Skip to content

Commit 2937b10

Browse files
feat: Let Vaults fill credentials from 1Password
Stainless-Generated-From: 6d937aebb18d99636c515de11d6958083e7ca24c
1 parent 74dbad8 commit 2937b10

31 files changed

Lines changed: 3164 additions & 764 deletions

‎api.md‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -555,6 +555,8 @@ from kernel.types.vaults import (
555555
CardVaultItemSpec,
556556
CardVaultItemState,
557557
CollectVaultItemOperationRequest,
558+
CredentialAccountVaultItem,
559+
CredentialAccountVaultItemRequest,
558560
CredentialCollectionAction,
559561
CredentialVaultFieldDefinition,
560562
CredentialVaultFieldInput,
@@ -570,6 +572,19 @@ from kernel.types.vaults import (
570572
CredentialVaultItemUpdateRequest,
571573
FillVaultItemOperationRequest,
572574
FillVaultItemOperationResult,
575+
KernelCredentialVaultItemSpec,
576+
KernelCredentialVaultItemSpecInput,
577+
KernelCredentialVaultItemState,
578+
OnePasswordCredentialAccountSpec,
579+
OnePasswordCredentialAccountState,
580+
OnePasswordCredentialVaultItemSpec,
581+
OnePasswordCredentialVaultItemSpecInput,
582+
OnePasswordCredentialVaultItemState,
583+
OnePasswordFillVaultItemOperationRequest,
584+
OnePasswordFillVaultItemOperationResult,
585+
OnePasswordOAuthAction,
586+
OnePasswordRecoverVaultItemOperationRequest,
587+
OnePasswordRequestAccessVaultItemOperationRequest,
573588
PrepareCheckoutVaultItemOperationRequest,
574589
VaultCardAliases,
575590
VaultCardFillField,

‎src/kernel/resources/vaults/items.py‎

Lines changed: 748 additions & 98 deletions
Large diffs are not rendered by default.

‎src/kernel/types/vaults/__init__.py‎

Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,7 @@
2020
from .wallet_vault_item_spec import WalletVaultItemSpec as WalletVaultItemSpec
2121
from .vault_fill_field_result import VaultFillFieldResult as VaultFillFieldResult
2222
from .wallet_vault_item_state import WalletVaultItemState as WalletVaultItemState
23+
from .one_password_oauth_action import OnePasswordOAuthAction as OnePasswordOAuthAction
2324
from .card_vault_item_spec_param import CardVaultItemSpecParam as CardVaultItemSpecParam
2425
from .credential_vault_item_spec import CredentialVaultItemSpec as CredentialVaultItemSpec
2526
from .credential_vault_field_type import CredentialVaultFieldType as CredentialVaultFieldType
@@ -28,15 +29,22 @@
2829
from .credential_collection_action import CredentialCollectionAction as CredentialCollectionAction
2930
from .credential_vault_field_state import CredentialVaultFieldState as CredentialVaultFieldState
3031
from .vault_checkout_context_param import VaultCheckoutContextParam as VaultCheckoutContextParam
32+
from .credential_account_vault_item import CredentialAccountVaultItem as CredentialAccountVaultItem
3133
from .item_perform_operation_params import ItemPerformOperationParams as ItemPerformOperationParams
3234
from .vault_item_operation_response import VaultItemOperationResponse as VaultItemOperationResponse
3335
from .agentcard_checkout_preparation import AgentcardCheckoutPreparation as AgentcardCheckoutPreparation
3436
from .agentcard_checkout_authorization import AgentcardCheckoutAuthorization as AgentcardCheckoutAuthorization
3537
from .fill_vault_item_operation_result import FillVaultItemOperationResult as FillVaultItemOperationResult
3638
from .credential_vault_field_definition import CredentialVaultFieldDefinition as CredentialVaultFieldDefinition
39+
from .kernel_credential_vault_item_spec import KernelCredentialVaultItemSpec as KernelCredentialVaultItemSpec
3740
from .credential_vault_field_input_param import CredentialVaultFieldInputParam as CredentialVaultFieldInputParam
41+
from .kernel_credential_vault_item_state import KernelCredentialVaultItemState as KernelCredentialVaultItemState
3842
from .credential_vault_field_update_param import CredentialVaultFieldUpdateParam as CredentialVaultFieldUpdateParam
3943
from .credential_vault_item_request_param import CredentialVaultItemRequestParam as CredentialVaultItemRequestParam
44+
from .one_password_credential_account_spec import OnePasswordCredentialAccountSpec as OnePasswordCredentialAccountSpec
45+
from .one_password_credential_account_state import (
46+
OnePasswordCredentialAccountState as OnePasswordCredentialAccountState,
47+
)
4048
from .credential_vault_item_spec_input_param import (
4149
CredentialVaultItemSpecInputParam as CredentialVaultItemSpecInputParam,
4250
)
@@ -46,15 +54,45 @@
4654
from .fill_vault_item_operation_request_param import (
4755
FillVaultItemOperationRequestParam as FillVaultItemOperationRequestParam,
4856
)
57+
from .one_password_credential_vault_item_spec import (
58+
OnePasswordCredentialVaultItemSpec as OnePasswordCredentialVaultItemSpec,
59+
)
60+
from .one_password_credential_vault_item_state import (
61+
OnePasswordCredentialVaultItemState as OnePasswordCredentialVaultItemState,
62+
)
4963
from .collect_vault_item_operation_request_param import (
5064
CollectVaultItemOperationRequestParam as CollectVaultItemOperationRequestParam,
5165
)
5266
from .credential_vault_item_update_request_param import (
5367
CredentialVaultItemUpdateRequestParam as CredentialVaultItemUpdateRequestParam,
5468
)
69+
from .one_password_credential_account_spec_param import (
70+
OnePasswordCredentialAccountSpecParam as OnePasswordCredentialAccountSpecParam,
71+
)
72+
from .credential_account_vault_item_request_param import (
73+
CredentialAccountVaultItemRequestParam as CredentialAccountVaultItemRequestParam,
74+
)
5575
from .authorize_vault_item_operation_request_param import (
5676
AuthorizeVaultItemOperationRequestParam as AuthorizeVaultItemOperationRequestParam,
5777
)
78+
from .kernel_credential_vault_item_spec_input_param import (
79+
KernelCredentialVaultItemSpecInputParam as KernelCredentialVaultItemSpecInputParam,
80+
)
81+
from .one_password_fill_vault_item_operation_result import (
82+
OnePasswordFillVaultItemOperationResult as OnePasswordFillVaultItemOperationResult,
83+
)
84+
from .one_password_credential_vault_item_spec_input_param import (
85+
OnePasswordCredentialVaultItemSpecInputParam as OnePasswordCredentialVaultItemSpecInputParam,
86+
)
5887
from .prepare_checkout_vault_item_operation_request_param import (
5988
PrepareCheckoutVaultItemOperationRequestParam as PrepareCheckoutVaultItemOperationRequestParam,
6089
)
90+
from .one_password_fill_vault_item_operation_request_param import (
91+
OnePasswordFillVaultItemOperationRequestParam as OnePasswordFillVaultItemOperationRequestParam,
92+
)
93+
from .one_password_recover_vault_item_operation_request_param import (
94+
OnePasswordRecoverVaultItemOperationRequestParam as OnePasswordRecoverVaultItemOperationRequestParam,
95+
)
96+
from .one_password_request_access_vault_item_operation_request_param import (
97+
OnePasswordRequestAccessVaultItemOperationRequestParam as OnePasswordRequestAccessVaultItemOperationRequestParam,
98+
)
Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
# File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details.
2+
3+
from typing import List, Optional
4+
from datetime import datetime
5+
from typing_extensions import Literal
6+
7+
from ..._models import BaseModel
8+
from .one_password_oauth_action import OnePasswordOAuthAction
9+
from .one_password_credential_account_spec import OnePasswordCredentialAccountSpec
10+
from .one_password_credential_account_state import OnePasswordCredentialAccountState
11+
12+
__all__ = ["CredentialAccountVaultItem", "AvailableExpansion", "AvailableOperation"]
13+
14+
15+
class AvailableExpansion(BaseModel):
16+
"""
17+
Live data that can currently be requested by passing its type to the item GET expand parameter.
18+
"""
19+
20+
description: str
21+
22+
type: Literal["payment_methods"]
23+
24+
25+
class AvailableOperation(BaseModel):
26+
"""An operation that is currently valid for this item.
27+
28+
Read the description before invoking it through the item operations endpoint.
29+
"""
30+
31+
description: str
32+
33+
type: Literal[
34+
"authorize",
35+
"collect",
36+
"prepare_checkout",
37+
"fill",
38+
"1pw_create_access_request",
39+
"1pw_access_request_status",
40+
"1pw_fill",
41+
"1pw_recover",
42+
"1pw_update_access_token",
43+
]
44+
45+
46+
class CredentialAccountVaultItem(BaseModel):
47+
id: str
48+
49+
available_expansions: List[AvailableExpansion]
50+
51+
available_operations: List[AvailableOperation]
52+
"""Advertises 1pw_recover when Kernel can recover a failed account link.
53+
54+
Recovery is unavailable while authorization is pending or after the connection
55+
has already been reset.
56+
"""
57+
58+
created_at: datetime
59+
60+
key: str
61+
"""Immutable item key assigned when the item is created."""
62+
63+
spec: OnePasswordCredentialAccountSpec
64+
65+
state: OnePasswordCredentialAccountState
66+
67+
type: Literal["credential_account"]
68+
69+
updated_at: datetime
70+
71+
action: Optional[OnePasswordOAuthAction] = None
72+
73+
expires_at: Optional[datetime] = None
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
# File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details.
2+
3+
from __future__ import annotations
4+
5+
from typing_extensions import Literal, Required, TypedDict
6+
7+
from .one_password_credential_account_spec_param import OnePasswordCredentialAccountSpecParam
8+
9+
__all__ = ["CredentialAccountVaultItemRequestParam"]
10+
11+
12+
class CredentialAccountVaultItemRequestParam(TypedDict, total=False):
13+
spec: Required[OnePasswordCredentialAccountSpecParam]
14+
15+
type: Required[Literal["credential_account"]]

‎src/kernel/types/vaults/credential_vault_item.py‎

Lines changed: 52 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,22 @@
11
# File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details.
22

3-
from typing import List, Optional
3+
from typing import List, Union, Optional
44
from datetime import datetime
5-
from typing_extensions import Literal
5+
from typing_extensions import Literal, Annotated, TypeAlias
66

7+
from ..._utils import PropertyInfo
78
from ..._models import BaseModel
89
from .credential_vault_item_spec import CredentialVaultItemSpec
910
from .credential_vault_item_state import CredentialVaultItemState
1011
from .credential_collection_action import CredentialCollectionAction
1112

12-
__all__ = ["CredentialVaultItem", "AvailableExpansion", "AvailableOperation"]
13+
__all__ = [
14+
"CredentialVaultItem",
15+
"AvailableExpansion",
16+
"AvailableOperation",
17+
"Action",
18+
"ActionOnePasswordAccessApprovalAction",
19+
]
1320

1421

1522
class AvailableExpansion(BaseModel):
@@ -30,7 +37,39 @@ class AvailableOperation(BaseModel):
3037

3138
description: str
3239

33-
type: Literal["authorize", "collect", "prepare_checkout", "fill"]
40+
type: Literal[
41+
"authorize",
42+
"collect",
43+
"prepare_checkout",
44+
"fill",
45+
"1pw_create_access_request",
46+
"1pw_access_request_status",
47+
"1pw_fill",
48+
"1pw_recover",
49+
"1pw_update_access_token",
50+
]
51+
52+
53+
class ActionOnePasswordAccessApprovalAction(BaseModel):
54+
instructions: str
55+
"""
56+
Steps for the agent to hand approval to the human and poll the resulting
57+
decision.
58+
"""
59+
60+
name: Literal["1password_access_approval"]
61+
62+
url: str
63+
"""Native 1Password approval link.
64+
65+
Present it to the account owner without modifying it; it does not grant access
66+
until they approve in their app.
67+
"""
68+
69+
70+
Action: TypeAlias = Annotated[
71+
Union[CredentialCollectionAction, ActionOnePasswordAccessApprovalAction], PropertyInfo(discriminator="name")
72+
]
3473

3574

3675
class CredentialVaultItem(BaseModel):
@@ -39,9 +78,11 @@ class CredentialVaultItem(BaseModel):
3978
available_expansions: List[AvailableExpansion]
4079

4180
available_operations: List[AvailableOperation]
42-
"""Advertises collect for ready and pending_collection items.
81+
"""Kernel credentials advertise collect and fill when eligible.
4382
44-
Browser fill is advertised only when separately implemented and eligible.
83+
1Password credentials advertise 1pw_create_access_request until a request is
84+
made, 1pw_access_request_status while its approval is pending, and 1pw_fill
85+
after access is granted.
4586
"""
4687

4788
created_at: datetime
@@ -50,6 +91,10 @@ class CredentialVaultItem(BaseModel):
5091
"""Immutable item key assigned when the item is created."""
5192

5293
spec: CredentialVaultItemSpec
94+
"""
95+
Stored-token credentials omit account and never return access_token or
96+
integration_key.
97+
"""
5398

5499
state: CredentialVaultItemState
55100

@@ -63,7 +108,7 @@ class CredentialVaultItem(BaseModel):
63108
collection-link renewal.
64109
"""
65110

66-
action: Optional[CredentialCollectionAction] = None
111+
action: Optional[Action] = None
67112
"""
68113
One schema-derived form for the item, available in ready or pending_collection
69114
state. Render every form-supported field as editable; omit totp fields and

‎src/kernel/types/vaults/credential_vault_item_request_param.py‎

Lines changed: 12 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -11,19 +11,18 @@
1111

1212
class CredentialVaultItemRequestParam(TypedDict, total=False):
1313
"""
14-
Create a credential item without a wallet or external provider.
15-
Do not use credential items to store, collect, or fill credit card data,
16-
including card numbers (PANs), security codes (CVV/CVC), or expiration dates.
17-
Use wallet and card item types for credit cards and payment checkout instead.
18-
If all required fields have values, return ready without a collection action;
19-
collect can still open its form. Otherwise return pending_collection with
20-
a time-scoped Kernel-hosted collection action. Missing
21-
optional fields alone do not trigger collection. Repeating the original
22-
creation request returns the current item without overwriting later edits;
23-
a different request at the same key returns 409. Use PATCH for updates.
24-
Required totp fields must include a valid seed on creation; otherwise return
25-
400 rather than opening a form that cannot collect it. Optional totp fields
26-
may be unset and populated later through PATCH.
14+
Ask the end-user whether to link their site credential through 1Password.
15+
If they choose 1Password, connect their account and request access to a login
16+
in their own non-shared vault; passkeys are not supported. If they decline
17+
or that path fails, collect a Kernel-hosted credential item instead. Never
18+
automatically retry an uncertain 1Password request or fill.
19+
Do not use credential items for credit card data. Use wallet and card item types instead.
20+
Kernel credentials declare fields and may enter pending_collection.
21+
1Password credentials either reference a connected credential_account or
22+
store a supplied access token and integration key encrypted on the item.
23+
They store no login values or selectors. Repeating the original creation
24+
request returns the current item without overwriting later state. A
25+
different request at the same key returns 409.
2726
"""
2827

2928
spec: Required[CredentialVaultItemSpecInputParam]
Lines changed: 8 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,22 +1,14 @@
11
# File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details.
22

3-
from typing import List, Optional
3+
from typing import Union
4+
from typing_extensions import Annotated, TypeAlias
45

5-
from ..._models import BaseModel
6-
from .credential_vault_field_definition import CredentialVaultFieldDefinition
6+
from ..._utils import PropertyInfo
7+
from .kernel_credential_vault_item_spec import KernelCredentialVaultItemSpec
8+
from .one_password_credential_vault_item_spec import OnePasswordCredentialVaultItemSpec
79

810
__all__ = ["CredentialVaultItemSpec"]
911

10-
11-
class CredentialVaultItemSpec(BaseModel):
12-
fields: List[CredentialVaultFieldDefinition]
13-
"""
14-
Ordered field definitions rendered in this order by credential collection forms.
15-
"""
16-
17-
description: Optional[str] = None
18-
"""
19-
Recognizable site or service name displayed verbatim as the form title, without
20-
suffixes such as sign-in credentials. Display text only, not an enforced
21-
destination policy.
22-
"""
12+
CredentialVaultItemSpec: TypeAlias = Annotated[
13+
Union[KernelCredentialVaultItemSpec, OnePasswordCredentialVaultItemSpec], PropertyInfo(discriminator="provider")
14+
]

‎src/kernel/types/vaults/credential_vault_item_spec_input_param.py‎

Lines changed: 7 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -2,31 +2,14 @@
22

33
from __future__ import annotations
44

5-
from typing import Iterable
6-
from typing_extensions import Required, TypedDict
5+
from typing import Union
6+
from typing_extensions import TypeAlias
77

8-
from .credential_vault_field_input_param import CredentialVaultFieldInputParam
8+
from .kernel_credential_vault_item_spec_input_param import KernelCredentialVaultItemSpecInputParam
9+
from .one_password_credential_vault_item_spec_input_param import OnePasswordCredentialVaultItemSpecInputParam
910

1011
__all__ = ["CredentialVaultItemSpecInputParam"]
1112

12-
13-
class CredentialVaultItemSpecInputParam(TypedDict, total=False):
14-
"""Credential fields are for login and other non-payment credentials.
15-
16-
Do not store, collect, or fill credit card data in credential items. Use wallet and card item types for credit cards and payment checkout instead. Field order is preserved in the user-facing collection form, so list fields in the same top-to-bottom order as the website.
17-
"""
18-
19-
fields: Required[Iterable[CredentialVaultFieldInputParam]]
20-
"""Ordered field definitions.
21-
22-
Use the website's top-to-bottom field order; the collection form renders this
23-
order unchanged.
24-
"""
25-
26-
description: str
27-
"""
28-
The site's recognizable display name, used verbatim as the user-facing form
29-
title (for example, Hacker News). Use only the site or service name; do not
30-
append sign-in, login, credentials, or task instructions. This is display text,
31-
not an enforced destination policy. At most 16 KiB in UTF-8 bytes.
32-
"""
13+
CredentialVaultItemSpecInputParam: TypeAlias = Union[
14+
KernelCredentialVaultItemSpecInputParam, OnePasswordCredentialVaultItemSpecInputParam
15+
]

0 commit comments

Comments
 (0)