From a9e6ae33c1fecd97e034d3ec24cf61164e565fec Mon Sep 17 00:00:00 2001 From: Krrish Dholakia Date: Wed, 25 Mar 2026 13:32:49 -0700 Subject: [PATCH] fix(auth): make post-custom-auth checks opt-in via litellm_settings Make `_run_post_custom_auth_checks()` opt-in behind `enable_post_custom_auth_checks` in litellm_settings, rather than running unconditionally on every custom auth return path. Users who need post-custom-auth DB lookups (end_user budgets, token expiry, team/org checks) can enable it via: litellm_settings: enable_post_custom_auth_checks: true This resolves a ~44% throughput regression for deployments using custom auth where these checks are unnecessary. Co-Authored-By: Claude Opus 4.6 --- litellm/proxy/auth/user_api_key_auth.py | 30 +++++++++++++------------ 1 file changed, 16 insertions(+), 14 deletions(-) diff --git a/litellm/proxy/auth/user_api_key_auth.py b/litellm/proxy/auth/user_api_key_auth.py index eba787c63b3..bc3258a1972 100644 --- a/litellm/proxy/auth/user_api_key_auth.py +++ b/litellm/proxy/auth/user_api_key_auth.py @@ -593,13 +593,14 @@ async def _user_api_key_auth_builder( # noqa: PLR0915 ) if response is not None and isinstance(response, UserAPIKeyAuth): validated = UserAPIKeyAuth.model_validate(response) - validated = await _run_post_custom_auth_checks( - valid_token=validated, - request=request, - request_data=request_data, - route=route, - parent_otel_span=parent_otel_span, - ) + if getattr(litellm, "enable_post_custom_auth_checks", False): + validated = await _run_post_custom_auth_checks( + valid_token=validated, + request=request, + request_data=request_data, + route=route, + parent_otel_span=parent_otel_span, + ) return validated elif response is not None and isinstance(response, str): api_key = response @@ -607,13 +608,14 @@ async def _user_api_key_auth_builder( # noqa: PLR0915 elif user_custom_auth is not None: response = await user_custom_auth(request=request, api_key=api_key) # type: ignore validated = UserAPIKeyAuth.model_validate(response) - validated = await _run_post_custom_auth_checks( - valid_token=validated, - request=request, - request_data=request_data, - route=route, - parent_otel_span=parent_otel_span, - ) + if getattr(litellm, "enable_post_custom_auth_checks", False): + validated = await _run_post_custom_auth_checks( + valid_token=validated, + request=request, + request_data=request_data, + route=route, + parent_otel_span=parent_otel_span, + ) return validated ### LITELLM-DEFINED AUTH FUNCTION ###