Claude Code 2.1.286 MCP Bearer redaction: Sume key cleanup

Claude Code 2.1.286 stopped MCP errors from printing a credential after Bearer. Update, then sweep old logs and rotate any Sume key that appeared there.

4 min readSume
All posts

Claude Code 2.1.286 fixed MCP error messages that could print a credential's value after "Bearer". Updating stops new leaks, but it does not clean what older versions already wrote. Sweep old logs and transcripts for your Sume Bearer value, and rotate the key if it shows up.

The Claude Code changelog (read 2026-10-01) lists 2.1.286, dated 2026-09-30: "Fixed MCP error messages showing a credential's value when "Bearer" or "Basic" came before its key name". Sume side: Authentication. A companion post covers the rotate decision itself, Claude Code MCP error showed a Bearer token; this one is the cleanup checklist.

Which values do I search for?

Search for the exact key string, not only the word Bearer. Sume accepts the key as Authorization: Bearer <SUME_API_KEY> or as x-api-key, so check both header forms in any saved output. Sume's own missing-credential error reads "Remote MCP tool execution requires x-api-key or Authorization bearer auth." It names the headers and carries no value, so that message is safe to paste.

Where should a key never end up?

Safety rules from the Sume authentication page, read 2026-10-01: https://docs.sume.com/authentication
PlaceRule in the docs
Frontend JavaScript, mobile appsDo not place API keys there
Support tickets and screenshotsDo not place API keys there
Signed upload and download URLsTreat as temporary secrets
Exposed keyRotate from the dashboard

How do I rotate without downtime?

Create a replacement key, deploy it to your server, verify it with GET /v1/me, then revoke the old key in the dashboard. Revoking last means nothing you run loses its credential before the new key is live.

What about the request mode I configured?

Send exactly one credential. A request with both Authorization: Bearer and x-api-key fails with 401 unauthorized and Send only one API key credential. After rotating, update whichever single header your Claude Code MCP config uses. OAuth sessions use consent instead of a pasted key, and a Claude Code reconnect after rotation is a quick way to confirm the new credential works.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume