{"record":{"id":"2c5e71d70a6ae270","repo":"paperclipai/paperclip","slug":"company-id-is-required-pass-company-id-set-pap","errorCode":null,"errorMessage":"Company ID is required. Pass --company-id, set PAPERCLIP_COMPANY_ID, or set context profile companyId via `paperclipai context set`.","messagePattern":"Company ID is required\\. Pass --company-id, set PAPERCLIP_COMPANY_ID, or set context profile companyId via `paperclipai context set`\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"cli/src/commands/client/common.ts","lineNumber":68,"sourceCode":"  opts?: { requireCompany?: boolean },\n): ResolvedClientContext {\n  const context = readContext(options.context);\n  const { name: profileName, profile } = resolveProfile(context, options.profile);\n\n  const apiBase = resolveApiBase(options, profile);\n\n  const resolvedApiKey = resolveApiKey(options, profile);\n  const explicitApiKey = resolvedApiKey.value;\n  const storedBoardCredential = explicitApiKey ? null : getStoredBoardCredential(apiBase);\n  const apiKey = explicitApiKey || storedBoardCredential?.token;\n\n  const companyId =\n    options.companyId?.trim() ||\n    process.env.PAPERCLIP_COMPANY_ID?.trim() ||\n    profile.companyId;\n\n  if (opts?.requireCompany && !companyId) {\n    throw new Error(\n      \"Company ID is required. Pass --company-id, set PAPERCLIP_COMPANY_ID, or set context profile companyId via `paperclipai context set`.\",\n    );\n  }\n\n  // Agent-authenticated mutations (checkout, release, interactions, PATCH of an\n  // in-progress issue) require the X-Paperclip-Run-Id header (the server returns\n  // \"401 Agent run id required\" without it). Source it from --run-id, else the\n  // PAPERCLIP_RUN_ID env the adapter/embodiment context already exports.\n  const runId = options.runId?.trim() || process.env.PAPERCLIP_RUN_ID?.trim() || undefined;\n\n  const api = new PaperclipApiClient({\n    apiBase,\n    apiKey,\n    runId,\n    recoverAuth: explicitApiKey || !canAttemptInteractiveBoardAuth()\n      ? undefined\n      : async ({ error }) => {\n          const requestedAccess = error.message.includes(\"Instance admin required\")","sourceCodeStart":50,"sourceCodeEnd":86,"githubUrl":"https://github.com/paperclipai/paperclip/blob/120ae5428fa29bee300bcf806491cd4d965fbb7c/cli/src/commands/client/common.ts#L50-L86","documentation":"HTTP 404 with body {\"error\":\"User secret value not found\"} from PATCH /api/companies/:companyId/me/user-secrets/:secretId (secrets.ts:786). svc.updateCurrentUserSecretValue(companyId, ownerUserId, secretId, ...) returned null: no secret value row matches the triple (company, current board user, secretId). The lookup is owner-scoped - a secretId belonging to another user 404s even within the same company - and it also 404s if the value was deleted or never created for this user.","triggerScenarios":"Patching a secret value the current user never set (definition exists, but this user has no value row); patching after the user removed their value; using someone else's secretId gleaned from logs; :companyId mismatch with where the value was stored.","commonSituations":"Profile/settings UIs preloading a value that another session just cleared; onboarding flows that PATCH before the initial PUT/POST of the secret value; scripts replaying captured secret IDs across user accounts.","solutions":["Confirm the current user actually has a value: list this user's secrets for the company and check secretId is present.","If absent, create the value first (the create/upsert path), then patch it.","Never assume a shared secretId works across users - values are per-owner.","After any user secret deletion, refresh the local list before further edits."],"exampleFix":"// before\nawait api.patch(`/api/companies/${companyId}/me/user-secrets/${secretId}`, { value: newValue });\n\n// after\nconst mine = await api.listMyUserSecrets(companyId);\nif (!mine.some((s) => s.id === secretId)) {\n  await api.createUserSecretValue(companyId, secretId, newValue); // first setValue path\n} else {\n  await api.patch(`/api/companies/${companyId}/me/user-secrets/${secretId}`, { value: newValue });\n}","handlingStrategy":"validation","validationCode":"async function upsertMySecretValue(api: ApiClient, companyId: string, secretId: string, value: unknown) {\n  const mine = await api.fetch(`/api/companies/${companyId}/me/user-secrets`);\n  const list = await mine.json();\n  const has = (Array.isArray(list) ? list : list.items ?? []).some(\n    (s: { id: string }) => s.id === secretId,\n  );\n  if (!has) {\n    // no value row for this user yet: create first, then patch later\n    return api.createUserSecretValue(companyId, secretId, value);\n  }\n  return api.fetch(`/api/companies/${companyId}/me/user-secrets/${secretId}`, {\n    method: 'PATCH',\n    body: JSON.stringify({ value }),\n  });\n}","typeGuard":"function isApiErrorBody(body: unknown): body is { error: string } {\n  return typeof body === 'object' && body !== null &&\n    typeof (body as Record<string, unknown>).error === 'string';\n}\nconst isValueNotFound = (b: unknown): boolean =>\n  isApiErrorBody(b) && b.error === 'User secret value not found';","tryCatchPattern":"try {\n  await api.patch(`/api/companies/${companyId}/me/user-secrets/${secretId}`, { value });\n} catch (err) {\n  if (err instanceof ApiError && err.status === 404 && isValueNotFound(err.body)) {\n    // this user has no value for that id (or it was just deleted): create it\n    await api.createUserSecretValue(companyId, secretId, value);\n    return;\n  }\n  throw err;\n}","preventionTips":["Remember values are per-user: never reuse a secretId across accounts.","Refresh 'my secrets' state after any create/delete before further edits.","In onboarding flows, PUT/POST the value before allowing PATCH-based updates.","Handle 404 on PATCH as 'create instead', not as a retryable error."],"tags":["http-404","express","secrets","user-secret-values","owner-scoping","paperclip"],"backgroundTag":"http-404-resource-not-found","analyzedSha":"120ae5428fa29bee300bcf806491cd4d965fbb7c","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}