diff --git a/litellm/types/utils.py b/litellm/types/utils.py index d62f00f3676..b61f4bfe96e 100644 --- a/litellm/types/utils.py +++ b/litellm/types/utils.py @@ -3791,6 +3791,7 @@ all_litellm_params = ( "rust", "prompt_label", "shared_session", + "ssl_verify", "search_tool_name", "order", "enable_tag_filtering", diff --git a/tests/test_litellm/test_utils.py b/tests/test_litellm/test_utils.py index e42608c9904..f6ddc9044c2 100644 --- a/tests/test_litellm/test_utils.py +++ b/tests/test_litellm/test_utils.py @@ -5268,6 +5268,19 @@ def test_client_side_timeout_marker_never_reaches_the_provider(): ) +def test_ssl_verify_never_reaches_the_provider_params(): + """SSL transport configuration must stay in litellm_params instead of extra_body.""" + kwargs = {"a_real_provider_specific_param": 1, "ssl_verify": "/tmp/ca.pem"} + + non_default = get_non_default_completion_params(kwargs) + + assert non_default == {"a_real_provider_specific_param": 1}, ( + "ssl_verify leaked into the provider params: " + f"{sorted(set(non_default) - {'a_real_provider_specific_param'})}" + ) + assert "ssl_verify" in all_litellm_params + + class _RecordingDeploymentFailureLogger(CustomLogger): def __init__(self) -> None: super().__init__()