{"version":"2.1.280","anchor":"new-credentialsecret-redaction-pattern-for-tool-output","canonical_anchor":"new-credentialsecret-redaction-pattern-for-tool-output","heading":"New credential\/secret redaction pattern for tool output","tier":"notice","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/new-credentialsecret-redaction-pattern-for-tool-output","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### New credential\/secret redaction pattern for tool output\n\nA new, broader redaction pattern hides secret keys and tokens found in tool output\n\n**What**\n\nA new redaction routine scans text for patterns that look like credentials, such as AWS secret keys, bearer tokens, and session tokens, written as either `key=value` or `key: value`, including escaped or quoted forms. Any matching value is replaced with `<token>`.\n\nPlaceholder-like values, such as `undefined`, `null`, `none`, `true`, `false`, `bearer`, or `basic`, are left alone rather than redacted, since they aren't actual secrets.\n\n**Why**\n\nThis reduces the chance that real credentials get shown or logged when they appear in tool output.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}