API-key auth is no longer sent to another host on a redirect
HTTP monitors now drop the api-key auth header when a redirect leaves the original origin, the same as they already did for Authorization.
HTTP monitors that use api-key auth now remove that header when a
redirect points at a different origin (a different scheme, host or port).
Monitors using basic or bearer auth already behaved this way, because
the Authorization header has always been dropped on a cross-origin
redirect. An API key is just as much a credential, so it now gets the same
treatment.
What might change for you. If a monitor with api-key auth targets a
URL that redirects to another host, and that second host needs the key, the
monitor will start getting 401 or 403 from it. Point the monitor at the
final URL directly to fix it.
Nothing changes for redirects that stay on the same origin, or for monitors
with followRedirects off.
Headers you set yourself under headers are still forwarded on every
redirect, so keep credentials in auth rather than in a custom header. The
full rules are in the configuration reference under
Redirects and credentials.