{"version":"2.1.286","anchor":"bearer-token-redaction-regex-handles-percent-encoded-tokens","canonical_anchor":"bearer-token-redaction-regex-handles-percent-encoded-tokens","heading":"Percent-encoded Bearer tokens are now hidden when secrets are scrubbed","tier":"notice","area":"Secret Scrubbing","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286\/e\/bearer-token-redaction-regex-handles-percent-encoded-tokens","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286","markdown":"### Percent-encoded Bearer tokens are now hidden when secrets are scrubbed\n\nClaude Code's secret scrubber now also hides Bearer tokens that contain URL-encoded characters such as %2F\n\n**Unclear.** It is not stated which logs or outputs the scrubber is applied to.\n\n**What**\n\nClaude Code has a secret scrubber that hides Bearer tokens before text is kept or shown. A Bearer token is the long secret string that follows the word `Bearer` in an authorization header. The pattern that spots these tokens has been widened. It now also catches tokens that contain percent-encoded characters, where a character is written as `%` followed by two hexadecimal digits (for example `%2F`). An encoded space (`%20`) still ends the match, and a token still has to be at least 8 characters long to be hidden.\n\n**Why**\n\nTokens copied out of URLs are often percent-encoded, and the older pattern could miss them. Catching them makes it less likely that such a secret ends up visible in logs or diagnostic output.\n\n- Area: Secret Scrubbing\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}