Claude Code 2.1.286 MCP Bearer redaction: Sume key cleanup
Claude Code 2.1.286 stopped MCP errors from printing a credential after Bearer. Update, then sweep old logs and rotate any Sume key that appeared there.

Claude Code 2.1.286 fixed MCP error messages that could print a credential's value after "Bearer". Updating stops new leaks, but it does not clean what older versions already wrote. Sweep old logs and transcripts for your Sume Bearer value, and rotate the key if it shows up.
The Claude Code changelog (read 2026-10-01) lists 2.1.286, dated 2026-09-30: "Fixed MCP error messages showing a credential's value when "Bearer" or "Basic" came before its key name". Sume side: Authentication. A companion post covers the rotate decision itself, Claude Code MCP error showed a Bearer token; this one is the cleanup checklist.
Which values do I search for?
Search for the exact key string, not only the word Bearer. Sume accepts the key as Authorization: Bearer <SUME_API_KEY> or as x-api-key, so check both header forms in any saved output. Sume's own missing-credential error reads "Remote MCP tool execution requires x-api-key or Authorization bearer auth." It names the headers and carries no value, so that message is safe to paste.
Where should a key never end up?
| Place | Rule in the docs |
|---|---|
| Frontend JavaScript, mobile apps | Do not place API keys there |
| Support tickets and screenshots | Do not place API keys there |
| Signed upload and download URLs | Treat as temporary secrets |
| Exposed key | Rotate from the dashboard |
How do I rotate without downtime?
Create a replacement key, deploy it to your server, verify it with GET /v1/me, then revoke the old key in the dashboard. Revoking last means nothing you run loses its credential before the new key is live.
What about the request mode I configured?
Send exactly one credential. A request with both Authorization: Bearer and x-api-key fails with 401 unauthorized and Send only one API key credential. After rotating, update whichever single header your Claude Code MCP config uses. OAuth sessions use consent instead of a pasted key, and a Claude Code reconnect after rotation is a quick way to confirm the new credential works.
Sources
Related posts
More in Developers
- Claude Code MCP 403 insufficient_scope: re-auth Sume with Write
Claude Code 2.1.274 names the missing permission on a 403 insufficient_scope. For Sume, a read-only grant lacks mcp:write: re-authenticate and turn Write on.
- Claude Code alwaysLoad meta false: deferred Sume tools
Claude Code 2.1.285: a tool with _meta anthropic/alwaysLoad false stays deferred under a server alwaysLoad. What that means for Sume's tool set.
- Claude Code API 400 after a tool returned an object: Sume results
Claude Code 2.1.286 fixed API 400s when a tool returned an object, number or boolean. Sume tools return text content blocks, errors too.
- Claude Code background Bash 30-minute limit and Sume jobs
Claude Code 2.1.285 stops background Bash after 30 minutes by default (2 h max). A Sume render is a job id, so poll it with jobs_wait slices, never resubmit.
Written by Sume