Repository navigation
Fix federated-token auth, webhook signatures, phantom endpoints; docs → developer.rhombus.com - #6
Merged
Merged
Conversation
Docs and contact: - Developer docs, llms.txt and deep links now use developer.rhombus.com; drop the legacy apidocs line and the forum links; contact is support@rhombus.com. The docs MCP URL (api-docs.rhombus.community/mcp) is unchanged until developer.rhombus.com serves /mcp. Corrections, checked against the live OpenAPI spec: - Federated tokens: mint with POST /api/org/generateFederatedSessionToken (durationSec, optional deviceUUid/domain), send x-auth-scheme: federated-token + x-auth-ft (headers or media-URL query params); never in x-auth-apikey; LAN devices accept only federated tokens. - Webhooks: organization webhooks sign with x-rhombus-signature-sha1 and rule webhook actions with x-rhombus-signature-sha256 (lowercase-hex HMAC of the raw body, secret as-is). Real org and rule payloads, constant-time verification code checked against a test vector. - Replace endpoints that don't exist (getVodUri, door/unlockDoor, developer/*Webhook, lockdown/executePlan, user/getOrgUserList, event/createSeekpoint, and others) with the real ones; every /api/ path in the repo now resolves in the spec. MCP tool table uses the real rhombus-node-mcp tool names. - Rate limits: per-organization token bucket, per-second refill, ~10x burst, 429 + Retry-After. - API keys: Settings > Integrations & Developer Resources > API Tokens > Add API Key (partners: Settings > API Management). - EU base URL https://api2.eu.rhombussystems.com wherever a base URL is given. - EdgeCaster re-streams Rhombus cameras as RTSP (one direction); third-party cameras come in through a Rhombus Relay. - Refresh the bundled OpenAPI spec (986 endpoints) and fix the two spec grep recipes that no longer matched its layout. - Bump rhombus-developer, rhombus-user and rhombus-partner to 2.0.1. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
These skills feed AI-generated customer integrations, and an audit against the live OpenAPI spec and backend found guidance that breaks integrations. Fixes:
federated-session-tokenscheme. Correct:x-auth-scheme: federated-token+x-auth-ft(header, or query params on media URLs); never inx-auth-apikey; LAN devices accept only federated tokens.ttlSec→durationSec.x-rhombus-signature-sha1(HMAC-SHA1, lowercase hex of the raw body), rule actionsx-rhombus-signature-sha256; constant-time verification; real payload fields./api/...path now exists in the live spec (checker: 106 match, 0 miss; was 39 misses).…/mcp) left unchanged until the new site serves/mcp.🤖 Generated with Claude Code