Agent skill

OmniRoute Authentication

by diegosouzapw in diegosouzapw/OmniRoute

Documents how OmniRoute authenticates requests: Bearer credentials for the API, management-password login with session cookies, CSRF tokens and optional OIDC for the dashboard.

MITAuto-check passedBackend & APIs

Install OmniRoute Authentication

skills CLI
$ npx skills add diegosouzapw/OmniRoute --skill omni-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install diegosouzapw/OmniRoute omni-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/diegosouzapw/OmniRoute.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/omni-auth .claude/skills/omni-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
omni-auth
GitHub stars
74k
Token cost
~1.8k tokens
SKILL.md length
409 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Documents how OmniRoute authenticates requests: Bearer credentials for the API, management-password login with session cookies, CSRF tokens and optional OIDC for the dashboard.

  • Authenticating requests to the OmniRoute API with a Bearer token
  • SKILL.md covers Overview, Authentication, Endpoints and Payloads, plus 6 more sections
  • Calls curl and jq; needs OMNIROUTE_KEY
  • Logging in to the dashboard and keeping a session cookie in a script

What it does

Remote API requests carry a Bearer credential, while dashboard login is separate: POST /api/auth/login takes a management password and returns an auth_token session cookie. Logout needs a CSRF token fetched from /api/auth/csrf, and /api/auth/status reports the current state. The skill is positioned as the place to start for authenticating against OmniRoute, an OpenAI-compatible gateway reached through an OMNIROUTE_URL setting.

OIDC login for the dashboard admin gate works in two steps. The login route builds an authorization URL from the configured issuer and client, sets a short-lived oidc_state cookie and redirects. The callback validates that cookie, exchanges the code for tokens, verifies the ID token against the issuer's JWKS, optionally checks the subject or email against an allowlist, then issues the same 30-day session token as password login and redirects to the dashboard. Password login stays available as a fallback.

When your agent uses it

  • Authenticating requests to the OmniRoute API with a Bearer token
  • Logging in to the dashboard and keeping a session cookie in a script
  • Setting up OIDC login for the dashboard admin gate
  • Checking login status or fetching a CSRF token before logging out

Example prompts

  • “Log in to my local OmniRoute with the management password and save the session cookie.”
  • “Explain how the OIDC callback validates the ID token and who is allowed in.”
  • “Log out of the OmniRoute dashboard from a script, including the CSRF token step.”

Requirements

  • A running OmniRoute server, with a management password or Bearer key

What it can do on your machine

Read from SKILL.md and the folder at commit 8ad6b1c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OMNIROUTE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

OmniRoute Authentication loads about 1.8k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 409 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from diegosouzapw/OmniRoute at commit 8ad6b1c, republished under its MIT licence (© diegosouzapw). 409 words, ~1,845 tokens.

Download SKILL.mdSave it as .claude/skills/omni-auth/SKILL.md (or your agent's skills folder).
name
omni-auth
description
Manage API key authentication and session tokens. Start here to authenticate requests via Bearer token, obtain session cookies, and configure login requirements for the OmniRoute API.
<!-- generated by src/lib/agentSkills/generator.ts; manual edits will be overwritten -->

Overview

Manage API key authentication and session tokens. Start here to authenticate requests via Bearer token, obtain session cookies, and configure login requirements for the OmniRoute API.

Authentication

Remote API requests use a Bearer credential. Dashboard login is different: POST /api/auth/login accepts a management password and returns an auth_token session cookie.

Endpoints

POST /api/auth/login

Authenticate user

bash
curl -X POST https://localhost:20128/api/auth/login \
  -H "Content-Type: application/json" \
  -c cookie.jar \
  -d '{"password":"<management-password>"}'
POST /api/auth/logout

Log out

bash
CSRF_TOKEN=$(curl -s https://localhost:20128/api/auth/csrf -b cookie.jar | jq -r .token)
curl -X POST https://localhost:20128/api/auth/logout \
  -b cookie.jar \
  -H "x-omniroute-csrf: $CSRF_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'
GET /api/auth/oidc/login

Start OIDC login for the dashboard admin gate

Builds an authorization URL from the configured OIDC issuer/client (discovered via {issuer}/.well-known/openid-configuration, falling back to {issuer}/authorize), sets a short-lived oidc_state cookie, and redirects the browser. Password login remains available as a fallback while OIDC is enabled.

bash
curl https://localhost:20128/api/auth/oidc/login \
  -b cookie.jar
GET /api/auth/oidc/callback

Complete OIDC login for the dashboard admin gate

Validates the state cookie, exchanges the authorization code for tokens, verifies the ID token against the issuer's JWKS (audience = client id), and — if oidcAllowedSubjects is configured — checks the token's sub/email against that allowlist. On success it mints the same 30-day auth_token dashboard-session JWT used by password login and redirects to /dashboard.

bash
curl https://localhost:20128/api/auth/oidc/callback \
  -b cookie.jar
GET /api/auth/csrf

GET auth › csrf

bash
curl https://localhost:20128/api/auth/csrf \
  -b cookie.jar
GET /api/auth/status

GET auth › status

bash
curl https://localhost:20128/api/auth/status \
  -b cookie.jar

Payloads

See the full OpenAPI specification at GET /api/openapi/spec or docs/openapi.yaml for detailed request/response schemas.

<!-- skill:custom-start -->
<!-- Migrated from skills/omniroute/SKILL.md (preserved curated content) -->

OmniRoute

Local/remote AI gateway exposing OpenAI-compatible REST. One key, 327 providers, auto-fallback, RTK token saver, MCP server, A2A agents.

Setup

bash
export OMNIROUTE_URL="http://localhost:20128"      # or VPS / tunnel URL
export OMNIROUTE_KEY="sk-..."                       # from Dashboard → API Keys

All requests: ${OMNIROUTE_URL}/v1/... with Authorization: Bearer ${OMNIROUTE_KEY}.

Verify: curl $OMNIROUTE_URL/api/health → {"ok":true}

Discover models

bash
curl $OMNIROUTE_URL/v1/models                  # chat/LLM (default)
curl $OMNIROUTE_URL/v1/models/image            # image-gen
curl $OMNIROUTE_URL/v1/models/tts              # text-to-speech
curl $OMNIROUTE_URL/v1/models/embedding        # embeddings
curl $OMNIROUTE_URL/v1/models/web              # web search + fetch
curl $OMNIROUTE_URL/v1/models/stt              # speech-to-text

Use data[].id as model field in requests. Combos appear with owned_by:"combo".

Show full SKILL.md (174 more words)Show less

Capability skills

CLI skills (omniroute binary)

Errors

  • 401 → set/refresh OMNIROUTE_KEY (Dashboard → API Keys)
  • 400 Invalid model format → check model exists in /v1/models/<kind>
  • 503 Provider circuit open → upstream provider down; retry after Retry-After seconds
  • 429 → rate limited; honor Retry-After

Differentiators vs OpenAI direct

  • Auto-fallback combos (19 strategies): never stop coding even if a provider rate-limits
  • RTK token saver: tool_result compressed via 47 specialized filters (git-diff, test-jest, terraform-plan, docker-logs…) — 20-40% token reduction
  • Caveman mode: optional terse system prompt injection (LITE/FULL/ULTRA) — 15-25% completion reduction
  • MCP + A2A servers built-in (this is the only AI router that exposes both protocols)
  • Memory with FTS5 + Qdrant for persistent agent context
  • Guardrails for PII masking, prompt injection detection, vision policies
<!-- skill:custom-end -->

© diegosouzapw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/omni-auth of diegosouzapw/OmniRoute.

Open the folder on GitHubat commit 8ad6b1c

Compare with similar skills

OmniRoute Authentication next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

OmniRoute Authentication compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
OmniRoute Authentication this skilldiegosouzapw/OmniRoute74k—~1.8kAutomated safety check: PassMIT
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT
Open Redirect TestingNeoTheCapt/RedteamAgent140—~608Automated safety check: PassNone
Web Ssrfs0ld13rr/pentestcode817—~660Automated safety check: WarnMIT
Secure Authjamditis/claude-skills-journalism416—~14kAutomated safety check: PassMIT
API Security EngineerFerroxLabs/wayland608—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Open Redirect Testing

    NeoTheCapt/RedteamAgent

    Test for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains

    140 GitHub stars~608 tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Web Ssrf

    s0ld13rr/pentestcode

    Server-Side Request Forgery detection→internal-access→proof for web apps.

    817 GitHub stars~660 tokensUpdated 5 days ago
    Backend & APIsAuto-check: warnings
  • Secure Auth

    jamditis/claude-skills-journalism

    Secure authentication patterns (OWASP, NIST). An agent skill from jamditis/claude-skills-journalism.

    416 GitHub stars~14k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • API Security Engineer

    FerroxLabs/wayland

    API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0…

    608 GitHub stars~3.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from diegosouzapw/OmniRoute

All 50 skills in this repo
  • OmniRoute Backup and Sync CLI

    diegosouzapw/OmniRoute

    Backup and restore OmniRoute data from the CLI. Trigger incremental snapshots, sync to cloud storage, manage backup schedules, and restore from archive files.

    74k GitHub stars~948 tokensUpdated today
    Auto-check passed
  • OmniRoute Settings API

    diegosouzapw/OmniRoute

    Read and update global application settings: system prompts, thinking budget, IP filters, payload rules, combo defaults, and require-login configuration.

    74k GitHub starsUsed in 1 repo~3.6k tokens
    Auto-check passed
  • Quality Scan

    diegosouzapw/OmniRoute

    Runs a scoped, read-only quality scan on a repository candidate and reports exact evidence, failures and frozen debt, without treating a static scan as release acceptance.

    74k GitHub stars~748 tokensUpdated today
    Auto-check passed
  • OmniRoute Database Backups

    diegosouzapw/OmniRoute

    Trigger system backups, restore from backup files, and manage the SQLite database lifecycle. Supports export, import, and incremental snapshot strategies.

    74k GitHub starsUsed in 1 repo~395 tokens
    Auto-check passed
  • OmniRoute Provider Management

    diegosouzapw/OmniRoute

    Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.

    74k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • OmniRoute LLM Cache

    diegosouzapw/OmniRoute

    Documents OmniRoute's cache endpoints for reading cache statistics and clearing entries, statistics or the reasoning cache, with notes on TTL and similarity settings.

    74k GitHub starsUsed in 1 repo~529 tokens
    Auto-check passed

Questions about OmniRoute Authentication

What does OmniRoute Authentication do?

Documents how OmniRoute authenticates requests: Bearer credentials for the API, management-password login with session cookies, CSRF tokens and optional OIDC for the dashboard. Remote API requests carry a Bearer credential, while dashboard login is separate: POST /api/auth/login takes a management password and returns an auth_token session cookie. Logout needs a CSRF token fetched from /api/auth/csrf, and /api/auth/status reports the current state.

When should I use OmniRoute Authentication?

OmniRoute Authentication fits situations like: authenticating requests to the OmniRoute API with a Bearer token; logging in to the dashboard and keeping a session cookie in a script; setting up OIDC login for the dashboard admin gate; checking login status or fetching a CSRF token before logging out.

How do I install OmniRoute Authentication in Claude Code?

Run `npx skills add diegosouzapw/OmniRoute --skill omni-auth -a claude-code`. Or copy the skill folder (skills/omni-auth in diegosouzapw/OmniRoute) into .claude/skills/omni-auth in your project. Claude Code loads it when a task matches its description.

How do I install OmniRoute Authentication in Codex?

Run `npx skills add diegosouzapw/OmniRoute --skill omni-auth -a codex`. Or copy the skill folder (skills/omni-auth in diegosouzapw/OmniRoute) into .agents/skills/omni-auth in your project. Codex loads it when a task matches its description.

Can I use OmniRoute Authentication in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add diegosouzapw/OmniRoute --skill omni-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/omni-auth, .gemini/skills/omni-auth, .github/skills/omni-auth and .opencode/skills/omni-auth in your project.

What does OmniRoute Authentication need to run?

Going by SKILL.md and its folder, OmniRoute Authentication needs the command-line tools its instructions call (curl and jq) and credentials named OMNIROUTE_KEY. Our summary lists: A running OmniRoute server, with a management password or Bearer key.

Does OmniRoute Authentication access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is OmniRoute Authentication safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does OmniRoute Authentication use?

OmniRoute Authentication is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does OmniRoute Authentication use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to OmniRoute Authentication?

Skills that share tags, products or a category with OmniRoute Authentication: Security Review (doorkeeper-gem/doorkeeper, 5.5k stars), Open Redirect Testing (NeoTheCapt/RedteamAgent, 140 stars), Web Ssrf (s0ld13rr/pentestcode, 817 stars) and Secure Auth (jamditis/claude-skills-journalism, 416 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains OmniRoute Authentication?

diegosouzapw (a GitHub user) maintains it in diegosouzapw/OmniRoute, which has 73,701 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 6, 2026.

Source: diegosouzapw/OmniRoute on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.