From 9b87bdf1765d827f3a7fce476f88254923a5e52f Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Fri, 6 Mar 2026 14:17:51 -0800 Subject: [PATCH] use HTTP 401 for PKCE missing config errors GENERIC_CLIENT_ID and GENERIC_TOKEN_ENDPOINT missing when PKCE is enabled are auth-flow failures, not server errors. Use 401 instead of 500 to avoid triggering false-positive server error alerts in monitoring systems. --- litellm/proxy/management_endpoints/ui_sso.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/litellm/proxy/management_endpoints/ui_sso.py b/litellm/proxy/management_endpoints/ui_sso.py index 998e14d2c4d..b17a29d0e9a 100644 --- a/litellm/proxy/management_endpoints/ui_sso.py +++ b/litellm/proxy/management_endpoints/ui_sso.py @@ -813,14 +813,14 @@ async def get_generic_sso_response( message="GENERIC_CLIENT_ID must be set when PKCE is enabled", type=ProxyErrorTypes.auth_error, param="GENERIC_CLIENT_ID", - code=status.HTTP_500_INTERNAL_SERVER_ERROR, + code=status.HTTP_401_UNAUTHORIZED, ) if not generic_token_endpoint: raise ProxyException( message="GENERIC_TOKEN_ENDPOINT must be set when PKCE is enabled", type=ProxyErrorTypes.auth_error, param="GENERIC_TOKEN_ENDPOINT", - code=status.HTTP_500_INTERNAL_SERVER_ERROR, + code=status.HTTP_401_UNAUTHORIZED, ) # All guards above raise, so authorization_code is a non-empty str here. # Use an explicit type guard rather than assert (assert is a no-op with -O).