Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .release-please-manifest.json
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
{
".": "0.115.0"
".": "0.116.0"
}
7 changes: 7 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,12 @@
# Changelog

## [0.116.0](https://github.com/kernel/kernel-node-sdk/compare/v0.115.0...v0.116.0) (2026-10-01)


### Features

* chore(stlc): seal custom-code tracking files ([4616669](https://github.com/kernel/kernel-node-sdk/commit/461666905f32dd676b482af118c0e1bdf8d70f07))

## [0.115.0](https://github.com/kernel/kernel-node-sdk/compare/v0.114.0...v0.115.0) (2026-09-30)


Expand Down
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@onkernel/sdk",
"version": "0.115.0",
"version": "0.116.0",
"description": "The official TypeScript library for the Kernel API",
"author": "Kernel <>",
"types": "dist/index.d.ts",
Expand Down
122 changes: 112 additions & 10 deletions src/resources/credentials.ts
Original file line number Diff line number Diff line change
Expand Up @@ -139,8 +139,29 @@ export interface CreateCredentialRequest {
sso_provider?: string;

/**
* Base32-encoded TOTP secret for generating one-time passwords. Used for automatic
* 2FA during login.
* HMAC algorithm used to generate TOTP codes. Defaults to SHA1 and is ignored when
* an `otpauth://` URI supplies the algorithm.
*/
totp_algorithm?: 'SHA1' | 'SHA256' | 'SHA512';

/**
* Number of digits in generated TOTP codes. Defaults to 6 and is ignored when an
* `otpauth://` URI supplies the digit count.
*/
totp_digits?: number;

/**
* TOTP rotation period in seconds. Defaults to 30 and is ignored when an
* `otpauth://` URI supplies the period.
*/
totp_period?: number;

/**
* Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
* URI. The range accepts existing shorter seeds and longer seeds regardless of
* HMAC algorithm; RFC 6238 recommends unpadded base32 lengths of 32/52/103 for
* SHA1/SHA256/SHA512. Only URI parameters present override the corresponding
* explicit TOTP fields. Used for automatic 2FA during login.
*/
totp_secret?: string;
}
Expand Down Expand Up @@ -193,8 +214,14 @@ export interface Credential {
sso_provider?: string | null;

/**
* Current 6-digit TOTP code. Only included in create/update responses when
* totp_secret was just set.
* HMAC algorithm used to generate TOTP codes. Defaults to SHA1 for credentials
* created before this metadata was stored.
*/
totp_algorithm?: 'SHA1' | 'SHA256' | 'SHA512';

/**
* Current TOTP code. Only included in create/update responses when totp_secret was
* just set.
*/
totp_code?: string;

Expand All @@ -203,6 +230,18 @@ export interface Credential {
*/
totp_code_expires_at?: string;

/**
* Number of digits in generated TOTP codes. Defaults to 6 for credentials created
* before this metadata was stored.
*/
totp_digits?: number;

/**
* TOTP rotation period in seconds. Defaults to 30 for credentials created before
* this metadata was stored.
*/
totp_period?: number;

/**
* The field names stored in this credential's values (e.g., username, password).
* Values themselves are never returned. Included on single-credential responses
Expand Down Expand Up @@ -233,8 +272,29 @@ export interface UpdateCredentialRequest {
sso_provider?: string | null;

/**
* Base32-encoded TOTP secret for generating one-time passwords. Spaces and
* formatting are automatically normalized. Set to empty string to remove.
* HMAC algorithm used to generate TOTP codes. Requires totp_secret and is ignored
* when an `otpauth://` URI supplies the algorithm.
*/
totp_algorithm?: 'SHA1' | 'SHA256' | 'SHA512';

/**
* Number of digits in generated TOTP codes. Requires totp_secret and is ignored
* when an `otpauth://` URI supplies the digit count.
*/
totp_digits?: number;

/**
* TOTP rotation period in seconds. Requires totp_secret and is ignored when an
* `otpauth://` URI supplies the period.
*/
totp_period?: number;

/**
* Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
* URI. Only URI parameters present override the corresponding explicit TOTP
* fields. When rotating a raw secret, omitted fields preserve their existing
* values; a new URI defaults unspecified fields to SHA1/6/30. Set to empty string
* to remove the secret and its metadata.
*/
totp_secret?: string;

Expand Down Expand Up @@ -282,8 +342,29 @@ export interface CredentialCreateParams {
sso_provider?: string;

/**
* Base32-encoded TOTP secret for generating one-time passwords. Used for automatic
* 2FA during login.
* HMAC algorithm used to generate TOTP codes. Defaults to SHA1 and is ignored when
* an `otpauth://` URI supplies the algorithm.
*/
totp_algorithm?: 'SHA1' | 'SHA256' | 'SHA512';

/**
* Number of digits in generated TOTP codes. Defaults to 6 and is ignored when an
* `otpauth://` URI supplies the digit count.
*/
totp_digits?: number;

/**
* TOTP rotation period in seconds. Defaults to 30 and is ignored when an
* `otpauth://` URI supplies the period.
*/
totp_period?: number;

/**
* Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
* URI. The range accepts existing shorter seeds and longer seeds regardless of
* HMAC algorithm; RFC 6238 recommends unpadded base32 lengths of 32/52/103 for
* SHA1/SHA256/SHA512. Only URI parameters present override the corresponding
* explicit TOTP fields. Used for automatic 2FA during login.
*/
totp_secret?: string;
}
Expand All @@ -307,8 +388,29 @@ export interface CredentialUpdateParams {
sso_provider?: string | null;

/**
* Base32-encoded TOTP secret for generating one-time passwords. Spaces and
* formatting are automatically normalized. Set to empty string to remove.
* HMAC algorithm used to generate TOTP codes. Requires totp_secret and is ignored
* when an `otpauth://` URI supplies the algorithm.
*/
totp_algorithm?: 'SHA1' | 'SHA256' | 'SHA512';

/**
* Number of digits in generated TOTP codes. Requires totp_secret and is ignored
* when an `otpauth://` URI supplies the digit count.
*/
totp_digits?: number;

/**
* TOTP rotation period in seconds. Requires totp_secret and is ignored when an
* `otpauth://` URI supplies the period.
*/
totp_period?: number;

/**
* Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
* URI. Only URI parameters present override the corresponding explicit TOTP
* fields. When rotating a raw secret, omitted fields preserve their existing
* values; a new URI defaults unspecified fields to SHA1/6/30. Set to empty string
* to remove the secret and its metadata.
*/
totp_secret?: string;

Expand Down
17 changes: 15 additions & 2 deletions src/resources/vaults/items.ts
Original file line number Diff line number Diff line change
Expand Up @@ -413,8 +413,9 @@ export namespace CardVaultItemSpec {

/**
* AgentCard reusable live payment card. Test-mode card creation is not supported.
* Each checkout creates an approval-gated authorization for spec.merchant /
* spec.amount. The card stays ready after each authorization.
* Each checkout creates an authorization for spec.merchant / spec.amount that the
* cardholder approves, unless AgentCard runs it under one of the cardholder's
* autopilot rules. The card stays ready after each authorization.
*/
export interface AgentCardCardVaultItemSpec {
/**
Expand Down Expand Up @@ -442,6 +443,18 @@ export namespace CardVaultItemSpec {
* picks on the approval screen.
*/
card_id?: string;

/**
* Origin of the top-level checkout page, such as https://shop.example.com: https,
* a lowercase host, a port only when it is not 443, and no path. http is accepted
* only for localhost test pages. Checkouts without a preparation send it to
* AgentCard, which uses it to match the cardholder's autopilot rules; prepared
* checkouts send the preparation's merchant_origin instead. Kernel sends the
* declared value and does not compare it with the page the browser has open.
* Omitted, those checkouts ask the cardholder to approve. Card updates replace the
* whole spec, so an update that omits it removes it.
*/
checkout_origin?: string;
}
}

Expand Down
2 changes: 1 addition & 1 deletion src/version.ts
Original file line number Diff line number Diff line change
@@ -1 +1 @@
export const VERSION = '0.115.0'; // x-release-please-version
export const VERSION = '0.116.0'; // x-release-please-version
3 changes: 3 additions & 0 deletions tests/api-resources/credentials.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,9 @@ describe('resource credentials', () => {
name: 'my-netflix-login',
values: { username: 'user@example.com', password: 'mysecretpassword' },
sso_provider: 'google',
totp_algorithm: 'SHA1',
totp_digits: 6,
totp_period: 30,
totp_secret: 'JBSWY3DPEHPK3PXP',
});
});
Expand Down
Loading