diff --git a/ui/litellm-dashboard/src/components/model_info_view.tsx b/ui/litellm-dashboard/src/components/model_info_view.tsx index a36f19569ef..afa9bc6331a 100644 --- a/ui/litellm-dashboard/src/components/model_info_view.tsx +++ b/ui/litellm-dashboard/src/components/model_info_view.tsx @@ -355,11 +355,19 @@ export default function ModelInfoView({ await modelPatchUpdateCall(accessToken, updateData, modelId); + // The secrets the user just typed were sent in the request and are now + // stored encrypted by the backend. Don't echo their plaintext into local + // display state — the read-only LiteLLM Params JSON would render it. + const displayLitellmParams = { ...updatedLitellmParams }; + for (const key of Object.keys(authFieldUpdates)) { + delete displayLitellmParams[key]; + } + const updatedModelData = { ...localModelData, model_name: values.model_name, litellm_model_name: values.litellm_model_name, - litellm_params: updatedLitellmParams, + litellm_params: displayLitellmParams, model_info: updatedModelInfo, }; diff --git a/ui/litellm-dashboard/src/components/networking.tsx b/ui/litellm-dashboard/src/components/networking.tsx index 756348f4937..6213bcc5a6c 100644 --- a/ui/litellm-dashboard/src/components/networking.tsx +++ b/ui/litellm-dashboard/src/components/networking.tsx @@ -3738,8 +3738,8 @@ export const modelPatchUpdateCall = async ( modelId: string, ) => { try { - console.log("Form Values in modelUpateCall:", formValues); // Log the form values before making the API call - + // Intentionally not logging the payload: it can contain freshly-entered + // provider secrets (api_key, vertex_credentials, AWS creds). const url = proxyBaseUrl ? `${proxyBaseUrl}/model/${modelId}/update` : `/model/${modelId}/update`; const response = await fetch(url, { method: "PATCH",