From 73817c0b9c4e93502daf9ecaa0bcf27e11e827bb Mon Sep 17 00:00:00 2001
From: "kernel-internal[bot]"
<260533166+kernel-internal[bot]@users.noreply.github.com>
Date: Fri, 2 Oct 2026 22:46:44 +0000
Subject: [PATCH 1/3] feat: chore(stlc): seal custom-code tracking files
Stainless-Generated-From: 4aa69773719f9a97d96a16e861abf1e4d20bb3f1
---
api.md | 4 +
vaultitem.go | 389 ++++++++++++++++++++++++++++++++++++++++------
vaultitem_test.go | 41 +----
3 files changed, 356 insertions(+), 78 deletions(-)
diff --git a/api.md b/api.md
index 9f3d84c..c19b14b 100644
--- a/api.md
+++ b/api.md
@@ -536,6 +536,7 @@ Params Types:
- kernel.KernelCardVaultItemSpecParam
- kernel.KernelCredentialVaultItemSpecInputParam
- kernel.KernelWalletVaultItemSpecParam
+- kernel.ManagedAuthCredentialVaultItemSpecInputParam
- kernel.OnePasswordCredentialAccountSpecParam
- kernel.OnePasswordCredentialVaultItemSpecInputParam
- kernel.OnePasswordFillVaultItemOperationRequestParam
@@ -569,6 +570,9 @@ Response Types:
- kernel.KernelCredentialVaultItemState
- kernel.KernelWalletState
- kernel.KernelWalletVaultItemSpec
+- kernel.ManagedAuthCredentialVaultField
+- kernel.ManagedAuthCredentialVaultItemSpec
+- kernel.ManagedAuthCredentialVaultItemState
- kernel.OnePasswordCredentialAccountSpec
- kernel.OnePasswordCredentialAccountState
- kernel.OnePasswordCredentialVaultItemSpec
diff --git a/vaultitem.go b/vaultitem.go
index 76f8804..3ed8f33 100644
--- a/vaultitem.go
+++ b/vaultitem.go
@@ -112,7 +112,8 @@ func (r *VaultItemService) List(ctx context.Context, idOrName string, opts ...op
// recovery_required whose checkout create response returned no authorization ID
// may be explicitly abandoned by deleting that card directly; deleting its wallet
// or vault remains blocked. Deleting or recreating an item is not proof that a
-// payment did not occur.
+// payment did not occur. Deleting a managed auth credential item leaves the
+// connection and its saved credential unchanged.
func (r *VaultItemService) Delete(ctx context.Context, key string, body VaultItemDeleteParams, opts ...option.RequestOption) (err error) {
opts = slices.Concat(r.Options, opts)
opts = append([]option.RequestOption{option.WithHeader("Accept", "*/*")}, opts...)
@@ -1583,7 +1584,8 @@ type CredentialVaultItem struct {
// Kernel credentials advertise collect and fill when eligible. 1Password
// credentials advertise 1pw_create_access_request until a request is made,
// 1pw_access_request_status while its approval is pending, and 1pw_fill after
- // access is granted.
+ // access is granted. Managed auth credentials advertise fill while ready and
+ // nothing otherwise.
AvailableOperations []CredentialVaultItemAvailableOperation `json:"available_operations" api:"required"`
CreatedAt time.Time `json:"created_at" api:"required" format:"date-time"`
// Immutable item key assigned when the item is created.
@@ -1596,7 +1598,8 @@ type CredentialVaultItem struct {
Type CredentialVaultItemType `json:"type" api:"required"`
UpdatedAt time.Time `json:"updated_at" api:"required" format:"date-time"`
// Starts at 1 and increments on PATCH and successful hosted submission, but not
- // collection-link renewal.
+ // collection-link renewal. Managed auth credentials stay at 1; changes to the
+ // underlying credential are read at fill time and do not change the version.
Version int64 `json:"version" api:"required"`
// One schema-derived form for the item, available in ready or pending_collection
// state. Render every form-supported field as editable; omit totp fields and
@@ -1800,7 +1803,9 @@ func (r *CredentialVaultItemAction1passwordAccessApproval) UnmarshalJSON(data []
// declare fields and may enter pending_collection. 1Password credentials either
// reference a connected credential_account or store a supplied access token and
// integration key encrypted on the item. They store no login values or selectors.
-// Repeating the original creation request returns the current item without
+// Managed auth credentials reference a managed auth connection in the same project
+// that already has a saved credential, and read it at fill time; they store no
+// values. Repeating the original creation request returns the current item without
// overwriting later state. A different request at the same key returns 409.
//
// The properties Spec, Type are required.
@@ -1831,7 +1836,8 @@ const (
)
// CredentialVaultItemSpecUnion contains all possible properties and values from
-// [KernelCredentialVaultItemSpec], [OnePasswordCredentialVaultItemSpec].
+// [KernelCredentialVaultItemSpec], [OnePasswordCredentialVaultItemSpec],
+// [ManagedAuthCredentialVaultItemSpec].
//
// Use the [CredentialVaultItemSpecUnion.AsAny] method to switch on the variant.
//
@@ -1839,9 +1845,8 @@ const (
type CredentialVaultItemSpecUnion struct {
// This field is from variant [KernelCredentialVaultItemSpec].
Fields []CredentialVaultFieldDefinition `json:"fields"`
- // Any of "kernel", "1password".
- Provider string `json:"provider"`
- // This field is from variant [KernelCredentialVaultItemSpec].
+ // Any of "kernel", "1password", "managed_auth".
+ Provider string `json:"provider"`
Description string `json:"description"`
// This field is from variant [OnePasswordCredentialVaultItemSpec].
Requests OnePasswordCredentialVaultItemSpecRequests `json:"requests"`
@@ -1849,13 +1854,16 @@ type CredentialVaultItemSpecUnion struct {
AccessTokenExpiresAt time.Time `json:"access_token_expires_at"`
// This field is from variant [OnePasswordCredentialVaultItemSpec].
Account string `json:"account"`
- JSON struct {
+ // This field is from variant [ManagedAuthCredentialVaultItemSpec].
+ ConnectionID string `json:"connection_id"`
+ JSON struct {
Fields respjson.Field
Provider respjson.Field
Description respjson.Field
Requests respjson.Field
AccessTokenExpiresAt respjson.Field
Account respjson.Field
+ ConnectionID respjson.Field
raw string
} `json:"-"`
}
@@ -1869,12 +1877,14 @@ type anyCredentialVaultItemSpec interface {
func (KernelCredentialVaultItemSpec) implCredentialVaultItemSpecUnion() {}
func (OnePasswordCredentialVaultItemSpec) implCredentialVaultItemSpecUnion() {}
+func (ManagedAuthCredentialVaultItemSpec) implCredentialVaultItemSpecUnion() {}
// Use the following switch statement to find the correct variant
//
// switch variant := CredentialVaultItemSpecUnion.AsAny().(type) {
// case kernel.KernelCredentialVaultItemSpec:
// case kernel.OnePasswordCredentialVaultItemSpec:
+// case kernel.ManagedAuthCredentialVaultItemSpec:
// default:
// fmt.Errorf("no variant present")
// }
@@ -1884,6 +1894,8 @@ func (u CredentialVaultItemSpecUnion) AsAny() anyCredentialVaultItemSpec {
return u.AsKernel()
case "1password":
return u.As1password()
+ case "managed_auth":
+ return u.AsManagedAuth()
}
return nil
}
@@ -1898,6 +1910,11 @@ func (u CredentialVaultItemSpecUnion) As1password() (v OnePasswordCredentialVaul
return
}
+func (u CredentialVaultItemSpecUnion) AsManagedAuth() (v ManagedAuthCredentialVaultItemSpec) {
+ apijson.UnmarshalRoot(json.RawMessage(u.JSON.raw), &v)
+ return
+}
+
// Returns the unmodified JSON received from the API
func (u CredentialVaultItemSpecUnion) RawJSON() string { return u.JSON.raw }
@@ -1917,17 +1934,24 @@ func CredentialVaultItemSpecInputParamOf1password(provider OnePasswordCredential
return CredentialVaultItemSpecInputUnionParam{Of1password: &number_1password}
}
+func CredentialVaultItemSpecInputParamOfManagedAuth(connectionID string) CredentialVaultItemSpecInputUnionParam {
+ var managedAuth ManagedAuthCredentialVaultItemSpecInputParam
+ managedAuth.ConnectionID = connectionID
+ return CredentialVaultItemSpecInputUnionParam{OfManagedAuth: &managedAuth}
+}
+
// Only one field can be non-zero.
//
// Use [param.IsOmitted] to confirm if a field is set.
type CredentialVaultItemSpecInputUnionParam struct {
- OfKernel *KernelCredentialVaultItemSpecInputParam `json:",omitzero,inline"`
- Of1password *OnePasswordCredentialVaultItemSpecInputParam `json:",omitzero,inline"`
+ OfKernel *KernelCredentialVaultItemSpecInputParam `json:",omitzero,inline"`
+ Of1password *OnePasswordCredentialVaultItemSpecInputParam `json:",omitzero,inline"`
+ OfManagedAuth *ManagedAuthCredentialVaultItemSpecInputParam `json:",omitzero,inline"`
paramUnion
}
func (u CredentialVaultItemSpecInputUnionParam) MarshalJSON() ([]byte, error) {
- return param.MarshalUnion(u, u.OfKernel, u.Of1password)
+ return param.MarshalUnion(u, u.OfKernel, u.Of1password, u.OfManagedAuth)
}
func (u *CredentialVaultItemSpecInputUnionParam) UnmarshalJSON(data []byte) error {
return apijson.UnmarshalRoot(data, u)
@@ -1938,6 +1962,8 @@ func (u *CredentialVaultItemSpecInputUnionParam) asAny() any {
return u.OfKernel
} else if !param.IsOmitted(u.Of1password) {
return u.Of1password
+ } else if !param.IsOmitted(u.OfManagedAuth) {
+ return u.OfManagedAuth
}
return nil
}
@@ -1950,14 +1976,6 @@ func (u CredentialVaultItemSpecInputUnionParam) GetFields() []CredentialVaultFie
return nil
}
-// Returns a pointer to the underlying variant's property, if present.
-func (u CredentialVaultItemSpecInputUnionParam) GetDescription() *string {
- if vt := u.OfKernel; vt != nil && vt.Description.Valid() {
- return &vt.Description.Value
- }
- return nil
-}
-
// Returns a pointer to the underlying variant's property, if present.
func (u CredentialVaultItemSpecInputUnionParam) GetAccessToken() *string {
if vt := u.Of1password; vt != nil && vt.AccessToken.Valid() {
@@ -2006,12 +2024,32 @@ func (u CredentialVaultItemSpecInputUnionParam) GetWebsite() *string {
return nil
}
+// Returns a pointer to the underlying variant's property, if present.
+func (u CredentialVaultItemSpecInputUnionParam) GetConnectionID() *string {
+ if vt := u.OfManagedAuth; vt != nil {
+ return &vt.ConnectionID
+ }
+ return nil
+}
+
// Returns a pointer to the underlying variant's property, if present.
func (u CredentialVaultItemSpecInputUnionParam) GetProvider() *string {
if vt := u.OfKernel; vt != nil {
return (*string)(&vt.Provider)
} else if vt := u.Of1password; vt != nil {
return (*string)(&vt.Provider)
+ } else if vt := u.OfManagedAuth; vt != nil {
+ return (*string)(&vt.Provider)
+ }
+ return nil
+}
+
+// Returns a pointer to the underlying variant's property, if present.
+func (u CredentialVaultItemSpecInputUnionParam) GetDescription() *string {
+ if vt := u.OfKernel; vt != nil && vt.Description.Valid() {
+ return &vt.Description.Value
+ } else if vt := u.OfManagedAuth; vt != nil && vt.Description.Valid() {
+ return &vt.Description.Value
}
return nil
}
@@ -2021,6 +2059,7 @@ func init() {
"provider",
apijson.Discriminator[KernelCredentialVaultItemSpecInputParam]("kernel"),
apijson.Discriminator[OnePasswordCredentialVaultItemSpecInputParam]("1password"),
+ apijson.Discriminator[ManagedAuthCredentialVaultItemSpecInputParam]("managed_auth"),
)
}
@@ -2042,24 +2081,25 @@ func (r *CredentialVaultItemSpecUpdateParam) UnmarshalJSON(data []byte) error {
}
// CredentialVaultItemStateUnion contains all possible properties and values from
-// [KernelCredentialVaultItemState], [OnePasswordCredentialVaultItemState].
+// [KernelCredentialVaultItemState], [OnePasswordCredentialVaultItemState],
+// [ManagedAuthCredentialVaultItemState].
//
// Use the [CredentialVaultItemStateUnion.AsAny] method to switch on the variant.
//
// Use the methods beginning with 'As' to cast the union to one of its variants.
type CredentialVaultItemStateUnion struct {
- // This field is from variant [KernelCredentialVaultItemState].
- Fields map[string]CredentialVaultFieldState `json:"fields"`
- // Any of "kernel", "1password".
+ // This field is a union of [map[string]CredentialVaultFieldState],
+ // [map[string]ManagedAuthCredentialVaultField]
+ Fields CredentialVaultItemStateUnionFields `json:"fields"`
+ // Any of "kernel", "1password", "managed_auth".
Provider string `json:"provider"`
Status string `json:"status"`
// This field is from variant [OnePasswordCredentialVaultItemState].
AccessRequest OnePasswordCredentialVaultItemStateAccessRequest `json:"access_request"`
// This field is from variant [OnePasswordCredentialVaultItemState].
AccessRequestID string `json:"access_request_id"`
- // This field is from variant [OnePasswordCredentialVaultItemState].
- StatusReason string `json:"status_reason"`
- JSON struct {
+ StatusReason string `json:"status_reason"`
+ JSON struct {
Fields respjson.Field
Provider respjson.Field
Status respjson.Field
@@ -2079,12 +2119,14 @@ type anyCredentialVaultItemState interface {
func (KernelCredentialVaultItemState) implCredentialVaultItemStateUnion() {}
func (OnePasswordCredentialVaultItemState) implCredentialVaultItemStateUnion() {}
+func (ManagedAuthCredentialVaultItemState) implCredentialVaultItemStateUnion() {}
// Use the following switch statement to find the correct variant
//
// switch variant := CredentialVaultItemStateUnion.AsAny().(type) {
// case kernel.KernelCredentialVaultItemState:
// case kernel.OnePasswordCredentialVaultItemState:
+// case kernel.ManagedAuthCredentialVaultItemState:
// default:
// fmt.Errorf("no variant present")
// }
@@ -2094,6 +2136,8 @@ func (u CredentialVaultItemStateUnion) AsAny() anyCredentialVaultItemState {
return u.AsKernel()
case "1password":
return u.As1password()
+ case "managed_auth":
+ return u.AsManagedAuth()
}
return nil
}
@@ -2108,6 +2152,11 @@ func (u CredentialVaultItemStateUnion) As1password() (v OnePasswordCredentialVau
return
}
+func (u CredentialVaultItemStateUnion) AsManagedAuth() (v ManagedAuthCredentialVaultItemState) {
+ apijson.UnmarshalRoot(json.RawMessage(u.JSON.raw), &v)
+ return
+}
+
// Returns the unmodified JSON received from the API
func (u CredentialVaultItemStateUnion) RawJSON() string { return u.JSON.raw }
@@ -2115,6 +2164,31 @@ func (r *CredentialVaultItemStateUnion) UnmarshalJSON(data []byte) error {
return apijson.UnmarshalRoot(data, r)
}
+// CredentialVaultItemStateUnionFields is an implicit subunion of
+// [CredentialVaultItemStateUnion]. CredentialVaultItemStateUnionFields provides
+// convenient access to the sub-properties of the union.
+//
+// For type safety it is recommended to directly use a variant of the
+// [CredentialVaultItemStateUnion].
+type CredentialVaultItemStateUnionFields struct {
+ // This field is from variant [map[string]CredentialVaultFieldState].
+ HasValue bool `json:"has_value"`
+ // This field is from variant [map[string]CredentialVaultFieldState].
+ Value string `json:"value"`
+ // This field is from variant [map[string]ManagedAuthCredentialVaultField].
+ Type CredentialVaultFieldType `json:"type"`
+ JSON struct {
+ HasValue respjson.Field
+ Value respjson.Field
+ Type respjson.Field
+ raw string
+ } `json:"-"`
+}
+
+func (r *CredentialVaultItemStateUnionFields) UnmarshalJSON(data []byte) error {
+ return apijson.UnmarshalRoot(data, r)
+}
+
// Atomically update description and selected values. Omitted properties are
// preserved. Field names, types, required flags, and sensitivity cannot change.
// Unknown field names return 400; stale versions or mismatched item types return
@@ -2122,7 +2196,8 @@ func (r *CredentialVaultItemStateUnion) UnmarshalJSON(data []byte) error {
// invalidates outstanding Kernel-hosted collection sessions. If required values
// remain missing, return pending_collection and a fresh collection action.
// Otherwise return ready without an action; collect can open the form again
-// without clearing values. Customer URLs have no Kernel-managed expiry.
+// without clearing values. Customer URLs have no Kernel-managed expiry. 1Password
+// and managed auth credentials return 409.
//
// The properties Spec, Type, Version are required.
type CredentialVaultItemUpdateRequestParam struct {
@@ -2658,6 +2733,171 @@ func (r *KernelWalletVaultItemSpecParam) UnmarshalJSON(data []byte) error {
return apijson.UnmarshalRoot(data, r)
}
+type ManagedAuthCredentialVaultField struct {
+ // Text, email, and password have form inputs; totp does not and is omitted from
+ // both Kernel-hosted and customer React forms. Password and totp must be
+ // sensitive. A totp value is an RFC 4648 Base32 generator seed (case-insensitive,
+ // optional trailing padding), not an otpauth URI or current code. Reject invalid
+ // or empty decoded seeds. Browser fill generates an RFC 6238 code at execution
+ // time using HMAC-SHA1, 6 digits, and a 30-second period. Preserve leading zeros;
+ // never fill the seed. Custom algorithms, digits, periods, and form enrollment are
+ // unsupported.
+ //
+ // Any of "text", "email", "password", "totp".
+ Type CredentialVaultFieldType `json:"type" api:"required"`
+ // JSON contains metadata for fields, check presence with [respjson.Field.Valid].
+ JSON struct {
+ Type respjson.Field
+ ExtraFields map[string]respjson.Field
+ raw string
+ } `json:"-"`
+}
+
+// Returns the unmodified JSON received from the API
+func (r ManagedAuthCredentialVaultField) RawJSON() string { return r.JSON.raw }
+func (r *ManagedAuthCredentialVaultField) UnmarshalJSON(data []byte) error {
+ return apijson.UnmarshalRoot(data, r)
+}
+
+type ManagedAuthCredentialVaultItemSpec struct {
+ // ID of the managed auth connection whose saved credential this item reads. List
+ // connections with `GET /auth/connections`.
+ ConnectionID string `json:"connection_id" api:"required"`
+ // Any of "managed_auth".
+ Provider ManagedAuthCredentialVaultItemSpecProvider `json:"provider" api:"required"`
+ // Display text supplied when the item was created. Omitted when none was given.
+ Description string `json:"description"`
+ // JSON contains metadata for fields, check presence with [respjson.Field.Valid].
+ JSON struct {
+ ConnectionID respjson.Field
+ Provider respjson.Field
+ Description respjson.Field
+ ExtraFields map[string]respjson.Field
+ raw string
+ } `json:"-"`
+}
+
+// Returns the unmodified JSON received from the API
+func (r ManagedAuthCredentialVaultItemSpec) RawJSON() string { return r.JSON.raw }
+func (r *ManagedAuthCredentialVaultItemSpec) UnmarshalJSON(data []byte) error {
+ return apijson.UnmarshalRoot(data, r)
+}
+
+type ManagedAuthCredentialVaultItemSpecProvider string
+
+const (
+ ManagedAuthCredentialVaultItemSpecProviderManagedAuth ManagedAuthCredentialVaultItemSpecProvider = "managed_auth"
+)
+
+// A credential backed by a managed auth connection. The item stores no values: it
+// reads the connection's saved credential at fill time, so updates made through
+// managed auth apply immediately. The connection must be in the vault's project
+// and hold a saved Kernel credential. The check is the saved credential, not
+// connection status: a connection that needs re-authentication qualifies, and an
+// authenticated one without a saved credential does not. Returns 404 for an
+// unknown connection, and 409 when the connection is in another project, has no
+// saved credential yet, or uses an external credential provider such as 1Password.
+// No collection form is offered; managed auth collects the login.
+//
+// The properties ConnectionID, Provider are required.
+type ManagedAuthCredentialVaultItemSpecInputParam struct {
+ // ID of the managed auth connection whose saved credential this item reads. List
+ // connections with `GET /auth/connections`.
+ ConnectionID string `json:"connection_id" api:"required"`
+ // Any of "managed_auth".
+ Provider ManagedAuthCredentialVaultItemSpecInputProvider `json:"provider,omitzero" api:"required"`
+ // Optional display text for the item, such as the site or service name. Set at
+ // creation and cannot be changed later; repeating the request with a different
+ // description returns 409. At most 16 KiB in UTF-8 bytes.
+ Description param.Opt[string] `json:"description,omitzero"`
+ paramObj
+}
+
+func (r ManagedAuthCredentialVaultItemSpecInputParam) MarshalJSON() (data []byte, err error) {
+ type shadow ManagedAuthCredentialVaultItemSpecInputParam
+ return param.MarshalObject(r, (*shadow)(&r))
+}
+func (r *ManagedAuthCredentialVaultItemSpecInputParam) UnmarshalJSON(data []byte) error {
+ return apijson.UnmarshalRoot(data, r)
+}
+
+type ManagedAuthCredentialVaultItemSpecInputProvider string
+
+const (
+ ManagedAuthCredentialVaultItemSpecInputProviderManagedAuth ManagedAuthCredentialVaultItemSpecInputProvider = "managed_auth"
+)
+
+type ManagedAuthCredentialVaultItemState struct {
+ // Any of "managed_auth".
+ Provider ManagedAuthCredentialVaultItemStateProvider `json:"provider" api:"required"`
+ // Items are created ready, which means the connection has a saved Kernel
+ // credential that stores values or a TOTP seed (what has_values or has_totp_secret
+ // report on credentials), not that a login succeeded. Unavailable means it no
+ // longer does; such items advertise no operations.
+ //
+ // Any of "ready", "unavailable".
+ Status ManagedAuthCredentialVaultItemStateStatus `json:"status" api:"required"`
+ // One entry per non-empty value on the connection's saved credential, keyed by the
+ // field name to use in fill bindings. Included on single-item responses (create
+ // and get) and omitted from list responses, like `value_keys` on credentials.
+ // Empty when unavailable or when every stored value is empty. A stored value named
+ // totp_secret is never listed or filled. Values are never returned. A totp entry
+ // is present when the credential has a TOTP seed; fill writes a generated code for
+ // it. Entries follow the connection's credential.
+ Fields map[string]ManagedAuthCredentialVaultField `json:"fields"`
+ // Present when status is unavailable. connection_not_found means the connection
+ // was deleted. no_credential means the connection's credential was deleted or
+ // emptied after the item was created. external_credential means the connection was
+ // moved to an external credential provider.
+ //
+ // Any of "connection_not_found", "no_credential", "external_credential".
+ StatusReason ManagedAuthCredentialVaultItemStateStatusReason `json:"status_reason"`
+ // JSON contains metadata for fields, check presence with [respjson.Field.Valid].
+ JSON struct {
+ Provider respjson.Field
+ Status respjson.Field
+ Fields respjson.Field
+ StatusReason respjson.Field
+ ExtraFields map[string]respjson.Field
+ raw string
+ } `json:"-"`
+}
+
+// Returns the unmodified JSON received from the API
+func (r ManagedAuthCredentialVaultItemState) RawJSON() string { return r.JSON.raw }
+func (r *ManagedAuthCredentialVaultItemState) UnmarshalJSON(data []byte) error {
+ return apijson.UnmarshalRoot(data, r)
+}
+
+type ManagedAuthCredentialVaultItemStateProvider string
+
+const (
+ ManagedAuthCredentialVaultItemStateProviderManagedAuth ManagedAuthCredentialVaultItemStateProvider = "managed_auth"
+)
+
+// Items are created ready, which means the connection has a saved Kernel
+// credential that stores values or a TOTP seed (what has_values or has_totp_secret
+// report on credentials), not that a login succeeded. Unavailable means it no
+// longer does; such items advertise no operations.
+type ManagedAuthCredentialVaultItemStateStatus string
+
+const (
+ ManagedAuthCredentialVaultItemStateStatusReady ManagedAuthCredentialVaultItemStateStatus = "ready"
+ ManagedAuthCredentialVaultItemStateStatusUnavailable ManagedAuthCredentialVaultItemStateStatus = "unavailable"
+)
+
+// Present when status is unavailable. connection_not_found means the connection
+// was deleted. no_credential means the connection's credential was deleted or
+// emptied after the item was created. external_credential means the connection was
+// moved to an external credential provider.
+type ManagedAuthCredentialVaultItemStateStatusReason string
+
+const (
+ ManagedAuthCredentialVaultItemStateStatusReasonConnectionNotFound ManagedAuthCredentialVaultItemStateStatusReason = "connection_not_found"
+ ManagedAuthCredentialVaultItemStateStatusReasonNoCredential ManagedAuthCredentialVaultItemStateStatusReason = "no_credential"
+ ManagedAuthCredentialVaultItemStateStatusReasonExternalCredential ManagedAuthCredentialVaultItemStateStatusReason = "external_credential"
+)
+
type OnePasswordCredentialAccountSpec struct {
Authorization OnePasswordCredentialAccountSpecAuthorization `json:"authorization" api:"required"`
// Any of "1password".
@@ -3515,8 +3755,9 @@ const (
// The properties Field, Selector are required.
type VaultFillFieldParam struct {
- // A declared credential field name or a supported card field. Unset credential
- // fields cannot be filled.
+ // A credential field name from the item's declared fields (Kernel) or state.fields
+ // from a single-item read (managed auth), or a supported card field. Unset
+ // credential fields cannot be filled.
Field string `json:"field" api:"required"`
Selector string `json:"selector" api:"required"`
// Required only for a card's combined expiration field. Forbidden for other card
@@ -3832,16 +4073,17 @@ type VaultItemUnionSpec struct {
// This field is from variant [CardVaultItemSpecUnion].
CheckoutOrigin string `json:"checkout_origin"`
// This field is from variant [CredentialVaultItemSpecUnion].
- Fields []CredentialVaultFieldDefinition `json:"fields"`
- // This field is from variant [CredentialVaultItemSpecUnion].
- Description string `json:"description"`
+ Fields []CredentialVaultFieldDefinition `json:"fields"`
+ Description string `json:"description"`
// This field is from variant [CredentialVaultItemSpecUnion].
Requests OnePasswordCredentialVaultItemSpecRequests `json:"requests"`
// This field is from variant [CredentialVaultItemSpecUnion].
AccessTokenExpiresAt time.Time `json:"access_token_expires_at"`
// This field is from variant [CredentialVaultItemSpecUnion].
Account string `json:"account"`
- JSON struct {
+ // This field is from variant [CredentialVaultItemSpecUnion].
+ ConnectionID string `json:"connection_id"`
+ JSON struct {
Authorization respjson.Field
Provider respjson.Field
ProviderConfig respjson.Field
@@ -3865,6 +4107,7 @@ type VaultItemUnionSpec struct {
Requests respjson.Field
AccessTokenExpiresAt respjson.Field
Account respjson.Field
+ ConnectionID respjson.Field
raw string
} `json:"-"`
}
@@ -3938,8 +4181,9 @@ type VaultItemUnionState struct {
Authorization AgentcardCheckoutAuthorization `json:"authorization"`
// This field is from variant [CardVaultItemStateUnion].
Preparation AgentcardCheckoutPreparation `json:"preparation"`
- // This field is from variant [CredentialVaultItemStateUnion].
- Fields map[string]CredentialVaultFieldState `json:"fields"`
+ // This field is a union of [map[string]CredentialVaultFieldState],
+ // [map[string]ManagedAuthCredentialVaultField]
+ Fields VaultItemUnionStateFields `json:"fields"`
// This field is from variant [CredentialVaultItemStateUnion].
AccessRequest OnePasswordCredentialVaultItemStateAccessRequest `json:"access_request"`
// This field is from variant [CredentialVaultItemStateUnion].
@@ -3987,6 +4231,31 @@ func (r *VaultItemUnionStateMasks) UnmarshalJSON(data []byte) error {
return apijson.UnmarshalRoot(data, r)
}
+// VaultItemUnionStateFields is an implicit subunion of [VaultItemUnion].
+// VaultItemUnionStateFields provides convenient access to the sub-properties of
+// the union.
+//
+// For type safety it is recommended to directly use a variant of the
+// [VaultItemUnion].
+type VaultItemUnionStateFields struct {
+ // This field is from variant [map[string]CredentialVaultFieldState].
+ HasValue bool `json:"has_value"`
+ // This field is from variant [map[string]CredentialVaultFieldState].
+ Value string `json:"value"`
+ // This field is from variant [map[string]ManagedAuthCredentialVaultField].
+ Type CredentialVaultFieldType `json:"type"`
+ JSON struct {
+ HasValue respjson.Field
+ Value respjson.Field
+ Type respjson.Field
+ raw string
+ } `json:"-"`
+}
+
+func (r *VaultItemUnionStateFields) UnmarshalJSON(data []byte) error {
+ return apijson.UnmarshalRoot(data, r)
+}
+
// VaultItemUnionAction is an implicit subunion of [VaultItemUnion].
// VaultItemUnionAction provides convenient access to the sub-properties of the
// union.
@@ -4704,16 +4973,17 @@ type VaultItemOperationResponseUnionSpec struct {
// This field is from variant [CardVaultItemSpecUnion].
CheckoutOrigin string `json:"checkout_origin"`
// This field is from variant [CredentialVaultItemSpecUnion].
- Fields []CredentialVaultFieldDefinition `json:"fields"`
- // This field is from variant [CredentialVaultItemSpecUnion].
- Description string `json:"description"`
+ Fields []CredentialVaultFieldDefinition `json:"fields"`
+ Description string `json:"description"`
// This field is from variant [CredentialVaultItemSpecUnion].
Requests OnePasswordCredentialVaultItemSpecRequests `json:"requests"`
// This field is from variant [CredentialVaultItemSpecUnion].
AccessTokenExpiresAt time.Time `json:"access_token_expires_at"`
// This field is from variant [CredentialVaultItemSpecUnion].
Account string `json:"account"`
- JSON struct {
+ // This field is from variant [CredentialVaultItemSpecUnion].
+ ConnectionID string `json:"connection_id"`
+ JSON struct {
Authorization respjson.Field
Provider respjson.Field
ProviderConfig respjson.Field
@@ -4737,6 +5007,7 @@ type VaultItemOperationResponseUnionSpec struct {
Requests respjson.Field
AccessTokenExpiresAt respjson.Field
Account respjson.Field
+ ConnectionID respjson.Field
raw string
} `json:"-"`
}
@@ -4812,8 +5083,9 @@ type VaultItemOperationResponseUnionState struct {
Authorization AgentcardCheckoutAuthorization `json:"authorization"`
// This field is from variant [CardVaultItemStateUnion].
Preparation AgentcardCheckoutPreparation `json:"preparation"`
- // This field is from variant [CredentialVaultItemStateUnion].
- Fields map[string]CredentialVaultFieldState `json:"fields"`
+ // This field is a union of [map[string]CredentialVaultFieldState],
+ // [map[string]ManagedAuthCredentialVaultField]
+ Fields VaultItemOperationResponseUnionStateFields `json:"fields"`
// This field is from variant [CredentialVaultItemStateUnion].
AccessRequest OnePasswordCredentialVaultItemStateAccessRequest `json:"access_request"`
// This field is from variant [CredentialVaultItemStateUnion].
@@ -4861,6 +5133,31 @@ func (r *VaultItemOperationResponseUnionStateMasks) UnmarshalJSON(data []byte) e
return apijson.UnmarshalRoot(data, r)
}
+// VaultItemOperationResponseUnionStateFields is an implicit subunion of
+// [VaultItemOperationResponseUnion]. VaultItemOperationResponseUnionStateFields
+// provides convenient access to the sub-properties of the union.
+//
+// For type safety it is recommended to directly use a variant of the
+// [VaultItemOperationResponseUnion].
+type VaultItemOperationResponseUnionStateFields struct {
+ // This field is from variant [map[string]CredentialVaultFieldState].
+ HasValue bool `json:"has_value"`
+ // This field is from variant [map[string]CredentialVaultFieldState].
+ Value string `json:"value"`
+ // This field is from variant [map[string]ManagedAuthCredentialVaultField].
+ Type CredentialVaultFieldType `json:"type"`
+ JSON struct {
+ HasValue respjson.Field
+ Value respjson.Field
+ Type respjson.Field
+ raw string
+ } `json:"-"`
+}
+
+func (r *VaultItemOperationResponseUnionStateFields) UnmarshalJSON(data []byte) error {
+ return apijson.UnmarshalRoot(data, r)
+}
+
// VaultItemOperationResponseUnionAction is an implicit subunion of
// [VaultItemOperationResponseUnion]. VaultItemOperationResponseUnionAction
// provides convenient access to the sub-properties of the union.
@@ -5722,6 +6019,7 @@ type VaultItemGetParams struct {
// approval, or credential collection. Return the current item when ready or when
// the wait elapses. This does not wait for edits to an already-ready credential;
// poll GET without wait and compare version to observe changes after collect.
+ // Managed auth credentials are created ready, so wait returns immediately.
Wait param.Opt[int64] `query:"wait,omitzero" json:"-"`
// Live fields advertised by `available_expansions` to include in `expanded`.
//
@@ -5755,7 +6053,8 @@ type VaultItemUpdateParams struct {
// invalidates outstanding Kernel-hosted collection sessions. If required values
// remain missing, return pending_collection and a fresh collection action.
// Otherwise return ready without an action; collect can open the form again
- // without clearing values. Customer URLs have no Kernel-managed expiry.
+ // without clearing values. Customer URLs have no Kernel-managed expiry. 1Password
+ // and managed auth credentials return 409.
OfCredentialVaultItemUpdateRequest *CredentialVaultItemUpdateRequestParam `json:",inline"`
paramObj
@@ -6010,7 +6309,9 @@ type VaultItemUpsertParams struct {
// declare fields and may enter pending_collection. 1Password credentials either
// reference a connected credential_account or store a supplied access token and
// integration key encrypted on the item. They store no login values or selectors.
- // Repeating the original creation request returns the current item without
+ // Managed auth credentials reference a managed auth connection in the same project
+ // that already has a saved credential, and read it at fill time; they store no
+ // values. Repeating the original creation request returns the current item without
// overwriting later state. A different request at the same key returns 409.
OfCredential *CredentialVaultItemRequestParam `json:",inline"`
diff --git a/vaultitem_test.go b/vaultitem_test.go
index 538aa6b..1900265 100644
--- a/vaultitem_test.go
+++ b/vaultitem_test.go
@@ -244,42 +244,15 @@ func TestVaultItemUpsertWithOptionalParams(t *testing.T) {
"x",
kernel.VaultItemUpsertParams{
IDOrName: "id_or_name",
- OfCard: &kernel.VaultItemUpsertParamsBodyCard{
- Spec: kernel.CardVaultItemSpecUnionParam{
- OfLink: &kernel.CardVaultItemSpecLinkParam{
- Amount: 2599,
- Context: "Purchase one notebook for USD 25.99 including shipping and taxes. This is a new order at Example Store, not a retry of an earlier payment.",
- Currency: "usd",
- MerchantName: "Example Store",
- MerchantURL: "https://store.example.com",
- PaymentMethodID: "pm_example",
- Wallet: "link-wallet",
- ExpiresAt: kernel.Int(0),
- LineItems: []kernel.CardVaultItemSpecLinkLineItemParam{{
- Name: "name",
- Description: kernel.String("description"),
- ImageURL: kernel.String("image_url"),
- ProductURL: kernel.String("product_url"),
- Quantity: kernel.Int(1),
- SKU: kernel.String("sku"),
- Totals: []kernel.CardVaultItemSpecLinkLineItemTotalParam{{
- Amount: 0,
- DisplayText: "display_text",
- Type: "type",
- }},
- UnitAmount: kernel.Int(0),
- URL: kernel.String("url"),
- }},
- Metadata: map[string]string{
- "foo": "string",
- },
- Totals: []kernel.CardVaultItemSpecLinkTotalParam{{
- Amount: 0,
- DisplayText: "display_text",
- Type: "type",
- }},
+ OfCredential: &kernel.CredentialVaultItemRequestParam{
+ Spec: kernel.CredentialVaultItemSpecInputUnionParam{
+ OfManagedAuth: &kernel.ManagedAuthCredentialVaultItemSpecInputParam{
+ ConnectionID: "ma_abc123xyz",
+ Provider: kernel.ManagedAuthCredentialVaultItemSpecInputProviderManagedAuth,
+ Description: kernel.String("Amazon"),
},
},
+ Type: kernel.CredentialVaultItemRequestTypeCredential,
},
},
)
From 10723a5b7fecae0c3928b786a2def8f3868c0e88 Mon Sep 17 00:00:00 2001
From: "kernel-internal[bot]"
<260533166+kernel-internal[bot]@users.noreply.github.com>
Date: Fri, 2 Oct 2026 22:51:55 +0000
Subject: [PATCH 2/3] release: 0.119.0
---
.release-please-manifest.json | 2 +-
CHANGELOG.md | 7 +++++++
README.md | 2 +-
internal/version.go | 2 +-
4 files changed, 10 insertions(+), 3 deletions(-)
diff --git a/.release-please-manifest.json b/.release-please-manifest.json
index 617f750..124b984 100644
--- a/.release-please-manifest.json
+++ b/.release-please-manifest.json
@@ -1,3 +1,3 @@
{
- ".": "0.118.0"
+ ".": "0.119.0"
}
\ No newline at end of file
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 68ed9dc..c2308ee 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,5 +1,12 @@
# Changelog
+## [0.119.0](https://github.com/kernel/kernel-go-sdk/compare/v0.118.0...v0.119.0) (2026-10-02)
+
+
+### Features
+
+* chore(stlc): seal custom-code tracking files ([73817c0](https://github.com/kernel/kernel-go-sdk/commit/73817c0b9c4e93502daf9ecaa0bcf27e11e827bb))
+
## [0.118.0](https://github.com/kernel/kernel-go-sdk/compare/v0.117.0...v0.118.0) (2026-10-02)
diff --git a/README.md b/README.md
index 48da05c..31d3c28 100644
--- a/README.md
+++ b/README.md
@@ -28,7 +28,7 @@ Or to pin the version:
```sh
-go get -u 'github.com/kernel/kernel-go-sdk@v0.118.0'
+go get -u 'github.com/kernel/kernel-go-sdk@v0.119.0'
```
diff --git a/internal/version.go b/internal/version.go
index 13a5326..cb0b4f7 100644
--- a/internal/version.go
+++ b/internal/version.go
@@ -2,4 +2,4 @@
package internal
-const PackageVersion = "0.118.0" // x-release-please-version
+const PackageVersion = "0.119.0" // x-release-please-version
From 481dc7f4d6acc721919adbfc3421532638e63bb0 Mon Sep 17 00:00:00 2001
From: Behroz Saadat
Date: Fri, 2 Oct 2026 18:03:41 -0500
Subject: [PATCH 3/3] docs: correct 0.119.0 changelog entry for managed auth
vault credentials
Co-Authored-By: Claude Opus 5.5 (1M context)
---
CHANGELOG.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/CHANGELOG.md b/CHANGELOG.md
index c2308ee..66a2c38 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -5,7 +5,7 @@
### Features
-* chore(stlc): seal custom-code tracking files ([73817c0](https://github.com/kernel/kernel-go-sdk/commit/73817c0b9c4e93502daf9ecaa0bcf27e11e827bb))
+* Add managed auth provider to vault credential items ([73817c0](https://github.com/kernel/kernel-go-sdk/commit/73817c0b9c4e93502daf9ecaa0bcf27e11e827bb))
## [0.118.0](https://github.com/kernel/kernel-go-sdk/compare/v0.117.0...v0.118.0) (2026-10-02)