Issue evidence · AI API · BerriAI/litellm

custom_auth_run_common_checks never runs the key max_budget check on custom-auth requests

GitHub issue: https://github.com/BerriAI/litellm/issues/45605

Confirmed from source (not run)

A virtual key returned by custom auth is never blocked by its own max_budget.

What Badgr ran

Read LiteLLM's auth code on main and 1.104.2. Not run live, because the reproduction needs a Postgres-backed proxy.

What came back

  • virtual_key_max_budget_check has one call site, in the stock virtual-key branch of user_api_key_auth.
  • common_checks gathers the user, team and multi-budget checks but not the key's own max_budget.

This is a code reading, not a reproduction.

Checked 2026-10-10 in Badgr’s local development environment.

← All issue evidence