diff --git a/agent/auxiliary_client.py b/agent/auxiliary_client.py index d66d5d81acc15..1f41b89415633 100644 --- a/agent/auxiliary_client.py +++ b/agent/auxiliary_client.py @@ -5949,6 +5949,11 @@ def _wrap_if_needed(client_obj, final_model_str: str, base_url_str: str = "", custom_key = "" if explicit_base_url: custom_base = _to_openai_base_url(explicit_base_url).strip() + # Resolve callable API keys (short-lived credential suppliers) + # before string operations — the runtime path preserves callables + # but auxiliary resolution must invoke them first. (#79121) + if callable(explicit_api_key): + explicit_api_key = str(explicit_api_key() or "").strip() custom_key = ( (explicit_api_key or "").strip() or _scoped_key_env("OPENAI_API_KEY") @@ -5969,7 +5974,10 @@ def _wrap_if_needed(client_obj, final_model_str: str, base_url_str: str = "", # OpenRouter or a wrong API-key provider — the main agent already # solved this, we just need to reuse its answer. (#45472) _main_base = str(main_runtime.get("base_url") or "").strip().rstrip("/") - _main_key = str(main_runtime.get("api_key") or "").strip() + _main_raw = main_runtime.get("api_key") + if callable(_main_raw): + _main_raw = _main_raw() + _main_key = str(_main_raw or "").strip() if _main_base and _main_key: custom_base = _main_base custom_key = _main_key