Skip to content

Commit f98bcb5

Browse files
authored
Merge pull request #201 from kernel/release-please--branches--main--changes--next--components--sdk
release: 0.119.0
2 parents 0b59fa3 + 55ab06f commit f98bcb5

8 files changed

Lines changed: 146 additions & 16 deletions

File tree

‎.release-please-manifest.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,3 @@
11
{
2-
".": "0.118.0"
2+
".": "0.119.0"
33
}

‎CHANGELOG.md‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,12 @@
11
# Changelog
22

3+
## [0.119.0](https://github.com/kernel/kernel-node-sdk/compare/v0.118.0...v0.119.0) (2026-10-02)
4+
5+
6+
### Features
7+
8+
* Add managed auth provider to vault credential items ([6a23c73](https://github.com/kernel/kernel-node-sdk/commit/6a23c73ccc4716c40fff473e2234194e76a354e0))
9+
310
## [0.118.0](https://github.com/kernel/kernel-node-sdk/compare/v0.117.0...v0.118.0) (2026-10-02)
411

512

‎api.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -520,6 +520,10 @@ Types:
520520
- <code><a href="./src/resources/vaults/items.ts">KernelCredentialVaultItemState</a></code>
521521
- <code><a href="./src/resources/vaults/items.ts">KernelWalletState</a></code>
522522
- <code><a href="./src/resources/vaults/items.ts">KernelWalletVaultItemSpec</a></code>
523+
- <code><a href="./src/resources/vaults/items.ts">ManagedAuthCredentialVaultField</a></code>
524+
- <code><a href="./src/resources/vaults/items.ts">ManagedAuthCredentialVaultItemSpec</a></code>
525+
- <code><a href="./src/resources/vaults/items.ts">ManagedAuthCredentialVaultItemSpecInput</a></code>
526+
- <code><a href="./src/resources/vaults/items.ts">ManagedAuthCredentialVaultItemState</a></code>
523527
- <code><a href="./src/resources/vaults/items.ts">OnePasswordCredentialAccountSpec</a></code>
524528
- <code><a href="./src/resources/vaults/items.ts">OnePasswordCredentialAccountState</a></code>
525529
- <code><a href="./src/resources/vaults/items.ts">OnePasswordCredentialVaultItemSpec</a></code>

‎package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "@onkernel/sdk",
3-
"version": "0.118.0",
3+
"version": "0.119.0",
44
"description": "The official TypeScript library for the Kernel API",
55
"author": "Kernel <>",
66
"types": "dist/index.d.ts",

‎src/resources/vaults/index.ts‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,10 @@ export {
3333
type KernelCredentialVaultItemState,
3434
type KernelWalletState,
3535
type KernelWalletVaultItemSpec,
36+
type ManagedAuthCredentialVaultField,
37+
type ManagedAuthCredentialVaultItemSpec,
38+
type ManagedAuthCredentialVaultItemSpecInput,
39+
type ManagedAuthCredentialVaultItemState,
3640
type OnePasswordCredentialAccountSpec,
3741
type OnePasswordCredentialAccountState,
3842
type OnePasswordCredentialVaultItemSpec,

‎src/resources/vaults/items.ts‎

Lines changed: 120 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -93,7 +93,8 @@ export class Items extends APIResource {
9393
* recovery_required whose checkout create response returned no authorization ID
9494
* may be explicitly abandoned by deleting that card directly; deleting its wallet
9595
* or vault remains blocked. Deleting or recreating an item is not proof that a
96-
* payment did not occur.
96+
* payment did not occur. Deleting a managed auth credential item leaves the
97+
* connection and its saved credential unchanged.
9798
*
9899
* @example
99100
* ```ts
@@ -185,8 +186,8 @@ export class Items extends APIResource {
185186
* ```ts
186187
* const vaultItem = await client.vaults.items.upsert('x', {
187188
* id_or_name: 'id_or_name',
188-
* spec: { provider: 'link' },
189-
* type: 'card',
189+
* spec: { provider: 'managed_auth' },
190+
* type: 'credential',
190191
* });
191192
* ```
192193
*/
@@ -839,7 +840,8 @@ export interface CredentialVaultItem {
839840
* Kernel credentials advertise collect and fill when eligible. 1Password
840841
* credentials advertise 1pw_create_access_request until a request is made,
841842
* 1pw_access_request_status while its approval is pending, and 1pw_fill after
842-
* access is granted.
843+
* access is granted. Managed auth credentials advertise fill while ready and
844+
* nothing otherwise.
843845
*/
844846
available_operations: Array<CredentialVaultItem.AvailableOperation>;
845847

@@ -864,7 +866,8 @@ export interface CredentialVaultItem {
864866

865867
/**
866868
* Starts at 1 and increments on PATCH and successful hosted submission, but not
867-
* collection-link renewal.
869+
* collection-link renewal. Managed auth credentials stay at 1; changes to the
870+
* underlying credential are read at fill time and do not change the version.
868871
*/
869872
version: number;
870873

@@ -956,7 +959,9 @@ export namespace CredentialVaultItem {
956959
* declare fields and may enter pending_collection. 1Password credentials either
957960
* reference a connected credential_account or store a supplied access token and
958961
* integration key encrypted on the item. They store no login values or selectors.
959-
* Repeating the original creation request returns the current item without
962+
* Managed auth credentials reference a managed auth connection in the same project
963+
* that already has a saved credential, and read it at fill time; they store no
964+
* values. Repeating the original creation request returns the current item without
960965
* overwriting later state. A different request at the same key returns 409.
961966
*/
962967
export interface CredentialVaultItemRequest {
@@ -976,7 +981,10 @@ export interface CredentialVaultItemRequest {
976981
* Stored-token credentials omit account and never return access_token or
977982
* integration_key.
978983
*/
979-
export type CredentialVaultItemSpec = KernelCredentialVaultItemSpec | OnePasswordCredentialVaultItemSpec;
984+
export type CredentialVaultItemSpec =
985+
| KernelCredentialVaultItemSpec
986+
| OnePasswordCredentialVaultItemSpec
987+
| ManagedAuthCredentialVaultItemSpec;
980988

981989
/**
982990
* Credential fields are for login and other non-payment credentials. Do not store,
@@ -987,7 +995,8 @@ export type CredentialVaultItemSpec = KernelCredentialVaultItemSpec | OnePasswor
987995
*/
988996
export type CredentialVaultItemSpecInput =
989997
| KernelCredentialVaultItemSpecInput
990-
| OnePasswordCredentialVaultItemSpecInput;
998+
| OnePasswordCredentialVaultItemSpecInput
999+
| ManagedAuthCredentialVaultItemSpecInput;
9911000

9921001
export interface CredentialVaultItemSpecUpdate {
9931002
/**
@@ -1000,7 +1009,10 @@ export interface CredentialVaultItemSpecUpdate {
10001009
fields?: { [key: string]: CredentialVaultFieldUpdate };
10011010
}
10021011

1003-
export type CredentialVaultItemState = KernelCredentialVaultItemState | OnePasswordCredentialVaultItemState;
1012+
export type CredentialVaultItemState =
1013+
| KernelCredentialVaultItemState
1014+
| OnePasswordCredentialVaultItemState
1015+
| ManagedAuthCredentialVaultItemState;
10041016

10051017
/**
10061018
* Atomically update description and selected values. Omitted properties are
@@ -1010,7 +1022,8 @@ export type CredentialVaultItemState = KernelCredentialVaultItemState | OnePassw
10101022
* invalidates outstanding Kernel-hosted collection sessions. If required values
10111023
* remain missing, return pending_collection and a fresh collection action.
10121024
* Otherwise return ready without an action; collect can open the form again
1013-
* without clearing values. Customer URLs have no Kernel-managed expiry.
1025+
* without clearing values. Customer URLs have no Kernel-managed expiry. 1Password
1026+
* and managed auth credentials return 409.
10141027
*/
10151028
export interface CredentialVaultItemUpdateRequest {
10161029
spec: CredentialVaultItemSpecUpdate;
@@ -1283,6 +1296,94 @@ export interface KernelWalletVaultItemSpec {
12831296
provider: 'kernel';
12841297
}
12851298

1299+
export interface ManagedAuthCredentialVaultField {
1300+
/**
1301+
* Text, email, and password have form inputs; totp does not and is omitted from
1302+
* both Kernel-hosted and customer React forms. Password and totp must be
1303+
* sensitive. A totp value is an RFC 4648 Base32 generator seed (case-insensitive,
1304+
* optional trailing padding), not an otpauth URI or current code. Reject invalid
1305+
* or empty decoded seeds. Browser fill generates an RFC 6238 code at execution
1306+
* time using HMAC-SHA1, 6 digits, and a 30-second period. Preserve leading zeros;
1307+
* never fill the seed. Custom algorithms, digits, periods, and form enrollment are
1308+
* unsupported.
1309+
*/
1310+
type: CredentialVaultFieldType;
1311+
}
1312+
1313+
export interface ManagedAuthCredentialVaultItemSpec {
1314+
/**
1315+
* ID of the managed auth connection whose saved credential this item reads. List
1316+
* connections with `GET /auth/connections`.
1317+
*/
1318+
connection_id: string;
1319+
1320+
provider: 'managed_auth';
1321+
1322+
/**
1323+
* Display text supplied when the item was created. Omitted when none was given.
1324+
*/
1325+
description?: string;
1326+
}
1327+
1328+
/**
1329+
* A credential backed by a managed auth connection. The item stores no values: it
1330+
* reads the connection's saved credential at fill time, so updates made through
1331+
* managed auth apply immediately. The connection must be in the vault's project
1332+
* and hold a saved Kernel credential. The check is the saved credential, not
1333+
* connection status: a connection that needs re-authentication qualifies, and an
1334+
* authenticated one without a saved credential does not. Returns 404 for an
1335+
* unknown connection, and 409 when the connection is in another project, has no
1336+
* saved credential yet, or uses an external credential provider such as 1Password.
1337+
* No collection form is offered; managed auth collects the login.
1338+
*/
1339+
export interface ManagedAuthCredentialVaultItemSpecInput {
1340+
/**
1341+
* ID of the managed auth connection whose saved credential this item reads. List
1342+
* connections with `GET /auth/connections`.
1343+
*/
1344+
connection_id: string;
1345+
1346+
provider: 'managed_auth';
1347+
1348+
/**
1349+
* Optional display text for the item, such as the site or service name. Set at
1350+
* creation and cannot be changed later; repeating the request with a different
1351+
* description returns 409. At most 16 KiB in UTF-8 bytes.
1352+
*/
1353+
description?: string;
1354+
}
1355+
1356+
export interface ManagedAuthCredentialVaultItemState {
1357+
provider: 'managed_auth';
1358+
1359+
/**
1360+
* Items are created ready, which means the connection has a saved Kernel
1361+
* credential that stores values or a TOTP seed (what has_values or has_totp_secret
1362+
* report on credentials), not that a login succeeded. Unavailable means it no
1363+
* longer does; such items advertise no operations.
1364+
*/
1365+
status: 'ready' | 'unavailable';
1366+
1367+
/**
1368+
* One entry per non-empty value on the connection's saved credential, keyed by the
1369+
* field name to use in fill bindings. Included on single-item responses (create
1370+
* and get) and omitted from list responses, like `value_keys` on credentials.
1371+
* Empty when unavailable or when every stored value is empty. A stored value named
1372+
* totp_secret is never listed or filled. Values are never returned. A totp entry
1373+
* is present when the credential has a TOTP seed; fill writes a generated code for
1374+
* it. Entries follow the connection's credential.
1375+
*/
1376+
fields?: { [key: string]: ManagedAuthCredentialVaultField };
1377+
1378+
/**
1379+
* Present when status is unavailable. connection_not_found means the connection
1380+
* was deleted. no_credential means the connection's credential was deleted or
1381+
* emptied after the item was created. external_credential means the connection was
1382+
* moved to an external credential provider.
1383+
*/
1384+
status_reason?: 'connection_not_found' | 'no_credential' | 'external_credential';
1385+
}
1386+
12861387
export interface OnePasswordCredentialAccountSpec {
12871388
authorization: OnePasswordCredentialAccountSpec.Authorization;
12881389

@@ -1798,8 +1899,9 @@ export interface VaultCheckoutContext {
17981899

17991900
export interface VaultFillField {
18001901
/**
1801-
* A declared credential field name or a supported card field. Unset credential
1802-
* fields cannot be filled.
1902+
* A credential field name from the item's declared fields (Kernel) or state.fields
1903+
* from a single-item read (managed auth), or a supported card field. Unset
1904+
* credential fields cannot be filled.
18031905
*/
18041906
field: string;
18051907

@@ -2503,7 +2605,8 @@ export interface ItemRetrieveParams {
25032605
* authorization, approval, or credential collection. Return the current item when
25042606
* ready or when the wait elapses. This does not wait for edits to an already-ready
25052607
* credential; poll GET without wait and compare version to observe changes after
2506-
* collect.
2608+
* collect. Managed auth credentials are created ready, so wait returns
2609+
* immediately.
25072610
*/
25082611
wait?: number;
25092612
}
@@ -3112,6 +3215,10 @@ export declare namespace Items {
31123215
type KernelCredentialVaultItemState as KernelCredentialVaultItemState,
31133216
type KernelWalletState as KernelWalletState,
31143217
type KernelWalletVaultItemSpec as KernelWalletVaultItemSpec,
3218+
type ManagedAuthCredentialVaultField as ManagedAuthCredentialVaultField,
3219+
type ManagedAuthCredentialVaultItemSpec as ManagedAuthCredentialVaultItemSpec,
3220+
type ManagedAuthCredentialVaultItemSpecInput as ManagedAuthCredentialVaultItemSpecInput,
3221+
type ManagedAuthCredentialVaultItemState as ManagedAuthCredentialVaultItemState,
31153222
type OnePasswordCredentialAccountSpec as OnePasswordCredentialAccountSpec,
31163223
type OnePasswordCredentialAccountState as OnePasswordCredentialAccountState,
31173224
type OnePasswordCredentialVaultItemSpec as OnePasswordCredentialVaultItemSpec,

‎src/resources/vaults/vaults.ts‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,10 @@ import {
4343
KernelCredentialVaultItemState,
4444
KernelWalletState,
4545
KernelWalletVaultItemSpec,
46+
ManagedAuthCredentialVaultField,
47+
ManagedAuthCredentialVaultItemSpec,
48+
ManagedAuthCredentialVaultItemSpecInput,
49+
ManagedAuthCredentialVaultItemState,
4650
OnePasswordCredentialAccountSpec,
4751
OnePasswordCredentialAccountState,
4852
OnePasswordCredentialVaultItemSpec,
@@ -217,6 +221,10 @@ export declare namespace Vaults {
217221
type KernelCredentialVaultItemState as KernelCredentialVaultItemState,
218222
type KernelWalletState as KernelWalletState,
219223
type KernelWalletVaultItemSpec as KernelWalletVaultItemSpec,
224+
type ManagedAuthCredentialVaultField as ManagedAuthCredentialVaultField,
225+
type ManagedAuthCredentialVaultItemSpec as ManagedAuthCredentialVaultItemSpec,
226+
type ManagedAuthCredentialVaultItemSpecInput as ManagedAuthCredentialVaultItemSpecInput,
227+
type ManagedAuthCredentialVaultItemState as ManagedAuthCredentialVaultItemState,
220228
type OnePasswordCredentialAccountSpec as OnePasswordCredentialAccountSpec,
221229
type OnePasswordCredentialAccountState as OnePasswordCredentialAccountState,
222230
type OnePasswordCredentialVaultItemSpec as OnePasswordCredentialVaultItemSpec,

‎src/version.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
export const VERSION = '0.118.0'; // x-release-please-version
1+
export const VERSION = '0.119.0'; // x-release-please-version

0 commit comments

Comments
 (0)