본문으로 건너뛰기
이 페이지는 아직 사용자의 언어로 번역되지 않았거나 번역이 기술 검토를 기다리고 있습니다. 아래에는 영어 원문이 표시됩니다. 영어 페이지 열기

E1710. Secret approval required

Severity: ERROR. Class: SecretApprovalRequired (subclass of PolicyDeniedError).

What happened​

Secrets:read denied. The SDK got this code on a get_secret() call where the agent did NOT call request_approval() to escalate.

Why it matters​

Secret reads are higher-stakes than tool calls. The behavior on this deny is to require an explicit approval request from the agent, not a silent fail-closed -- and "explicit" is literal: the agent's code makes the request_approval() call, no policy tag makes it for you.

How to fix​

Wrap get_secret() in a request_approval() flow like you would guard().

Removing escalate_on_deny: true from the secret-read rule will NOT change this error. That tag is currently inert (#2391) and never raises a request, so it cannot be what put the read behind approval.

Catching this error​

except PolicyDeniedError catches this.

See also​