Claude Code Tightens Secret Redaction in Logs, Transcripts and MCP Errors

Claude CodeView original changelog

Claude Code 2.1.286 closes several gaps where credentials could still appear in MCP error messages, logs, transcripts and the /feedback bundle. Fixes cover Bearer and Basic values placed before their key name, percent-encoded tokens, secrets with invisible characters in the key, and URL passwords containing punctuation. A related fix in 2.1.285 handled passwords containing @ or written as %40.

Key Takeaways

  • Bearer and Basic values that precede their key name are now fully redacted in MCP error messages.
  • Percent-encoded Bearer tokens are masked completely instead of partially.
  • Secrets whose key names hide a zero-width or invisible character no longer escape redaction in logs and transcripts.
  • URL passwords with punctuation such as ), quotes, ], & or a second @ are fully hidden, including in ssh URLs with bracketed hosts.
  • The /feedback zip now has valid JSON lines after redaction, avoiding manual edits that risk leaks.
  • These fixes build on a 2.1.285 change covering URL passwords with @ or %40.

Why redaction matters

Claude Code writes logs and session transcripts, prints MCP errors in the terminal, and can zip a transcript for /feedback. Developers often paste these into issues or chats, so any secret that slips past redaction can leak. Claude Code 2.1.286 fixes a cluster of cases where redaction missed part of a credential.

MCP error messages

Two fixes affect MCP errors. Error messages could show a credential's value when the word "Bearer" or "Basic" came before its key name, and percent-encoded Bearer tokens were only partly masked. Both now redact the full value.

Logs and transcripts

Redacted logs and transcripts could still show a secret whose key name contained an invisible character, such as a zero-width space. That trick defeats pattern matching, and it is now handled. URL passwords were another weak point: part of a password could appear when it contained punctuation such as ), quotes, ], & or a second @, or when it ran past a / to a bracketed host such as [::1] in an ssh URL. These are now fully masked. The previous release, 2.1.285, had already fixed URL passwords containing @, including those written as %40.

The feedback bundle

The transcript in the zip that /feedback saves to disk could contain invalid JSON lines after secret redaction. That file is now valid, which matters because a broken file might be edited by hand, and hand editing is where redactions are lost.