diff --git a/litellm/proxy/management_endpoints/ui_sso.py b/litellm/proxy/management_endpoints/ui_sso.py index 613508da22b..7a5f9bcf610 100644 --- a/litellm/proxy/management_endpoints/ui_sso.py +++ b/litellm/proxy/management_endpoints/ui_sso.py @@ -48,6 +48,7 @@ from litellm._logging import verbose_proxy_logger from litellm._uuid import uuid from litellm.caching.dual_cache import DualCache from litellm.constants import ( + CLI_JWT_EXPIRATION_HOURS, CLI_SSO_CLAIM_MAP, CLI_SSO_CLAIM_MAX_SCALAR_LENGTH, CLI_SSO_SESSION_CACHE_KEY_PREFIX, @@ -2514,6 +2515,7 @@ async def cli_poll_key( poll_response = { "status": "ready", "key": jwt_token, + "expires_in": CLI_JWT_EXPIRATION_HOURS * 3600, "user_id": user_id, "team_id": team_id, "teams": user_teams, diff --git a/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py b/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py index e648bd09734..99b1e663a07 100644 --- a/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py +++ b/tests/test_litellm/proxy/management_endpoints/test_ui_sso.py @@ -12,6 +12,7 @@ from litellm._uuid import uuid import litellm +from litellm.constants import CLI_JWT_EXPIRATION_HOURS from litellm.proxy._types import LiteLLM_UserTable, NewUserResponse from litellm.proxy.auth.handle_jwt import JWTHandler from litellm.proxy.management_endpoints.sso import CustomMicrosoftSSO @@ -3540,6 +3541,7 @@ class TestCLIKeyRegenerationFlow: assert result["user_id"] == "test-user-789" assert result["team_id"] == selected_team assert result["teams"] == ["team-a", "team-b", "team-c"] + assert result["expires_in"] == CLI_JWT_EXPIRATION_HOURS * 3600 # Verify JWT was generated with correct team and no budget cap # (team lookup failed, but team_id is set, so fallback cap must not apply)