Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .release-please-manifest.json
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
{
".": "0.117.0"
".": "0.118.0"
}
8 changes: 8 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,13 @@
# Changelog

## [0.118.0](https://github.com/kernel/kernel-python-sdk/compare/v0.117.0...v0.118.0) (2026-10-02)


### Features

* Add a query filter to the vault list endpoint ([eaa17a1](https://github.com/kernel/kernel-python-sdk/commit/eaa17a1e7068bb70abe9f07f4bba1c818ddeeba1))
* Add Kernel wallets backed by VGS agentic network tokens, with hosted card capture ([04d839e](https://github.com/kernel/kernel-python-sdk/commit/04d839e6bb948049d3683380efeaae5a3732c959))

## [0.117.0](https://github.com/kernel/kernel-python-sdk/compare/v0.116.0...v0.117.0) (2026-10-02)


Expand Down
4 changes: 4 additions & 0 deletions api.md
Original file line number Diff line number Diff line change
Expand Up @@ -572,9 +572,13 @@ from kernel.types.vaults import (
CredentialVaultItemUpdateRequest,
FillVaultItemOperationRequest,
FillVaultItemOperationResult,
KernelCardState,
KernelCardVaultItemSpec,
KernelCredentialVaultItemSpec,
KernelCredentialVaultItemSpecInput,
KernelCredentialVaultItemState,
KernelWalletState,
KernelWalletVaultItemSpec,
OnePasswordCredentialAccountSpec,
OnePasswordCredentialAccountState,
OnePasswordCredentialVaultItemSpec,
Expand Down
2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[project]
name = "kernel"
version = "0.117.0"
version = "0.118.0"
description = "The official Python library for the kernel API"
dynamic = ["readme"]
license = "Apache-2.0"
Expand Down
2 changes: 1 addition & 1 deletion src/kernel/_version.py
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details.

__title__ = "kernel"
__version__ = "0.117.0" # x-release-please-version
__version__ = "0.118.0" # x-release-please-version
22 changes: 14 additions & 8 deletions src/kernel/resources/vaults/items.py
Original file line number Diff line number Diff line change
Expand Up @@ -309,10 +309,13 @@ def delete(
) -> None:
"""
Unresolved payment operations normally block deletion, including operations on
child cards of a wallet. An AgentCard card in recovery_required whose checkout
create response returned no authorization ID may be explicitly abandoned by
deleting that card directly; deleting its wallet or vault remains blocked.
Deleting or recreating an item is not proof that a payment did not occur.
child cards of a wallet. Deleting a connected Kernel wallet first blocks new
payments on it, then removes its enrolled card. If that fails, the wallet is
kept and keeps refusing payments; retry the deletion. An AgentCard card in
recovery_required whose checkout create response returned no authorization ID
may be explicitly abandoned by deleting that card directly; deleting its wallet
or vault remains blocked. Deleting or recreating an item is not proof that a
payment did not occur.

Args:
extra_headers: Send extra headers
Expand Down Expand Up @@ -1483,10 +1486,13 @@ async def delete(
) -> None:
"""
Unresolved payment operations normally block deletion, including operations on
child cards of a wallet. An AgentCard card in recovery_required whose checkout
create response returned no authorization ID may be explicitly abandoned by
deleting that card directly; deleting its wallet or vault remains blocked.
Deleting or recreating an item is not proof that a payment did not occur.
child cards of a wallet. Deleting a connected Kernel wallet first blocks new
payments on it, then removes its enrolled card. If that fails, the wallet is
kept and keeps refusing payments; retry the deletion. An AgentCard card in
recovery_required whose checkout create response returned no authorization ID
may be explicitly abandoned by deleting that card directly; deleting its wallet
or vault remains blocked. Deleting or recreating an item is not proof that a
payment did not occur.

Args:
extra_headers: Send extra headers
Expand Down
24 changes: 18 additions & 6 deletions src/kernel/resources/vaults/vaults.py
Original file line number Diff line number Diff line change
Expand Up @@ -92,6 +92,7 @@ def list(
*,
limit: int | Omit = omit,
offset: int | Omit = omit,
query: str | Omit = omit,
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
# The extra values given here take precedence over values defined on the client or passed to this method.
extra_headers: Headers | None = None,
Expand All @@ -103,6 +104,8 @@ def list(
List vaults in the current project

Args:
query: Case-insensitive substring match against vault name. IDs match by exact value.

extra_headers: Send extra headers

extra_query: Add additional query parameters to the request
Expand All @@ -123,6 +126,7 @@ def list(
{
"limit": limit,
"offset": offset,
"query": query,
},
vault_list_params.VaultListParams,
),
Expand All @@ -143,9 +147,11 @@ def delete(
) -> None:
"""Unresolved payment operations block deletion.

Reconcile the original attempt
with the provider or support first; deleting or recreating an item is not proof
that a payment did not occur.
Deleting a connected Kernel wallet
first blocks new payments on it, then removes its enrolled card. If that fails,
the wallet is kept and keeps refusing payments; retry the deletion. Reconcile
the original attempt with the provider or support first; deleting or recreating
an item is not proof that a payment did not occur.

Args:
extra_headers: Send extra headers
Expand Down Expand Up @@ -266,6 +272,7 @@ def list(
*,
limit: int | Omit = omit,
offset: int | Omit = omit,
query: str | Omit = omit,
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
# The extra values given here take precedence over values defined on the client or passed to this method.
extra_headers: Headers | None = None,
Expand All @@ -277,6 +284,8 @@ def list(
List vaults in the current project

Args:
query: Case-insensitive substring match against vault name. IDs match by exact value.

extra_headers: Send extra headers

extra_query: Add additional query parameters to the request
Expand All @@ -297,6 +306,7 @@ def list(
{
"limit": limit,
"offset": offset,
"query": query,
},
vault_list_params.VaultListParams,
),
Expand All @@ -317,9 +327,11 @@ async def delete(
) -> None:
"""Unresolved payment operations block deletion.

Reconcile the original attempt
with the provider or support first; deleting or recreating an item is not proof
that a payment did not occur.
Deleting a connected Kernel wallet
first blocks new payments on it, then removes its enrolled card. If that fails,
the wallet is kept and keeps refusing payments; retry the deletion. Reconcile
the original attempt with the provider or support first; deleting or recreating
an item is not proof that a payment did not occur.

Args:
extra_headers: Send extra headers
Expand Down
3 changes: 3 additions & 0 deletions src/kernel/types/vault_list_params.py
Original file line number Diff line number Diff line change
Expand Up @@ -11,3 +11,6 @@ class VaultListParams(TypedDict, total=False):
limit: int

offset: int

query: str
"""Case-insensitive substring match against vault name. IDs match by exact value."""
6 changes: 6 additions & 0 deletions src/kernel/types/vaults/__init__.py
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,14 @@

from .vault_item import VaultItem as VaultItem
from .vault_item_event import VaultItemEvent as VaultItemEvent
from .kernel_card_state import KernelCardState as KernelCardState
from .vault_item_action import VaultItemAction as VaultItemAction
from .item_events_params import ItemEventsParams as ItemEventsParams
from .item_list_response import ItemListResponse as ItemListResponse
from .item_update_params import ItemUpdateParams as ItemUpdateParams
from .item_upsert_params import ItemUpsertParams as ItemUpsertParams
from .vault_card_aliases import VaultCardAliases as VaultCardAliases
from .kernel_wallet_state import KernelWalletState as KernelWalletState
from .card_vault_item_spec import CardVaultItemSpec as CardVaultItemSpec
from .item_events_response import ItemEventsResponse as ItemEventsResponse
from .item_retrieve_params import ItemRetrieveParams as ItemRetrieveParams
Expand All @@ -26,22 +28,26 @@
from .vault_webmcp_binding_param import VaultWebmcpBindingParam as VaultWebmcpBindingParam
from .credential_vault_field_type import CredentialVaultFieldType as CredentialVaultFieldType
from .credential_vault_item_state import CredentialVaultItemState as CredentialVaultItemState
from .kernel_card_vault_item_spec import KernelCardVaultItemSpec as KernelCardVaultItemSpec
from .agentcard_prepared_processor import AgentcardPreparedProcessor as AgentcardPreparedProcessor
from .credential_collection_action import CredentialCollectionAction as CredentialCollectionAction
from .credential_vault_field_state import CredentialVaultFieldState as CredentialVaultFieldState
from .vault_checkout_context_param import VaultCheckoutContextParam as VaultCheckoutContextParam
from .credential_account_vault_item import CredentialAccountVaultItem as CredentialAccountVaultItem
from .item_perform_operation_params import ItemPerformOperationParams as ItemPerformOperationParams
from .kernel_wallet_vault_item_spec import KernelWalletVaultItemSpec as KernelWalletVaultItemSpec
from .vault_item_operation_response import VaultItemOperationResponse as VaultItemOperationResponse
from .agentcard_checkout_preparation import AgentcardCheckoutPreparation as AgentcardCheckoutPreparation
from .agentcard_checkout_authorization import AgentcardCheckoutAuthorization as AgentcardCheckoutAuthorization
from .fill_vault_item_operation_result import FillVaultItemOperationResult as FillVaultItemOperationResult
from .credential_vault_field_definition import CredentialVaultFieldDefinition as CredentialVaultFieldDefinition
from .kernel_card_vault_item_spec_param import KernelCardVaultItemSpecParam as KernelCardVaultItemSpecParam
from .kernel_credential_vault_item_spec import KernelCredentialVaultItemSpec as KernelCredentialVaultItemSpec
from .credential_vault_field_input_param import CredentialVaultFieldInputParam as CredentialVaultFieldInputParam
from .kernel_credential_vault_item_state import KernelCredentialVaultItemState as KernelCredentialVaultItemState
from .credential_vault_field_update_param import CredentialVaultFieldUpdateParam as CredentialVaultFieldUpdateParam
from .credential_vault_item_request_param import CredentialVaultItemRequestParam as CredentialVaultItemRequestParam
from .kernel_wallet_vault_item_spec_param import KernelWalletVaultItemSpecParam as KernelWalletVaultItemSpecParam
from .one_password_credential_account_spec import OnePasswordCredentialAccountSpec as OnePasswordCredentialAccountSpec
from .one_password_credential_account_state import (
OnePasswordCredentialAccountState as OnePasswordCredentialAccountState,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@


class AuthorizeVaultItemOperationRequestParam(TypedDict, total=False):
"""Authorize a Link card using its existing purchase specification.
"""Authorize a Link or Kernel card using its existing purchase specification.

Use only after explicit user approval and when the item advertises authorize. Do not automatically retry provider failures or indeterminate outcomes. Checkout context is not accepted.
"""
Expand Down
4 changes: 3 additions & 1 deletion src/kernel/types/vaults/card_vault_item_spec.py
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@

from ..._utils import PropertyInfo
from ..._models import BaseModel
from .kernel_card_vault_item_spec import KernelCardVaultItemSpec

__all__ = [
"CardVaultItemSpec",
Expand Down Expand Up @@ -133,5 +134,6 @@ class AgentCardCardVaultItemSpec(BaseModel):


CardVaultItemSpec: TypeAlias = Annotated[
Union[LinkCardVaultItemSpec, AgentCardCardVaultItemSpec], PropertyInfo(discriminator="provider")
Union[LinkCardVaultItemSpec, AgentCardCardVaultItemSpec, KernelCardVaultItemSpec],
PropertyInfo(discriminator="provider"),
]
6 changes: 5 additions & 1 deletion src/kernel/types/vaults/card_vault_item_spec_param.py
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@
from typing import Dict, Union, Iterable
from typing_extensions import Literal, Required, TypeAlias, TypedDict

from .kernel_card_vault_item_spec_param import KernelCardVaultItemSpecParam

__all__ = [
"CardVaultItemSpecParam",
"LinkCardVaultItemSpec",
Expand Down Expand Up @@ -131,4 +133,6 @@ class AgentCardCardVaultItemSpec(TypedDict, total=False):
"""


CardVaultItemSpecParam: TypeAlias = Union[LinkCardVaultItemSpec, AgentCardCardVaultItemSpec]
CardVaultItemSpecParam: TypeAlias = Union[
LinkCardVaultItemSpec, AgentCardCardVaultItemSpec, KernelCardVaultItemSpecParam
]
9 changes: 8 additions & 1 deletion src/kernel/types/vaults/card_vault_item_state.py
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@

from ..._utils import PropertyInfo
from ..._models import BaseModel
from .kernel_card_state import KernelCardState
from .vault_card_aliases import VaultCardAliases
from .agentcard_checkout_preparation import AgentcardCheckoutPreparation
from .agentcard_checkout_authorization import AgentcardCheckoutAuthorization
Expand All @@ -19,6 +20,9 @@ class LinkCardStateMasks(BaseModel):

last4: Optional[str] = None

token_last4: Optional[str] = None
"""Last four digits of the network token presented to the merchant."""

if TYPE_CHECKING:
# Some versions of Pydantic <2.8.0 have a bug and don’t allow assigning a
# value to this field, so for compatibility we avoid doing it at runtime.
Expand Down Expand Up @@ -64,6 +68,9 @@ class AgentCardCardStateMasks(BaseModel):

last4: Optional[str] = None

token_last4: Optional[str] = None
"""Last four digits of the network token presented to the merchant."""

if TYPE_CHECKING:
# Some versions of Pydantic <2.8.0 have a bug and don’t allow assigning a
# value to this field, so for compatibility we avoid doing it at runtime.
Expand Down Expand Up @@ -127,5 +134,5 @@ class AgentCardCardState(BaseModel):


CardVaultItemState: TypeAlias = Annotated[
Union[LinkCardState, AgentCardCardState], PropertyInfo(discriminator="provider")
Union[LinkCardState, AgentCardCardState, KernelCardState], PropertyInfo(discriminator="provider")
]
Original file line number Diff line number Diff line change
Expand Up @@ -12,8 +12,8 @@

class FillVaultItemOperationRequestParam(TypedDict, total=False):
"""
Fill selected fields from one ready credential or ready, unexpired Link card
into a browser linked to its vault.
Fill selected fields from one ready credential or ready, unexpired Link or
Kernel card into a browser linked to its vault.
Only invoke when the item advertises `fill`. Browser and vault must belong
to the same project. Kernel checks access and allowed destinations before
filling; providing a page URL does not authorize a destination.
Expand All @@ -34,7 +34,7 @@ class FillVaultItemOperationRequestParam(TypedDict, total=False):
Fill in request order and stop on the first failure. This operation is
not atomic: previously filled fields are not rolled back. Never submit
the form or click buttons, though input/change events may trigger site
behavior. Link cards use fill for browser checkout and do not expose
behavior. Link and Kernel cards use fill for browser checkout and do not expose
aliases or support egress substitution. Do not automatically retry a
failed or indeterminate operation.

Expand Down
5 changes: 4 additions & 1 deletion src/kernel/types/vaults/item_upsert_params.py
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@
from typing_extensions import Literal, Required, TypeAlias, TypedDict

from .card_vault_item_spec_param import CardVaultItemSpecParam
from .kernel_wallet_vault_item_spec_param import KernelWalletVaultItemSpecParam
from .credential_vault_item_spec_input_param import CredentialVaultItemSpecInputParam
from .one_password_credential_account_spec_param import OnePasswordCredentialAccountSpecParam

Expand Down Expand Up @@ -176,7 +177,9 @@ class WalletVaultItemRequestSpecAgentCardWalletVaultItemSpec(TypedDict, total=Fa


WalletVaultItemRequestSpec: TypeAlias = Union[
WalletVaultItemRequestSpecLinkWalletVaultItemRequestSpec, WalletVaultItemRequestSpecAgentCardWalletVaultItemSpec
WalletVaultItemRequestSpecLinkWalletVaultItemRequestSpec,
WalletVaultItemRequestSpecAgentCardWalletVaultItemSpec,
KernelWalletVaultItemSpecParam,
]


Expand Down
60 changes: 60 additions & 0 deletions src/kernel/types/vaults/kernel_card_state.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
# File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details.

from typing import TYPE_CHECKING, Dict, List, Optional
from typing_extensions import Literal

from pydantic import Field as FieldInfo

from ..._models import BaseModel

__all__ = ["KernelCardState", "Masks"]


class Masks(BaseModel):
brand: Optional[str] = None

last4: Optional[str] = None

token_last4: Optional[str] = None
"""Last four digits of the network token presented to the merchant."""

if TYPE_CHECKING:
# Some versions of Pydantic <2.8.0 have a bug and don’t allow assigning a
# value to this field, so for compatibility we avoid doing it at runtime.
__pydantic_extra__: Dict[str, str] = FieldInfo(init=False) # pyright: ignore[reportIncompatibleVariableOverride]

# Stub to indicate that arbitrary properties are accepted.
# To access properties that are not valid identifiers you can use `getattr`, e.g.
# `getattr(obj, '$type')`
def __getattr__(self, attr: str) -> str: ...
else:
__pydantic_extra__: Dict[str, str]


class KernelCardState(BaseModel):
"""
A ready Kernel card retains its encrypted network token and one-time code for the fill operation until the item's expires_at. Fill and submit checkout before then. Visa cards can be enrolled, but Visa purchases are not yet supported and authorize returns 400; supported Mastercard purchases need no cardholder approval. masks.last4 is the enrolled card's last four digits; masks.token_last4 is the network token's last four digits shown to the merchant. Kernel cards do not expose aliases or support egress substitution. Kernel does not observe whether the merchant charged the card.
"""

provider: Literal["kernel"]

status: Literal[
"requested", "pending_authorization", "ready", "consumed", "expired", "declined", "recovery_required"
]
"""recovery_required means issuing the one-time code has an unresolved outcome.

Kernel never issues another code for the item automatically, and the item cannot
be deleted or replaced until the original attempt is reconciled with support.
When status_reason says the provider refused retrieval before acceptance, no
code was issued and a later read retries.
"""

domains: Optional[List[str]] = None
"""Informational registrable domain.

Fill is locked to merchant_url's exact origin.
"""

masks: Optional[Masks] = None

status_reason: Optional[str] = None
Loading
Loading