You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@@ -223,6 +224,7 @@ Commands with JSON output support:
223
224
-`--proxy-mode direct|default` - Egress mode instead of a selected proxy: `direct` for no proxy regardless of stealth, `default` for the stealth-derived default (Kernel's stealth proxy with `--stealth`, direct egress otherwise). Omit all proxy flags to get the default.
224
225
-`--name <name>` - Optional unique name for the session (used to find it later by name; can be changed with `browsers update --name`)
225
226
-`--tag <KEY=VALUE>` - Set a tag on the session, repeatable; up to 50 pairs
227
+
-`--vault <id-or-name>` - Attach a project-owned vault at creation (repeatable, max 20). Requires `--project` or `KERNEL_PROJECT`. Cannot be combined with pool flags, even with `--yes`; vault bindings cannot be added to existing sessions.
226
228
-`--pool-id <id>` - Acquire a browser from the specified pool (mutually exclusive with --pool-name; ignores other session flags). `--name`/`--tag` still apply to the acquired session.
227
229
-`--pool-name <name>` - Acquire a browser from the pool name (mutually exclusive with --pool-id; ignores other session flags)
228
230
-`--telemetry=all` - Enable telemetry for all categories
@@ -266,6 +268,108 @@ Commands with JSON output support:
266
268
-`-s, --silent` - Suppress progress output
267
269
-_Note: redirects are followed automatically by Chromium._
268
270
271
+
### Vaults
272
+
273
+
Vault commands **prepare and observe payment credentials; they do not submit merchant payments**.
274
+
Vault names, item keys, and project ownership are immutable. Select the project explicitly with
275
+
`--project <id-or-name>` or `KERNEL_PROJECT`; the API assigns ownership from that scope, not a
276
+
`project_id` body field. Project-scoped credentials cannot switch projects.
277
+
278
+
#### Command reference
279
+
280
+
| Command | Purpose / flags |
281
+
| --- | --- |
282
+
|`kernel vaults create --name <name>`| Create or retrieve the vault with that immutable name |
283
+
|`kernel vaults list`|`--limit 1..100` (default 20), `--offset`; JSON includes `vaults` and optional `next_offset`|
284
+
|`kernel vaults get <vault>`| Get by ID or name |
285
+
|`kernel vaults delete <vault>`| Invalidate the vault and all its items; `--yes` skips confirmation |
286
+
|`kernel vaults wallets create <vault> <key> --provider link\|agentcard`| Connect/enroll a wallet; `--open` opens a returned HTTPS action URL; AgentCard optionally accepts `--user-id` for an already enrolled user in this organization |
287
+
|`kernel vaults wallets payment-methods <vault> <key>`| Fetch advertised live payment methods; JSON is the item with `expanded.payment_methods`|
288
+
|`kernel vaults cards create <vault> <key>`| Create a card request with the typed flags below; never implicitly authorize Link |
289
+
|`kernel vaults cards update <vault> <key>`| Replace the full card spec using the same flags; the API enforces state/provider constraints |
290
+
|`kernel vaults cards authorize <vault> <key>`| After explicit user approval, GET the requested Link card and POST `authorize` only if advertised; optional `--open`|
291
+
|`kernel vaults items list <vault>`| List item keys, types, providers, status, and required actions |
--context 'Purchase the selected office supplies from Example Shop for the approved order, with a total spending limit of 1234 minor currency units.' \
339
+
--test
340
+
```
341
+
342
+
3. After explicit user approval, authorize **only if the item advertises it**. Follow the
0 commit comments