Claude Code Tightens Secret Redaction in Logs, Transcripts and MCP Errors
Claude Code 2.1.286 closes several gaps where credentials could still appear in MCP error messages, logs, transcripts and the /feedback bundle. Fixes cover Bearer and Basic values placed before their key name, percent-encoded tokens, secrets with invisible characters in the key, and URL passwords containing punctuation. A related fix in 2.1.285 handled passwords containing @ or written as %40.
Key Takeaways
- Bearer and Basic values that precede their key name are now fully redacted in MCP error messages.
- Percent-encoded Bearer tokens are masked completely instead of partially.
- Secrets whose key names hide a zero-width or invisible character no longer escape redaction in logs and transcripts.
- URL passwords with punctuation such as
), quotes,],&or a second@are fully hidden, including in ssh URLs with bracketed hosts. - The
/feedbackzip now has valid JSON lines after redaction, avoiding manual edits that risk leaks. - These fixes build on a 2.1.285 change covering URL passwords with
@or%40.
Why redaction matters
Claude Code writes logs and session transcripts, prints MCP errors in the terminal, and can zip a transcript for /feedback. Developers often paste these into issues or chats, so any secret that slips past redaction can leak. Claude Code 2.1.286 fixes a cluster of cases where redaction missed part of a credential.
MCP error messages
Two fixes affect MCP errors. Error messages could show a credential's value when the word "Bearer" or "Basic" came before its key name, and percent-encoded Bearer tokens were only partly masked. Both now redact the full value.
Logs and transcripts
Redacted logs and transcripts could still show a secret whose key name contained an invisible character, such as a zero-width space. That trick defeats pattern matching, and it is now handled. URL passwords were another weak point: part of a password could appear when it contained punctuation such as ), quotes, ], & or a second @, or when it ran past a / to a bracketed host such as [::1] in an ssh URL. These are now fully masked. The previous release, 2.1.285, had already fixed URL passwords containing @, including those written as %40.
The feedback bundle
The transcript in the zip that /feedback saves to disk could contain invalid JSON lines after secret redaction. That file is now valid, which matters because a broken file might be edited by hand, and hand editing is where redactions are lost.