Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .release-please-manifest.json
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
{
".": "0.115.0"
".": "0.116.0"
}
7 changes: 7 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,12 @@
# Changelog

## [0.116.0](https://github.com/kernel/kernel-python-sdk/compare/v0.115.0...v0.116.0) (2026-10-01)


### Features

* chore(stlc): seal custom-code tracking files ([c053ce4](https://github.com/kernel/kernel-python-sdk/commit/c053ce45e5d6bfaa4577310d28b3ecf0a7c16f4e))

## [0.115.0](https://github.com/kernel/kernel-python-sdk/compare/v0.114.0...v0.115.0) (2026-09-30)


Expand Down
2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[project]
name = "kernel"
version = "0.115.0"
version = "0.116.0"
description = "The official Python library for the kernel API"
dynamic = ["readme"]
license = "Apache-2.0"
Expand Down
2 changes: 1 addition & 1 deletion src/kernel/_version.py
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details.

__title__ = "kernel"
__version__ = "0.115.0" # x-release-please-version
__version__ = "0.116.0" # x-release-please-version
89 changes: 81 additions & 8 deletions src/kernel/resources/credentials.py
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
from __future__ import annotations

from typing import Dict, Optional
from typing_extensions import Literal

import httpx

Expand Down Expand Up @@ -54,6 +55,9 @@ def create(
name: str,
values: Dict[str, str],
sso_provider: str | Omit = omit,
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"] | Omit = omit,
totp_digits: int | Omit = omit,
totp_period: int | Omit = omit,
totp_secret: str | Omit = omit,
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
# The extra values given here take precedence over values defined on the client or passed to this method.
Expand All @@ -77,8 +81,20 @@ def create(
button, it will be clicked first before filling credential values on the
identity provider's login page.
totp_secret: Base32-encoded TOTP secret for generating one-time passwords. Used for automatic
2FA during login.
totp_algorithm: HMAC algorithm used to generate TOTP codes. Defaults to SHA1 and is ignored when
an `otpauth://` URI supplies the algorithm.
totp_digits: Number of digits in generated TOTP codes. Defaults to 6 and is ignored when an
`otpauth://` URI supplies the digit count.
totp_period: TOTP rotation period in seconds. Defaults to 30 and is ignored when an
`otpauth://` URI supplies the period.
totp_secret: Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
URI. The range accepts existing shorter seeds and longer seeds regardless of
HMAC algorithm; RFC 6238 recommends unpadded base32 lengths of 32/52/103 for
SHA1/SHA256/SHA512. Only URI parameters present override the corresponding
explicit TOTP fields. Used for automatic 2FA during login.
extra_headers: Send extra headers
Expand All @@ -96,6 +112,9 @@ def create(
"name": name,
"values": values,
"sso_provider": sso_provider,
"totp_algorithm": totp_algorithm,
"totp_digits": totp_digits,
"totp_period": totp_period,
"totp_secret": totp_secret,
},
credential_create_params.CredentialCreateParams,
Expand Down Expand Up @@ -147,6 +166,9 @@ def update(
name: str | Omit = omit,
remove_value_keys: SequenceNotStr[str] | Omit = omit,
sso_provider: Optional[str] | Omit = omit,
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"] | Omit = omit,
totp_digits: int | Omit = omit,
totp_period: int | Omit = omit,
totp_secret: str | Omit = omit,
values: Dict[str, str] | Omit = omit,
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
Expand All @@ -170,8 +192,20 @@ def update(
sso_provider: If set, indicates this credential should be used with the specified SSO
provider. Set to empty string or null to remove.
totp_secret: Base32-encoded TOTP secret for generating one-time passwords. Spaces and
formatting are automatically normalized. Set to empty string to remove.
totp_algorithm: HMAC algorithm used to generate TOTP codes. Requires totp_secret and is ignored
when an `otpauth://` URI supplies the algorithm.
totp_digits: Number of digits in generated TOTP codes. Requires totp_secret and is ignored
when an `otpauth://` URI supplies the digit count.
totp_period: TOTP rotation period in seconds. Requires totp_secret and is ignored when an
`otpauth://` URI supplies the period.
totp_secret: Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
URI. Only URI parameters present override the corresponding explicit TOTP
fields. When rotating a raw secret, omitted fields preserve their existing
values; a new URI defaults unspecified fields to SHA1/6/30. Set to empty string
to remove the secret and its metadata.
values: Field name to value mapping. Values are merged with existing values (new keys
added, existing keys overwritten).
Expand All @@ -193,6 +227,9 @@ def update(
"name": name,
"remove_value_keys": remove_value_keys,
"sso_provider": sso_provider,
"totp_algorithm": totp_algorithm,
"totp_digits": totp_digits,
"totp_period": totp_period,
"totp_secret": totp_secret,
"values": values,
},
Expand Down Expand Up @@ -360,6 +397,9 @@ async def create(
name: str,
values: Dict[str, str],
sso_provider: str | Omit = omit,
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"] | Omit = omit,
totp_digits: int | Omit = omit,
totp_period: int | Omit = omit,
totp_secret: str | Omit = omit,
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
# The extra values given here take precedence over values defined on the client or passed to this method.
Expand All @@ -383,8 +423,20 @@ async def create(
button, it will be clicked first before filling credential values on the
identity provider's login page.
totp_secret: Base32-encoded TOTP secret for generating one-time passwords. Used for automatic
2FA during login.
totp_algorithm: HMAC algorithm used to generate TOTP codes. Defaults to SHA1 and is ignored when
an `otpauth://` URI supplies the algorithm.
totp_digits: Number of digits in generated TOTP codes. Defaults to 6 and is ignored when an
`otpauth://` URI supplies the digit count.
totp_period: TOTP rotation period in seconds. Defaults to 30 and is ignored when an
`otpauth://` URI supplies the period.
totp_secret: Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
URI. The range accepts existing shorter seeds and longer seeds regardless of
HMAC algorithm; RFC 6238 recommends unpadded base32 lengths of 32/52/103 for
SHA1/SHA256/SHA512. Only URI parameters present override the corresponding
explicit TOTP fields. Used for automatic 2FA during login.
extra_headers: Send extra headers
Expand All @@ -402,6 +454,9 @@ async def create(
"name": name,
"values": values,
"sso_provider": sso_provider,
"totp_algorithm": totp_algorithm,
"totp_digits": totp_digits,
"totp_period": totp_period,
"totp_secret": totp_secret,
},
credential_create_params.CredentialCreateParams,
Expand Down Expand Up @@ -453,6 +508,9 @@ async def update(
name: str | Omit = omit,
remove_value_keys: SequenceNotStr[str] | Omit = omit,
sso_provider: Optional[str] | Omit = omit,
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"] | Omit = omit,
totp_digits: int | Omit = omit,
totp_period: int | Omit = omit,
totp_secret: str | Omit = omit,
values: Dict[str, str] | Omit = omit,
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
Expand All @@ -476,8 +534,20 @@ async def update(
sso_provider: If set, indicates this credential should be used with the specified SSO
provider. Set to empty string or null to remove.
totp_secret: Base32-encoded TOTP secret for generating one-time passwords. Spaces and
formatting are automatically normalized. Set to empty string to remove.
totp_algorithm: HMAC algorithm used to generate TOTP codes. Requires totp_secret and is ignored
when an `otpauth://` URI supplies the algorithm.
totp_digits: Number of digits in generated TOTP codes. Requires totp_secret and is ignored
when an `otpauth://` URI supplies the digit count.
totp_period: TOTP rotation period in seconds. Requires totp_secret and is ignored when an
`otpauth://` URI supplies the period.
totp_secret: Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
URI. Only URI parameters present override the corresponding explicit TOTP
fields. When rotating a raw secret, omitted fields preserve their existing
values; a new URI defaults unspecified fields to SHA1/6/30. Set to empty string
to remove the secret and its metadata.
values: Field name to value mapping. Values are merged with existing values (new keys
added, existing keys overwritten).
Expand All @@ -499,6 +569,9 @@ async def update(
"name": name,
"remove_value_keys": remove_value_keys,
"sso_provider": sso_provider,
"totp_algorithm": totp_algorithm,
"totp_digits": totp_digits,
"totp_period": totp_period,
"totp_secret": totp_secret,
"values": values,
},
Expand Down
21 changes: 20 additions & 1 deletion src/kernel/types/credential.py
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@

from typing import List, Optional
from datetime import datetime
from typing_extensions import Literal

from .._models import BaseModel

Expand Down Expand Up @@ -40,15 +41,33 @@ class Credential(BaseModel):
identity provider's login page.
"""

totp_algorithm: Optional[Literal["SHA1", "SHA256", "SHA512"]] = None
"""HMAC algorithm used to generate TOTP codes.
Defaults to SHA1 for credentials created before this metadata was stored.
"""

totp_code: Optional[str] = None
"""Current 6-digit TOTP code.
"""Current TOTP code.
Only included in create/update responses when totp_secret was just set.
"""

totp_code_expires_at: Optional[datetime] = None
"""When the totp_code expires. Only included when totp_code is present."""

totp_digits: Optional[int] = None
"""Number of digits in generated TOTP codes.
Defaults to 6 for credentials created before this metadata was stored.
"""

totp_period: Optional[int] = None
"""TOTP rotation period in seconds.
Defaults to 30 for credentials created before this metadata was stored.
"""

value_keys: Optional[List[str]] = None
"""The field names stored in this credential's values (e.g., username, password).
Expand Down
29 changes: 25 additions & 4 deletions src/kernel/types/credential_create_params.py
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
from __future__ import annotations

from typing import Dict
from typing_extensions import Required, TypedDict
from typing_extensions import Literal, Required, TypedDict

__all__ = ["CredentialCreateParams"]

Expand All @@ -26,8 +26,29 @@ class CredentialCreateParams(TypedDict, total=False):
identity provider's login page.
"""

totp_secret: str
"""Base32-encoded TOTP secret for generating one-time passwords.
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"]
"""HMAC algorithm used to generate TOTP codes.
Defaults to SHA1 and is ignored when an `otpauth://` URI supplies the algorithm.
"""

totp_digits: int
"""Number of digits in generated TOTP codes.
Defaults to 6 and is ignored when an `otpauth://` URI supplies the digit count.
"""

Used for automatic 2FA during login.
totp_period: int
"""TOTP rotation period in seconds.
Defaults to 30 and is ignored when an `otpauth://` URI supplies the period.
"""

totp_secret: str
"""
Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
URI. The range accepts existing shorter seeds and longer seeds regardless of
HMAC algorithm; RFC 6238 recommends unpadded base32 lengths of 32/52/103 for
SHA1/SHA256/SHA512. Only URI parameters present override the corresponding
explicit TOTP fields. Used for automatic 2FA during login.
"""
33 changes: 28 additions & 5 deletions src/kernel/types/credential_update_params.py
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
from __future__ import annotations

from typing import Dict, Optional
from typing_extensions import TypedDict
from typing_extensions import Literal, TypedDict

from .._types import SequenceNotStr

Expand All @@ -28,11 +28,34 @@ class CredentialUpdateParams(TypedDict, total=False):
Set to empty string or null to remove.
"""

totp_secret: str
"""Base32-encoded TOTP secret for generating one-time passwords.
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"]
"""HMAC algorithm used to generate TOTP codes.
Requires totp_secret and is ignored when an `otpauth://` URI supplies the
algorithm.
"""

totp_digits: int
"""Number of digits in generated TOTP codes.
Requires totp_secret and is ignored when an `otpauth://` URI supplies the digit
count.
"""

Spaces and formatting are automatically normalized. Set to empty string to
remove.
totp_period: int
"""TOTP rotation period in seconds.
Requires totp_secret and is ignored when an `otpauth://` URI supplies the
period.
"""

totp_secret: str
"""
Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
URI. Only URI parameters present override the corresponding explicit TOTP
fields. When rotating a raw secret, omitted fields preserve their existing
values; a new URI defaults unspecified fields to SHA1/6/30. Set to empty string
to remove the secret and its metadata.
"""

values: Dict[str, str]
Expand Down
14 changes: 13 additions & 1 deletion src/kernel/types/vaults/card_vault_item_spec.py
Original file line number Diff line number Diff line change
Expand Up @@ -96,7 +96,7 @@ class LinkCardVaultItemSpec(BaseModel):
class AgentCardCardVaultItemSpec(BaseModel):
"""AgentCard reusable live payment card.
Test-mode card creation is not supported. Each checkout creates an approval-gated authorization for spec.merchant / spec.amount. The card stays ready after each authorization.
Test-mode card creation is not supported. Each checkout creates an authorization for spec.merchant / spec.amount that the cardholder approves, unless AgentCard runs it under one of the cardholder's autopilot rules. The card stays ready after each authorization.
"""

amount: int
Expand All @@ -119,6 +119,18 @@ class AgentCardCardVaultItemSpec(BaseModel):
cardholder picks on the approval screen.
"""

checkout_origin: Optional[str] = None
"""
Origin of the top-level checkout page, such as https://shop.example.com: https,
a lowercase host, a port only when it is not 443, and no path. http is accepted
only for localhost test pages. Checkouts without a preparation send it to
AgentCard, which uses it to match the cardholder's autopilot rules; prepared
checkouts send the preparation's merchant_origin instead. Kernel sends the
declared value and does not compare it with the page the browser has open.
Omitted, those checkouts ask the cardholder to approve. Card updates replace the
whole spec, so an update that omits it removes it.
"""


CardVaultItemSpec: TypeAlias = Annotated[
Union[LinkCardVaultItemSpec, AgentCardCardVaultItemSpec], PropertyInfo(discriminator="provider")
Expand Down
Loading
Loading