Repository navigation
docs(proxy): say how spend logs record which requests a client-forwarded OAuth token paid for - #1703
Merged
Merged
Conversation
…ded OAuth token paid for
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Contributor
Author
|
bugbot run |
Contributor
Author
|
bugbot run |
Contributor
Author
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 89a6a39. Configure here.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TLDR
Documents the
metadata.used_client_oauth_tokenspend log flag that BerriAI/litellm#43063 adds, so an admin whose developers run Claude Code on Max seats through the gateway can tell which requests a seat paid for and which ones the deployment's configured key paid for. The code is in main and first shipped inv1.105.0-rc.1(Sat, Oct 3); stablev1.105.0is not cut yet, so the docs name v1.105.0 as the first release with the flagUser Flow
Before: the admin reads the Max subscription tutorial and finds no way to split seat-billed requests from key-billed ones, so the API bill they reconcile from the logs stays wrong
/loginforwards an OAuth token, but says nothing about how that shows up in the logsGET https://litellm-domain/spend/logs/uiand have no documented parameter to passAfter: the admin finds a section that names the flag, the Logs page filter, and the API parameter, and gets the seat-billed rows on the first try
metadata.used_client_oauth_tokenistruefor a forwarded OAuth token andfalsefor the configured key, it needs v1.105.0 or later, Bedrock and Vertex routes readfalse, andspendstays at list price, so they subtract the seat-billed rowsGET https://litellm-domain/spend/logs/ui?used_client_oauth_token=truewithAuthorization: Bearer <admin key>and get back 200 with only those rows;used_client_oauth_token=falsereturns the key-billed onesChanges
docs/tutorials/claude_code_max_subscription.mdgains a section on listing the requests a Max seat paid for, on the Logs page and withGET /spend/logs/ui?used_client_oauth_token=true, names v1.105.0 as the first release with the flag, and says spend stays at list price so reporting subtracts those rowsdocs/proxy/forward_client_headers.mdnames the flag and its filters next to the OAuth forwarding paragraphChecks
node scripts/check-writing-style.js docs blog release_notesandpython3 scripts/check-docs.py docsboth pass locally at the tip after merging main. Every claim was checked against litellm main ataa64b07281: theused_client_oauth_tokenquery parameter on/spend/logs/ui, the Credential filter and drawer labels (Client OAuth token, Configured key), the flag resolving tofalsefor any provider other than direct Anthropic, and no spend change on seat-billed rowsCaveats
Low: "Every spend log row" was checked for the unified
/v1/messages,/v1/chat/completionsand/v1/responsesroutes this tutorial uses, not for the/anthropicpass-through route, whose rows may carry no value. Left as is, since chasing it needs a live pass-through run for a route the tutorial never sends toScreenshots / Proof of Fix
Rendered pages at 1280x900: before is https://docs.litellm.ai (built from main), after is this PR's Vercel preview at
89a6a39c. To reproduce, open/docs/tutorials/claude_code_max_subscriptionand scroll to the end of Advanced Configuration, then open/docs/proxy/forward_client_headersand find the Claude Code paragraph under "Use Case: Client-Side API Keys (BYOK)"Before, Budget Controls runs straight into Troubleshooting and nothing says which rows a Max seat paid for
After, "Seeing Which Requests Were Billed to a Seat" sits between them with the flag, the v1.105.0 floor, the Credential filter, and the curl
After, the Claude Code paragraph on the forward headers page names the same flag and filters (the production page has no mention of
used_client_oauth_token)The release claim was checked against tags:
v1.105.0-rc.1carries theused_client_oauth_tokenquery parameter and the Client OAuth token / Configured key labels, andv1.104.2, the newest stable, carries neither. The live behavior the section describes (seat rowstrue, configured-key rowsfalse,spendunchanged,?used_client_oauth_token=truereturning only seat rows) is the Claude Code proof on BerriAI/litellm#43063Note
Low Risk
Documentation-only changes with no runtime or security behavior modifications.
Overview
Documents
metadata.used_client_oauth_tokenon spend logs so operators can tell whether upstream Anthropic was billed via a forwarded client OAuth token or the deployment’s configured API key (the token itself is never logged).docs/tutorials/claude_code_max_subscription.mdadds Seeing Which Requests Were Billed to a Seat: meaning of the flag (including Bedrock/Vertex routes asfalse), thatspendstays at list price for budgets while real API cost requires subtracting seat-billed rows, and how to filter in the Logs Credential dropdown or withGET /spend/logs/ui?used_client_oauth_token=true|false.docs/proxy/forward_client_headers.mdextends the Claude Code OAuth forwarding note with the same metadata field and filter options.Reviewed by Cursor Bugbot for commit 5bce11f. Bugbot is set up for automated code reviews on this repo. Configure here.