paperclipai/paperclip · error

Deletion requires --confirm

Error message

Deletion requires --confirm <secretId> matching the secret ID.

What it means

--yes was given but --confirm is empty or does not equal the secret id argument, so the typed-confirmation guard for secret deletion rejects the request.

Solutions

  1. Pass --confirm with the exact secret ID being deleted.
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at cli/src/commands/client/secrets.ts:545 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of paperclipai/paperclip@120ae5428f (2026-08-18). Data as JSON: /api/errors/a9e6b11e9ff2d412. Report an issue: GitHub.

Appendix: source

Thrown at cli/src/commands/client/secrets.ts:545

          printOutput(await ctx.api.get(apiPath`/api/secrets/${secretId}/access-events`), { json: ctx.json });
        } catch (err) {
          handleCommandError(err);
        }
      }),
  );

  addCommonClientOptions(
    secrets
      .command("delete")
      .description("Delete a secret")
      .argument("<secretId>", "Secret ID")
      .option("--yes", "Required safety flag to confirm destructive action", false)
      .option("--confirm <secretId>", "Repeat the secret ID to confirm deletion")
      .action(async (secretId: string, opts: SecretDeleteOptions) => {
        try {
          if (!opts.yes) throw new Error("Deletion requires --yes.");
          if (opts.confirm !== secretId) {
            throw new Error("Deletion requires --confirm <secretId> matching the secret ID.");
          }
          const ctx = resolveCommandContext(opts);
          printOutput(await ctx.api.delete(apiPath`/api/secrets/${secretId}`), { json: ctx.json });
        } catch (err) {
          handleCommandError(err);
        }
      }),
  );

  addCommonClientOptions(
    secrets
      .command("doctor")
      .description("Run secret provider health checks through the Paperclip API")
      .requiredOption("-C, --company-id <id>", "Company ID")
      .action(async (opts: SecretDoctorOptions) => {
        try {
          const ctx = resolveCommandContext(opts, { requireCompany: true });
          const health = await ctx.api.get<SecretProviderHealthResponse>(

View on GitHub (pinned to 120ae5428f)