diff --git a/litellm/proxy/agent_endpoints/a2a_endpoints.py b/litellm/proxy/agent_endpoints/a2a_endpoints.py index 5e5e43e2da2..b63afe536e1 100644 --- a/litellm/proxy/agent_endpoints/a2a_endpoints.py +++ b/litellm/proxy/agent_endpoints/a2a_endpoints.py @@ -174,13 +174,16 @@ async def _resolve_backend_auth_header( # Headers the proxy mints itself on the backend call. Forged client copies of -# these must not be forwarded, but any other x-litellm-* header (e.g. an -# admin-allowlisted x-litellm-api-key from extra_headers) is valid passthrough. +# these must not be forwarded (agent-id is minted later in asend_message, where +# agent_extra_headers would otherwise overwrite it), but any other x-litellm-* +# header (e.g. an admin-allowlisted x-litellm-api-key from extra_headers) is +# valid passthrough. _MINTED_A2A_IDENTITY_HEADERS: Final = frozenset( { AGENT_CALLER_USER_ID_HEADER.lower(), AGENT_CALLER_TEAM_ID_HEADER.lower(), "x-litellm-trace-id", + "x-litellm-agent-id", } ) diff --git a/tests/test_litellm/proxy/agent_endpoints/test_a2a_endpoints.py b/tests/test_litellm/proxy/agent_endpoints/test_a2a_endpoints.py index ea1143a1d8e..2690bb88401 100644 --- a/tests/test_litellm/proxy/agent_endpoints/test_a2a_endpoints.py +++ b/tests/test_litellm/proxy/agent_endpoints/test_a2a_endpoints.py @@ -657,6 +657,7 @@ async def test_message_methods_forward_allowlisted_x_litellm_api_key(method: str mock_request.headers = { "x-litellm-api-key": "sk-allowlisted", "x-a2a-test-agent-x-litellm-team-id": "attacker-team", + "x-a2a-test-agent-x-litellm-agent-id": "attacker-agent", } user_api_key_dict = UserAPIKeyAuth(api_key="sk-test", user_id="real-user", team_id="real-team") @@ -670,6 +671,9 @@ async def test_message_methods_forward_allowlisted_x_litellm_api_key(method: str assert forwarded_headers.get("X-LiteLLM-Team-Id") == "real-team", ( "proxy-minted team id must not be overridden by a forged client header" ) + assert "x-litellm-agent-id" not in {k.lower() for k in forwarded_headers}, ( + "forged agent id must be stripped before asend_message mints the real one" + ) @pytest.mark.asyncio