{"version":"2.1.281","anchor":"windows-credential-manager-vault-and-dpapi-folders-added-to","canonical_anchor":"windows-credential-manager-vault-and-dpapi-folders-added-to","heading":"Windows Credential Manager, Vault and DPAPI folders added to protected credential paths","tier":null,"area":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/windows-credential-manager-vault-and-dpapi-folders-added-to","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Windows Credential Manager, Vault and DPAPI folders added to protected credential paths\n\nFive Windows folders that store saved passwords and encryption keys are now treated as sensitive paths\n\n**What**\n\nClaude Code keeps a list of file locations it treats as sensitive, such as the `gh`, `glab-cli` and `gnupg` folders and `.claude\/settings.json`. Five Windows locations join that list:\n\n- `AppData\\Local\\Microsoft\\Credentials`\n\n- `AppData\\Roaming\\Microsoft\\Credentials`\n\n- `AppData\\Local\\Microsoft\\Vault`\n\n- `AppData\\Roaming\\Microsoft\\Vault`\n\n- `AppData\\Roaming\\Microsoft\\Protect`, which holds the master keys for DPAPI, the Windows system for encrypting saved secrets.\n\n**Why**\n\nThe places where Windows keeps saved credentials and the keys that unlock them now get the same treatment as other credential folders."}