diff --git a/litellm/proxy/_experimental/mcp_server/mcp_server_manager.py b/litellm/proxy/_experimental/mcp_server/mcp_server_manager.py index db2e7de37c3..de058add0c9 100644 --- a/litellm/proxy/_experimental/mcp_server/mcp_server_manager.py +++ b/litellm/proxy/_experimental/mcp_server/mcp_server_manager.py @@ -6045,11 +6045,12 @@ class MCPServerManager: if proxy_logging_obj is None: return hook_result - inbound_authorization: Final = _raw_header_value(raw_headers, "authorization") or "" + normalized_raw: Final = {k.lower(): v for k, v in (raw_headers or {}).items()} + inbound_authorization: Final = normalized_raw.get("authorization", "") incoming_bearer_token: Final = ( inbound_authorization[len("bearer ") :] if inbound_authorization.lower().startswith("bearer ") else None ) - incoming_subject_token: Final = self._caller_sign_in_subject_token(None, raw_headers) + incoming_subject_token: Final = self._caller_sign_in_subject_token(None, normalized_raw) pre_hook_kwargs: Final = { "guardrail_context": guardrail_context, diff --git a/tests/unit/proxy/_experimental/mcp_server/test_mcp_server_manager.py b/tests/unit/proxy/_experimental/mcp_server/test_mcp_server_manager.py index fc16bb17506..86ced491b3f 100644 --- a/tests/unit/proxy/_experimental/mcp_server/test_mcp_server_manager.py +++ b/tests/unit/proxy/_experimental/mcp_server/test_mcp_server_manager.py @@ -6992,6 +6992,20 @@ class TestMCPServerManager: " eyJ.x.y", id="bearer-credential-is-taken-verbatim-after-one-space", ), + pytest.param( + {"authorization": "Bearer sk-request-key", "Authorization": "Bearer eyJ.caller.jws"}, + "sk-request-key", + "eyJ.caller.jws", + "eyJ.caller.jws", + id="responses-bridge-tool-authorization-overrides-the-request-key", + ), + pytest.param( + {"Authorization": "Bearer eyJ.caller.jws", "authorization": "Bearer sk-request-key"}, + "sk-request-key", + "sk-request-key", + None, + id="last-duplicate-case-authorization-wins", + ), ], ) async def test_pre_call_tool_check_separates_raw_bearer_from_subject(