Skip to content

fix(proxy): let llm_api virtual keys read /model_group/info - #38662

Merged
ryan-crabbe-berri merged 1 commit into
litellm_internal_stagingfrom
litellm_fix_playground_model_group_info_llm_api_key
Aug 28, 2026
Merged

ryan-crabbe-berri merged 1 commit into
litellm_internal_stagingfrom
litellm_fix_playground_model_group_info_llm_api_key

Conversation

@devin-ai-integration

Copy link
Copy Markdown
Contributor

TLDR

Problem this solves:

  • Playground model picker is empty with a virtual key
  • Keys made in the UI default to key type "llm_api"
  • Those keys get a 403 listing model groups

How it solves it:

  • Model group info joins the model info reads llm_api keys already get
  • The listing stays scoped to the models the key can call

User Flow

Before: someone testing a virtual key in the Playground has no model to pick, so they can't send anything

  1. They create a key at http://localhost:4000/ui/?page=api-keys leaving Key Type on its default, "AI API Key"
  2. They open the Playground, set Virtual Key Source to "Virtual Key" and paste the key
  3. The Select Model dropdown only offers "Enter custom model", with none of the key's models listed
  4. Fetching the same list by hand, GET /model_group/info with that key, returns 403 "Virtual key is not allowed to call this route. Only allowed to call routes: ['llm_api_routes']"

After: the same key lists its models and the chat works

  1. They create a key at http://localhost:4000/ui/?page=api-keys leaving Key Type on its default, "AI API Key"
  2. They open the Playground, set Virtual Key Source to "Virtual Key" and paste the key
  3. The Select Model dropdown now lists the key's models, gpt-4o-mini here, and picking one lets them chat
  4. GET /model_group/info with that key returns 200 with only the models that key is allowed to call

A key still only sees its own models, so this does not widen what anyone can read

Relevant issues

Linear ticket

Pre-Submission checklist

Please complete all items before asking a LiteLLM maintainer to review your PR

  • I have added meaningful tests
  • The handful of test files covering my change pass locally, e.g. uv run pytest tests/test_litellm/<your_test_file>.py -v. Leave the suites (make test-unit-*, make test-unit) to CI: it finishes in ~15 minutes where a laptop takes an hour or more
  • My PR passes all required CI/CD checks (e.g., lint, schema.d.ts sync check, etc.)
  • My PR's scope is as isolated as possible; it only solves 1 specific problem
  • I have received a Greptile Confidence Score of at least 4/5 before requesting a maintainer review (Greptile reviews automatically once the PR is opened; only comment @greptileai to re-request a review after pushing changes)

Delays in PR merge?

If you're seeing a delay in your PR being merged, ping the LiteLLM Team on Slack (#pr-review).

Screenshots / Proof of Fix

Shared setup, run against a live proxy on localhost:4000 started with litellm --config litellm/proxy/dev_config.yaml --port 4000, minting the same kind of key the UI creates by default:

K=$(curl -s -X POST localhost:4000/key/generate \
  -H "Authorization: Bearer sk-1234" -H "Content-Type: application/json" \
  -d '{"models":["gpt-4o-mini"],"key_type":"llm_api"}' | jq -r .key)

Before (ca0b951)

Listing model groups with the key

  1. curl -s -w "\nHTTP %{http_code}\n" localhost:4000/model_group/info -H "Authorization: Bearer $K"
  2. Output:
{"detail":"Virtual key is not allowed to call this route. Only allowed to call routes: ['llm_api_routes']. Tried to call route: /model_group/info"}
HTTP 403

Playground model picker

  1. Open http://localhost:3000/playground/, set Virtual Key Source to "Virtual Key", paste the key, open Select Model
  2. The dropdown shows only "Enter custom model"

After (418b820)

Listing model groups with the key

  1. curl -s -w "\nHTTP %{http_code}\n" localhost:4000/model_group/info -H "Authorization: Bearer $K"
  2. Output, trimmed:
{"data":[{"model_group":"gpt-4o-mini","providers":["openai"],"max_input_tokens":128000.0,"max_output_tokens":16384.0,"input_cost_per_token":1.5e-07,"output_cost_per_token":6e-07,"mode":"chat", ...}]}
HTTP 200

Playground model picker

  1. Open http://localhost:3000/playground/, set Virtual Key Source to "Virtual Key", paste the key, open Select Model
  2. The dropdown now lists gpt-4o-mini with "Mode: chat" next to "Enter custom model"

Real chat call with the same key

  1. curl -s localhost:4000/v1/chat/completions -H "Authorization: Bearer $K" -H "Content-Type: application/json" -d '{"model":"gpt-4o-mini","messages":[{"role":"user","content":"say hi in 3 words"}]}'
  2. Output, trimmed:
{"id":"chatcmpl-EHs4BjCr797ruQxggzBkD9GNDWbLj","model":"gpt-4o-mini","choices":[{"finish_reason":"stop","index":0,"message":{"content":"Hello, how are you?","role":"assistant"}}], ...}

Type

🐛 Bug Fix

Caveats (if any)

Low

  • Management keys still get a 403 on this route

Link to Devin session: https://app.devin.ai/sessions/a043eb6e3a324294a133ffd6bee3362f
Open in Devin Desktop: https://app.devin.ai/desktop/session/a043eb6e3a324294a133ffd6bee3362f?variant=devin
Requested by: @yassin-berriai

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

No action taken on #38662 — repo and author check out (devin-ai-integration[bot]), but the PR has no labels at all, so the required enterprise label is absent. Out of scope; no GitHub or Linear changes made.

@greptile-apps

greptile-apps Bot commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR allows llm_api virtual keys to read model-group metadata needed by the Playground while preserving per-key model scoping.

  • Adds /model_group/info to the model-information routes included in the llm_api_routes allowlist.
  • Adds regression coverage for route access and confirms the endpoint remains outside the broader LLM API endpoint classification.

Confidence Score: 5/5

The PR appears safe to merge because the new read access remains restricted to models available to the requesting virtual key.

The route-category change has a narrow authorization effect, the handler applies existing per-key model filtering, and no credentials or deployment identifiers are added to the response.

Important Files Changed

Filename Overview
litellm/proxy/_types.py Extends the virtual-key model-information allowlist with /model_group/info without changing its separate endpoint classification.
tests/test_litellm/proxy/auth/test_route_checks.py Adds focused regression coverage for the new grant and preserves negative coverage for the administrative /v2/model/info route.

Reviews (1): Last reviewed commit: "fix(proxy): let llm_api virtual keys rea..." | Re-trigger Greptile

@codecov

codecov Bot commented Aug 28, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@codspeed

codspeed Bot commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

Merging this PR will not alter performance

✅ 31 untouched benchmarks


Comparing litellm_fix_playground_model_group_info_llm_api_key (418b820) with litellm_internal_staging (ca0b951)

Open in CodSpeed

@ryan-crabbe-berri
ryan-crabbe-berri merged commit 5476f91 into litellm_internal_staging Aug 28, 2026
79 checks passed
@ryan-crabbe-berri
ryan-crabbe-berri deleted the litellm_fix_playground_model_group_info_llm_api_key branch August 28, 2026 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants