diff --git a/.release-please-manifest.json b/.release-please-manifest.json
index c8f1da56..3200815c 100644
--- a/.release-please-manifest.json
+++ b/.release-please-manifest.json
@@ -1,3 +1,3 @@
{
- ".": "0.116.0"
+ ".": "0.117.0"
}
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 76c7c22a..09a70a0d 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,5 +1,12 @@
# Changelog
+## [0.117.0](https://github.com/kernel/kernel-node-sdk/compare/v0.116.0...v0.117.0) (2026-10-02)
+
+
+### Features
+
+* Invoke WebMCP tools with vault item fields ([c05cf49](https://github.com/kernel/kernel-node-sdk/commit/c05cf4977c3fa33b2525e61eebd74728991e5e36))
+
## [0.116.0](https://github.com/kernel/kernel-node-sdk/compare/v0.115.0...v0.116.0) (2026-10-01)
diff --git a/api.md b/api.md
index 0d32721d..6cd750a7 100644
--- a/api.md
+++ b/api.md
@@ -537,8 +537,11 @@ Types:
- VaultItemEvent
- VaultItemOperationResponse
- VaultPaymentMethod
+- VaultWebmcpBinding
- WalletVaultItemSpec
- WalletVaultItemState
+- WebmcpInvokeVaultItemOperationRequest
+- WebmcpInvokeVaultItemOperationResult
- ItemListResponse
- ItemEventsResponse
diff --git a/package.json b/package.json
index 06cb0113..1a5b569b 100644
--- a/package.json
+++ b/package.json
@@ -1,6 +1,6 @@
{
"name": "@onkernel/sdk",
- "version": "0.116.0",
+ "version": "0.117.0",
"description": "The official TypeScript library for the Kernel API",
"author": "Kernel <>",
"types": "dist/index.d.ts",
diff --git a/src/resources/vaults/index.ts b/src/resources/vaults/index.ts
index f25e0324..69b544b1 100644
--- a/src/resources/vaults/index.ts
+++ b/src/resources/vaults/index.ts
@@ -50,8 +50,11 @@ export {
type VaultItemEvent,
type VaultItemOperationResponse,
type VaultPaymentMethod,
+ type VaultWebmcpBinding,
type WalletVaultItemSpec,
type WalletVaultItemState,
+ type WebmcpInvokeVaultItemOperationRequest,
+ type WebmcpInvokeVaultItemOperationResult,
type ItemListResponse,
type ItemEventsResponse,
type ItemRetrieveParams,
diff --git a/src/resources/vaults/items.ts b/src/resources/vaults/items.ts
index 05a29073..bdc632b6 100644
--- a/src/resources/vaults/items.ts
+++ b/src/resources/vaults/items.ts
@@ -641,7 +641,8 @@ export namespace CredentialAccountVaultItem {
| '1pw_access_request_status'
| '1pw_fill'
| '1pw_recover'
- | '1pw_update_access_token';
+ | '1pw_update_access_token'
+ | 'webmcp_invoke';
}
}
@@ -907,7 +908,8 @@ export namespace CredentialVaultItem {
| '1pw_access_request_status'
| '1pw_fill'
| '1pw_recover'
- | '1pw_update_access_token';
+ | '1pw_update_access_token'
+ | 'webmcp_invoke';
}
export interface OnePasswordAccessApprovalAction {
@@ -1772,7 +1774,8 @@ export namespace VaultItem {
| '1pw_access_request_status'
| '1pw_fill'
| '1pw_recover'
- | '1pw_update_access_token';
+ | '1pw_update_access_token'
+ | 'webmcp_invoke';
}
/**
@@ -1844,7 +1847,8 @@ export namespace VaultItem {
| '1pw_access_request_status'
| '1pw_fill'
| '1pw_recover'
- | '1pw_update_access_token';
+ | '1pw_update_access_token'
+ | 'webmcp_invoke';
}
}
}
@@ -1911,9 +1915,9 @@ export interface VaultItemEvent {
}
/**
- * The submission result reported by the 1Password extension when available. Kernel
- * returns fill_unknown if the extension call has no conclusive result. Inspect the
- * page to determine successful authentication on the website.
+ * Authorization and preparation return the existing item shape. Fill returns a
+ * value-free result; WebMCP invocation returns the tool's output. Neither persists
+ * transient outcomes on the item.
*/
export type VaultItemOperationResponse =
| VaultItemOperationResponse.WalletVaultItem
@@ -1921,7 +1925,8 @@ export type VaultItemOperationResponse =
| CredentialAccountVaultItem
| CredentialVaultItem
| FillVaultItemOperationResult
- | OnePasswordFillVaultItemOperationResult;
+ | OnePasswordFillVaultItemOperationResult
+ | WebmcpInvokeVaultItemOperationResult;
export namespace VaultItemOperationResponse {
export interface WalletVaultItem {
@@ -1991,7 +1996,8 @@ export namespace VaultItemOperationResponse {
| '1pw_access_request_status'
| '1pw_fill'
| '1pw_recover'
- | '1pw_update_access_token';
+ | '1pw_update_access_token'
+ | 'webmcp_invoke';
}
/**
@@ -2063,7 +2069,8 @@ export namespace VaultItemOperationResponse {
| '1pw_access_request_status'
| '1pw_fill'
| '1pw_recover'
- | '1pw_update_access_token';
+ | '1pw_update_access_token'
+ | 'webmcp_invoke';
}
}
}
@@ -2118,6 +2125,27 @@ export namespace VaultPaymentMethod {
}
}
+export interface VaultWebmcpBinding {
+ /**
+ * A declared, populated credential field or supported card field. A TOTP field
+ * supplies a fresh code, never its seed.
+ */
+ field: string;
+
+ /**
+ * RFC 6901 JSON Pointer to an existing null value in input. Object keys are exact;
+ * array indices must be canonical and in range. No root or array-append paths.
+ * Each path and each field may occur only once.
+ */
+ input_path: string;
+
+ /**
+ * Required for card expiration (MM/YY or MM/YYYY), forbidden for other fields.
+ * Invalid formats are rejected before invocation.
+ */
+ format?: string;
+}
+
/**
* AgentCard wallet. Omit provider_config to use Kernel-managed credentials, or
* select a customer-owned configuration. Mode (sandbox vs live) is determined by
@@ -2235,6 +2263,85 @@ export namespace WalletVaultItemState {
}
}
+/**
+ * Invoke a WebMCP tool using values from a vaulted item. The browser must be
+ * attached to the item's vault. Discover the tool_ref, inputSchema, and source
+ * with GET /browsers/{id_or_name}/webmcp/tools or webmcp.listTools() in the
+ * Browser REPL (POST /browsers/{id_or_name}/repl) before invoking it. Input paths
+ * replace existing null slots in input. Tool output is returned without redaction
+ * and may include the supplied values. The tool may submit or perform other side
+ * effects. Any item destination restrictions apply to the tool's top-level page
+ * and registering frame (if any).
+ */
+export interface WebmcpInvokeVaultItemOperationRequest {
+ bindings: Array;
+
+ /**
+ * Browser session ID, not a reusable browser name.
+ */
+ browser_id: string;
+
+ /**
+ * Public tool arguments with an existing null slot at each binding path. At most
+ * 64 KiB after JSON serialization, including substituted values. Never include
+ * vault values here.
+ */
+ input: { [key: string]: unknown };
+
+ /**
+ * Exact top-level URL from the discovered tool source (fragment omitted). This
+ * pins the target page; it does not authorize a destination.
+ */
+ page_url: string;
+
+ /**
+ * Opaque reference to the exact live WebMCP registration.
+ */
+ tool_ref: string;
+
+ type: 'webmcp_invoke';
+
+ /**
+ * Tool invocation timeout in seconds; preflight and response handling have an
+ * additional bounded allowance. An indeterminate outcome is not retried.
+ */
+ timeout_sec?: number;
+}
+
+/**
+ * Returns the same tool result fields as the browser WebMCP invoke API, plus the
+ * vault operation discriminator. Output and error text are untrusted page-provided
+ * data, returned without redaction; tools may include supplied vault values.
+ * Inspect the browser page to determine whether the intended site action
+ * succeeded.
+ */
+export interface WebmcpInvokeVaultItemOperationResult {
+ /**
+ * Unknown means invocation may have run; do not retry automatically. No status
+ * confirms that the website accepted the action.
+ */
+ status: 'completed' | 'canceled' | 'error' | 'awaiting_submission' | 'unknown';
+
+ type: 'webmcp_invoke';
+
+ /**
+ * Untrusted page-provided error text, returned without redaction. May contain
+ * supplied vault values.
+ */
+ error_text?: string;
+
+ /**
+ * Present when the browser reported one.
+ */
+ invocation_id?: string;
+
+ /**
+ * Untrusted page-provided output, returned without redaction. May contain supplied
+ * vault values.
+ */
+ output?: unknown;
+}
+
export type ItemListResponse = Array;
export type ItemEventsResponse = Array;
@@ -2344,7 +2451,8 @@ export type ItemPerformOperationParams =
| ItemPerformOperationParams.OnePasswordPollAccessVaultItemOperationRequest
| ItemPerformOperationParams.OnePasswordFillVaultItemOperationRequest
| ItemPerformOperationParams.OnePasswordRecoverVaultItemOperationRequest
- | ItemPerformOperationParams.OnePasswordUpdateAccessTokenVaultItemOperationRequest;
+ | ItemPerformOperationParams.OnePasswordUpdateAccessTokenVaultItemOperationRequest
+ | ItemPerformOperationParams.WebmcpInvokeVaultItemOperationRequest;
export declare namespace ItemPerformOperationParams {
export interface AuthorizeVaultItemOperationRequest {
@@ -2551,6 +2659,52 @@ export declare namespace ItemPerformOperationParams {
*/
access_token_expires_at?: string;
}
+
+ export interface WebmcpInvokeVaultItemOperationRequest {
+ /**
+ * Path param
+ */
+ id_or_name: string;
+
+ /**
+ * Body param
+ */
+ bindings: Array;
+
+ /**
+ * Body param: Browser session ID, not a reusable browser name.
+ */
+ browser_id: string;
+
+ /**
+ * Body param: Public tool arguments with an existing null slot at each binding
+ * path. At most 64 KiB after JSON serialization, including substituted values.
+ * Never include vault values here.
+ */
+ input: { [key: string]: unknown };
+
+ /**
+ * Body param: Exact top-level URL from the discovered tool source (fragment
+ * omitted). This pins the target page; it does not authorize a destination.
+ */
+ page_url: string;
+
+ /**
+ * Body param: Opaque reference to the exact live WebMCP registration.
+ */
+ tool_ref: string;
+
+ /**
+ * Body param
+ */
+ type: 'webmcp_invoke';
+
+ /**
+ * Body param: Tool invocation timeout in seconds; preflight and response handling
+ * have an additional bounded allowance. An indeterminate outcome is not retried.
+ */
+ timeout_sec?: number;
+ }
}
export type ItemUpsertParams =
@@ -2834,8 +2988,11 @@ export declare namespace Items {
type VaultItemEvent as VaultItemEvent,
type VaultItemOperationResponse as VaultItemOperationResponse,
type VaultPaymentMethod as VaultPaymentMethod,
+ type VaultWebmcpBinding as VaultWebmcpBinding,
type WalletVaultItemSpec as WalletVaultItemSpec,
type WalletVaultItemState as WalletVaultItemState,
+ type WebmcpInvokeVaultItemOperationRequest as WebmcpInvokeVaultItemOperationRequest,
+ type WebmcpInvokeVaultItemOperationResult as WebmcpInvokeVaultItemOperationResult,
type ItemListResponse as ItemListResponse,
type ItemEventsResponse as ItemEventsResponse,
type ItemRetrieveParams as ItemRetrieveParams,
diff --git a/src/resources/vaults/vaults.ts b/src/resources/vaults/vaults.ts
index 67d66dde..57c1b4bb 100644
--- a/src/resources/vaults/vaults.ts
+++ b/src/resources/vaults/vaults.ts
@@ -60,8 +60,11 @@ import {
VaultItemEvent,
VaultItemOperationResponse,
VaultPaymentMethod,
+ VaultWebmcpBinding,
WalletVaultItemSpec,
WalletVaultItemState,
+ WebmcpInvokeVaultItemOperationRequest,
+ WebmcpInvokeVaultItemOperationResult,
} from './items';
import { APIPromise } from '../../core/api-promise';
import { OffsetPagination, type OffsetPaginationParams, PagePromise } from '../../core/pagination';
@@ -220,8 +223,11 @@ export declare namespace Vaults {
type VaultItemEvent as VaultItemEvent,
type VaultItemOperationResponse as VaultItemOperationResponse,
type VaultPaymentMethod as VaultPaymentMethod,
+ type VaultWebmcpBinding as VaultWebmcpBinding,
type WalletVaultItemSpec as WalletVaultItemSpec,
type WalletVaultItemState as WalletVaultItemState,
+ type WebmcpInvokeVaultItemOperationRequest as WebmcpInvokeVaultItemOperationRequest,
+ type WebmcpInvokeVaultItemOperationResult as WebmcpInvokeVaultItemOperationResult,
type ItemListResponse as ItemListResponse,
type ItemEventsResponse as ItemEventsResponse,
type ItemRetrieveParams as ItemRetrieveParams,
diff --git a/src/version.ts b/src/version.ts
index e15e6528..d3116d4a 100644
--- a/src/version.ts
+++ b/src/version.ts
@@ -1 +1 @@
-export const VERSION = '0.116.0'; // x-release-please-version
+export const VERSION = '0.117.0'; // x-release-please-version