Masked fields in logs

Problem statement

We noticed that some field values in logs are masked with ‘*****’. Which fields does this apply to?

Solution

We mask any fields containing the following (not case-sensitive):

password
secret
signingKey
client_assertion
passkey