Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .release-please-manifest.json
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
{
".": "0.116.0"
".": "0.117.0"
}
7 changes: 7 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,12 @@
# Changelog

## [0.117.0](https://github.com/kernel/kernel-go-sdk/compare/v0.116.0...v0.117.0) (2026-10-02)


### Features

* Invoke WebMCP tools with vault item fields ([615cfaf](https://github.com/kernel/kernel-go-sdk/commit/615cfaf0c5a80549cba3cd643c00b58c517f5475))

## [0.116.0](https://github.com/kernel/kernel-go-sdk/compare/v0.115.0...v0.116.0) (2026-10-01)


Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ Or to pin the version:
<!-- x-release-please-start-version -->

```sh
go get -u 'github.com/kernel/kernel-go-sdk@v0.116.0'
go get -u 'github.com/kernel/kernel-go-sdk@v0.117.0'
```

<!-- x-release-please-end -->
Expand Down
3 changes: 3 additions & 0 deletions api.md
Original file line number Diff line number Diff line change
Expand Up @@ -542,6 +542,8 @@ Params Types:
- <a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk">kernel</a>.<a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk#PrepareCheckoutVaultItemOperationRequestParam">PrepareCheckoutVaultItemOperationRequestParam</a>
- <a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk">kernel</a>.<a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk#VaultCheckoutContextParam">VaultCheckoutContextParam</a>
- <a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk">kernel</a>.<a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk#VaultFillFieldParam">VaultFillFieldParam</a>
- <a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk">kernel</a>.<a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk#VaultWebmcpBindingParam">VaultWebmcpBindingParam</a>
- <a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk">kernel</a>.<a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk#WebmcpInvokeVaultItemOperationRequestParam">WebmcpInvokeVaultItemOperationRequestParam</a>

Response Types:

Expand Down Expand Up @@ -576,6 +578,7 @@ Response Types:
- <a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk">kernel</a>.<a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk#VaultPaymentMethod">VaultPaymentMethod</a>
- <a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk">kernel</a>.<a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk#WalletVaultItemSpecUnion">WalletVaultItemSpecUnion</a>
- <a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk">kernel</a>.<a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk#WalletVaultItemStateUnion">WalletVaultItemStateUnion</a>
- <a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk">kernel</a>.<a href="https://pkg.go.dev/github.com/kernel/kernel-go-sdk#WebmcpInvokeVaultItemOperationResult">WebmcpInvokeVaultItemOperationResult</a>

Methods:

Expand Down
2 changes: 1 addition & 1 deletion internal/version.go
Original file line number Diff line number Diff line change
Expand Up @@ -2,4 +2,4 @@

package internal

const PackageVersion = "0.116.0" // x-release-please-version
const PackageVersion = "0.117.0" // x-release-please-version
169 changes: 160 additions & 9 deletions vaultitem.go
Original file line number Diff line number Diff line change
Expand Up @@ -1291,7 +1291,7 @@ type CredentialAccountVaultItemAvailableOperation struct {
Description string `json:"description" api:"required"`
// Any of "authorize", "collect", "prepare_checkout", "fill",
// "1pw_create_access_request", "1pw_access_request_status", "1pw_fill",
// "1pw_recover", "1pw_update_access_token".
// "1pw_recover", "1pw_update_access_token", "webmcp_invoke".
Type string `json:"type" api:"required"`
// JSON contains metadata for fields, check presence with [respjson.Field.Valid].
JSON struct {
Expand Down Expand Up @@ -1632,7 +1632,7 @@ type CredentialVaultItemAvailableOperation struct {
Description string `json:"description" api:"required"`
// Any of "authorize", "collect", "prepare_checkout", "fill",
// "1pw_create_access_request", "1pw_access_request_status", "1pw_fill",
// "1pw_recover", "1pw_update_access_token".
// "1pw_recover", "1pw_update_access_token", "webmcp_invoke".
Type string `json:"type" api:"required"`
// JSON contains metadata for fields, check presence with [respjson.Field.Valid].
JSON struct {
Expand Down Expand Up @@ -3753,7 +3753,7 @@ type VaultItemWalletAvailableOperation struct {
Description string `json:"description" api:"required"`
// Any of "authorize", "collect", "prepare_checkout", "fill",
// "1pw_create_access_request", "1pw_access_request_status", "1pw_fill",
// "1pw_recover", "1pw_update_access_token".
// "1pw_recover", "1pw_update_access_token", "webmcp_invoke".
Type string `json:"type" api:"required"`
// JSON contains metadata for fields, check presence with [respjson.Field.Valid].
JSON struct {
Expand Down Expand Up @@ -3854,7 +3854,7 @@ type VaultItemCardAvailableOperation struct {
Description string `json:"description" api:"required"`
// Any of "authorize", "collect", "prepare_checkout", "fill",
// "1pw_create_access_request", "1pw_access_request_status", "1pw_fill",
// "1pw_recover", "1pw_update_access_token".
// "1pw_recover", "1pw_update_access_token", "webmcp_invoke".
Type string `json:"type" api:"required"`
// JSON contains metadata for fields, check presence with [respjson.Field.Valid].
JSON struct {
Expand Down Expand Up @@ -4137,7 +4137,8 @@ func (r *VaultItemEvent) UnmarshalJSON(data []byte) error {
// [VaultItemOperationResponseWalletVaultItem],
// [VaultItemOperationResponseCardVaultItem], [CredentialAccountVaultItem],
// [CredentialVaultItem], [FillVaultItemOperationResult],
// [OnePasswordFillVaultItemOperationResult].
// [OnePasswordFillVaultItemOperationResult],
// [WebmcpInvokeVaultItemOperationResult].
//
// Use the methods beginning with 'As' to cast the union to one of its variants.
type VaultItemOperationResponseUnion struct {
Expand Down Expand Up @@ -4177,7 +4178,13 @@ type VaultItemOperationResponseUnion struct {
Status string `json:"status"`
// This field is from variant [OnePasswordFillVaultItemOperationResult].
ErrorCode OnePasswordFillVaultItemOperationResultErrorCode `json:"error_code"`
JSON struct {
// This field is from variant [WebmcpInvokeVaultItemOperationResult].
ErrorText string `json:"error_text"`
// This field is from variant [WebmcpInvokeVaultItemOperationResult].
InvocationID string `json:"invocation_id"`
// This field is from variant [WebmcpInvokeVaultItemOperationResult].
Output any `json:"output"`
JSON struct {
ID respjson.Field
AvailableExpansions respjson.Field
AvailableOperations respjson.Field
Expand All @@ -4194,6 +4201,9 @@ type VaultItemOperationResponseUnion struct {
Fields respjson.Field
Status respjson.Field
ErrorCode respjson.Field
ErrorText respjson.Field
InvocationID respjson.Field
Output respjson.Field
raw string
} `json:"-"`
}
Expand Down Expand Up @@ -4228,6 +4238,11 @@ func (u VaultItemOperationResponseUnion) AsOnePasswordFillVaultItemOperationResu
return
}

func (u VaultItemOperationResponseUnion) AsWebmcpInvokeVaultItemOperationResult() (v WebmcpInvokeVaultItemOperationResult) {
apijson.UnmarshalRoot(json.RawMessage(u.JSON.raw), &v)
return
}

// Returns the unmodified JSON received from the API
func (u VaultItemOperationResponseUnion) RawJSON() string { return u.JSON.raw }

Expand Down Expand Up @@ -4616,7 +4631,7 @@ type VaultItemOperationResponseWalletVaultItemAvailableOperation struct {
Description string `json:"description" api:"required"`
// Any of "authorize", "collect", "prepare_checkout", "fill",
// "1pw_create_access_request", "1pw_access_request_status", "1pw_fill",
// "1pw_recover", "1pw_update_access_token".
// "1pw_recover", "1pw_update_access_token", "webmcp_invoke".
Type string `json:"type" api:"required"`
// JSON contains metadata for fields, check presence with [respjson.Field.Valid].
JSON struct {
Expand Down Expand Up @@ -4722,7 +4737,7 @@ type VaultItemOperationResponseCardVaultItemAvailableOperation struct {
Description string `json:"description" api:"required"`
// Any of "authorize", "collect", "prepare_checkout", "fill",
// "1pw_create_access_request", "1pw_access_request_status", "1pw_fill",
// "1pw_recover", "1pw_update_access_token".
// "1pw_recover", "1pw_update_access_token", "webmcp_invoke".
Type string `json:"type" api:"required"`
// JSON contains metadata for fields, check presence with [respjson.Field.Valid].
JSON struct {
Expand Down Expand Up @@ -4827,6 +4842,29 @@ func (r *VaultPaymentMethodDisplay) UnmarshalJSON(data []byte) error {
return apijson.UnmarshalRoot(data, r)
}

// The properties Field, InputPath are required.
type VaultWebmcpBindingParam struct {
// A declared, populated credential field or supported card field. A TOTP field
// supplies a fresh code, never its seed.
Field string `json:"field" api:"required"`
// RFC 6901 JSON Pointer to an existing null value in input. Object keys are exact;
// array indices must be canonical and in range. No root or array-append paths.
// Each path and each field may occur only once.
InputPath string `json:"input_path" api:"required"`
// Required for card expiration (MM/YY or MM/YYYY), forbidden for other fields.
// Invalid formats are rejected before invocation.
Format param.Opt[string] `json:"format,omitzero"`
paramObj
}

func (r VaultWebmcpBindingParam) MarshalJSON() (data []byte, err error) {
type shadow VaultWebmcpBindingParam
return param.MarshalObject(r, (*shadow)(&r))
}
func (r *VaultWebmcpBindingParam) UnmarshalJSON(data []byte) error {
return apijson.UnmarshalRoot(data, r)
}

// WalletVaultItemSpecUnion contains all possible properties and values from
// [WalletVaultItemSpecLink], [WalletVaultItemSpecAgentcard].
//
Expand Down Expand Up @@ -5224,6 +5262,108 @@ func (r *WalletVaultItemStateAgentcard) UnmarshalJSON(data []byte) error {
return apijson.UnmarshalRoot(data, r)
}

// Invoke a WebMCP tool using values from a vaulted item. The browser must be
// attached to the item's vault. Discover the tool_ref, inputSchema, and source
// with GET /browsers/{id_or_name}/webmcp/tools or webmcp.listTools() in the
// Browser REPL (POST /browsers/{id_or_name}/repl) before invoking it. Input paths
// replace existing null slots in input. Tool output is returned without redaction
// and may include the supplied values. The tool may submit or perform other side
// effects. Any item destination restrictions apply to the tool's top-level page
// and registering frame (if any).
//
// The properties Bindings, BrowserID, Input, PageURL, ToolRef, Type are required.
type WebmcpInvokeVaultItemOperationRequestParam struct {
Bindings []VaultWebmcpBindingParam `json:"bindings,omitzero" api:"required"`
// Browser session ID, not a reusable browser name.
BrowserID string `json:"browser_id" api:"required"`
// Public tool arguments with an existing null slot at each binding path. At most
// 64 KiB after JSON serialization, including substituted values. Never include
// vault values here.
Input map[string]any `json:"input,omitzero" api:"required"`
// Exact top-level URL from the discovered tool source (fragment omitted). This
// pins the target page; it does not authorize a destination.
PageURL string `json:"page_url" api:"required" format:"uri"`
// Opaque reference to the exact live WebMCP registration.
ToolRef string `json:"tool_ref" api:"required"`
// Any of "webmcp_invoke".
Type WebmcpInvokeVaultItemOperationRequestType `json:"type,omitzero" api:"required"`
// Tool invocation timeout in seconds; preflight and response handling have an
// additional bounded allowance. An indeterminate outcome is not retried.
TimeoutSec param.Opt[int64] `json:"timeout_sec,omitzero"`
paramObj
}

func (r WebmcpInvokeVaultItemOperationRequestParam) MarshalJSON() (data []byte, err error) {
type shadow WebmcpInvokeVaultItemOperationRequestParam
return param.MarshalObject(r, (*shadow)(&r))
}
func (r *WebmcpInvokeVaultItemOperationRequestParam) UnmarshalJSON(data []byte) error {
return apijson.UnmarshalRoot(data, r)
}

type WebmcpInvokeVaultItemOperationRequestType string

const (
WebmcpInvokeVaultItemOperationRequestTypeWebmcpInvoke WebmcpInvokeVaultItemOperationRequestType = "webmcp_invoke"
)

// Returns the same tool result fields as the browser WebMCP invoke API, plus the
// vault operation discriminator. Output and error text are untrusted page-provided
// data, returned without redaction; tools may include supplied vault values.
// Inspect the browser page to determine whether the intended site action
// succeeded.
type WebmcpInvokeVaultItemOperationResult struct {
// Unknown means invocation may have run; do not retry automatically. No status
// confirms that the website accepted the action.
//
// Any of "completed", "canceled", "error", "awaiting_submission", "unknown".
Status WebmcpInvokeVaultItemOperationResultStatus `json:"status" api:"required"`
// Any of "webmcp_invoke".
Type WebmcpInvokeVaultItemOperationResultType `json:"type" api:"required"`
// Untrusted page-provided error text, returned without redaction. May contain
// supplied vault values.
ErrorText string `json:"error_text"`
// Present when the browser reported one.
InvocationID string `json:"invocation_id"`
// Untrusted page-provided output, returned without redaction. May contain supplied
// vault values.
Output any `json:"output"`
// JSON contains metadata for fields, check presence with [respjson.Field.Valid].
JSON struct {
Status respjson.Field
Type respjson.Field
ErrorText respjson.Field
InvocationID respjson.Field
Output respjson.Field
ExtraFields map[string]respjson.Field
raw string
} `json:"-"`
}

// Returns the unmodified JSON received from the API
func (r WebmcpInvokeVaultItemOperationResult) RawJSON() string { return r.JSON.raw }
func (r *WebmcpInvokeVaultItemOperationResult) UnmarshalJSON(data []byte) error {
return apijson.UnmarshalRoot(data, r)
}

// Unknown means invocation may have run; do not retry automatically. No status
// confirms that the website accepted the action.
type WebmcpInvokeVaultItemOperationResultStatus string

const (
WebmcpInvokeVaultItemOperationResultStatusCompleted WebmcpInvokeVaultItemOperationResultStatus = "completed"
WebmcpInvokeVaultItemOperationResultStatusCanceled WebmcpInvokeVaultItemOperationResultStatus = "canceled"
WebmcpInvokeVaultItemOperationResultStatusError WebmcpInvokeVaultItemOperationResultStatus = "error"
WebmcpInvokeVaultItemOperationResultStatusAwaitingSubmission WebmcpInvokeVaultItemOperationResultStatus = "awaiting_submission"
WebmcpInvokeVaultItemOperationResultStatusUnknown WebmcpInvokeVaultItemOperationResultStatus = "unknown"
)

type WebmcpInvokeVaultItemOperationResultType string

const (
WebmcpInvokeVaultItemOperationResultTypeWebmcpInvoke WebmcpInvokeVaultItemOperationResultType = "webmcp_invoke"
)

type VaultItemGetParams struct {
IDOrName string `path:"id_or_name" api:"required" json:"-"`
// Hold for up to this many seconds while the item is pending authorization,
Expand Down Expand Up @@ -5417,6 +5557,16 @@ type VaultItemPerformOperationParams struct {
// integration key, request and approved references. Does not invoke 1Password or
// retry a pending/uncertain operation.
Of1pwUpdateAccessToken *VaultItemPerformOperationParamsBody1pwUpdateAccessToken `json:",inline"`
// This field is a request body variant, only one variant field can be set. Invoke
// a WebMCP tool using values from a vaulted item. The browser must be attached to
// the item's vault. Discover the tool_ref, inputSchema, and source with GET
// /browsers/{id_or_name}/webmcp/tools or webmcp.listTools() in the Browser REPL
// (POST /browsers/{id_or_name}/repl) before invoking it. Input paths replace
// existing null slots in input. Tool output is returned without redaction and may
// include the supplied values. The tool may submit or perform other side effects.
// Any item destination restrictions apply to the tool's top-level page and
// registering frame (if any).
OfWebmcpInvoke *WebmcpInvokeVaultItemOperationRequestParam `json:",inline"`

paramObj
}
Expand All @@ -5430,7 +5580,8 @@ func (u VaultItemPerformOperationParams) MarshalJSON() ([]byte, error) {
u.Of1pwAccessRequestStatus,
u.Of1pwFill,
u.Of1pwRecover,
u.Of1pwUpdateAccessToken)
u.Of1pwUpdateAccessToken,
u.OfWebmcpInvoke)
}
func (r *VaultItemPerformOperationParams) UnmarshalJSON(data []byte) error {
return apijson.UnmarshalRoot(data, r)
Expand Down
Loading