Skip to content

Commit 04d839e

Browse files
feat: Add Kernel wallets backed by VGS agentic network tokens, with hosted card capture
Stainless-Generated-From: 1b0aa5849d3ee8fe7ca69bec3d598286918fc571
1 parent eaa17a1 commit 04d839e

18 files changed

Lines changed: 250 additions & 24 deletions

‎api.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -572,9 +572,13 @@ from kernel.types.vaults import (
572572
CredentialVaultItemUpdateRequest,
573573
FillVaultItemOperationRequest,
574574
FillVaultItemOperationResult,
575+
KernelCardState,
576+
KernelCardVaultItemSpec,
575577
KernelCredentialVaultItemSpec,
576578
KernelCredentialVaultItemSpecInput,
577579
KernelCredentialVaultItemState,
580+
KernelWalletState,
581+
KernelWalletVaultItemSpec,
578582
OnePasswordCredentialAccountSpec,
579583
OnePasswordCredentialAccountState,
580584
OnePasswordCredentialVaultItemSpec,

‎src/kernel/resources/vaults/items.py‎

Lines changed: 14 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -309,10 +309,13 @@ def delete(
309309
) -> None:
310310
"""
311311
Unresolved payment operations normally block deletion, including operations on
312-
child cards of a wallet. An AgentCard card in recovery_required whose checkout
313-
create response returned no authorization ID may be explicitly abandoned by
314-
deleting that card directly; deleting its wallet or vault remains blocked.
315-
Deleting or recreating an item is not proof that a payment did not occur.
312+
child cards of a wallet. Deleting a connected Kernel wallet first blocks new
313+
payments on it, then removes its enrolled card. If that fails, the wallet is
314+
kept and keeps refusing payments; retry the deletion. An AgentCard card in
315+
recovery_required whose checkout create response returned no authorization ID
316+
may be explicitly abandoned by deleting that card directly; deleting its wallet
317+
or vault remains blocked. Deleting or recreating an item is not proof that a
318+
payment did not occur.
316319
317320
Args:
318321
extra_headers: Send extra headers
@@ -1483,10 +1486,13 @@ async def delete(
14831486
) -> None:
14841487
"""
14851488
Unresolved payment operations normally block deletion, including operations on
1486-
child cards of a wallet. An AgentCard card in recovery_required whose checkout
1487-
create response returned no authorization ID may be explicitly abandoned by
1488-
deleting that card directly; deleting its wallet or vault remains blocked.
1489-
Deleting or recreating an item is not proof that a payment did not occur.
1489+
child cards of a wallet. Deleting a connected Kernel wallet first blocks new
1490+
payments on it, then removes its enrolled card. If that fails, the wallet is
1491+
kept and keeps refusing payments; retry the deletion. An AgentCard card in
1492+
recovery_required whose checkout create response returned no authorization ID
1493+
may be explicitly abandoned by deleting that card directly; deleting its wallet
1494+
or vault remains blocked. Deleting or recreating an item is not proof that a
1495+
payment did not occur.
14901496
14911497
Args:
14921498
extra_headers: Send extra headers

‎src/kernel/resources/vaults/vaults.py‎

Lines changed: 10 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -147,9 +147,11 @@ def delete(
147147
) -> None:
148148
"""Unresolved payment operations block deletion.
149149
150-
Reconcile the original attempt
151-
with the provider or support first; deleting or recreating an item is not proof
152-
that a payment did not occur.
150+
Deleting a connected Kernel wallet
151+
first blocks new payments on it, then removes its enrolled card. If that fails,
152+
the wallet is kept and keeps refusing payments; retry the deletion. Reconcile
153+
the original attempt with the provider or support first; deleting or recreating
154+
an item is not proof that a payment did not occur.
153155
154156
Args:
155157
extra_headers: Send extra headers
@@ -325,9 +327,11 @@ async def delete(
325327
) -> None:
326328
"""Unresolved payment operations block deletion.
327329
328-
Reconcile the original attempt
329-
with the provider or support first; deleting or recreating an item is not proof
330-
that a payment did not occur.
330+
Deleting a connected Kernel wallet
331+
first blocks new payments on it, then removes its enrolled card. If that fails,
332+
the wallet is kept and keeps refusing payments; retry the deletion. Reconcile
333+
the original attempt with the provider or support first; deleting or recreating
334+
an item is not proof that a payment did not occur.
331335
332336
Args:
333337
extra_headers: Send extra headers

‎src/kernel/types/vaults/__init__.py‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,12 +4,14 @@
44

55
from .vault_item import VaultItem as VaultItem
66
from .vault_item_event import VaultItemEvent as VaultItemEvent
7+
from .kernel_card_state import KernelCardState as KernelCardState
78
from .vault_item_action import VaultItemAction as VaultItemAction
89
from .item_events_params import ItemEventsParams as ItemEventsParams
910
from .item_list_response import ItemListResponse as ItemListResponse
1011
from .item_update_params import ItemUpdateParams as ItemUpdateParams
1112
from .item_upsert_params import ItemUpsertParams as ItemUpsertParams
1213
from .vault_card_aliases import VaultCardAliases as VaultCardAliases
14+
from .kernel_wallet_state import KernelWalletState as KernelWalletState
1315
from .card_vault_item_spec import CardVaultItemSpec as CardVaultItemSpec
1416
from .item_events_response import ItemEventsResponse as ItemEventsResponse
1517
from .item_retrieve_params import ItemRetrieveParams as ItemRetrieveParams
@@ -26,22 +28,26 @@
2628
from .vault_webmcp_binding_param import VaultWebmcpBindingParam as VaultWebmcpBindingParam
2729
from .credential_vault_field_type import CredentialVaultFieldType as CredentialVaultFieldType
2830
from .credential_vault_item_state import CredentialVaultItemState as CredentialVaultItemState
31+
from .kernel_card_vault_item_spec import KernelCardVaultItemSpec as KernelCardVaultItemSpec
2932
from .agentcard_prepared_processor import AgentcardPreparedProcessor as AgentcardPreparedProcessor
3033
from .credential_collection_action import CredentialCollectionAction as CredentialCollectionAction
3134
from .credential_vault_field_state import CredentialVaultFieldState as CredentialVaultFieldState
3235
from .vault_checkout_context_param import VaultCheckoutContextParam as VaultCheckoutContextParam
3336
from .credential_account_vault_item import CredentialAccountVaultItem as CredentialAccountVaultItem
3437
from .item_perform_operation_params import ItemPerformOperationParams as ItemPerformOperationParams
38+
from .kernel_wallet_vault_item_spec import KernelWalletVaultItemSpec as KernelWalletVaultItemSpec
3539
from .vault_item_operation_response import VaultItemOperationResponse as VaultItemOperationResponse
3640
from .agentcard_checkout_preparation import AgentcardCheckoutPreparation as AgentcardCheckoutPreparation
3741
from .agentcard_checkout_authorization import AgentcardCheckoutAuthorization as AgentcardCheckoutAuthorization
3842
from .fill_vault_item_operation_result import FillVaultItemOperationResult as FillVaultItemOperationResult
3943
from .credential_vault_field_definition import CredentialVaultFieldDefinition as CredentialVaultFieldDefinition
44+
from .kernel_card_vault_item_spec_param import KernelCardVaultItemSpecParam as KernelCardVaultItemSpecParam
4045
from .kernel_credential_vault_item_spec import KernelCredentialVaultItemSpec as KernelCredentialVaultItemSpec
4146
from .credential_vault_field_input_param import CredentialVaultFieldInputParam as CredentialVaultFieldInputParam
4247
from .kernel_credential_vault_item_state import KernelCredentialVaultItemState as KernelCredentialVaultItemState
4348
from .credential_vault_field_update_param import CredentialVaultFieldUpdateParam as CredentialVaultFieldUpdateParam
4449
from .credential_vault_item_request_param import CredentialVaultItemRequestParam as CredentialVaultItemRequestParam
50+
from .kernel_wallet_vault_item_spec_param import KernelWalletVaultItemSpecParam as KernelWalletVaultItemSpecParam
4551
from .one_password_credential_account_spec import OnePasswordCredentialAccountSpec as OnePasswordCredentialAccountSpec
4652
from .one_password_credential_account_state import (
4753
OnePasswordCredentialAccountState as OnePasswordCredentialAccountState,

‎src/kernel/types/vaults/authorize_vault_item_operation_request_param.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88

99

1010
class AuthorizeVaultItemOperationRequestParam(TypedDict, total=False):
11-
"""Authorize a Link card using its existing purchase specification.
11+
"""Authorize a Link or Kernel card using its existing purchase specification.
1212
1313
Use only after explicit user approval and when the item advertises authorize. Do not automatically retry provider failures or indeterminate outcomes. Checkout context is not accepted.
1414
"""

‎src/kernel/types/vaults/card_vault_item_spec.py‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@
55

66
from ..._utils import PropertyInfo
77
from ..._models import BaseModel
8+
from .kernel_card_vault_item_spec import KernelCardVaultItemSpec
89

910
__all__ = [
1011
"CardVaultItemSpec",
@@ -133,5 +134,6 @@ class AgentCardCardVaultItemSpec(BaseModel):
133134

134135

135136
CardVaultItemSpec: TypeAlias = Annotated[
136-
Union[LinkCardVaultItemSpec, AgentCardCardVaultItemSpec], PropertyInfo(discriminator="provider")
137+
Union[LinkCardVaultItemSpec, AgentCardCardVaultItemSpec, KernelCardVaultItemSpec],
138+
PropertyInfo(discriminator="provider"),
137139
]

‎src/kernel/types/vaults/card_vault_item_spec_param.py‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,8 @@
55
from typing import Dict, Union, Iterable
66
from typing_extensions import Literal, Required, TypeAlias, TypedDict
77

8+
from .kernel_card_vault_item_spec_param import KernelCardVaultItemSpecParam
9+
810
__all__ = [
911
"CardVaultItemSpecParam",
1012
"LinkCardVaultItemSpec",
@@ -131,4 +133,6 @@ class AgentCardCardVaultItemSpec(TypedDict, total=False):
131133
"""
132134

133135

134-
CardVaultItemSpecParam: TypeAlias = Union[LinkCardVaultItemSpec, AgentCardCardVaultItemSpec]
136+
CardVaultItemSpecParam: TypeAlias = Union[
137+
LinkCardVaultItemSpec, AgentCardCardVaultItemSpec, KernelCardVaultItemSpecParam
138+
]

‎src/kernel/types/vaults/card_vault_item_state.py‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@
77

88
from ..._utils import PropertyInfo
99
from ..._models import BaseModel
10+
from .kernel_card_state import KernelCardState
1011
from .vault_card_aliases import VaultCardAliases
1112
from .agentcard_checkout_preparation import AgentcardCheckoutPreparation
1213
from .agentcard_checkout_authorization import AgentcardCheckoutAuthorization
@@ -19,6 +20,9 @@ class LinkCardStateMasks(BaseModel):
1920

2021
last4: Optional[str] = None
2122

23+
token_last4: Optional[str] = None
24+
"""Last four digits of the network token presented to the merchant."""
25+
2226
if TYPE_CHECKING:
2327
# Some versions of Pydantic <2.8.0 have a bug and don’t allow assigning a
2428
# value to this field, so for compatibility we avoid doing it at runtime.
@@ -64,6 +68,9 @@ class AgentCardCardStateMasks(BaseModel):
6468

6569
last4: Optional[str] = None
6670

71+
token_last4: Optional[str] = None
72+
"""Last four digits of the network token presented to the merchant."""
73+
6774
if TYPE_CHECKING:
6875
# Some versions of Pydantic <2.8.0 have a bug and don’t allow assigning a
6976
# value to this field, so for compatibility we avoid doing it at runtime.
@@ -127,5 +134,5 @@ class AgentCardCardState(BaseModel):
127134

128135

129136
CardVaultItemState: TypeAlias = Annotated[
130-
Union[LinkCardState, AgentCardCardState], PropertyInfo(discriminator="provider")
137+
Union[LinkCardState, AgentCardCardState, KernelCardState], PropertyInfo(discriminator="provider")
131138
]

‎src/kernel/types/vaults/fill_vault_item_operation_request_param.py‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,8 +12,8 @@
1212

1313
class FillVaultItemOperationRequestParam(TypedDict, total=False):
1414
"""
15-
Fill selected fields from one ready credential or ready, unexpired Link card
16-
into a browser linked to its vault.
15+
Fill selected fields from one ready credential or ready, unexpired Link or
16+
Kernel card into a browser linked to its vault.
1717
Only invoke when the item advertises `fill`. Browser and vault must belong
1818
to the same project. Kernel checks access and allowed destinations before
1919
filling; providing a page URL does not authorize a destination.
@@ -34,7 +34,7 @@ class FillVaultItemOperationRequestParam(TypedDict, total=False):
3434
Fill in request order and stop on the first failure. This operation is
3535
not atomic: previously filled fields are not rolled back. Never submit
3636
the form or click buttons, though input/change events may trigger site
37-
behavior. Link cards use fill for browser checkout and do not expose
37+
behavior. Link and Kernel cards use fill for browser checkout and do not expose
3838
aliases or support egress substitution. Do not automatically retry a
3939
failed or indeterminate operation.
4040

‎src/kernel/types/vaults/item_upsert_params.py‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@
66
from typing_extensions import Literal, Required, TypeAlias, TypedDict
77

88
from .card_vault_item_spec_param import CardVaultItemSpecParam
9+
from .kernel_wallet_vault_item_spec_param import KernelWalletVaultItemSpecParam
910
from .credential_vault_item_spec_input_param import CredentialVaultItemSpecInputParam
1011
from .one_password_credential_account_spec_param import OnePasswordCredentialAccountSpecParam
1112

@@ -176,7 +177,9 @@ class WalletVaultItemRequestSpecAgentCardWalletVaultItemSpec(TypedDict, total=Fa
176177

177178

178179
WalletVaultItemRequestSpec: TypeAlias = Union[
179-
WalletVaultItemRequestSpecLinkWalletVaultItemRequestSpec, WalletVaultItemRequestSpecAgentCardWalletVaultItemSpec
180+
WalletVaultItemRequestSpecLinkWalletVaultItemRequestSpec,
181+
WalletVaultItemRequestSpecAgentCardWalletVaultItemSpec,
182+
KernelWalletVaultItemSpecParam,
180183
]
181184

182185

0 commit comments

Comments
 (0)