Follow Discord
Sweep 22 Sep 2026 · 17:19Z Build v2.1.280 501 read Stable v2.1.267 Latest v2.1.280 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.260 ·

MCP websearch built-in server steers API keys out of headers

Web search server headers now redact as 'presence' instead of being dropped entirely.

TierUnder the hoodhow much it should matter to you
Useful1my rating, 1 to 5
Signal1worth watching, 1 to 5
AreaMCPwhat it touches
KindInternal Changesin v2.1.260,
Group of 2 Under the hood

Web search server headers now redact as 'presence' instead of being dropped entirely.

The built-in websearch MCP server's config schema now more strongly steers users toward a headers-helper script instead of storing provider API keys directly in the headers field, with new copy framing the API key as a credential that should not be stored inline.

The headers subfield's redaction annotation changed its redact mode from drop to presence, so config/telemetry snapshots now record only that headers were set rather than fully dropping the field.

See this entry in the whole of v2.1.260 →

Feedback