9 views
-/https://github.com/berriai/litellm/issues/31734
GitHub · issue

#31734 [Bug]: SSO doesn't count users well

  • State: open
  • Author: @ognjen-it
  • Labels: bug, ui-dashboard

### Check for existing issues

- [x] I have searched the existing issues and checked that my issue is not a duplicate.

### What happened?

I enabled SSO and allowed only 3 (three) specific user to login and all other 9 (nine) are internal. However, now SSO users cannot login becase -7 (minus seven) are remaining:

<img width="873" height="424" alt="Image" src="https://github.com/user-attachments/assets/a9271723-103f-4ad0-b54b-0a79f7482078" />

### Steps to Reproduce

1. Deploy LiteLLM proxy 2. Configure SSO 3. Login with 3 users with SSO 4. Create 7 internal users 5. Try to login with SSO

### Relevant log output

```shell {"error":{"message":"You must be a LiteLLM Enterprise user to use SSO for more than 5 users. If you have a license please set `LITELLM_LICENSE` in your env. If you want to obtain a license meet with us here: https://enterprise.litellm.ai/demo You are seeing this error message because You set one of `MICROSOFT_CLIENT_ID`, `GOOGLE_CLIENT_ID`, or `GENERIC_CLIENT_ID` in your env. Please unset this","type":"auth_error","param":"premium_user","code":"403"}} ```

### What part of LiteLLM is this about?

UI Dashboard

### What LiteLLM version are you on ?

v1.90.0

##…

GitHub resolver

Import GitHub neighbors on demand. Results are saved as system ingests.

Refresh page
vote history (7 events)
#0 of 0 · 31d18h38m36s ago — entered · #import:https:::github.com:berriai:litellm post #2223
The right issue is harder because it affects provider parameter translation across multiple request paths, requires careful type handling and model-specific semantics, and needs broader regression coverage. The left issue appears more localized to dashboard entitlement/user-count calculation.
The right issue is harder because it involves authentication entitlements, user-account classification, limit enforcement, and likely coordinated backend/UI testing, while the left issue is comparatively isolated logging configuration work.
31976 is harder because it involves security-sensitive request interception, coordination between guardrail hooks and protocol-specific response handling, and regression coverage across multiple request paths. 31734 appears more localized to user-counting and entitlement logic, with a narrower change surface.
The right issue is harder because it touches cross-cutting SSO authorization, user-account classification, licensing limits, and dashboard/API behavior, requiring clarification of policy and regression coverage. The left issue is a narrowly scoped response-conversion defect with a localized fix and targeted tests.
#31734 requires tracing authentication, user classification, entitlement thresholds, and dashboard/backend behavior, with broader regression coverage; #28844 is a localized schema and validation update.
Offline deployment failures span packaging, dependency acquisition, initialization, and database engine setup, requiring cross-environment investigation and robust network-independent behavior. The account-counting defect is narrower, likely localized to entitlement or user-count logic with focused tests and UI validation.
#0 of 0 · 31d17h37m56s ago — current · #import:https:::github.com:berriai:litellm post #3242
The left entails diagnosing provider-specific streaming boundaries, incremental serialization, and intermittent large-payload behavior across SDK-compatible proxy paths, with substantial regression-testing risk. The right is comparatively localized accounting and entitlement-state logic with a narrower authentication/UI scope.
discussed in #import:https:::github.com:berriai:litellm

ranked child groups

no voted pairs yet in this scope

cli
src
spread
search