콘텐츠로 이동
OmniRoute source

Inference Auth Posture

GET /v1/models and the inference endpoints are gated by different settings. The most natural probe an operator runs to answer “is my API protected?” can therefore return the wrong answer.

Endpoint Gated by
GET /v1/models The dashboard login posture — isAuthRequired(), overridable per-instance with requireAuthForModels (src/app/api/v1/models/catalogRequest.ts)
POST /v1/chat/completions, POST /v1/responses, and the other client API routes REQUIRE_API_KEY (src/server/authz/policies/clientApi.ts)

On an instance that has an admin password set and REQUIRE_API_KEY=false, /v1/models answers 401 while inference is open to anyone who can reach the port.

Probing caveat: a 401 from /v1/models does not verify that inference is protected. It only tells you the dashboard requires login.

This is not hypothetical. In discussion #13310 a self-hosted instance behind Traefik had its Codex quota spent by anonymous POST /v1/responses traffic while /v1/models returned 401 — which, in the reporter’s words, “initially created the impression that the entire API was protected” and sent them investigating the wrong component.

Probe an inference route, not the catalog:

터미널 창
curl -s -o /dev/null -w '%{http_code}\n' \
-X POST http://<host>:<api-port>/v1/chat/completions \
-H 'content-type: application/json' \
-d '{"model":"<any-model>","messages":[{"role":"user","content":"ping"}]}'

A 401 means REQUIRE_API_KEY is enforcing. Anything that reaches routing (including a model-not-found error) means anonymous traffic is accepted.

Note that with REQUIRE_API_KEY=false an invalid bearer degrades to anonymous rather than rejecting (#2257), so sending a junk key is not a valid probe either.

When REQUIRE_API_KEY is disabled and a server binds a non-loopback interface, OmniRoute logs a warning at boot (src/lib/startup/nonLoopbackApiKeyGuard.ts). This covers three surfaces:

  • the Dashboard/API server that serves /v1 inference — HOST, default 0.0.0.0
  • the API bridge — API_HOST, default 127.0.0.1
  • the live dashboard WebSocket — its own host

The warning never blocks boot: a reverse proxy in front of OmniRoute may already be enforcing its own authentication.

  • REQUIRE_API_KEY in ENVIRONMENT.md
  • APP_BIND_HOST and the compose loopback defaults (#12568)
  • #2257 — invalid bearer degrades to anonymous when REQUIRE_API_KEY is off
  • #13695 — this document

OmniRoute 소스 코드 (a58000c7685f)

HagiCode

HagiCode는 구조화된 워크플로, 다중 에이전트 실행, Hero Dungeon 뷰를 갖춘 에이전트 코딩 작업 공간입니다.

더 스마트하고 빠르며 즐거운 에이전트 워크플로로 유용한 소프트웨어를 만드세요.

HagiCode 라이트 테마 메인 화면
  • Smart구조화된 워크플로는 의도를 아이디어부터 배포까지 실행 가능한 경로로 바꿉니다.
  • Efficient다중 에이전트 워크플로로 조사, 구현, 검토를 병렬로 진행합니다.
  • FunHero Dungeon은 긴 코딩 세션을 시각적이고 협업적인 경험으로 만듭니다.
HagiCode 방문