diff --git a/litellm/proxy/auth/auth_checks.py b/litellm/proxy/auth/auth_checks.py index 224c936a1d5..b6078d1cc11 100644 --- a/litellm/proxy/auth/auth_checks.py +++ b/litellm/proxy/auth/auth_checks.py @@ -2910,6 +2910,14 @@ async def can_key_call_model( team_id=valid_token.team_id, object_type="key", ) + verbose_proxy_logger.warning( + "Key has access_group_ids=%s, but those access groups resolved to no model permissions. " + "Denying model=%s for key_alias=%s, team_id=%s.", + key_access_group_ids, + model, + valid_token.key_alias, + valid_token.team_id, + ) raise ProxyException( message=f"key not allowed to access model. This key has access_group_ids={key_access_group_ids}, but those groups do not grant any models. Tried to access {model}", type=ProxyErrorTypes.key_model_access_denied, diff --git a/tests/proxy_unit_tests/test_auth_checks.py b/tests/proxy_unit_tests/test_auth_checks.py index d16acf51420..9535fe49ebe 100644 --- a/tests/proxy_unit_tests/test_auth_checks.py +++ b/tests/proxy_unit_tests/test_auth_checks.py @@ -1250,10 +1250,13 @@ async def test_can_key_call_model_denies_when_access_group_ids_resolve_no_models access_group_ids=["empty-group"], ) - with patch( - "litellm.proxy.auth.auth_checks._get_models_from_access_groups", - new_callable=AsyncMock, - return_value=[], + with ( + patch( + "litellm.proxy.auth.auth_checks._get_models_from_access_groups", + new_callable=AsyncMock, + return_value=[], + ), + patch("litellm.proxy.auth.auth_checks.verbose_proxy_logger.warning") as warning, ): with pytest.raises(ProxyException): await can_key_call_model( @@ -1262,6 +1265,8 @@ async def test_can_key_call_model_denies_when_access_group_ids_resolve_no_models valid_token=user_api_key_object, llm_router=None, ) + warning.assert_called_once() + assert "resolved to no model permissions" in warning.call_args.args[0] # ---------------------------------------------------------------------------