Files
OmniRoute/docs
diegosouzapw 78c4ef33ee feat(cli): remote mode — drive a remote OmniRoute with scoped access tokens
`omniroute connect <host>` logs in (management password → scoped access token,
or paste one with --key) and saves it as the active context, so every CLI
command then targets that remote server. One CLI, local or remote.

Access tokens (oma_):
- new cli_access_tokens table + src/lib/db/accessTokens.ts (sha-256 hashed,
  plaintext shown once, prefix, revoke by id/prefix, expiry, last_used)
- 3-level scopes read ⊂ write ⊂ admin (src/lib/accessTokens/scopes.ts)

Enforcement:
- shared evaluateAccessTokenAuth used by BOTH the central managementPolicy
  (proxy.ts gate) and requireManagementAuth — no drift
- required scope inferred from HTTP method + admin allowlist (accessScopes.ts)
- loopback-only routes stay unreachable by remote tokens (hard rules #15/#17)

Endpoints: POST /api/cli/connect (public, password+lockout), GET /api/cli/whoami,
GET/POST /api/cli/tokens, DELETE /api/cli/tokens/:id.

CLI: connect, tokens create/list/revoke/scopes, configure <cli> (interactive
provider+model → local profile from the remote catalog); unified context
resolution now reads baseUrl AND accessToken from the active context.

Dashboard: Settings → Access Tokens (create / copy-once / revoke).
Docs: docs/guides/REMOTE-MODE.md, README section + index, openapi entries.
Tests: 63 unit/integration (scopes, token store, inference, auth gate, helpers).
2026-06-19 02:31:33 -03:00
..
2026-06-16 01:00:40 -03:00
2026-06-17 19:26:32 -03:00
2026-05-23 01:46:59 -03:00
2026-06-16 01:00:40 -03:00
2026-05-23 01:46:59 -03:00
2026-06-09 15:56:24 -03:00
2026-06-17 19:26:32 -03:00
2026-05-23 01:46:59 -03:00
2026-06-11 04:01:24 -03:00
2026-06-16 01:00:40 -03:00
2026-06-17 19:26:32 -03:00
2026-06-16 01:00:40 -03:00
2026-06-13 17:27:40 -03:00

title, version, lastUpdated
title version lastUpdated
OmniRoute Documentation 3.8.24 2026-06-13

OmniRoute Documentation

Navigable index of the OmniRoute documentation set. Topics are grouped by intent so you can find what you need quickly.

Looking for the project overview, install steps, or release notes? See the root README.md, CHANGELOG.md, and CONTRIBUTING.md.


architecture/

How the system is put together — read these to understand the runtime, code layout, and resilience model.

For Non-Tech Users

Simple guides for using OmniRoute — no technical background needed.

getting-started/

guides/

For Tech Users

Technical documentation for developers and contributors.

reference/

Lookup material — API surface, environment variables, CLI flags, provider catalog.

frameworks/

Pluggable subsystems exposed to clients, agents, and operators.

routing/

Combo routing, scoring, and replay.

security/

Guardrails, compliance, stealth, and the mandatory patterns for handling public credentials and error messages.

  • GUARDRAILS.md — PII, prompt injection, vision guardrails.
  • COMPLIANCE.md — audit trails and compliance.
  • STEALTH_GUIDE.md — TLS / fingerprint stealth.
  • PUBLIC_CREDS.mdmandatory pattern for embedding public upstream OAuth client_id/secret + Firebase Web keys without tripping secret scanners.
  • ERROR_SANITIZATION.mdmandatory pattern for routing every error response through sanitizeErrorMessage to prevent stack-trace exposure.

compression/

Prompt compression engines, rules, and language packs.

ops/

Release, deployment, proxies, tunnels, coverage.

diagrams/

Mermaid sources and exported SVG/PNG diagrams referenced from the docs above. Populated incrementally — see diagrams/README.md.

i18n/

Translated mirrors of the documentation in 42 locales. See i18n/README.md for the supported language list.

screenshots/

Static screenshots used by the dashboard and the README. Not part of the doc body.


Auto-generated artifacts

  • reference/PROVIDER_REFERENCE.md is generated by scripts/docs/gen-provider-reference.ts from src/shared/constants/providers.ts. Do not edit by hand.
  • The /docs UI is backed by Fumadocs MDX source generation from the subfolders above.