Joshua Valluru
4fda0092d3
fix(mcp): explain missing public client dependencies
2026-09-19 19:52:13 -07:00
joshua-berri
8df260a13d
Merge pull request #42051 from BerriAI/litellm_mcp_oauth_e2e_3467_rework
...
test(e2e): restore MCP OAuth happy-path coverage (LIT-3467)
2026-09-20 02:50:14 +00:00
Joshua Valluru
124196cbaa
fix(auth): preserve scope-admin email policy during status lookup
2026-09-19 19:48:53 -07:00
mateo
fdd91a347a
test: drop narration comment from telemetry flag test
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 02:44:52 +00:00
Mateo Wang
b4447096e4
Merge pull request #42067 from BerriAI/litellm_genai_adapter_response_schema_tool_params
...
fix(google_genai): forward response schema and tool parameters through the generateContent adapter
2026-09-19 19:43:32 -07:00
kerry-berri
a8790db419
Merge pull request #42077 from BerriAI/litellm-providers/price-sync-openrouter
...
chore(prices): sync OpenRouter prices: 2 models
2026-09-19 19:42:00 -07:00
Mateo Wang
79e25d1e96
Merge pull request #42045 from BerriAI/litellm_lit_8201_notfound_retry_policy
...
fix(router): add NotFoundErrorRetries so a retry policy can pin 404 retries
2026-09-19 19:37:45 -07:00
mateo
8e530cf819
fix: keep --telemetry as a hidden no-op so existing start commands still parse
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 02:36:59 +00:00
Joshua Valluru
6ea74d70f1
fix(auth): enforce SCIM status for admin JWTs and refresh SCIM caches
2026-09-19 19:33:47 -07:00
berriai-litellm-provider-info-sync[bot]
344ce9328b
chore(prices): sync OpenRouter prices: 2 models
...
openrouter/~deepseek/deepseek-pro-latest: max_tokens, max_output_tokens, input_cost_per_token, output_cost_per_token, cache_read_input_token_cost
openrouter/deepseek/deepseek-v4-pro-0813: max_tokens, max_output_tokens, off_peak_pricing, input_cost_per_token, output_cost_per_token, cache_read_input_token_cost
2026-09-20 02:30:52 +00:00
mateo-berri
a3e9ed34fe
fix(mcp): gate the pre-call listing per tool, not per server
...
A tools/call on a cold worker listed the target server once and then never
again, so a later caller whose credentials expose a wider upstream catalog
got 404 for tools the first caller never had. Gate the pre-call listing on
whether this worker already exposes the requested tool, so callers with
different catalogs no longer mask each other. Removing the per-server guard
also drops the empty-listing case that re-listed on every call.
2026-09-19 19:29:33 -07:00
yuneng-jiang
09e14a485c
Merge pull request #42061 from BerriAI/litellm_fix_gcs_pub_sub_autorouter_golden
...
test(logging): add autorouter estimate keys to the GCS pub/sub spend-log golden
2026-09-19 19:22:41 -07:00
mateo-berri
5eb967d925
fix(google_genai): drop non-object tool parameters instead of forwarding them
2026-09-19 19:19:33 -07:00
Mateo Wang
5417abd586
Merge pull request #42011 from BerriAI/litellm_scrub_default_master_key
...
docs: stop advertising sk-1234 as the master key in shipped configs and examples
2026-09-19 19:05:31 -07:00
Mateo Wang
b6dd3d932c
Merge pull request #42019 from BerriAI/litellm_master_key_boot_enforcement
...
feat(proxy)!: refuse to start with an unset, empty, or publicly known master key
2026-09-19 19:04:02 -07:00
mateo-berri
325d17aca9
fix(litellm): keep a function tool without a body on the chat route
...
A tools entry of only {"type": "function"} has nothing for the Responses
bridge to convert, and the bridge raised a 500 for it where the chat
route returns the provider's own 400. The gate now counts a tool as a
function tool only when it carries a function body or a top-level name,
on every provider the gate serves
2026-09-19 18:58:08 -07:00
ryan-crabbe-berri
ecf17513fb
refactor(proxy): rename the local development override to dangerously_permit_weak_or_unset_master_key so the name says exactly what it permits
2026-09-19 18:53:14 -07:00
mateo-berri
2e83871d54
test(guardrails): type the recorder hook's logging_obj as object
2026-09-19 18:52:28 -07:00
mateo-berri
47ebfa10a0
fix(google_genai): reuse the shared key filter for Gemini-only schema keys
2026-09-19 18:52:00 -07:00
mateo-berri
92ff54f134
fix(mcp): list a never-listed server before its first tools/call
...
The startup tool-name fill skips servers whose upstream wants the caller's
own token (true_passthrough, OAuth discovery), and mcp 2 no longer runs the
list handler before an uncached tools/call, so every uvicorn worker that had
not served tools/list answered 404 "Tool not found" for prefixed tools/call
and the REST server_id route on those servers.
On a resolution miss, execute_mcp_tool now lists the prefix-matched (or
server_id-requested) server once, with the caller's credentials, through the
existing tools/list path, then resolves as before. Listing failures fall
through to the existing 404, a worker that already listed the server never
re-lists it, and a server outside the caller's allowed set is never listed.
2026-09-19 18:49:26 -07:00
mateo-berri
827d1c99a0
test: type the cache hook test helpers
Terraform Provider / gofmt, vet, build, test (push) Has been cancelled
Terraform Provider / Provider endpoints vs proxy OpenAPI schema (push) Has been cancelled
LiteLLM Rust / rust-lint (push) Has been cancelled
LiteLLM Rust / rust-test (push) Has been cancelled
LiteLLM Rust / rust-wheel (push) Has been cancelled
2026-09-19 18:48:39 -07:00
kerry
8d6326356d
test(integration): wait for the batch retrieval row and drop the failed-only output file
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 01:46:23 +00:00
mateo
f820472488
chore: remove the dead telemetry flag from the SDK, proxy CLI and configs
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 01:44:10 +00:00
mateo-berri
3772993032
fix(anthropic_messages): only Mantle consumes get_llm_provider's api_base
...
The /v1/messages handler passed the api_base get_llm_provider resolved to every
provider's native messages config, which shadowed DEEPSEEK_ANTHROPIC_API_BASE and
TENCENT_ANTHROPIC_API_BASE with the chat default and changed the azure_ai
precedence. Messages configs now opt in through uses_get_llm_provider_api_base(),
true only for Bedrock Mantle, whose region-prefixed model must resolve to a
region host before the prefix is stripped. Also registers
BedrockMantleAnthropicMessagesConfig in the lazy import registry.
2026-09-19 18:42:05 -07:00
mateo-berri
810acdad97
chore(streaming): drop the redundant tool-call map comment and restore the OpenAPI snapshot
2026-09-19 18:35:11 -07:00
mateo-berri
2c3fc4cbff
test: drop narrating docstrings and wrap long lines in the cache hook tests
2026-09-19 18:34:23 -07:00
mateo-berri
875f015e24
fix(token_counter): count replayed redacted_thinking blocks so prompt_caching keeps pinning
...
A conversation that replays a redacted_thinking block (Anthropic redacted reasoning, or the
/v1/messages bridge's stand-in for a reasoning item that carries no summary) made
_count_content_list raise, is_prompt_caching_valid_prompt swallowed that to False, and the
prompt_caching pre-call check neither recorded nor pinned the serving deployment, so the
conversation bounced across the group and paid a cache write on every deployment. The block
now counts like a thinking block with no text: zero tokens for the encrypted payload.
2026-09-19 18:33:56 -07:00
mateo-berri
fba179f2c0
fix(google_genai): forward response schema and tool parameters through the generateContent adapter
2026-09-19 18:31:09 -07:00
kerry
2e16cd76c1
test(integration): tighten batch and realtime cost assertions
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 01:29:46 +00:00
joshua-berri
daecea3eb8
Merge pull request #42050 from BerriAI/litellm_mcp_scoped_regressions_4506_rework
...
test(mcp): restore scoped execution and credential isolation regressions
2026-09-20 01:29:44 +00:00
Tin Chi Lo
94b2fd827b
feat(ui): show prompt caching requests and net savings
2026-09-19 18:27:38 -07:00
kerry
807541291d
test(integration): batch and realtime cost cases
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 01:25:28 +00:00
Mateo Wang
93e39d5042
Merge pull request #42062 from BerriAI/litellm_pr38499_batch_retrieve_model_group
...
fix(router): stamp model_group when retrieving a batch, so batch tokens are attributable (internal copy of #38499 )
2026-09-19 18:23:06 -07:00
mateo-berri
b0971ee0ba
fix: count extra_body tools and cache_control in place of the direct ones
2026-09-19 18:22:41 -07:00
Yassin Kortam
56b3422cc2
Merge pull request #42046 from BerriAI/litellm_cost_poll_404_no_cooldown
2026-09-19 18:20:27 -07:00
Yassin Kortam
755f5c535d
Merge pull request #41994 from BerriAI/litellm_redis_spend_requeue_safety
2026-09-19 18:19:57 -07:00
yuneng-jiang
fba00f5084
Merge pull request #42054 from BerriAI/litellm_/release-ui-build-95a688
...
chore: rebuild Admin UI bundle from main (build kXnLzJ6ylsRPmgSkCkCKM)
2026-09-19 18:19:33 -07:00
mateo-berri
e833bdccde
fix(azure_ai): bridge Foundry function-tool requests only where the chat surface rejects them
...
Foundry's OpenAI v1 chat surface rejects function tools with an explicit
reasoning_effort from gpt-5.6 on and with reasoning left on from gpt-6 on,
while gpt-5.4, gpt-5.5 and unset-effort gpt-5.6 serve them. Key the
azure_ai bridge on those measured boundaries instead of the azure
provider's gpt-5.4+ rule so working chat traffic keeps its n, logprobs,
seed and chatcmpl ids.
2026-09-19 18:19:02 -07:00
Joshua Valluru
fdc4ad54c5
docs(mcp): remove duplicate regression coverage inventory
2026-09-19 18:18:37 -07:00
kerry-berri
faa2a71fba
Merge pull request #42063 from BerriAI/litellm-providers/price-sync-openrouter
...
chore(prices): sync OpenRouter prices: 2 models
2026-09-19 18:13:28 -07:00
ryan-crabbe-berri
99f99cfb46
fix(proxy): stop the boot when the requested master key migration fails, unless allow_requests_on_db_unavailable tolerates the outage
2026-09-19 18:10:52 -07:00
Joshua Valluru
a82f0a0bd2
fix(auth): reject deactivated JWT users and invalidate cached status
2026-09-19 18:10:49 -07:00
mateo-berri
368a839640
fix(bedrock_mantle): send anthropic betas in the header Mantle reads on /v1/messages
2026-09-19 18:08:41 -07:00
Moe Khalil
24b7a38b5f
fix(auto-router): validate saved JEV probe payloads without credentials
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 01:06:41 +00:00
berriai-litellm-provider-info-sync[bot]
b652aaad4a
chore(prices): sync OpenRouter prices: 2 models
...
openrouter/deepseek/deepseek-v4-flash: input_cost_per_token, output_cost_per_token, cache_read_input_token_cost
openrouter/z-ai/glm-5.3: input_cost_per_token, output_cost_per_token, cache_read_input_token_cost
2026-09-20 01:00:52 +00:00
kerry
96ca550377
test(integration): register deployments for bedrock passthrough cases
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 01:00:25 +00:00
mateo-berri
2a35dc5217
fix(guardrails): keep the undeliverable rewrite reason through copies and name the responses mismatch
2026-09-19 18:00:03 -07:00
Moe Khalil
8898d11f6e
test(auto-router): keep editor probe on unsaved configuration
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 00:59:48 +00:00
Yuneng Jiang
98a3f45d21
chore: update Next.js build artifacts (2026-09-20 00:59 UTC, node v24.19.0)
2026-09-19 17:59:07 -07:00
mateo-berri
a114af2a26
fix(proxy): resolve the view setup gate through the search_path and set the row count before the views
2026-09-19 17:54:20 -07:00