From 3ef0e3bdb82efcb7e0c507ea754c9873d3215269 Mon Sep 17 00:00:00 2001
From: "kernel-internal[bot]"
<260533166+kernel-internal[bot]@users.noreply.github.com>
Date: Mon, 28 Sep 2026 14:20:26 +0000
Subject: [PATCH 1/8] feat: Accept telemetry.storage and settle it at browser
create
Stainless-Generated-From: 37ff74bd963dfa02ace012efbb2b98eed5d53e5c
---
api.md | 1 +
src/resources/auth/connections.ts | 112 ++++++++++++++++++
src/resources/browser-pools.ts | 48 ++++++++
src/resources/browsers/browsers.ts | 34 ++++++
src/resources/browsers/index.ts | 1 +
src/resources/browsers/telemetry.ts | 19 +++
tests/api-resources/auth/connections.test.ts | 4 +
tests/api-resources/browser-pools.test.ts | 1 +
tests/api-resources/browsers/browsers.test.ts | 1 +
9 files changed, 221 insertions(+)
diff --git a/api.md b/api.md
index dee34db6..fb81b71f 100644
--- a/api.md
+++ b/api.md
@@ -185,6 +185,7 @@ Types:
- BrowserTelemetryEvent
- BrowserTelemetryExportConfig
- BrowserTelemetryOtlpExportConfig
+- BrowserTelemetryStorageConfig
- TelemetryEventsResponse
- TelemetryStreamResponse
diff --git a/src/resources/auth/connections.ts b/src/resources/auth/connections.ts
index 2fa308bb..3efcb475 100644
--- a/src/resources/auth/connections.ts
+++ b/src/resources/auth/connections.ts
@@ -587,6 +587,11 @@ export namespace ManagedAuth {
* exporting.
*/
export?: BrowserTelemetry.Export;
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ storage?: BrowserTelemetry.Storage;
}
export namespace BrowserTelemetry {
@@ -638,6 +643,17 @@ export namespace ManagedAuth {
}
}
}
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ export interface Storage {
+ /**
+ * Whether captured telemetry is persisted to Kernel storage. Defaults to true.
+ * Setting false is not supported yet and is rejected.
+ */
+ enabled?: boolean;
+ }
}
/**
@@ -970,6 +986,11 @@ export namespace ManagedAuthBrowserConfig {
* exporting.
*/
export?: Telemetry.Export;
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ storage?: Telemetry.Storage;
}
export namespace Telemetry {
@@ -1021,6 +1042,17 @@ export namespace ManagedAuthBrowserConfig {
}
}
}
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ export interface Storage {
+ /**
+ * Whether captured telemetry is persisted to Kernel storage. Defaults to true.
+ * Setting false is not supported yet and is rejected.
+ */
+ enabled?: boolean;
+ }
}
}
@@ -1173,6 +1205,11 @@ export namespace ManagedAuthCreateRequest {
* exporting.
*/
export?: BrowserTelemetry.Export;
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ storage?: BrowserTelemetry.Storage;
}
export namespace BrowserTelemetry {
@@ -1224,6 +1261,17 @@ export namespace ManagedAuthCreateRequest {
}
}
}
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ export interface Storage {
+ /**
+ * Whether captured telemetry is persisted to Kernel storage. Defaults to true.
+ * Setting false is not supported yet and is rejected.
+ */
+ enabled?: boolean;
+ }
}
/**
@@ -1479,6 +1527,11 @@ export namespace ManagedAuthUpdateRequest {
* exporting.
*/
export?: BrowserTelemetry.Export;
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ storage?: BrowserTelemetry.Storage;
}
export namespace BrowserTelemetry {
@@ -1530,6 +1583,17 @@ export namespace ManagedAuthUpdateRequest {
}
}
}
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ export interface Storage {
+ /**
+ * Whether captured telemetry is persisted to Kernel storage. Defaults to true.
+ * Setting false is not supported yet and is rejected.
+ */
+ enabled?: boolean;
+ }
}
/**
@@ -2141,6 +2205,11 @@ export namespace ConnectionCreateParams {
* exporting.
*/
export?: BrowserTelemetry.Export;
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ storage?: BrowserTelemetry.Storage;
}
export namespace BrowserTelemetry {
@@ -2192,6 +2261,17 @@ export namespace ConnectionCreateParams {
}
}
}
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ export interface Storage {
+ /**
+ * Whether captured telemetry is persisted to Kernel storage. Defaults to true.
+ * Setting false is not supported yet and is rejected.
+ */
+ enabled?: boolean;
+ }
}
/**
@@ -2352,6 +2432,11 @@ export namespace ConnectionUpdateParams {
* exporting.
*/
export?: BrowserTelemetry.Export;
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ storage?: BrowserTelemetry.Storage;
}
export namespace BrowserTelemetry {
@@ -2403,6 +2488,17 @@ export namespace ConnectionUpdateParams {
}
}
}
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ export interface Storage {
+ /**
+ * Whether captured telemetry is persisted to Kernel storage. Defaults to true.
+ * Setting false is not supported yet and is rejected.
+ */
+ enabled?: boolean;
+ }
}
/**
@@ -2537,6 +2633,11 @@ export namespace ConnectionLoginParams {
* exporting.
*/
export?: BrowserTelemetry.Export;
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ storage?: BrowserTelemetry.Storage;
}
export namespace BrowserTelemetry {
@@ -2588,6 +2689,17 @@ export namespace ConnectionLoginParams {
}
}
}
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ export interface Storage {
+ /**
+ * Whether captured telemetry is persisted to Kernel storage. Defaults to true.
+ * Setting false is not supported yet and is rejected.
+ */
+ enabled?: boolean;
+ }
}
/**
diff --git a/src/resources/browser-pools.ts b/src/resources/browser-pools.ts
index a4d88533..2eb040f4 100644
--- a/src/resources/browser-pools.ts
+++ b/src/resources/browser-pools.ts
@@ -726,6 +726,11 @@ export namespace BrowserPoolCreateParams {
* exporting.
*/
export?: Telemetry.Export;
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ storage?: Telemetry.Storage;
}
export namespace Telemetry {
@@ -777,6 +782,17 @@ export namespace BrowserPoolCreateParams {
}
}
}
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ export interface Storage {
+ /**
+ * Whether captured telemetry is persisted to Kernel storage. Defaults to true.
+ * Setting false is not supported yet and is rejected.
+ */
+ enabled?: boolean;
+ }
}
}
@@ -984,6 +1000,11 @@ export namespace BrowserPoolUpdateParams {
* exporting.
*/
export?: Telemetry.Export;
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ storage?: Telemetry.Storage;
}
export namespace Telemetry {
@@ -1035,6 +1056,17 @@ export namespace BrowserPoolUpdateParams {
}
}
}
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ export interface Storage {
+ /**
+ * Whether captured telemetry is persisted to Kernel storage. Defaults to true.
+ * Setting false is not supported yet and is rejected.
+ */
+ enabled?: boolean;
+ }
}
}
@@ -1159,6 +1191,11 @@ export namespace BrowserPoolAcquireParams {
* exporting.
*/
export?: Telemetry.Export;
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ storage?: Telemetry.Storage;
}
export namespace Telemetry {
@@ -1210,6 +1247,17 @@ export namespace BrowserPoolAcquireParams {
}
}
}
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ export interface Storage {
+ /**
+ * Whether captured telemetry is persisted to Kernel storage. Defaults to true.
+ * Setting false is not supported yet and is rejected.
+ */
+ enabled?: boolean;
+ }
}
}
diff --git a/src/resources/browsers/browsers.ts b/src/resources/browsers/browsers.ts
index 63e8380b..721bd63e 100644
--- a/src/resources/browsers/browsers.ts
+++ b/src/resources/browsers/browsers.ts
@@ -102,6 +102,7 @@ import {
BrowserTelemetryEvent,
BrowserTelemetryExportConfig,
BrowserTelemetryOtlpExportConfig,
+ BrowserTelemetryStorageConfig,
Telemetry as TelemetryAPITelemetry,
TelemetryEventsParams,
TelemetryEventsResponse,
@@ -1556,6 +1557,11 @@ export namespace BrowserCreateParams {
* exporting.
*/
export?: Telemetry.Export;
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ storage?: Telemetry.Storage;
}
export namespace Telemetry {
@@ -1607,6 +1613,17 @@ export namespace BrowserCreateParams {
}
}
}
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ export interface Storage {
+ /**
+ * Whether captured telemetry is persisted to Kernel storage. Defaults to true.
+ * Setting false is not supported yet and is rejected.
+ */
+ enabled?: boolean;
+ }
}
}
@@ -1722,6 +1739,11 @@ export namespace BrowserUpdateParams {
* exporting.
*/
export?: Telemetry.Export;
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ storage?: Telemetry.Storage;
}
export namespace Telemetry {
@@ -1773,6 +1795,17 @@ export namespace BrowserUpdateParams {
}
}
}
+
+ /**
+ * Whether to persist this session's captured telemetry to Kernel storage.
+ */
+ export interface Storage {
+ /**
+ * Whether captured telemetry is persisted to Kernel storage. Defaults to true.
+ * Setting false is not supported yet and is rejected.
+ */
+ enabled?: boolean;
+ }
}
/**
@@ -1989,6 +2022,7 @@ export declare namespace Browsers {
type BrowserTelemetryEvent as BrowserTelemetryEvent,
type BrowserTelemetryExportConfig as BrowserTelemetryExportConfig,
type BrowserTelemetryOtlpExportConfig as BrowserTelemetryOtlpExportConfig,
+ type BrowserTelemetryStorageConfig as BrowserTelemetryStorageConfig,
type TelemetryEventsResponse as TelemetryEventsResponse,
type TelemetryStreamResponse as TelemetryStreamResponse,
type TelemetryEventsResponsesOffsetPagination as TelemetryEventsResponsesOffsetPagination,
diff --git a/src/resources/browsers/index.ts b/src/resources/browsers/index.ts
index ed0d11c3..2755333d 100644
--- a/src/resources/browsers/index.ts
+++ b/src/resources/browsers/index.ts
@@ -144,6 +144,7 @@ export {
type BrowserTelemetryEvent,
type BrowserTelemetryExportConfig,
type BrowserTelemetryOtlpExportConfig,
+ type BrowserTelemetryStorageConfig,
type TelemetryEventsResponse,
type TelemetryStreamResponse,
type TelemetryEventsParams,
diff --git a/src/resources/browsers/telemetry.ts b/src/resources/browsers/telemetry.ts
index 99f6d4d4..530bac36 100644
--- a/src/resources/browsers/telemetry.ts
+++ b/src/resources/browsers/telemetry.ts
@@ -4694,6 +4694,12 @@ export interface BrowserTelemetryConfig {
* export state is unknown.
*/
export?: BrowserTelemetryExportConfig;
+
+ /**
+ * Whether the session's captured telemetry is persisted to Kernel storage. Omitted
+ * for browsers created before this setting existed, which persist it.
+ */
+ storage?: BrowserTelemetryStorageConfig;
}
/**
@@ -4789,6 +4795,18 @@ export interface BrowserTelemetryOtlpExportConfig {
enabled?: boolean;
}
+/**
+ * Kernel storage state for a session's captured telemetry.
+ */
+export interface BrowserTelemetryStorageConfig {
+ /**
+ * Whether captured telemetry is persisted to Kernel storage. When off, the
+ * session's events are only available on the live stream and through any
+ * configured export.
+ */
+ enabled?: boolean;
+}
+
/**
* Envelope wrapping a browser telemetry event with its monotonic sequence number.
* Each SSE data: frame carries one envelope as JSON. The seq value is also emitted
@@ -4955,6 +4973,7 @@ export declare namespace Telemetry {
type BrowserTelemetryEvent as BrowserTelemetryEvent,
type BrowserTelemetryExportConfig as BrowserTelemetryExportConfig,
type BrowserTelemetryOtlpExportConfig as BrowserTelemetryOtlpExportConfig,
+ type BrowserTelemetryStorageConfig as BrowserTelemetryStorageConfig,
type TelemetryEventsResponse as TelemetryEventsResponse,
type TelemetryStreamResponse as TelemetryStreamResponse,
type TelemetryEventsResponsesOffsetPagination as TelemetryEventsResponsesOffsetPagination,
diff --git a/tests/api-resources/auth/connections.test.ts b/tests/api-resources/auth/connections.test.ts
index b67db534..7a08c45e 100644
--- a/tests/api-resources/auth/connections.test.ts
+++ b/tests/api-resources/auth/connections.test.ts
@@ -61,6 +61,7 @@ describe('resource connections', () => {
enabled: true,
},
},
+ storage: { enabled: true },
},
},
browser_telemetry: {
@@ -86,6 +87,7 @@ describe('resource connections', () => {
enabled: true,
},
},
+ storage: { enabled: true },
},
credential: {
auto: true,
@@ -229,6 +231,7 @@ describe('resource connections', () => {
enabled: true,
},
},
+ storage: { enabled: true },
},
},
browser_telemetry: {
@@ -254,6 +257,7 @@ describe('resource connections', () => {
enabled: true,
},
},
+ storage: { enabled: true },
},
proxy: { id: 'id', name: 'name' },
record_session: true,
diff --git a/tests/api-resources/browser-pools.test.ts b/tests/api-resources/browser-pools.test.ts
index 6d7d2848..be25a04e 100644
--- a/tests/api-resources/browser-pools.test.ts
+++ b/tests/api-resources/browser-pools.test.ts
@@ -69,6 +69,7 @@ describe('resource browserPools', () => {
enabled: true,
},
},
+ storage: { enabled: true },
},
timeout_seconds: 10,
viewport: {
diff --git a/tests/api-resources/browsers/browsers.test.ts b/tests/api-resources/browsers/browsers.test.ts
index bc364170..6db1e634 100644
--- a/tests/api-resources/browsers/browsers.test.ts
+++ b/tests/api-resources/browsers/browsers.test.ts
@@ -81,6 +81,7 @@ describe('resource browsers', () => {
enabled: true,
},
},
+ storage: { enabled: true },
},
timeout_seconds: 10,
vaults: [{ id: 'id', name: 'x' }],
From db2aeee160879f89df81a0bdd5c3147648fb4c89 Mon Sep 17 00:00:00 2001
From: "kernel-internal[bot]"
<260533166+kernel-internal[bot]@users.noreply.github.com>
Date: Mon, 28 Sep 2026 17:00:01 +0000
Subject: [PATCH 2/8] feat: Allow export-only network and console telemetry for
BAA orgs
Stainless-Generated-From: cfd045a765de19b54acf87a2bcc3879b90f0776b
---
src/resources/auth/connections.ts | 21 ++++++++++++++-------
src/resources/browser-pools.ts | 9 ++++++---
src/resources/browsers/browsers.ts | 6 ++++--
3 files changed, 24 insertions(+), 12 deletions(-)
diff --git a/src/resources/auth/connections.ts b/src/resources/auth/connections.ts
index 3efcb475..fd32977c 100644
--- a/src/resources/auth/connections.ts
+++ b/src/resources/auth/connections.ts
@@ -650,7 +650,8 @@ export namespace ManagedAuth {
export interface Storage {
/**
* Whether captured telemetry is persisted to Kernel storage. Defaults to true.
- * Setting false is not supported yet and is rejected.
+ * Setting false requires an OTLP destination and cannot be changed after the
+ * browser is created.
*/
enabled?: boolean;
}
@@ -1049,7 +1050,8 @@ export namespace ManagedAuthBrowserConfig {
export interface Storage {
/**
* Whether captured telemetry is persisted to Kernel storage. Defaults to true.
- * Setting false is not supported yet and is rejected.
+ * Setting false requires an OTLP destination and cannot be changed after the
+ * browser is created.
*/
enabled?: boolean;
}
@@ -1268,7 +1270,8 @@ export namespace ManagedAuthCreateRequest {
export interface Storage {
/**
* Whether captured telemetry is persisted to Kernel storage. Defaults to true.
- * Setting false is not supported yet and is rejected.
+ * Setting false requires an OTLP destination and cannot be changed after the
+ * browser is created.
*/
enabled?: boolean;
}
@@ -1590,7 +1593,8 @@ export namespace ManagedAuthUpdateRequest {
export interface Storage {
/**
* Whether captured telemetry is persisted to Kernel storage. Defaults to true.
- * Setting false is not supported yet and is rejected.
+ * Setting false requires an OTLP destination and cannot be changed after the
+ * browser is created.
*/
enabled?: boolean;
}
@@ -2268,7 +2272,8 @@ export namespace ConnectionCreateParams {
export interface Storage {
/**
* Whether captured telemetry is persisted to Kernel storage. Defaults to true.
- * Setting false is not supported yet and is rejected.
+ * Setting false requires an OTLP destination and cannot be changed after the
+ * browser is created.
*/
enabled?: boolean;
}
@@ -2495,7 +2500,8 @@ export namespace ConnectionUpdateParams {
export interface Storage {
/**
* Whether captured telemetry is persisted to Kernel storage. Defaults to true.
- * Setting false is not supported yet and is rejected.
+ * Setting false requires an OTLP destination and cannot be changed after the
+ * browser is created.
*/
enabled?: boolean;
}
@@ -2696,7 +2702,8 @@ export namespace ConnectionLoginParams {
export interface Storage {
/**
* Whether captured telemetry is persisted to Kernel storage. Defaults to true.
- * Setting false is not supported yet and is rejected.
+ * Setting false requires an OTLP destination and cannot be changed after the
+ * browser is created.
*/
enabled?: boolean;
}
diff --git a/src/resources/browser-pools.ts b/src/resources/browser-pools.ts
index 2eb040f4..18c496dc 100644
--- a/src/resources/browser-pools.ts
+++ b/src/resources/browser-pools.ts
@@ -789,7 +789,8 @@ export namespace BrowserPoolCreateParams {
export interface Storage {
/**
* Whether captured telemetry is persisted to Kernel storage. Defaults to true.
- * Setting false is not supported yet and is rejected.
+ * Setting false requires an OTLP destination and cannot be changed after the
+ * browser is created.
*/
enabled?: boolean;
}
@@ -1063,7 +1064,8 @@ export namespace BrowserPoolUpdateParams {
export interface Storage {
/**
* Whether captured telemetry is persisted to Kernel storage. Defaults to true.
- * Setting false is not supported yet and is rejected.
+ * Setting false requires an OTLP destination and cannot be changed after the
+ * browser is created.
*/
enabled?: boolean;
}
@@ -1254,7 +1256,8 @@ export namespace BrowserPoolAcquireParams {
export interface Storage {
/**
* Whether captured telemetry is persisted to Kernel storage. Defaults to true.
- * Setting false is not supported yet and is rejected.
+ * Setting false requires an OTLP destination and cannot be changed after the
+ * browser is created.
*/
enabled?: boolean;
}
diff --git a/src/resources/browsers/browsers.ts b/src/resources/browsers/browsers.ts
index 721bd63e..ec781acb 100644
--- a/src/resources/browsers/browsers.ts
+++ b/src/resources/browsers/browsers.ts
@@ -1620,7 +1620,8 @@ export namespace BrowserCreateParams {
export interface Storage {
/**
* Whether captured telemetry is persisted to Kernel storage. Defaults to true.
- * Setting false is not supported yet and is rejected.
+ * Setting false requires an OTLP destination and cannot be changed after the
+ * browser is created.
*/
enabled?: boolean;
}
@@ -1802,7 +1803,8 @@ export namespace BrowserUpdateParams {
export interface Storage {
/**
* Whether captured telemetry is persisted to Kernel storage. Defaults to true.
- * Setting false is not supported yet and is rejected.
+ * Setting false requires an OTLP destination and cannot be changed after the
+ * browser is created.
*/
enabled?: boolean;
}
From eafcdcf57f345c2495fdfc37501b1be2118cb5b8 Mon Sep 17 00:00:00 2001
From: "kernel-internal[bot]"
<260533166+kernel-internal[bot]@users.noreply.github.com>
Date: Mon, 28 Sep 2026 17:20:34 +0000
Subject: [PATCH 3/8] feat: Expose missing managed auth check URL as
verification unavailable
Stainless-Generated-From: 5ac7a1bde4916387694e123d50845e49a88a1957
---
src/resources/auth/connections.ts | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
diff --git a/src/resources/auth/connections.ts b/src/resources/auth/connections.ts
index fd32977c..125cfd50 100644
--- a/src/resources/auth/connections.ts
+++ b/src/resources/auth/connections.ts
@@ -256,7 +256,8 @@ export interface ManagedAuth {
save_credentials: boolean;
/**
- * Current authentication status of the managed profile
+ * Last known authentication status of the managed profile. An inconclusive health
+ * check preserves this status and does not verify the current session.
*/
status: 'AUTHENTICATED' | 'NEEDS_AUTH';
@@ -463,6 +464,13 @@ export interface ManagedAuth {
*/
health_check_interval?: number | null;
+ /**
+ * Why health checks cannot verify this connection. Present when health checks are
+ * enabled but no auth check URL is available; a recent last_auth_check_at is not
+ * evidence of a valid session.
+ */
+ health_check_unavailable_reason?: 'no_auth_check_url';
+
/**
* Whether periodic health checks are enabled for this connection. When false, the
* system will not automatically verify authentication status, and `auto_reauth`
From d2383af2bd08443d548ae14bff22a790f87d03a9 Mon Sep 17 00:00:00 2001
From: "kernel-internal[bot]"
<260533166+kernel-internal[bot]@users.noreply.github.com>
Date: Tue, 29 Sep 2026 20:17:33 +0000
Subject: [PATCH 4/8] feat: Let Vaults fill credentials from 1Password
Stainless-Generated-From: 098a9823fb59b3ce51825db13694ca30889876f5
---
api.md | 15 +
src/resources/vaults/index.ts | 15 +
src/resources/vaults/items.ts | 843 ++++++++++++++++++++++++++++++---
src/resources/vaults/vaults.ts | 30 ++
4 files changed, 833 insertions(+), 70 deletions(-)
diff --git a/api.md b/api.md
index fb81b71f..e05d4237 100644
--- a/api.md
+++ b/api.md
@@ -496,6 +496,8 @@ Types:
- CardVaultItemSpec
- CardVaultItemState
- CollectVaultItemOperationRequest
+- CredentialAccountVaultItem
+- CredentialAccountVaultItemRequest
- CredentialCollectionAction
- CredentialVaultFieldDefinition
- CredentialVaultFieldInput
@@ -511,6 +513,19 @@ Types:
- CredentialVaultItemUpdateRequest
- FillVaultItemOperationRequest
- FillVaultItemOperationResult
+- KernelCredentialVaultItemSpec
+- KernelCredentialVaultItemSpecInput
+- KernelCredentialVaultItemState
+- OnePasswordCredentialAccountSpec
+- OnePasswordCredentialAccountState
+- OnePasswordCredentialVaultItemSpec
+- OnePasswordCredentialVaultItemSpecInput
+- OnePasswordCredentialVaultItemState
+- OnePasswordFillVaultItemOperationRequest
+- OnePasswordFillVaultItemOperationResult
+- OnePasswordOAuthAction
+- OnePasswordRecoverVaultItemOperationRequest
+- OnePasswordRequestAccessVaultItemOperationRequest
- PrepareCheckoutVaultItemOperationRequest
- VaultCardAliases
- VaultCardFillField
diff --git a/src/resources/vaults/index.ts b/src/resources/vaults/index.ts
index 0df179b4..f25e0324 100644
--- a/src/resources/vaults/index.ts
+++ b/src/resources/vaults/index.ts
@@ -9,6 +9,8 @@ export {
type CardVaultItemSpec,
type CardVaultItemState,
type CollectVaultItemOperationRequest,
+ type CredentialAccountVaultItem,
+ type CredentialAccountVaultItemRequest,
type CredentialCollectionAction,
type CredentialVaultFieldDefinition,
type CredentialVaultFieldInput,
@@ -24,6 +26,19 @@ export {
type CredentialVaultItemUpdateRequest,
type FillVaultItemOperationRequest,
type FillVaultItemOperationResult,
+ type KernelCredentialVaultItemSpec,
+ type KernelCredentialVaultItemSpecInput,
+ type KernelCredentialVaultItemState,
+ type OnePasswordCredentialAccountSpec,
+ type OnePasswordCredentialAccountState,
+ type OnePasswordCredentialVaultItemSpec,
+ type OnePasswordCredentialVaultItemSpecInput,
+ type OnePasswordCredentialVaultItemState,
+ type OnePasswordFillVaultItemOperationRequest,
+ type OnePasswordFillVaultItemOperationResult,
+ type OnePasswordOAuthAction,
+ type OnePasswordRecoverVaultItemOperationRequest,
+ type OnePasswordRequestAccessVaultItemOperationRequest,
type PrepareCheckoutVaultItemOperationRequest,
type VaultCardAliases,
type VaultCardFillField,
diff --git a/src/resources/vaults/items.ts b/src/resources/vaults/items.ts
index af7c3b57..1ab50ff7 100644
--- a/src/resources/vaults/items.ts
+++ b/src/resources/vaults/items.ts
@@ -569,6 +569,75 @@ export interface CollectVaultItemOperationRequest {
type: 'collect';
}
+export interface CredentialAccountVaultItem {
+ id: string;
+
+ available_expansions: Array;
+
+ /**
+ * Advertises 1pw_recover when Kernel can recover a failed account link. Recovery
+ * is unavailable while authorization is pending or after the connection has
+ * already been reset.
+ */
+ available_operations: Array;
+
+ created_at: string;
+
+ /**
+ * Immutable item key assigned when the item is created.
+ */
+ key: string;
+
+ spec: OnePasswordCredentialAccountSpec;
+
+ state: OnePasswordCredentialAccountState;
+
+ type: 'credential_account';
+
+ updated_at: string;
+
+ action?: OnePasswordOAuthAction;
+
+ expires_at?: string;
+}
+
+export namespace CredentialAccountVaultItem {
+ /**
+ * Live data that can currently be requested by passing its type to the item GET
+ * expand parameter.
+ */
+ export interface AvailableExpansion {
+ description: string;
+
+ type: 'payment_methods';
+ }
+
+ /**
+ * An operation that is currently valid for this item. Read the description before
+ * invoking it through the item operations endpoint.
+ */
+ export interface AvailableOperation {
+ description: string;
+
+ type:
+ | 'authorize'
+ | 'collect'
+ | 'prepare_checkout'
+ | 'fill'
+ | '1pw_create_access_request'
+ | '1pw_access_request_status'
+ | '1pw_fill'
+ | '1pw_recover'
+ | '1pw_update_access_token';
+ }
+}
+
+export interface CredentialAccountVaultItemRequest {
+ spec: OnePasswordCredentialAccountSpec;
+
+ type: 'credential_account';
+}
+
/**
* One schema-derived form for the item, available in ready or pending_collection
* state. Render every form-supported field as editable; omit totp fields and
@@ -736,8 +805,10 @@ export interface CredentialVaultItem {
available_expansions: Array;
/**
- * Advertises collect for ready and pending_collection items. Browser fill is
- * advertised only when separately implemented and eligible.
+ * Kernel credentials advertise collect and fill when eligible. 1Password
+ * credentials advertise 1pw_create_access_request until a request is made,
+ * 1pw_access_request_status while its approval is pending, and 1pw_fill after
+ * access is granted.
*/
available_operations: Array;
@@ -748,6 +819,10 @@ export interface CredentialVaultItem {
*/
key: string;
+ /**
+ * Stored-token credentials omit account and never return access_token or
+ * integration_key.
+ */
spec: CredentialVaultItemSpec;
state: CredentialVaultItemState;
@@ -789,7 +864,7 @@ export interface CredentialVaultItem {
* authenticate the customer's end users. Treat URLs and submitted values as
* secrets and exclude them from logs, traces, and errors.
*/
- action?: CredentialCollectionAction;
+ action?: CredentialCollectionAction | CredentialVaultItem.OnePasswordAccessApprovalAction;
}
export namespace CredentialVaultItem {
@@ -810,23 +885,47 @@ export namespace CredentialVaultItem {
export interface AvailableOperation {
description: string;
- type: 'authorize' | 'collect' | 'prepare_checkout' | 'fill';
+ type:
+ | 'authorize'
+ | 'collect'
+ | 'prepare_checkout'
+ | 'fill'
+ | '1pw_create_access_request'
+ | '1pw_access_request_status'
+ | '1pw_fill'
+ | '1pw_recover'
+ | '1pw_update_access_token';
+ }
+
+ export interface OnePasswordAccessApprovalAction {
+ /**
+ * Steps for the agent to hand approval to the human and poll the resulting
+ * decision.
+ */
+ instructions: string;
+
+ name: '1password_access_approval';
+
+ /**
+ * Native 1Password approval link. Present it to the account owner without
+ * modifying it; it does not grant access until they approve in their app.
+ */
+ url: string;
}
}
/**
- * Create a credential item without a wallet or external provider. Do not use
- * credential items to store, collect, or fill credit card data, including card
- * numbers (PANs), security codes (CVV/CVC), or expiration dates. Use wallet and
- * card item types for credit cards and payment checkout instead. If all required
- * fields have values, return ready without a collection action; collect can still
- * open its form. Otherwise return pending_collection with a time-scoped
- * Kernel-hosted collection action. Missing optional fields alone do not trigger
- * collection. Repeating the original creation request returns the current item
- * without overwriting later edits; a different request at the same key
- * returns 409. Use PATCH for updates. Required totp fields must include a valid
- * seed on creation; otherwise return 400 rather than opening a form that cannot
- * collect it. Optional totp fields may be unset and populated later through PATCH.
+ * Ask the end-user whether to link their site credential through 1Password. If
+ * they choose 1Password, connect their account and request access to a login in
+ * their own non-shared vault; passkeys are not supported. If they decline or that
+ * path fails, collect a Kernel-hosted credential item instead. Never automatically
+ * retry an uncertain 1Password request or fill. Do not use credential items for
+ * credit card data. Use wallet and card item types instead. Kernel credentials
+ * declare fields and may enter pending_collection. 1Password credentials either
+ * reference a connected credential_account or store a supplied access token and
+ * integration key encrypted on the item. They store no login values or selectors.
+ * Repeating the original creation request returns the current item without
+ * overwriting later state. A different request at the same key returns 409.
*/
export interface CredentialVaultItemRequest {
/**
@@ -841,19 +940,11 @@ export interface CredentialVaultItemRequest {
type: 'credential';
}
-export interface CredentialVaultItemSpec {
- /**
- * Ordered field definitions rendered in this order by credential collection forms.
- */
- fields: Array;
-
- /**
- * Recognizable site or service name displayed verbatim as the form title, without
- * suffixes such as sign-in credentials. Display text only, not an enforced
- * destination policy.
- */
- description?: string;
-}
+/**
+ * Stored-token credentials omit account and never return access_token or
+ * integration_key.
+ */
+export type CredentialVaultItemSpec = KernelCredentialVaultItemSpec | OnePasswordCredentialVaultItemSpec;
/**
* Credential fields are for login and other non-payment credentials. Do not store,
@@ -862,21 +953,9 @@ export interface CredentialVaultItemSpec {
* the user-facing collection form, so list fields in the same top-to-bottom order
* as the website.
*/
-export interface CredentialVaultItemSpecInput {
- /**
- * Ordered field definitions. Use the website's top-to-bottom field order; the
- * collection form renders this order unchanged.
- */
- fields: Array;
-
- /**
- * The site's recognizable display name, used verbatim as the user-facing form
- * title (for example, Hacker News). Use only the site or service name; do not
- * append sign-in, login, credentials, or task instructions. This is display text,
- * not an enforced destination policy. At most 16 KiB in UTF-8 bytes.
- */
- description?: string;
-}
+export type CredentialVaultItemSpecInput =
+ | KernelCredentialVaultItemSpecInput
+ | OnePasswordCredentialVaultItemSpecInput;
export interface CredentialVaultItemSpecUpdate {
/**
@@ -889,18 +968,7 @@ export interface CredentialVaultItemSpecUpdate {
fields?: { [key: string]: CredentialVaultFieldUpdate };
}
-export interface CredentialVaultItemState {
- /**
- * Exactly one entry for each declared field.
- */
- fields: { [key: string]: CredentialVaultFieldState };
-
- /**
- * Ready means all required fields have values, not that a login succeeded.
- * Optional fields may remain unset.
- */
- status: 'pending_collection' | 'ready';
-}
+export type CredentialVaultItemState = KernelCredentialVaultItemState | OnePasswordCredentialVaultItemState;
/**
* Atomically update description and selected values. Omitted properties are
@@ -1006,6 +1074,438 @@ export interface FillVaultItemOperationResult {
type: 'fill';
}
+export interface KernelCredentialVaultItemSpec {
+ /**
+ * Ordered field definitions rendered in this order by credential collection forms.
+ */
+ fields: Array;
+
+ provider: 'kernel';
+
+ /**
+ * Recognizable site or service name displayed verbatim as the form title, without
+ * suffixes such as sign-in credentials. Display text only, not an enforced
+ * destination policy.
+ */
+ description?: string;
+}
+
+/**
+ * Credential fields are for login and other non-payment credentials. Do not store,
+ * collect, or fill credit card data in credential items. Use wallet and card item
+ * types for credit cards and payment checkout instead. Field order is preserved in
+ * the user-facing collection form, so list fields in the same top-to-bottom order
+ * as the website.
+ */
+export interface KernelCredentialVaultItemSpecInput {
+ /**
+ * Ordered field definitions. Use the website's top-to-bottom field order; the
+ * collection form renders this order unchanged.
+ */
+ fields: Array;
+
+ provider: 'kernel';
+
+ /**
+ * The site's recognizable display name, used verbatim as the user-facing form
+ * title (for example, Hacker News). Use only the site or service name; do not
+ * append sign-in, login, credentials, or task instructions. This is display text,
+ * not an enforced destination policy. At most 16 KiB in UTF-8 bytes.
+ */
+ description?: string;
+}
+
+export interface KernelCredentialVaultItemState {
+ /**
+ * Exactly one entry for each declared field.
+ */
+ fields: { [key: string]: CredentialVaultFieldState };
+
+ provider: 'kernel';
+
+ /**
+ * Ready means all required fields have values, not that a login succeeded.
+ * Optional fields may remain unset.
+ */
+ status: 'pending_collection' | 'ready';
+}
+
+export interface OnePasswordCredentialAccountSpec {
+ authorization: OnePasswordCredentialAccountSpec.Authorization;
+
+ provider: '1password';
+}
+
+export namespace OnePasswordCredentialAccountSpec {
+ export interface Authorization {
+ client: Authorization.Client;
+
+ method: 'oauth';
+ }
+
+ export namespace Authorization {
+ export interface Client {
+ type: 'kernel_managed';
+ }
+ }
+}
+
+export interface OnePasswordCredentialAccountState {
+ provider: '1password';
+
+ status: 'pending_authorization' | 'connected' | 'reconnect_required' | 'declined';
+
+ status_reason?: string;
+}
+
+/**
+ * Stored-token credentials omit account and never return access_token or
+ * integration_key.
+ */
+export interface OnePasswordCredentialVaultItemSpec {
+ provider: '1password';
+
+ /**
+ * Credential Request v2 input sent to the extension. A credential item may request
+ * up to five login entries.
+ */
+ requests: OnePasswordCredentialVaultItemSpec.Requests;
+
+ /**
+ * Customer-supplied expiry metadata, if provided.
+ */
+ access_token_expires_at?: string;
+
+ account?: string;
+}
+
+export namespace OnePasswordCredentialVaultItemSpec {
+ /**
+ * Credential Request v2 input sent to the extension. A credential item may request
+ * up to five login entries.
+ */
+ export interface Requests {
+ entries: Array;
+
+ /**
+ * Must be 2.
+ */
+ version: number;
+
+ goal?: string;
+ }
+
+ export namespace Requests {
+ export interface Entry {
+ parameters: Entry.Parameters;
+
+ /**
+ * Must be login.
+ */
+ type: string;
+
+ keywords?: Array;
+
+ reason?: string;
+ }
+
+ export namespace Entry {
+ export interface Parameters {
+ website: string;
+ }
+ }
+ }
+}
+
+/**
+ * A login request backed by a connected 1Password account or by a
+ * customer-supplied access token and matching integration key. Supply either
+ * account or both secrets, never both. Supplied secrets are write-only and never
+ * returned. Supply requests for new items; website remains supported for existing
+ * account-backed callers.
+ */
+export interface OnePasswordCredentialVaultItemSpecInput {
+ provider: '1password';
+
+ /**
+ * Optional supplied token expiry metadata for stored-token credentials. Omit if
+ * providing a connected credential_account item via the account field.
+ */
+ access_token_expires_at?: string;
+
+ /**
+ * Key of a connected credential_account item in the same vault. Omit for
+ * stored-token credentials.
+ */
+ account?: string;
+
+ /**
+ * Credential Request v2 input sent to the extension. A credential item may request
+ * up to five login entries.
+ */
+ requests?: OnePasswordCredentialVaultItemSpecInput.Requests;
+
+ /**
+ * @deprecated Legacy single-login shorthand. Supply requests instead.
+ */
+ website?: string;
+}
+
+export namespace OnePasswordCredentialVaultItemSpecInput {
+ /**
+ * Credential Request v2 input sent to the extension. A credential item may request
+ * up to five login entries.
+ */
+ export interface Requests {
+ entries: Array;
+
+ /**
+ * Must be 2.
+ */
+ version: number;
+
+ goal?: string;
+ }
+
+ export namespace Requests {
+ export interface Entry {
+ parameters: Entry.Parameters;
+
+ /**
+ * Must be login.
+ */
+ type: string;
+
+ keywords?: Array;
+
+ reason?: string;
+ }
+
+ export namespace Entry {
+ export interface Parameters {
+ website: string;
+ }
+ }
+ }
+}
+
+export interface OnePasswordCredentialVaultItemState {
+ provider: '1password';
+
+ status: 'pending_authorization' | 'ready' | 'declined' | 'failed';
+
+ /**
+ * Non-secret broker state. Granted credential references stay encrypted
+ * server-side and can only be used by the fill operation.
+ */
+ access_request?: OnePasswordCredentialVaultItemState.AccessRequest;
+
+ /**
+ * Opaque request ID returned by the 1Password broker after a successful
+ * createAccessRequest call.
+ */
+ access_request_id?: string;
+
+ status_reason?: string;
+}
+
+export namespace OnePasswordCredentialVaultItemState {
+ /**
+ * Non-secret broker state. Granted credential references stay encrypted
+ * server-side and can only be used by the fill operation.
+ */
+ export interface AccessRequest {
+ id: string;
+
+ has_autofill_token: boolean;
+
+ /**
+ * One of pending, resolved, denied, or failed.
+ */
+ state: string;
+
+ /**
+ * Provider-created timestamp as returned by the broker.
+ */
+ createdAt?: string;
+
+ /**
+ * Login entries returned directly on accessRequest by the observed extension
+ * build. Omitted when the provider does not supply them.
+ */
+ entries?: Array;
+
+ /**
+ * Goal echoed by the observed createAccessRequest response when present.
+ */
+ goal?: string;
+
+ granted_count?: number;
+
+ /**
+ * Opaque provider identity returned by the broker.
+ */
+ identity?: string;
+
+ /**
+ * Provider path if supplied in the broker response.
+ */
+ path?: string;
+
+ /**
+ * The request object if returned by the extension. The observed create response
+ * may omit entries; no entry IDs are invented.
+ */
+ request?: AccessRequest.Request;
+ }
+
+ export namespace AccessRequest {
+ export interface Entry {
+ id?: string;
+
+ keywords?: Array;
+
+ parameters?: Entry.Parameters;
+
+ reason?: string;
+
+ type?: string;
+ }
+
+ export namespace Entry {
+ export interface Parameters {
+ website?: string;
+ }
+ }
+
+ /**
+ * The request object if returned by the extension. The observed create response
+ * may omit entries; no entry IDs are invented.
+ */
+ export interface Request {
+ entries?: Array;
+
+ goal?: string;
+
+ version?: number;
+ }
+
+ export namespace Request {
+ export interface Entry {
+ id?: string;
+
+ keywords?: Array;
+
+ parameters?: Entry.Parameters;
+
+ reason?: string;
+
+ type?: string;
+ }
+
+ export namespace Entry {
+ export interface Parameters {
+ website?: string;
+ }
+ }
+ }
+ }
+}
+
+/**
+ * Fill and submit an approved 1Password login in the selected browser page. The
+ * page must share the selected entry's login origin. Supply entry_id when more
+ * than one approved entry matches the page origin. The extension selects fields;
+ * callers cannot supply selectors or secret values. Submission does not confirm
+ * website authentication.
+ */
+export interface OnePasswordFillVaultItemOperationRequest {
+ /**
+ * Browser session ID, not a reusable browser name.
+ */
+ browser_id: string;
+
+ /**
+ * Exact current top-level page URL. Must match exactly one open page in the
+ * browser.
+ */
+ page_url: string;
+
+ type: '1pw_fill';
+
+ /**
+ * ID of an approved request entry. Required when several approved entries have the
+ * page's origin.
+ */
+ entry_id?: string;
+
+ timeout_ms?: number;
+}
+
+/**
+ * The submission result reported by the 1Password extension when available. Kernel
+ * returns fill_unknown if the extension call has no conclusive result. Inspect the
+ * page to determine successful authentication on the website.
+ */
+export interface OnePasswordFillVaultItemOperationResult {
+ /**
+ * Kernel's outcome of the extension call. fill_submitted means the extension
+ * reported submission, not website authentication. fill_failed means the extension
+ * returned a known failure and may include error_code. fill_unknown means
+ * submission may have happened without a conclusive response; it has no error_code
+ * and must not be retried in the same browser.
+ */
+ status: 'fill_submitted' | 'fill_failed' | 'fill_unknown';
+
+ type: '1pw_fill';
+
+ /**
+ * Present only for a conclusive fill_failed response. These are allowlisted
+ * 1Password extension codes, never raw errors, secrets, or page content.
+ */
+ error_code?: 'fillFailed' | 'autosubmitFailed' | 'noExistingCredentials' | 'authenticationFailed';
+}
+
+export interface OnePasswordOAuthAction {
+ name: '1password_oauth';
+
+ /**
+ * 1Password-hosted OAuth authorization URL for the human to open.
+ */
+ url: string;
+}
+
+/**
+ * Kernel encountered a recoverable error while linking this 1Password account. Use
+ * this action to get a new link to recover the connection. After recovery
+ * completes, start a new authorization on the same item.
+ */
+export interface OnePasswordRecoverVaultItemOperationRequest {
+ type: '1pw_recover';
+}
+
+/**
+ * Request access to login entries in the end-user's own, non-shared 1Password
+ * vault through the browser extension, auto-loaded into the browser. The end-user
+ * approves access in the 1Password app. Shared-vault items and passkeys are not
+ * supported. Per-entry reason and keywords overrides are only supported for a
+ * single login entry.
+ */
+export interface OnePasswordRequestAccessVaultItemOperationRequest {
+ /**
+ * Kernel browser session used to invoke the extension.
+ */
+ browser_id: string;
+
+ type: '1pw_create_access_request';
+
+ goal?: string;
+
+ keywords?: Array;
+
+ reason?: string;
+}
+
/**
* Prepare an unused AgentCard card for a supported checkout. Deliver the returned
* approval URL and keep the approval page open. Poll the item until
@@ -1171,7 +1671,11 @@ export interface VaultFillFieldResult {
| 'execution_failed';
}
-export type VaultItem = VaultItem.WalletVaultItem | VaultItem.CardVaultItem | CredentialVaultItem;
+export type VaultItem =
+ | VaultItem.WalletVaultItem
+ | VaultItem.CardVaultItem
+ | CredentialAccountVaultItem
+ | CredentialVaultItem;
export namespace VaultItem {
export interface WalletVaultItem {
@@ -1232,7 +1736,16 @@ export namespace VaultItem {
export interface AvailableOperation {
description: string;
- type: 'authorize' | 'collect' | 'prepare_checkout' | 'fill';
+ type:
+ | 'authorize'
+ | 'collect'
+ | 'prepare_checkout'
+ | 'fill'
+ | '1pw_create_access_request'
+ | '1pw_access_request_status'
+ | '1pw_fill'
+ | '1pw_recover'
+ | '1pw_update_access_token';
}
/**
@@ -1295,13 +1808,23 @@ export namespace VaultItem {
export interface AvailableOperation {
description: string;
- type: 'authorize' | 'collect' | 'prepare_checkout' | 'fill';
+ type:
+ | 'authorize'
+ | 'collect'
+ | 'prepare_checkout'
+ | 'fill'
+ | '1pw_create_access_request'
+ | '1pw_access_request_status'
+ | '1pw_fill'
+ | '1pw_recover'
+ | '1pw_update_access_token';
}
}
}
export type VaultItemAction =
| VaultItemAction.LinkOAuthAction
+ | OnePasswordOAuthAction
| VaultItemAction.SpendApprovalAction
| VaultItemAction.PushApprovalAction
| VaultItemAction.CollectAction
@@ -1361,15 +1884,17 @@ export interface VaultItemEvent {
}
/**
- * Authorization and preparation return the existing item shape. Fill returns a
- * value-free execution result; it does not persist transient field outcomes on the
- * item.
+ * The submission result reported by the 1Password extension when available. Kernel
+ * returns fill_unknown if the extension call has no conclusive result. Inspect the
+ * page to determine successful authentication on the website.
*/
export type VaultItemOperationResponse =
| VaultItemOperationResponse.WalletVaultItem
| VaultItemOperationResponse.CardVaultItem
+ | CredentialAccountVaultItem
| CredentialVaultItem
- | FillVaultItemOperationResult;
+ | FillVaultItemOperationResult
+ | OnePasswordFillVaultItemOperationResult;
export namespace VaultItemOperationResponse {
export interface WalletVaultItem {
@@ -1430,7 +1955,16 @@ export namespace VaultItemOperationResponse {
export interface AvailableOperation {
description: string;
- type: 'authorize' | 'collect' | 'prepare_checkout' | 'fill';
+ type:
+ | 'authorize'
+ | 'collect'
+ | 'prepare_checkout'
+ | 'fill'
+ | '1pw_create_access_request'
+ | '1pw_access_request_status'
+ | '1pw_fill'
+ | '1pw_recover'
+ | '1pw_update_access_token';
}
/**
@@ -1493,7 +2027,16 @@ export namespace VaultItemOperationResponse {
export interface AvailableOperation {
description: string;
- type: 'authorize' | 'collect' | 'prepare_checkout' | 'fill';
+ type:
+ | 'authorize'
+ | 'collect'
+ | 'prepare_checkout'
+ | 'fill'
+ | '1pw_create_access_request'
+ | '1pw_access_request_status'
+ | '1pw_fill'
+ | '1pw_recover'
+ | '1pw_update_access_token';
}
}
}
@@ -1582,7 +2125,7 @@ export namespace WalletVaultItemSpec {
export interface CustomerManagedOAuthClient {
/**
* Select a provider config by ID or name. Responses return the ID. Renaming a
- * config does not change existing wallet bindings; a wallet cannot switch to a
+ * config does not change existing wallet bindings; an item cannot switch to a
* different config after creation.
*/
provider_config: CustomerManagedOAuthClient.ProviderConfig;
@@ -1593,7 +2136,7 @@ export namespace WalletVaultItemSpec {
export namespace CustomerManagedOAuthClient {
/**
* Select a provider config by ID or name. Responses return the ID. Renaming a
- * config does not change existing wallet bindings; a wallet cannot switch to a
+ * config does not change existing wallet bindings; an item cannot switch to a
* different config after creation.
*/
export interface ProviderConfig {
@@ -1769,7 +2312,12 @@ export type ItemPerformOperationParams =
| ItemPerformOperationParams.AuthorizeVaultItemOperationRequest
| ItemPerformOperationParams.CollectVaultItemOperationRequest
| ItemPerformOperationParams.PrepareCheckoutVaultItemOperationRequest
- | ItemPerformOperationParams.FillVaultItemOperationRequest;
+ | ItemPerformOperationParams.FillVaultItemOperationRequest
+ | ItemPerformOperationParams.OnePasswordRequestAccessVaultItemOperationRequest
+ | ItemPerformOperationParams.OnePasswordPollAccessVaultItemOperationRequest
+ | ItemPerformOperationParams.OnePasswordFillVaultItemOperationRequest
+ | ItemPerformOperationParams.OnePasswordRecoverVaultItemOperationRequest
+ | ItemPerformOperationParams.OnePasswordUpdateAccessTokenVaultItemOperationRequest;
export declare namespace ItemPerformOperationParams {
export interface AuthorizeVaultItemOperationRequest {
@@ -1854,11 +2402,134 @@ export declare namespace ItemPerformOperationParams {
*/
timeout_ms?: number;
}
+
+ export interface OnePasswordRequestAccessVaultItemOperationRequest {
+ /**
+ * Path param
+ */
+ id_or_name: string;
+
+ /**
+ * Body param: Kernel browser session used to invoke the extension.
+ */
+ browser_id: string;
+
+ /**
+ * Body param
+ */
+ type: '1pw_create_access_request';
+
+ /**
+ * Body param
+ */
+ goal?: string;
+
+ /**
+ * Body param
+ */
+ keywords?: Array;
+
+ /**
+ * Body param
+ */
+ reason?: string;
+ }
+
+ export interface OnePasswordPollAccessVaultItemOperationRequest {
+ /**
+ * Path param
+ */
+ id_or_name: string;
+
+ /**
+ * Body param
+ */
+ browser_id: string;
+
+ /**
+ * Body param
+ */
+ type: '1pw_access_request_status';
+
+ /**
+ * Body param
+ */
+ timeout_seconds?: number;
+ }
+
+ export interface OnePasswordFillVaultItemOperationRequest {
+ /**
+ * Path param
+ */
+ id_or_name: string;
+
+ /**
+ * Body param: Browser session ID, not a reusable browser name.
+ */
+ browser_id: string;
+
+ /**
+ * Body param: Exact current top-level page URL. Must match exactly one open page
+ * in the browser.
+ */
+ page_url: string;
+
+ /**
+ * Body param
+ */
+ type: '1pw_fill';
+
+ /**
+ * Body param: ID of an approved request entry. Required when several approved
+ * entries have the page's origin.
+ */
+ entry_id?: string;
+
+ /**
+ * Body param
+ */
+ timeout_ms?: number;
+ }
+
+ export interface OnePasswordRecoverVaultItemOperationRequest {
+ /**
+ * Path param
+ */
+ id_or_name: string;
+
+ /**
+ * Body param
+ */
+ type: '1pw_recover';
+ }
+
+ export interface OnePasswordUpdateAccessTokenVaultItemOperationRequest {
+ /**
+ * Path param
+ */
+ id_or_name: string;
+
+ /**
+ * Body param
+ */
+ access_token: string;
+
+ /**
+ * Body param
+ */
+ type: '1pw_update_access_token';
+
+ /**
+ * Body param: Optional supplied expiry. Omit to clear the old expiry.
+ */
+ access_token_expires_at?: string;
+ }
}
export type ItemUpsertParams =
| ItemUpsertParams.WalletVaultItemRequest
| ItemUpsertParams.CardVaultItemRequest
+ | ItemUpsertParams.CredentialAccountVaultItemRequest
| ItemUpsertParams.CredentialVaultItemRequest;
export declare namespace ItemUpsertParams {
@@ -1961,7 +2632,7 @@ export declare namespace ItemUpsertParams {
export interface Client {
/**
* Select a provider config by ID or name. Responses return the ID. Renaming a
- * config does not change existing wallet bindings; a wallet cannot switch to a
+ * config does not change existing wallet bindings; an item cannot switch to a
* different config after creation.
*/
provider_config: Client.ProviderConfig;
@@ -1972,7 +2643,7 @@ export declare namespace ItemUpsertParams {
export namespace Client {
/**
* Select a provider config by ID or name. Responses return the ID. Renaming a
- * config does not change existing wallet bindings; a wallet cannot switch to a
+ * config does not change existing wallet bindings; an item cannot switch to a
* different config after creation.
*/
export interface ProviderConfig {
@@ -2047,6 +2718,23 @@ export declare namespace ItemUpsertParams {
type: 'card';
}
+ export interface CredentialAccountVaultItemRequest {
+ /**
+ * Path param
+ */
+ id_or_name: string;
+
+ /**
+ * Body param
+ */
+ spec: OnePasswordCredentialAccountSpec;
+
+ /**
+ * Body param
+ */
+ type: 'credential_account';
+ }
+
export interface CredentialVaultItemRequest {
/**
* Path param
@@ -2078,6 +2766,8 @@ export declare namespace Items {
type CardVaultItemSpec as CardVaultItemSpec,
type CardVaultItemState as CardVaultItemState,
type CollectVaultItemOperationRequest as CollectVaultItemOperationRequest,
+ type CredentialAccountVaultItem as CredentialAccountVaultItem,
+ type CredentialAccountVaultItemRequest as CredentialAccountVaultItemRequest,
type CredentialCollectionAction as CredentialCollectionAction,
type CredentialVaultFieldDefinition as CredentialVaultFieldDefinition,
type CredentialVaultFieldInput as CredentialVaultFieldInput,
@@ -2093,6 +2783,19 @@ export declare namespace Items {
type CredentialVaultItemUpdateRequest as CredentialVaultItemUpdateRequest,
type FillVaultItemOperationRequest as FillVaultItemOperationRequest,
type FillVaultItemOperationResult as FillVaultItemOperationResult,
+ type KernelCredentialVaultItemSpec as KernelCredentialVaultItemSpec,
+ type KernelCredentialVaultItemSpecInput as KernelCredentialVaultItemSpecInput,
+ type KernelCredentialVaultItemState as KernelCredentialVaultItemState,
+ type OnePasswordCredentialAccountSpec as OnePasswordCredentialAccountSpec,
+ type OnePasswordCredentialAccountState as OnePasswordCredentialAccountState,
+ type OnePasswordCredentialVaultItemSpec as OnePasswordCredentialVaultItemSpec,
+ type OnePasswordCredentialVaultItemSpecInput as OnePasswordCredentialVaultItemSpecInput,
+ type OnePasswordCredentialVaultItemState as OnePasswordCredentialVaultItemState,
+ type OnePasswordFillVaultItemOperationRequest as OnePasswordFillVaultItemOperationRequest,
+ type OnePasswordFillVaultItemOperationResult as OnePasswordFillVaultItemOperationResult,
+ type OnePasswordOAuthAction as OnePasswordOAuthAction,
+ type OnePasswordRecoverVaultItemOperationRequest as OnePasswordRecoverVaultItemOperationRequest,
+ type OnePasswordRequestAccessVaultItemOperationRequest as OnePasswordRequestAccessVaultItemOperationRequest,
type PrepareCheckoutVaultItemOperationRequest as PrepareCheckoutVaultItemOperationRequest,
type VaultCardAliases as VaultCardAliases,
type VaultCardFillField as VaultCardFillField,
diff --git a/src/resources/vaults/vaults.ts b/src/resources/vaults/vaults.ts
index 43915c90..67d66dde 100644
--- a/src/resources/vaults/vaults.ts
+++ b/src/resources/vaults/vaults.ts
@@ -10,6 +10,8 @@ import {
CardVaultItemSpec,
CardVaultItemState,
CollectVaultItemOperationRequest,
+ CredentialAccountVaultItem,
+ CredentialAccountVaultItemRequest,
CredentialCollectionAction,
CredentialVaultFieldDefinition,
CredentialVaultFieldInput,
@@ -34,6 +36,19 @@ import {
ItemUpdateParams,
ItemUpsertParams,
Items,
+ KernelCredentialVaultItemSpec,
+ KernelCredentialVaultItemSpecInput,
+ KernelCredentialVaultItemState,
+ OnePasswordCredentialAccountSpec,
+ OnePasswordCredentialAccountState,
+ OnePasswordCredentialVaultItemSpec,
+ OnePasswordCredentialVaultItemSpecInput,
+ OnePasswordCredentialVaultItemState,
+ OnePasswordFillVaultItemOperationRequest,
+ OnePasswordFillVaultItemOperationResult,
+ OnePasswordOAuthAction,
+ OnePasswordRecoverVaultItemOperationRequest,
+ OnePasswordRequestAccessVaultItemOperationRequest,
PrepareCheckoutVaultItemOperationRequest,
VaultCardAliases,
VaultCardFillField,
@@ -164,6 +179,8 @@ export declare namespace Vaults {
type CardVaultItemSpec as CardVaultItemSpec,
type CardVaultItemState as CardVaultItemState,
type CollectVaultItemOperationRequest as CollectVaultItemOperationRequest,
+ type CredentialAccountVaultItem as CredentialAccountVaultItem,
+ type CredentialAccountVaultItemRequest as CredentialAccountVaultItemRequest,
type CredentialCollectionAction as CredentialCollectionAction,
type CredentialVaultFieldDefinition as CredentialVaultFieldDefinition,
type CredentialVaultFieldInput as CredentialVaultFieldInput,
@@ -179,6 +196,19 @@ export declare namespace Vaults {
type CredentialVaultItemUpdateRequest as CredentialVaultItemUpdateRequest,
type FillVaultItemOperationRequest as FillVaultItemOperationRequest,
type FillVaultItemOperationResult as FillVaultItemOperationResult,
+ type KernelCredentialVaultItemSpec as KernelCredentialVaultItemSpec,
+ type KernelCredentialVaultItemSpecInput as KernelCredentialVaultItemSpecInput,
+ type KernelCredentialVaultItemState as KernelCredentialVaultItemState,
+ type OnePasswordCredentialAccountSpec as OnePasswordCredentialAccountSpec,
+ type OnePasswordCredentialAccountState as OnePasswordCredentialAccountState,
+ type OnePasswordCredentialVaultItemSpec as OnePasswordCredentialVaultItemSpec,
+ type OnePasswordCredentialVaultItemSpecInput as OnePasswordCredentialVaultItemSpecInput,
+ type OnePasswordCredentialVaultItemState as OnePasswordCredentialVaultItemState,
+ type OnePasswordFillVaultItemOperationRequest as OnePasswordFillVaultItemOperationRequest,
+ type OnePasswordFillVaultItemOperationResult as OnePasswordFillVaultItemOperationResult,
+ type OnePasswordOAuthAction as OnePasswordOAuthAction,
+ type OnePasswordRecoverVaultItemOperationRequest as OnePasswordRecoverVaultItemOperationRequest,
+ type OnePasswordRequestAccessVaultItemOperationRequest as OnePasswordRequestAccessVaultItemOperationRequest,
type PrepareCheckoutVaultItemOperationRequest as PrepareCheckoutVaultItemOperationRequest,
type VaultCardAliases as VaultCardAliases,
type VaultCardFillField as VaultCardFillField,
From eb88be6f349083eb2eea6e0024b2b1362bca291d Mon Sep 17 00:00:00 2001
From: "kernel-internal[bot]"
<260533166+kernel-internal[bot]@users.noreply.github.com>
Date: Wed, 30 Sep 2026 12:57:21 +0000
Subject: [PATCH 5/8] feat: Expose 1Password supplied-token inputs in the Node
SDK
Stainless-Generated-From: 3f0f19ce31808c421bddcb6a3a7ee983b4f76910
---
src/resources/vaults/items.ts | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/src/resources/vaults/items.ts b/src/resources/vaults/items.ts
index 1ab50ff7..01fe78d2 100644
--- a/src/resources/vaults/items.ts
+++ b/src/resources/vaults/items.ts
@@ -1227,6 +1227,13 @@ export namespace OnePasswordCredentialVaultItemSpec {
export interface OnePasswordCredentialVaultItemSpecInput {
provider: '1password';
+ /**
+ * Customer-supplied 1Password broker token. Requires integration_key; stored
+ * encrypted on this item. Omit if providing a connected credential_account item
+ * via the account field.
+ */
+ access_token?: string;
+
/**
* Optional supplied token expiry metadata for stored-token credentials. Omit if
* providing a connected credential_account item via the account field.
@@ -1239,6 +1246,13 @@ export interface OnePasswordCredentialVaultItemSpecInput {
*/
account?: string;
+ /**
+ * Matching customer-supplied integration key. Requires access_token; stored
+ * encrypted on this item. Omit if providing a connected credential_account item
+ * via the account field.
+ */
+ integration_key?: string;
+
/**
* Credential Request v2 input sent to the extension. A credential item may request
* up to five login entries.
From 0e427286118637317cb3f796f5124d4e868494a4 Mon Sep 17 00:00:00 2001
From: "kernel-internal[bot]"
<260533166+kernel-internal[bot]@users.noreply.github.com>
Date: Wed, 30 Sep 2026 13:29:44 +0000
Subject: [PATCH 6/8] feat: chore(stlc): seal custom-code tracking files
Stainless-Generated-From: 63f6e4d346cb4e448b2aff95976470da737c73a4
---
src/resources/vault-provider-configs.ts | 21 +++++++++++++++++++
.../vault-provider-configs.test.ts | 6 +++++-
2 files changed, 26 insertions(+), 1 deletion(-)
diff --git a/src/resources/vault-provider-configs.ts b/src/resources/vault-provider-configs.ts
index 00f9219d..24ba4d00 100644
--- a/src/resources/vault-provider-configs.ts
+++ b/src/resources/vault-provider-configs.ts
@@ -22,6 +22,7 @@ export class VaultProviderConfigs extends APIResource {
* credentials: {
* client_id: 'example-client-id',
* client_secret: 'example-client-secret',
+ * publishable_key: 'pk_live_example',
* },
* name: 'my-link-client',
* provider: 'link',
@@ -143,6 +144,12 @@ export namespace VaultProviderConfig {
provider: 'link';
updated_at: string;
+
+ /**
+ * Stripe publishable key sent to Link when refreshing and revoking wallet grants.
+ * Omitted when not configured.
+ */
+ publishable_key?: string;
}
/**
@@ -191,6 +198,14 @@ export declare namespace VaultProviderConfigCreateParams {
client_id: string;
client_secret: string;
+
+ /**
+ * Stripe publishable key for the account that owns the Link OAuth client. Link
+ * requires it as the bearer credential when Kernel refreshes or revokes imported
+ * wallet grants; without it, those wallets stop working when the imported access
+ * token expires.
+ */
+ publishable_key?: string;
}
}
@@ -234,6 +249,12 @@ export namespace VaultProviderConfigUpdateParams {
*/
export interface Credentials {
client_secret?: string;
+
+ /**
+ * Link configurations only. Stripe publishable key sent to Link when refreshing
+ * and revoking wallet grants.
+ */
+ publishable_key?: string;
}
}
diff --git a/tests/api-resources/vault-provider-configs.test.ts b/tests/api-resources/vault-provider-configs.test.ts
index d75ca7b3..ddf5007a 100644
--- a/tests/api-resources/vault-provider-configs.test.ts
+++ b/tests/api-resources/vault-provider-configs.test.ts
@@ -27,7 +27,11 @@ describe('resource vaultProviderConfigs', () => {
// Mock server tests are disabled
test.skip('create: required and optional params', async () => {
const response = await client.vaultProviderConfigs.create({
- credentials: { client_id: 'x', client_secret: 'x' },
+ credentials: {
+ client_id: 'x',
+ client_secret: 'x',
+ publishable_key: 'pk_test_lK9w2kI5J1',
+ },
name: 'name',
provider: 'link',
});
From 8337e90cd1a8837cdbde925a0a643ed397af7cd4 Mon Sep 17 00:00:00 2001
From: "kernel-internal[bot]"
<260533166+kernel-internal[bot]@users.noreply.github.com>
Date: Wed, 30 Sep 2026 13:35:05 +0000
Subject: [PATCH 7/8] release: 0.114.0
---
.release-please-manifest.json | 2 +-
CHANGELOG.md | 12 ++++++++++++
package.json | 2 +-
src/version.ts | 2 +-
4 files changed, 15 insertions(+), 3 deletions(-)
diff --git a/.release-please-manifest.json b/.release-please-manifest.json
index f85d240a..5b80644b 100644
--- a/.release-please-manifest.json
+++ b/.release-please-manifest.json
@@ -1,3 +1,3 @@
{
- ".": "0.113.0"
+ ".": "0.114.0"
}
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 50a77127..e373d3bb 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,5 +1,17 @@
# Changelog
+## [0.114.0](https://github.com/kernel/kernel-node-sdk/compare/v0.113.0...v0.114.0) (2026-09-30)
+
+
+### Features
+
+* Accept telemetry.storage and settle it at browser create ([3ef0e3b](https://github.com/kernel/kernel-node-sdk/commit/3ef0e3bdb82efcb7e0c507ea754c9873d3215269))
+* Allow export-only network and console telemetry for BAA orgs ([db2aeee](https://github.com/kernel/kernel-node-sdk/commit/db2aeee160879f89df81a0bdd5c3147648fb4c89))
+* chore(stlc): seal custom-code tracking files ([0e42728](https://github.com/kernel/kernel-node-sdk/commit/0e427286118637317cb3f796f5124d4e868494a4))
+* Expose 1Password supplied-token inputs in the Node SDK ([eb88be6](https://github.com/kernel/kernel-node-sdk/commit/eb88be6f349083eb2eea6e0024b2b1362bca291d))
+* Expose missing managed auth check URL as verification unavailable ([eafcdcf](https://github.com/kernel/kernel-node-sdk/commit/eafcdcf57f345c2495fdfc37501b1be2118cb5b8))
+* Let Vaults fill credentials from 1Password ([d2383af](https://github.com/kernel/kernel-node-sdk/commit/d2383af2bd08443d548ae14bff22a790f87d03a9))
+
## [0.113.0](https://github.com/kernel/kernel-node-sdk/compare/v0.112.0...v0.113.0) (2026-09-27)
diff --git a/package.json b/package.json
index 32f1e608..480a7a96 100644
--- a/package.json
+++ b/package.json
@@ -1,6 +1,6 @@
{
"name": "@onkernel/sdk",
- "version": "0.113.0",
+ "version": "0.114.0",
"description": "The official TypeScript library for the Kernel API",
"author": "Kernel <>",
"types": "dist/index.d.ts",
diff --git a/src/version.ts b/src/version.ts
index 4e025b9f..115e062e 100644
--- a/src/version.ts
+++ b/src/version.ts
@@ -1 +1 @@
-export const VERSION = '0.113.0'; // x-release-please-version
+export const VERSION = '0.114.0'; // x-release-please-version
From ffbe75c6151bf00474fa4d3df6582bd7d136781c Mon Sep 17 00:00:00 2001
From: rgarcia <72655+rgarcia@users.noreply.github.com>
Date: Wed, 30 Sep 2026 13:38:52 +0000
Subject: [PATCH 8/8] docs: correct 0.114.0 changelog entry for Link
publishable key
---
CHANGELOG.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/CHANGELOG.md b/CHANGELOG.md
index e373d3bb..9488559c 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -7,10 +7,10 @@
* Accept telemetry.storage and settle it at browser create ([3ef0e3b](https://github.com/kernel/kernel-node-sdk/commit/3ef0e3bdb82efcb7e0c507ea754c9873d3215269))
* Allow export-only network and console telemetry for BAA orgs ([db2aeee](https://github.com/kernel/kernel-node-sdk/commit/db2aeee160879f89df81a0bdd5c3147648fb4c89))
-* chore(stlc): seal custom-code tracking files ([0e42728](https://github.com/kernel/kernel-node-sdk/commit/0e427286118637317cb3f796f5124d4e868494a4))
* Expose 1Password supplied-token inputs in the Node SDK ([eb88be6](https://github.com/kernel/kernel-node-sdk/commit/eb88be6f349083eb2eea6e0024b2b1362bca291d))
* Expose missing managed auth check URL as verification unavailable ([eafcdcf](https://github.com/kernel/kernel-node-sdk/commit/eafcdcf57f345c2495fdfc37501b1be2118cb5b8))
* Let Vaults fill credentials from 1Password ([d2383af](https://github.com/kernel/kernel-node-sdk/commit/d2383af2bd08443d548ae14bff22a790f87d03a9))
+* Send Stripe publishable key when refreshing customer-owned Link grants ([0e42728](https://github.com/kernel/kernel-node-sdk/commit/0e427286118637317cb3f796f5124d4e868494a4))
## [0.113.0](https://github.com/kernel/kernel-node-sdk/compare/v0.112.0...v0.113.0) (2026-09-27)