Skip to content

fix(streaming): surface upstream connection resets instead of empty 200 streams - #33222

Merged
mateo-berri merged 5 commits into
litellm_internal_stagingfrom
litellm_fix_stream_reset_empty_200
Jul 16, 2026
Merged

fix(streaming): surface upstream connection resets instead of empty 200 streams#33222
mateo-berri merged 5 commits into
litellm_internal_stagingfrom
litellm_fix_stream_reset_empty_200

Conversation

@mateo-berri

@mateo-berri mateo-berri commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Relevant issues

Linear ticket

Resolves LIT-4450

Pre-Submission checklist

Please complete all items before asking a LiteLLM maintainer to review your PR

  • I have added meaningful tests
  • My PR passes all CI/CD checks (e.g., lint, format, unit tests)
  • My PR's scope is as isolated as possible; it only solves 1 specific problem
  • I have received a Greptile Confidence Score of at least 4/5 before requesting a maintainer review (Greptile reviews automatically once the PR is opened; only comment @greptileai to re-request a review after pushing changes)

Delays in PR merge?

If you're seeing a delay in your PR being merged, ping the LiteLLM Team on Slack (#pr-review).

Screenshots / Proof of Fix

A customer replaying a captured streaming chat/completions request through the proxy saw intermittent HTTP 200 responses whose SSE body carried no content, no tool calls, and no reasoning, just finish_reason: "stop" (66 out of 1000 attempts), while the same request replayed directly against the downstream endpoint never produced one. Datadog tracing on the affected requests showed Connection reset by peer errors on the upstream call inside spans that still returned 200

This cannot be reproduced on demand against a real provider because it needs the upstream to kill the TCP connection mid-response, so the proof uses a realistic e2e test harness around a live proxy: a fault-injecting OpenAI-compatible downstream (fault_downstream.py) that streams a role delta plus N content deltas as chunked SSE and then kills the connection without ever sending a finish chunk, and a probe (probe_litellm_stream.py) that classifies the SSE body the proxy hands back. Two fault shapes are exercised, a hard RST (SO_LINGER 0) and a half-close FIN that omits the terminal chunk; curl pointed directly at the faulting downstream reports the failure plainly (curl: (18) transfer closed with outstanding read data remaining), so anything other than an explicit error out of the proxy is data loss. Everything from the proxy inward is the real production code path: aiohttp transport, openai provider, streaming wrapper. The harness and config are in the details block below

Before, captured on litellm v1.93.0rc1 from PyPI (the swallow also reproduces identically at this branch's base, b200d66): the probe classifies the proxy response as true_empty_stop, the exact shape from the report above. In the FIN shape all 50 real content deltas are consumed and replaced with a single fabricated empty stop plus [DONE]; the RST shape produces the same class

$ python fault_downstream.py --port 9317
$ litellm --config litellm_config.yaml --port 9463
$ python probe_litellm_stream.py --base-url http://127.0.0.1:9463/v1 --fault-fin
{
  "model": "fault-reset-after-partial-200",
  "fault_chunk_count": 50,
  "status": 200,
  "class": "true_empty_stop"
}
--- raw stream ---
data: {"id":"chatcmpl-ec5da108-5d4e-47b9-977a-ab739dc2d471","object":"chat.completion.chunk","created":1784124097,"model":"fault-reset-after-partial-200","choices":[{"index":0,"delta":{},"finish_reason":"stop"}]}

data: [DONE]

After, same harness against a proxy running this branch at 26a7f6d (94c579a only merges the base branch in; re-ran the full harness at the branch tip e14da65 with identical results): a connection killed before the first delta reaches the client fails the request outright with a retriable 500

$ python probe_litellm_stream.py --base-url http://127.0.0.1:9464/v1
{
  "model": "fault-reset-after-partial-200",
  "fault_chunk_count": 0,
  "status": 500,
  "class": "http_500"
}
--- raw stream ---
{"error":{"message":"litellm.APIConnectionError: APIConnectionError: OpenAIException - Response payload is not completed: <TransferEncodingError: 400, message='Not enough data to satisfy transfer length header.'>. ConnectionResetError(54, 'Connection reset by peer')","type":null,"param":null,"code":"500"}}

and a connection killed mid-stream (20 paced deltas already forwarded to the client) delivers every real delta and then surfaces the failure as an SSE error chunk, with no fabricated finish_reason: "stop" and no [DONE]

$ curl -sN -w "\nHTTP_STATUS: %{http_code}\n" http://127.0.0.1:9464/v1/chat/completions \
    -H "Content-Type: application/json" \
    -d '{"model":"fault-reset-after-partial-200","stream":true,"fault_chunk_count":20,"fault_delay_ms":50,"fault_fin":true,"messages":[{"role":"user","content":"hi"}]}'
data: {..."delta":{"role":"assistant"}}]}
data: {..."delta":{"content":"chunk-0 "}}]}
...
data: {..."delta":{"content":"chunk-19 "}}]}
data: {"error": {"message": "litellm.APIConnectionError: APIConnectionError: OpenAIException - Response payload is not completed: <TransferEncodingError: 400, message='Not enough data to satisfy transfer length header.'>", "type": null, "param": null, "code": "500"}}

HTTP_STATUS: 200

At the router level the failure stays a single upstream call: streaming router.acompletion through the same fault yields all 50 real deltas and then raises litellm.APIConnectionError, and the downstream's request log shows exactly one request for the run, so surfacing the error introduces no hidden retries or duplicate upstream calls

Harness: fault-injecting downstream, probe, proxy config

litellm_config.yaml:

model_list:
  - model_name: fault-reset-after-partial-200
    litellm_params:
      model: fault-reset-after-partial-200
      api_base: http://127.0.0.1:9317/v1
      api_key: dummy
      custom_llm_provider: openai
    model_info:
      mode: chat
      id: fault-reset-after-partial-200

litellm_settings:
  drop_params: true
  request_timeout: 600
  set_verbose: true

fault_downstream.py (fault shape per request body: fault_chunk_count deltas, fault_delay_ms pacing, fault_fin for FIN instead of RST):

#!/usr/bin/env python3
from __future__ import annotations

from http.server import BaseHTTPRequestHandler, ThreadingHTTPServer
from urllib.parse import urlparse
import argparse
import json
import socket
import struct
import time
import uuid


MODEL_RESET = "fault-reset-after-partial-200"


def now() -> int:
    return int(time.time())


def json_bytes(payload: dict) -> bytes:
    return json.dumps(payload, separators=(",", ":")).encode("utf-8")


def int_body(request_json: dict, name: str, default: int) -> int:
    candidates = [
        request_json.get(name),
        (request_json.get("metadata") or {}).get(name)
        if isinstance(request_json.get("metadata"), dict)
        else None,
    ]
    for value in candidates:
        try:
            if value is not None:
                return int(value)
        except (TypeError, ValueError):
            continue
    return default


class Handler(BaseHTTPRequestHandler):
    protocol_version = "HTTP/1.1"
    server_version = "fault-downstream/0.1"

    def do_GET(self) -> None:
        if self.path in {"/", "/healthz", "/readyz"}:
            payload = json_bytes(
                {
                    "ok": True,
                    "models": [MODEL_RESET],
                    "ts": time.time(),
                }
            )
            self.send_response(200)
            self.send_header("content-type", "application/json")
            self.send_header("content-length", str(len(payload)))
            self.end_headers()
            self.wfile.write(payload)
            self.wfile.flush()
            return
        self.send_error(404, "not found")

    def do_POST(self) -> None:
        parsed = urlparse(self.path)
        request_id = self.headers.get("x-request-id") or uuid.uuid4().hex[:12]
        body = self._read_body()
        request_json = self._parse_json(body)
        model = request_json.get("model")
        stream = bool(request_json.get("stream"))

        self._log(
            {
                "event": "request",
                "request_id": request_id,
                "path": parsed.path,
                "model": model,
                "stream": stream,
                "bytes": len(body),
            }
        )

        if parsed.path != "/v1/chat/completions":
            self._send_json(404, {"error": {"message": "unsupported path"}}, request_id)
            return

        if not stream:
            self._send_json(
                400,
                {"error": {"message": "this repro expects stream=true"}},
                request_id,
            )
            return

        if model == MODEL_RESET:
            self._send_chunks_then_reset(request_json, request_id)
            return

        self._send_json(
            400,
            {"error": {"message": f"unknown model: {model}"}},
            request_id,
        )

    def _read_body(self) -> bytes:
        length = int(self.headers.get("content-length") or "0")
        return self.rfile.read(length) if length else b""

    def _parse_json(self, body: bytes) -> dict:
        try:
            parsed = json.loads(body.decode("utf-8"))
            return parsed if isinstance(parsed, dict) else {}
        except Exception:
            return {}

    def _send_chunks_then_reset(self, request_json: dict, request_id: str) -> None:
        self._start_sse(200, request_id, "reset_after_partial_200")
        self._write_sse(
            {
                "id": f"chatcmpl-{request_id}",
                "object": "chat.completion.chunk",
                "created": now(),
                "model": MODEL_RESET,
                "choices": [
                    {
                        "index": 0,
                        "delta": {"role": "assistant"},
                        "finish_reason": None,
                    }
                ],
            }
        )
        chunk_count = max(0, min(int_body(request_json, "fault_chunk_count", 0), 1000))
        delay_ms = max(0, min(int_body(request_json, "fault_delay_ms", 0), 5000))
        for index in range(chunk_count):
            if delay_ms:
                time.sleep(delay_ms / 1000)
            self._write_sse(
                {
                    "id": f"chatcmpl-{request_id}",
                    "object": "chat.completion.chunk",
                    "created": now(),
                    "model": MODEL_RESET,
                    "choices": [
                        {
                            "index": 0,
                            "delta": {"content": f"chunk-{index} "},
                            "finish_reason": None,
                        }
                    ],
                }
            )
        fin_mode = bool(request_json.get("fault_fin"))
        self._log(
            {
                "event": "fin_after_chunks" if fin_mode else "reset_after_chunks",
                "request_id": request_id,
                "content_chunks": chunk_count,
            }
        )
        if fin_mode:
            self.close_connection = True
            self.connection.shutdown(socket.SHUT_WR)
            return
        self._reset_connection(request_id)

    def _send_json(self, status: int, payload: dict, request_id: str) -> None:
        raw = json_bytes(payload)
        self.send_response(status)
        self.send_header("content-type", "application/json")
        self.send_header("content-length", str(len(raw)))
        self.send_header("x-fault-request-id", request_id)
        self.end_headers()
        self.wfile.write(raw)
        self.wfile.flush()

    def _start_sse(self, status: int, request_id: str, fault_mode: str) -> None:
        self.send_response(status)
        self.send_header("content-type", "text/event-stream")
        self.send_header("cache-control", "no-cache")
        self.send_header("transfer-encoding", "chunked")
        self.send_header("x-fault-request-id", request_id)
        self.send_header("x-fault-mode", fault_mode)
        self.end_headers()

    def _write_sse(self, payload: dict) -> None:
        self._write_chunk(
            ("data: " + json.dumps(payload, separators=(",", ":")) + "\n\n").encode(
                "utf-8"
            )
        )

    def _write_chunk(self, payload: bytes) -> None:
        self.wfile.write(("%x\r\n" % len(payload)).encode("ascii"))
        self.wfile.write(payload)
        self.wfile.write(b"\r\n")
        self.wfile.flush()

    def _reset_connection(self, request_id: str) -> None:
        self._log({"event": "tcp_reset", "request_id": request_id})
        try:
            linger = struct.pack("ii", 1, 0)
            self.connection.setsockopt(socket.SOL_SOCKET, socket.SO_LINGER, linger)
        finally:
            self.close_connection = True
            self.connection.close()

    def _log(self, payload: dict) -> None:
        payload = {"ts": time.time(), **payload}
        print(json.dumps(payload, sort_keys=True), flush=True)

    def log_message(self, fmt: str, *args) -> None:
        self._log({"event": "access", "message": fmt % args})


def main() -> int:
    parser = argparse.ArgumentParser()
    parser.add_argument("--host", default="127.0.0.1")
    parser.add_argument("--port", type=int, default=8080)
    args = parser.parse_args()

    server = ThreadingHTTPServer((args.host, args.port), Handler)
    print(
        json.dumps(
            {
                "event": "startup",
                "host": args.host,
                "port": args.port,
                "models": [MODEL_RESET],
            },
            sort_keys=True,
        ),
        flush=True,
    )
    server.serve_forever()
    return 0


if __name__ == "__main__":
    raise SystemExit(main())

probe_litellm_stream.py:

#!/usr/bin/env python3
from __future__ import annotations

import argparse
import json
import os
import time
import urllib.error
import urllib.request
from typing import Any


def sse_payloads(raw: str) -> list[dict[str, Any]]:
    payloads: list[dict[str, Any]] = []
    lines: list[str] = []
    for raw_line in raw.splitlines():
        line = raw_line.rstrip("\r")
        if line.startswith("data:"):
            lines.append(line.split("data:", 1)[1].strip())
            continue
        if line == "" and lines:
            payload = "\n".join(lines)
            lines = []
            if payload == "[DONE]":
                continue
            try:
                parsed = json.loads(payload)
            except json.JSONDecodeError:
                continue
            if isinstance(parsed, dict):
                payloads.append(parsed)
    return payloads


def classify(status: int | None, raw: str, error: str | None) -> str:
    if error:
        return "transport_error"
    if status is not None and status >= 400:
        return f"http_{status}"

    events = sse_payloads(raw)
    deltas: list[dict[str, Any]] = []
    finish_reasons: list[Any] = []
    for event in events:
        for choice in event.get("choices") or []:
            if not isinstance(choice, dict):
                continue
            delta = choice.get("delta")
            if isinstance(delta, dict):
                deltas.append(delta)
            if "finish_reason" in choice:
                finish_reasons.append(choice.get("finish_reason"))

    has_role = any(delta.get("role") for delta in deltas)
    has_content = any(delta.get("content") for delta in deltas)
    has_tool_calls = any(delta.get("tool_calls") for delta in deltas)
    has_empty_stop = any(
        delta == {} and reason == "stop"
        for delta, reason in zip(deltas, finish_reasons, strict=False)
    )

    if has_empty_stop:
        if has_content or has_role or has_tool_calls:
            return "partial_stream_then_synthetic_stop"
        return "true_empty_stop"
    if has_content:
        if '"error"' in raw:
            return "content_then_stream_error"
        return "content_then_incomplete_or_done"
    if has_role:
        if '"error"' in raw:
            return "role_only_then_stream_error"
        return "role_only_then_incomplete_or_done"
    return "other"


def call_once(
    base_url: str,
    model: str,
    timeout: float,
    fault_chunk_count: int,
    fault_fin: bool,
) -> dict[str, Any]:
    url = base_url.rstrip("/") + "/chat/completions"
    body = {
        "model": model,
        "messages": [{"role": "user", "content": "hi"}],
        "stream": True,
        "metadata": {"fault_chunk_count": fault_chunk_count},
        "fault_chunk_count": fault_chunk_count,
        "fault_fin": fault_fin,
    }
    started = time.time()
    headers = {"Content-Type": "application/json"}
    probe_key = os.environ.get("LITELLM_PROBE_KEY")
    if probe_key:
        headers["Authorization"] = f"Bearer {probe_key}"
    request = urllib.request.Request(
        url,
        data=json.dumps(body).encode("utf-8"),
        headers=headers,
        method="POST",
    )
    status: int | None = None
    raw = ""
    error = None
    try:
        with urllib.request.urlopen(request, timeout=timeout) as response:
            status = response.status
            raw = response.read().decode("utf-8", errors="replace")
    except urllib.error.HTTPError as exc:
        status = exc.code
        raw = exc.read().decode("utf-8", errors="replace")
    except Exception as exc:  # noqa: BLE001 - repro script should report all failures.
        error = repr(exc)

    return {
        "model": model,
        "fault_chunk_count": fault_chunk_count,
        "status": status,
        "class": classify(status, raw, error),
        "elapsed_sec": round(time.time() - started, 3),
        "error": error,
        "raw": raw,
    }


def main() -> int:
    parser = argparse.ArgumentParser()
    parser.add_argument("--base-url", default="http://127.0.0.1:4000/v1")
    parser.add_argument("--timeout", type=float, default=10)
    parser.add_argument("--model", action="append")
    parser.add_argument(
        "--fault-chunk-count",
        type=int,
        action="append",
        help="Number of content chunks the downstream sends before resetting.",
    )
    parser.add_argument("--fault-fin", action="store_true")
    args = parser.parse_args()

    models = args.model or ["fault-reset-after-partial-200"]
    chunk_counts = args.fault_chunk_count or [0, 50]
    for model in models:
        for chunk_count in chunk_counts:
            result = call_once(args.base_url, model, args.timeout, chunk_count, args.fault_fin)
            print("=" * 80)
            print(
                json.dumps({k: v for k, v in result.items() if k != "raw"}, indent=2)
            )
            print("--- raw stream ---")
            print(result["raw"])

    return 0


if __name__ == "__main__":
    raise SystemExit(main())

Type

🐛 Bug Fix

Changes

AiohttpResponseStream.__aiter__ in the aiohttp transport caught aiohttp.ClientPayloadError, RuntimeError("Connection closed."), and TransferEncodingError during body iteration and returned as if the body had completed normally. For a streaming request this means an upstream TCP reset mid-response looks like a clean end of stream, so CustomStreamWrapper fabricates a final chunk with finish_reason: "stop" (plus a usage chunk when stream_options.include_usage is set) and the client receives a well-formed but empty or truncated HTTP 200 stream with no indication anything failed. No failure is logged and no router retry or fallback ever triggers. The transport now maps all three to httpx.ReadError (chaining the original exception) instead of swallowing them; the connection-release finally from #30192 is unchanged

Those swallows were originally added (#11162, #11561, #16294) because some providers close or reset the connection sloppily after delivering a complete response, and erroring those streams at the tail would be a regression. That concern is handled at the layer that actually knows whether the response was complete: CustomStreamWrapper.__anext__ now treats httpx.ReadError / httpx.RemoteProtocolError as a graceful end of stream when the provider's finish_reason has already been received, and as a real failure (failure logging plus MidStreamFallbackError, so router retries and fallbacks engage) when it has not. Streams that end with [DONE] never read past it, so they are unaffected either way

The Responses API streaming iterator is the one other consumer that reads its SSE stream all the way to EOF (its terminal signal is a response.completed event, not [DONE]), so it relied on the same transport swallow when a provider closes with broken framing after the final event. It now applies the same rule as the wrapper, in both the async and sync iterators: httpx.ReadError / httpx.RemoteProtocolError after a terminal event (response.completed, response.incomplete, response.failed) ends the stream cleanly, and before one it remains a real failure (df60e36)

To let both the end-of-stream path and the new post-finish path share one implementation, the body of the StopAsyncIteration handler in __anext__ moved verbatim into _finalize_completed_stream, and the duplicated failure-logging block into _log_stream_failure_and_raise. No behavior change for existing paths

Tests: the two transport tests that pinned the old swallowing behavior are inverted into regression tests asserting httpx.ReadError is raised (mid-stream, before the first chunk, on RuntimeError("Connection closed."), and on raw TransferEncodingError, with the response still closed and unrelated RuntimeErrors untouched), and two new CustomStreamWrapper tests pin the split: a transport read error after the finish chunk completes the stream cleanly with the provider's own finish_reason, and one before any finish chunk raises MidStreamFallbackError with no fabricated finish_reason ever emitted. Six responses-iterator tests pin the same split on that surface: clean end after response.completed for both ReadError and RemoteProtocolError, a raise before any terminal event, each for the async and sync iterators

One unrelated commit to keep CI deterministic: base commit 4a81ec4 added mcp_rpm_limit to UpdateTeamRequest without documenting it in update_team's docstring, and the api-docs check only catches that when directory walk order lets team_endpoints.py shadow the legacy update_team shim in model_management_endpoints.py, so the code-quality job failed on a coin flip per run. e14da65 adds the missing docstring line plus the dashboard schema types regenerated from it

Final Attestation

  • The tests check the right things, including the edge cases, and regressions in the respective real-world customer use-cases are not possible after this PR

@codecov

codecov Bot commented Jul 14, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 96.77419% with 2 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
litellm/litellm_core_utils/streaming_handler.py 95.65% 2 Missing ⚠️

📢 Thoughts on this report? Let us know!

@greptile-apps

greptile-apps Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR fixes a silent data-loss bug where upstream TCP connection resets during streaming were swallowed by the aiohttp transport layer, causing CustomStreamWrapper to fabricate a clean finish_reason: "stop" response rather than surfacing the failure.

  • Transport layer fix (aiohttp_transport.py): aiohttp.ClientPayloadError, RuntimeError("Connection closed."), and TransferEncodingError previously returned silently from AiohttpResponseStream.__aiter__, making connection resets look like clean end-of-stream. They now map to httpx.ReadError (chaining the original exception), allowing the caller to distinguish genuine transport failures from normal stream completion.
  • Wrapper layer fix (streaming_handler.py): CustomStreamWrapper.__anext__ now catches httpx.ReadError/RemoteProtocolError and applies a split: if the provider's finish_reason was already received (received_finish_reason is not None), the error is treated as sloppy-close and the stream ends cleanly via the extracted _finalize_completed_stream helper; if the finish chunk has not yet been received, it logs the failure and raises MidStreamFallbackError so router retries and fallbacks engage. The same split is applied symmetrically in both async/sync ResponsesAPIStreamingIterator paths (terminal event = response.completed/incomplete/failed).

Confidence Score: 5/5

Safe to merge. The change targets a well-isolated bug path (aiohttp transport swallowing connection resets), the fix is applied at two distinct layers with a clear discriminant for post-finish vs mid-stream errors, and every modified behavior is covered by new or inverted regression tests.

The root-cause fix in the transport layer is minimal and surgical. The wrapper-layer split between post-finish and mid-stream errors relies on received_finish_reason which is set atomically inside chunk_creator, making the invariant sound. All three previously-silenced error shapes are now covered by explicit tests asserting httpx.ReadError, and the two new CustomStreamWrapper tests pin both sides of the split. The ResponsesAPIStreamingIterator changes apply the same pattern symmetrically for async and sync paths.

No files require special attention. The core logic is concentrated in streaming_handler.py and aiohttp_transport.py, both of which are well-tested by the accompanying test changes.

Important Files Changed

Filename Overview
litellm/llms/custom_httpx/aiohttp_transport.py Removes the three silent-swallow clauses (ClientPayloadError, RuntimeError('Connection closed.'), TransferEncodingError) and maps them to httpx.ReadError instead; ClientPayloadError is now handled by the existing map_aiohttp_exceptions() context manager which already maps it to httpx.ReadError. The finally connection-release block is unchanged.
litellm/litellm_core_utils/streaming_handler.py Adds except (httpx.ReadError, httpx.RemoteProtocolError) handler to anext with a post-finish vs mid-stream split; extracts the StopAsyncIteration cleanup block into _finalize_completed_stream and the failure-logging block into _log_stream_failure_and_raise with no behavioral change to existing paths.
litellm/responses/streaming_iterator.py Applies the same post-finish / mid-stream split to both ResponsesAPIStreamingIterator.anext and SyncResponsesAPIStreamingIterator.next, using self.completed_response is None as the discriminant for whether a terminal event was received.
tests/test_litellm/llms/custom_httpx/test_aiohttp_transport.py Inverts two previously-swallow tests into regression guards asserting httpx.ReadError is raised; adds three new tests covering RuntimeError('Connection closed.'), unrelated RuntimeError pass-through, and raw TransferEncodingError. Also fixes a 0 or default falsy-zero bug in MockContent.exception_at_chunk.
tests/test_litellm/litellm_core_utils/test_streaming_handler.py Adds two new wrapper-level tests: ReadError after the provider finish chunk ends the stream cleanly (correct finish_reason delivered, no fabricated stop), and ReadError before any finish chunk raises MidStreamFallbackError with no fabricated finish_reason.
tests/test_litellm/responses/test_streaming_iterator.py Adds six new tests covering ReadError/RemoteProtocolError after a response.completed event (clean end) and before any terminal event (raises) for both async and sync iterators; refactors the helper to accept an optional trailing error.
litellm/proxy/management_endpoints/team_endpoints.py Adds the missing mcp_rpm_limit docstring line to update_team, fixing a non-deterministic CI failure in the api-docs check.
ui/litellm-dashboard/src/lib/http/schema.d.ts Auto-generated schema type updated to include the mcp_rpm_limit parameter description in the update_team endpoint definition.

Reviews (5): Last reviewed commit: "docs(proxy): document mcp_rpm_limit in u..." | Re-trigger Greptile

Comment thread litellm/litellm_core_utils/streaming_handler.py
Comment thread litellm/litellm_core_utils/streaming_handler.py
@codspeed-hq

codspeed-hq Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Merging this PR will not alter performance

✅ 31 untouched benchmarks


Comparing litellm_fix_stream_reset_empty_200 (40aeb33) with litellm_internal_staging (582907d)1

Open in CodSpeed

Footnotes

  1. No successful run was found on litellm_internal_staging (ebdf0bb) during the generation of this report, so 582907d was used instead as the comparison base. There might be some changes unrelated to this pull request in this report.

@mateo-berri

Copy link
Copy Markdown
Contributor Author

@greptileai

@mateo-berri

Copy link
Copy Markdown
Contributor Author

@greptileai

@mateo-berri

Copy link
Copy Markdown
Contributor Author

@greptileai

EkkoG added a commit to EkkoG/litellm that referenced this pull request Jul 16, 2026
@mateo-berri
mateo-berri enabled auto-merge July 16, 2026 19:24
@mateo-berri
mateo-berri merged commit fba7ac4 into litellm_internal_staging Jul 16, 2026
125 of 126 checks passed
@mateo-berri
mateo-berri deleted the litellm_fix_stream_reset_empty_200 branch July 16, 2026 19:43
doonga pushed a commit to greyrock-labs/home-ops that referenced this pull request Jul 29, 2026
…4.0) (#201)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ghcr.io/berriai/litellm](https://images.chainguard.dev/directory/image/wolfi-base/overview) ([source](https://github.com/BerriAI/litellm)) | minor | `v1.93.0` → `v1.94.0` |

---

### Release Notes

<details>
<summary>BerriAI/litellm (ghcr.io/berriai/litellm)</summary>

### [`v1.94.0`](https://github.com/BerriAI/litellm/releases/tag/v1.94.0)

[Compare Source](https://github.com/BerriAI/litellm/compare/v1.94.0...v1.94.0)

##### Verify Docker Image Signature

All LiteLLM Docker images are signed with [cosign](https://docs.sigstore.dev/cosign/overview/). Every release is signed with the same key introduced in [commit `0112e53`](https://github.com/BerriAI/litellm/commit/0112e53046018d726492c814b3644b7d376029d0).

**Verify using the pinned commit hash (recommended):**

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

```bash
cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.94.0
```

**Verify using the release tag (convenience):**

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

```bash
cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.94.0/cosign.pub \
  ghcr.io/berriai/litellm:v1.94.0
```

Expected output:

```
The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key
```

***

##### What's Changed

- feat(ui): working Test Connection for the complexity auto router by [@&#8203;akapur99](https://github.com/akapur99) in [#&#8203;32950](https://github.com/BerriAI/litellm/pull/32950)
- fix(xecguard): use StandardLoggingGuardrailInformation in logging hook by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;32911](https://github.com/BerriAI/litellm/pull/32911)
- feat(ui): adopt openapi-react-query ($api) and convert useCustomers by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;32949](https://github.com/BerriAI/litellm/pull/32949)
- refactor(ui): colocate the mcp-servers view, keeping the shared mcp\_tools surface by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;32968](https://github.com/BerriAI/litellm/pull/32968)
- refactor(ui): convert endpoint usage charts to shadcn/recharts by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;32723](https://github.com/BerriAI/litellm/pull/32723)
- fix(proxy-auth): stop unrecognized model namespaces slipping through provider wildcard keys by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;32979](https://github.com/BerriAI/litellm/pull/32979)
- feat(router): random-pick multi-model complexity tiers by [@&#8203;krrish-berri-2](https://github.com/krrish-berri-2) in [#&#8203;32967](https://github.com/BerriAI/litellm/pull/32967)
- fix(xecguard): sanitize scan result before recording it for logging by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;32935](https://github.com/BerriAI/litellm/pull/32935)
- fix(auto\_router): filter embedding models in complexity tab dropdowns, require all tiers, inline validation by [@&#8203;akapur99](https://github.com/akapur99) in [#&#8203;32978](https://github.com/BerriAI/litellm/pull/32978)
- fix(anthropic): translate raw adaptive thinking for pre-4.6 models on chat completions and Bedrock Converse by [@&#8203;akapur99](https://github.com/akapur99) in [#&#8203;32944](https://github.com/BerriAI/litellm/pull/32944)
- feat(router): add Router(plugins=\[...]) routing-plugin pipeline by [@&#8203;krrish-berri-2](https://github.com/krrish-berri-2) in [#&#8203;32972](https://github.com/BerriAI/litellm/pull/32972)
- feat(router): soft-floor adaptive mode for complexity router by [@&#8203;krrish-berri-2](https://github.com/krrish-berri-2) in [#&#8203;32947](https://github.com/BerriAI/litellm/pull/32947)
- docs(github): add QA runbook section to the PR template by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;32965](https://github.com/BerriAI/litellm/pull/32965)
- fix(model\_cost): add supports\_reasoning: false to Gemini image generation models by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;32836](https://github.com/BerriAI/litellm/pull/32836)
- build(dev-env): add make bootstrap and unprovisioned-checkout preflight to pre-commit by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;32981](https://github.com/BerriAI/litellm/pull/32981)
- ci(ui): report only error-level knip findings in CI by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;32971](https://github.com/BerriAI/litellm/pull/32971)
- feat(batches): track cost for unmanaged Bedrock batches, generalize the flag by [@&#8203;Sameerlite](https://github.com/Sameerlite) in [#&#8203;32315](https://github.com/BerriAI/litellm/pull/32315)
- fix(guardrails): walk custom\_tool\_call\_output items in \_content\_utils by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;32969](https://github.com/BerriAI/litellm/pull/32969)
- fix: show and allow editing team model aliases after team creation by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33047](https://github.com/BerriAI/litellm/pull/33047)
- chore(deps): bump pillow to 12.3.0 to resolve osv-scan CVEs by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33093](https://github.com/BerriAI/litellm/pull/33093)
- feat(mcp): mint gateway-bound envelope at the token endpoint for dcr\_bridge oauth\_delegate by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;32828](https://github.com/BerriAI/litellm/pull/32828)
- fix(mcp): surface rejected delegate-auth upstream tokens as connect-time 401 by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;32741](https://github.com/BerriAI/litellm/pull/32741)
- fix(proxy): track unauthenticated pass-through requests in spend logs by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;32410](https://github.com/BerriAI/litellm/pull/32410)
- feat(lasso): send source.type for Used By attribution by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33090](https://github.com/BerriAI/litellm/pull/33090)
- fix(responses): continue MCP gateway tool turns from the final response and surface failures by [@&#8203;thibault-linktree](https://github.com/thibault-linktree) in [#&#8203;33025](https://github.com/BerriAI/litellm/pull/33025)
- fix(responses): continue MCP gateway tool turns from the final response and surface failures by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33099](https://github.com/BerriAI/litellm/pull/33099)
- fix(completion): forward aws credential kwargs into litellm\_params so the responses bridge keeps WIF auth by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;32956](https://github.com/BerriAI/litellm/pull/32956)
- fix(ui): respect litellm\_key\_header\_name in BYOK credential save and workflow runs fetches by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33103](https://github.com/BerriAI/litellm/pull/33103)
- refactor(ui): standardize debounce waits behind shared DEBOUNCE\_WAIT\_MS constant by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33040](https://github.com/BerriAI/litellm/pull/33040)
- feat(ui): rebuild the Virtual Keys table on the shared DataTable by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;32991](https://github.com/BerriAI/litellm/pull/32991)
- fix: redact async complete streaming response for custom callbacks by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33106](https://github.com/BerriAI/litellm/pull/33106)
- build(ui): bump [@&#8203;tanstack/react-pacer](https://github.com/tanstack/react-pacer) from 0.2.0 to 0.22.1 by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33041](https://github.com/BerriAI/litellm/pull/33041)
- fix(ui): address Virtual Keys redesign review nits by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33112](https://github.com/BerriAI/litellm/pull/33112)
- fix(openai/responses): clamp max\_output\_tokens below API minimum by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33098](https://github.com/BerriAI/litellm/pull/33098)
- fix(prometheus): read v3 rate limiter remaining values for per-key model gauges by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33119](https://github.com/BerriAI/litellm/pull/33119)
- fix(ui): drop w-full from page-content wrappers to remove 32px horizontal overflow by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33118](https://github.com/BerriAI/litellm/pull/33118)
- refactor(ui): migrate straightforward value debounces to react-pacer by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33042](https://github.com/BerriAI/litellm/pull/33042)
- feat(mcp): interactive SSO sign-in for dcr\_bridge oauth\_delegate DCR clients by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;32946](https://github.com/BerriAI/litellm/pull/32946)
- test(proxy): add regression tests for management\_endpoints edge cases by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;32976](https://github.com/BerriAI/litellm/pull/32976)
- fix(auto-router): correct Responses API tool\_choice shape and propagate alias litellm\_params by [@&#8203;krrish-berri-2](https://github.com/krrish-berri-2) in [#&#8203;32974](https://github.com/BerriAI/litellm/pull/32974)
- fix(ui): render the sidebar scrollbar with shadcn ScrollArea by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33124](https://github.com/BerriAI/litellm/pull/33124)
- refactor(ui): migrate callback debounce sites to react-pacer with regression tests by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33043](https://github.com/BerriAI/litellm/pull/33043)
- chore: add CODEOWNERS for ui and proxy UI build artifacts by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33131](https://github.com/BerriAI/litellm/pull/33131)
- feat(mcp): client-held refresh envelope for the dcr\_bridge oauth\_delegate flow by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;32980](https://github.com/BerriAI/litellm/pull/32980)
- feat(ui): rebuild the Teams table on the shared DataTable by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33128](https://github.com/BerriAI/litellm/pull/33128)
- fix(mcp): relay upstream OAuth token and DCR rejections instead of a generic 500 by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33113](https://github.com/BerriAI/litellm/pull/33113)
- fix(keys): persist key\_type so the UI shows correct key scope instead of "All Proxy Models" by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33115](https://github.com/BerriAI/litellm/pull/33115)
- feat(router): opt-in session affinity for complexity router by [@&#8203;krrish-berri-2](https://github.com/krrish-berri-2) in [#&#8203;33126](https://github.com/BerriAI/litellm/pull/33126)
- feat(prometheus): expose video duration and image count consumption metrics by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33138](https://github.com/BerriAI/litellm/pull/33138)
- test(e2e): otel trace completeness on /chat/completions by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33132](https://github.com/BerriAI/litellm/pull/33132)
- fix(sso): paginate through all pages when fetching service principal group assignments by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33149](https://github.com/BerriAI/litellm/pull/33149)
- test(e2e): otel trace completeness on /v1/messages by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33133](https://github.com/BerriAI/litellm/pull/33133)
- feat(ui): add adaptive routing settings to Auto-Router v2 by [@&#8203;krrish-berri-2](https://github.com/krrish-berri-2) in [#&#8203;33146](https://github.com/BerriAI/litellm/pull/33146)
- refactor(mcp): extract the dcr\_bridge token flow into bridge\_token\_flow\.py by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33141](https://github.com/BerriAI/litellm/pull/33141)
- chore: bump litellm 1.93.0 -> 1.94.0, litellm-enterprise 0.1.49 -> 0.1.50, litellm-proxy-extras 0.4.76 -> 0.4.77 by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33229](https://github.com/BerriAI/litellm/pull/33229)
- fix(proxy): route master key to team-scoped models by [@&#8203;kunal2002](https://github.com/kunal2002) in [#&#8203;32926](https://github.com/BerriAI/litellm/pull/32926)
- chore(deps): pin httplib2 and setuptools transitive floors by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33233](https://github.com/BerriAI/litellm/pull/33233)
- feat(ui): left-anchor the Create Key and Create Team CTAs by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33248](https://github.com/BerriAI/litellm/pull/33248)
- fix(anthropic/passthrough): drop incompatible temperature when downgrading adaptive thinking for pre-4.6 models by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33244](https://github.com/BerriAI/litellm/pull/33244)
- fix(guardrails): run apply\_guardrail-style model-level pre\_call guardrails at deployment hook by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33136](https://github.com/BerriAI/litellm/pull/33136)
- fix(proxy)!: enforce user budget on team keys (read-time + reservation) with UI opt-out by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;32005](https://github.com/BerriAI/litellm/pull/32005)
- fix(e2e): bound spend-log snapshots to a /spend/logs/v2 window by [@&#8203;mubashir1osmani](https://github.com/mubashir1osmani) in [#&#8203;33265](https://github.com/BerriAI/litellm/pull/33265)
- test(e2e): cover key rpm/tpm rate limiting, window reset, and pacing headers by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;32914](https://github.com/BerriAI/litellm/pull/32914)
- fix(anthropic): use native output capability by [@&#8203;krrish-berri-2](https://github.com/krrish-berri-2) in [#&#8203;33235](https://github.com/BerriAI/litellm/pull/33235)
- fix(ci): retry setup-uv installs to survive transient manifest fetch failures by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;33279](https://github.com/BerriAI/litellm/pull/33279)
- fix(proxy): never log raw virtual keys in key insertion debug output by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33268](https://github.com/BerriAI/litellm/pull/33268)
- fix(bedrock\_mantle): route xai.grok-4.3 via /openai/v1 frontier path by [@&#8203;marty-sullivan](https://github.com/marty-sullivan) in [#&#8203;33027](https://github.com/BerriAI/litellm/pull/33027)
- feat(pricing): add gemini-omni-flash-preview with video output token pricing by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;33274](https://github.com/BerriAI/litellm/pull/33274)
- fix(auth): scope the JWT enterprise gate to actual JWTs by [@&#8203;mubashir1osmani](https://github.com/mubashir1osmani) in [#&#8203;33296](https://github.com/BerriAI/litellm/pull/33296)
- fix(s3): sanitize slashes in response-id-derived object key file name by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33271](https://github.com/BerriAI/litellm/pull/33271)
- refactor(ui): migrate guardrails table onto shared DataTable by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33303](https://github.com/BerriAI/litellm/pull/33303)
- chore(ci): promote internal staging to main by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33308](https://github.com/BerriAI/litellm/pull/33308)
- feat(guardrails): streaming text transformation in generic\_guardrail\_api by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33110](https://github.com/BerriAI/litellm/pull/33110)
- test(e2e): cover model-aware mid-conversation system handling on Bedrock Invoke /v1/messages by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;32963](https://github.com/BerriAI/litellm/pull/32963)
- test(claude\_code): move the Claude Code compatibility matrix under tests/e2e by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;32548](https://github.com/BerriAI/litellm/pull/32548)
- chore(ci): sync litellm\_internal\_staging into daily OSS branch by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33337](https://github.com/BerriAI/litellm/pull/33337)
- feat(bedrock guardrails): add resource-less InvokeGuardrailChecks (detect-only) mode by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33299](https://github.com/BerriAI/litellm/pull/33299)
- Revert "chore(ci): sync litellm\_internal\_staging into daily OSS branch" by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33339](https://github.com/BerriAI/litellm/pull/33339)
- fix(websearch): intercept web search on the Responses API by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33129](https://github.com/BerriAI/litellm/pull/33129)
- fix(anthropic-adapter): drop empty content\_block\_delta events by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;33315](https://github.com/BerriAI/litellm/pull/33315)
- fix(mcp): persist discovered OAuth endpoints and keep last known good on failed re-discovery by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33286](https://github.com/BerriAI/litellm/pull/33286)
- test(e2e): otel trace completeness on streaming chat, messages, and responses (LIT-3787) by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33234](https://github.com/BerriAI/litellm/pull/33234)
- feat(router): resolve auto-router routing plugins from proxy YAML config by [@&#8203;krrish-berri-2](https://github.com/krrish-berri-2) in [#&#8203;33251](https://github.com/BerriAI/litellm/pull/33251)
- test(e2e): failed request error span carries the full untruncated message and status (LIT-4179) by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33304](https://github.com/BerriAI/litellm/pull/33304)
- refactor(ui): migrate tags table onto shared DataTable by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33314](https://github.com/BerriAI/litellm/pull/33314)
- fix(cli): surface actionable CLI SSO errors when CLI and proxy versions skew by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33309](https://github.com/BerriAI/litellm/pull/33309)
- feat(bedrock\_mantle): add GPT-5.6 sol/terra/luna to model cost map by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;33412](https://github.com/BerriAI/litellm/pull/33412)
- chore(codeowners): exempt generated schema.d.ts from UI ownership by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33411](https://github.com/BerriAI/litellm/pull/33411)
- feat(proxy): push-based OTLP billable-request metering for enterprise deployments by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;31592](https://github.com/BerriAI/litellm/pull/31592)
- fix(mcp): cap per-user OAuth token cache TTL at the token's own lifetime by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33346](https://github.com/BerriAI/litellm/pull/33346)
- feat(ui): move Caching out of Experimental into Developer Tools by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33432](https://github.com/BerriAI/litellm/pull/33432)
- chore(ci): promote internal staging to main by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33425](https://github.com/BerriAI/litellm/pull/33425)
- chore(ci): merge daily internal staging branch by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33335](https://github.com/BerriAI/litellm/pull/33335)
- feat(guardrails): add Compresr guardrail for query-aware context compression by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33295](https://github.com/BerriAI/litellm/pull/33295)
- fix(logging): preserve callback order in get\_combined\_callback\_list by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33005](https://github.com/BerriAI/litellm/pull/33005)
- fix(logging): redact assistant tool call arguments in spend logs by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33111](https://github.com/BerriAI/litellm/pull/33111)
- fix(anthropic): honor messages request timeout by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33418](https://github.com/BerriAI/litellm/pull/33418)
- fix(llm\_guard): apply sanitized prompt returned by moderation API to request by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33331](https://github.com/BerriAI/litellm/pull/33331)
- fix(logging): stop pinning large request payloads past request end by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33455](https://github.com/BerriAI/litellm/pull/33455)
- feat(guardrails): forward optional metadata on POST /guardrails/apply\_guardrail by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33067](https://github.com/BerriAI/litellm/pull/33067)
- build: raise requires-python cap to <3.15 so Python 3.14 installs current releases by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33438](https://github.com/BerriAI/litellm/pull/33438)
- feat(ui): add reusable BetaBadge and use it for Projects sidebar item by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33449](https://github.com/BerriAI/litellm/pull/33449)
- fix(mcp): discover missing OAuth scopes and token\_url when authorization\_url is set manually by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33317](https://github.com/BerriAI/litellm/pull/33317)
- feat(ui): show exact license expiration date in usage cards by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33478](https://github.com/BerriAI/litellm/pull/33478)
- test(claude\_code): rename misleading REPO\_ROOT to SUITE\_ROOT in test\_v0\_layout by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;33472](https://github.com/BerriAI/litellm/pull/33472)
- build(deps): update ddtrace to the 4.x line by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33484](https://github.com/BerriAI/litellm/pull/33484)
- fix(complexity\_router): return empty dict from \_classifier\_call\_metadata when metadata is absent by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33452](https://github.com/BerriAI/litellm/pull/33452)
- fix(ui/chat): resolve chat routes at render time so navigation works under server\_root\_path by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33446](https://github.com/BerriAI/litellm/pull/33446)
- fix(key management): enforce minimum custom key length and mask short keys in key\_name by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33462](https://github.com/BerriAI/litellm/pull/33462)
- chore(ui): remove unmounted UsageIndicator and the Hide Usage Indicator flag by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33482](https://github.com/BerriAI/litellm/pull/33482)
- test(e2e/claude\_code): add passthrough matrix row for the big-3 clouds and Anthropic API by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;33473](https://github.com/BerriAI/litellm/pull/33473)
- chore(ci): promote internal staging to main by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33491](https://github.com/BerriAI/litellm/pull/33491)
- fix(ui): stop sending the complexity-router pseudo-model to /health/test\_connection by [@&#8203;krrish-berri-2](https://github.com/krrish-berri-2) in [#&#8203;33498](https://github.com/BerriAI/litellm/pull/33498)
- feat(cli): add lite up/down to ambiently route Claude Code through the proxy by [@&#8203;krrish-berri-2](https://github.com/krrish-berri-2) in [#&#8203;33231](https://github.com/BerriAI/litellm/pull/33231)
- feat(complexity\_router): enable session\_affinity by default by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33500](https://github.com/BerriAI/litellm/pull/33500)
- fix(anthropic): stop 500 on combined thinking+signature streaming chunk by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33505](https://github.com/BerriAI/litellm/pull/33505)
- feat(autoroute): prompt for semantic keywords per tier in configure wizard by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33508](https://github.com/BerriAI/litellm/pull/33508)
- fix(cli/anthropic): unblock lite autoroute proxy deps, adaptive thinking, and thinking+signature streaming by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33507](https://github.com/BerriAI/litellm/pull/33507)
- test(ocr): use mistral-document-ai-2512 in azure\_ai OCR tests by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;33489](https://github.com/BerriAI/litellm/pull/33489)
- fix(guardrails): show YAML-defined guardrails in the Guardrail Monitor by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;32853](https://github.com/BerriAI/litellm/pull/32853)
- refactor(ui): migrate policies, deleted keys, deleted teams, budgets, and search tools tables onto shared DataTable by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33357](https://github.com/BerriAI/litellm/pull/33357)
- refactor(ui): migrate vector stores, prompts, and skills tables onto shared DataTable by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33343](https://github.com/BerriAI/litellm/pull/33343)
- test(e2e): datadog log delivery for successful chat, messages, and responses (LIT-4447) by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33415](https://github.com/BerriAI/litellm/pull/33415)
- fix(cli): make CLI output ASCII-only so it doesn't crash legacy Windows consoles by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33465](https://github.com/BerriAI/litellm/pull/33465)
- fix: remove dead user-cache lookup with None key in spend-update path by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33555](https://github.com/BerriAI/litellm/pull/33555)
- feat(helm): add per-component PodDisruptionBudget and topologySpreadConstraints to componentized chart by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33430](https://github.com/BerriAI/litellm/pull/33430)
- fix(e2e/claude\_code): unblock stage collection, align proxy env names, register compat models by [@&#8203;mubashir1osmani](https://github.com/mubashir1osmani) in [#&#8203;33433](https://github.com/BerriAI/litellm/pull/33433)
- fix(mcp): index authed request-time tools missing from the semantic filter startup index by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33318](https://github.com/BerriAI/litellm/pull/33318)
- fix(streaming): use provider-reported usage cost for OpenRouter streams by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;32255](https://github.com/BerriAI/litellm/pull/32255)
- feat(mcp): issuer-anchored OAuth discovery (RFC 8414 §3.3) to close the authorization-server mix-up by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33450](https://github.com/BerriAI/litellm/pull/33450)
- feat(logging): add user and team level spend and budget to StandardLoggingPayload metadata by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33459](https://github.com/BerriAI/litellm/pull/33459)
- fix(router): cast model\_info cost values to float in \_set\_model\_group\_info by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33556](https://github.com/BerriAI/litellm/pull/33556)
- chore(e2e): establish litellm\_e2e\_staging integration line by [@&#8203;mubashir1osmani](https://github.com/mubashir1osmani) in [#&#8203;33502](https://github.com/BerriAI/litellm/pull/33502)
- fix(ui): navigate to /ui/login/ with trailing slash via hard navigation by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33561](https://github.com/BerriAI/litellm/pull/33561)
- feat(logging): add structured budget fields to budget rejection failure logs by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33460](https://github.com/BerriAI/litellm/pull/33460)
- fix(streaming): surface upstream connection resets instead of empty 200 streams by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;33222](https://github.com/BerriAI/litellm/pull/33222)
- fix(proxy\_cli): reap orphaned prisma query-engine processes when a worker dies by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33424](https://github.com/BerriAI/litellm/pull/33424)
- test(reasoning\_effort\_grid): enable azure fable-5 and opus-4-8 grid cells by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;33485](https://github.com/BerriAI/litellm/pull/33485)
- build(deps): bump uvicorn lock to 0.51.0 so worker health-check and jitter flags take effect by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33574](https://github.com/BerriAI/litellm/pull/33574)
- fix(proxy): coerce default\_internal\_user\_params.max\_budget to float on config load by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;32434](https://github.com/BerriAI/litellm/pull/32434)
- fix(router): honor per-request routing\_strategy from key/team router\_settings by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33429](https://github.com/BerriAI/litellm/pull/33429)
- fix(redis): honor ssl value instead of key presence when building async connection pool by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;32590](https://github.com/BerriAI/litellm/pull/32590)
- fix(langfuse\_otel): build per-request OTLP exporter from key and team dynamic Langfuse credentials by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;32437](https://github.com/BerriAI/litellm/pull/32437)
- ci: run zizmor and proxy-db unit tests on PRs targeting litellm\_ branches by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;33568](https://github.com/BerriAI/litellm/pull/33568)
- fix(router): apply team/key enable\_tag\_filtering to tag routing by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33436](https://github.com/BerriAI/litellm/pull/33436)
- feat(proxy): add disable\_auto\_add\_proxy\_admin\_to\_teams flag by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33563](https://github.com/BerriAI/litellm/pull/33563)
- fix(proxy): stop stale auth cache re-publish to Redis so key updates propagate across replicas by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33565](https://github.com/BerriAI/litellm/pull/33565)
- feat(e2e): emit structured E2E\_RESULT lines for package status history by [@&#8203;mubashir1osmani](https://github.com/mubashir1osmani) in [#&#8203;33578](https://github.com/BerriAI/litellm/pull/33578)
- chore: bump litellm-enterprise 0.1.50 -> 0.1.51, litellm-proxy-extras 0.4.77 -> 0.4.78 by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33571](https://github.com/BerriAI/litellm/pull/33571)
- fix(docker): restore litellm-proxy-extras source dir in runtime images by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33592](https://github.com/BerriAI/litellm/pull/33592)
- feat(ui): require embedding model for semantic auto router by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33313](https://github.com/BerriAI/litellm/pull/33313)
- feat(scim): ingest and round-trip SCIM entitlements and roles user attributes by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33587](https://github.com/BerriAI/litellm/pull/33587)
- refactor(ui): migrate 5 simple tables onto shared DataTable by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33548](https://github.com/BerriAI/litellm/pull/33548)
- fix(model\_armor): restore reference attachments via skip\_unscannable\_attachments and remove the attachment count cap by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33554](https://github.com/BerriAI/litellm/pull/33554)
- fix(mcp): keep the MCP reference intact when the semantic filter narrows tools by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33584](https://github.com/BerriAI/litellm/pull/33584)
- fix(sso): stop enforcing UI session budget on CLI login tokens by [@&#8203;mubashir1osmani](https://github.com/mubashir1osmani) in [#&#8203;33312](https://github.com/BerriAI/litellm/pull/33312)
- test: e2e staging leftovers by [@&#8203;mubashir1osmani](https://github.com/mubashir1osmani) in [#&#8203;33613](https://github.com/BerriAI/litellm/pull/33613)
- test(e2e/claude\_code): add GPT-5.6 Sol/Terra/Luna columns for OpenAI, Azure OpenAI, and Bedrock Mantle by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;33474](https://github.com/BerriAI/litellm/pull/33474)
- test(e2e): otel streaming spans record a real ttft below span duration by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33588](https://github.com/BerriAI/litellm/pull/33588)
- fix(mcp): make the preemptive-401 OAuth challenge decision mode-aware by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33586](https://github.com/BerriAI/litellm/pull/33586)
- fix(ui): show all teams in policy attachment form for admins by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33628](https://github.com/BerriAI/litellm/pull/33628)
- refactor(ui): migrate AI Hub, public hub, and MCP Toolsets tables onto shared DataTable by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33629](https://github.com/BerriAI/litellm/pull/33629)
- test(e2e): datadog log delivery for streamed routes, read back from the real datadog api by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33566](https://github.com/BerriAI/litellm/pull/33566)
- chore(ci): promote internal staging to main by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33640](https://github.com/BerriAI/litellm/pull/33640)
- fix(vertex\_ai): surface Gemini grounding toolUsePromptTokenCount in Usage by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33533](https://github.com/BerriAI/litellm/pull/33533)
- test(e2e): harness fixes for stage job green (skips + router/UI/budget) by [@&#8203;mubashir1osmani](https://github.com/mubashir1osmani) in [#&#8203;33634](https://github.com/BerriAI/litellm/pull/33634)
- fix(router): resolve prompt cache minimum per model instead of a flat 1024 by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33637](https://github.com/BerriAI/litellm/pull/33637)
- fix(logging): classify async anthropic\_messages and generate\_content as async by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33589](https://github.com/BerriAI/litellm/pull/33589)
- fix(ui): remove Chat item from dashboard leftnav by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33647](https://github.com/BerriAI/litellm/pull/33647)
- fix(router): tag-aware pre-routing strategy selection for shared model\_name by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33691](https://github.com/BerriAI/litellm/pull/33691)
- fix(proxy): enforce max\_parallel\_requests as a per-slot concurrency gauge by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;32441](https://github.com/BerriAI/litellm/pull/32441)
- fix(proxy): stop treating upstream model body field as a LiteLLM model on auth-enforced pass-through routes by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33710](https://github.com/BerriAI/litellm/pull/33710)
- fix(mcp): expand toolset grants in shared permission primitives so tools/call honors them by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33612](https://github.com/BerriAI/litellm/pull/33612)
- feat(complexity-router): user-triggered escalation keywords by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33656](https://github.com/BerriAI/litellm/pull/33656)
- fix(fireworks\_ai): bill prompt-cache hits at cache\_read rate by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33714](https://github.com/BerriAI/litellm/pull/33714)
- fix(pricing): mark realtime-only gpt-realtime models as mode realtime by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33728](https://github.com/BerriAI/litellm/pull/33728)
- fix(rag): track LLM completion usage and spend for /v1/rag/query by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;32438](https://github.com/BerriAI/litellm/pull/32438)
- feat(anthropic): add enable\_anthropic\_prompt\_caching for automatic cache\_control injection by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33573](https://github.com/BerriAI/litellm/pull/33573)
- fix(anthropic): self-heal on missing thinking-signature errors from Bedrock/Vertex by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33719](https://github.com/BerriAI/litellm/pull/33719)
- fix(proxy): resolve router\_settings.plugins dotted paths and load plugins from installed packages by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33644](https://github.com/BerriAI/litellm/pull/33644)
- test(e2e): budget refusals are 429 for bare keys and team caps block every team key by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33632](https://github.com/BerriAI/litellm/pull/33632)
- feat(router): add router plugin reference catalog by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33746](https://github.com/BerriAI/litellm/pull/33746)
- test(e2e): assert an org budget block is a 429 naming the organization by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33638](https://github.com/BerriAI/litellm/pull/33638)
- fix(proxy): bill partial streamed spend when the client disconnects mid-stream by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33736](https://github.com/BerriAI/litellm/pull/33736)
- test(e2e): delete unreferenced Grafana panel docs by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33743](https://github.com/BerriAI/litellm/pull/33743)
- docs(tests/e2e): align skip-vs-fail docs with the hard-fail contract and scope the no-unit-tests rule by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33755](https://github.com/BerriAI/litellm/pull/33755)
- refactor(e2e): replace bespoke result reporter with standard JUnit report by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33758](https://github.com/BerriAI/litellm/pull/33758)
- test(e2e): user budget across keys and team member budget isolation by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33745](https://github.com/BerriAI/litellm/pull/33745)
- refactor(e2e): remove bob\_the\_builder; drive remediation from a Grafana alert (provisioned outside the repo) by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33749](https://github.com/BerriAI/litellm/pull/33749)
- feat(mcp): per-server outcomes for aggregate tools/list and truthful single-server REST statuses by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33153](https://github.com/BerriAI/litellm/pull/33153)
- test(e2e): mcp suite for key-without-access denial by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33752](https://github.com/BerriAI/litellm/pull/33752)
- chore(ci): merge oss branch by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33784](https://github.com/BerriAI/litellm/pull/33784)
- chore(ci): merge oss branch - July 17th by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33793](https://github.com/BerriAI/litellm/pull/33793)
- fix(ui): migrate tag deletion to shared DeleteResourceModal by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33795](https://github.com/BerriAI/litellm/pull/33795)
- build(rust): raise pyo3 to 0.29 so the native bridge compiles on Python 3.14 by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33798](https://github.com/BerriAI/litellm/pull/33798)
- chore(guardrails): remove docstring from singulr module for consistency by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33800](https://github.com/BerriAI/litellm/pull/33800)
- fix(ui): stop credential edit from persisting the masked api key by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33797](https://github.com/BerriAI/litellm/pull/33797)
- build(deps): allow redisvl, pypdf, and openapi-core on Python 3.14 by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33801](https://github.com/BerriAI/litellm/pull/33801)
- test(proxy): make streaming-cancel mocks awaitable for the disconnect slot release by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33802](https://github.com/BerriAI/litellm/pull/33802)
- test(e2e): a member's team budget cuts off only that member's key by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33718](https://github.com/BerriAI/litellm/pull/33718)
- test(e2e): a user's max\_budget follows the person across personal and team keys by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33762](https://github.com/BerriAI/litellm/pull/33762)
- test(e2e): skip flaky OpenAI GPT cells; raise multi-window max\_tokens by [@&#8203;mubashir1osmani](https://github.com/mubashir1osmani) in [#&#8203;33799](https://github.com/BerriAI/litellm/pull/33799)
- chore: remove accidentally committed dist tarball and ignore dist/ by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33805](https://github.com/BerriAI/litellm/pull/33805)
- fix(passthrough): stop classifying plain 'predict'/'search' paths as Vertex by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33658](https://github.com/BerriAI/litellm/pull/33658)
- build(deps): bump mcp lock to 1.28.1 to clear image-scan findings by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33803](https://github.com/BerriAI/litellm/pull/33803)
- test(pricing): pin the realtime mode assertion to the bundled cost map by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33806](https://github.com/BerriAI/litellm/pull/33806)
- fix(proxy): derive session id from Anthropic metadata.user\_id for session affinity by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33723](https://github.com/BerriAI/litellm/pull/33723)
- test(e2e): budget reset diagonal for team, org, user, and [#&#8203;32005](https://github.com/BerriAI/litellm/issues/32005) team-member keys by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33771](https://github.com/BerriAI/litellm/pull/33771)
- fix(proxy): source /v1/models token limits from the cost map instead of Router.get\_model\_group\_info by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33721](https://github.com/BerriAI/litellm/pull/33721)
- fix(fireworks\_ai): correct glm-5p2 prompt-cache read price to $0.14/1M by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33796](https://github.com/BerriAI/litellm/pull/33796)
- feat(proxy): add x-litellm-model-name response header with deployment model string by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33698](https://github.com/BerriAI/litellm/pull/33698)
- feat: add Straiker guardrail integration by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33781](https://github.com/BerriAI/litellm/pull/33781)
- fix(vertex\_ai): exclude Gemini Google Search grounding tokens from input token billing by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33742](https://github.com/BerriAI/litellm/pull/33742)
- feat(fireworks\_ai): map litellm session id to x-session-affinity header for prompt caching by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33717](https://github.com/BerriAI/litellm/pull/33717)
- feat(ui): configure Anthropic automatic prompt caching from the Admin UI by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33581](https://github.com/BerriAI/litellm/pull/33581)
- fix(router): enforce context-window pre-call checks for Responses API input by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33706](https://github.com/BerriAI/litellm/pull/33706)
- fix(otel): restore proxy-level error.\* attributes on v2 failure spans (LIT-4179) by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33664](https://github.com/BerriAI/litellm/pull/33664)
- fix(mcp): persist config.yaml DCR clients in a server-scoped store so refresh survives token expiry by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33768](https://github.com/BerriAI/litellm/pull/33768)
- refactor(ui): consolidate Add/Edit credential modals into one CredentialModal by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;32572](https://github.com/BerriAI/litellm/pull/32572)
- feat(mcp): add ID-JAG (identity assertion authorization grant) support for MCP egress by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;31516](https://github.com/BerriAI/litellm/pull/31516)
- refactor(ui): migrate policy attachments table onto shared DataTable by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33827](https://github.com/BerriAI/litellm/pull/33827)
- docs(litellm-rust): add provider coding standards by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33833](https://github.com/BerriAI/litellm/pull/33833)
- test(e2e): rename Gateway to ProxyClient and expose it as a session-scoped pytest fixture by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33750](https://github.com/BerriAI/litellm/pull/33750)
- feat(messages): route Azure Anthropic /messages through Rust behind rust:true by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33616](https://github.com/BerriAI/litellm/pull/33616)
- test(e2e): add Locust throughput load test that runs last by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33748](https://github.com/BerriAI/litellm/pull/33748)
- fix(proxy): resolve team wildcard credentials for vector store files by [@&#8203;shivamrawat1](https://github.com/shivamrawat1) in [#&#8203;33649](https://github.com/BerriAI/litellm/pull/33649)
- refactor(e2e): fold claude\_code HTTP probes onto shared ProxyClient methods by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33760](https://github.com/BerriAI/litellm/pull/33760)
- test(e2e): harden stage flakes for batches, UI, and MCP by [@&#8203;mubashir1osmani](https://github.com/mubashir1osmani) in [#&#8203;33831](https://github.com/BerriAI/litellm/pull/33831)
- fix(e2e): migrate load suite from e2e\_gateway to ProxyClient by [@&#8203;mubashir1osmani](https://github.com/mubashir1osmani) in [#&#8203;33839](https://github.com/BerriAI/litellm/pull/33839)
- chore(e2e): remove tests/e2e/docker-compose.yml by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33837](https://github.com/BerriAI/litellm/pull/33837)
- test(e2e): cover /v1/responses openai basic nonstream and stream by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33830](https://github.com/BerriAI/litellm/pull/33830)
- test(e2e): cover /v1/responses openai cost\_logged and tool\_use by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33835](https://github.com/BerriAI/litellm/pull/33835)
- test(e2e): cover /v1/responses OpenAI vision and Anthropic basic by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33838](https://github.com/BerriAI/litellm/pull/33838)
- test(e2e): spendlog cost for streaming /v1/messages via responses bridge by [@&#8203;yassin-berriai](https://github.com/yassin-berriai) in [#&#8203;33753](https://github.com/BerriAI/litellm/pull/33753)
- fix(docker): bake prisma CLI and engines at a fixed path so fresh-DB migrations work for any uid offline by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33853](https://github.com/BerriAI/litellm/pull/33853)
- feat(chat-ui): add personal Logs view scoped to the current user by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33829](https://github.com/BerriAI/litellm/pull/33829)
- chore: bump litellm-proxy-extras 0.4.78 -> 0.4.79 by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33855](https://github.com/BerriAI/litellm/pull/33855)
- docs(litellm-rust): require the official Rust Style Guide in agent rules by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33867](https://github.com/BerriAI/litellm/pull/33867)
- fix(router): treat malformed configured token limits as absent on /v1/models by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33864](https://github.com/BerriAI/litellm/pull/33864)
- chore: rebuild admin UI bundle for the rc release by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33857](https://github.com/BerriAI/litellm/pull/33857)
- docs(rust): add provider abstraction standards by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33865](https://github.com/BerriAI/litellm/pull/33865)
- chore(ci): promote internal staging to main by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33868](https://github.com/BerriAI/litellm/pull/33868)
- chore(release): backport [#&#8203;33929](https://github.com/BerriAI/litellm/issues/33929) to rc/1.94.0 by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;34033](https://github.com/BerriAI/litellm/pull/34033)
- chore(release): backport [#&#8203;33810](https://github.com/BerriAI/litellm/issues/33810), [#&#8203;33733](https://github.com/BerriAI/litellm/issues/33733) to rc/1.94.0 and bump litellm-proxy-extras to 0.4.79.post1 by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;34215](https://github.com/BerriAI/litellm/pull/34215)
- chore(ui): rebuild Next.js bundle on rc/1.94.0 so the Cost Optimization page ships by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;34216](https://github.com/BerriAI/litellm/pull/34216)
- chore(release): backport auth, CLI SSO and guardrail fixes to rc/1.94.0 and refresh flagged dependencies by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;34640](https://github.com/BerriAI/litellm/pull/34640)
- chore(release): backport [#&#8203;33899](https://github.com/BerriAI/litellm/issues/33899), [#&#8203;33978](https://github.com/BerriAI/litellm/issues/33978), [#&#8203;34582](https://github.com/BerriAI/litellm/issues/34582), [#&#8203;34675](https://github.com/BerriAI/litellm/issues/34675) to rc/1.94.0 and bump litellm-proxy-extras to 0.4.79.post2 by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;34855](https://github.com/BerriAI/litellm/pull/34855)
- fix(ui): backport cache leakage card layout fix to rc/1.94.0 by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;34964](https://github.com/BerriAI/litellm/pull/34964)
- fix(ui): add missing cost-optimization page description on rc/1.94.0 by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;34967](https://github.com/BerriAI/litellm/pull/34967)
- feat(ui): mark Cost Optimization as beta in the left nav ([#&#8203;34984](https://github.com/BerriAI/litellm/issues/34984)) by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;34987](https://github.com/BerriAI/litellm/pull/34987)
- chore: rebuild Admin UI bundle for v1.94.0 by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;34982](https://github.com/BerriAI/litellm/pull/34982)
- fix(cost-optimization): backport the savings chart axis fix and methodology popovers to rc/1.94.0 by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;34994](https://github.com/BerriAI/litellm/pull/34994)
- chore: rebuild Admin UI bundle for rc/1.94.0 by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;34995](https://github.com/BerriAI/litellm/pull/34995)

**Full Changelog**: <https://github.com/BerriAI/litellm/compare/v1.93.0...v1.94.0>

### [`v1.94.0`](https://github.com/BerriAI/litellm/releases/tag/v1.94.0)

##### Verify Docker Image Signature

All LiteLLM Docker images are signed with [cosign](https://docs.sigstore.dev/cosign/overview/). Every release is signed with the same key introduced in [commit `0112e53`](https://github.com/BerriAI/litellm/commit/0112e53046018d726492c814b3644b7d376029d0).

**Verify using the pinned commit hash (recommended):**

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

```bash
cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.94.0
```

**Verify using the release tag (convenience):**

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

```bash
cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.94.0/cosign.pub \
  ghcr.io/berriai/litellm:v1.94.0
```

Expected output:

```
The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key
```

***

##### What's Changed

- feat(ui): working Test Connection for the complexity auto router by [@&#8203;akapur99](https://github.com/akapur99) in [#&#8203;32950](https://github.com/BerriAI/litellm/pull/32950)
- fix(xecguard): use StandardLoggingGuardrailInformation in logging hook by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;32911](https://github.com/BerriAI/litellm/pull/32911)
- feat(ui): adopt openapi-react-query ($api) and convert useCustomers by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;32949](https://github.com/BerriAI/litellm/pull/32949)
- refactor(ui): colocate the mcp-servers view, keeping the shared mcp\_tools surface by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;32968](https://github.com/BerriAI/litellm/pull/32968)
- refactor(ui): convert endpoint usage charts to shadcn/recharts by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;32723](https://github.com/BerriAI/litellm/pull/32723)
- fix(proxy-auth): stop unrecognized model namespaces slipping through provider wildcard keys by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;32979](https://github.com/BerriAI/litellm/pull/32979)
- feat(router): random-pick multi-model complexity tiers by [@&#8203;krrish-berri-2](https://github.com/krrish-berri-2) in [#&#8203;32967](https://github.com/BerriAI/litellm/pull/32967)
- fix(xecguard): sanitize scan result before recording it for logging by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;32935](https://github.com/BerriAI/litellm/pull/32935)
- fix(auto\_router): filter embedding models in complexity tab dropdowns, require all tiers, inline validation by [@&#8203;akapur99](https://github.com/akapur99) in [#&#8203;32978](https://github.com/BerriAI/litellm/pull/32978)
- fix(anthropic): translate raw adaptive thinking for pre-4.6 models on chat completions and Bedrock Converse by [@&#8203;akapur99](https://github.com/akapur99) in [#&#8203;32944](https://github.com/BerriAI/litellm/pull/32944)
- feat(router): add Router(plugins=\[...]) routing-plugin pipeline by [@&#8203;krrish-berri-2](https://github.com/krrish-berri-2) in [#&#8203;32972](https://github.com/BerriAI/litellm/pull/32972)
- feat(router): soft-floor adaptive mode for complexity router by [@&#8203;krrish-berri-2](https://github.com/krrish-berri-2) in [#&#8203;32947](https://github.com/BerriAI/litellm/pull/32947)
- docs(github): add QA runbook section to the PR template by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;32965](https://github.com/BerriAI/litellm/pull/32965)
- fix(model\_cost): add supports\_reasoning: false to Gemini image generation models by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;32836](https://github.com/BerriAI/litellm/pull/32836)
- build(dev-env): add make bootstrap and unprovisioned-checkout preflight to pre-commit by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;32981](https://github.com/BerriAI/litellm/pull/32981)
- ci(ui): report only error-level knip findings in CI by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;32971](https://github.com/BerriAI/litellm/pull/32971)
- feat(batches): track cost for unmanaged Bedrock batches, generalize the flag by [@&#8203;Sameerlite](https://github.com/Sameerlite) in [#&#8203;32315](https://github.com/BerriAI/litellm/pull/32315)
- fix(guardrails): walk custom\_tool\_call\_output items in \_content\_utils by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;32969](https://github.com/BerriAI/litellm/pull/32969)
- fix: show and allow editing team model aliases after team creation by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33047](https://github.com/BerriAI/litellm/pull/33047)
- chore(deps): bump pillow to 12.3.0 to resolve osv-scan CVEs by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33093](https://github.com/BerriAI/litellm/pull/33093)
- feat(mcp): mint gateway-bound envelope at the token endpoint for dcr\_bridge oauth\_delegate by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;32828](https://github.com/BerriAI/litellm/pull/32828)
- fix(mcp): surface rejected delegate-auth upstream tokens as connect-time 401 by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;32741](https://github.com/BerriAI/litellm/pull/32741)
- fix(proxy): track unauthenticated pass-through requests in spend logs by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;32410](https://github.com/BerriAI/litellm/pull/32410)
- feat(lasso): send source.type for Used By attribution by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33090](https://github.com/BerriAI/litellm/pull/33090)
- fix(responses): continue MCP gateway tool turns from the final response and surface failures by [@&#8203;thibault-linktree](https://github.com/thibault-linktree) in [#&#8203;33025](https://github.com/BerriAI/litellm/pull/33025)
- fix(responses): continue MCP gateway tool turns from the final response and surface failures by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33099](https://github.com/BerriAI/litellm/pull/33099)
- fix(completion): forward aws credential kwargs into litellm\_params so the responses bridge keeps WIF auth by [@&#8203;mateo-berri](https://github.com/mateo-berri) in [#&#8203;32956](https://github.com/BerriAI/litellm/pull/32956)
- fix(ui): respect litellm\_key\_header\_name in BYOK credential save and workflow runs fetches by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33103](https://github.com/BerriAI/litellm/pull/33103)
- refactor(ui): standardize debounce waits behind shared DEBOUNCE\_WAIT\_MS constant by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33040](https://github.com/BerriAI/litellm/pull/33040)
- feat(ui): rebuild the Virtual Keys table on the shared DataTable by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;32991](https://github.com/BerriAI/litellm/pull/32991)
- fix: redact async complete streaming response for custom callbacks by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33106](https://github.com/BerriAI/litellm/pull/33106)
- build(ui): bump [@&#8203;tanstack/react-pacer](https://github.com/tanstack/react-pacer) from 0.2.0 to 0.22.1 by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33041](https://github.com/BerriAI/litellm/pull/33041)
- fix(ui): address Virtual Keys redesign review nits by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33112](https://github.com/BerriAI/litellm/pull/33112)
- fix(openai/responses): clamp max\_output\_tokens below API minimum by [@&#8203;devin-ai-integration](https://github.com/devin-ai-integration)\[bot] in [#&#8203;33098](https://github.com/BerriAI/litellm/pull/33098)
- fix(prometheus): read v3 rate limiter remaining values for per-key model gauges by [@&#8203;yucheng-berri](https://github.com/yucheng-berri) in [#&#8203;33119](https://github.com/BerriAI/litellm/pull/33119)
- fix(ui): drop w-full from page-content wrappers to remove 32px horizontal overflow by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33118](https://github.com/BerriAI/litellm/pull/33118)
- refactor(ui): migrate straightforward value debounces to react-pacer by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33042](https://github.com/BerriAI/litellm/pull/33042)
- feat(mcp): interactive SSO sign-in for dcr\_bridge oauth\_delegate DCR clients by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;32946](https://github.com/BerriAI/litellm/pull/32946)
- test(proxy): add regression tests for management\_endpoints edge cases by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;32976](https://github.com/BerriAI/litellm/pull/32976)
- fix(auto-router): correct Responses API tool\_choice shape and propagate alias litellm\_params by [@&#8203;krrish-berri-2](https://github.com/krrish-berri-2) in [#&#8203;32974](https://github.com/BerriAI/litellm/pull/32974)
- fix(ui): render the sidebar scrollbar with shadcn ScrollArea by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33124](https://github.com/BerriAI/litellm/pull/33124)
- refactor(ui): migrate callback debounce sites to react-pacer with regression tests by [@&#8203;ryan-crabbe-berri](https://github.com/ryan-crabbe-berri) in [#&#8203;33043](https://github.com/BerriAI/litellm/pull/33043)
- chore: add CODEOWNERS for ui and proxy UI build artifacts by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33131](https://github.com/BerriAI/litellm/pull/33131)
- feat(mcp): client-held refresh envelope for the dcr\_bridge oauth\_delegate flow by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;32980](https://github.com/BerriAI/litellm/pull/32980)
- feat(ui): rebuild the Teams table on the shared DataTable by [@&#8203;yuneng-berri](https://github.com/yuneng-berri) in [#&#8203;33128](https://github.com/BerriAI/litellm/pull/33128)
- fix(mcp): relay upstream OAuth token and DCR rejections instead of a generic 500 by [@&#8203;tin-berri](https://github.com/tin-berri) in [#&#8203;33113](https://github.com/BerriAI/litellm/pull/33113)
- fix(keys): persist key\_type so the UI shows correct key scope instead of "All Proxy…
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants