Skip to content

Commit 3927c96

Browse files
feat: Add guarded vault card fill operations
Stainless-Generated-From: 8e37c63cadbed622dfdf688b8e94ae2e5116344e
1 parent c276ebc commit 3927c96

11 files changed

Lines changed: 970 additions & 39 deletions

‎api.md‎

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -527,10 +527,15 @@ from kernel.types.vaults import (
527527
AgentcardCheckoutAuthorization,
528528
CardVaultItemSpec,
529529
CardVaultItemState,
530+
FillVaultItemOperationRequest,
531+
FillVaultItemOperationResult,
530532
VaultCardAliases,
533+
VaultCardFillField,
534+
VaultFillFieldResult,
531535
VaultItem,
532536
VaultItemAction,
533537
VaultItemEvent,
538+
VaultItemOperationResponse,
534539
VaultPaymentMethod,
535540
WalletVaultItemSpec,
536541
WalletVaultItemState,
@@ -546,7 +551,7 @@ Methods:
546551
- <code title="get /vaults/{id_or_name}/items">client.vaults.items.<a href="./src/kernel/resources/vaults/items.py">list</a>(id_or_name) -> <a href="./src/kernel/types/vaults/item_list_response.py">ItemListResponse</a></code>
547552
- <code title="delete /vaults/{id_or_name}/items/{key}">client.vaults.items.<a href="./src/kernel/resources/vaults/items.py">delete</a>(key, \*, id_or_name) -> None</code>
548553
- <code title="get /vaults/{id_or_name}/items/{key}/events">client.vaults.items.<a href="./src/kernel/resources/vaults/items.py">events</a>(key, \*, id_or_name, \*\*<a href="src/kernel/types/vaults/item_events_params.py">params</a>) -> <a href="./src/kernel/types/vaults/item_events_response.py">ItemEventsResponse</a></code>
549-
- <code title="post /vaults/{id_or_name}/items/{key}/operations">client.vaults.items.<a href="./src/kernel/resources/vaults/items.py">perform_operation</a>(key, \*, id_or_name, \*\*<a href="src/kernel/types/vaults/item_perform_operation_params.py">params</a>) -> <a href="./src/kernel/types/vaults/vault_item.py">VaultItem</a></code>
554+
- <code title="post /vaults/{id_or_name}/items/{key}/operations">client.vaults.items.<a href="./src/kernel/resources/vaults/items.py">perform_operation</a>(key, \*, id_or_name, \*\*<a href="src/kernel/types/vaults/item_perform_operation_params.py">params</a>) -> <a href="./src/kernel/types/vaults/vault_item_operation_response.py">VaultItemOperationResponse</a></code>
550555
- <code title="put /vaults/{id_or_name}/items/{key}">client.vaults.items.<a href="./src/kernel/resources/vaults/items.py">upsert</a>(key, \*, id_or_name, \*\*<a href="src/kernel/types/vaults/item_upsert_params.py">params</a>) -> <a href="./src/kernel/types/vaults/vault_item.py">VaultItem</a></code>
551556

552557
# Credentials

‎src/kernel/resources/vaults/items.py‎

Lines changed: 211 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22

33
from __future__ import annotations
44

5-
from typing import Any, List, cast
5+
from typing import Any, List, Iterable, cast
66
from typing_extensions import Literal, overload
77

88
import httpx
@@ -29,6 +29,8 @@
2929
from ...types.vaults.item_list_response import ItemListResponse
3030
from ...types.vaults.item_events_response import ItemEventsResponse
3131
from ...types.vaults.card_vault_item_spec_param import CardVaultItemSpecParam
32+
from ...types.vaults.vault_card_fill_field_param import VaultCardFillFieldParam
33+
from ...types.vaults.vault_item_operation_response import VaultItemOperationResponse
3234

3335
__all__ = ["ItemsResource", "AsyncItemsResource"]
3436

@@ -289,6 +291,7 @@ def events(
289291
cast_to=ItemEventsResponse,
290292
)
291293

294+
@overload
292295
def perform_operation(
293296
self,
294297
key: str,
@@ -301,17 +304,81 @@ def perform_operation(
301304
extra_query: Query | None = None,
302305
extra_body: Body | None = None,
303306
timeout: float | httpx.Timeout | None | NotGiven = not_given,
304-
) -> VaultItem:
307+
) -> VaultItemOperationResponse:
308+
"""
309+
Retrieve the item first and invoke only an operation listed in
310+
`available_operations`, following its natural-language description. Availability
311+
is rechecked at execution time; unavailable operations return 409. Authorization
312+
may call an external provider and returns the updated item. Link cards advertise
313+
authorize when eligible. AgentCard cards are created with PUT and request
314+
approval when their aliases are used at checkout; they do not expose authorize.
315+
If spend-request creation is rate limited, returns HTTP 429 with code
316+
`spend_request_rate_limited`; stop and back off before retrying.
317+
318+
Fill returns a value-free execution result. Validation failures before writing
319+
return 400 (invalid request or targets), 403 (access or destination denied), 404
320+
(resource not found), or 409 (item or browser not ready). Once writing starts,
321+
known partial failures and indeterminate field outcomes return 200 with status
322+
`failed` or `unknown`, not an automatic-retry signal. A transport error may
323+
leave the outcome unknown; do not automatically retry.
324+
325+
Args:
326+
extra_headers: Send extra headers
327+
328+
extra_query: Add additional query parameters to the request
329+
330+
extra_body: Add additional JSON properties to the request
331+
332+
timeout: Override the client-level default timeout for this request, in seconds
333+
"""
334+
...
335+
336+
@overload
337+
def perform_operation(
338+
self,
339+
key: str,
340+
*,
341+
id_or_name: str,
342+
browser_id: str,
343+
fields: Iterable[VaultCardFillFieldParam],
344+
page_url: str,
345+
type: Literal["fill"],
346+
timeout_ms: int | Omit = omit,
347+
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
348+
# The extra values given here take precedence over values defined on the client or passed to this method.
349+
extra_headers: Headers | None = None,
350+
extra_query: Query | None = None,
351+
extra_body: Body | None = None,
352+
timeout: float | httpx.Timeout | None | NotGiven = not_given,
353+
) -> VaultItemOperationResponse:
305354
"""
306355
Retrieve the item first and invoke only an operation listed in
307-
`available_operations`, following its natural-language description. Operations
308-
may call an external provider and return updated state. Link cards advertise
309-
authorize. AgentCard cards are created with PUT and request approval when their
310-
aliases are used at checkout; they do not expose this operation. If
311-
spend-request creation is rate limited, returns HTTP 429 with code
356+
`available_operations`, following its natural-language description. Availability
357+
is rechecked at execution time; unavailable operations return 409. Authorization
358+
may call an external provider and returns the updated item. Link cards advertise
359+
authorize when eligible. AgentCard cards are created with PUT and request
360+
approval when their aliases are used at checkout; they do not expose authorize.
361+
If spend-request creation is rate limited, returns HTTP 429 with code
312362
`spend_request_rate_limited`; stop and back off before retrying.
313363
364+
Fill returns a value-free execution result. Validation failures before writing
365+
return 400 (invalid request or targets), 403 (access or destination denied), 404
366+
(resource not found), or 409 (item or browser not ready). Once writing starts,
367+
known partial failures and indeterminate field outcomes return 200 with status
368+
`failed` or `unknown`, not an automatic-retry signal. A transport error may
369+
leave the outcome unknown; do not automatically retry.
370+
314371
Args:
372+
browser_id: Browser session ID, not a reusable browser name.
373+
374+
fields: Field bindings for this step. No two bindings may resolve to the same element.
375+
376+
page_url: Exact current top-level page URL, including path, query, and fragment. Must
377+
match exactly one open page in the browser; zero or multiple matches fail. No
378+
prefix or glob matching. Must use HTTPS without embedded credentials.
379+
380+
timeout_ms: Total operation deadline in milliseconds, not a per-field timeout.
381+
315382
extra_headers: Send extra headers
316383
317384
extra_query: Add additional query parameters to the request
@@ -320,19 +387,50 @@ def perform_operation(
320387
321388
timeout: Override the client-level default timeout for this request, in seconds
322389
"""
390+
...
391+
392+
@required_args(["id_or_name", "type"], ["id_or_name", "browser_id", "fields", "page_url", "type"])
393+
def perform_operation(
394+
self,
395+
key: str,
396+
*,
397+
id_or_name: str,
398+
type: Literal["authorize"] | Literal["fill"],
399+
browser_id: str | Omit = omit,
400+
fields: Iterable[VaultCardFillFieldParam] | Omit = omit,
401+
page_url: str | Omit = omit,
402+
timeout_ms: int | Omit = omit,
403+
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
404+
# The extra values given here take precedence over values defined on the client or passed to this method.
405+
extra_headers: Headers | None = None,
406+
extra_query: Query | None = None,
407+
extra_body: Body | None = None,
408+
timeout: float | httpx.Timeout | None | NotGiven = not_given,
409+
) -> VaultItemOperationResponse:
323410
if not id_or_name:
324411
raise ValueError(f"Expected a non-empty value for `id_or_name` but received {id_or_name!r}")
325412
if not key:
326413
raise ValueError(f"Expected a non-empty value for `key` but received {key!r}")
327414
return cast(
328-
VaultItem,
415+
VaultItemOperationResponse,
329416
self._post(
330417
path_template("/vaults/{id_or_name}/items/{key}/operations", id_or_name=id_or_name, key=key),
331-
body=maybe_transform({"type": type}, item_perform_operation_params.ItemPerformOperationParams),
418+
body=maybe_transform(
419+
{
420+
"type": type,
421+
"browser_id": browser_id,
422+
"fields": fields,
423+
"page_url": page_url,
424+
"timeout_ms": timeout_ms,
425+
},
426+
item_perform_operation_params.ItemPerformOperationParams,
427+
),
332428
options=make_request_options(
333429
extra_headers=extra_headers, extra_query=extra_query, extra_body=extra_body, timeout=timeout
334430
),
335-
cast_to=cast(Any, VaultItem), # Union types cannot be passed in as arguments in the type system
431+
cast_to=cast(
432+
Any, VaultItemOperationResponse
433+
), # Union types cannot be passed in as arguments in the type system
336434
),
337435
)
338436

@@ -707,6 +805,7 @@ async def events(
707805
cast_to=ItemEventsResponse,
708806
)
709807

808+
@overload
710809
async def perform_operation(
711810
self,
712811
key: str,
@@ -719,17 +818,81 @@ async def perform_operation(
719818
extra_query: Query | None = None,
720819
extra_body: Body | None = None,
721820
timeout: float | httpx.Timeout | None | NotGiven = not_given,
722-
) -> VaultItem:
821+
) -> VaultItemOperationResponse:
822+
"""
823+
Retrieve the item first and invoke only an operation listed in
824+
`available_operations`, following its natural-language description. Availability
825+
is rechecked at execution time; unavailable operations return 409. Authorization
826+
may call an external provider and returns the updated item. Link cards advertise
827+
authorize when eligible. AgentCard cards are created with PUT and request
828+
approval when their aliases are used at checkout; they do not expose authorize.
829+
If spend-request creation is rate limited, returns HTTP 429 with code
830+
`spend_request_rate_limited`; stop and back off before retrying.
831+
832+
Fill returns a value-free execution result. Validation failures before writing
833+
return 400 (invalid request or targets), 403 (access or destination denied), 404
834+
(resource not found), or 409 (item or browser not ready). Once writing starts,
835+
known partial failures and indeterminate field outcomes return 200 with status
836+
`failed` or `unknown`, not an automatic-retry signal. A transport error may
837+
leave the outcome unknown; do not automatically retry.
838+
839+
Args:
840+
extra_headers: Send extra headers
841+
842+
extra_query: Add additional query parameters to the request
843+
844+
extra_body: Add additional JSON properties to the request
845+
846+
timeout: Override the client-level default timeout for this request, in seconds
847+
"""
848+
...
849+
850+
@overload
851+
async def perform_operation(
852+
self,
853+
key: str,
854+
*,
855+
id_or_name: str,
856+
browser_id: str,
857+
fields: Iterable[VaultCardFillFieldParam],
858+
page_url: str,
859+
type: Literal["fill"],
860+
timeout_ms: int | Omit = omit,
861+
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
862+
# The extra values given here take precedence over values defined on the client or passed to this method.
863+
extra_headers: Headers | None = None,
864+
extra_query: Query | None = None,
865+
extra_body: Body | None = None,
866+
timeout: float | httpx.Timeout | None | NotGiven = not_given,
867+
) -> VaultItemOperationResponse:
723868
"""
724869
Retrieve the item first and invoke only an operation listed in
725-
`available_operations`, following its natural-language description. Operations
726-
may call an external provider and return updated state. Link cards advertise
727-
authorize. AgentCard cards are created with PUT and request approval when their
728-
aliases are used at checkout; they do not expose this operation. If
729-
spend-request creation is rate limited, returns HTTP 429 with code
870+
`available_operations`, following its natural-language description. Availability
871+
is rechecked at execution time; unavailable operations return 409. Authorization
872+
may call an external provider and returns the updated item. Link cards advertise
873+
authorize when eligible. AgentCard cards are created with PUT and request
874+
approval when their aliases are used at checkout; they do not expose authorize.
875+
If spend-request creation is rate limited, returns HTTP 429 with code
730876
`spend_request_rate_limited`; stop and back off before retrying.
731877
878+
Fill returns a value-free execution result. Validation failures before writing
879+
return 400 (invalid request or targets), 403 (access or destination denied), 404
880+
(resource not found), or 409 (item or browser not ready). Once writing starts,
881+
known partial failures and indeterminate field outcomes return 200 with status
882+
`failed` or `unknown`, not an automatic-retry signal. A transport error may
883+
leave the outcome unknown; do not automatically retry.
884+
732885
Args:
886+
browser_id: Browser session ID, not a reusable browser name.
887+
888+
fields: Field bindings for this step. No two bindings may resolve to the same element.
889+
890+
page_url: Exact current top-level page URL, including path, query, and fragment. Must
891+
match exactly one open page in the browser; zero or multiple matches fail. No
892+
prefix or glob matching. Must use HTTPS without embedded credentials.
893+
894+
timeout_ms: Total operation deadline in milliseconds, not a per-field timeout.
895+
733896
extra_headers: Send extra headers
734897
735898
extra_query: Add additional query parameters to the request
@@ -738,21 +901,50 @@ async def perform_operation(
738901
739902
timeout: Override the client-level default timeout for this request, in seconds
740903
"""
904+
...
905+
906+
@required_args(["id_or_name", "type"], ["id_or_name", "browser_id", "fields", "page_url", "type"])
907+
async def perform_operation(
908+
self,
909+
key: str,
910+
*,
911+
id_or_name: str,
912+
type: Literal["authorize"] | Literal["fill"],
913+
browser_id: str | Omit = omit,
914+
fields: Iterable[VaultCardFillFieldParam] | Omit = omit,
915+
page_url: str | Omit = omit,
916+
timeout_ms: int | Omit = omit,
917+
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
918+
# The extra values given here take precedence over values defined on the client or passed to this method.
919+
extra_headers: Headers | None = None,
920+
extra_query: Query | None = None,
921+
extra_body: Body | None = None,
922+
timeout: float | httpx.Timeout | None | NotGiven = not_given,
923+
) -> VaultItemOperationResponse:
741924
if not id_or_name:
742925
raise ValueError(f"Expected a non-empty value for `id_or_name` but received {id_or_name!r}")
743926
if not key:
744927
raise ValueError(f"Expected a non-empty value for `key` but received {key!r}")
745928
return cast(
746-
VaultItem,
929+
VaultItemOperationResponse,
747930
await self._post(
748931
path_template("/vaults/{id_or_name}/items/{key}/operations", id_or_name=id_or_name, key=key),
749932
body=await async_maybe_transform(
750-
{"type": type}, item_perform_operation_params.ItemPerformOperationParams
933+
{
934+
"type": type,
935+
"browser_id": browser_id,
936+
"fields": fields,
937+
"page_url": page_url,
938+
"timeout_ms": timeout_ms,
939+
},
940+
item_perform_operation_params.ItemPerformOperationParams,
751941
),
752942
options=make_request_options(
753943
extra_headers=extra_headers, extra_query=extra_query, extra_body=extra_body, timeout=timeout
754944
),
755-
cast_to=cast(Any, VaultItem), # Union types cannot be passed in as arguments in the type system
945+
cast_to=cast(
946+
Any, VaultItemOperationResponse
947+
), # Union types cannot be passed in as arguments in the type system
756948
),
757949
)
758950

‎src/kernel/types/vaults/__init__.py‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,14 @@
1616
from .vault_payment_method import VaultPaymentMethod as VaultPaymentMethod
1717
from .card_vault_item_state import CardVaultItemState as CardVaultItemState
1818
from .wallet_vault_item_spec import WalletVaultItemSpec as WalletVaultItemSpec
19+
from .vault_fill_field_result import VaultFillFieldResult as VaultFillFieldResult
1920
from .wallet_vault_item_state import WalletVaultItemState as WalletVaultItemState
2021
from .card_vault_item_spec_param import CardVaultItemSpecParam as CardVaultItemSpecParam
22+
from .vault_card_fill_field_param import VaultCardFillFieldParam as VaultCardFillFieldParam
2123
from .item_perform_operation_params import ItemPerformOperationParams as ItemPerformOperationParams
24+
from .vault_item_operation_response import VaultItemOperationResponse as VaultItemOperationResponse
2225
from .agentcard_checkout_authorization import AgentcardCheckoutAuthorization as AgentcardCheckoutAuthorization
26+
from .fill_vault_item_operation_result import FillVaultItemOperationResult as FillVaultItemOperationResult
27+
from .fill_vault_item_operation_request_param import (
28+
FillVaultItemOperationRequestParam as FillVaultItemOperationRequestParam,
29+
)

0 commit comments

Comments
 (0)