Claude Code v2.1.277 · 18 Sep 2026
More secret patterns caught when scrubbing tool output and logs
Tool output and log scrubbing now also redacts Stripe, Google API, and Google OAuth secret keys
You'll notice Tier: how much it should matter to you
2 Useful: my rating, 1 to 5
1 Signal: worth watching, 1 to 5
Elsewhere Area: what it touches
Improvements Kind: in v2.1.277, 18 Sep 26
Improvements Section of the release
What
The pattern list Claude Code uses to find and redact secrets in tool output and logs has been expanded. It now also catches:
Stripe-style secret keys (sk_live_, sk_test_, sk_prod_, rk_...)
Google API keys (AIza...)
Google OAuth client secrets (GOCSPX-...)
Matches are replaced with a placeholder like [REDACTED-PAT] (PAT stands for personal access token) instead of being shown in plain text. A second related redaction table was also updated with matching <token> replacements for these same patterns.
Why
This reduces the chance that live API keys or secrets accidentally show up in command output, logs, or anything Claude Code displays or transmits, lowering the risk of credentials leaking.
See this entry in the whole of v2.1.277 →
18 Sep 2026 · 402 entries, this one is #97.
Use it now29 You'll notice126 Nothing to try yet23 Under the hood224
Open the release →
Is this right?
0
0
Feedback
What's wrong with this entry?
Hard to understand Too vague Looks wrong Not relevant to me Too long Missing the detail I wanted Duplicate of another card
Clear Learned something new I can act on this Good catch
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
← Previous · 96 of 402
New ripgrep spawn-failure diagnostics with cause-specific advice
You'll notice Search Tools
In v2.1.277 Improvements release-page order
Next → · 98 of 402
New reserved-name lock for skills, commands and tools
You'll notice Permissions