{"version":"2.1.277","anchor":"new-secret-redaction-patterns-google-api-keys-google-oauth","canonical_anchor":"credential-scrubbing-patterns-expanded-to-include-stripe-sty","heading":"More secret patterns caught when scrubbing tool output and logs","tier":"notice","area":"Elsewhere","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.277\/e\/new-secret-redaction-patterns-google-api-keys-google-oauth","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.277","markdown":"### More secret patterns caught when scrubbing tool output and logs\n\nTool output and log scrubbing now also redacts Stripe, Google API, and Google OAuth secret keys\n\n**What**\n\nThe pattern list Claude Code uses to find and redact secrets in tool output and logs has been expanded. It now also catches:\n\n- Stripe-style secret keys (`sk_live_`, `sk_test_`, `sk_prod_`, `rk_...`)\n\n- Google API keys (`AIza...`)\n\n- Google OAuth client secrets (`GOCSPX-...`)\n\nMatches are replaced with a placeholder like `[REDACTED-PAT]` (PAT stands for personal access token) instead of being shown in plain text. A second related redaction table was also updated with matching `<token>` replacements for these same patterns.\n\n**Why**\n\nThis reduces the chance that live API keys or secrets accidentally show up in command output, logs, or anything Claude Code displays or transmits, lowering the risk of credentials leaking.\n\n- Area: Elsewhere\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}