litellm/tests/test_litellm/proxy/_experimental
Yassin Kortam 27d1974e2f
fix(mcp): cap an agent key's tools at what the invoking user and team may call (#42478)
* fix(mcp): cap an agent key's tools at what the invoking user and team may call

The invoking user's and team's x-litellm-user-id / x-litellm-team-id, echoed back by the
agent, already narrowed which MCP servers the agent key could reach, but not which tools on
those servers. An agent granted every tool on a server kept them all when acting for a user
who may only call a subset. The caller's team and user tool grants now intersect the agent's
tool list on each server, mirroring the servers axis, so the headers only ever narrow.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(mcp): pick the caller principal explicitly instead of getattr in the tool grant stub

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(mcp): return immutable tool sequences from the agent caller tool ceiling

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-24 18:47:44 -05:00
..
mcp_server fix(mcp): cap an agent key's tools at what the invoking user and team may call (#42478) 2026-09-24 18:47:44 -05:00