{"version":"2.1.290","anchor":"url-redaction-and-detection-handles-bracketpercent-encoded","canonical_anchor":"url-redaction-and-detection-handles-bracketpercent-encoded","heading":"Redaction of secrets in URLs and tokens was changed","tier":"notice","area":"Secret Redaction","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/url-redaction-and-detection-handles-bracketpercent-encoded","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Redaction of secrets in URLs and tokens was changed\n\nClaude Code now hides bracketed and percent-encoded login details in URLs, and its pattern for hiding JWT tokens was replaced\n\n**Unclear.** It is not clear in which places Claude Code applies this hiding.\n\n**What**\n\nRedaction means replacing secret values with a placeholder so they do not appear in text Claude Code records. Two redaction rules changed:\n\n- URLs: Claude Code now finds login details in a URL written with brackets (`@[`) or with percent-encoding, which writes characters as `%` codes. It replaces them with `[REDACTED]`. Before, only the plain `:\/\/...@` form was caught.\n\n- JWTs: the rule for JSON Web Tokens, a common kind of login token, now uses a shared pattern. That pattern keeps some text in front of the token, so the replacement keeps that text and then adds `[REDACTED-JWT]`.\n\n**Why**\n\nPasswords and tokens hidden inside URLs in the forms above are now replaced before they are recorded. The JWT change affects exactly which text around a token is kept and which is replaced.\n\n- Area: Secret Redaction\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}