Skip to content

docs: correct Claude subscription and ChatGPT subscription credential behavior - #2164

Merged
mateo-berri merged 4 commits into
mainfrom
litellm_docs_subscription_credentials
Oct 10, 2026
Merged

mateo-berri merged 4 commits into
mainfrom
litellm_docs_subscription_credentials

Conversation

@jesus-berri

@jesus-berri jesus-berri commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Both subscription pages described more than LiteLLM does, or left out how credentials and attribution actually behave. Every new claim was checked against litellm main (0e076008e1) with a live proxy, a header-capturing upstream, and real Anthropic and auth.openai.com calls for the rejected-token cases

Claude subscription page (tutorials/claude_code_max_subscription). It now covers Pro, Max, Team, and Enterprise, since LiteLLM treats every sk-ant-oat token the same way. The page also listed forward_client_headers_to_llm_api: true as "Required". add_provider_specific_headers_to_request has forwarded the token to anthropic/ deployments without that setting since v1.81.14 (#19912), and a probe with and without the setting sent identical upstream headers, so the setting is removed from the configs and troubleshooting. New sections cover four areas. Routes: the token is used on /v1/messages and /v1/chat/completions, never on Bedrock or Vertex (v1.99.0), not on count_tokens, and not on the /anthropic pass-through when a key is configured. Credentials: Claude Code stores and refreshes the login, LiteLLM keeps nothing (0 token hits in --detailed_debug logs and SpendLogs), and 20 concurrent two-user requests had 0 token mismatches. Revocation: a revoked token returns 401 OAuth access token is invalid., LiteLLM cannot revoke a Claude login, and blocking the virtual key is the gateway-side cutoff. Attribution: cost is charged at API list price against key/user/team budgets, and the used_client_oauth_token flag is covered by the existing "Seeing Which Requests Were Billed to a Seat" section from #1703, which this PR now links to and generalizes from Max to any subscription seat (plus a note that /anthropic pass-through rows don't carry the flag). It also documents LIT-5116: one user's 401 cools down the deployment, so the next users get 429 No deployments available. A rerun with router_settings.disable_cooldowns: true returned 200 for them

ChatGPT page (providers/chatgpt). "ChatGPT Pro/Max" is replaced with the Codex plan list (ChatGPT has no Max plan), and the page now says device-code login must be enabled in ChatGPT security settings or by a workspace admin. New sections cover four points. There is one auth.json per proxy process, so every key shares one ChatGPT account and ChatGPT-Account-Id; a client-supplied ChatGPT token was ignored upstream. Recorded spend is $0, so max_budget does nothing. Refresh happens only on expiry, so a 401 on an unexpired token is not retried. A rejected refresh token returns HTTP 400 device-code login needs a human. LiteLLM has no logout or revoke for this provider

Link to Devin session: https://app.devin.ai/sessions/bd9cd9d16c90458aa8efc32ab8421f46
Open in Devin Desktop: https://app.devin.ai/desktop/session/bd9cd9d16c90458aa8efc32ab8421f46?variant=devin
Requested by: @jesus-berri


Note

Low Risk
Markdown documentation only; no application or proxy logic changes.

Overview
Documentation-only update that aligns subscription guides with verified proxy behavior (no runtime code changes).

Claude Code tutorial (claude_code_max_subscription.md) is retitled and reframed for Pro, Max, Team, and Enterprise, not Max-only. It drops forward_client_headers_to_llm_api: true as required (v1.81.14+ forwards sk-ant-oat OAuth on anthropic/ automatically) and adds guidance on deployment api_key fallback, env vars that override subscription login, which routes forward the token (and which do not), per-user credential handling, deployment cooldown after one user's 401 (router_settings.disable_cooldowns: true), attribution/cost at API list prices, and refreshed troubleshooting.

ChatGPT provider doc (chatgpt.md) replaces incorrect Pro/Max wording with Codex-inclusive subscription plans, notes device-code login must be enabled in account/workspace settings, and adds sections on one shared auth.json per proxy (no per-client ChatGPT tokens), $0 recorded spend / max_budget ineffectiveness, and refresh vs mid-session 401 / revocation behavior.

Reviewed by Cursor Bugbot for commit 2a4af9d. Bugbot is set up for automated code reviews on this repo. Configure here.

… behavior

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
litellm Ready Ready Preview Oct 10, 2026 3:42am UTC

Request Review

@mateo-berri

Copy link
Copy Markdown
Contributor

#1703 merged a "Seeing Which Requests Were Billed to a Seat" section here that repeats your used_client_oauth_token paragraph. Want to fold them into one?

jesus-berri and others added 2 commits October 9, 2026 22:03
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor

Folded in 2421d05. #1703's "Seeing Which Requests Were Billed to a Seat" section is now the only place that describes used_client_oauth_token. "Attribution and cost" and the credential storage paragraph link to it instead of repeating it. In that section I also changed "Max seat" to "subscription seat" and added that /anthropic pass-through rows don't carry the field (LIT-8607)

Written by Devin

@mateo-berri

Copy link
Copy Markdown
Contributor

The token already forwards without the setting on v1.81.14 (#19912 shipped there, checked live). Could the three v1.82.3 mentions say v1.81.14?

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor

Agreed, changed all three to v1.81.14 in 2a4af9d. I checked the tag: v1.81.14-stable is the first stable tag that contains #19912 (8d50956051), and v1.81.12-stable doesn't have it. On that tag, add_provider_specific_headers_to_request scopes the sk-ant-oat Authorization header into provider_specific_header with no forward_client_headers_to_llm_api check. The "never sent to Bedrock or Vertex AI (since v1.99.0)" line stays as it is, because on v1.81.14 the scope still listed anthropic,bedrock,vertex_ai

Written by Devin

@mateo-berri

Copy link
Copy Markdown
Contributor

bugbot run

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 2a4af9d. Configure here.

@mateo-berri mateo-berri left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks!

@mateo-berri
mateo-berri merged commit f23b7d9 into main Oct 10, 2026
7 checks passed
@mateo-berri
mateo-berri deleted the litellm_docs_subscription_credentials branch October 10, 2026 04:22

This branch was successfully deployed

1 active deployment
Preview — 2a4af9d1 Deployed Oct 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants