Group of 2 Under the hood
Web search server headers now redact as 'presence' instead of being dropped entirely.
The built-in websearch MCP server's config schema now more strongly steers users toward a headers-helper script instead of storing provider API keys directly in the headers field, with new copy framing the API key as a credential that should not be stored inline.
The headers subfield's redaction annotation changed its redact mode from drop to presence, so config/telemetry snapshots now record only that headers were set rather than fully dropping the field.