diff --git a/.release-please-manifest.json b/.release-please-manifest.json
index d9c93890..4101a550 100644
--- a/.release-please-manifest.json
+++ b/.release-please-manifest.json
@@ -1,3 +1,3 @@
{
- ".": "0.104.0"
+ ".": "0.106.0"
}
diff --git a/.stats.yml b/.stats.yml
index a0ee50ed..88ce9db5 100644
--- a/.stats.yml
+++ b/.stats.yml
@@ -1 +1 @@
-configured_endpoints: 163
+configured_endpoints: 164
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 9521f533..7ce8d460 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,5 +1,16 @@
# Changelog
+## 0.106.0 (2026-09-16)
+
+Full Changelog: [v0.104.0...v0.106.0](https://github.com/kernel/kernel-node-sdk/compare/v0.104.0...v0.106.0)
+
+### Features
+
+* Add processor-bound AgentCard preparation contracts ([725bcc8](https://github.com/kernel/kernel-node-sdk/commit/725bcc8dafab5fb2a7c348d4057990a58f476fbd))
+* Add start_url to browser session updates ([10ab182](https://github.com/kernel/kernel-node-sdk/commit/10ab18213ba857f37aaa113c1f802f009db8ceab))
+* Polish and publish the Config Registry API ([92a7d13](https://github.com/kernel/kernel-node-sdk/commit/92a7d131a4e1af661b4b05ab6be95ac27df166eb))
+* Square UKP and Hypeman placement load factors ([ed270d2](https://github.com/kernel/kernel-node-sdk/commit/ed270d2c34763157eecd9c9f2177198071c0c810))
+
## [0.104.0](https://github.com/kernel/kernel-node-sdk/compare/v0.103.0...v0.104.0) (2026-09-15)
diff --git a/api.md b/api.md
index 37fd00ba..11bd685c 100644
--- a/api.md
+++ b/api.md
@@ -93,6 +93,7 @@ Methods:
- client.configRegistry.analyses.retrieve(id) -> ConfigRegistryResponse
- client.configRegistry.analyses.list({ ...params }) -> AnalysisSummariesOffsetPagination
+- client.configRegistry.analyses.cancel(id) -> ConfigRegistryResponse
# Browsers
@@ -466,6 +467,7 @@ Types:
- AgentcardCheckoutAuthorization
- AgentcardCheckoutPreparation
+- AgentcardPreparedProcessor
- AuthorizeVaultItemOperationRequest
- CardVaultItemSpec
- CardVaultItemState
diff --git a/package.json b/package.json
index 15b87e48..d46d0670 100644
--- a/package.json
+++ b/package.json
@@ -1,6 +1,6 @@
{
"name": "@onkernel/sdk",
- "version": "0.104.0",
+ "version": "0.106.0",
"description": "The official TypeScript library for the Kernel API",
"author": "Kernel <>",
"types": "dist/index.d.ts",
diff --git a/src/resources/browser-pools.ts b/src/resources/browser-pools.ts
index e61cbc90..7444b45a 100644
--- a/src/resources/browser-pools.ts
+++ b/src/resources/browser-pools.ts
@@ -477,7 +477,7 @@ export interface BrowserPoolAcquireResponse {
proxy_id?: string;
/**
- * URL the session was asked to navigate to on creation, if any. Recorded for
+ * URL the session was most recently asked to navigate to, if any. Recorded for
* debugging. Navigation is fire-and-forget — the URL is dispatched to the browser
* without waiting for it to load, and any errors (DNS failure, bad status,
* timeout) are silently dropped. Captures what was requested, not what the browser
diff --git a/src/resources/browsers/browsers.ts b/src/resources/browsers/browsers.ts
index cd3e2ca5..670d5bbc 100644
--- a/src/resources/browsers/browsers.ts
+++ b/src/resources/browsers/browsers.ts
@@ -607,7 +607,7 @@ export interface BrowserCreateResponse {
proxy_id?: string;
/**
- * URL the session was asked to navigate to on creation, if any. Recorded for
+ * URL the session was most recently asked to navigate to, if any. Recorded for
* debugging. Navigation is fire-and-forget — the URL is dispatched to the browser
* without waiting for it to load, and any errors (DNS failure, bad status,
* timeout) are silently dropped. Captures what was requested, not what the browser
@@ -778,7 +778,7 @@ export interface BrowserRetrieveResponse {
proxy_id?: string;
/**
- * URL the session was asked to navigate to on creation, if any. Recorded for
+ * URL the session was most recently asked to navigate to, if any. Recorded for
* debugging. Navigation is fire-and-forget — the URL is dispatched to the browser
* without waiting for it to load, and any errors (DNS failure, bad status,
* timeout) are silently dropped. Captures what was requested, not what the browser
@@ -949,7 +949,7 @@ export interface BrowserUpdateResponse {
proxy_id?: string;
/**
- * URL the session was asked to navigate to on creation, if any. Recorded for
+ * URL the session was most recently asked to navigate to, if any. Recorded for
* debugging. Navigation is fire-and-forget — the URL is dispatched to the browser
* without waiting for it to load, and any errors (DNS failure, bad status,
* timeout) are silently dropped. Captures what was requested, not what the browser
@@ -1120,7 +1120,7 @@ export interface BrowserListResponse {
proxy_id?: string;
/**
- * URL the session was asked to navigate to on creation, if any. Recorded for
+ * URL the session was most recently asked to navigate to, if any. Recorded for
* debugging. Navigation is fire-and-forget — the URL is dispatched to the browser
* without waiting for it to load, and any errors (DNS failure, bad status,
* timeout) are silently dropped. Captures what was requested, not what the browser
@@ -1482,6 +1482,14 @@ export interface BrowserUpdateParams {
*/
proxy_id?: string | null;
+ /**
+ * Optional URL to navigate the browser to after applying this update. When a
+ * profile is loaded in the same update, this overrides the profile's restored
+ * tabs. Navigation is best-effort, so failures do not fail the update. Omit or set
+ * to an empty string to leave the current page unchanged.
+ */
+ start_url?: string;
+
/**
* User-defined key-value tags for the browser session. Omit to leave unchanged.
* Provide a map to replace the entire tag set (full replace, not a merge). Set to
diff --git a/src/resources/config-registry/analyses.ts b/src/resources/config-registry/analyses.ts
index 187ffde9..83b9d294 100644
--- a/src/resources/config-registry/analyses.ts
+++ b/src/resources/config-registry/analyses.ts
@@ -47,6 +47,22 @@ export class Analyses extends APIResource {
{ query, ...options },
);
}
+
+ /**
+ * Requests cancellation of a running project-scoped analysis. Cancellation is
+ * asynchronous; poll the analysis until its status becomes canceled. Repeating the
+ * request after the analysis reaches a terminal state returns the existing
+ * outcome.
+ *
+ * @example
+ * ```ts
+ * const configRegistryResponse =
+ * await client.configRegistry.analyses.cancel('id');
+ * ```
+ */
+ cancel(id: string, options?: RequestOptions): APIPromise {
+ return this._client.post(path`/config-registry/analyses/${id}/cancel`, options);
+ }
}
export interface AnalysisListParams extends OffsetPaginationParams {
diff --git a/src/resources/config-registry/config-registry.ts b/src/resources/config-registry/config-registry.ts
index 9a054a24..b45c6140 100644
--- a/src/resources/config-registry/config-registry.ts
+++ b/src/resources/config-registry/config-registry.ts
@@ -104,6 +104,12 @@ export interface Analysis {
* Lifecycle status of a background analysis.
*/
status: 'running' | 'completed' | 'failed' | 'canceled' | 'expired';
+
+ /**
+ * The workload description supplied for this analysis. Null when the analysis only
+ * tested connectivity.
+ */
+ intent?: string | null;
}
export interface AnalysisSummary {
@@ -208,11 +214,11 @@ export interface Evidence {
success_rate: number;
/**
- * Most recent contributing run where this config met the success threshold.
- * Omitted for knowledge assembled from runs that did not independently meet the
- * threshold.
+ * Most recent contributing run whose evidence supported recommending this
+ * configuration. Omitted when no individual run independently met the
+ * recommendation threshold.
*/
- last_verified_at?: string | null;
+ last_supported_at?: string | null;
}
export interface LookupRequest {
@@ -453,7 +459,9 @@ export interface Recommendation {
evidence: Evidence;
/**
- * Specificity of knowledge matched for this recommendation.
+ * Specificity of knowledge matched for this recommendation. Exact matches use
+ * knowledge for the requested target; host and domain matches use broader fallback
+ * knowledge.
*/
match_scope: 'exact' | 'host' | 'domain';
@@ -468,13 +476,6 @@ export interface Recommendation {
proxy: Proxy;
type: 'recommendation';
-
- /**
- * Exact matches meet the evidence threshold; host and domain fallbacks are
- * inferred. Check evidence.last_verified_at for successful verification age and
- * last_observed_at for the latest evidence.
- */
- verification: 'verified' | 'inferred';
}
/**
@@ -542,8 +543,9 @@ export interface ResolveRequest {
* any non-HTTPS destination as off-site and will not drive an http one. Kernel
* uses it to drive the browser further into the site, where it can observe
* protections that only appear once a session interacts. When this target already
- * has a verified configuration, the run confirms that one instead of re-deriving
- * the whole matrix, so supplying an intent narrows what can be recommended.
+ * has a recommended configuration, the run confirms that one instead of
+ * re-deriving the whole matrix, so supplying an intent narrows what can be
+ * recommended.
*/
intent?: string;
}
@@ -609,8 +611,9 @@ export interface ConfigRegistryResolveParams {
* any non-HTTPS destination as off-site and will not drive an http one. Kernel
* uses it to drive the browser further into the site, where it can observe
* protections that only appear once a session interacts. When this target already
- * has a verified configuration, the run confirms that one instead of re-deriving
- * the whole matrix, so supplying an intent narrows what can be recommended.
+ * has a recommended configuration, the run confirms that one instead of
+ * re-deriving the whole matrix, so supplying an intent narrows what can be
+ * recommended.
*/
intent?: string;
}
diff --git a/src/resources/invocations.ts b/src/resources/invocations.ts
index 300caac1..fb507c4a 100644
--- a/src/resources/invocations.ts
+++ b/src/resources/invocations.ts
@@ -566,7 +566,7 @@ export namespace InvocationListBrowsersResponse {
proxy_id?: string;
/**
- * URL the session was asked to navigate to on creation, if any. Recorded for
+ * URL the session was most recently asked to navigate to, if any. Recorded for
* debugging. Navigation is fire-and-forget — the URL is dispatched to the browser
* without waiting for it to load, and any errors (DNS failure, bad status,
* timeout) are silently dropped. Captures what was requested, not what the browser
diff --git a/src/resources/vaults/index.ts b/src/resources/vaults/index.ts
index 44bd61cd..0df179b4 100644
--- a/src/resources/vaults/index.ts
+++ b/src/resources/vaults/index.ts
@@ -4,6 +4,7 @@ export {
Items,
type AgentcardCheckoutAuthorization,
type AgentcardCheckoutPreparation,
+ type AgentcardPreparedProcessor,
type AuthorizeVaultItemOperationRequest,
type CardVaultItemSpec,
type CardVaultItemState,
diff --git a/src/resources/vaults/items.ts b/src/resources/vaults/items.ts
index 8f3553c4..94c835da 100644
--- a/src/resources/vaults/items.ts
+++ b/src/resources/vaults/items.ts
@@ -256,19 +256,21 @@ export interface AgentcardCheckoutAuthorization {
}
/**
- * One-use Square checkout preparation. Keep the approval page open through token
- * handoff. The amount is display-only and does not constrain the merchant's
- * eventual charge.
+ * One-use processor-bound checkout preparation. Keep the approval page open
+ * through token handoff. The amount is display-only and does not constrain the
+ * merchant's eventual charge.
*/
export interface AgentcardCheckoutPreparation {
browser_id: string;
created_at: string;
- environment: 'production' | 'sandbox';
+ environment: 'production' | 'sandbox' | 'shared';
merchant_origin: string;
+ psp: AgentcardPreparedProcessor;
+
/**
* Preparation consumed means egress claimed the preparation and it cannot be
* reused. It does not mean the attempt settled. Use the enclosing item's status as
@@ -289,6 +291,8 @@ export interface AgentcardCheckoutPreparation {
expires_at?: string;
}
+export type AgentcardPreparedProcessor = 'square' | 'braintree' | 'worldpay' | 'bambora' | 'mercado_pago';
+
/**
* Authorize a Link card using its existing purchase specification. Use only after
* explicit user approval and when the item advertises authorize. Do not
@@ -429,9 +433,17 @@ export namespace CardVaultItemSpec {
}
}
+/**
+ * Issued Link cards retain encrypted card material for the fill operation. Link
+ * cards do not expose aliases or support egress substitution.
+ */
export type CardVaultItemState = CardVaultItemState.LinkCardState | CardVaultItemState.AgentCardCardState;
export namespace CardVaultItemState {
+ /**
+ * Issued Link cards retain encrypted card material for the fill operation. Link
+ * cards do not expose aliases or support egress substitution.
+ */
export interface LinkCardState {
provider: 'link';
@@ -451,8 +463,6 @@ export namespace CardVaultItemState {
| 'declined'
| 'recovery_required';
- aliases?: ItemsAPI.VaultCardAliases;
-
domains?: Array;
masks?: LinkCardState.Masks;
@@ -507,9 +517,9 @@ export namespace CardVaultItemState {
masks?: AgentCardCardState.Masks;
/**
- * One-use Square checkout preparation. Keep the approval page open through token
- * handoff. The amount is display-only and does not constrain the merchant's
- * eventual charge.
+ * One-use processor-bound checkout preparation. Keep the approval page open
+ * through token handoff. The amount is display-only and does not constrain the
+ * merchant's eventual charge.
*/
preparation?: ItemsAPI.AgentcardCheckoutPreparation;
@@ -891,10 +901,9 @@ export interface CredentialVaultItemUpdateRequest {
*
* Fill in request order and stop on the first failure. This operation is not
* atomic: previously filled fields are not rolled back. Never submit the form or
- * click buttons, though input/change events may trigger site behavior. Fill is the
- * preferred browser-checkout path. Aliases remain an alternative for explicitly
- * chosen egress-substitution integrations. Do not automatically retry or fall back
- * to aliases after a failed or indeterminate operation.
+ * click buttons, though input/change events may trigger site behavior. Link cards
+ * use fill for browser checkout and do not expose aliases or support egress
+ * substitution. Do not automatically retry a failed or indeterminate operation.
*
* Secret values are never returned or included in operation logs, traces, audit
* events, or error details. This does not prevent an agent with unrestricted
@@ -947,8 +956,8 @@ export interface FillVaultItemOperationResult {
}
/**
- * Prepare an unused AgentCard card for Square checkout. Deliver the returned
- * approval URL and keep the approval page open. Poll the item until
+ * Prepare an unused AgentCard card for a supported tokenization checkout. Deliver
+ * the returned approval URL and keep the approval page open. Poll the item until
* ready_to_submit, then submit native Pay before preparation.expires_at. Readiness
* lasts at most 30 seconds. Unused preparations expire automatically. Preparations
* are single-use even after failure or expiry; do not automatically retry and
@@ -956,11 +965,11 @@ export interface FillVaultItemOperationResult {
*/
export interface PrepareCheckoutVaultItemOperationRequest {
/**
- * Required when preparing an unused AgentCard card for Square. Consent is bound to
- * this browser and declared merchant origin, not a tab. Wait for the item's
- * ready_to_submit status before native Pay and submit within its readiness
- * deadline. Unused preparations expire automatically; every preparation is
- * single-use, including after failure or expiry.
+ * Required when preparing an unused AgentCard card for a supported tokenization
+ * processor. Consent is bound to this browser and declared merchant origin, not a
+ * tab. Wait for the item's ready_to_submit status before native Pay and submit
+ * within its readiness deadline. Unused preparations expire automatically; every
+ * preparation is single-use, including after failure or expiry.
*/
checkout: VaultCheckoutContext;
@@ -1033,11 +1042,11 @@ export namespace VaultCardFillField {
}
/**
- * Required when preparing an unused AgentCard card for Square. Consent is bound to
- * this browser and declared merchant origin, not a tab. Wait for the item's
- * ready_to_submit status before native Pay and submit within its readiness
- * deadline. Unused preparations expire automatically; every preparation is
- * single-use, including after failure or expiry.
+ * Required when preparing an unused AgentCard card for a supported tokenization
+ * processor. Consent is bound to this browser and declared merchant origin, not a
+ * tab. Wait for the item's ready_to_submit status before native Pay and submit
+ * within its readiness deadline. Unused preparations expire automatically; every
+ * preparation is single-use, including after failure or expiry.
*/
export interface VaultCheckoutContext {
/**
@@ -1046,15 +1055,24 @@ export interface VaultCheckoutContext {
browser_id: string;
/**
- * Square environment, independent of the AgentCard credential mode.
+ * Use production or sandbox for Square, Braintree and Worldpay; shared for Bambora
+ * and Mercado Pago. Shared endpoints do not establish test mode. Merchant
+ * credentials/configuration determine processor test mode, independently of the
+ * AgentCard credential mode.
*/
- environment: 'production' | 'sandbox';
+ environment: 'production' | 'sandbox' | 'shared';
/**
- * Canonical HTTPS origin of the top-level merchant document, not the Square
+ * Canonical HTTPS origin of the top-level merchant document, not a processor
* iframe. HTTP localhost is accepted for tests.
*/
merchant_origin: string;
+
+ /**
+ * Tokenization processor. Omit for Square compatibility. Non-Square processors
+ * require multi-processor preparation enablement.
+ */
+ psp?: AgentcardPreparedProcessor;
}
export interface VaultFillField {
@@ -1190,6 +1208,10 @@ export namespace VaultItem {
*/
spec: ItemsAPI.CardVaultItemSpec;
+ /**
+ * Issued Link cards retain encrypted card material for the fill operation. Link
+ * cards do not expose aliases or support egress substitution.
+ */
state: ItemsAPI.CardVaultItemState;
type: 'card';
@@ -1384,6 +1406,10 @@ export namespace VaultItemOperationResponse {
*/
spec: ItemsAPI.CardVaultItemSpec;
+ /**
+ * Issued Link cards retain encrypted card material for the fill operation. Link
+ * cards do not expose aliases or support egress substitution.
+ */
state: ItemsAPI.CardVaultItemState;
type: 'card';
@@ -1723,11 +1749,12 @@ export declare namespace ItemPerformOperationParams {
id_or_name: string;
/**
- * Body param: Required when preparing an unused AgentCard card for Square. Consent
- * is bound to this browser and declared merchant origin, not a tab. Wait for the
- * item's ready_to_submit status before native Pay and submit within its readiness
- * deadline. Unused preparations expire automatically; every preparation is
- * single-use, including after failure or expiry.
+ * Body param: Required when preparing an unused AgentCard card for a supported
+ * tokenization processor. Consent is bound to this browser and declared merchant
+ * origin, not a tab. Wait for the item's ready_to_submit status before native Pay
+ * and submit within its readiness deadline. Unused preparations expire
+ * automatically; every preparation is single-use, including after failure or
+ * expiry.
*/
checkout: VaultCheckoutContext;
@@ -1990,6 +2017,7 @@ export declare namespace Items {
export {
type AgentcardCheckoutAuthorization as AgentcardCheckoutAuthorization,
type AgentcardCheckoutPreparation as AgentcardCheckoutPreparation,
+ type AgentcardPreparedProcessor as AgentcardPreparedProcessor,
type AuthorizeVaultItemOperationRequest as AuthorizeVaultItemOperationRequest,
type CardVaultItemSpec as CardVaultItemSpec,
type CardVaultItemState as CardVaultItemState,
diff --git a/src/resources/vaults/vaults.ts b/src/resources/vaults/vaults.ts
index 349f4ec6..43915c90 100644
--- a/src/resources/vaults/vaults.ts
+++ b/src/resources/vaults/vaults.ts
@@ -5,6 +5,7 @@ import * as ItemsAPI from './items';
import {
AgentcardCheckoutAuthorization,
AgentcardCheckoutPreparation,
+ AgentcardPreparedProcessor,
AuthorizeVaultItemOperationRequest,
CardVaultItemSpec,
CardVaultItemState,
@@ -158,6 +159,7 @@ export declare namespace Vaults {
Items as Items,
type AgentcardCheckoutAuthorization as AgentcardCheckoutAuthorization,
type AgentcardCheckoutPreparation as AgentcardCheckoutPreparation,
+ type AgentcardPreparedProcessor as AgentcardPreparedProcessor,
type AuthorizeVaultItemOperationRequest as AuthorizeVaultItemOperationRequest,
type CardVaultItemSpec as CardVaultItemSpec,
type CardVaultItemState as CardVaultItemState,
diff --git a/src/version.ts b/src/version.ts
index e50cdd9c..013fb8ed 100644
--- a/src/version.ts
+++ b/src/version.ts
@@ -1 +1 @@
-export const VERSION = '0.104.0'; // x-release-please-version
+export const VERSION = '0.106.0'; // x-release-please-version
diff --git a/tests/api-resources/config-registry/analyses.test.ts b/tests/api-resources/config-registry/analyses.test.ts
index 35811e58..87d576d1 100644
--- a/tests/api-resources/config-registry/analyses.test.ts
+++ b/tests/api-resources/config-registry/analyses.test.ts
@@ -46,4 +46,16 @@ describe('resource analyses', () => {
),
).rejects.toThrow(Kernel.NotFoundError);
});
+
+ // Mock server tests are disabled
+ test.skip('cancel', async () => {
+ const responsePromise = client.configRegistry.analyses.cancel('id');
+ const rawResponse = await responsePromise.asResponse();
+ expect(rawResponse).toBeInstanceOf(Response);
+ const response = await responsePromise;
+ expect(response).not.toBeInstanceOf(Response);
+ const dataAndResponse = await responsePromise.withResponse();
+ expect(dataAndResponse.data).toBe(response);
+ expect(dataAndResponse.response).toBe(rawResponse);
+ });
});