Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .release-please-manifest.json
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
{
".": "0.117.0"
".": "0.118.0"
}
8 changes: 8 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,13 @@
# Changelog

## [0.118.0](https://github.com/kernel/kernel-node-sdk/compare/v0.117.0...v0.118.0) (2026-10-02)


### Features

* Add a query filter to the vault list endpoint ([2a9d2e8](https://github.com/kernel/kernel-node-sdk/commit/2a9d2e844cb301f882f807a304b7fb6dc82ea077))
* Add Kernel wallets backed by VGS agentic network tokens, with hosted card capture ([3fced64](https://github.com/kernel/kernel-node-sdk/commit/3fced64a6872afc6dd92f22713c61716cc75ecaa))

## [0.117.0](https://github.com/kernel/kernel-node-sdk/compare/v0.116.0...v0.117.0) (2026-10-02)


Expand Down
4 changes: 4 additions & 0 deletions api.md
Original file line number Diff line number Diff line change
Expand Up @@ -513,9 +513,13 @@ Types:
- <code><a href="./src/resources/vaults/items.ts">CredentialVaultItemUpdateRequest</a></code>
- <code><a href="./src/resources/vaults/items.ts">FillVaultItemOperationRequest</a></code>
- <code><a href="./src/resources/vaults/items.ts">FillVaultItemOperationResult</a></code>
- <code><a href="./src/resources/vaults/items.ts">KernelCardState</a></code>
- <code><a href="./src/resources/vaults/items.ts">KernelCardVaultItemSpec</a></code>
- <code><a href="./src/resources/vaults/items.ts">KernelCredentialVaultItemSpec</a></code>
- <code><a href="./src/resources/vaults/items.ts">KernelCredentialVaultItemSpecInput</a></code>
- <code><a href="./src/resources/vaults/items.ts">KernelCredentialVaultItemState</a></code>
- <code><a href="./src/resources/vaults/items.ts">KernelWalletState</a></code>
- <code><a href="./src/resources/vaults/items.ts">KernelWalletVaultItemSpec</a></code>
- <code><a href="./src/resources/vaults/items.ts">OnePasswordCredentialAccountSpec</a></code>
- <code><a href="./src/resources/vaults/items.ts">OnePasswordCredentialAccountState</a></code>
- <code><a href="./src/resources/vaults/items.ts">OnePasswordCredentialVaultItemSpec</a></code>
Expand Down
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@onkernel/sdk",
"version": "0.117.0",
"version": "0.118.0",
"description": "The official TypeScript library for the Kernel API",
"author": "Kernel <>",
"types": "dist/index.d.ts",
Expand Down
4 changes: 4 additions & 0 deletions src/resources/vaults/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -26,9 +26,13 @@ export {
type CredentialVaultItemUpdateRequest,
type FillVaultItemOperationRequest,
type FillVaultItemOperationResult,
type KernelCardState,
type KernelCardVaultItemSpec,
type KernelCredentialVaultItemSpec,
type KernelCredentialVaultItemSpecInput,
type KernelCredentialVaultItemState,
type KernelWalletState,
type KernelWalletVaultItemSpec,
type OnePasswordCredentialAccountSpec,
type OnePasswordCredentialAccountState,
type OnePasswordCredentialVaultItemSpec,
Expand Down
183 changes: 164 additions & 19 deletions src/resources/vaults/items.ts
Original file line number Diff line number Diff line change
Expand Up @@ -87,10 +87,13 @@ export class Items extends APIResource {

/**
* Unresolved payment operations normally block deletion, including operations on
* child cards of a wallet. An AgentCard card in recovery_required whose checkout
* create response returned no authorization ID may be explicitly abandoned by
* deleting that card directly; deleting its wallet or vault remains blocked.
* Deleting or recreating an item is not proof that a payment did not occur.
* child cards of a wallet. Deleting a connected Kernel wallet first blocks new
* payments on it, then removes its enrolled card. If that fails, the wallet is
* kept and keeps refusing payments; retry the deletion. An AgentCard card in
* recovery_required whose checkout create response returned no authorization ID
* may be explicitly abandoned by deleting that card directly; deleting its wallet
* or vault remains blocked. Deleting or recreating an item is not proof that a
* payment did not occur.
*
* @example
* ```ts
Expand Down Expand Up @@ -304,8 +307,8 @@ export type AgentcardPreparedProcessor =
| 'adyen';

/**
* Authorize a Link card using its existing purchase specification. Use only after
* explicit user approval and when the item advertises authorize. Do not
* Authorize a Link or Kernel card using its existing purchase specification. Use
* only after explicit user approval and when the item advertises authorize. Do not
* automatically retry provider failures or indeterminate outcomes. Checkout
* context is not accepted.
*/
Expand All @@ -318,7 +321,8 @@ export interface AuthorizeVaultItemOperationRequest {
*/
export type CardVaultItemSpec =
| CardVaultItemSpec.LinkCardVaultItemSpec
| CardVaultItemSpec.AgentCardCardVaultItemSpec;
| CardVaultItemSpec.AgentCardCardVaultItemSpec
| KernelCardVaultItemSpec;

export namespace CardVaultItemSpec {
/**
Expand Down Expand Up @@ -462,7 +466,10 @@ export namespace CardVaultItemSpec {
* Issued Link cards retain encrypted card material for the fill operation. Link
* cards do not expose aliases or support egress substitution.
*/
export type CardVaultItemState = CardVaultItemState.LinkCardState | CardVaultItemState.AgentCardCardState;
export type CardVaultItemState =
| CardVaultItemState.LinkCardState
| CardVaultItemState.AgentCardCardState
| KernelCardState;

export namespace CardVaultItemState {
/**
Expand Down Expand Up @@ -501,6 +508,11 @@ export namespace CardVaultItemState {

last4?: string;

/**
* Last four digits of the network token presented to the merchant.
*/
token_last4?: string;

[k: string]: string | undefined;
}
}
Expand Down Expand Up @@ -559,6 +571,11 @@ export namespace CardVaultItemState {

last4?: string;

/**
* Last four digits of the network token presented to the merchant.
*/
token_last4?: string;

[k: string]: string | undefined;
}
}
Expand Down Expand Up @@ -1015,11 +1032,11 @@ export interface CredentialVaultItemUpdateRequest {
}

/**
* Fill selected fields from one ready credential or ready, unexpired Link card
* into a browser linked to its vault. Only invoke when the item advertises `fill`.
* Browser and vault must belong to the same project. Kernel checks access and
* allowed destinations before filling; providing a page URL does not authorize a
* destination.
* Fill selected fields from one ready credential or ready, unexpired Link or
* Kernel card into a browser linked to its vault. Only invoke when the item
* advertises `fill`. Browser and vault must belong to the same project. Kernel
* checks access and allowed destinations before filling; providing a page URL does
* not authorize a destination.
*
* Find exactly one open page matching `page_url`. Credential items may omit
* `page_url` to require exactly one open page; cards require an HTTPS page URL.
Expand All @@ -1035,9 +1052,10 @@ export interface CredentialVaultItemUpdateRequest {
*
* Fill in request order and stop on the first failure. This operation is not
* atomic: previously filled fields are not rolled back. Never submit the form or
* click buttons, though input/change events may trigger site behavior. Link cards
* use fill for browser checkout and do not expose aliases or support egress
* substitution. Do not automatically retry a failed or indeterminate operation.
* click buttons, though input/change events may trigger site behavior. Link and
* Kernel cards use fill for browser checkout and do not expose aliases or support
* egress substitution. Do not automatically retry a failed or indeterminate
* operation.
*
* Secret values are never returned or included in operation logs, traces, audit
* events, or error details. This does not prevent an agent with unrestricted
Expand Down Expand Up @@ -1089,6 +1107,98 @@ export interface FillVaultItemOperationResult {
type: 'fill';
}

/**
* A ready Kernel card retains its encrypted network token and one-time code for
* the fill operation until the item's expires_at. Fill and submit checkout before
* then. Visa cards can be enrolled, but Visa purchases are not yet supported and
* authorize returns 400; supported Mastercard purchases need no cardholder
* approval. masks.last4 is the enrolled card's last four digits; masks.token_last4
* is the network token's last four digits shown to the merchant. Kernel cards do
* not expose aliases or support egress substitution. Kernel does not observe
* whether the merchant charged the card.
*/
export interface KernelCardState {
provider: 'kernel';

/**
* recovery_required means issuing the one-time code has an unresolved outcome.
* Kernel never issues another code for the item automatically, and the item cannot
* be deleted or replaced until the original attempt is reconciled with support.
* When status_reason says the provider refused retrieval before acceptance, no
* code was issued and a later read retries.
*/
status:
| 'requested'
| 'pending_authorization'
| 'ready'
| 'consumed'
| 'expired'
| 'declined'
| 'recovery_required';

/**
* Informational registrable domain. Fill is locked to merchant_url's exact origin.
*/
domains?: Array<string>;

masks?: KernelCardState.Masks;

status_reason?: string;
}

export namespace KernelCardState {
export interface Masks {
brand?: string;

last4?: string;

/**
* Last four digits of the network token presented to the merchant.
*/
token_last4?: string;

[k: string]: string | undefined;
}
}

/**
* One live purchase with a Kernel-enrolled card. Authorization obtains an agentic
* network token number, expiry and one-time 3-digit code. They are stored
* encrypted for the fill operation, which types them only on merchant_url's
* origin; the merchant's own checkout submits the payment. The one-time code is
* valid until the item's expires_at; fill and submit checkout before then. Visa
* cards can be enrolled, but Visa purchases are not yet supported: authorize
* returns 400. Supported Mastercard purchases need no cardholder approval. Card
* updates are not supported; delete and create a new item instead.
*/
export interface KernelCardVaultItemSpec {
/**
* Integer amount in minor currency units (at most 50000), bound to the one-time
* code.
*/
amount: number;

/**
* ISO 4217 code. Supported: aud, brl, cad, chf, czk, dkk, eur, gbp, hkd, inr, jpy,
* krw, mxn, nok, nzd, pln, sek, sgd, usd, zar.
*/
currency: string;

merchant_name: string;

/**
* Merchant checkout URL. Fill is allowed only on this URL's origin.
*/
merchant_url: string;

provider: 'kernel';

/**
* Key of the Kernel wallet item whose enrolled card pays.
*/
wallet: string;
}

export interface KernelCredentialVaultItemSpec {
/**
* Ordered field definitions rendered in this order by credential collection forms.
Expand Down Expand Up @@ -1145,6 +1255,34 @@ export interface KernelCredentialVaultItemState {
status: 'pending_collection' | 'ready';
}

export interface KernelWalletState {
provider: 'kernel';

/**
* pending_authorization asks the cardholder to use the card_enrollment action.
* connected is ready for supported purchases. reconnect_required asks the
* cardholder to use a new card_enrollment action after an uncertain enrollment was
* safely removed. degraded means the enrollment outcome is unknown and the wallet
* must be deleted before adding another card.
*/
status: 'pending_authorization' | 'connected' | 'reconnect_required' | 'degraded';

status_reason?: string;
}

/**
* One card Kernel enrolls for Visa or Mastercard agentic network tokens using
* Kernel-managed credentials. Creation returns a card_enrollment action: the
* cardholder enters the card and their email on a Kernel-hosted page, then Kernel
* enrolls the securely stored card. The card number never reaches Kernel. The
* connected wallet's payment_methods expansion lists the enrolled card. Visa cards
* can be enrolled, but Visa purchases are not yet supported: authorize
* returns 400.
*/
export interface KernelWalletVaultItemSpec {
provider: 'kernel';
}

export interface OnePasswordCredentialAccountSpec {
authorization: OnePasswordCredentialAccountSpec.Authorization;

Expand Down Expand Up @@ -2156,7 +2294,8 @@ export interface VaultWebmcpBinding {
*/
export type WalletVaultItemSpec =
| WalletVaultItemSpec.LinkWalletVaultItemSpec
| WalletVaultItemSpec.AgentCardWalletVaultItemSpec;
| WalletVaultItemSpec.AgentCardWalletVaultItemSpec
| KernelWalletVaultItemSpec;

export namespace WalletVaultItemSpec {
export interface LinkWalletVaultItemSpec {
Expand Down Expand Up @@ -2238,7 +2377,8 @@ export namespace WalletVaultItemSpec {

export type WalletVaultItemState =
| WalletVaultItemState.LinkWalletState
| WalletVaultItemState.AgentCardWalletState;
| WalletVaultItemState.AgentCardWalletState
| KernelWalletState;

export namespace WalletVaultItemState {
export interface LinkWalletState {
Expand Down Expand Up @@ -2730,7 +2870,8 @@ export declare namespace ItemUpsertParams {
*/
spec:
| WalletVaultItemRequest.LinkWalletVaultItemRequestSpec
| WalletVaultItemRequest.AgentCardWalletVaultItemSpec;
| WalletVaultItemRequest.AgentCardWalletVaultItemSpec
| KernelWalletVaultItemSpec;

/**
* Body param
Expand Down Expand Up @@ -2964,9 +3105,13 @@ export declare namespace Items {
type CredentialVaultItemUpdateRequest as CredentialVaultItemUpdateRequest,
type FillVaultItemOperationRequest as FillVaultItemOperationRequest,
type FillVaultItemOperationResult as FillVaultItemOperationResult,
type KernelCardState as KernelCardState,
type KernelCardVaultItemSpec as KernelCardVaultItemSpec,
type KernelCredentialVaultItemSpec as KernelCredentialVaultItemSpec,
type KernelCredentialVaultItemSpecInput as KernelCredentialVaultItemSpecInput,
type KernelCredentialVaultItemState as KernelCredentialVaultItemState,
type KernelWalletState as KernelWalletState,
type KernelWalletVaultItemSpec as KernelWalletVaultItemSpec,
type OnePasswordCredentialAccountSpec as OnePasswordCredentialAccountSpec,
type OnePasswordCredentialAccountState as OnePasswordCredentialAccountState,
type OnePasswordCredentialVaultItemSpec as OnePasswordCredentialVaultItemSpec,
Expand Down
23 changes: 19 additions & 4 deletions src/resources/vaults/vaults.ts
Original file line number Diff line number Diff line change
Expand Up @@ -36,9 +36,13 @@ import {
ItemUpdateParams,
ItemUpsertParams,
Items,
KernelCardState,
KernelCardVaultItemSpec,
KernelCredentialVaultItemSpec,
KernelCredentialVaultItemSpecInput,
KernelCredentialVaultItemState,
KernelWalletState,
KernelWalletVaultItemSpec,
OnePasswordCredentialAccountSpec,
OnePasswordCredentialAccountState,
OnePasswordCredentialVaultItemSpec,
Expand Down Expand Up @@ -106,9 +110,11 @@ export class Vaults extends APIResource {
}

/**
* Unresolved payment operations block deletion. Reconcile the original attempt
* with the provider or support first; deleting or recreating an item is not proof
* that a payment did not occur.
* Unresolved payment operations block deletion. Deleting a connected Kernel wallet
* first blocks new payments on it, then removes its enrolled card. If that fails,
* the wallet is kept and keeps refusing payments; retry the deletion. Reconcile
* the original attempt with the provider or support first; deleting or recreating
* an item is not proof that a payment did not occur.
*
* @example
* ```ts
Expand Down Expand Up @@ -154,7 +160,12 @@ export interface Vault {
updated_at: string;
}

export interface VaultListParams extends OffsetPaginationParams {}
export interface VaultListParams extends OffsetPaginationParams {
/**
* Case-insensitive substring match against vault name. IDs match by exact value.
*/
query?: string;
}

export interface VaultUpsertParams {
/**
Expand Down Expand Up @@ -199,9 +210,13 @@ export declare namespace Vaults {
type CredentialVaultItemUpdateRequest as CredentialVaultItemUpdateRequest,
type FillVaultItemOperationRequest as FillVaultItemOperationRequest,
type FillVaultItemOperationResult as FillVaultItemOperationResult,
type KernelCardState as KernelCardState,
type KernelCardVaultItemSpec as KernelCardVaultItemSpec,
type KernelCredentialVaultItemSpec as KernelCredentialVaultItemSpec,
type KernelCredentialVaultItemSpecInput as KernelCredentialVaultItemSpecInput,
type KernelCredentialVaultItemState as KernelCredentialVaultItemState,
type KernelWalletState as KernelWalletState,
type KernelWalletVaultItemSpec as KernelWalletVaultItemSpec,
type OnePasswordCredentialAccountSpec as OnePasswordCredentialAccountSpec,
type OnePasswordCredentialAccountState as OnePasswordCredentialAccountState,
type OnePasswordCredentialVaultItemSpec as OnePasswordCredentialVaultItemSpec,
Expand Down
2 changes: 1 addition & 1 deletion src/version.ts
Original file line number Diff line number Diff line change
@@ -1 +1 @@
export const VERSION = '0.117.0'; // x-release-please-version
export const VERSION = '0.118.0'; // x-release-please-version
Loading
Loading