Fetching from the wire…
Tools2026-08-08 · source-backed
2.1.224 added structured masking: extract with onExtractNoMatch pulls a value from a structured env var, decode: "jwt" with maskClaims redacts named claims inside a token rather than blanking the whole thing, and awsPairs/sigv4 re-sign AWS requests on the way out. SigV4 and JWT paths require network.tlsTerminate since the proxy must see the request to re-sign. This closes the gap where you either hand an agent a live credential or lose the tool. The agent gets a working request, the raw secret never enters its context or transcript.
Each link below shares sources, entities, or timing with this story.
Claude Code supports JWT / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Claude Code supports JWT); both cover AWS SigV4, JWT; overlapping topics (claim, credential, masking).
Claude Code supports JWT / Shared entity: Sandbox / Same source / Earlier coverage
Linked by a graph relationship (Claude Code supports JWT); both cover Sandbox; cite the same source (2.1.224).
Claude Code supports JWT / Same source / Shared topic / Tension
Linked by a graph relationship (Claude Code supports JWT); cite the same source (2.1.224); overlapping topics (agent, context).
Claude Code supports JWT / Shared entity: AWS / Shared topic / Earlier coverage
Linked by a graph relationship (Claude Code supports JWT); both cover AWS; overlapping topics (agent, context, credential).
Linked by a graph relationship (Claude Code supports JWT); both cover AWS; overlapping topics (agent, context, credential).
Claude Code supports JWT / Same source / Shared topic
Linked by a graph relationship (Claude Code supports JWT); cite the same source (2.1.224); overlapping topics (agent, credential).
Linked by a graph relationship (Claude Code supports JWT); cite the same source (2.1.224); overlapping topics (added, agent).
Linked by a graph relationship (Claude Code supports JWT); cite the same source (2.1.224); overlapping topics (agent, context).