Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.280 Latest v2.1.285 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.277 ·

More secret patterns caught when scrubbing tool output and logs

Tool output and log scrubbing now also redacts Stripe, Google API, and Google OAuth secret keys

Group of 2 You'll notice Improvements
JSON All of v2.1.277
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
ElsewhereArea: what it touches
ImprovementsKind: in v2.1.277,
ImprovementsSection of the release

What

The pattern list Claude Code uses to find and redact secrets in tool output and logs has been expanded. It now also catches:

  • Stripe-style secret keys (sk_live_, sk_test_, sk_prod_, rk_...)
  • Google API keys (AIza...)
  • Google OAuth client secrets (GOCSPX-...)

Matches are replaced with a placeholder like [REDACTED-PAT] (PAT stands for personal access token) instead of being shown in plain text. A second related redaction table was also updated with matching <token> replacements for these same patterns.

Why

This reduces the chance that live API keys or secrets accidentally show up in command output, logs, or anything Claude Code displays or transmits, lowering the risk of credentials leaking.

See this entry in the whole of v2.1.277 →

Feedback