@@ -93,7 +93,8 @@ export class Items extends APIResource {
9393 * recovery_required whose checkout create response returned no authorization ID
9494 * may be explicitly abandoned by deleting that card directly; deleting its wallet
9595 * or vault remains blocked. Deleting or recreating an item is not proof that a
96- * payment did not occur.
96+ * payment did not occur. Deleting a managed auth credential item leaves the
97+ * connection and its saved credential unchanged.
9798 *
9899 * @example
99100 * ```ts
@@ -185,8 +186,8 @@ export class Items extends APIResource {
185186 * ```ts
186187 * const vaultItem = await client.vaults.items.upsert('x', {
187188 * id_or_name: 'id_or_name',
188- * spec: { provider: 'link ' },
189- * type: 'card ',
189+ * spec: { provider: 'managed_auth ' },
190+ * type: 'credential ',
190191 * });
191192 * ```
192193 */
@@ -839,7 +840,8 @@ export interface CredentialVaultItem {
839840 * Kernel credentials advertise collect and fill when eligible. 1Password
840841 * credentials advertise 1pw_create_access_request until a request is made,
841842 * 1pw_access_request_status while its approval is pending, and 1pw_fill after
842- * access is granted.
843+ * access is granted. Managed auth credentials advertise fill while ready and
844+ * nothing otherwise.
843845 */
844846 available_operations : Array < CredentialVaultItem . AvailableOperation > ;
845847
@@ -864,7 +866,8 @@ export interface CredentialVaultItem {
864866
865867 /**
866868 * Starts at 1 and increments on PATCH and successful hosted submission, but not
867- * collection-link renewal.
869+ * collection-link renewal. Managed auth credentials stay at 1; changes to the
870+ * underlying credential are read at fill time and do not change the version.
868871 */
869872 version : number ;
870873
@@ -956,7 +959,9 @@ export namespace CredentialVaultItem {
956959 * declare fields and may enter pending_collection. 1Password credentials either
957960 * reference a connected credential_account or store a supplied access token and
958961 * integration key encrypted on the item. They store no login values or selectors.
959- * Repeating the original creation request returns the current item without
962+ * Managed auth credentials reference a managed auth connection in the same project
963+ * that already has a saved credential, and read it at fill time; they store no
964+ * values. Repeating the original creation request returns the current item without
960965 * overwriting later state. A different request at the same key returns 409.
961966 */
962967export interface CredentialVaultItemRequest {
@@ -976,7 +981,10 @@ export interface CredentialVaultItemRequest {
976981 * Stored-token credentials omit account and never return access_token or
977982 * integration_key.
978983 */
979- export type CredentialVaultItemSpec = KernelCredentialVaultItemSpec | OnePasswordCredentialVaultItemSpec ;
984+ export type CredentialVaultItemSpec =
985+ | KernelCredentialVaultItemSpec
986+ | OnePasswordCredentialVaultItemSpec
987+ | ManagedAuthCredentialVaultItemSpec ;
980988
981989/**
982990 * Credential fields are for login and other non-payment credentials. Do not store,
@@ -987,7 +995,8 @@ export type CredentialVaultItemSpec = KernelCredentialVaultItemSpec | OnePasswor
987995 */
988996export type CredentialVaultItemSpecInput =
989997 | KernelCredentialVaultItemSpecInput
990- | OnePasswordCredentialVaultItemSpecInput ;
998+ | OnePasswordCredentialVaultItemSpecInput
999+ | ManagedAuthCredentialVaultItemSpecInput ;
9911000
9921001export interface CredentialVaultItemSpecUpdate {
9931002 /**
@@ -1000,7 +1009,10 @@ export interface CredentialVaultItemSpecUpdate {
10001009 fields ?: { [ key : string ] : CredentialVaultFieldUpdate } ;
10011010}
10021011
1003- export type CredentialVaultItemState = KernelCredentialVaultItemState | OnePasswordCredentialVaultItemState ;
1012+ export type CredentialVaultItemState =
1013+ | KernelCredentialVaultItemState
1014+ | OnePasswordCredentialVaultItemState
1015+ | ManagedAuthCredentialVaultItemState ;
10041016
10051017/**
10061018 * Atomically update description and selected values. Omitted properties are
@@ -1010,7 +1022,8 @@ export type CredentialVaultItemState = KernelCredentialVaultItemState | OnePassw
10101022 * invalidates outstanding Kernel-hosted collection sessions. If required values
10111023 * remain missing, return pending_collection and a fresh collection action.
10121024 * Otherwise return ready without an action; collect can open the form again
1013- * without clearing values. Customer URLs have no Kernel-managed expiry.
1025+ * without clearing values. Customer URLs have no Kernel-managed expiry. 1Password
1026+ * and managed auth credentials return 409.
10141027 */
10151028export interface CredentialVaultItemUpdateRequest {
10161029 spec : CredentialVaultItemSpecUpdate ;
@@ -1283,6 +1296,94 @@ export interface KernelWalletVaultItemSpec {
12831296 provider : 'kernel' ;
12841297}
12851298
1299+ export interface ManagedAuthCredentialVaultField {
1300+ /**
1301+ * Text, email, and password have form inputs; totp does not and is omitted from
1302+ * both Kernel-hosted and customer React forms. Password and totp must be
1303+ * sensitive. A totp value is an RFC 4648 Base32 generator seed (case-insensitive,
1304+ * optional trailing padding), not an otpauth URI or current code. Reject invalid
1305+ * or empty decoded seeds. Browser fill generates an RFC 6238 code at execution
1306+ * time using HMAC-SHA1, 6 digits, and a 30-second period. Preserve leading zeros;
1307+ * never fill the seed. Custom algorithms, digits, periods, and form enrollment are
1308+ * unsupported.
1309+ */
1310+ type : CredentialVaultFieldType ;
1311+ }
1312+
1313+ export interface ManagedAuthCredentialVaultItemSpec {
1314+ /**
1315+ * ID of the managed auth connection whose saved credential this item reads. List
1316+ * connections with `GET /auth/connections`.
1317+ */
1318+ connection_id : string ;
1319+
1320+ provider : 'managed_auth' ;
1321+
1322+ /**
1323+ * Display text supplied when the item was created. Omitted when none was given.
1324+ */
1325+ description ?: string ;
1326+ }
1327+
1328+ /**
1329+ * A credential backed by a managed auth connection. The item stores no values: it
1330+ * reads the connection's saved credential at fill time, so updates made through
1331+ * managed auth apply immediately. The connection must be in the vault's project
1332+ * and hold a saved Kernel credential. The check is the saved credential, not
1333+ * connection status: a connection that needs re-authentication qualifies, and an
1334+ * authenticated one without a saved credential does not. Returns 404 for an
1335+ * unknown connection, and 409 when the connection is in another project, has no
1336+ * saved credential yet, or uses an external credential provider such as 1Password.
1337+ * No collection form is offered; managed auth collects the login.
1338+ */
1339+ export interface ManagedAuthCredentialVaultItemSpecInput {
1340+ /**
1341+ * ID of the managed auth connection whose saved credential this item reads. List
1342+ * connections with `GET /auth/connections`.
1343+ */
1344+ connection_id : string ;
1345+
1346+ provider : 'managed_auth' ;
1347+
1348+ /**
1349+ * Optional display text for the item, such as the site or service name. Set at
1350+ * creation and cannot be changed later; repeating the request with a different
1351+ * description returns 409. At most 16 KiB in UTF-8 bytes.
1352+ */
1353+ description ?: string ;
1354+ }
1355+
1356+ export interface ManagedAuthCredentialVaultItemState {
1357+ provider : 'managed_auth' ;
1358+
1359+ /**
1360+ * Items are created ready, which means the connection has a saved Kernel
1361+ * credential that stores values or a TOTP seed (what has_values or has_totp_secret
1362+ * report on credentials), not that a login succeeded. Unavailable means it no
1363+ * longer does; such items advertise no operations.
1364+ */
1365+ status : 'ready' | 'unavailable' ;
1366+
1367+ /**
1368+ * One entry per non-empty value on the connection's saved credential, keyed by the
1369+ * field name to use in fill bindings. Included on single-item responses (create
1370+ * and get) and omitted from list responses, like `value_keys` on credentials.
1371+ * Empty when unavailable or when every stored value is empty. A stored value named
1372+ * totp_secret is never listed or filled. Values are never returned. A totp entry
1373+ * is present when the credential has a TOTP seed; fill writes a generated code for
1374+ * it. Entries follow the connection's credential.
1375+ */
1376+ fields ?: { [ key : string ] : ManagedAuthCredentialVaultField } ;
1377+
1378+ /**
1379+ * Present when status is unavailable. connection_not_found means the connection
1380+ * was deleted. no_credential means the connection's credential was deleted or
1381+ * emptied after the item was created. external_credential means the connection was
1382+ * moved to an external credential provider.
1383+ */
1384+ status_reason ?: 'connection_not_found' | 'no_credential' | 'external_credential' ;
1385+ }
1386+
12861387export interface OnePasswordCredentialAccountSpec {
12871388 authorization : OnePasswordCredentialAccountSpec . Authorization ;
12881389
@@ -1798,8 +1899,9 @@ export interface VaultCheckoutContext {
17981899
17991900export interface VaultFillField {
18001901 /**
1801- * A declared credential field name or a supported card field. Unset credential
1802- * fields cannot be filled.
1902+ * A credential field name from the item's declared fields (Kernel) or state.fields
1903+ * from a single-item read (managed auth), or a supported card field. Unset
1904+ * credential fields cannot be filled.
18031905 */
18041906 field : string ;
18051907
@@ -2503,7 +2605,8 @@ export interface ItemRetrieveParams {
25032605 * authorization, approval, or credential collection. Return the current item when
25042606 * ready or when the wait elapses. This does not wait for edits to an already-ready
25052607 * credential; poll GET without wait and compare version to observe changes after
2506- * collect.
2608+ * collect. Managed auth credentials are created ready, so wait returns
2609+ * immediately.
25072610 */
25082611 wait ?: number ;
25092612}
@@ -3112,6 +3215,10 @@ export declare namespace Items {
31123215 type KernelCredentialVaultItemState as KernelCredentialVaultItemState ,
31133216 type KernelWalletState as KernelWalletState ,
31143217 type KernelWalletVaultItemSpec as KernelWalletVaultItemSpec ,
3218+ type ManagedAuthCredentialVaultField as ManagedAuthCredentialVaultField ,
3219+ type ManagedAuthCredentialVaultItemSpec as ManagedAuthCredentialVaultItemSpec ,
3220+ type ManagedAuthCredentialVaultItemSpecInput as ManagedAuthCredentialVaultItemSpecInput ,
3221+ type ManagedAuthCredentialVaultItemState as ManagedAuthCredentialVaultItemState ,
31153222 type OnePasswordCredentialAccountSpec as OnePasswordCredentialAccountSpec ,
31163223 type OnePasswordCredentialAccountState as OnePasswordCredentialAccountState ,
31173224 type OnePasswordCredentialVaultItemSpec as OnePasswordCredentialVaultItemSpec ,
0 commit comments