litellm/tests/test_litellm/proxy/_experimental
Tin Chi Lo 45fed6a50a feat(mcp): generalize the bridge envelope identity to a key_hash or user_id subject
The scripted two-header client mints under a virtual key it presents at the token
endpoint (key_hash), but the interactive DCR client authenticates via SSO at the
bridged authorize, which yields a user, not a key. Make EnvelopeIdentity a
discriminated subject (subject_type key_hash | user_id) with key_hash_identity /
user_identity constructors, and dispatch admission on it: a key_hash reloads the
key, a user_id reloads the user and admits them as themselves (user-level budget
and SCIM enforced via the same centralized gate; no team bound, since a user
belongs to many teams or none). The interactive producer that mints a user_id
envelope lands in the follow-up commit.
2026-07-13 10:41:38 -07:00
..
mcp_server feat(mcp): generalize the bridge envelope identity to a key_hash or user_id subject 2026-07-13 10:41:38 -07:00