omni-api-keys

SkillDev tools

Lets your agent create, rotate, and revoke OmniRoute API keys with scopes, spending limits, and expiration.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the omni-api-keys skill

About this capability

Create, list, rotate, and revoke OmniRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints.

What this skill tells your AI

The instructions your AI receives, as published by diegosouzapw/omniroute in skills/omni-api-keys/SKILL.md and read by ahel’s review.

Overview

Create, list, rotate, and revoke OmniRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints.

Authentication

All requests require a valid Bearer token or session cookie. Obtain a token via POST /api/auth/login or configure REQUIRE_API_KEY=false for local development.

Endpoints

GET /api/keys

List API keys

curl https://localhost:20128/api/keys \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

POST /api/keys

Create API key

curl -X POST https://localhost:20128/api/keys \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

GET /api/keys/{id}

Get API key

curl https://localhost:20128/api/keys/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

PATCH /api/keys/{id}

Update API key

curl -X PATCH https://localhost:20128/api/keys/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

DELETE /api/keys/{id}

Delete API key

curl -X DELETE https://localhost:20128/api/keys/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

GET /api/keys/{id}/devices

List devices for an API key

Lists the distinct devices (masked IP + User-Agent fingerprints) tracked for an API key by the in-memory device tracker. IPs are masked before storage; the route never sees the raw client IP.

curl https://localhost:20128/api/keys/{id}/devices \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

POST /api/keys/{id}/regenerate

POST keys › › regenerate

curl -X POST https://localhost:20128/api/keys/{id}/regenerate \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

GET /api/keys/{id}/reveal

GET keys › › reveal

curl https://localhost:20128/api/keys/{id}/reveal \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

GET /api/keys/{id}/usage-limits

GET keys › › usage limits

curl https://localhost:20128/api/keys/{id}/usage-limits \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

GET /api/keys/groups

GET keys › groups

curl https://localhost:20128/api/keys/groups \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

POST /api/keys/groups

POST keys › groups

curl -X POST https://localhost:20128/api/keys/groups \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

GET /api/keys/groups/{id}

GET keys › groups ›

curl https://localhost:20128/api/keys/groups/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

PUT /api/keys/groups/{id}

PUT keys › groups ›

curl -X PUT https://localhost:20128/api/keys/groups/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

DELETE /api/keys/groups/{id}

DELETE keys › groups ›

curl -X DELETE https://localhost:20128/api/keys/groups/{id} \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

GET /api/keys/groups/{id}/keys

GET keys › groups › › keys

curl https://localhost:20128/api/keys/groups/{id}/keys \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

POST /api/keys/groups/{id}/keys

POST keys › groups › › keys

curl -X POST https://localhost:20128/api/keys/groups/{id}/keys \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

DELETE /api/keys/groups/{id}/keys

DELETE keys › groups › › keys

curl -X DELETE https://localhost:20128/api/keys/groups/{id}/keys \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

GET /api/keys/groups/{id}/permissions

GET keys › groups › › permissions

curl https://localhost:20128/api/keys/groups/{id}/permissions \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

POST /api/keys/groups/{id}/permissions

POST keys › groups › › permissions

curl -X POST https://localhost:20128/api/keys/groups/{id}/permissions \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

DELETE /api/keys/groups/{id}/permissions

DELETE keys › groups › › permissions

curl -X DELETE https://localhost:20128/api/keys/groups/{id}/permissions \
  -H "Authorization: Bearer $OMNIROUTE_TOKEN"

Payloads

See the full OpenAPI specification at GET /api/openapi/spec or docs/openapi.yaml for detailed request/response schemas.

Signals

GitHub stars
64k
Forks
9k
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
omni-api-keys
Source
github.com/diegosouzapw/omniroute