LiteLLM v1.104.0
LiteLLM v1.104.0 introduces a breaking proxy startup check that blocks unset or known default master keys (like sk-1234), enhances password security policies, and fixes MCP routing and container recovery issues.
Why this signal matters
LiteLLM release v1.104.0 delivers security, proxy, and routing improvements. Most notably, PR 42019 introduces a breaking security check causing the proxy to refuse startup if provided with an unset, empty, or publicly known master key (such as sk-1234, which is also deprecated across docs and examples). Auth updates include breached password detection, self-service password changes, and mandatory resets for compromised or admin-set credentials. For Model Context Protocol (MCP) integrations, fix 42072 resolves an issue where tools/call would return a 404 on workers that had not previously executed tools/list, alongside restored scoped execution and credential isolation tests. Other notable adjustments include Google GenAI schema/tool parameter forwarding, Redis spend batch handling fixes, and massive unit test suite migrations.
Actionable summary
LiteLLM v1.104.0 includes a breaking change where the proxy refuses to start if the master key is unset, empty, or publicly known. It also adds breached password detection, fixes MCP tools/call 404 errors across multi-worker setups, and updates Docker image cosign signature verification.
- Agent usefulness
- 89/100
- Confidence
- 96%
- Canonical data
- JSON + Markdown
What builders should check
- Verify LiteLLM proxy deployment configurations ensure the master key is set, non-empty, and does not use well-known default values (e.g., sk-1234).
- Optionally verify the v1.104.0 Docker image signature using cosign against the pinned commit hash or release tag public key.