Follow Discord
Sweep 09 Oct 2026 · 17:27Z Build v2.1.296 517 read Stable v2.1.287 Latest v2.1.296 Next v2.1.296 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.296 ·

Hook error details are hidden when they could expose secrets in the URL

Claude Code now hides a hook's error details unless the hook's web address is plain http or https with no secrets in it

You'll notice Improvements
JSON All of v2.1.296
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
HooksArea: what it touches
ImprovementsKind: in v2.1.296,
ImprovementsSection of the release
What

Some hooks send a request to a web address. Hooks are actions Claude Code runs automatically at set moments. When such a hook fails, Claude Code now hides the error details. It says they may contain the hook's URL and that any secrets in it cannot be reliably removed. The details are shown only when the address starts with http:// or https:// and has no embedded credentials, such as a username or password.

In some cases Claude Code also leaves out timing figures and shortens the output it reports from hooks.

Why

A failing web hook no longer prints secrets from its address into Claude Code's output.

See this entry in the whole of v2.1.296 →

Feedback