AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

HuggingFaceEndpoint Drops Token For Dedicated Inference Endpoints (*.Endpoints.Huggingface.Cloud)

The HuggingFaceEndpoint class discards the explicitly provided huggingfacehub_api_token when endpoint_url points to a dedicated Inference Endpoint served from *.endpoints.huggingface.cloud, because the internal _is_huggingface_hosted_url check does not recognise this hostname. This causes requests to protected endpoints to be sent without an Authorization header, resulting in 401 Unauthorized, and may silently replace the explicit token with a cached or environment token if present.

highConfidence 95%Langchain-HuggingfaceAffected V1.2.2

Origin Analysis

The helper _is_huggingface_hosted_url only treats huggingface.co and hf.space (and their subdomains) as Hugging Face hosted URLs. Dedicated Inference Endpoints use the domain *.endpoints.huggingface.cloud, which is not covered by the check, so validate_environment considers the endpoint as local and omits the token when instantiating InferenceClient and AsyncInferenceClient.
1. Install langchain-huggingface 1.2.2 and huggingface_hub 1.31.0. 2. Run the provided reproduction code that instantiates HuggingFaceEndpoint with endpoint_url='https://jzgu0buei5.us-east-1.aws.endpoints.huggingface.cloud' and an explicit huggingfacehub_api_token. 3. Observe that _is_huggingface_hosted_url returns False and both InferenceClient and AsyncInferenceClient are called with api_key=None.

Fixing Code Block

Edge Case Audit

The change is minimal and only broadens the set of hostnames considered Hugging Face hosted. However, it means the token will be sent to any subdomain of endpoints.huggingface.cloud; that domain is controlled by Hugging Face, but if it were ever compromised or repurposed, tokens could leak. No threading or concurrency issues are introduced because the helper is a pure function. Rollback is straightforward: revert the hosted_domains tuple to the previous two entries. For additional safety, users can still override headers via server_kwargs as a workaround.

Ecosystem Topology