Claude Code keeps a list of file locations it treats as sensitive, such as the gh, glab-cli and gnupg folders and .claude/settings.json. Five Windows locations join that list:
AppData\Local\Microsoft\Credentials
AppData\Roaming\Microsoft\Credentials
AppData\Local\Microsoft\Vault
AppData\Roaming\Microsoft\Vault
AppData\Roaming\Microsoft\Protect, which holds the master keys for DPAPI, the Windows system for encrypting saved secrets.
Why
The places where Windows keeps saved credentials and the keys that unlock them now get the same treatment as other credential folders.
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's release notes agreeAdded "attribution": false in settings.json to hide all commit and PR attribution; older CLI versions skip a settings file that holds it, so…