Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.293 ·

Settings that look like passwords or keys are kept out of cloud sessions

When local settings and CLAUDE.md files are sent to a cloud session, anything that looks like a credential is now held back

You'll notice Improvements
JSON All of v2.1.293
You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
Cloud SessionsArea: what it touches
ImprovementsKind: in v2.1.293,
ImprovementsSection of the release
What

When you start a cloud session (a Claude Code session that runs on a remote machine instead of your own), Claude Code can send along settings from your home folder. It now checks that material for text that looks like a credential, meaning a password, API key, token or similar secret. It checks two kinds of material:

  • Permission rules: the allow, ask and deny rules that decide what Claude may do. A rule that looks like it contains a credential is withheld.
  • Memory and instruction files such as CLAUDE.md, including any files they import. A file that looks like it contains a credential is left behind, and Claude Code notes the line number where the match was found.

The count of what was and was not forwarded now includes how many pieces of text were withheld for this reason. Before, permission rules were only checked for problems such as being invalid or too large, with no check for credentials.

Why

It lowers the chance of a secret in your local settings or instruction files being copied to a remote machine. If a rule or file you rely on is missing in a cloud session, a credential-like string inside it may be the reason.

See this entry in the whole of v2.1.293 →

Feedback