Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

Windows Credential Manager, Vault and DPAPI folders added to protected credential paths

Five Windows folders that store saved passwords and encryption keys are now treated as sensitive paths

Entry
JSON All of v2.1.281
EntryKind: in v2.1.281,
ChangesSection of the release
What

Claude Code keeps a list of file locations it treats as sensitive, such as the gh, glab-cli and gnupg folders and .claude/settings.json. Five Windows locations join that list:

  • AppData\Local\Microsoft\Credentials
  • AppData\Roaming\Microsoft\Credentials
  • AppData\Local\Microsoft\Vault
  • AppData\Roaming\Microsoft\Vault
  • AppData\Roaming\Microsoft\Protect, which holds the master keys for DPAPI, the Windows system for encrypting saved secrets.
Why

The places where Windows keeps saved credentials and the keys that unlock them now get the same treatment as other credential folders.

How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's release notes agreeAdded "attribution": false in settings.json to hide all commit and PR attribution; older CLI versions skip a settings file that holds it, so…

See this entry in the whole of v2.1.281 →

Feedback