Skip to content

release: 0.117.0 - #199

Merged
rgarcia merged 2 commits into
mainfrom
release-please--branches--main--changes--next--components--sdk
Oct 2, 2026
Merged

rgarcia merged 2 commits into
mainfrom
release-please--branches--main--changes--next--components--sdk

Conversation

@kernel-internal

@kernel-internal kernel-internal Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Automated Release PR

0.117.0 (2026-10-02)

Features

  • Invoke WebMCP tools with vault item fields (c05cf49)

This pull request is managed by Stainless's GitHub App.

The semver version number is based on included commit messages. Alternatively, you can manually set the version number in the title of this pull request.

For a better experience, it is recommended to use either rebase-merge or squash-merge when merging this pull request.

🔗 Stainless website
📚 Read the docs
🙋 Reach out for help or questions


Note

Medium Risk
Adds typed support for vault-backed WebMCP invocation where secrets can reach browser tools and responses may echo them unredacted; SDK change is mostly generated types, but callers must treat this as a sensitive, side-effect-capable path.

Overview
Release 0.117.0 bumps package/version metadata and documents the headline feature: invoke WebMCP tools using vaulted item fields via client.vaults.items.performOperation with type: 'webmcp_invoke'.

The SDK adds VaultWebmcpBinding, WebmcpInvokeVaultItemOperationRequest, and WebmcpInvokeVaultItemOperationResult, wiring them into ItemPerformOperationParams, VaultItemOperationResponse, and vault item available_operations unions (alongside existing ops like fill and 1pw_fill). Bindings map credential/card fields to JSON Pointer paths in public input (null slots only); the request also requires browser_id, tool_ref, and page_url.

Docs note that WebMCP invocation returns unredacted, page-provided output/errors (possibly including injected vault values) and does not persist transient results on the item; VaultItemOperationResponse commentary is updated to reflect that distinction from fill/authorize flows.

Reviewed by Cursor Bugbot for commit 5bfcf45. Bugbot is set up for automated code reviews on this repo. Configure here.

Stainless-Generated-From: 90f88eaed536d247a3ad0c92ada5635339155c1a

@rgarcia rgarcia left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed generated WebMCP invoke request/response types and release checks; approved for release.

@rgarcia
rgarcia merged commit 545fed5 into main Oct 2, 2026
11 checks passed
@kernel-internal

Copy link
Copy Markdown
Contributor Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant