Follow Discord
Sweep 01 Oct 2026 · 17:27Z Build v2.1.287 508 read Stable v2.1.285 Latest v2.1.287 Next v2.1.287 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.286 ·

Percent-encoded Bearer tokens are now hidden when secrets are scrubbed

Claude Code's secret scrubber now also hides Bearer tokens that contain URL-encoded characters such as %2F

You'll notice Improvements
JSON All of v2.1.286
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
Secret ScrubbingArea: what it touches
ImprovementsKind: in v2.1.286,
ImprovementsSection of the release
What

Claude Code has a secret scrubber that hides Bearer tokens before text is kept or shown. A Bearer token is the long secret string that follows the word Bearer in an authorization header. The pattern that spots these tokens has been widened. It now also catches tokens that contain percent-encoded characters, where a character is written as % followed by two hexadecimal digits (for example %2F). An encoded space (%20) still ends the match, and a token still has to be at least 8 characters long to be hidden.

Why

Tokens copied out of URLs are often percent-encoded, and the older pattern could miss them. Catching them makes it less likely that such a secret ends up visible in logs or diagnostic output.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not stated which logs or outputs the scrubber is applied to.
Anthropic's release notes agreeFixed MCP error messages showing a credential's value when "Bearer" or "Basic" came before its key name

See this entry in the whole of v2.1.286 →

Feedback