This required a server-side fix, which the Zapier team deployed, old logs rotated out and new logs are properly censored, with the reporter confirming redaction works. If you see auth secrets in Zapier logs on a current platform version, report it, since the redaction is handled server-side and needs no client change.
Source: https://github.com/zapier/zapier-platform/issues/354
Source: https://github.com/zapier/zapier-platform/issues/354