Hi - I answer from the OpenSmartRoute documentation: routing, the API, plans and quotas, self-hosting. Ask away, or open a support ticket if you need a person.
Grounded in the docs - follow a source before acting on it.
Instruction file imported from startmeupai/swe-agents (.github/instructions/security-rbac.instructions.md). Copyright stays with the author.
Security and RBAC Rules
Authenticate before resource lookup and authorize against tenant/project scope.
Re-authorize mutations at apply time.
Never trust client, tool, or model-supplied identifiers without scope checks.
Keep resource-scoped roles from granting unintended global privilege.
Verify role persistence, the explicitly approved administrative policy, scoped member lists,
and negative access behavior at runtime.
Redact secrets and personal information from logs and errors.
Use it
Copy one of these into your project. Installing also returns the manifest and these snippets.
# after Install: the listing is in your workspace's routing pool - a plan picks it for its slot
curl -s -X POST https://api.opensmartroute.ai/api/v1/route -H 'Authorization: Bearer $OSR_API_KEY' -H 'Content-Type: application/json' -d '{"text": "...", "plan": true}'
Manifest
An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.