{"version":"2.1.286","anchor":"log-redaction-now-takes-per-caller-regexes-for-keyvalue-and","canonical_anchor":"log-redaction-now-takes-per-caller-regexes-for-keyvalue-and","heading":"Log redaction patterns for keys and Bearer tokens can now vary by caller","tier":"internal","area":"Secret Scrubbing","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286\/e\/log-redaction-now-takes-per-caller-regexes-for-keyvalue-and","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286","markdown":"### Log redaction patterns for keys and Bearer tokens can now vary by caller\n\nThe rules that hide key, token, password and Bearer values in logs are now supplied by each part of Claude Code that uses them\n\n**Unclear.** Which patterns each part of Claude Code passes in, and whether any hide less than before.\n\n**What**\n\nRedaction means hiding secrets such as passwords and tokens before text is written to a log. Two of the patterns Claude Code uses for this used to be fixed:\n\n- values after words like secret, key, token, password or credential\n\n- Bearer tokens\n\nEach part of Claude Code that asks for redaction now supplies these two patterns itself. Redaction of credentials inside URLs, of values starting with `sk-ant-`, and of JWT tokens is unchanged.\n\n**Why**\n\nWhat gets hidden in a log can now differ depending on which part of Claude Code wrote it.\n\n- Area: Secret Scrubbing\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 1\/5"}