diff --git a/litellm/proxy/auth/auth_checks.py b/litellm/proxy/auth/auth_checks.py index e4e2ceb6621..17b905e4bb7 100644 --- a/litellm/proxy/auth/auth_checks.py +++ b/litellm/proxy/auth/auth_checks.py @@ -2780,7 +2780,12 @@ async def can_team_access_model( object_type="team", ) except ProxyException: - # Fallback: check team's access_group_ids + # Fallback: check team's access_group_ids. + # Note: access groups are a team-level concept and are NOT restricted by + # per-member model overrides. If a team has access_group_ids configured, + # any member can access models from those groups regardless of their + # effective_models set. This is by design — access groups grant team-wide + # access, while default_models/member.models control the team's own model list. team_access_group_ids = ( (team_object.access_group_ids or []) if team_object else [] ) diff --git a/litellm/proxy/management_endpoints/key_management_endpoints.py b/litellm/proxy/management_endpoints/key_management_endpoints.py index 69e7c7c27d5..c3b957d14a2 100644 --- a/litellm/proxy/management_endpoints/key_management_endpoints.py +++ b/litellm/proxy/management_endpoints/key_management_endpoints.py @@ -638,15 +638,17 @@ async def _common_key_generation_helper( # noqa: PLR0915 data_json = data.model_dump(exclude_unset=True, exclude_none=True) # type: ignore - # [TEAM MODEL OVERRIDES] Handle effective team models for the key + # [TEAM MODEL OVERRIDES] Handle effective team models for the key. + # Only applies when a user_id is specified — service/bot keys (no user_id) use + # the full team.models pool, preserving pre-feature behavior. if ( litellm.team_model_overrides_enabled or os.getenv("TEAM_MODEL_OVERRIDES", "").lower() == "true" - ) and team_table is not None: + ) and team_table is not None and data.user_id: # Read member models from LiteLLM_TeamMembership via the standard cached helper # (NOT from members_with_roles JSON blob which can be stale after /team/member_update). member_models: List[str] = [] - if data.user_id and prisma_client is not None: + if prisma_client is not None: from litellm.proxy.proxy_server import user_api_key_cache _membership = await get_team_membership(