kmail.at
← learning

langchain · difficulty ◆◆

LANGSMITH_API_KEY Gateway Fallback in langchain-core 1.5.3

Let your LangServe gateway discover credentials the same way your chat models already do.

The gateway is the one place LangChain quietly forgot to look for your API key - until 1.5.3.

2026-08-02 · 7 min read

$ pip install -U langchain-core==1.5.3

What it does

When you initialize a LangChain gateway - the server that sits between your application and the LLM providers - the code now reads the LANGSMITH_API_KEY environment variable as a fallback when no explicit API key is supplied through configuration. Previously, if the gateway config omitted the key, initialization would fail or behave unexpectedly, forcing developers to always pass the key explicitly in code. The fallback makes the gateway behave consistently with the rest of LangChain\u2019s client-side behavior, which already respects LANGSMITH_API_KEY for tracing.

Why it matters

In real deployments - development, staging, containers, VMs - you lean on environment variables rather than hardcoded credentials. If you run a LangServe gateway in a Docker container or behind a systemd unit, you want the same credential resolution you get when calling ChatAnthropic directly in a script. Without this fix you had to work around the gap: pass the key explicitly in your gateway setup code, or wrap startup in a custom loader. Now the gateway slots naturally into existing env-var workflows, cutting boilerplate and removing the risk of shipping without the right key.

Release context

This is the langchain-core==1.5.3 patch (published 2026-07-30). It is a targeted follow-up to a cluster of gateway credential fixes, rounding out the story: gateway init now resolves credentials from the same single source of truth as everything else in LangChain.

Example

$ Set LANGSMITH_API_KEY in the environment and boot a gateway with no explicit key
$ export LANGSMITH_API_KEY="ls__mock-key-12345"
$ python3 gateway_env_fallback.py
Gateway initialized successfully!
LangSmith key source: LANGSMITH_API_KEY
$ Now pass an explicit key in the config dict to confirm both paths work
gateway = Gateway(config={"host": "0.0.0.0", "port": 8080, "langsmith_api_key": "ls__explicit-key"})
LangSmith key source: config

The source attribute flips from LANGSMITH_API_KEY to config, proving the fallback only fires when no explicit key is present.

Common flags

--key-source
Reports where the gateway resolved its key from: config or LANGSMITH_API_KEY.
-H/--host
The bind address for the gateway server, e.g. 0.0.0.0.
-p/--port
The listening port, e.g. 8080.

History

From client-side tracing to server-side auth

LANGSMITH_API_KEY has long been the single key that powers LangSmith tracing on the client side - every chat model reads it for observability. The gateway, introduced to front the providers and give a stable server surface, lagged behind: it demanded an explicit credential. This patch closes that gap, making the gateway \u201cjust work\u201d in the same environments where the rest of LangChain already works. It is part of the 1.5.x gateway/auth hardening wave.

Fun facts

Pros & cons

pros

  • + One env var for tracing and gateway auth
  • + No more custom loader hacks
  • + Consistent with client-side behavior

cons

  • − Only the single LANGSMITH_API_KEY var, not an arbitrary key
  • − Server-side gateways still need explicit config for host/port

Takeaways

  1. 1Set LANGSMITH_API_KEY once and let the gateway discover it.
  2. 2Assert the resolved source at startup to catch misconfiguration early.
  3. 3Pass an explicit key only when you need to override the environment.

Related commands

← all learning