From 9082d54e0564dd511949081dff8cb454fb413d03 Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Sat, 7 Mar 2026 11:54:20 -0800 Subject: [PATCH] fix: treat empty-string cache sentinel as a miss in _get_byok_credential The status endpoint writes '' to _byok_cred_cache for connected=True (no actual token needed for status checks). Without this fix, _get_byok_credential would return '' as the credential, causing an empty Bearer header and silent 401s on tool calls after the user just authorized. Treat '' as a cache miss and fall through to the DB to fetch the real token. --- litellm/proxy/_experimental/mcp_server/server.py | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/litellm/proxy/_experimental/mcp_server/server.py b/litellm/proxy/_experimental/mcp_server/server.py index 385128c7f96..433ee330bb8 100644 --- a/litellm/proxy/_experimental/mcp_server/server.py +++ b/litellm/proxy/_experimental/mcp_server/server.py @@ -1580,7 +1580,12 @@ if MCP_AVAILABLE: if cached is not None: credential, ts = cached if time.monotonic() - ts < _BYOK_CRED_CACHE_TTL: - return credential + # Treat "" as a cache miss: the status endpoint may write an + # empty-string sentinel to record "connected=True" without a + # real token value. Fall through to the DB to fetch the actual + # credential rather than returning an empty Bearer header. + if credential is None or credential: + return credential from litellm.proxy._experimental.mcp_server.db import get_user_credential from litellm.proxy.proxy_server import prisma_client