{"name":"credentials.envVars","slug":"credentials-envvars","family":"setting","title":"Settings keys","noun":"settings key","description":"Sandbox credential masking adds JWT decoding, per-claim masking, and scrubbing of duplicate secret values","description_source":"entry","described_by":{"version":"2.1.268","anchor":"sandbox-runtime-credential-masking-gains-jwt-decoding-claim"},"presence":{"first_seen":null,"removed_in":null,"in_current_build":false,"newest_mined":"2.1.296","builds":0,"mined_builds":139,"first_cited":{"version":"2.1.208","released_at":"2026-07-13 21:31:27","spans":1}},"aliases":[],"entries":[{"version":"2.1.296","anchor":"sandbox-option-settings-merge","heading":"The sandbox option now merges with your settings instead of replacing them","line":"Sandbox options passed in now merge with your sandbox settings, deny lists add up, and failIfUnavailable defaults to true","released_at":"2026-10-09 16:58:10","reason":"found in this entry's text"},{"version":"2.1.268","anchor":"sandbox-runtime-credential-masking-gains-jwt-decoding-claim","heading":"Sandbox-runtime credential masking gains JWT decoding, claim-level masking, and duplicate-value scrubbing","line":"Sandbox credential masking adds JWT decoding, per-claim masking, and scrubbing of duplicate secret values","released_at":"2026-09-10 18:41:11","reason":"named in this entry, found in this entry's text"},{"version":"2.1.216","anchor":"jwt-credential-masking-for-sandbox-environments","heading":"JWT Credential Masking for Sandbox Environments","line":null,"released_at":"2026-07-20 20:19:37","reason":"found in this entry's text"},{"version":"2.1.208","anchor":"credential-masking-extract-patterns-with-onextractnomatch-co","heading":"Credential masking: extract patterns with onExtractNoMatch control","line":null,"released_at":"2026-07-13 21:31:27","reason":"found in this entry's text"}],"entries_total":4,"docs":[{"source":"claude-code","path":"sandboxing","title":"Configure the sandboxed Bash tool","documented":false},{"source":"claude-code","path":"settings","title":"Claude Code settings","documented":false},{"source":"claude-code","path":"settings-reference","title":"All settings","documented":false}],"docs_total":3,"gates":[],"related":[{"name":"credentials.awsPairs","slug":"credentials-awspairs","description":"Conflicting AWS credential pairs in the sandbox now resolve predictably and warn about risky setups."},{"name":"credentials.files","slug":"credentials-files","description":"Settings docs now explain that masked credential files survive a relaxed sandbox filesystem policy while denied ones do not."},{"name":"credentials.sigv4","slug":"credentials-sigv4","description":"AWS calls from inside the sandbox now work with masked credentials, since the proxy re-signs them for you."}],"url":"https:\/\/changelogs.core-directive.com\/reference\/setting\/credentials-envvars","family_url":"https:\/\/changelogs.core-directive.com\/reference\/setting.json"}