From daeb9292a495665858609cfb3ee32ef8edf7ad44 Mon Sep 17 00:00:00 2001 From: Vigilans Date: Thu, 16 Apr 2026 21:27:15 +0800 Subject: [PATCH] fix(messages): copy metadata dict to prevent raw_request leak to Anthropic API LiteLLM's logging layer injects raw_request into the metadata dict via a shared reference with litellm_params. Without a copy, this extra key reaches the Anthropic API and triggers "Extra inputs are not permitted". PR #24661 fixed the same issue for the chat/completions path by stripping non-user_id keys. Here we use a shallow copy to break the shared reference before the request is sent. --- .../experimental_pass_through/messages/transformation.py | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/litellm/llms/anthropic/experimental_pass_through/messages/transformation.py b/litellm/llms/anthropic/experimental_pass_through/messages/transformation.py index 7617ad52ab1..234312b1aef 100644 --- a/litellm/llms/anthropic/experimental_pass_through/messages/transformation.py +++ b/litellm/llms/anthropic/experimental_pass_through/messages/transformation.py @@ -222,6 +222,12 @@ class AnthropicMessagesConfig(BaseAnthropicMessagesConfig): optional_params=anthropic_messages_optional_request_params, ) + # Break metadata shared reference with litellm_params so that + # pre_call's raw_request injection doesn't leak into the API request. + metadata = anthropic_messages_optional_request_params.get("metadata") + if isinstance(metadata, dict): + anthropic_messages_optional_request_params["metadata"] = dict(metadata) + # Filter out x-anthropic-billing-header from system messages system_param = anthropic_messages_optional_request_params.get("system") if system_param is not None: