The #7786 squash accidentally committed its worktree copy (.claude/worktrees/feat-7786/**, since untracked) and leaked probe tests (repro-8522/probe-9033/repro-8956 — each now green via #9355/#9385/#9354) plus a stray changelog.d/fixes/9159-fix.plan.md describing an UNMERGED fix (would fabricate a changelog entry at release time — removed; #9159's own PR ships its fragment). This restores the PR's actual deliverable at the right paths: the management-auth terminology guide (now with the required MDX frontmatter), its docs test (3/3 green) and its changelog fragment.
1.8 KiB
title, version, lastUpdated
| title | version | lastUpdated |
|---|---|---|
| Management Authentication | 3.8.50 | 2026-08-05 |
Management Authentication
OmniRoute uses four distinct credential families for management access. This guide distinguishes them by purpose, scope, and locality.
| Credential | Scope | Locality | Use Case |
|---|---|---|---|
| Dashboard JWT session | Full management | Localhost | Web dashboard login |
| CLI machine-id token | Full management | Per-machine | omniroute CLI commands |
Scoped oma_ token |
Configurable scope | External | Automation / CI / API access |
| Manage-scope API key | manage scope |
External | Management API calls |
Dashboard JWT Session
Generated on dashboard login (/api/auth/login). Stored in HTTP-only cookie.
Valid for the session duration. Cannot be used from external hosts.
CLI Machine-ID Token
Created by omniroute auth login on first use. Stored in ~/.omniroute/auth.json.
Used by the CLI for all management operations. Tied to the machine identity.
Scoped oma_ Access Token
Created via dashboard or CLI with configurable scopes (e.g., manage, read).
Format: oma_<random-hex>. Used for programmatic access from external systems.
Manage-Scope API Key
Standard API key with the manage scope enabled. Created in dashboard API Keys page.
Used for management API calls from external hosts.
Header Examples
Authorization: Bearer oma_abc123def456
Authorization: Bearer <standard-api-key-with-manage-scope>
Cookie: omniroute_session=<jwt-token>
See docs/reference/API_REFERENCE.md for endpoint-specific auth requirements.