---
title: "1.104.0rc2 - UI and CLI Session Token Format"
url: "/release_notes/v1.104.0rc2/v1-104-0-rc-2"
canonical_url: "https://docs.litellm.ai/release_notes/v1.104.0rc2/v1-104-0-rc-2"
type: "release-notes"
last_updated: "2026-10-02"
related:
  - "/release_notes/v1.104.0rc1/v1-104-0-rc-1"
  - "/release_notes/v1.103.2/v1-103-2"
---
# 1.104.0rc2 - UI and CLI Session Token Format

> Index of all LiteLLM docs: https://docs.litellm.ai/llms.txt

## Deploy this version

**Docker**

```bash
docker run \
-e LITELLM_MASTER_KEY=sk-<paste-a-long-random-key> \
-e DATABASE_URL=postgresql://<user>:<password>@<host>:5432/<dbname> \
-e STORE_MODEL_IN_DB=True \
-p 4000:4000 \
docker.litellm.ai/berriai/litellm:1.104.0-rc.2
```

**Pip**

```bash
pip install litellm==1.104.0rc2
```

This release is published as [`ghcr.io/berriai/litellm:v1.104.0-rc.2`](https://github.com/BerriAI/litellm/pkgs/container/litellm). See the [GitHub release](https://github.com/BerriAI/litellm/releases/tag/v1.104.0-rc.2) and the full [releases page](https://github.com/BerriAI/litellm/releases)

:::danger Breaking Changes

**Session tokens issued before the upgrade stop working.** Admin UI and `lite` CLI users sign in once more after upgrading. During a rolling upgrade, pods on the old and new versions reject each other's session tokens, so finish the rollout before asking users to sign in again. Virtual keys, the master key and stored credentials are unaffected. See [`9fa1a64`](https://github.com/BerriAI/litellm/commit/9fa1a641119dd0d4fe43e93622eae5f482ceb63f)

:::

:::warning `lite` CLI users must log in again

After upgrading the proxy, every `lite` CLI user has to run `lite login` once more. Until they do, the CLI keeps sending its old session token and its requests to the proxy fail

:::

`1.104.0rc2` is the current release candidate for 1.104.0. The published GitHub tag is `v1.104.0-rc.2`. It is a patch on top of [`v1.104.0-rc.1`](https://github.com/BerriAI/litellm/releases/tag/v1.104.0-rc.1) with one change: the session tokens the Admin UI and the `lite` CLI receive after sign-in now use their own encryption context and a header-safe format. Both the Docker image and the PyPI package were built from [`e926084`](https://github.com/BerriAI/litellm/commit/e926084212ab2eb234c58840d741b3c62c35911b)

## UI and CLI session tokens get their own format

Session tokens were encrypted with the same routine the proxy uses for stored credentials, so they carried a `v2:gcm:` prefix and base64 padding. Basic auth parsers split on the first `:` and browsers reject `:` and `=` in WebSocket subprotocols, so Langfuse pass-through and the realtime playground could not use them. About one login in 262,144 also produced a token starting with `sk-`, which the proxy then treated as a virtual key and rejected with a 401

Session tokens are now AES-256-GCM encrypted under a context of their own and returned as `litellm_login_` followed by unpadded base64url. They pass through any header, are easy to spot in logs, and are checked only as session tokens. Stored credentials keep their current encryption, so there is nothing to migrate

### What's Changed

- refactor(auth): bind UI/CLI session tokens to their own AES-GCM context - [`9fa1a64`](https://github.com/BerriAI/litellm/commit/9fa1a641119dd0d4fe43e93622eae5f482ceb63f)
- chore(lint): scope a TRY004 suppression to the bearer-token salt key check - [`975f9be`](https://github.com/BerriAI/litellm/commit/975f9beb950fe0b9068c4cf32c5a1c3313da50de)

## Full Changelog

https://github.com/BerriAI/litellm/compare/v1.104.0-rc.1...v1.104.0-rc.2

## Related pages

- [v1.104.0rc1](https://docs.litellm.ai/release_notes/v1.104.0rc1/v1-104-0-rc-1.md)
- [v1.103.2](https://docs.litellm.ai/release_notes/v1.103.2/v1-103-2.md)
