From 41407f7be1dd86054598be3a57bdc292279abcf1 Mon Sep 17 00:00:00 2001 From: Krish Dholakia Date: Thu, 30 Jan 2025 22:17:00 -0800 Subject: [PATCH] Doc updates - add key rotations to docs (#8136) * docs(virtual_keys.md): add key rotations to virtual keys doc * docs(enterprise.md): add key rotations to enterprise docs --- docs/my-website/docs/proxy/custom_auth.md | 48 ++++++++++++ docs/my-website/docs/proxy/enterprise.md | 1 + docs/my-website/docs/proxy/virtual_keys.md | 89 ++++++++++------------ docs/my-website/sidebars.js | 1 + 4 files changed, 90 insertions(+), 49 deletions(-) create mode 100644 docs/my-website/docs/proxy/custom_auth.md diff --git a/docs/my-website/docs/proxy/custom_auth.md b/docs/my-website/docs/proxy/custom_auth.md new file mode 100644 index 00000000000..c98ad8e09d8 --- /dev/null +++ b/docs/my-website/docs/proxy/custom_auth.md @@ -0,0 +1,48 @@ +# Custom Auth + +You can now override the default api key auth. + +Here's how: + +#### 1. Create a custom auth file. + +Make sure the response type follows the `UserAPIKeyAuth` pydantic object. This is used by for logging usage specific to that user key. + +```python +from litellm.proxy._types import UserAPIKeyAuth + +async def user_api_key_auth(request: Request, api_key: str) -> UserAPIKeyAuth: + try: + modified_master_key = "sk-my-master-key" + if api_key == modified_master_key: + return UserAPIKeyAuth(api_key=api_key) + raise Exception + except: + raise Exception +``` + +#### 2. Pass the filepath (relative to the config.yaml) + +Pass the filepath to the config.yaml + +e.g. if they're both in the same dir - `./config.yaml` and `./custom_auth.py`, this is what it looks like: +```yaml +model_list: + - model_name: "openai-model" + litellm_params: + model: "gpt-3.5-turbo" + +litellm_settings: + drop_params: True + set_verbose: True + +general_settings: + custom_auth: custom_auth.user_api_key_auth +``` + +[**Implementation Code**](https://github.com/BerriAI/litellm/blob/caf2a6b279ddbe89ebd1d8f4499f65715d684851/litellm/proxy/utils.py#L122) + +#### 3. Start the proxy +```shell +$ litellm --config /path/to/config.yaml +``` diff --git a/docs/my-website/docs/proxy/enterprise.md b/docs/my-website/docs/proxy/enterprise.md index f2211aa0350..a5988cab8e8 100644 --- a/docs/my-website/docs/proxy/enterprise.md +++ b/docs/my-website/docs/proxy/enterprise.md @@ -24,6 +24,7 @@ Features: - ✅ [Use LiteLLM keys/authentication on Pass Through Endpoints](pass_through#✨-enterprise---use-litellm-keysauthentication-on-pass-through-endpoints) - ✅ [Set Max Request Size / File Size on Requests](#set-max-request--response-size-on-litellm-proxy) - ✅ [Enforce Required Params for LLM Requests (ex. Reject requests missing ["metadata"]["generation_name"])](#enforce-required-params-for-llm-requests) + - ✅ [Key Rotations](./virtual_keys.md#-key-rotations) - **Customize Logging, Guardrails, Caching per project** - ✅ [Team Based Logging](./team_logging.md) - Allow each team to use their own Langfuse Project / custom callbacks - ✅ [Disable Logging for a Team](./team_logging.md#disable-logging-for-a-team) - Switch off all logging for a team/project (GDPR Compliance) diff --git a/docs/my-website/docs/proxy/virtual_keys.md b/docs/my-website/docs/proxy/virtual_keys.md index 254b50bca30..183beee4a63 100644 --- a/docs/my-website/docs/proxy/virtual_keys.md +++ b/docs/my-website/docs/proxy/virtual_keys.md @@ -393,55 +393,6 @@ curl -L -X POST 'http://0.0.0.0:4000/key/unblock' \ ``` -### Custom Auth - -You can now override the default api key auth. - -Here's how: - -#### 1. Create a custom auth file. - -Make sure the response type follows the `UserAPIKeyAuth` pydantic object. This is used by for logging usage specific to that user key. - -```python -from litellm.proxy._types import UserAPIKeyAuth - -async def user_api_key_auth(request: Request, api_key: str) -> UserAPIKeyAuth: - try: - modified_master_key = "sk-my-master-key" - if api_key == modified_master_key: - return UserAPIKeyAuth(api_key=api_key) - raise Exception - except: - raise Exception -``` - -#### 2. Pass the filepath (relative to the config.yaml) - -Pass the filepath to the config.yaml - -e.g. if they're both in the same dir - `./config.yaml` and `./custom_auth.py`, this is what it looks like: -```yaml -model_list: - - model_name: "openai-model" - litellm_params: - model: "gpt-3.5-turbo" - -litellm_settings: - drop_params: True - set_verbose: True - -general_settings: - custom_auth: custom_auth.user_api_key_auth -``` - -[**Implementation Code**](https://github.com/BerriAI/litellm/blob/caf2a6b279ddbe89ebd1d8f4499f65715d684851/litellm/proxy/utils.py#L122) - -#### 3. Start the proxy -```shell -$ litellm --config /path/to/config.yaml -``` - ### Custom /key/generate If you need to add custom logic before generating a Proxy API Key (Example Validating `team_id`) @@ -568,6 +519,46 @@ litellm_settings: team_id: "core-infra" ``` +### ✨ Key Rotations + +:::info + +This is an Enterprise feature. + +[Enterprise Pricing](https://www.litellm.ai/#pricing) + +[Get free 7-day trial key](https://www.litellm.ai/#trial) + + +::: + +Rotate an existing API Key, while optionally updating its parameters. + +```bash + +curl 'http://localhost:4000/key/sk-1234/regenerate' \ + -X POST \ + -H 'Authorization: Bearer sk-1234' \ + -H 'Content-Type: application/json' \ + -d '{ + "max_budget": 100, + "metadata": { + "team": "core-infra" + }, + "models": [ + "gpt-4", + "gpt-3.5-turbo" + ] + }' + +``` + +**Read More** + +- [Write rotated keys to secrets manager](https://docs.litellm.ai/docs/secret#aws-secret-manager) + +[**👉 API REFERENCE DOCS**](https://litellm-api.up.railway.app/#/key%20management/regenerate_key_fn_key__key__regenerate_post) + ### Restricting Key Generation Use this to control who can generate keys. Useful when letting others create keys on the UI. diff --git a/docs/my-website/sidebars.js b/docs/my-website/sidebars.js index b4c9b13b310..cda84067ba0 100644 --- a/docs/my-website/sidebars.js +++ b/docs/my-website/sidebars.js @@ -77,6 +77,7 @@ const sidebars = { "proxy/token_auth", "proxy/service_accounts", "proxy/access_control", + "proxy/custom_auth", "proxy/ip_address", "proxy/email", "proxy/multiple_admins",