docs: add MCP verification details and Accept header note

- Documented MCP endpoint verification (2026-08-07): tested with real key,
  confirmed initialize handshake works and virtual keys have MCP access
- Added note about Accept header requirement (handled by MCP client library)
- Clarified that the Accept header is NOT part of the config template
This commit is contained in:
2026-09-17 12:19:00 +00:00
parent d2bca5405a
commit 077972fa2b
+8
View File
@@ -150,6 +150,8 @@ mcp_servers:
url: https://litellm.sysloggh.net/mcp
headers:
x-litellm-api-key: "Bearer <AGENT_KEY>" # Rule 15: must be a REAL key (sk-...), not an env-var name
# Note: MCP endpoint requires Accept: application/json, text/event-stream header
# This is handled by the MCP client library; don't add to config
# ─── Compression ───
compression:
@@ -237,6 +239,12 @@ MCP server entries in `mcp_servers:` must follow the format shown in the Templat
- For template-based config generation: substitute the agent's key from the agent_keys table
- For manual config updates: retrieve the key from the vault and insert the literal value
**Verification (2026-08-07):**
- Tested MCP initialize handshake against litellm.sysloggh.net/mcp with real key
- Confirmed: 200 response with `serverInfo.name: "litellm-mcp-server"`
- Confirmed: virtual keys have MCP access (tools/list returns 200, not 403)
- Key requirement: must be a valid LiteLLM virtual key (HTTP 200 on /v1/models)
## Violation Classification
When reporting findings, separate POLICY observations from FAULT findings: