CLI: Update SDK to 2f367635f58ffca59a764f8a8280784fb0f9f7e7 and add new commands/flags - #278
Open
kernel-internal[bot] wants to merge 11 commits into
Open
kernel-internal[bot] wants to merge 11 commits into
kernel-internal[bot] wants to merge 11 commits into
Conversation
SDK version bump only. A full enumeration of SDK methods vs CLI commands found no coverage gaps (config-registry endpoints are x-cli-skip). Tested: go build ./... (no new commands/flags to smoke test) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
- Bump github.com/kernel/kernel-go-sdk to 10c4031082d73b41180adeb54a722f89341907ff - Add --totp-algorithm, --totp-digits, --totp-period to `kernel credentials create` and `kernel credentials update` (CreateCredentialRequestParam / UpdateCredentialRequestParam TotpAlgorithm, TotpDigits, TotpPeriod) - Show TOTP algorithm/digits/period in credentials get/create output Tested: credentials create --totp-secret --totp-algorithm sha256 --totp-digits 8 --totp-period 60 (8-digit code returned, metadata shown in get), credentials totp-code, credentials update --totp-secret --totp-algorithm SHA512 --totp-digits 7 (verified in get -o json), invalid --totp-algorithm rejected, otpauth:// URI params take precedence over explicit flags, credentials delete cleanup. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bumps kernel-go-sdk to v0.116.0 (c026e806a1bd). The SDK changes since 10c4031082d7 are release metadata only. A full enumeration of SDK methods against CLI commands found no coverage gaps. Config-registry endpoints are x-cli-skip. Tested: go build ./..., go test ./... (SDK version bump only, no new commands/flags) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Bump github.com/kernel/kernel-go-sdk to 615cfaf0c5a80549cba3cd643c00b58c517f5475 - Add `webmcp_invoke` to `kernel vaults items invoke` (--params/--spec-file with browser_id, tool_ref, page_url, input, bindings, timeout_sec) for WebmcpInvokeVaultItemOperationRequestParam / VaultWebmcpBindingParam Tested: created vault + credential (populated via hosted collect form), vault-bound browser with a custom WebMCP tool on example.com; `vaults items invoke <vault> login webmcp_invoke --params ...` (table) and `--spec-file - -o json` both returned completed with vaulted values substituted; mismatched page_url returned HTTP 400 with guidance. Resources cleaned up. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 3 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit dced2d6. Configure here.
SDK bump only (v0.117.0 release; no API changes). Full enumeration of SDK methods vs CLI commands found no coverage gaps. Tested: go build, go test ./cmd/..., kernel browsers list Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Bump kernel-go-sdk to 0aa2b3c772eb7eff991947d84a8f0bbb3a879abe - Add --query to `kernel vaults list` (VaultListParams.Query); preserved in Next: hint - Forward explicit --since to InvocationFollowParams.Since in `kernel logs --invocation` Tested: vaults create/list --query (substring match, no match, -o json)/delete; logs <app> --invocation <id> [--since 1h]; go test ./... Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Update kernel-go-sdk to a1378239c479aeeb6d360e0719426ff0c9821da6. - vaults wallets create / cards create: accept --provider kernel (KernelWalletVaultItemSpecParam, KernelCardVaultItemSpecParam) - Reject provider config/tokens-file for Kernel wallets and updates for Kernel cards (unsupported per API) - Document KernelWalletSpec and KernelCardSpec in spec help - Show merchant URL, card last4, and network token last4 (masks.token_last4) in item output; keep token_last4 in filtered JSON Tested: vaults wallets create --provider kernel (request forwarded; staging API returned "provider configuration is unavailable"), vaults cards create --provider kernel (API validated kernel spec), client-side rejection of cards update/provider-config for kernel, items get output, vault cleanup. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bump kernel-go-sdk to v0.118.0 (681b969). The SDK change is a release only (no API surface changes); full enumeration found no coverage gaps. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bump kernel-go-sdk to 73817c0b9c4e93502daf9ecaa0bcf27e11e827bb, which adds the managed_auth credential vault item spec (ManagedAuthCredentialVaultItemSpecInputParam). - vaults credentials create accepts spec provider "managed_auth" with connection_id and optional description - Display-safe vault output keeps spec.connection_id and state.fields[*].type, and no longer rewrites managed_auth state fields with has_value - Table output shows the managed auth connection; help/README document the flow Tested: vaults credentials create --spec-file (provider managed_auth) against the live API, then vaults items get (table + json), vaults items list, missing connection_id validation, unknown connection (404), cleanup via items delete and vaults delete. go test ./... passes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…9.0) Full enumeration of SDK methods vs CLI commands found no coverage gaps; the SDK change contains only release metadata (version/changelog). Tested: go build ./..., go vet ./..., go test ./... Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

This PR updates the Go SDK to 2f367635f58ffca59a764f8a8280784fb0f9f7e7 and adds CLI commands/flags for new SDK methods.
SDK Update
managed_authcredential vault item provider (ManagedAuthCredentialVaultItemSpecInputParam,ManagedAuthCredentialVaultItemSpec,ManagedAuthCredentialVaultItemState). It adds no new methods.Coverage Analysis
This PR was generated by performing a full enumeration of SDK methods and CLI commands. All 172 SDK methods in api.md have CLI coverage, except the ConfigRegistry endpoints, which are marked
x-cli-skip.kernel search(get/providers/contents) andkernel browsers curlcover the Search and Curl methods through raw requests.New Commands
New Flags / Spec Options
kernel vaults credentials create --spec-filenow accepts{"provider":"managed_auth","connection_id":"...","description":"..."}forCredentialVaultItemSpecInputUnionParam.OfManagedAuth(ManagedAuthCredentialVaultItemSpecInputParam.ConnectionID,.Description). A missingconnection_idis rejected before the request is sent.spec.connection_idandstate.fields[*].type, and no longer rewrites managed_auth state fields withhas_value. Table output shows the managed auth connection and a fill hint. The help text and README document the flow.These came from earlier commits on this branch (SDK a1378239c479):
--provider kernelonkernel vaults wallets createforWalletVaultItemSpecUnionParam.OfKernel(KernelWalletVaultItemSpecParam): Kernel-managed agentic network token wallet with hosted card enrollment. Provider config and--tokens-fileare rejected for this provider.--provider kernelonkernel vaults cards createforCardVaultItemSpecUnionParam.OfKernel(KernelCardVaultItemSpecParam: wallet, amount, currency, merchant_name, merchant_url).cards updaterejects Kernel cards because the API doesn't support updating them.--queryonkernel vaults listforVaultListParams.Query.KernelWalletSpecandKernelCardSpec.masks.token_last4); filtered JSON output keepstoken_last4.Testing
go build ./...,go vet ./...andgo test ./...pass. This change adds no new commands or flags, so there was nothing new to smoke test.vaults credentials createwith amanaged_authspec, run against the live API using an existing connection with a saved credential: the item was createdreadywith thefilloperation advertised.items get(table and JSON) showedconnection_idand the field binding types (email,password,sms_code), anditems listshowed providermanaged_auth.connection_idis rejected client-side, and an unknown connection returns 404.cmd/vaults_managed_auth_test.go);go test ./...andgo vet ./...pass.vaults wallets create --provider kernelsent its request, but the staging API answeredprovider configuration is unavailable.vaults cards create --provider kernelreached the API, which validated the kernel card spec.Triggered by: kernel/kernel-go-sdk@2f36763
Reviewer: @bmsaadat
🤖 Generated with Claude Code
Note
High Risk
Adds managed-auth credential binding, Kernel card/wallet flows, and webmcp_invoke with vaulted secrets and possible page side effects—all security- and payment-sensitive paths.
Overview
Bumps kernel-go-sdk to v0.119.0 and expands vault/credential CLI support for new API providers and operations.
Vault credentials can be created with
managed_auth(connection_id+ optional description): no stored values; fill reads the linked auth connection’s saved credential at runtime. Parsing, help, table/JSON output, and tests cover the new provider.Vault items gain
webmcp_invoke(--params/--spec-file): bind vaulted fields into a WebMCP tool call on a vault-bound browser session, with validation, no retries on uncertain outcomes, and status-based exit codes. Docs and README list it alongside fill / collect.Kernel payment provider is wired for
vaults wallets createandvaults cards create(--provider kernel); Kernel wallets reject provider config/tokens; cards update is blocked for Kernel items. Output/docs add merchant URL and card/network token last4 fields.kernel vaults listadds--query(name substring / exact ID), preserved in pagination hints.kernel credentialstable output shows TOTP algorithm/digits/period when configured.kernel logsonly sends--sincewhen the flag was explicitly set.Unit tests cover WebMCP invoke, managed auth, Kernel wallet validation, vault list query, and TOTP algorithm normalization.
Reviewed by Cursor Bugbot for commit 21ce1a2. Bugbot is set up for automated code reviews on this repo. Configure here.