From eaa17a1e7068bb70abe9f07f4bba1c818ddeeba1 Mon Sep 17 00:00:00 2001 From: "kernel-internal[bot]" <260533166+kernel-internal[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 18:51:54 +0000 Subject: [PATCH 1/3] feat: Add a query filter to the vault list endpoint Stainless-Generated-From: 2ad89a5e5d2f5cd1b76eac4a3291e961f8894bdd --- src/kernel/resources/vaults/vaults.py | 8 ++++++++ src/kernel/types/vault_list_params.py | 3 +++ tests/api_resources/test_vaults.py | 2 ++ 3 files changed, 13 insertions(+) diff --git a/src/kernel/resources/vaults/vaults.py b/src/kernel/resources/vaults/vaults.py index 16619462..4f3003b9 100644 --- a/src/kernel/resources/vaults/vaults.py +++ b/src/kernel/resources/vaults/vaults.py @@ -92,6 +92,7 @@ def list( *, limit: int | Omit = omit, offset: int | Omit = omit, + query: str | Omit = omit, # Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs. # The extra values given here take precedence over values defined on the client or passed to this method. extra_headers: Headers | None = None, @@ -103,6 +104,8 @@ def list( List vaults in the current project Args: + query: Case-insensitive substring match against vault name. IDs match by exact value. + extra_headers: Send extra headers extra_query: Add additional query parameters to the request @@ -123,6 +126,7 @@ def list( { "limit": limit, "offset": offset, + "query": query, }, vault_list_params.VaultListParams, ), @@ -266,6 +270,7 @@ def list( *, limit: int | Omit = omit, offset: int | Omit = omit, + query: str | Omit = omit, # Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs. # The extra values given here take precedence over values defined on the client or passed to this method. extra_headers: Headers | None = None, @@ -277,6 +282,8 @@ def list( List vaults in the current project Args: + query: Case-insensitive substring match against vault name. IDs match by exact value. + extra_headers: Send extra headers extra_query: Add additional query parameters to the request @@ -297,6 +304,7 @@ def list( { "limit": limit, "offset": offset, + "query": query, }, vault_list_params.VaultListParams, ), diff --git a/src/kernel/types/vault_list_params.py b/src/kernel/types/vault_list_params.py index 7530bc28..7a0848df 100644 --- a/src/kernel/types/vault_list_params.py +++ b/src/kernel/types/vault_list_params.py @@ -11,3 +11,6 @@ class VaultListParams(TypedDict, total=False): limit: int offset: int + + query: str + """Case-insensitive substring match against vault name. IDs match by exact value.""" diff --git a/tests/api_resources/test_vaults.py b/tests/api_resources/test_vaults.py index f9b36c73..5d11ac98 100644 --- a/tests/api_resources/test_vaults.py +++ b/tests/api_resources/test_vaults.py @@ -72,6 +72,7 @@ def test_method_list_with_all_params(self, client: Kernel) -> None: vault = client.vaults.list( limit=1, offset=0, + query="query", ) assert_matches_type(SyncOffsetPagination[Vault], vault, path=["response"]) @@ -233,6 +234,7 @@ async def test_method_list_with_all_params(self, async_client: AsyncKernel) -> N vault = await async_client.vaults.list( limit=1, offset=0, + query="query", ) assert_matches_type(AsyncOffsetPagination[Vault], vault, path=["response"]) From 04d839e6bb948049d3683380efeaae5a3732c959 Mon Sep 17 00:00:00 2001 From: "kernel-internal[bot]" <260533166+kernel-internal[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 19:55:46 +0000 Subject: [PATCH 2/3] feat: Add Kernel wallets backed by VGS agentic network tokens, with hosted card capture Stainless-Generated-From: 1b0aa5849d3ee8fe7ca69bec3d598286918fc571 --- api.md | 4 ++ src/kernel/resources/vaults/items.py | 22 ++++--- src/kernel/resources/vaults/vaults.py | 16 +++-- src/kernel/types/vaults/__init__.py | 6 ++ ...rize_vault_item_operation_request_param.py | 2 +- .../types/vaults/card_vault_item_spec.py | 4 +- .../vaults/card_vault_item_spec_param.py | 6 +- .../types/vaults/card_vault_item_state.py | 9 ++- ...fill_vault_item_operation_request_param.py | 6 +- src/kernel/types/vaults/item_upsert_params.py | 5 +- src/kernel/types/vaults/kernel_card_state.py | 60 +++++++++++++++++++ .../vaults/kernel_card_vault_item_spec.py | 37 ++++++++++++ .../kernel_card_vault_item_spec_param.py | 37 ++++++++++++ .../types/vaults/kernel_wallet_state.py | 23 +++++++ .../vaults/kernel_wallet_vault_item_spec.py | 15 +++++ .../kernel_wallet_vault_item_spec_param.py | 15 +++++ .../types/vaults/wallet_vault_item_spec.py | 4 +- .../types/vaults/wallet_vault_item_state.py | 3 +- 18 files changed, 250 insertions(+), 24 deletions(-) create mode 100644 src/kernel/types/vaults/kernel_card_state.py create mode 100644 src/kernel/types/vaults/kernel_card_vault_item_spec.py create mode 100644 src/kernel/types/vaults/kernel_card_vault_item_spec_param.py create mode 100644 src/kernel/types/vaults/kernel_wallet_state.py create mode 100644 src/kernel/types/vaults/kernel_wallet_vault_item_spec.py create mode 100644 src/kernel/types/vaults/kernel_wallet_vault_item_spec_param.py diff --git a/api.md b/api.md index 90bbc16d..a043d74d 100644 --- a/api.md +++ b/api.md @@ -572,9 +572,13 @@ from kernel.types.vaults import ( CredentialVaultItemUpdateRequest, FillVaultItemOperationRequest, FillVaultItemOperationResult, + KernelCardState, + KernelCardVaultItemSpec, KernelCredentialVaultItemSpec, KernelCredentialVaultItemSpecInput, KernelCredentialVaultItemState, + KernelWalletState, + KernelWalletVaultItemSpec, OnePasswordCredentialAccountSpec, OnePasswordCredentialAccountState, OnePasswordCredentialVaultItemSpec, diff --git a/src/kernel/resources/vaults/items.py b/src/kernel/resources/vaults/items.py index 433551aa..ffda784c 100644 --- a/src/kernel/resources/vaults/items.py +++ b/src/kernel/resources/vaults/items.py @@ -309,10 +309,13 @@ def delete( ) -> None: """ Unresolved payment operations normally block deletion, including operations on - child cards of a wallet. An AgentCard card in recovery_required whose checkout - create response returned no authorization ID may be explicitly abandoned by - deleting that card directly; deleting its wallet or vault remains blocked. - Deleting or recreating an item is not proof that a payment did not occur. + child cards of a wallet. Deleting a connected Kernel wallet first blocks new + payments on it, then removes its enrolled card. If that fails, the wallet is + kept and keeps refusing payments; retry the deletion. An AgentCard card in + recovery_required whose checkout create response returned no authorization ID + may be explicitly abandoned by deleting that card directly; deleting its wallet + or vault remains blocked. Deleting or recreating an item is not proof that a + payment did not occur. Args: extra_headers: Send extra headers @@ -1483,10 +1486,13 @@ async def delete( ) -> None: """ Unresolved payment operations normally block deletion, including operations on - child cards of a wallet. An AgentCard card in recovery_required whose checkout - create response returned no authorization ID may be explicitly abandoned by - deleting that card directly; deleting its wallet or vault remains blocked. - Deleting or recreating an item is not proof that a payment did not occur. + child cards of a wallet. Deleting a connected Kernel wallet first blocks new + payments on it, then removes its enrolled card. If that fails, the wallet is + kept and keeps refusing payments; retry the deletion. An AgentCard card in + recovery_required whose checkout create response returned no authorization ID + may be explicitly abandoned by deleting that card directly; deleting its wallet + or vault remains blocked. Deleting or recreating an item is not proof that a + payment did not occur. Args: extra_headers: Send extra headers diff --git a/src/kernel/resources/vaults/vaults.py b/src/kernel/resources/vaults/vaults.py index 4f3003b9..a8b5446f 100644 --- a/src/kernel/resources/vaults/vaults.py +++ b/src/kernel/resources/vaults/vaults.py @@ -147,9 +147,11 @@ def delete( ) -> None: """Unresolved payment operations block deletion. - Reconcile the original attempt - with the provider or support first; deleting or recreating an item is not proof - that a payment did not occur. + Deleting a connected Kernel wallet + first blocks new payments on it, then removes its enrolled card. If that fails, + the wallet is kept and keeps refusing payments; retry the deletion. Reconcile + the original attempt with the provider or support first; deleting or recreating + an item is not proof that a payment did not occur. Args: extra_headers: Send extra headers @@ -325,9 +327,11 @@ async def delete( ) -> None: """Unresolved payment operations block deletion. - Reconcile the original attempt - with the provider or support first; deleting or recreating an item is not proof - that a payment did not occur. + Deleting a connected Kernel wallet + first blocks new payments on it, then removes its enrolled card. If that fails, + the wallet is kept and keeps refusing payments; retry the deletion. Reconcile + the original attempt with the provider or support first; deleting or recreating + an item is not proof that a payment did not occur. Args: extra_headers: Send extra headers diff --git a/src/kernel/types/vaults/__init__.py b/src/kernel/types/vaults/__init__.py index 8458ebce..75f523f0 100644 --- a/src/kernel/types/vaults/__init__.py +++ b/src/kernel/types/vaults/__init__.py @@ -4,12 +4,14 @@ from .vault_item import VaultItem as VaultItem from .vault_item_event import VaultItemEvent as VaultItemEvent +from .kernel_card_state import KernelCardState as KernelCardState from .vault_item_action import VaultItemAction as VaultItemAction from .item_events_params import ItemEventsParams as ItemEventsParams from .item_list_response import ItemListResponse as ItemListResponse from .item_update_params import ItemUpdateParams as ItemUpdateParams from .item_upsert_params import ItemUpsertParams as ItemUpsertParams from .vault_card_aliases import VaultCardAliases as VaultCardAliases +from .kernel_wallet_state import KernelWalletState as KernelWalletState from .card_vault_item_spec import CardVaultItemSpec as CardVaultItemSpec from .item_events_response import ItemEventsResponse as ItemEventsResponse from .item_retrieve_params import ItemRetrieveParams as ItemRetrieveParams @@ -26,22 +28,26 @@ from .vault_webmcp_binding_param import VaultWebmcpBindingParam as VaultWebmcpBindingParam from .credential_vault_field_type import CredentialVaultFieldType as CredentialVaultFieldType from .credential_vault_item_state import CredentialVaultItemState as CredentialVaultItemState +from .kernel_card_vault_item_spec import KernelCardVaultItemSpec as KernelCardVaultItemSpec from .agentcard_prepared_processor import AgentcardPreparedProcessor as AgentcardPreparedProcessor from .credential_collection_action import CredentialCollectionAction as CredentialCollectionAction from .credential_vault_field_state import CredentialVaultFieldState as CredentialVaultFieldState from .vault_checkout_context_param import VaultCheckoutContextParam as VaultCheckoutContextParam from .credential_account_vault_item import CredentialAccountVaultItem as CredentialAccountVaultItem from .item_perform_operation_params import ItemPerformOperationParams as ItemPerformOperationParams +from .kernel_wallet_vault_item_spec import KernelWalletVaultItemSpec as KernelWalletVaultItemSpec from .vault_item_operation_response import VaultItemOperationResponse as VaultItemOperationResponse from .agentcard_checkout_preparation import AgentcardCheckoutPreparation as AgentcardCheckoutPreparation from .agentcard_checkout_authorization import AgentcardCheckoutAuthorization as AgentcardCheckoutAuthorization from .fill_vault_item_operation_result import FillVaultItemOperationResult as FillVaultItemOperationResult from .credential_vault_field_definition import CredentialVaultFieldDefinition as CredentialVaultFieldDefinition +from .kernel_card_vault_item_spec_param import KernelCardVaultItemSpecParam as KernelCardVaultItemSpecParam from .kernel_credential_vault_item_spec import KernelCredentialVaultItemSpec as KernelCredentialVaultItemSpec from .credential_vault_field_input_param import CredentialVaultFieldInputParam as CredentialVaultFieldInputParam from .kernel_credential_vault_item_state import KernelCredentialVaultItemState as KernelCredentialVaultItemState from .credential_vault_field_update_param import CredentialVaultFieldUpdateParam as CredentialVaultFieldUpdateParam from .credential_vault_item_request_param import CredentialVaultItemRequestParam as CredentialVaultItemRequestParam +from .kernel_wallet_vault_item_spec_param import KernelWalletVaultItemSpecParam as KernelWalletVaultItemSpecParam from .one_password_credential_account_spec import OnePasswordCredentialAccountSpec as OnePasswordCredentialAccountSpec from .one_password_credential_account_state import ( OnePasswordCredentialAccountState as OnePasswordCredentialAccountState, diff --git a/src/kernel/types/vaults/authorize_vault_item_operation_request_param.py b/src/kernel/types/vaults/authorize_vault_item_operation_request_param.py index 10ba11bc..d267b310 100644 --- a/src/kernel/types/vaults/authorize_vault_item_operation_request_param.py +++ b/src/kernel/types/vaults/authorize_vault_item_operation_request_param.py @@ -8,7 +8,7 @@ class AuthorizeVaultItemOperationRequestParam(TypedDict, total=False): - """Authorize a Link card using its existing purchase specification. + """Authorize a Link or Kernel card using its existing purchase specification. Use only after explicit user approval and when the item advertises authorize. Do not automatically retry provider failures or indeterminate outcomes. Checkout context is not accepted. """ diff --git a/src/kernel/types/vaults/card_vault_item_spec.py b/src/kernel/types/vaults/card_vault_item_spec.py index 880ce111..61f8fff4 100644 --- a/src/kernel/types/vaults/card_vault_item_spec.py +++ b/src/kernel/types/vaults/card_vault_item_spec.py @@ -5,6 +5,7 @@ from ..._utils import PropertyInfo from ..._models import BaseModel +from .kernel_card_vault_item_spec import KernelCardVaultItemSpec __all__ = [ "CardVaultItemSpec", @@ -133,5 +134,6 @@ class AgentCardCardVaultItemSpec(BaseModel): CardVaultItemSpec: TypeAlias = Annotated[ - Union[LinkCardVaultItemSpec, AgentCardCardVaultItemSpec], PropertyInfo(discriminator="provider") + Union[LinkCardVaultItemSpec, AgentCardCardVaultItemSpec, KernelCardVaultItemSpec], + PropertyInfo(discriminator="provider"), ] diff --git a/src/kernel/types/vaults/card_vault_item_spec_param.py b/src/kernel/types/vaults/card_vault_item_spec_param.py index 3f27771a..635bcdc1 100644 --- a/src/kernel/types/vaults/card_vault_item_spec_param.py +++ b/src/kernel/types/vaults/card_vault_item_spec_param.py @@ -5,6 +5,8 @@ from typing import Dict, Union, Iterable from typing_extensions import Literal, Required, TypeAlias, TypedDict +from .kernel_card_vault_item_spec_param import KernelCardVaultItemSpecParam + __all__ = [ "CardVaultItemSpecParam", "LinkCardVaultItemSpec", @@ -131,4 +133,6 @@ class AgentCardCardVaultItemSpec(TypedDict, total=False): """ -CardVaultItemSpecParam: TypeAlias = Union[LinkCardVaultItemSpec, AgentCardCardVaultItemSpec] +CardVaultItemSpecParam: TypeAlias = Union[ + LinkCardVaultItemSpec, AgentCardCardVaultItemSpec, KernelCardVaultItemSpecParam +] diff --git a/src/kernel/types/vaults/card_vault_item_state.py b/src/kernel/types/vaults/card_vault_item_state.py index df7a4306..cead6d53 100644 --- a/src/kernel/types/vaults/card_vault_item_state.py +++ b/src/kernel/types/vaults/card_vault_item_state.py @@ -7,6 +7,7 @@ from ..._utils import PropertyInfo from ..._models import BaseModel +from .kernel_card_state import KernelCardState from .vault_card_aliases import VaultCardAliases from .agentcard_checkout_preparation import AgentcardCheckoutPreparation from .agentcard_checkout_authorization import AgentcardCheckoutAuthorization @@ -19,6 +20,9 @@ class LinkCardStateMasks(BaseModel): last4: Optional[str] = None + token_last4: Optional[str] = None + """Last four digits of the network token presented to the merchant.""" + if TYPE_CHECKING: # Some versions of Pydantic <2.8.0 have a bug and don’t allow assigning a # value to this field, so for compatibility we avoid doing it at runtime. @@ -64,6 +68,9 @@ class AgentCardCardStateMasks(BaseModel): last4: Optional[str] = None + token_last4: Optional[str] = None + """Last four digits of the network token presented to the merchant.""" + if TYPE_CHECKING: # Some versions of Pydantic <2.8.0 have a bug and don’t allow assigning a # value to this field, so for compatibility we avoid doing it at runtime. @@ -127,5 +134,5 @@ class AgentCardCardState(BaseModel): CardVaultItemState: TypeAlias = Annotated[ - Union[LinkCardState, AgentCardCardState], PropertyInfo(discriminator="provider") + Union[LinkCardState, AgentCardCardState, KernelCardState], PropertyInfo(discriminator="provider") ] diff --git a/src/kernel/types/vaults/fill_vault_item_operation_request_param.py b/src/kernel/types/vaults/fill_vault_item_operation_request_param.py index 012ec2b9..da288f04 100644 --- a/src/kernel/types/vaults/fill_vault_item_operation_request_param.py +++ b/src/kernel/types/vaults/fill_vault_item_operation_request_param.py @@ -12,8 +12,8 @@ class FillVaultItemOperationRequestParam(TypedDict, total=False): """ - Fill selected fields from one ready credential or ready, unexpired Link card - into a browser linked to its vault. + Fill selected fields from one ready credential or ready, unexpired Link or + Kernel card into a browser linked to its vault. Only invoke when the item advertises `fill`. Browser and vault must belong to the same project. Kernel checks access and allowed destinations before filling; providing a page URL does not authorize a destination. @@ -34,7 +34,7 @@ class FillVaultItemOperationRequestParam(TypedDict, total=False): Fill in request order and stop on the first failure. This operation is not atomic: previously filled fields are not rolled back. Never submit the form or click buttons, though input/change events may trigger site - behavior. Link cards use fill for browser checkout and do not expose + behavior. Link and Kernel cards use fill for browser checkout and do not expose aliases or support egress substitution. Do not automatically retry a failed or indeterminate operation. diff --git a/src/kernel/types/vaults/item_upsert_params.py b/src/kernel/types/vaults/item_upsert_params.py index fc9acbdf..e77fbabf 100644 --- a/src/kernel/types/vaults/item_upsert_params.py +++ b/src/kernel/types/vaults/item_upsert_params.py @@ -6,6 +6,7 @@ from typing_extensions import Literal, Required, TypeAlias, TypedDict from .card_vault_item_spec_param import CardVaultItemSpecParam +from .kernel_wallet_vault_item_spec_param import KernelWalletVaultItemSpecParam from .credential_vault_item_spec_input_param import CredentialVaultItemSpecInputParam from .one_password_credential_account_spec_param import OnePasswordCredentialAccountSpecParam @@ -176,7 +177,9 @@ class WalletVaultItemRequestSpecAgentCardWalletVaultItemSpec(TypedDict, total=Fa WalletVaultItemRequestSpec: TypeAlias = Union[ - WalletVaultItemRequestSpecLinkWalletVaultItemRequestSpec, WalletVaultItemRequestSpecAgentCardWalletVaultItemSpec + WalletVaultItemRequestSpecLinkWalletVaultItemRequestSpec, + WalletVaultItemRequestSpecAgentCardWalletVaultItemSpec, + KernelWalletVaultItemSpecParam, ] diff --git a/src/kernel/types/vaults/kernel_card_state.py b/src/kernel/types/vaults/kernel_card_state.py new file mode 100644 index 00000000..526eb4b3 --- /dev/null +++ b/src/kernel/types/vaults/kernel_card_state.py @@ -0,0 +1,60 @@ +# File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details. + +from typing import TYPE_CHECKING, Dict, List, Optional +from typing_extensions import Literal + +from pydantic import Field as FieldInfo + +from ..._models import BaseModel + +__all__ = ["KernelCardState", "Masks"] + + +class Masks(BaseModel): + brand: Optional[str] = None + + last4: Optional[str] = None + + token_last4: Optional[str] = None + """Last four digits of the network token presented to the merchant.""" + + if TYPE_CHECKING: + # Some versions of Pydantic <2.8.0 have a bug and don’t allow assigning a + # value to this field, so for compatibility we avoid doing it at runtime. + __pydantic_extra__: Dict[str, str] = FieldInfo(init=False) # pyright: ignore[reportIncompatibleVariableOverride] + + # Stub to indicate that arbitrary properties are accepted. + # To access properties that are not valid identifiers you can use `getattr`, e.g. + # `getattr(obj, '$type')` + def __getattr__(self, attr: str) -> str: ... + else: + __pydantic_extra__: Dict[str, str] + + +class KernelCardState(BaseModel): + """ + A ready Kernel card retains its encrypted network token and one-time code for the fill operation until the item's expires_at. Fill and submit checkout before then. Visa cards can be enrolled, but Visa purchases are not yet supported and authorize returns 400; supported Mastercard purchases need no cardholder approval. masks.last4 is the enrolled card's last four digits; masks.token_last4 is the network token's last four digits shown to the merchant. Kernel cards do not expose aliases or support egress substitution. Kernel does not observe whether the merchant charged the card. + """ + + provider: Literal["kernel"] + + status: Literal[ + "requested", "pending_authorization", "ready", "consumed", "expired", "declined", "recovery_required" + ] + """recovery_required means issuing the one-time code has an unresolved outcome. + + Kernel never issues another code for the item automatically, and the item cannot + be deleted or replaced until the original attempt is reconciled with support. + When status_reason says the provider refused retrieval before acceptance, no + code was issued and a later read retries. + """ + + domains: Optional[List[str]] = None + """Informational registrable domain. + + Fill is locked to merchant_url's exact origin. + """ + + masks: Optional[Masks] = None + + status_reason: Optional[str] = None diff --git a/src/kernel/types/vaults/kernel_card_vault_item_spec.py b/src/kernel/types/vaults/kernel_card_vault_item_spec.py new file mode 100644 index 00000000..65f75f8d --- /dev/null +++ b/src/kernel/types/vaults/kernel_card_vault_item_spec.py @@ -0,0 +1,37 @@ +# File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details. + +from typing_extensions import Literal + +from ..._models import BaseModel + +__all__ = ["KernelCardVaultItemSpec"] + + +class KernelCardVaultItemSpec(BaseModel): + """One live purchase with a Kernel-enrolled card. + + Authorization obtains an agentic network token number, expiry and one-time 3-digit code. They are stored encrypted for the fill operation, which types them only on merchant_url's origin; the merchant's own checkout submits the payment. The one-time code is valid until the item's expires_at; fill and submit checkout before then. Visa cards can be enrolled, but Visa purchases are not yet supported: authorize returns 400. Supported Mastercard purchases need no cardholder approval. Card updates are not supported; delete and create a new item instead. + """ + + amount: int + """ + Integer amount in minor currency units (at most 50000), bound to the one-time + code. + """ + + currency: str + """ISO 4217 code. + + Supported: aud, brl, cad, chf, czk, dkk, eur, gbp, hkd, inr, jpy, krw, mxn, nok, + nzd, pln, sek, sgd, usd, zar. + """ + + merchant_name: str + + merchant_url: str + """Merchant checkout URL. Fill is allowed only on this URL's origin.""" + + provider: Literal["kernel"] + + wallet: str + """Key of the Kernel wallet item whose enrolled card pays.""" diff --git a/src/kernel/types/vaults/kernel_card_vault_item_spec_param.py b/src/kernel/types/vaults/kernel_card_vault_item_spec_param.py new file mode 100644 index 00000000..c625dfac --- /dev/null +++ b/src/kernel/types/vaults/kernel_card_vault_item_spec_param.py @@ -0,0 +1,37 @@ +# File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details. + +from __future__ import annotations + +from typing_extensions import Literal, Required, TypedDict + +__all__ = ["KernelCardVaultItemSpecParam"] + + +class KernelCardVaultItemSpecParam(TypedDict, total=False): + """One live purchase with a Kernel-enrolled card. + + Authorization obtains an agentic network token number, expiry and one-time 3-digit code. They are stored encrypted for the fill operation, which types them only on merchant_url's origin; the merchant's own checkout submits the payment. The one-time code is valid until the item's expires_at; fill and submit checkout before then. Visa cards can be enrolled, but Visa purchases are not yet supported: authorize returns 400. Supported Mastercard purchases need no cardholder approval. Card updates are not supported; delete and create a new item instead. + """ + + amount: Required[int] + """ + Integer amount in minor currency units (at most 50000), bound to the one-time + code. + """ + + currency: Required[str] + """ISO 4217 code. + + Supported: aud, brl, cad, chf, czk, dkk, eur, gbp, hkd, inr, jpy, krw, mxn, nok, + nzd, pln, sek, sgd, usd, zar. + """ + + merchant_name: Required[str] + + merchant_url: Required[str] + """Merchant checkout URL. Fill is allowed only on this URL's origin.""" + + provider: Required[Literal["kernel"]] + + wallet: Required[str] + """Key of the Kernel wallet item whose enrolled card pays.""" diff --git a/src/kernel/types/vaults/kernel_wallet_state.py b/src/kernel/types/vaults/kernel_wallet_state.py new file mode 100644 index 00000000..4051c709 --- /dev/null +++ b/src/kernel/types/vaults/kernel_wallet_state.py @@ -0,0 +1,23 @@ +# File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details. + +from typing import Optional +from typing_extensions import Literal + +from ..._models import BaseModel + +__all__ = ["KernelWalletState"] + + +class KernelWalletState(BaseModel): + provider: Literal["kernel"] + + status: Literal["pending_authorization", "connected", "reconnect_required", "degraded"] + """pending_authorization asks the cardholder to use the card_enrollment action. + + connected is ready for supported purchases. reconnect_required asks the + cardholder to use a new card_enrollment action after an uncertain enrollment was + safely removed. degraded means the enrollment outcome is unknown and the wallet + must be deleted before adding another card. + """ + + status_reason: Optional[str] = None diff --git a/src/kernel/types/vaults/kernel_wallet_vault_item_spec.py b/src/kernel/types/vaults/kernel_wallet_vault_item_spec.py new file mode 100644 index 00000000..70b95ea4 --- /dev/null +++ b/src/kernel/types/vaults/kernel_wallet_vault_item_spec.py @@ -0,0 +1,15 @@ +# File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details. + +from typing_extensions import Literal + +from ..._models import BaseModel + +__all__ = ["KernelWalletVaultItemSpec"] + + +class KernelWalletVaultItemSpec(BaseModel): + """ + One card Kernel enrolls for Visa or Mastercard agentic network tokens using Kernel-managed credentials. Creation returns a card_enrollment action: the cardholder enters the card and their email on a Kernel-hosted page, then Kernel enrolls the securely stored card. The card number never reaches Kernel. The connected wallet's payment_methods expansion lists the enrolled card. Visa cards can be enrolled, but Visa purchases are not yet supported: authorize returns 400. + """ + + provider: Literal["kernel"] diff --git a/src/kernel/types/vaults/kernel_wallet_vault_item_spec_param.py b/src/kernel/types/vaults/kernel_wallet_vault_item_spec_param.py new file mode 100644 index 00000000..df1337c5 --- /dev/null +++ b/src/kernel/types/vaults/kernel_wallet_vault_item_spec_param.py @@ -0,0 +1,15 @@ +# File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details. + +from __future__ import annotations + +from typing_extensions import Literal, Required, TypedDict + +__all__ = ["KernelWalletVaultItemSpecParam"] + + +class KernelWalletVaultItemSpecParam(TypedDict, total=False): + """ + One card Kernel enrolls for Visa or Mastercard agentic network tokens using Kernel-managed credentials. Creation returns a card_enrollment action: the cardholder enters the card and their email on a Kernel-hosted page, then Kernel enrolls the securely stored card. The card number never reaches Kernel. The connected wallet's payment_methods expansion lists the enrolled card. Visa cards can be enrolled, but Visa purchases are not yet supported: authorize returns 400. + """ + + provider: Required[Literal["kernel"]] diff --git a/src/kernel/types/vaults/wallet_vault_item_spec.py b/src/kernel/types/vaults/wallet_vault_item_spec.py index a09456a0..288fd7e3 100644 --- a/src/kernel/types/vaults/wallet_vault_item_spec.py +++ b/src/kernel/types/vaults/wallet_vault_item_spec.py @@ -5,6 +5,7 @@ from ..._utils import PropertyInfo from ..._models import BaseModel +from .kernel_wallet_vault_item_spec import KernelWalletVaultItemSpec __all__ = [ "WalletVaultItemSpec", @@ -95,5 +96,6 @@ class AgentCardWalletVaultItemSpec(BaseModel): WalletVaultItemSpec: TypeAlias = Annotated[ - Union[LinkWalletVaultItemSpec, AgentCardWalletVaultItemSpec], PropertyInfo(discriminator="provider") + Union[LinkWalletVaultItemSpec, AgentCardWalletVaultItemSpec, KernelWalletVaultItemSpec], + PropertyInfo(discriminator="provider"), ] diff --git a/src/kernel/types/vaults/wallet_vault_item_state.py b/src/kernel/types/vaults/wallet_vault_item_state.py index 9b76f419..e91b08d8 100644 --- a/src/kernel/types/vaults/wallet_vault_item_state.py +++ b/src/kernel/types/vaults/wallet_vault_item_state.py @@ -5,6 +5,7 @@ from ..._utils import PropertyInfo from ..._models import BaseModel +from .kernel_wallet_state import KernelWalletState __all__ = ["WalletVaultItemState", "LinkWalletState", "AgentCardWalletState"] @@ -29,5 +30,5 @@ class AgentCardWalletState(BaseModel): WalletVaultItemState: TypeAlias = Annotated[ - Union[LinkWalletState, AgentCardWalletState], PropertyInfo(discriminator="provider") + Union[LinkWalletState, AgentCardWalletState, KernelWalletState], PropertyInfo(discriminator="provider") ] From 8415f29726a11e2436e4a45ee1c02955abe6352b Mon Sep 17 00:00:00 2001 From: "kernel-internal[bot]" <260533166+kernel-internal[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 20:00:08 +0000 Subject: [PATCH 3/3] release: 0.118.0 --- .release-please-manifest.json | 2 +- CHANGELOG.md | 8 ++++++++ pyproject.toml | 2 +- src/kernel/_version.py | 2 +- 4 files changed, 11 insertions(+), 3 deletions(-) diff --git a/.release-please-manifest.json b/.release-please-manifest.json index b6700282..617f7502 100644 --- a/.release-please-manifest.json +++ b/.release-please-manifest.json @@ -1,3 +1,3 @@ { - ".": "0.117.0" + ".": "0.118.0" } \ No newline at end of file diff --git a/CHANGELOG.md b/CHANGELOG.md index 378dbceb..003737b4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,13 @@ # Changelog +## [0.118.0](https://github.com/kernel/kernel-python-sdk/compare/v0.117.0...v0.118.0) (2026-10-02) + + +### Features + +* Add a query filter to the vault list endpoint ([eaa17a1](https://github.com/kernel/kernel-python-sdk/commit/eaa17a1e7068bb70abe9f07f4bba1c818ddeeba1)) +* Add Kernel wallets backed by VGS agentic network tokens, with hosted card capture ([04d839e](https://github.com/kernel/kernel-python-sdk/commit/04d839e6bb948049d3683380efeaae5a3732c959)) + ## [0.117.0](https://github.com/kernel/kernel-python-sdk/compare/v0.116.0...v0.117.0) (2026-10-02) diff --git a/pyproject.toml b/pyproject.toml index e9124bb2..6cee807d 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -1,6 +1,6 @@ [project] name = "kernel" -version = "0.117.0" +version = "0.118.0" description = "The official Python library for the kernel API" dynamic = ["readme"] license = "Apache-2.0" diff --git a/src/kernel/_version.py b/src/kernel/_version.py index f9d870e7..e2ba1a1e 100644 --- a/src/kernel/_version.py +++ b/src/kernel/_version.py @@ -1,4 +1,4 @@ # File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details. __title__ = "kernel" -__version__ = "0.117.0" # x-release-please-version +__version__ = "0.118.0" # x-release-please-version