{"version":"2.1.296","anchor":"hook-url-error-details-hidden-unless-url-is-https-with-no","canonical_anchor":"hook-url-error-details-hidden-unless-url-is-https-with-no","heading":"Hook error details are hidden when they could expose secrets in the URL","tier":"notice","area":"Hooks","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.296\/e\/hook-url-error-details-hidden-unless-url-is-https-with-no","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.296","markdown":"### Hook error details are hidden when they could expose secrets in the URL\n\nClaude Code now hides a hook's error details unless the hook's web address is plain http or https with no secrets in it\n\n**What**\n\nSome hooks send a request to a web address. Hooks are actions Claude Code runs automatically at set moments. When such a hook fails, Claude Code now hides the error details. It says they may contain the hook's URL and that any secrets in it cannot be reliably removed. The details are shown only when the address starts with `http:\/\/` or `https:\/\/` and has no embedded credentials, such as a username or password.\n\nIn some cases Claude Code also leaves out timing figures and shortens the output it reports from hooks.\n\n**Why**\n\nA failing web hook no longer prints secrets from its address into Claude Code's output.\n\n- Area: Hooks\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: yes"}