paperclipai/paperclip · error

path must start with / and be relative to /api, and must…

Error message

path must start with / and be relative to /api, and must not contain '..'

What it means

Path validation inside the paperclipApiRequest escape-hatch tool: the caller-supplied API path failed one of the structural rules (must begin with '/', is joined onto /api, and must not contain '..'). This is a generic request-shape guard preventing path traversal outside the /api namespace before client.requestJson is invoked.

Solutions

  1. Pass a path starting with / that stays under /api and contains no '..' segments.
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at packages/mcp-server/src/tools.ts:626 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of paperclipai/paperclip@a7e689b3c3 (2026-08-18). Data as JSON: /api/errors/15c053fb703a8486. Report an issue: GitHub.

Appendix: source

Thrown at packages/mcp-server/src/tools.ts:626

        return client.requestJson("POST", path, { body });
      },
    ),
    makeTool(
      "paperclipAddApprovalComment",
      "Add a comment to an approval",
      z.object({ approvalId: approvalIdSchema, body: z.string().min(1) }),
      async ({ approvalId, body }) =>
        client.requestJson("POST", `/approvals/${encodeURIComponent(approvalId)}/comments`, {
          body: { body },
        }),
    ),
    makeTool(
      "paperclipApiRequest",
      "Make a JSON request to an existing Paperclip /api endpoint for unsupported operations",
      apiRequestSchema,
      async ({ method, path, jsonBody }) => {
        if (!path.startsWith("/") || path.includes("..")) {
          throw new Error("path must start with / and be relative to /api, and must not contain '..'");
        }
        return client.requestJson(method, path, {
          body: parseOptionalJson(jsonBody),
        });
      },
    ),
  ];
}

View on GitHub (pinned to a7e689b3c3)