Authentication

Authentication of the Proxy passthrough’s callers, with a Smarter API key.

A Proxy’s callers use the provider’s own SDK, with the Proxy’s URL as its base URL, and a Smarter API key in place of the provider’s. Each SDK sends its API key in its own header, so SmarterProxyAuthentication reads the Smarter API key from any of them. See CREDENTIAL_HEADERS.

from openai import OpenAI

client = OpenAI(
    base_url="https://platform.smarter.sh/api/v1/proxy/openai/",
    api_key="<your Smarter API key>",
)
class smarter.apps.proxy.authentication.SmarterProxyAuthentication[source]

Bases: BaseAuthentication

Authenticate a Proxy’s caller by a Smarter API key, in any of the headers that LLM SDKs use.

The key is verified by SmarterTokenAuthentication, as for the rest of the Smarter API: it must exist, and be active.

authenticate(request)[source]

Authenticate the request and return a two-tuple of (user, token).

Return type:

Optional[tuple[User, SmarterAuthToken]]

authenticate_header(request)[source]

The WWW-Authenticate header of a 401 response, so that DRF returns 401 rather than 403.

Return type:

str

smarter.apps.proxy.authentication.get_api_key(request)[source]

The Smarter API key of a request: from Authorization: Bearer <key> or Authorization: Token <key>,.

else from the x-api-key, x-goog-api-key or api-key header.

Return type:

Optional[str]

Returns:

The API key, or None if there is none.

Raises:

AuthenticationFailed – if the Authorization header is malformed.