You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 322acab
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: README.md
+51-9Lines changed: 51 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -397,9 +397,10 @@ cannot switch projects.
397
397
|`kernel vaults list`|`--limit 1..100` (default 20), `--offset`; JSON includes `vaults` and optional `next_offset`|
398
398
|`kernel vaults get <vault>`| Get by ID or name |
399
399
|`kernel vaults delete <vault>`| Invalidate the vault and all its items; `--yes` skips confirmation |
400
-
|`kernel vaults wallets create <vault> <key> --provider link\|agentcard --spec '<json>'`| Connect/enroll a wallet using its provider's spec; `--open` opens a returned HTTPS action URL |
400
+
|`kernel vaults wallets create <vault> <key> --provider link\|agentcard\|kernel --spec '<json>'`| Connect/enroll a wallet using its provider's spec; `--open` opens a returned HTTPS action URL |
401
+
|`kernel vaults wallets get <vault> <key>`| Observe wallet state and its hosted action; `--wait 0..60`, `--open`|
401
402
|`kernel vaults wallets payment-methods <vault> <key>`| Fetch advertised live payment methods; JSON is the item with `expanded.payment_methods`|
402
-
|`kernel vaults cards create <vault> <key> --provider link\|agentcard --spec '<json>'`| Create a card request; never implicitly authorize Link|
403
+
|`kernel vaults cards create <vault> <key> --provider link\|agentcard\|kernel --spec '<json>'`| Create a card request without authorizing it|
403
404
|`kernel vaults cards update <vault> <key> --provider link\|agentcard --spec '<json>'`| Update a card spec; pending issuance preserves omitted optional fields, and the API enforces state/provider constraints |
404
405
|`kernel vaults items list <vault>`| List item keys, types, providers, status, and required actions |
405
406
|`kernel vaults items get <vault> <key>`| Inspect state/actions/returned AgentCard aliases and copyable operation commands; `--wait 0..60`, `--expand payment_methods`, `--open`|
@@ -414,7 +415,8 @@ its generated item ID. Names and keys use letters, digits, dots, underscores, an
414
415
JSON preserves field presence and API-returned AgentCard aliases, while omitting unknown fields,
415
416
opaque metadata, and unrecognized event data. Human output labels aliases as non-secret
416
417
checkout values and distinguishes card readiness from checkout authorization/payment outcomes.
417
-
Link cards do not expose aliases or support egress substitution; browser checkout uses only `fill`.
418
+
Link and Kernel cards do not expose aliases or support egress substitution; browser checkout
419
+
uses only advertised `fill`.
418
420
Action and approval URLs print in full on separate lines, without table truncation.
419
421
Most API failures use the CLI's standard error formatter. Wallet creation and provider config
420
422
commands withhold response/transport details to prevent credential echoes; HTTP status remains visible.
@@ -425,23 +427,29 @@ Other API errors still return a nonzero exit status.
425
427
**Provider specifications:** wallet creation and card creation/update require `--provider`
426
428
and `--spec '<json>'`. Supply only the spec object, not a `{type, spec}` envelope. The command
427
429
sets the item type and injects `provider`; if JSON also contains `provider`, it must match.
428
-
Other values are forwarded unchanged, including optional fields, without defaults or normalization.
429
-
The API validates the provider-specific schema. Each command's `--help` includes its raw
430
+
Other non-secret values are forwarded unchanged, including optional fields, without defaults
431
+
or normalization. The API validates the provider-specific schema. Each command's `--help` includes its raw
430
432
TypeScript-style types, which must stay in sync with the [API spec](https://api.onkernel.com/spec.yaml).
431
433
434
+
-**Kernel wallet:** use `{}`; no provider configuration or token file is accepted. The hosted
435
+
`card_enrollment` action collects card details from the cardholder, never from the CLI.
0 commit comments