fix(auth): make post-custom-auth checks opt-in via litellm_settings

Make `_run_post_custom_auth_checks()` opt-in behind
`enable_post_custom_auth_checks` in litellm_settings, rather than
running unconditionally on every custom auth return path.

Users who need post-custom-auth DB lookups (end_user budgets, token
expiry, team/org checks) can enable it via:

  litellm_settings:
    enable_post_custom_auth_checks: true

This resolves a ~44% throughput regression for deployments using custom
auth where these checks are unnecessary.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Krrish Dholakia 2026-03-25 13:32:49 -07:00
parent 90b850ef8e
commit a9e6ae33c1

View file

@ -593,13 +593,14 @@ async def _user_api_key_auth_builder( # noqa: PLR0915
)
if response is not None and isinstance(response, UserAPIKeyAuth):
validated = UserAPIKeyAuth.model_validate(response)
validated = await _run_post_custom_auth_checks(
valid_token=validated,
request=request,
request_data=request_data,
route=route,
parent_otel_span=parent_otel_span,
)
if getattr(litellm, "enable_post_custom_auth_checks", False):
validated = await _run_post_custom_auth_checks(
valid_token=validated,
request=request,
request_data=request_data,
route=route,
parent_otel_span=parent_otel_span,
)
return validated
elif response is not None and isinstance(response, str):
api_key = response
@ -607,13 +608,14 @@ async def _user_api_key_auth_builder( # noqa: PLR0915
elif user_custom_auth is not None:
response = await user_custom_auth(request=request, api_key=api_key) # type: ignore
validated = UserAPIKeyAuth.model_validate(response)
validated = await _run_post_custom_auth_checks(
valid_token=validated,
request=request,
request_data=request_data,
route=route,
parent_otel_span=parent_otel_span,
)
if getattr(litellm, "enable_post_custom_auth_checks", False):
validated = await _run_post_custom_auth_checks(
valid_token=validated,
request=request,
request_data=request_data,
route=route,
parent_otel_span=parent_otel_span,
)
return validated
### LITELLM-DEFINED AUTH FUNCTION ###