◉CLAUDE LABJP
●2.1.293 — v2.1.293 makes Claude Haiku 5.5 the default Haiku model (1M context)●SONNET 4.5 — Retires on the Claude API on 11/30, 53 days left. Migrate to Sonnet 5.5●API CACHE — Sonnet 5.5 cache reads drop to $0.10/Mtok (Oct 7)●Q&A — People are asking what to cut first when always-loaded instruction files grow too big●HAIKU 5.5 — Code written for Haiku 4.5 hits a 400 error on budget_tokens●NEW — If Pro looks unpaid, where you bought it decides which screen to check●2.1.293 — v2.1.293 makes Claude Haiku 5.5 the default Haiku model (1M context)●SONNET 4.5 — Retires on the Claude API on 11/30, 53 days left. Migrate to Sonnet 5.5●API CACHE — Sonnet 5.5 cache reads drop to $0.10/Mtok (Oct 7)●Q&A — People are asking what to cut first when always-loaded instruction files grow too big●HAIKU 5.5 — Code written for Haiku 4.5 hits a 400 error on budget_tokens●NEW — If Pro looks unpaid, where you bought it decides which screen to check
TAG

credentials

3 articles
← Back to all tags
Related:
automation3Claude Code2sandbox2security2headless1OAuth1claude-code1
⟐ Claude Code/2026-08-09Advanced

One Transient 401 Replaced My Long-Lived Token — Giving Credentials a Provenance Field

A shared credential file can lose its long-lived token to a single transient 401. I injected exactly one 401 into a 24-worker fleet, measured the blast radius, and compared a provenance guard against full isolation.

⟐ Claude Code/2026-08-05Advanced

Passing the Request, Not the Secret — Where Sandbox Credential Masking Works and Where Substitution Breaks

Claude Code's sandbox credential masking lets processes read sentinel values while a proxy swaps in the real secret at send time. I rebuilt it as a minimal proxy and measured which auth schemes survive the swap, which break, what happens when the secret rides in the body, and where chunked framing makes the substitution miss entirely.

⟐ Claude Code/2026-06-25Advanced

Your Sandbox Can Run the Code but Shouldn't Read Your Credentials — Shrinking the Secret-Read Surface with sandbox.credentials

Claude Code's sandbox can still read ~/.aws/credentials and token env vars by default. Using sandbox.credentials (v2.1.187+), here is how I tightened the secret-read surface of unattended runs at the OS level, with config and verification you can reuse.