fix: treat empty-string cache sentinel as a miss in _get_byok_credential

The status endpoint writes '' to _byok_cred_cache for connected=True (no
actual token needed for status checks). Without this fix, _get_byok_credential
would return '' as the credential, causing an empty Bearer header and silent
401s on tool calls after the user just authorized.

Treat '' as a cache miss and fall through to the DB to fetch the real token.
This commit is contained in:
Ishaan Jaffer 2026-03-07 11:54:20 -08:00
parent 2b0773d05f
commit 9082d54e05

View file

@ -1580,7 +1580,12 @@ if MCP_AVAILABLE:
if cached is not None:
credential, ts = cached
if time.monotonic() - ts < _BYOK_CRED_CACHE_TTL:
return credential
# Treat "" as a cache miss: the status endpoint may write an
# empty-string sentinel to record "connected=True" without a
# real token value. Fall through to the DB to fetch the actual
# credential rather than returning an empty Bearer header.
if credential is None or credential:
return credential
from litellm.proxy._experimental.mcp_server.db import get_user_credential
from litellm.proxy.proxy_server import prisma_client