v1.102.2 - UI and CLI Session Token Format
Deploy this version​
- Docker
- Pip
docker run \
-e LITELLM_MASTER_KEY=sk-<paste-a-long-random-key> \
-e DATABASE_URL=postgresql://<user>:<password>@<host>:5432/<dbname> \
-e STORE_MODEL_IN_DB=True \
-p 4000:4000 \
docker.litellm.ai/berriai/litellm:1.102.2
pip install litellm==1.102.2
This release is published as ghcr.io/berriai/litellm:v1.102.2. See the GitHub release and the full releases page
Session tokens issued before the upgrade stop working. Admin UI and lite CLI users sign in once more after upgrading. During a rolling upgrade, pods on the old and new versions reject each other's session tokens, so finish the rollout before asking users to sign in again. Virtual keys, the master key and stored credentials are unaffected. See 1d5fdc8
v1.102.2 is a patch release on top of v1.102.1. It carries one change: the session tokens the Admin UI and the lite CLI receive after sign-in now use their own encryption context and a header-safe format. Both the Docker image and the PyPI package were built from a0c4a33
UI and CLI session tokens get their own format​
Session tokens were encrypted with the same routine the proxy uses for stored credentials, so they carried a v2:gcm: prefix and base64 padding. Basic auth parsers split on the first : and browsers reject : and = in WebSocket subprotocols, so Langfuse pass-through and the realtime playground could not use them. About one login in 262,144 also produced a token starting with sk-, which the proxy then treated as a virtual key and rejected with a 401
Session tokens are now AES-256-GCM encrypted under a context of their own and returned as litellm_login_ followed by unpadded base64url. They pass through any header, are easy to spot in logs, and are checked only as session tokens. Stored credentials keep their current encryption, so there is nothing to migrate
What's Changed​
- refactor(auth): bind UI/CLI session tokens to their own AES-GCM context -
1d5fdc8 - chore(lint): scope a TRY004 suppression to the bearer-token salt key check -
02a0dc1
Full Changelog​
https://github.com/BerriAI/litellm/compare/v1.102.1...v1.102.2