You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
Secret ScrubbingArea: what it touches
ImprovementsKind: in v2.1.286,
ImprovementsSection of the release
What
Claude Code has a secret scrubber that hides Bearer tokens before text is kept or shown. A Bearer token is the long secret string that follows the word Bearer in an authorization header. The pattern that spots these tokens has been widened. It now also catches tokens that contain percent-encoded characters, where a character is written as % followed by two hexadecimal digits (for example %2F). An encoded space (%20) still ends the match, and a token still has to be at least 8 characters long to be hidden.
Why
Tokens copied out of URLs are often percent-encoded, and the older pattern could miss them. Catching them makes it less likely that such a secret ends up visible in logs or diagnostic output.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not stated which logs or outputs the scrubber is applied to.
Anthropic's release notes agreeFixed MCP error messages showing a credential's value when "Bearer" or "Basic" came before its key name