Create, list, rotate, and revoke AIRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints.
Scanned 9/8/2026
Install to Claude Code
npx -y skills add jaccen/AIRoute --skill omni-api-keys --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Omni Api Keys?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/jaccen-omni-api-keys)More formats (shields.io, HTML) on the badges page.
---
name: omni-api-keys
description: Create, list, rotate, and revoke AIRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints.
---
<!-- generated by src/lib/agentSkills/generator.ts; manual edits will be overwritten -->
## Overview
Create, list, rotate, and revoke AIRoute API keys. Control per-key scopes, spending limits, and expiration. Keys gate access to all proxy and management endpoints.
## Authentication
All requests require a valid Bearer token or session cookie. Obtain a token via `POST /api/auth/login` or configure `REQUIRE_API_KEY=false` for local development.
## Endpoints
### GET /api/keys
List API keys
```bash
curl https://localhost:20128/api/keys \
-H "Authorization: Bearer $AIRoute_TOKEN"
```
### POST /api/keys
Create API key
```bash
curl -X POST https://localhost:20128/api/keys \
-H "Authorization: Bearer $AIRoute_TOKEN"
-H "Content-Type: application/json" \
-d '{}'
```
### GET /api/keys/{id}
Get API key
```bash
curl https://localhost:20128/api/keys/{id} \
-H "Authorization: Bearer $AIRoute_TOKEN"
```
### PATCH /api/keys/{id}
Update API key
```bash
curl -X PATCH https://localhost:20128/api/keys/{id} \
-H "Authorization: Bearer $AIRoute_TOKEN"
-H "Content-Type: application/json" \
-d '{}'
```
### DELETE /api/keys/{id}
Delete API key
```bash
curl -X DELETE https://localhost:20128/api/keys/{id} \
-H "Authorization: Bearer $AIRoute_TOKEN"
```
### GET /api/keys/{id}/devices
List devices for an API key
Lists the distinct devices (masked IP + User-Agent fingerprints) tracked for an API key by the in-memory device tracker. IPs are masked before storage; the route never sees the raw client IP.
```bash
curl https://localhost:20128/api/keys/{id}/devices \
-H "Authorization: Bearer $AIRoute_TOKEN"
```
## Payloads
See the full OpenAPI specification at `GET /api/openapi/spec` or `docs/openapi.yaml` for detailed request/response schemas.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!