication All requests require a valid Bearer token or session cookie. Obtain a token via `POST /api/auth/login` or configure `REQUIRE_API_KEY=false` for local development. ## Endpoints ### GET /api/keys List API keys ```bash curl https://localhost:20128/api/keys \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" ``` ### POST /api/keys Create API key ```bash curl -X POST https://localhost:20128/api/keys \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" \ -H "Content-Type: application/json" \ -d '{}' ``` ### GET /api/keys/{id} Get API key ```bash curl https://localhost:20128/api/keys/{id} \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" ``` ### PATCH /api/keys/{id} Update API key ```bash curl -X PATCH https://localhost:20128/api/keys/{id} \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" \ -H "Content-Type: application/json" \ -d '{}' ``` ### DELETE /api/keys/{id} Delete API key ```bash curl -X DELETE https://localhost:20128/api/keys/{id} \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" ``` ### GET /api/keys/{id}/devices List devices for an API key Lists the distinct devices (masked IP + User-Agent fingerprints) tracked for an API key by the in-memory device tracker. IPs are masked before storage; the route never sees the raw client IP. ```bash curl https://localhost:20128/api/keys/{id}/devices \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" ``` ### POST /api/keys/{id}/regenerate POST keys › › regenerate ```bash curl -X POST https://localhost:20128/api/keys/{id}/regenerate \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" \ -H "Content-Type: application/json" \ -d '{}' ``` ### GET /api/keys/{id}/reveal GET keys › › reveal ```bash curl https://localhost:20128/api/keys/{id}/reveal \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" ``` ### GET /api/keys/{id}/usage-limits GET keys › › usage limits ```bash curl https://localhost:20128/api/keys/{id}/usage-limits \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" ``` ### GET /api/keys/groups GET keys › groups ```bash curl https://localhost:20128/api/keys/groups \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" ``` ### POST /api/keys/groups POST keys › groups ```bash curl -X POST https://localhost:20128/api/keys/groups \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" \ -H "Content-Type: application/json" \ -d '{}' ``` ### GET /api/keys/groups/{id} GET keys › groups › ```bash curl https://localhost:20128/api/keys/groups/{id} \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" ``` ### PUT /api/keys/groups/{id} PUT keys › groups › ```bash curl -X PUT https://localhost:20128/api/keys/groups/{id} \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" \ -H "Content-Type: application/json" \ -d '{}' ``` ### DELETE /api/keys/groups/{id} DELETE keys › groups › ```bash curl -X DELETE https://localhost:20128/api/keys/groups/{id} \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" ``` ### GET /api/keys/groups/{id}/keys GET keys › groups › › keys ```bash curl https://localhost:20128/api/keys/groups/{id}/keys \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" ``` ### POST /api/keys/groups/{id}/keys POST keys › groups › › keys ```bash curl -X POST https://localhost:20128/api/keys/groups/{id}/keys \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" \ -H "Content-Type: application/json" \ -d '{}' ``` ### DELETE /api/keys/groups/{id}/keys DELETE keys › groups › › keys ```bash curl -X DELETE https://localhost:20128/api/keys/groups/{id}/keys \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" ``` ### GET /api/keys/groups/{id}/permissions GET keys › groups › › permissions ```bash curl https://localhost:20128/api/keys/groups/{id}/permissions \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" ``` ### POST /api/keys/groups/{id}/permissions POST keys › groups › › permissions ```bash curl -X POST https://localhost:20128/api/keys/groups/{id}/permissions \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" \ -H "Content-Type: application/json" \ -d '{}' ``` ### DELETE /api/keys/groups/{id}/permissions DELETE keys › groups › › permissions ```bash curl -X DELETE https://localhost:20128/api/keys/groups/{id}/permissions \ -H "Authorization: Bearer $OMNIROUTE_TOKEN" ``` ## Payloads See the full OpenAPI specification at `GET /api/openapi/spec` or `docs/openapi.yaml` for detailed request/response schemas.