mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-09 03:18:44 +00:00
* feat(mcp): add tool search virtual tools for large catalogs
When mcp_tool_search_enabled is set on a key's object_permission,
tools/list returns only mcp_tool_search and mcp_tool_call instead of
the full catalog. The LLM searches by keyword then calls discovered
tools by name, avoiding context bloat with 100+ tool deployments.
* fix(mcp): persist mcp_tool_search_enabled and route tool_call by name
The mcp_tool_search_enabled flag existed on the Pydantic models but the
Prisma schema lacked the column, so keys generated with the flag never
persisted it and tools/list kept returning the full catalog. Add the
column across all three schema.prisma copies plus a migration.
handle_mcp_tool_call passed server_name="" into call_tool, which built a
malformed prefixed name ("-<tool>") and failed to resolve the server.
Resolve the caller's allowed servers and dispatch through execute_mcp_tool
instead, matching how the normal /tools/call path routes.
* fix(mcp): filter list_tools to virtual tools on the protocol path
The REST surface (/mcp-rest/tools/list) returned only the two virtual
tools when mcp_tool_search_enabled was set, but the MCP protocol handler
(handle_list_tools, used by real MCP clients over streamable-http/SSE)
still returned the full catalog. Apply the same early return there so an
actual MCP client sees mcp_tool_search and mcp_tool_call instead of every
tool. call_tool was already intercepted on this path.
* fix(mcp): enforce IP + server filtering on virtual tool search/call
Review flagged that the virtual mcp_tool_search/mcp_tool_call path skipped
access controls the normal MCP flow applies. mcp_tool_call resolved allowed
servers from key permissions only, never applying IP filtering, so a caller
on a public IP could invoke a tool on a server marked
available_on_public_internet: false. mcp_tool_search listed the raw catalog
via global_mcp_server_manager.list_tools, exposing tool names/schemas that
/tools/list would hide and ignoring per-key/per-server tool filters.
Route both virtual handlers through the same filtered paths used by the
normal MCP flow: search now calls _list_mcp_tools and call resolves servers
via _get_allowed_mcp_servers, both threaded with the request client IP so
filter_server_ids_by_ip applies. execute_mcp_tool then enforces the server
allowlist and per-key tool permissions. Thread client_ip through
_list_mcp_tools/_get_tools_from_mcp_servers and pass it from the REST and
SSE call sites.
* fix(ci): ruff format server.py and sync dashboard API types
ruff format normalizes the list_tools client_ip changes in server.py, and
schema.d.ts gains the mcp_tool_search_enabled object-permission field so the
generated dashboard types match the proxy OpenAPI spec.
* style(mcp): drop quoted annotations and sort imports
Clears UP037 on the virtual tool handler signatures (redundant with
from __future__ import annotations) and I001 on the list_tools import block.
* refactor(mcp): extract virtual-tool dispatch and host progress capture
Pulls the mcp_tool_search/mcp_tool_call interception and the host
progress-callback setup out of mcp_server_tool_call into helpers, keeping
that handler under the strict cyclomatic-complexity ceiling after the
client_ip threading. No behavior change.
* test(mcp): cover SSE virtual-tool dispatch and host progress helpers
Adds unit tests for _dispatch_virtual_mcp_tool (non-virtual passthrough,
flag-disabled rejection, search/call routing with client_ip),
_capture_host_progress_callback, and the protocol list_tools virtual
early-return, covering the new server.py paths.
* fix(mcp): forward per-request auth headers through virtual tool handlers
The virtual mcp_tool_search/mcp_tool_call path intercepted the request
before the normal header extraction ran, so client-supplied per-request
auth (Authorization for upstream pass-through, x-mcp-auth-<alias>) was
dropped and execute_mcp_tool/_list_mcp_tools received None. Thread
mcp_auth_header, mcp_server_auth_headers, oauth2_headers, and raw_headers
from both the REST and SSE call sites through the handlers so upstream MCP
servers that require pass-through auth can be listed and called.
* fix(mcp): preserve requested server scope in virtual tool calls
A scoped MCP session (/mcp/<server>/ or header-scoped) carries an
mcp_servers scope that the normal call path passes into routing so the
session can only reach that server. The virtual-tool branch dropped it and
resolved with mcp_servers=None, letting a scoped session call mcp_tool_call
for any server the key can access. Thread the context mcp_servers scope
through _dispatch_virtual_mcp_tool into both handlers so search and call
resolve against the same scoped server set.
* fix(mcp): convert virtual tool errors to isError on the protocol path
The virtual-tool dispatch ran before the protocol handler's HTTPException
and guardrail handling, so a rejected virtual call (e.g. an out-of-scope
403 from execute_mcp_tool) raised out of mcp_server_tool_call and broke the
MCP JSON-RPC stream instead of returning an isError CallToolResult. Move
the dispatch inside the same try that wraps call_mcp_tool so virtual-tool
errors get the same isError conversion as normal tool calls.
* fix(mcp): spend-log virtual tool calls on the REST path
The REST virtual-tool branch returned before common_processing_pre_call_logic,
so execute_mcp_tool ran without a litellm_logging_obj and virtual mcp_tool_call
invocations were not spend-logged or guardrail-checked like normal calls. Run
the same pre-call pipeline in the call branch and thread the resulting
litellm_logging_obj through handle_mcp_tool_call into execute_mcp_tool.
* fix(mcp): reject virtual tool call when key has no accessible servers
handle_mcp_tool_call passed an empty allowed_mcp_servers list into
execute_mcp_tool; an unprefixed local tool name then fell through to the
local registry, which has no server permission check, so a key with only
mcp_tool_search_enabled and no server grants could run operator-configured
local tools by name. Reject with 403 before dispatch when no servers are
accessible, matching call_mcp_tool.
* docs(mcp): document virtual tool_search module and parity rule in AGENTS.md
* style(mcp): apply ruff format at repo line-length (120)
* fix(mcp): add mcp_tool_search_enabled to ObjectPermissionDict and customer test fixture
* chore: trigger CI
* fix(mcp): mirror pre-call pipeline, guard imports, coerce top_k, honor include_disabled_tools
- SSE mcp_tool_call now runs common_processing_pre_call_logic so it spend-logs and runs guardrails like the REST path (P1)
- coerce_top_k avoids ValueError on non-integer top_k from clients (both REST and SSE)
- guard mcp.types import in tool_search behind runtime/TYPE_CHECKING per package convention
- admin list with include_disabled_tools returns the real catalog even when mcp_tool_search_enabled is set
|
||
|---|---|---|
| .. | ||
| 20260108_add_user_email_lower_idx | ||
| 20250326162113_baseline | ||
| 20250326171002_add_daily_user_table | ||
| 20250327180120_add_api_requests_to_daily_user_table | ||
| 20250329084805_new_cron_job_table | ||
| 20250331215456_track_success_and_failed_requests_daily_agg_table | ||
| 20250411215431_add_managed_file_table | ||
| 20250412081753_team_member_permissions | ||
| 20250415151647_add_cache_read_write_tokens_daily_spend_transactions | ||
| 20250415191926_add_daily_team_table | ||
| 20250416115320_add_tag_table_to_db | ||
| 20250416151339_drop_tag_uniqueness_requirement | ||
| 20250416185146_add_allowed_routes_litellm_verification_token | ||
| 20250425182129_add_session_id | ||
| 20250430193429_add_managed_vector_stores | ||
| 20250507161526_add_mcp_table_to_db | ||
| 20250507161527_add_health_check_fields_to_mcp_servers | ||
| 20250507184818_add_mcp_key_team_permission_mgmt | ||
| 20250508072103_add_status_to_spendlogs | ||
| 20250509141545_use_big_int_for_daily_spend_tables | ||
| 20250510142544_add_session_id_index_spend_logs | ||
| 20250514142245_add_guardrails_table | ||
| 20250522223020_managed_object_table | ||
| 20250526154401_allow_null_entity_id | ||
| 20250528185438_add_vector_stores_to_object_permissions | ||
| 20250603210143_cascade_budget_changes | ||
| 20250618225828_add_health_check_table | ||
| 20250625145206_cascade_budget_and_loosen_managed_file_json | ||
| 20250625213625_add_status_to_managed_object_table | ||
| 20250707212517_add_mcp_info_column_mcp_servers | ||
| 20250707230009_add_mcp_namespaced_tool_name | ||
| 20250711220620_add_stdio_mcp | ||
| 20250718125714_add_litellm_params_to_vector_stores | ||
| 20250802162330_prompt_table | ||
| 20250806095134_rename_alias_to_server_name_mcp_table | ||
| 20250918083359_drop_spec_version_column_from_mcp_table | ||
| 20250926194702_unnamed_migration | ||
| 20251003165142_add_allowed_tools_to_mcp | ||
| 20251003190954_extra_headers_to_mcp_table | ||
| 20251006143948_add_mcp_tool_permissions | ||
| 20251011084309_add_tag_table | ||
| 20251023141814_add_search_tool_table | ||
| 20251031181430_add_cache_config_table | ||
| 20251101131415_add_managed_vector_store_index_table | ||
| 20251103072422_add_static_headers | ||
| 20251104220043_add_credentials_to_mcp_servers | ||
| 20251113000000_add_project_table | ||
| 20251113000001_add_project_fields | ||
| 20251114173537_add_request_id_to_daily_tag_spend | ||
| 20251114180624_Add_org_usage_table | ||
| 20251114182247_agents_table | ||
| 20251119131227_add_prompt_versioning | ||
| 20251122125322_Add organization_id to spend logs | ||
| 20251204124859_add_end_user_spend_table | ||
| 20251204142718_add_agent_permissions | ||
| 20251209112246_add_ui_settings_table | ||
| 20251210125210_add_storage_backend_to_managed_files | ||
| 20251210205007_add_daily_agent_spend_table | ||
| 20251211100212_schema_sync | ||
| 20251219110931_add_deleted_keys_and_deleted_teams_tables | ||
| 20251220144550_schema_update | ||
| 20260102131258_add_metadata_urls_to_mcp_servers | ||
| 20260105151539_add_allow_all_keys_to_mcp_servers | ||
| 20260106155622_add_endpoint_to_daily_activity_tables | ||
| 20260107111013_add_router_settings_to_keys_teams | ||
| 20260116142756_update_deleted_keys_teams_table_routing_settings | ||
| 20260123131407_add_policy_tables_and_policies_field | ||
| 20260131150814_add_team_user_to_vector_stores | ||
| 20260203120000_add_deprecated_verification_token_table | ||
| 20260205091235_allow_team_guardrail_config | ||
| 20260205144610_add_soft_budget_to_team_table | ||
| 20260207093506_add_available_on_public_internet_to_mcp_servers | ||
| 20260207110613_add_soft_budget_to_deleted_teams_table | ||
| 20260209085821_add_verificationtoken_indexes | ||
| 20260212103349_adjust_tags_policy_table | ||
| 20260212143306_add_access_group_table | ||
| 20260213105436_add_managed_vector_store_table | ||
| 20260213170952_access_group_change_to_model_name | ||
| 20260214094754_schema_sync | ||
| 20260214163027_add_pipeline_to_policy_table | ||
| 20260214185341_object_permissions_for_end_users | ||
| 20260218231534_add_last_active_to_key_table | ||
| 20260219105005_add_project_id_to_deleted_keys | ||
| 20260219181415_baseline_diff | ||
| 20260220124742_add_spec_path_to_mcp_servers | ||
| 20260220153844_add_composite_index_aggregate_tables | ||
| 20260221000000_ensure_project_id_verification_token | ||
| 20260221183800_add_policy_versioning | ||
| 20260222000000_add_batch_processed_to_managed_object_table | ||
| 20260224201417_spend_logs_request_duration | ||
| 20260224203854_add_agent_object_permissions_table | ||
| 20260226000000_add_blocked_tools_to_object_permission | ||
| 20260226120000_add_spend_log_tool_index | ||
| 20260226202727_add_agent_id_to_delete_keys | ||
| 20260228000000_add_claude_code_plugin_table | ||
| 20260228100000_add_spend_logs_composite_index | ||
| 20260228110000_mcp_default_public_internet_true | ||
| 20260228170127_support_team_based_guardrails | ||
| 20260303000000_update_tool_table_policies | ||
| 20260304175016_add_spend_to_agent_table | ||
| 20260305000000_add_agent_headers | ||
| 20260305000000_add_rate_limits_to_agents | ||
| 20260306175056_add_configs_override_table | ||
| 20260306233848_schema_sync | ||
| 20260309000000_add_mcp_approval_status | ||
| 20260309000001_add_mcp_source_url | ||
| 20260312124619_schema_sync | ||
| 20260318140652_add_index_to_team_table | ||
| 20260319000000_restore_mcp_approval_fields | ||
| 20260321000000_add_mcp_toolsets | ||
| 20260331000000_add_prompt_environment_and_created_by | ||
| 20260401000000_add_budget_limits | ||
| 20260401000000_add_team_member_model_scope | ||
| 20260414140000_add_mcp_server_instructions | ||
| 20260415120000_health_check_latest_per_model_index | ||
| 20260418000000_add_adaptive_router_tables | ||
| 20260421120000_add_memory_table | ||
| 20260421135425_add_team_membership_total_spend | ||
| 20260429120000_search_tools_on_object_permission | ||
| 20260429161855_workflow_runs_tables | ||
| 20260501195714_managed_resource_team_owner | ||
| 20260513120000_add_delegate_auth_to_upstream_to_mcp_servers | ||
| 20260514120000_add_blocked_to_proxy_model_table | ||
| 20260520120000_add_mcp_env_vars | ||
| 20260526120000_add_oauth_passthrough_to_mcp_servers | ||
| 20260604120000_add_oauth2_flow_to_mcp_servers | ||
| 20260605182307_add_timeout_to_mcp_server_table | ||
| 20260626120000_add_mcp_tool_search_enabled | ||
| migration_lock.toml | ||