From 4800446b2fe3cae1b9e4e9f22e1e50a539a399ad Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Fri, 1 May 2026 11:24:58 -0700 Subject: [PATCH] fix(mcp): _extract_bearer_token returns None for non-Bearer auth schemes Previously returned the full auth header value (including scheme prefix like 'token abc') when no 'Bearer ' prefix was found, causing that verbatim value to be sent to the IDP as the subject_token. Now returns None, which correctly skips OBO token exchange for non-Bearer callers. --- litellm/proxy/_experimental/mcp_server/mcp_server_manager.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/litellm/proxy/_experimental/mcp_server/mcp_server_manager.py b/litellm/proxy/_experimental/mcp_server/mcp_server_manager.py index 37b7050fceb..bd7d2636848 100644 --- a/litellm/proxy/_experimental/mcp_server/mcp_server_manager.py +++ b/litellm/proxy/_experimental/mcp_server/mcp_server_manager.py @@ -1179,7 +1179,7 @@ class MCPServerManager: auth_value = normalized.get("authorization") if auth_value and auth_value.startswith("Bearer "): return auth_value[len("Bearer "):] - return auth_value + return None def _build_stdio_env( self,