From 2f24a7ebf233c0dac4a40edd696afaf6febe60db Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Wed, 4 Mar 2026 21:09:31 -0800 Subject: [PATCH] fix: address greptile review feedback (greploop iteration 4) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Unified credential cache: store actual credential value (Optional[str]) instead of just bool so _get_byok_credential also benefits from caching — eliminates the DB hit on every BYOK tool call within the 60s TTL window - Extracted _write_byok_cred_cache() helper for consistent cache writes - Replaced has_user_credential with get_user_credential in _check_byok_credential so one DB call satisfies both existence check and value retrieval - Remove false 'encrypted at rest' claim from OAuth HTML and ByokCredentialModal --- .../mcp_server/byok_oauth_endpoints.py | 2 +- .../proxy/_experimental/mcp_server/server.py | 55 +++++++++++++------ .../mcp_tools/ByokCredentialModal.tsx | 2 +- 3 files changed, 41 insertions(+), 18 deletions(-) diff --git a/litellm/proxy/_experimental/mcp_server/byok_oauth_endpoints.py b/litellm/proxy/_experimental/mcp_server/byok_oauth_endpoints.py index b4d3157b17e..db18885721a 100644 --- a/litellm/proxy/_experimental/mcp_server/byok_oauth_endpoints.py +++ b/litellm/proxy/_experimental/mcp_server/byok_oauth_endpoints.py @@ -480,7 +480,7 @@ def _build_authorize_html( -

Your key is encrypted at rest and transmitted securely. It is never shared with third parties.

+

Your key is stored securely and transmitted over HTTPS. It is never shared with third parties.