diff --git a/litellm/proxy/_experimental/mcp_server/openapi_oauth2_endpoints.py b/litellm/proxy/_experimental/mcp_server/openapi_oauth2_endpoints.py index ab226fcfac7..d6f0d5b1a4e 100644 --- a/litellm/proxy/_experimental/mcp_server/openapi_oauth2_endpoints.py +++ b/litellm/proxy/_experimental/mcp_server/openapi_oauth2_endpoints.py @@ -175,6 +175,16 @@ async def openapi_oauth2_connect( if master_key is None: raise HTTPException(status_code=500, detail="Master key not configured") + # Fail early if the DB is unavailable: without it the callback cannot store + # the token, so sending the user through the provider consent flow is wasted effort. + from litellm.proxy.proxy_server import prisma_client + + if prisma_client is None: + raise HTTPException( + status_code=503, + detail="Database is not configured. Cannot initiate OAuth2 flow.", + ) + user_id = user_api_key_dict.user_id or user_api_key_dict.api_key or "" if not user_id: raise HTTPException(status_code=400, detail="Cannot determine user identity from token") diff --git a/litellm/proxy/_experimental/mcp_server/server.py b/litellm/proxy/_experimental/mcp_server/server.py index 7301e6b917a..385128c7f96 100644 --- a/litellm/proxy/_experimental/mcp_server/server.py +++ b/litellm/proxy/_experimental/mcp_server/server.py @@ -105,8 +105,8 @@ def _write_byok_cred_cache( ) -> None: """Write a credential value to the cache, evicting the oldest entry if at capacity. - Evicts a single entry (LRU-style) rather than clearing all at once to avoid - a thundering-herd DB spike when the cache fills under load. + Evicts the oldest-inserted entry (FIFO) rather than clearing all at once to + avoid a thundering-herd DB spike when the cache fills under load. """ if len(_byok_cred_cache) >= _BYOK_CRED_CACHE_MAX_SIZE: oldest_key = next(iter(_byok_cred_cache))