BerriAI shipped LiteLLM v1.103.0 on 2026-09-28: delegated MCP OAuth now requires admission; Capability classifier + Fuse V2 routers land; the proxy can predict prompt-cache costs across deployments, bind JWT claims to agents, add tpd_limit, bulk user/team APIs, and /nvidia_nim passthrough. Also: Bedrock S3 managed file delete/list, Friendli price auto-sync, Responses↔Chat reasoning mapping, and cosign image verification docs.

Key Takeaways

  • ✓Shipped v1.103.0 — pip install litellm==1.103.0; docs.litellm.ai
  • ✓MCP delegated OAuth requires admission; cosign-verify Docker images
  • ✓Capability + Fuse V2 routers; cross-deployment prompt-cache cost prediction
  • ✓JWT→agent binding, tpd_limit, bulk user/team management APIs
  • ✓Bedrock S3 file delete/list, Friendli price sync, Codex model picker sync from proxy
🧭

Finished reading? Explore benchmark rankings & pricing

Real-world SWE-bench scores & $20/mo vs API cost break-even calculator

🔬

In-Depth Technical Analysis

Core Background & Industry Pain Points

LLM gateways must harden MCP delegated OAuth, forecast prompt-cache spend across deployments, and route by capability—while still batching user/team ops and folding Bedrock files plus third-party price feeds into one ledger.

Architecture Highlights & Internals

v1.103.0 requires admission for delegated MCP OAuth (#40923), adds Capability + Fuse V2 routers and cross-deployment prompt-cache cost prediction, binds JWT claims to agents, and ships bulk user/team APIs plus tpd_limit. Bedrock S3 managed file delete/list and Friendli price auto-sync land alongside Responses→Chat reasoning mapping.

Authoritative Benchmarks & Measured Scores

No unified latency/throughput table—validate MCP admission failure rates, Fuse/Capability hit/fallback counts, and prompt-cache forecast vs actual spend on your traffic. Cosign-verify ghcr.io/berriai/litellm:v1.103.0 per the release notes.

Developer Hands-on Guide

pip install -U litellm==1.103.0 (PyPI); configure via docs.litellm.ai. Enable admission before delegated MCP OAuth; use Capability/Fuse carefully (unlicensed caps). See the release.