diff --git a/litellm/proxy/_experimental/mcp_server/openapi_oauth2_endpoints.py b/litellm/proxy/_experimental/mcp_server/openapi_oauth2_endpoints.py index ea15cc14e1e..d9ca9660aa6 100644 --- a/litellm/proxy/_experimental/mcp_server/openapi_oauth2_endpoints.py +++ b/litellm/proxy/_experimental/mcp_server/openapi_oauth2_endpoints.py @@ -536,7 +536,7 @@ async def openapi_oauth2_callback( # noqa: PLR0915 # token for future renewal without a schema change. credential_to_store = ( json.dumps({"access_token": access_token, "refresh_token": refresh_token}) - if refresh_token + if refresh_token is not None else access_token ) diff --git a/litellm/proxy/_experimental/mcp_server/server.py b/litellm/proxy/_experimental/mcp_server/server.py index 45ca7291123..31373819199 100644 --- a/litellm/proxy/_experimental/mcp_server/server.py +++ b/litellm/proxy/_experimental/mcp_server/server.py @@ -1599,13 +1599,10 @@ if MCP_AVAILABLE: if not user_id: return None - cache_key = (user_id, mcp_server.server_id) - cached = _byok_cred_cache.get(cache_key) - if cached is not None: - credential, ts = cached - if time.monotonic() - ts < _BYOK_CRED_CACHE_TTL: - _byok_cred_cache.move_to_end(cache_key) # promote to MRU - return credential + result = get_cached_byok_credential(user_id, mcp_server.server_id) + if result is not None: + cached_credential, _ = result + return cached_credential from litellm.proxy.proxy_server import prisma_client @@ -1671,29 +1668,26 @@ if MCP_AVAILABLE: ) # Check shared credential cache before hitting the DB. - cache_key = (user_id, mcp_server.server_id) - cached = _byok_cred_cache.get(cache_key) - if cached is not None: - cached_cred, ts = cached - if time.monotonic() - ts < _BYOK_CRED_CACHE_TTL: - _byok_cred_cache.move_to_end(cache_key) # promote to MRU - if cached_cred is None: - raise HTTPException( - status_code=401, - detail={ - "error": "byok_auth_required", - "server_id": mcp_server.server_id, - "server_name": mcp_server.server_name or mcp_server.name, - "message": ( - "No stored credential found for this BYOK server. " - "Complete the OAuth authorization flow to provide your API key." - ), - }, - headers={ - "WWW-Authenticate": 'Bearer resource_metadata="/.well-known/oauth-protected-resource"' - }, - ) - return + cache_result = get_cached_byok_credential(user_id, mcp_server.server_id) + if cache_result is not None: + cached_cred, _ = cache_result + if cached_cred is None: + raise HTTPException( + status_code=401, + detail={ + "error": "byok_auth_required", + "server_id": mcp_server.server_id, + "server_name": mcp_server.server_name or mcp_server.name, + "message": ( + "No stored credential found for this BYOK server. " + "Complete the OAuth authorization flow to provide your API key." + ), + }, + headers={ + "WWW-Authenticate": 'Bearer resource_metadata="/.well-known/oauth-protected-resource"' + }, + ) + return from litellm.proxy.proxy_server import prisma_client diff --git a/ui/litellm-dashboard/src/components/mcp_tools/mcp_server_columns.tsx b/ui/litellm-dashboard/src/components/mcp_tools/mcp_server_columns.tsx index 15a66526d55..4484afddcd2 100644 --- a/ui/litellm-dashboard/src/components/mcp_tools/mcp_server_columns.tsx +++ b/ui/litellm-dashboard/src/components/mcp_tools/mcp_server_columns.tsx @@ -206,7 +206,17 @@ export const mcpServerColumns = ( return —; } if (server.is_byok && server.auth_type === AUTH_TYPE.OAUTH2) { - if (!accessToken || !refreshServers) return null; + if (!accessToken || !refreshServers) { + return ( + + ); + } return (