Improvement

API-key auth is no longer sent to another host on a redirect

HTTP monitors now drop the api-key auth header when a redirect leaves the original origin, the same as they already did for Authorization.

HTTP monitors that use api-key auth now remove that header when a redirect points at a different origin (a different scheme, host or port). Monitors using basic or bearer auth already behaved this way, because the Authorization header has always been dropped on a cross-origin redirect. An API key is just as much a credential, so it now gets the same treatment.

What might change for you. If a monitor with api-key auth targets a URL that redirects to another host, and that second host needs the key, the monitor will start getting 401 or 403 from it. Point the monitor at the final URL directly to fix it.

Nothing changes for redirects that stay on the same origin, or for monitors with followRedirects off.

Headers you set yourself under headers are still forwarded on every redirect, so keep credentials in auth rather than in a custom header. The full rules are in the configuration reference under Redirects and credentials.