Skip to content

Fix federated-token auth, webhook signatures, phantom endpoints; docs → developer.rhombus.com - #6

Merged
brandon-rhombus merged 1 commit into
mainfrom
devdocs-one-site
Oct 5, 2026
Merged

brandon-rhombus merged 1 commit into
mainfrom
devdocs-one-site

Conversation

@brandon-rhombus

Copy link
Copy Markdown
Contributor

Summary

These skills feed AI-generated customer integrations, and an audit against the live OpenAPI spec and backend found guidance that breaks integrations. Fixes:

  • Federated tokens: there is no federated-session-token scheme. Correct: x-auth-scheme: federated-token + x-auth-ft (header, or query params on media URLs); never in x-auth-apikey; LAN devices accept only federated tokens. ttlSec → durationSec.
  • Webhook signatures: org webhooks x-rhombus-signature-sha1 (HMAC-SHA1, lowercase hex of the raw body), rule actions x-rhombus-signature-sha256; constant-time verification; real payload fields.
  • Phantom endpoints: every /api/... path now exists in the live spec (checker: 106 match, 0 miss; was 39 misses).
  • Rate limits: one per-org token bucket (per-second refill, ~10× burst), not "1,000/hr per key".
  • Console API-key paths, EU base URL, bundled spec refreshed (986 endpoints), docs links → developer.rhombus.com, forum links → support; plugin versions 2.0.0 → 2.0.1.
  • Docs-MCP references (…/mcp) left unchanged until the new site serves /mcp.

🤖 Generated with Claude Code

Docs and contact:
- Developer docs, llms.txt and deep links now use developer.rhombus.com;
  drop the legacy apidocs line and the forum links; contact is
  support@rhombus.com. The docs MCP URL (api-docs.rhombus.community/mcp)
  is unchanged until developer.rhombus.com serves /mcp.

Corrections, checked against the live OpenAPI spec:
- Federated tokens: mint with POST /api/org/generateFederatedSessionToken
  (durationSec, optional deviceUUid/domain), send x-auth-scheme:
  federated-token + x-auth-ft (headers or media-URL query params); never
  in x-auth-apikey; LAN devices accept only federated tokens.
- Webhooks: organization webhooks sign with x-rhombus-signature-sha1 and
  rule webhook actions with x-rhombus-signature-sha256 (lowercase-hex
  HMAC of the raw body, secret as-is). Real org and rule payloads,
  constant-time verification code checked against a test vector.
- Replace endpoints that don't exist (getVodUri, door/unlockDoor,
  developer/*Webhook, lockdown/executePlan, user/getOrgUserList,
  event/createSeekpoint, and others) with the real ones; every /api/
  path in the repo now resolves in the spec. MCP tool table uses the
  real rhombus-node-mcp tool names.
- Rate limits: per-organization token bucket, per-second refill, ~10x
  burst, 429 + Retry-After.
- API keys: Settings > Integrations & Developer Resources > API Tokens >
  Add API Key (partners: Settings > API Management).
- EU base URL https://api2.eu.rhombussystems.com wherever a base URL is
  given.
- EdgeCaster re-streams Rhombus cameras as RTSP (one direction);
  third-party cameras come in through a Rhombus Relay.
- Refresh the bundled OpenAPI spec (986 endpoints) and fix the two spec
  grep recipes that no longer matched its layout.
- Bump rhombus-developer, rhombus-user and rhombus-partner to 2.0.1.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@brandon-rhombus
brandon-rhombus merged commit df49e51 into main Oct 5, 2026
1 check failed
@brandon-rhombus
brandon-rhombus deleted the devdocs-one-site branch October 5, 2026 23:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant