You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit e042607
Browse filesBrowse the repository at this point in the historyBrowse files
-`--project <project-id>` - Scope requests to a project ID (or set `KERNEL_PROJECT` to a project ID). Project-scoped OAuth tokens cannot switch projects.
106
+
-`--project <id-or-name>` - Scope requests to a project by ID or exact name (or set `KERNEL_PROJECT`). Project-scoped OAuth tokens cannot switch projects.
107
107
108
108
## JSON Output
109
109
@@ -210,25 +210,28 @@ Commands with JSON output support:
210
210
211
211
-`kernel browsers list` - List running browsers
212
212
-`--query <q>` - Search by name, session ID, profile ID, proxy ID, or pool name
213
-
-`--region <region>` - Filter sessions by region (us-east or eu-west); omit to list sessions in all regions
213
+
-`--region us-east|eu-west` - Filter by geographic region; omit to list sessions in all regions
214
214
-`--tag <KEY=VALUE>` - Filter by tag, repeatable; a session must match every pair
215
215
-`--output json`, `-o json` - Output raw JSON array
216
216
-`kernel browsers create` - Create a new browser session
217
217
-`-s, --stealth` - Launch browser in stealth mode to avoid detection
218
218
-`-H, --headless` - Launch browser without GUI access
219
219
-`--kiosk` - Launch browser in kiosk mode
220
-
-`--region <region>` - Region for the session (us-east or eu-west); fixed once created, defaults to us-east. Requires a Start-Up or Enterprise plan.
220
+
-`--region us-east|eu-west` - Geographic region for the session. Fixed once the session is created; requires a Start-Up or Enterprise plan and defaults to `us-east`.
221
+
-`--private-host <host>` - Destination the browser reaches directly through the session's own network instead of Kernel-managed egress, for private hosts on a VPN or tunnel the session joins (repeatable or comma-separated, max 32). Accepts hostname patterns (`*.example.ts.net`), IPs (`10.1.30.63`, `[fd00::1]`), and private CIDRs (`100.64.0.0/10`). Replaces the default private ranges (RFC1918, `100.64.0.0/10`, `fc00::/7`); omit to keep them. Fixed once the session is created. Unrelated to a proxy's `--bypass-host`, which only chooses between upstream proxy and Kernel-managed direct egress.
221
222
-`--start-url <url>` - Initial page to open on launch
223
+
-`--proxy-id <id>` / `--proxy-name <name>` - Use that proxy for the session regardless of stealth (mutually exclusive with each other and with `--proxy-mode`)
224
+
-`--proxy-mode direct|default` - Egress mode instead of a selected proxy: `direct` for no proxy regardless of stealth, `default` for the stealth-derived default (Kernel's stealth proxy with `--stealth`, direct egress otherwise). Omit all proxy flags to get the default.
222
225
-`--name <name>` - Optional unique name for the session (used to find it later by name; can be changed with `browsers update --name`)
223
226
-`--tag <KEY=VALUE>` - Set a tag on the session, repeatable; up to 50 pairs
224
227
-`--pool-id <id>` - Acquire a browser from the specified pool (mutually exclusive with --pool-name; ignores other session flags). `--name`/`--tag` still apply to the acquired session.
225
228
-`--pool-name <name>` - Acquire a browser from the pool name (mutually exclusive with --pool-id; ignores other session flags)
226
229
-`--telemetry=all` - Enable telemetry for all categories
227
230
-`--telemetry=off` - Disable telemetry
228
231
-`--telemetry=<list>` - Per-category config, e.g. `--telemetry=network=on,page=off`
232
+
-`--telemetry-export-otlp <id-or-name>` - Export captured telemetry over OTLP to one of the org's configured destinations. Implies `--telemetry=all` when `--telemetry` is not set, since export requires capture. Use `--telemetry-export-otlp=off` to disable export.
229
233
-`--chrome-policy <json>` - Custom Chrome enterprise policy as a JSON object. Kernel-managed policies (extensions, proxy, automation) are rejected server-side.
230
234
-`--chrome-policy-file <path>` - Read the Chrome enterprise policy from a file (use `-` for stdin). Mutually exclusive with `--chrome-policy`.
231
-
-`--private-host <host>` - Route a private hostname, IP, or CIDR through the session network instead of Kernel-managed egress. Repeatable or comma-separated; replaces the default private IP ranges.
232
235
-`--output json`, `-o json` - Output raw JSON object
233
236
-_Note: When a pool is specified, omit other session configuration flags—pool settings determine profile, proxy, viewport, etc._
234
237
-`kernel browsers delete <id-or-name>` - Delete a browser by ID or name
@@ -244,7 +247,10 @@ Commands with JSON output support:
244
247
-`--telemetry=all` - Enable telemetry for all categories
245
248
-`--telemetry=off` - Disable telemetry
246
249
-`--telemetry=<list>` - Per-category config, e.g. `--telemetry=network=on,page=off`
247
-
-`--disable-default-proxy` - Disable the default stealth proxy so the browser connects directly; use `--disable-default-proxy=false` to re-enable it
250
+
-`--proxy-id <id>` / `--proxy-name <name>` - Switch the session to that proxy regardless of stealth (mutually exclusive with each other and with `--proxy-mode`)
251
+
-`--proxy-mode direct|default` - Change egress mode: `direct` for no proxy regardless of stealth, `default` to restore the browser default after using a selected proxy. Changing the proxy does not change stealth or CAPTCHA solver behavior.
252
+
-`--clear-proxy` - Drop the selected proxy and restore the browser default (same as `--proxy-mode=default`)
253
+
-`--disable-default-proxy` - Connect directly instead of through the default stealth proxy (same as `--proxy-mode=direct`); use `--disable-default-proxy=false` to restore the default
248
254
-`--output json`, `-o json` - Output raw JSON object
249
255
-`kernel browsers curl <id> <url>` - Make HTTP requests through a browser session's Chrome network stack
250
256
-`-X, --request <method>` - HTTP method (default: GET; defaults to POST when `--data` is set)
@@ -264,7 +270,7 @@ Commands with JSON output support:
264
270
### Browser Pools
265
271
266
272
-`kernel browser-pools list` - List browser pools
267
-
-`--region <region>` - Filter pools by region (us-east or eu-west); omit to list pools in all regions
273
+
-`--region us-east|eu-west` - Filter by geographic region; omit to list pools in all regions
268
274
-`--output json`, `-o json` - Output raw JSON array
269
275
-`kernel browser-pools create` - Create a browser pool
270
276
-`--name <name>` - Optional unique name for the pool
@@ -325,6 +331,37 @@ Telemetry config is a sub-field of the browser session. Use `browsers create` or
325
331
326
332
Per-category updates are partial — only categories you name are changed; others retain their current state. `--telemetry=all` and `--telemetry=off` reset the entire config.
327
333
334
+
#### Exporting telemetry
335
+
336
+
Captured telemetry can be exported over OTLP to one of the org's configured destinations with `--telemetry-export-otlp <id-or-name>`. A value that looks like an ID is sent as one; anything else is resolved as a destination name, which must match exactly one destination in the org.
337
+
338
+
- Capture and export: `kernel browsers create --telemetry-export-otlp my-collector`
339
+
- Capture without exporting: `kernel browsers create --telemetry=all`
340
+
- Stop exporting: `--telemetry-export-otlp=off`
341
+
342
+
Export is bound at session creation, so it is available on `browsers create` and on the managed-auth commands that create a browser (`auth connections create`, `update`, and `login`). A browser session keeps the destination it was created with — `browsers update` cannot change it — and browser pools do not support export.
343
+
344
+
#### Telemetry destinations
345
+
346
+
Destinations are the OTLP/HTTP endpoints sessions export to, managed per project.
347
+
348
+
-`kernel telemetry destinations list` - List OTLP destinations
349
+
-`--page <n>` / `--per-page <n>` - Page number (1-based) and items per page (default 20)
350
+
-`--name <name>` - Filter by exact destination name
351
+
-`--query <text>` - Substring match against name or endpoint; IDs match by exact value
352
+
-`kernel telemetry destinations get <id-or-name>` - Get an OTLP destination
-`--endpoint <url>` - Base OTLP/HTTP endpoint without a signal path: pass `https://api.honeycomb.io`, not `https://api.honeycomb.io/v1/logs` (required)
355
+
-`--name <name>` - Destination name, unique within the project (required)
356
+
-`--description <text>` - Optional description
357
+
-`--header NAME=VALUE` - Header sent with each export request, typically an ingestion key (repeatable). Values are encrypted at rest and always returned redacted, so only header names are shown
358
+
-`kernel telemetry destinations update <id-or-name>` - Update an OTLP destination. Sessions already exporting pick up the new values without restarting, which makes this the way to rotate credentials without interrupting export
359
+
-`--name <name>` / `--endpoint <url>` / `--description <text>` - Update those fields; pass `--description ""` to clear it
360
+
-`--header NAME=VALUE` - Add or replace a header (repeatable). Headers you do not name are left as they are
361
+
-`--remove-header NAME` - Delete a header (repeatable). Removals are applied before `--header` is merged, so a header given to both keeps its new value
362
+
-`kernel telemetry destinations delete <id-or-name>` - Delete an OTLP destination. Refused while sessions are still exporting to it, or while a managed auth connection still selects it
363
+
-`-y, --yes` - Skip confirmation prompt
364
+
328
365
-`kernel browsers telemetry stream <id>` - Stream live telemetry events (NDJSON with `-o json`)
-`--types <list>` - Filter by event type (e.g. `network_response`, `console_error`)
@@ -482,10 +519,22 @@ Per-category updates are partial — only categories you name are changed; other
482
519
-`--offset <n>` - Number of projects to skip; table indexes match this offset
483
520
-`--output json`, `-o json` - Output `{ "projects": [...], "next_offset": <n> }`; `next_offset` is omitted on the last page
484
521
- When more projects are available, the CLI prints the exact command to fetch the next page
522
+
-`kernel projects get <id-or-name>` - Show a project's details
485
523
-`kernel projects update <id-or-name>` - Update a project's name or status
486
-
-`--name <name>` - New project name (1-255 characters)
524
+
-`--name <name>` - New project name (1-255 characters; cannot contain `/` or `%`)
487
525
-`--status <status>` - New project status: `active` or `archived`
488
526
-`--output json`, `-o json` - Output raw JSON object
527
+
-`kernel projects delete <id-or-name>` - Soft-delete a project (must have no active resources)
528
+
-`kernel projects limits get <id-or-name>` - Show a project's resource limit overrides
529
+
-`--output json`, `-o json` - Output raw JSON object
530
+
-`kernel projects limits set <id-or-name>` - Update a project's resource limit overrides
531
+
-`--max-concurrent-sessions <n>` - Cap on concurrent browser sessions (0 removes the cap)
532
+
-`--max-concurrent-invocations <n>` - Cap on concurrent invocations (0 removes the cap)
533
+
-`--max-pooled-sessions <n>` - Cap on pooled browser sessions (0 removes the cap)
534
+
-`--output json`, `-o json` - Output raw JSON object
535
+
536
+
Every `<id-or-name>` above is resolved by the API, so a project name works
537
+
anywhere a project ID does.
489
538
490
539
### Extension Management
491
540
@@ -538,6 +587,11 @@ Per-category updates are partial — only categories you name are changed; other
538
587
-`kernel proxies delete <id>` - Delete a proxy configuration
539
588
-`-y, --yes` - Skip confirmation prompt
540
589
590
+
### Auth Context
591
+
592
+
-`kernel auth context` - Show the identity and authorization context resolved for the current credentials: the authenticated principal, organization, credential scope, and the effective scope for the request. Credential secrets are never returned. Pass `--project <id>` to see the effective scope a project-scoped request would get.
593
+
-`--output json`, `-o json` - Output raw JSON object
594
+
541
595
### Auth Connections
542
596
543
597
Managed auth connections (`kernel auth connections`). The commands below are new or gained new flags; run `kernel auth connections --help` for the full command list.
@@ -547,16 +601,27 @@ Managed auth connections (`kernel auth connections`). The commands below are new
547
601
-`--page <n>` - Page number (1-based, default: 1)
548
602
-`--per-page <n>` - Items per page (default: 20)
549
603
-`--output json`, `-o json` - Output raw JSON array
550
-
-`kernel auth connections create` - New flag:
604
+
-`kernel auth connections create` - New flags:
605
+
-`--proxy-id <id>` / `--proxy-name <name>` / `--proxy-mode direct|default` - Proxy configuration for this connection's login, reauth, and health-check browser sessions (mutually exclusive). Omit to derive the default from stealth.
606
+
-`--stealth` - Whether those browser sessions run in stealth mode (default: true); use `--stealth=false` to disable
551
607
-`--telemetry=all` / `--telemetry=off` / `--telemetry=<categories>` - Default telemetry for this connection's browser sessions. Same semantics as `kernel browsers create`
552
-
-`kernel auth connections update <id>` - New flag:
608
+
-`--telemetry-export-otlp <id-or-name>` - Export this connection's captured telemetry over OTLP to one of the org's configured destinations. Implies `--telemetry=all` when `--telemetry` is not set. Use `=off` to disable export.
609
+
-`kernel auth connections update <id>` - New flags:
610
+
-`--proxy-id <id>` / `--proxy-name <name>` / `--proxy-mode direct|default` - Proxy configuration for future browser sessions (mutually exclusive). Use `--proxy-mode=default` to drop a selected proxy rather than passing an empty value.
611
+
-`--stealth` - Set whether future browser sessions run in stealth mode; use `--stealth=false` to disable
-`--telemetry-export-otlp <id-or-name>` - Update where future sessions export captured telemetry. Naming a destination requires passing `--telemetry` in the same command, since the API validates capture and export together and enabling capture here would replace the connection's current category selection. Use `=off` to disable export.
614
+
-`kernel auth connections login <id>` - New flags:
615
+
-`--proxy-id <id>` / `--proxy-name <name>` / `--proxy-mode direct|default` - Proxy override for this login's browser session (mutually exclusive); omitted properties inherit the connection defaults
616
+
-`--stealth` - Stealth override for this login's browser session; use `--stealth=false` to disable
555
617
-`--telemetry=all` / `--telemetry=off` / `--telemetry=<categories>` - Telemetry override for this login only, merged onto the connection's config
618
+
-`--telemetry-export-otlp <id-or-name>` - Export override for this login only. Naming a destination requires passing `--telemetry` in the same command. Use `=off` to disable export.
556
619
-`kernel auth connections submit <id>` - New flags:
557
620
-`--field-value <id=value>` - Canonical field-id=value pair from the connection's `fields` list (repeatable); preferred over the legacy `--field`
558
621
-`--choice-id <id>` - Canonical choice ID from the connection's `choices` list
559
622
623
+
`kernel auth connections get` and `follow` list those IDs alongside the metadata the API captured for them, so you can tell the options apart before submitting. Fields show their type, ref, and any hint (which names the masked destination a one-time code was sent to); choices show their type, semantic MFA method (`sms`, `totp`, `push`, …), and masked destination.
624
+
560
625
### Agent Auth
561
626
562
627
Automated authentication for web services. The `run` command orchestrates the full auth flow automatically.
0 commit comments