Repository navigation
docs: correct Claude subscription and ChatGPT subscription credential behavior - #2164
Conversation
… behavior Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
#1703 merged a "Seeing Which Requests Were Billed to a Seat" section here that repeats your |
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
Folded in 2421d05. #1703's "Seeing Which Requests Were Billed to a Seat" section is now the only place that describes |
|
The token already forwards without the setting on v1.81.14 (#19912 shipped there, checked live). Could the three v1.82.3 mentions say v1.81.14? |
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
Agreed, changed all three to v1.81.14 in 2a4af9d. I checked the tag: |
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 2a4af9d. Configure here.
Summary
Both subscription pages described more than LiteLLM does, or left out how credentials and attribution actually behave. Every new claim was checked against litellm main (
0e076008e1) with a live proxy, a header-capturing upstream, and real Anthropic andauth.openai.comcalls for the rejected-token casesClaude subscription page (
tutorials/claude_code_max_subscription). It now covers Pro, Max, Team, and Enterprise, since LiteLLM treats everysk-ant-oattoken the same way. The page also listedforward_client_headers_to_llm_api: trueas "Required".add_provider_specific_headers_to_requesthas forwarded the token toanthropic/deployments without that setting since v1.81.14 (#19912), and a probe with and without the setting sent identical upstream headers, so the setting is removed from the configs and troubleshooting. New sections cover four areas. Routes: the token is used on/v1/messagesand/v1/chat/completions, never on Bedrock or Vertex (v1.99.0), not oncount_tokens, and not on the/anthropicpass-through when a key is configured. Credentials: Claude Code stores and refreshes the login, LiteLLM keeps nothing (0 token hits in--detailed_debuglogs and SpendLogs), and 20 concurrent two-user requests had 0 token mismatches. Revocation: a revoked token returns401 OAuth access token is invalid., LiteLLM cannot revoke a Claude login, and blocking the virtual key is the gateway-side cutoff. Attribution: cost is charged at API list price against key/user/team budgets, and theused_client_oauth_tokenflag is covered by the existing "Seeing Which Requests Were Billed to a Seat" section from #1703, which this PR now links to and generalizes from Max to any subscription seat (plus a note that/anthropicpass-through rows don't carry the flag). It also documents LIT-5116: one user's 401 cools down the deployment, so the next users get429 No deployments available. A rerun withrouter_settings.disable_cooldowns: truereturned 200 for themChatGPT page (
providers/chatgpt). "ChatGPT Pro/Max" is replaced with the Codex plan list (ChatGPT has no Max plan), and the page now says device-code login must be enabled in ChatGPT security settings or by a workspace admin. New sections cover four points. There is oneauth.jsonper proxy process, so every key shares one ChatGPT account andChatGPT-Account-Id; a client-supplied ChatGPT token was ignored upstream. Recorded spend is $0, somax_budgetdoes nothing. Refresh happens only on expiry, so a 401 on an unexpired token is not retried. A rejected refresh token returns HTTP 400device-code login needs a human. LiteLLM has no logout or revoke for this providerLink to Devin session: https://app.devin.ai/sessions/bd9cd9d16c90458aa8efc32ab8421f46
Open in Devin Desktop: https://app.devin.ai/desktop/session/bd9cd9d16c90458aa8efc32ab8421f46?variant=devin
Requested by: @jesus-berri
Note
Low Risk
Markdown documentation only; no application or proxy logic changes.
Overview
Documentation-only update that aligns subscription guides with verified proxy behavior (no runtime code changes).
Claude Code tutorial (
claude_code_max_subscription.md) is retitled and reframed for Pro, Max, Team, and Enterprise, not Max-only. It dropsforward_client_headers_to_llm_api: trueas required (v1.81.14+ forwardssk-ant-oatOAuth onanthropic/automatically) and adds guidance on deploymentapi_keyfallback, env vars that override subscription login, which routes forward the token (and which do not), per-user credential handling, deployment cooldown after one user's 401 (router_settings.disable_cooldowns: true), attribution/cost at API list prices, and refreshed troubleshooting.ChatGPT provider doc (
chatgpt.md) replaces incorrect Pro/Max wording with Codex-inclusive subscription plans, notes device-code login must be enabled in account/workspace settings, and adds sections on one sharedauth.jsonper proxy (no per-client ChatGPT tokens), $0 recorded spend /max_budgetineffectiveness, and refresh vs mid-session 401 / revocation behavior.Reviewed by Cursor Bugbot for commit 2a4af9d. Bugbot is set up for automated code reviews on this repo. Configure here.