Files
OmniRoute/docs/guides/MANAGEMENT-AUTH.md
diegosouzapw 7589c9f71c fix(docs): repair the #7786 squash contamination on release/v3.8.50
The #7786 squash accidentally committed its worktree copy
(.claude/worktrees/feat-7786/**, since untracked) and leaked probe tests
(repro-8522/probe-9033/repro-8956 — each now green via #9355/#9385/#9354)
plus a stray changelog.d/fixes/9159-fix.plan.md describing an UNMERGED fix
(would fabricate a changelog entry at release time — removed; #9159's own
PR ships its fragment).

This restores the PR's actual deliverable at the right paths: the
management-auth terminology guide (now with the required MDX frontmatter),
its docs test (3/3 green) and its changelog fragment.
2026-08-05 16:16:33 -03:00

1.8 KiB

title, version, lastUpdated
title version lastUpdated
Management Authentication 3.8.50 2026-08-05

Management Authentication

OmniRoute uses four distinct credential families for management access. This guide distinguishes them by purpose, scope, and locality.

Credential Scope Locality Use Case
Dashboard JWT session Full management Localhost Web dashboard login
CLI machine-id token Full management Per-machine omniroute CLI commands
Scoped oma_ token Configurable scope External Automation / CI / API access
Manage-scope API key manage scope External Management API calls

Dashboard JWT Session

Generated on dashboard login (/api/auth/login). Stored in HTTP-only cookie. Valid for the session duration. Cannot be used from external hosts.

CLI Machine-ID Token

Created by omniroute auth login on first use. Stored in ~/.omniroute/auth.json. Used by the CLI for all management operations. Tied to the machine identity.

Scoped oma_ Access Token

Created via dashboard or CLI with configurable scopes (e.g., manage, read). Format: oma_<random-hex>. Used for programmatic access from external systems.

Manage-Scope API Key

Standard API key with the manage scope enabled. Created in dashboard API Keys page. Used for management API calls from external hosts.

Header Examples

Authorization: Bearer oma_abc123def456
Authorization: Bearer <standard-api-key-with-manage-scope>
Cookie: omniroute_session=<jwt-token>

See docs/reference/API_REFERENCE.md for endpoint-specific auth requirements.