Skip to content

Commit 6181c95

Browse files
authored
Merge pull request #183 from kernel/release-please--branches--main--changes--next
release: 0.116.0
2 parents bbfe7a8 + 689d5a2 commit 6181c95

11 files changed

Lines changed: 202 additions & 23 deletions

‎.release-please-manifest.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,3 @@
11
{
2-
".": "0.115.0"
2+
".": "0.116.0"
33
}

‎CHANGELOG.md‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,12 @@
11
# Changelog
22

3+
## [0.116.0](https://github.com/kernel/kernel-python-sdk/compare/v0.115.0...v0.116.0) (2026-10-01)
4+
5+
6+
### Features
7+
8+
* chore(stlc): seal custom-code tracking files ([c053ce4](https://github.com/kernel/kernel-python-sdk/commit/c053ce45e5d6bfaa4577310d28b3ecf0a7c16f4e))
9+
310
## [0.115.0](https://github.com/kernel/kernel-python-sdk/compare/v0.114.0...v0.115.0) (2026-09-30)
411

512

‎pyproject.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
[project]
22
name = "kernel"
3-
version = "0.115.0"
3+
version = "0.116.0"
44
description = "The official Python library for the kernel API"
55
dynamic = ["readme"]
66
license = "Apache-2.0"

‎src/kernel/_version.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
11
# File generated from our OpenAPI spec by Stainless. See CONTRIBUTING.md for details.
22

33
__title__ = "kernel"
4-
__version__ = "0.115.0" # x-release-please-version
4+
__version__ = "0.116.0" # x-release-please-version

‎src/kernel/resources/credentials.py‎

Lines changed: 81 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
from __future__ import annotations
44

55
from typing import Dict, Optional
6+
from typing_extensions import Literal
67

78
import httpx
89

@@ -54,6 +55,9 @@ def create(
5455
name: str,
5556
values: Dict[str, str],
5657
sso_provider: str | Omit = omit,
58+
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"] | Omit = omit,
59+
totp_digits: int | Omit = omit,
60+
totp_period: int | Omit = omit,
5761
totp_secret: str | Omit = omit,
5862
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
5963
# The extra values given here take precedence over values defined on the client or passed to this method.
@@ -77,8 +81,20 @@ def create(
7781
button, it will be clicked first before filling credential values on the
7882
identity provider's login page.
7983
80-
totp_secret: Base32-encoded TOTP secret for generating one-time passwords. Used for automatic
81-
2FA during login.
84+
totp_algorithm: HMAC algorithm used to generate TOTP codes. Defaults to SHA1 and is ignored when
85+
an `otpauth://` URI supplies the algorithm.
86+
87+
totp_digits: Number of digits in generated TOTP codes. Defaults to 6 and is ignored when an
88+
`otpauth://` URI supplies the digit count.
89+
90+
totp_period: TOTP rotation period in seconds. Defaults to 30 and is ignored when an
91+
`otpauth://` URI supplies the period.
92+
93+
totp_secret: Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
94+
URI. The range accepts existing shorter seeds and longer seeds regardless of
95+
HMAC algorithm; RFC 6238 recommends unpadded base32 lengths of 32/52/103 for
96+
SHA1/SHA256/SHA512. Only URI parameters present override the corresponding
97+
explicit TOTP fields. Used for automatic 2FA during login.
8298
8399
extra_headers: Send extra headers
84100
@@ -96,6 +112,9 @@ def create(
96112
"name": name,
97113
"values": values,
98114
"sso_provider": sso_provider,
115+
"totp_algorithm": totp_algorithm,
116+
"totp_digits": totp_digits,
117+
"totp_period": totp_period,
99118
"totp_secret": totp_secret,
100119
},
101120
credential_create_params.CredentialCreateParams,
@@ -147,6 +166,9 @@ def update(
147166
name: str | Omit = omit,
148167
remove_value_keys: SequenceNotStr[str] | Omit = omit,
149168
sso_provider: Optional[str] | Omit = omit,
169+
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"] | Omit = omit,
170+
totp_digits: int | Omit = omit,
171+
totp_period: int | Omit = omit,
150172
totp_secret: str | Omit = omit,
151173
values: Dict[str, str] | Omit = omit,
152174
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
@@ -170,8 +192,20 @@ def update(
170192
sso_provider: If set, indicates this credential should be used with the specified SSO
171193
provider. Set to empty string or null to remove.
172194
173-
totp_secret: Base32-encoded TOTP secret for generating one-time passwords. Spaces and
174-
formatting are automatically normalized. Set to empty string to remove.
195+
totp_algorithm: HMAC algorithm used to generate TOTP codes. Requires totp_secret and is ignored
196+
when an `otpauth://` URI supplies the algorithm.
197+
198+
totp_digits: Number of digits in generated TOTP codes. Requires totp_secret and is ignored
199+
when an `otpauth://` URI supplies the digit count.
200+
201+
totp_period: TOTP rotation period in seconds. Requires totp_secret and is ignored when an
202+
`otpauth://` URI supplies the period.
203+
204+
totp_secret: Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
205+
URI. Only URI parameters present override the corresponding explicit TOTP
206+
fields. When rotating a raw secret, omitted fields preserve their existing
207+
values; a new URI defaults unspecified fields to SHA1/6/30. Set to empty string
208+
to remove the secret and its metadata.
175209
176210
values: Field name to value mapping. Values are merged with existing values (new keys
177211
added, existing keys overwritten).
@@ -193,6 +227,9 @@ def update(
193227
"name": name,
194228
"remove_value_keys": remove_value_keys,
195229
"sso_provider": sso_provider,
230+
"totp_algorithm": totp_algorithm,
231+
"totp_digits": totp_digits,
232+
"totp_period": totp_period,
196233
"totp_secret": totp_secret,
197234
"values": values,
198235
},
@@ -360,6 +397,9 @@ async def create(
360397
name: str,
361398
values: Dict[str, str],
362399
sso_provider: str | Omit = omit,
400+
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"] | Omit = omit,
401+
totp_digits: int | Omit = omit,
402+
totp_period: int | Omit = omit,
363403
totp_secret: str | Omit = omit,
364404
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
365405
# The extra values given here take precedence over values defined on the client or passed to this method.
@@ -383,8 +423,20 @@ async def create(
383423
button, it will be clicked first before filling credential values on the
384424
identity provider's login page.
385425
386-
totp_secret: Base32-encoded TOTP secret for generating one-time passwords. Used for automatic
387-
2FA during login.
426+
totp_algorithm: HMAC algorithm used to generate TOTP codes. Defaults to SHA1 and is ignored when
427+
an `otpauth://` URI supplies the algorithm.
428+
429+
totp_digits: Number of digits in generated TOTP codes. Defaults to 6 and is ignored when an
430+
`otpauth://` URI supplies the digit count.
431+
432+
totp_period: TOTP rotation period in seconds. Defaults to 30 and is ignored when an
433+
`otpauth://` URI supplies the period.
434+
435+
totp_secret: Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
436+
URI. The range accepts existing shorter seeds and longer seeds regardless of
437+
HMAC algorithm; RFC 6238 recommends unpadded base32 lengths of 32/52/103 for
438+
SHA1/SHA256/SHA512. Only URI parameters present override the corresponding
439+
explicit TOTP fields. Used for automatic 2FA during login.
388440
389441
extra_headers: Send extra headers
390442
@@ -402,6 +454,9 @@ async def create(
402454
"name": name,
403455
"values": values,
404456
"sso_provider": sso_provider,
457+
"totp_algorithm": totp_algorithm,
458+
"totp_digits": totp_digits,
459+
"totp_period": totp_period,
405460
"totp_secret": totp_secret,
406461
},
407462
credential_create_params.CredentialCreateParams,
@@ -453,6 +508,9 @@ async def update(
453508
name: str | Omit = omit,
454509
remove_value_keys: SequenceNotStr[str] | Omit = omit,
455510
sso_provider: Optional[str] | Omit = omit,
511+
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"] | Omit = omit,
512+
totp_digits: int | Omit = omit,
513+
totp_period: int | Omit = omit,
456514
totp_secret: str | Omit = omit,
457515
values: Dict[str, str] | Omit = omit,
458516
# Use the following arguments if you need to pass additional parameters to the API that aren't available via kwargs.
@@ -476,8 +534,20 @@ async def update(
476534
sso_provider: If set, indicates this credential should be used with the specified SSO
477535
provider. Set to empty string or null to remove.
478536
479-
totp_secret: Base32-encoded TOTP secret for generating one-time passwords. Spaces and
480-
formatting are automatically normalized. Set to empty string to remove.
537+
totp_algorithm: HMAC algorithm used to generate TOTP codes. Requires totp_secret and is ignored
538+
when an `otpauth://` URI supplies the algorithm.
539+
540+
totp_digits: Number of digits in generated TOTP codes. Requires totp_secret and is ignored
541+
when an `otpauth://` URI supplies the digit count.
542+
543+
totp_period: TOTP rotation period in seconds. Requires totp_secret and is ignored when an
544+
`otpauth://` URI supplies the period.
545+
546+
totp_secret: Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
547+
URI. Only URI parameters present override the corresponding explicit TOTP
548+
fields. When rotating a raw secret, omitted fields preserve their existing
549+
values; a new URI defaults unspecified fields to SHA1/6/30. Set to empty string
550+
to remove the secret and its metadata.
481551
482552
values: Field name to value mapping. Values are merged with existing values (new keys
483553
added, existing keys overwritten).
@@ -499,6 +569,9 @@ async def update(
499569
"name": name,
500570
"remove_value_keys": remove_value_keys,
501571
"sso_provider": sso_provider,
572+
"totp_algorithm": totp_algorithm,
573+
"totp_digits": totp_digits,
574+
"totp_period": totp_period,
502575
"totp_secret": totp_secret,
503576
"values": values,
504577
},

‎src/kernel/types/credential.py‎

Lines changed: 20 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22

33
from typing import List, Optional
44
from datetime import datetime
5+
from typing_extensions import Literal
56

67
from .._models import BaseModel
78

@@ -40,15 +41,33 @@ class Credential(BaseModel):
4041
identity provider's login page.
4142
"""
4243

44+
totp_algorithm: Optional[Literal["SHA1", "SHA256", "SHA512"]] = None
45+
"""HMAC algorithm used to generate TOTP codes.
46+
47+
Defaults to SHA1 for credentials created before this metadata was stored.
48+
"""
49+
4350
totp_code: Optional[str] = None
44-
"""Current 6-digit TOTP code.
51+
"""Current TOTP code.
4552
4653
Only included in create/update responses when totp_secret was just set.
4754
"""
4855

4956
totp_code_expires_at: Optional[datetime] = None
5057
"""When the totp_code expires. Only included when totp_code is present."""
5158

59+
totp_digits: Optional[int] = None
60+
"""Number of digits in generated TOTP codes.
61+
62+
Defaults to 6 for credentials created before this metadata was stored.
63+
"""
64+
65+
totp_period: Optional[int] = None
66+
"""TOTP rotation period in seconds.
67+
68+
Defaults to 30 for credentials created before this metadata was stored.
69+
"""
70+
5271
value_keys: Optional[List[str]] = None
5372
"""The field names stored in this credential's values (e.g., username, password).
5473

‎src/kernel/types/credential_create_params.py‎

Lines changed: 25 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
from __future__ import annotations
44

55
from typing import Dict
6-
from typing_extensions import Required, TypedDict
6+
from typing_extensions import Literal, Required, TypedDict
77

88
__all__ = ["CredentialCreateParams"]
99

@@ -26,8 +26,29 @@ class CredentialCreateParams(TypedDict, total=False):
2626
identity provider's login page.
2727
"""
2828

29-
totp_secret: str
30-
"""Base32-encoded TOTP secret for generating one-time passwords.
29+
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"]
30+
"""HMAC algorithm used to generate TOTP codes.
31+
32+
Defaults to SHA1 and is ignored when an `otpauth://` URI supplies the algorithm.
33+
"""
34+
35+
totp_digits: int
36+
"""Number of digits in generated TOTP codes.
37+
38+
Defaults to 6 and is ignored when an `otpauth://` URI supplies the digit count.
39+
"""
3140

32-
Used for automatic 2FA during login.
41+
totp_period: int
42+
"""TOTP rotation period in seconds.
43+
44+
Defaults to 30 and is ignored when an `otpauth://` URI supplies the period.
45+
"""
46+
47+
totp_secret: str
48+
"""
49+
Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
50+
URI. The range accepts existing shorter seeds and longer seeds regardless of
51+
HMAC algorithm; RFC 6238 recommends unpadded base32 lengths of 32/52/103 for
52+
SHA1/SHA256/SHA512. Only URI parameters present override the corresponding
53+
explicit TOTP fields. Used for automatic 2FA during login.
3354
"""

‎src/kernel/types/credential_update_params.py‎

Lines changed: 28 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
from __future__ import annotations
44

55
from typing import Dict, Optional
6-
from typing_extensions import TypedDict
6+
from typing_extensions import Literal, TypedDict
77

88
from .._types import SequenceNotStr
99

@@ -28,11 +28,34 @@ class CredentialUpdateParams(TypedDict, total=False):
2828
Set to empty string or null to remove.
2929
"""
3030

31-
totp_secret: str
32-
"""Base32-encoded TOTP secret for generating one-time passwords.
31+
totp_algorithm: Literal["SHA1", "SHA256", "SHA512"]
32+
"""HMAC algorithm used to generate TOTP codes.
33+
34+
Requires totp_secret and is ignored when an `otpauth://` URI supplies the
35+
algorithm.
36+
"""
37+
38+
totp_digits: int
39+
"""Number of digits in generated TOTP codes.
40+
41+
Requires totp_secret and is ignored when an `otpauth://` URI supplies the digit
42+
count.
43+
"""
3344

34-
Spaces and formatting are automatically normalized. Set to empty string to
35-
remove.
45+
totp_period: int
46+
"""TOTP rotation period in seconds.
47+
48+
Requires totp_secret and is ignored when an `otpauth://` URI supplies the
49+
period.
50+
"""
51+
52+
totp_secret: str
53+
"""
54+
Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...`
55+
URI. Only URI parameters present override the corresponding explicit TOTP
56+
fields. When rotating a raw secret, omitted fields preserve their existing
57+
values; a new URI defaults unspecified fields to SHA1/6/30. Set to empty string
58+
to remove the secret and its metadata.
3659
"""
3760

3861
values: Dict[str, str]

‎src/kernel/types/vaults/card_vault_item_spec.py‎

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -96,7 +96,7 @@ class LinkCardVaultItemSpec(BaseModel):
9696
class AgentCardCardVaultItemSpec(BaseModel):
9797
"""AgentCard reusable live payment card.
9898
99-
Test-mode card creation is not supported. Each checkout creates an approval-gated authorization for spec.merchant / spec.amount. The card stays ready after each authorization.
99+
Test-mode card creation is not supported. Each checkout creates an authorization for spec.merchant / spec.amount that the cardholder approves, unless AgentCard runs it under one of the cardholder's autopilot rules. The card stays ready after each authorization.
100100
"""
101101

102102
amount: int
@@ -119,6 +119,18 @@ class AgentCardCardVaultItemSpec(BaseModel):
119119
cardholder picks on the approval screen.
120120
"""
121121

122+
checkout_origin: Optional[str] = None
123+
"""
124+
Origin of the top-level checkout page, such as https://shop.example.com: https,
125+
a lowercase host, a port only when it is not 443, and no path. http is accepted
126+
only for localhost test pages. Checkouts without a preparation send it to
127+
AgentCard, which uses it to match the cardholder's autopilot rules; prepared
128+
checkouts send the preparation's merchant_origin instead. Kernel sends the
129+
declared value and does not compare it with the page the browser has open.
130+
Omitted, those checkouts ask the cardholder to approve. Card updates replace the
131+
whole spec, so an update that omits it removes it.
132+
"""
133+
122134

123135
CardVaultItemSpec: TypeAlias = Annotated[
124136
Union[LinkCardVaultItemSpec, AgentCardCardVaultItemSpec], PropertyInfo(discriminator="provider")

0 commit comments

Comments
 (0)