Model BehaviorAutomated release watch

LiteLLM v1.104.0

LiteLLM v1.104.0 introduces a breaking proxy startup check that blocks unset or known default master keys (like sk-1234), enhances password security policies, and fixes MCP routing and container recovery issues.

Human read

Why this signal matters

LiteLLM release v1.104.0 delivers security, proxy, and routing improvements. Most notably, PR 42019 introduces a breaking security check causing the proxy to refuse startup if provided with an unset, empty, or publicly known master key (such as sk-1234, which is also deprecated across docs and examples). Auth updates include breached password detection, self-service password changes, and mandatory resets for compromised or admin-set credentials. For Model Context Protocol (MCP) integrations, fix 42072 resolves an issue where tools/call would return a 404 on workers that had not previously executed tools/list, alongside restored scoped execution and credential isolation tests. Other notable adjustments include Google GenAI schema/tool parameter forwarding, Redis spend batch handling fixes, and massive unit test suite migrations.

Agent parse

Actionable summary

LiteLLM v1.104.0 includes a breaking change where the proxy refuses to start if the master key is unset, empty, or publicly known. It also adds breached password detection, fixes MCP tools/call 404 errors across multi-worker setups, and updates Docker image cosign signature verification.

Agent usefulness
89/100
Confidence
96%
Canonical data
JSON + Markdown
Next actions

What builders should check

  • Verify LiteLLM proxy deployment configurations ensure the master key is set, non-empty, and does not use well-known default values (e.g., sk-1234).
  • Optionally verify the v1.104.0 Docker image signature using cosign against the pinned commit hash or release tag public key.
Classification

Tags and routing

gatewaymodelsobservability
Related signals

Continue the thread