{"components":{"examples":{"ExampleAgentCardCard":{"summary":"Ready AgentCard item with prepared checkout enabled. Alias values are synthetic.","value":{"available_expansions":[],"available_operations":[{"description":"Prepare this unused AgentCard card before the first Square Pay action. POST to this item's operations endpoint with a body like {\"type\":\"prepare_checkout\",\"checkout\":{\"browser_id\":\"\u003cbrowser-session-id\u003e\",\"merchant_origin\":\"https://shop.example.com\",\"environment\":\"production\"}}. Use the active browser session with this vault bound. merchant_origin is the top-level merchant document's origin, not the Square iframe. environment must be production or sandbox and describes Square, not the AgentCard credential mode. Deliver the returned approval URL and keep the approval page open. Poll the item until ready_to_submit, then submit native Pay before preparation.expires_at; readiness lasts at most 30 seconds. Unused preparations expire automatically. Preparation is single-use, including after failure or expiry. Do not automatically retry; reconcile uncertain outcomes with the merchant.","type":"prepare_checkout"}],"created_at":"2026-01-01T12:00:00Z","id":"card_agentcard_example","key":"agentcard-card","spec":{"amount":2599,"card_id":"vc_example","currency":"usd","merchant":"Example Store","provider":"agentcard","wallet":"agentcard-wallet"},"state":{"aliases":{"cvc":"123","exp_month":"12","exp_year":"2030","number":"4242424242424242"},"provider":"agentcard","status":"ready"},"type":"card","updated_at":"2026-01-01T12:00:00Z"}},"ExampleAgentCardCardEdit":{"summary":"Set the reusable checkout card to USD 30.00 between authorizations","value":{"spec":{"amount":3000,"card_id":"vc_example","currency":"usd","merchant":"Example Store","provider":"agentcard","wallet":"agentcard-wallet"},"type":"card"}},"ExampleAgentCardCardInput":{"summary":"Create a reusable USD 25.99 card at key agentcard-card after its wallet connects","value":{"spec":{"amount":2599,"card_id":"vc_example","currency":"usd","merchant":"Example Store","provider":"agentcard","wallet":"agentcard-wallet"},"type":"card"}},"ExampleAgentCardCardUpdated":{"summary":"Updated checkout amount retains the same card identity and synthetic aliases","value":{"available_expansions":[],"available_operations":[],"created_at":"2026-01-01T12:00:00Z","id":"card_agentcard_example","key":"agentcard-card","spec":{"amount":3000,"card_id":"vc_example","currency":"usd","merchant":"Example Store","provider":"agentcard","wallet":"agentcard-wallet"},"state":{"aliases":{"cvc":"123","exp_month":"12","exp_year":"2030","number":"4242424242424242"},"provider":"agentcard","status":"ready"},"type":"card","updated_at":"2026-01-02T12:00:00Z"}},"ExampleAgentCardConfig":{"summary":"AgentCard configuration response with introspected live mode","value":{"client_id":"example-client-id","created_at":"2026-01-01T12:00:00Z","id":"vpc_agentcard_example","name":"my-agentcard","provider":"agentcard","test_mode":false,"updated_at":"2026-01-01T12:00:00Z"}},"ExampleAgentCardConfigRotated":{"summary":"Rotating the secret preserves client identity and mode","value":{"client_id":"example-client-id","created_at":"2026-01-01T12:00:00Z","id":"vpc_agentcard_example","name":"my-agentcard","provider":"agentcard","test_mode":false,"updated_at":"2026-01-02T12:00:00Z"}},"ExampleConfiguredAgentCardWallet":{"summary":"Hosted enrollment using a customer-owned configuration","value":{"action":{"name":"card_enrollment","url":"https://example.com/card-enrollment"},"available_expansions":[],"available_operations":[],"created_at":"2026-01-01T12:00:00Z","expires_at":"2026-01-01T13:00:00Z","id":"wallet_agentcard_example","key":"agentcard-wallet","spec":{"provider":"agentcard","provider_config":{"id":"vpc_agentcard_example"}},"state":{"provider":"agentcard","status":"pending_authorization"},"type":"wallet","updated_at":"2026-01-01T12:00:00Z"}},"ExampleImportedLinkWallet":{"summary":"Connected imported grant; tokens are absent from the response","value":{"available_expansions":[{"description":"List funding methods available to this wallet.","type":"payment_methods"}],"available_operations":[],"created_at":"2026-01-01T12:00:00Z","id":"wallet_imported_example","key":"imported-wallet","spec":{"authorization":{"client":{"provider_config":{"id":"vpc_link_example"},"type":"customer_managed"},"method":"oauth"},"provider":"link"},"state":{"provider":"link","status":"connected"},"type":"wallet","updated_at":"2026-01-01T12:00:00Z"}},"ExampleLinkApproval":{"summary":"Link authorization creates or resumes a spend awaiting cardholder approval","value":{"action":{"name":"spend_approval","url":"https://example.com/spend-approval"},"available_expansions":[],"available_operations":[{"description":"Resume this existing spend request without creating another payment.","type":"authorize"}],"created_at":"2026-01-01T12:00:00Z","expires_at":"2026-01-01T13:00:00Z","id":"card_link_example","key":"link-card","spec":{"amount":2599,"context":"Purchase one notebook for USD 25.99 including shipping and taxes. This is a new order at Example Store, not a retry of an earlier payment.","currency":"usd","merchant_name":"Example Store","merchant_url":"https://store.example.com","payment_method_id":"pm_example","provider":"link","wallet":"link-wallet"},"state":{"domains":["store.example.com"],"provider":"link","status":"pending_authorization"},"type":"card","updated_at":"2026-01-01T12:01:00Z"}},"ExampleLinkCard":{"summary":"Requested Link card; identical PUT returns the same item without authorization","value":{"available_expansions":[],"available_operations":[{"description":"Request cardholder approval for this payment.","type":"authorize"}],"created_at":"2026-01-01T12:00:00Z","id":"card_link_example","key":"link-card","spec":{"amount":2599,"context":"Purchase one notebook for USD 25.99 including shipping and taxes. This is a new order at Example Store, not a retry of an earlier payment.","currency":"usd","merchant_name":"Example Store","merchant_url":"https://store.example.com","payment_method_id":"pm_example","provider":"link","wallet":"link-wallet"},"state":{"provider":"link","status":"requested"},"type":"card","updated_at":"2026-01-01T12:00:00Z"}},"ExampleLinkCardEdit":{"summary":"Set an unapproved Link card request to USD 30.00","value":{"spec":{"amount":3000,"context":"The order total changed to USD 30.00 including shipping and taxes for one notebook. Update this unapproved request rather than creating a second payment.","currency":"usd","merchant_name":"Example Store","merchant_url":"https://store.example.com","payment_method_id":"pm_example","provider":"link","wallet":"link-wallet"},"type":"card"}},"ExampleLinkCardInput":{"summary":"Create a USD 25.99 request at key link-card after its wallet connects","value":{"spec":{"amount":2599,"context":"Purchase one notebook for USD 25.99 including shipping and taxes. This is a new order at Example Store, not a retry of an earlier payment.","currency":"usd","merchant_name":"Example Store","merchant_url":"https://store.example.com","payment_method_id":"pm_example","provider":"link","wallet":"link-wallet"},"type":"card"}},"ExampleLinkCardUpdated":{"summary":"Updated Link request retains its key and ID","value":{"available_expansions":[],"available_operations":[{"description":"Request cardholder approval for this payment.","type":"authorize"}],"created_at":"2026-01-01T12:00:00Z","id":"card_link_example","key":"link-card","spec":{"amount":3000,"context":"The order total changed to USD 30.00 including shipping and taxes for one notebook. Update this unapproved request rather than creating a second payment.","currency":"usd","merchant_name":"Example Store","merchant_url":"https://store.example.com","payment_method_id":"pm_example","provider":"link","wallet":"link-wallet"},"state":{"provider":"link","status":"requested"},"type":"card","updated_at":"2026-01-02T12:00:00Z"}},"ExampleLinkConfig":{"summary":"Link configuration response; no secret credentials","value":{"client_id":"example-client-id","created_at":"2026-01-01T12:00:00Z","id":"vpc_link_example","name":"my-link-client","provider":"link","publishable_key":"pk_live_example","updated_at":"2026-01-01T12:00:00Z"}},"ExampleLinkConfigRenamed":{"summary":"Renaming preserves the configuration ID and wallet bindings","value":{"client_id":"example-client-id","created_at":"2026-01-01T12:00:00Z","id":"vpc_link_example","name":"renamed-link-client","provider":"link","publishable_key":"pk_live_example","updated_at":"2026-01-02T12:00:00Z"}},"ExampleManagedAgentCardWallet":{"summary":"Hosted enrollment using Kernel-managed credentials at key agentcard-wallet","value":{"action":{"name":"card_enrollment","url":"https://example.com/card-enrollment"},"available_expansions":[],"available_operations":[],"created_at":"2026-01-01T12:00:00Z","expires_at":"2026-01-01T13:00:00Z","id":"wallet_managed_agentcard_example","key":"agentcard-wallet","spec":{"provider":"agentcard"},"state":{"provider":"agentcard","status":"pending_authorization"},"type":"wallet","updated_at":"2026-01-01T12:00:00Z"}},"ExampleManagedLinkWallet":{"summary":"Pending OAuth through Kernel-managed credentials at key link-wallet","value":{"action":{"name":"link_oauth","url":"https://example.com/link-authorization"},"available_expansions":[],"available_operations":[],"created_at":"2026-01-01T12:00:00Z","expires_at":"2026-01-01T12:10:00Z","id":"wallet_link_example","key":"link-wallet","spec":{"authorization":{"client":{"type":"kernel_managed"},"method":"oauth"},"provider":"link"},"state":{"provider":"link","status":"pending_authorization"},"type":"wallet","updated_at":"2026-01-01T12:00:00Z"}},"ExampleVault":{"summary":"Provider-neutral vault; an identical name returns this same vault","value":{"created_at":"2026-01-01T12:00:00Z","id":"vault_example","name":"checkout","updated_at":"2026-01-01T12:00:00Z"}}},"responses":{"BadRequest":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Bad Request – invalid input"},"BrowserProxyError":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InstanceProxyError"}}},"description":"Error returned by the browser or its proxy"},"CapacityExhausted":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Capacity exhausted, unable to fulfill request at this time"},"Conflict":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Conflict – resource already exists"},"Forbidden":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Forbidden – insufficient permissions or plan"},"Gone":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Resource expired or no longer available"},"InternalError":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"},"NotFound":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Resource not found"},"SearchProviderError":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Search providers could not complete the request. Details contain\nper-attempt failure codes and provider names.\n"},"SearchTimeout":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Overall deadline exceeded before a search response was available."},"SearchUnavailable":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"No provider is currently available for the request."},"ServiceUnavailable":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Service unavailable"},"TooManyRequests":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Too Many Requests – rate limit exceeded","headers":{"Retry-After":{"description":"Seconds to wait before retrying","schema":{"type":"integer"}}}},"Unauthorized":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Unauthorized – missing or invalid authorization token"},"UnprocessableEntity":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Unprocessable Entity – request was valid but the operation failed"}},"schemas":{"AddCustomWebMCPToolsRequest":{"additionalProperties":false,"properties":{"force_overwrite_namespace":{"default":false,"description":"Atomically replace all existing tools in this namespace with this batch when true.","type":"boolean"},"namespace":{"pattern":"^[A-Za-z0-9_.-]{1,128}$","type":"string"},"source":{"description":"JavaScript expression that evaluates to a non-empty array of custom tool definitions. Limited to 8,000,000 bytes when UTF-8 encoded, so multi-byte characters reduce the allowed character count.","maxLength":8000000,"type":"string"}},"required":["namespace","source"],"type":"object"},"AgentCardCardState":{"additionalProperties":false,"properties":{"aliases":{"$ref":"#/components/schemas/VaultCardAliases"},"authorization":{"$ref":"#/components/schemas/AgentCardCheckoutAuthorization"},"masks":{"$ref":"#/components/schemas/VaultItemMasks"},"preparation":{"$ref":"#/components/schemas/AgentCardCheckoutPreparation"},"provider":{"enum":["agentcard"],"type":"string"},"status":{"description":"ready_to_submit is device readiness for at most 30 seconds. consumed means the prepared attempt has settled, not that an order succeeded. stopped cannot be reused. outcome_unknown requires merchant reconciliation and blocks new requests. recovery_required means the original checkout outcome is unresolved. Automatic reuse is blocked. Known authorization IDs must be reconciled through provider observations or support. When no authorization ID was returned, an explicitly confirmed item deletion may abandon the unresolved attempt so the caller can create a replacement; deletion does not prove that the original attempt failed. It does not mean declined or expired.","enum":["requested","ready","preparing","ready_to_submit","pending_approval","consumed","stopped","outcome_unknown","degraded","recovery_required"],"type":"string"},"status_reason":{"type":"string"}},"required":["provider","status"],"type":"object"},"AgentCardCardVaultItemSpec":{"additionalProperties":false,"description":"AgentCard reusable live payment card. Test-mode card creation is not supported. Each checkout creates an authorization for spec.merchant / spec.amount that the cardholder approves, unless AgentCard runs it under one of the cardholder's autopilot rules. The card stays ready after each authorization.","properties":{"amount":{"description":"Integer amount in minor currency units.","format":"int64","maximum":9007199254740991,"minimum":1,"type":"integer"},"card_id":{"description":"Opaque card ID returned by AgentCard for a card in the connected wallet. Pass it through unchanged without assuming a prefix or format. Omitted, the cardholder picks on the approval screen.","maxLength":256,"minLength":1,"type":"string"},"checkout_origin":{"description":"Origin of the top-level checkout page, such as https://shop.example.com: https, a lowercase host, a port only when it is not 443, and no path. http is accepted only for localhost test pages. Checkouts without a preparation send it to AgentCard, which uses it to match the cardholder's autopilot rules; prepared checkouts send the preparation's merchant_origin instead. Kernel sends the declared value and does not compare it with the page the browser has open. Omitted, those checkouts ask the cardholder to approve. Card updates replace the whole spec, so an update that omits it removes it.","minLength":1,"type":"string"},"currency":{"maxLength":3,"minLength":3,"pattern":"^[A-Za-z]{3}$","type":"string"},"merchant":{"description":"Merchant name shown on the cardholder's approval screen.","maxLength":120,"minLength":1,"type":"string"},"provider":{"enum":["agentcard"],"type":"string"},"wallet":{"description":"Wallet item key used to authorize checkouts.","type":"string"}},"required":["provider","wallet","merchant","amount","currency"],"type":"object"},"AgentCardCheckoutAuthorization":{"additionalProperties":false,"description":"The in-flight or most recent checkout authorization. Present while a checkout is pending approval and after it settles.","properties":{"actual_cents":{"format":"int64","type":"integer"},"amount":{"description":"Display amount shown on the approval screen.","type":"string"},"amount_authority":{"enum":["display_only","stripe_payment_intent"],"type":"string"},"amount_cents":{"format":"int64","type":"integer"},"amount_verified":{"type":"boolean"},"approval_url":{"format":"uri","type":"string"},"browser_id":{"description":"Browser session that submitted the checkout.","type":"string"},"charged_amount_cents":{"format":"int64","type":"integer"},"charged_currency":{"type":"string"},"charged_kind":{"enum":["captured","authorized","none"],"type":"string"},"created_at":{"format":"date-time","type":"string"},"currency":{"type":"string"},"expected_cents":{"format":"int64","type":"integer"},"expires_at":{"format":"date-time","type":"string"},"id":{"type":"string"},"merchant":{"type":"string"},"psp":{"type":"string"},"psp_error_code":{"type":"string"},"reason":{"type":"string"},"replay_attempted":{"type":"boolean"},"replay_delivered":{"description":"Whether the processor response was delivered to the browser.","type":"boolean"},"replay_status":{"description":"HTTP status of the replayed processor response.","type":"integer"},"status":{"enum":["awaiting_approval","approved","declined","expired"],"type":"string"}},"required":["id","status","psp","merchant","amount_cents","currency","created_at"],"type":"object"},"AgentCardCheckoutPreparation":{"additionalProperties":false,"description":"One-use processor-bound checkout preparation. Keep the approval page open through device handoff, including Adyen encryption. The amount is declared by the caller and does not constrain the merchant's eventual charge. Adyen device approval and browser Authorised responses are not capture or fulfillment evidence.","properties":{"approval_url":{"format":"uri","type":"string"},"browser_id":{"type":"string"},"created_at":{"format":"date-time","type":"string"},"environment":{"enum":["production","sandbox","shared"],"type":"string"},"expires_at":{"description":"When ready, the absolute deadline to submit the first native request; no later than provider readiness expiry or 30 seconds after Kernel first observes readiness. Polling never extends this deadline.","format":"date-time","type":"string"},"id":{"type":"string"},"merchant_origin":{"type":"string"},"psp":{"$ref":"#/components/schemas/AgentCardPreparedProcessor"},"status":{"description":"Preparation consumed means egress claimed the preparation and it cannot be reused. It does not mean the attempt settled. Use the enclosing item's status as the lifecycle indicator; item consumed means the attempt settled, not that an order or charge succeeded.","enum":["creating","awaiting_approval","ready","consumed","cancelled","expired","unknown"],"type":"string"}},"required":["status","browser_id","merchant_origin","psp","environment","created_at"],"type":"object"},"AgentCardPreparedProcessor":{"enum":["square","braintree","worldpay","bambora","mercado_pago","adyen"],"type":"string"},"AgentCardWalletState":{"additionalProperties":false,"properties":{"provider":{"enum":["agentcard"],"type":"string"},"status":{"enum":["pending_authorization","connected","degraded"],"type":"string"},"status_reason":{"type":"string"},"user_id":{"description":"AgentCard user id linked to this wallet. Present once connected.","type":"string"}},"required":["provider","status"],"type":"object"},"AgentCardWalletVaultItemSpec":{"additionalProperties":false,"description":"AgentCard wallet. Omit provider_config to use Kernel-managed credentials, or select a customer-owned configuration. Mode (sandbox vs live) is determined by the selected credential; there is no per-item test flag. Without user_id, creation returns a hosted enrollment action and Kernel polls until the user connects. user_id may only reference a user already enrolled by a wallet in this organization under the same configuration.","properties":{"provider":{"enum":["agentcard"],"type":"string"},"provider_config":{"$ref":"#/components/schemas/VaultProviderConfigReference","description":"Select an AgentCard configuration. The wallet's configuration cannot be changed after creation."},"user_id":{"pattern":"^usr_[A-Za-z0-9_]+$","type":"string"}},"required":["provider"],"type":"object"},"ApiKey":{"properties":{"created_at":{"description":"When the API key was created","format":"date-time","type":"string"},"created_by":{"$ref":"#/components/schemas/ApiKeyCreator"},"deleted_at":{"description":"When the API key was deleted (soft-deleted). Null for keys that have not been deleted.","format":"date-time","nullable":true,"type":"string"},"expires_at":{"description":"When the API key expires","format":"date-time","nullable":true,"type":"string"},"id":{"description":"Unique API key identifier","example":"ckv9w8q2f000001l5r3j7k9m4","type":"string"},"masked_key":{"description":"Masked version of the API key","example":"sk_1234...abcd","type":"string"},"name":{"description":"Label for the API key. API keys are not addressable by name; use the ID or key identifier for stable references.","example":"production","type":"string"},"project_id":{"description":"Project identifier for project-scoped API keys. Null means org-wide.","example":"proj_abc123","nullable":true,"type":"string"},"project_name":{"description":"Project name for project-scoped API keys. Null means the key is org-wide or the project name is unavailable.","example":"Production","nullable":true,"type":"string"}},"required":["id","name","created_at","created_by","expires_at","deleted_at","project_id","project_name","masked_key"],"type":"object"},"ApiKeyCreator":{"properties":{"email":{"description":"Email address of the creator.","example":"user@example.com","format":"email","type":"string"},"id":{"description":"Kernel user ID of the creator.","example":"user-abc123","type":"string"},"name":{"description":"Display name of the creator, if available.","example":"Jane Doe","nullable":true,"type":"string"}},"required":["id","email","name"],"type":"object"},"AppAction":{"description":"An action available on the app","properties":{"input_schema":{"additionalProperties":true,"description":"JSON Schema (draft-07) describing the expected input payload. Null if schema could not be automatically generated.","nullable":true,"type":"object"},"name":{"description":"Name of the action","example":"analyze","type":"string"},"output_schema":{"additionalProperties":true,"description":"JSON Schema (draft-07) describing the expected output payload. Null if schema could not be automatically generated.","nullable":true,"type":"object"}},"required":["name"],"type":"object"},"AppVersionSummary":{"description":"Summary of an application version.","properties":{"actions":{"description":"List of actions available on the app","items":{"$ref":"#/components/schemas/AppAction"},"type":"array"},"app_name":{"description":"Name of the application","example":"my-app","type":"string"},"deployment":{"description":"Deployment ID","type":"string"},"env_vars":{"additionalProperties":{"type":"string"},"description":"Environment variables configured for this app version. Values are redacted for API key, OAuth, and managed-auth callers, which receive every key with an empty string value. Only dashboard sessions receive the actual values.","type":"object"},"id":{"description":"Unique identifier for the app version","example":"rr33xuugxj9h0bkf1rdt2bet","type":"string"},"region":{"const":"aws.us-east-1a","description":"Deployment region code","example":"aws.us-east-1a","type":"string"},"version":{"description":"Version label for the application","example":"1.0.0","type":"string"}},"required":["id","app_name","version","region","deployment","actions","env_vars"],"type":"object"},"AppVersionSummaryEvent":{"description":"Summary of an application version.","properties":{"actions":{"description":"List of actions available on the app","items":{"$ref":"#/components/schemas/AppAction"},"type":"array"},"app_name":{"description":"Name of the application","example":"my-app","type":"string"},"env_vars":{"additionalProperties":{"type":"string"},"description":"Environment variables configured for this app version. Not currently populated on streamed app_version_summary events.","type":"object"},"event":{"const":"app_version_summary","description":"Event type identifier (always \"app_version_summary\").","type":"string"},"id":{"description":"Unique identifier for the app version","example":"rr33xuugxj9h0bkf1rdt2bet","type":"string"},"region":{"const":"aws.us-east-1a","description":"Deployment region code","example":"aws.us-east-1a","type":"string"},"timestamp":{"description":"Time the state was reported.","format":"date-time","type":"string"},"version":{"description":"Version label for the application","example":"1.0.0","type":"string"}},"required":["event","timestamp","id","app_name","version","region","actions"],"type":"object"},"AuditLogEntry":{"properties":{"auth_strategy":{"description":"Authentication strategy used for the request.","type":"string"},"client_ip":{"description":"Client IP address.","type":"string"},"domain":{"description":"Request host.","type":"string"},"duration_ms":{"description":"Request duration in milliseconds.","type":"integer"},"email":{"description":"Email of the authenticated user at request time, if any.","type":"string"},"method":{"description":"HTTP method.","type":"string"},"path":{"description":"Request path.","type":"string"},"route":{"description":"Matched API route pattern, if available.","type":"string"},"status":{"description":"HTTP response status code.","type":"integer"},"timestamp":{"description":"UTC time when the request was received.","format":"date-time","type":"string"},"user_agent":{"description":"User agent header.","type":"string"},"user_id":{"description":"ID of the authenticated user, if any.","type":"string"}},"required":["timestamp","auth_strategy","user_id","email","status","method","path","route","domain","duration_ms","client_ip","user_agent"],"type":"object"},"AuditLogExportDestination":{"additionalProperties":false,"description":"An organization-scoped audit log export destination.\n\nDelivery is at-least-once for rows visible when their window is committed: a delivery that is retried rewrites the same object, and the same `event_id` can appear in more than one object, so consumers must deduplicate on `event_id`. Each event-time window is held for ten minutes before it commits; a row that becomes visible after its window is committed may not be delivered.\n\nObjects are written as `\u003cprefix\u003e/destination_id=\u003cdestination\u003e/org_id=\u003corg\u003e/date=\u003cYYYY-MM-DD\u003e/hour=\u003cHH\u003e/\u003cwindow\u003e-\u003cchunk\u003e.jsonl.gz`, where `date` and `hour` are the UTC calendar hour that fully contains every row in the object, so the layout is safe to register as a Hive-partitioned table. The object name is derived from the rows it holds, so a retried delivery rewrites its own object.","properties":{"bucket":{"maxLength":63,"minLength":3,"type":"string"},"consecutive_failures":{"minimum":0,"readOnly":true,"type":"integer","x-go-type-skip-optional-pointer":true,"x-omitempty":false},"created_at":{"format":"date-time","readOnly":true,"type":"string","x-go-type-skip-optional-pointer":true},"external_id":{"maxLength":128,"readOnly":true,"type":"string","x-go-type-skip-optional-pointer":true},"format":{"enum":["jsonl.gz"],"type":"string"},"id":{"maxLength":128,"readOnly":true,"type":"string","x-go-type-skip-optional-pointer":true},"kernel_role_arn":{"description":"The Kernel role that assumes `role_arn` in your account to deliver logs. Allow this role as the principal in your role's trust policy, and require `external_id` as the `sts:ExternalId` condition.\n\nRecreating a destination issues a new `external_id`, which the trust policy has to be updated to match.","maxLength":2048,"readOnly":true,"type":"string","x-go-type-skip-optional-pointer":true},"kms_key_id":{"maxLength":2048,"type":"string"},"last_error":{"description":"Sanitized description of the most recent delivery failure.","readOnly":true,"type":"string"},"last_error_at":{"format":"date-time","readOnly":true,"type":"string"},"last_exported_cursor":{"description":"Opaque, versioned checkpoint for forward-only continuous export. This value is not compatible with audit-log list page tokens.\n\nDelivery starts at the moment the destination is activated, so events recorded before that are not delivered. Pausing stops delivery and resuming starts again from the time of the resume: events recorded while a destination was paused are never exported, and pausing is not a way to defer delivery.","readOnly":true,"type":"string"},"last_success_at":{"format":"date-time","readOnly":true,"type":"string"},"next_attempt_at":{"format":"date-time","readOnly":true,"type":"string"},"prefix":{"maxLength":512,"type":"string"},"region":{"maxLength":128,"minLength":1,"type":"string"},"role_arn":{"maxLength":2048,"minLength":1,"type":"string"},"status":{"description":"Pausing prevents new delivery attempts. An S3 upload already in progress may complete after the pause response; its rows can appear again after the destination is resumed.","enum":["active","paused"],"type":"string"},"type":{"enum":["s3"],"type":"string"},"updated_at":{"format":"date-time","readOnly":true,"type":"string","x-go-type-skip-optional-pointer":true}},"required":["id","type","region","bucket","prefix","role_arn","external_id","kernel_role_arn","format","status","consecutive_failures","created_at","updated_at"],"type":"object"},"AuditLogExportDestinationTestResult":{"additionalProperties":false,"properties":{"error":{"additionalProperties":false,"properties":{"code":{"enum":["assume_role_failed","put_object_failed"],"type":"string"},"message":{"type":"string"}},"required":["code","message"],"type":"object"},"stage":{"enum":["assume_role","put_object","complete"],"type":"string"},"success":{"type":"boolean"}},"required":["success","stage"],"type":"object"},"AuthContext":{"description":"The identity and authorization context resolved for the current request.","properties":{"authentication":{"$ref":"#/components/schemas/AuthContextAuthentication"},"authorization":{"$ref":"#/components/schemas/AuthContextAuthorization"},"organization":{"$ref":"#/components/schemas/AuthContextOrganization"},"principal":{"$ref":"#/components/schemas/AuthContextPrincipal"}},"required":["authentication","principal","organization","authorization"],"type":"object"},"AuthContextAuthentication":{"properties":{"credential_id":{"description":"The API key ID when authenticated with an API key; null for session credentials.","type":["string","null"]},"method":{"description":"The credential format used to authenticate the request.","enum":["api_key","jwt"],"type":"string"},"source":{"description":"The source classification resolved by authentication middleware.","enum":["api_key","oauth","dashboard"],"type":"string"}},"required":["method","source","credential_id"],"type":"object"},"AuthContextAuthorization":{"description":"The credential's maximum scope and the effective scope selected for this request. Future permission data can be added without changing scope semantics.","properties":{"credential_scope":{"$ref":"#/components/schemas/AuthContextScope"},"effective_scope":{"$ref":"#/components/schemas/AuthContextScope"}},"required":["credential_scope","effective_scope"],"type":"object"},"AuthContextOrganization":{"properties":{"id":{"description":"The authenticated Kernel organization ID.","type":"string"}},"required":["id"],"type":"object"},"AuthContextPrincipal":{"properties":{"id":{"description":"The API key ID for API-key principals or user ID for user principals.","type":"string"},"type":{"description":"The kind of principal authenticated for the request.","enum":["api_key","user"],"type":"string"}},"required":["type","id"],"type":"object"},"AuthContextScope":{"description":"A scope within the authenticated organization. A null project_id represents organization-wide scope.","properties":{"project_id":{"description":"The Kernel project ID, or null when the scope is organization-wide.","type":["string","null"]}},"required":["project_id"],"type":"object"},"AuthorizeVaultItemOperationRequest":{"additionalProperties":false,"description":"Authorize a Link card using its existing purchase specification. Use only after explicit user approval and when the item advertises authorize. Do not automatically retry provider failures or indeterminate outcomes. Checkout context is not accepted.","properties":{"type":{"enum":["authorize"],"type":"string","x-go-type":"VaultItemOperationType"}},"required":["type"],"type":"object"},"AvailableVaultItemExpansion":{"additionalProperties":false,"description":"Live data that can currently be requested by passing its type to the item GET expand parameter.","properties":{"description":{"type":"string"},"type":{"$ref":"#/components/schemas/VaultItemExpansionType"}},"required":["type","description"],"type":"object"},"AvailableVaultItemOperation":{"additionalProperties":false,"description":"An operation that is currently valid for this item. Read the description before invoking it through the item operations endpoint.","properties":{"description":{"type":"string"},"type":{"$ref":"#/components/schemas/VaultItemOperationType"}},"required":["type","description"],"type":"object"},"BatchComputerActionRequest":{"additionalProperties":false,"description":"A batch of computer actions to execute sequentially.","properties":{"actions":{"description":"Ordered list of actions to execute. Execution stops on the first error.","items":{"$ref":"#/components/schemas/ComputerAction"},"maxItems":100,"minItems":1,"type":"array"}},"required":["actions"],"type":"object"},"Browser":{"properties":{"base_url":{"description":"Metro-API HTTP base URL for this browser session.","example":"https://proxy.yul-upbeat-herschel.onkernel.com:8443/browser/kernel","type":"string"},"browser_live_view_url":{"description":"Remote URL for live viewing the browser session. Only available for non-headless browsers.","example":"https://proxy.yul-upbeat-herschel.onkernel.com:8443/browser/live?jwt=eyJ0eXAi...","type":"string"},"cdp_ws_url":{"description":"Websocket URL for Chrome DevTools Protocol connections to the browser session","example":"wss://proxy.yul-upbeat-herschel.onkernel.com:8443/browser/cdp?jwt=eyJ0eXAi...","type":"string"},"chrome_policy":{"additionalProperties":true,"description":"Custom Chrome enterprise policy overrides that were applied to this browser session, if any. Echoed back for verification. Keys are Chrome enterprise policy names.\n","type":"object"},"created_at":{"description":"When the browser session was created.","format":"date-time","type":"string"},"deleted_at":{"description":"When the browser session was soft-deleted. Only present for deleted sessions.","format":"date-time","type":"string"},"gpu":{"description":"Whether GPU acceleration is enabled for the browser session (only supported for headful sessions).","example":false,"type":"boolean"},"headless":{"description":"Whether the browser session is running in headless mode.","example":false,"type":"boolean"},"kiosk_mode":{"description":"Whether the browser session is running in kiosk mode.","example":false,"type":"boolean"},"memory":{"$ref":"#/components/schemas/BrowserMemory","description":"Memory allocated to the browser session."},"name":{"description":"Human-readable name of the browser session, if one was set at creation.","example":"checkout-flow-1","type":"string"},"network":{"$ref":"#/components/schemas/BrowserNetworkConfig","description":"Network configuration the session was created with, if any. Omitted when the session has no network configuration."},"pool":{"$ref":"#/components/schemas/BrowserPoolRef"},"profile":{"$ref":"#/components/schemas/Profile"},"profile_save_changes":{"description":"Whether changes made during this browser session are saved back to its profile when the session ends. Omitted when no profile is attached.","type":"boolean"},"proxy":{"$ref":"#/components/schemas/BrowserProxy","description":"Resolved proxy configuration for this browser session."},"proxy_id":{"deprecated":true,"description":"ID of the proxy associated with this browser session, if any. Deprecated in favor of proxy.","type":"string","x-deprecated-reason":"Use proxy instead."},"region":{"$ref":"#/components/schemas/Region","description":"Geographic region of the browser session. Fixed once the session is created.\n"},"session_id":{"description":"Unique identifier for the browser session","example":"htzv5orfit78e1m2biiifpbv","type":"string"},"start_url":{"description":"URL the session was most recently asked to navigate to, if any. Recorded for debugging. Navigation is fire-and-forget — the URL is dispatched to the browser without waiting for it to load, and any errors (DNS failure, bad status, timeout) are silently dropped. Captures what was requested, not what the browser actually loaded.","example":"https://example.com","type":"string"},"stealth":{"description":"Whether the browser session is running in stealth mode.","example":false,"type":"boolean"},"tags":{"$ref":"#/components/schemas/Tags","description":"User-defined key-value tags that were set on this browser session, if any. Echoed back when present."},"telemetry":{"$ref":"#/components/schemas/BrowserTelemetryConfig","description":"Active telemetry configuration for the session, if any.","nullable":true},"timeout_seconds":{"description":"The number of seconds of inactivity before the browser session is terminated.","type":"integer"},"usage":{"$ref":"#/components/schemas/BrowserUsage"},"usage_status":{"$ref":"#/components/schemas/BrowserUsageStatus"},"vaults":{"description":"Vaults linked when the browser session was created.","items":{"$ref":"#/components/schemas/VaultReference"},"type":"array"},"viewport":{"$ref":"#/components/schemas/BrowserViewport"},"webdriver_ws_url":{"description":"Websocket URL for WebDriver BiDi connections to the browser session","example":"wss://proxy.yul-upbeat-herschel.onkernel.com:8443/browser/webdriver/session?jwt=eyJ0eXAi...","type":"string"}},"required":["created_at","cdp_ws_url","webdriver_ws_url","session_id","region","stealth","headless","memory","timeout_seconds"],"type":"object"},"BrowserApiCallEvent":{"description":"An agent-driven HTTP call that drives the browser, handled by the in-VM API server. Calls that manage the VM instead emit platform_api_call.","properties":{"category":{"const":"control","type":"string"},"data":{"additionalProperties":false,"properties":{"code":{"description":"Source submitted to the Playwright code-execution endpoint, capped at 8192 bytes like every other captured string. A capped value is cut on a character boundary and ends in `...[truncated]`. Absent for every other operation.","type":"string"},"duration_ms":{"description":"Wall-clock duration of the handler in milliseconds.","type":"number"},"operation_id":{"description":"Matched route's operation, named as the in-VM API names its handler (e.g. ProcessExec, TakeScreenshot).","type":"string"},"request_id":{"description":"Per-request identifier from the in-VM API request middleware.","type":"string"},"status":{"description":"HTTP response status code.","type":"integer"}},"required":["request_id","operation_id","status","duration_ms"],"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"api_call","type":"string"}},"required":["ts","type","category","source"],"type":"object"},"BrowserCallStack":{"description":"CDP Runtime.StackTrace representing the JavaScript call stack at the time of an event. Fields use CDP naming conventions rather than snake_case to match the Chrome DevTools Protocol wire format.","properties":{"callFrames":{"description":"Ordered list of call frames, outermost first.","items":{"properties":{"columnNumber":{"description":"Zero-based column number within the line.","type":"integer"},"functionName":{"description":"JavaScript function name, or empty string for anonymous functions.","type":"string"},"lineNumber":{"description":"Zero-based line number within the script.","type":"integer"},"scriptId":{"description":"CDP script identifier.","type":"string"},"url":{"description":"URL or name of the script file.","type":"string"}},"required":["functionName","scriptId","url","lineNumber","columnNumber"],"type":"object"},"type":"array"},"description":{"description":"Optional label for the stack trace (e.g. async cause).","type":"string"},"parent":{"$ref":"#/components/schemas/BrowserCallStack","description":"Parent stack trace for async stacks."}},"required":["callFrames"],"type":"object"},"BrowserCaptchaChallengeID":{"description":"Opaque identifier shared by events for one visible challenge. An image-grid captcha may create multiple task_id values for one challenge_id. The same value may continue across a page reload when the challenge episode continues. It does not indicate task ordering or challenge completion.","type":"string"},"BrowserCaptchaChallengeResultEvent":{"description":"A visible captcha challenge reached a terminal outcome.","properties":{"category":{"const":"captcha","type":"string","x-enum-varnames":["BrowserCaptchaChallengeResultEventCategoryCaptcha"]},"data":{"additionalProperties":false,"description":"Per-challenge payload. This event is emitted once per challenge and determines its overall outcome; captcha_solve_started and captcha_solve_result describe individual tasks and may occur multiple times within the challenge.","properties":{"captcha_type":{"$ref":"#/components/schemas/BrowserCaptchaType"},"challenge_id":{"$ref":"#/components/schemas/BrowserCaptchaChallengeID"},"duration_ms":{"description":"Wall-clock duration from the challenge appearing to its terminal outcome, covering every solver attempt in between.","type":"number"},"status":{"description":"Terminal outcome of the visible challenge. solved: the page observed the challenge clear after a solver attempt. failure: a terminal solver failure occurred, or all attempts ended while the challenge remained. timeout: the challenge-level wait budget expired while the challenge remained. abandoned: observation ended without an attributable terminal challenge outcome. This includes a dismissed widget or page unload without a solved signal or terminal solver outcome, and a token appearing while multiple same-provider challenges are open, because the producer cannot attribute that token to this visible challenge. A captcha_solve_result with the same challenge_id may therefore report success while the challenge result reports abandoned. A solved challenge does not prove the site accepted the token or that the guarded action succeeded.","enum":["solved","failure","timeout","abandoned"],"type":"string","x-enum-varnames":["ChallengeSolved","ChallengeFailure","ChallengeTimeout","ChallengeAbandoned"]},"website_host":{"description":"Host of the page where the challenge appeared.","type":"string"},"website_path":{"description":"Path of the page where the challenge appeared. Query string excluded.","type":"string"}},"required":["captcha_type","status","challenge_id","duration_ms"],"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"captcha_challenge_result","type":"string"}},"required":["ts","type","category","source","data"],"type":"object"},"BrowserCaptchaSolveResultEvent":{"description":"A captcha solve attempt reached a terminal outcome.","properties":{"category":{"const":"captcha","type":"string"},"data":{"additionalProperties":false,"properties":{"captcha_type":{"$ref":"#/components/schemas/BrowserCaptchaType"},"challenge_id":{"$ref":"#/components/schemas/BrowserCaptchaChallengeID"},"duration_ms":{"description":"Wall-clock duration from solve start to terminal outcome. Authoritative solve timing; do not derive it from the gap to a captcha_solve_started event, whose delivery and ordering are not guaranteed.","type":"number"},"error_code":{"description":"Solver-specific error code on failure (e.g. ERROR_CAPTCHA_UNSOLVABLE). Absent on success.","type":"string"},"status":{"description":"Terminal outcome. success: solver returned a usable solution. failure: solver returned an error (see error_code). timeout: solver did not return within the caller's wait budget. abandoned: caller cancelled or the page navigated away mid-solve.","enum":["success","failure","timeout","abandoned"],"type":"string","x-go-type":"string"},"task_id":{"description":"Opaque identifier shared with the matching captcha_solve_started.","type":"string"},"website_host":{"description":"Host of the page where the captcha was solved.","type":"string"},"website_path":{"description":"Path of the page where the captcha was solved. Query string excluded.","type":"string"}},"required":["captcha_type","status","duration_ms"],"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"captcha_solve_result","type":"string"}},"required":["ts","type","category","source"],"type":"object"},"BrowserCaptchaSolveStartedEvent":{"description":"A captcha solver accepted a task.","properties":{"category":{"const":"captcha","type":"string","x-enum-varnames":["BrowserCaptchaSolveStartedEventCategoryCaptcha"]},"data":{"additionalProperties":false,"description":"Per-task payload. A visible challenge may create multiple tasks. When present, task_id correlates this event with a captcha_solve_result, while challenge_id groups tasks from the same challenge. Events may arrive out of order or be absent, so their arrival does not indicate current solve state.","properties":{"captcha_type":{"$ref":"#/components/schemas/BrowserCaptchaType"},"challenge_id":{"$ref":"#/components/schemas/BrowserCaptchaChallengeID"},"task_id":{"description":"Opaque identifier shared with the matching captcha_solve_result.","type":"string"},"website_host":{"description":"Host of the page where the captcha is being solved. May be empty for solver tasks that carry no page URL.","type":"string"},"website_path":{"description":"Path of the page where the captcha is being solved. Query string excluded.","type":"string"}},"required":["captcha_type"],"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"captcha_solve_started","type":"string"}},"required":["ts","type","category","source","data"],"type":"object"},"BrowserCaptchaType":{"description":"Captcha kind. Enterprise reCAPTCHA variants are grouped into their version bucket (recaptcha_v2 or recaptcha_v3), press-and-hold challenges use press_and_hold, and unlisted kinds use other.","enum":["hcaptcha","recaptcha_v2","recaptcha_v3","turnstile","geetest","press_and_hold","other"],"type":"string","x-go-type":"string"},"BrowserCdpAutofillMode":{"description":"Which kind of value autofill filled. Canonical values from devtools-protocol@2d019e73.\n","enum":["card","address"],"type":"string"},"BrowserCdpAutofillTriggerCommandData":{"additionalProperties":false,"description":"Sanitized `Autofill.trigger` arguments. Canonical input: `Autofill.trigger` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"address_field_count":{"description":"Number of address fields the command filled. Their names and values are never captured.\n","type":"integer"},"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"field_id":{"description":"Opaque backend node identifier of the field that was autofilled.\n","type":"integer"},"frame_id":{"description":"Opaque frame identifier. Clipped to 128 characters; a longer value is not a real identifier.\n","maxLength":128,"type":"string"},"method":{"const":"Autofill.trigger","type":"string"},"mode":{"$ref":"#/components/schemas/BrowserCdpAutofillMode","description":"What was filled: `card` or `address`. The values themselves are never captured.\n"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method","field_id"],"type":"object"},"BrowserCdpBrowserCancelDownloadCommandData":{"additionalProperties":false,"description":"Sanitized `Browser.cancelDownload` arguments. Canonical input: `Browser.cancelDownload` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"browser_context_id":{"description":"Opaque browser context identifier. Clipped to 128 characters; a longer value is not a real identifier.\n","maxLength":128,"type":"string"},"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"download_guid":{"description":"Opaque identifier of the download that was cancelled. Clipped to 128 characters; a longer value is not a real identifier.\n","maxLength":128,"type":"string"},"method":{"const":"Browser.cancelDownload","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method","download_guid"],"type":"object"},"BrowserCdpBrowserCloseCommandData":{"additionalProperties":false,"description":"Sanitized `Browser.close` arguments. Canonical input: `Browser.close` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"Browser.close","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method"],"type":"object"},"BrowserCdpBrowserSetContentsSizeCommandData":{"additionalProperties":false,"description":"Sanitized `Browser.setContentsSize` arguments. Canonical input: `Browser.setContentsSize` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"height":{"description":"Contents height in DIP.\n","type":"integer"},"method":{"const":"Browser.setContentsSize","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"width":{"description":"Contents width in DIP.\n","type":"integer"},"window_id":{"description":"Browser window identifier.\n","type":"integer"}},"required":["method","window_id"],"type":"object"},"BrowserCdpBrowserSetWindowBoundsCommandData":{"additionalProperties":false,"description":"Sanitized `Browser.setWindowBounds` arguments. Canonical input: `Browser.setWindowBounds` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"height":{"description":"Window height in DIP.\n","type":"integer"},"left":{"description":"Window x position in screen coordinates.\n","type":"integer"},"method":{"const":"Browser.setWindowBounds","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"top":{"description":"Window y position in screen coordinates.\n","type":"integer"},"width":{"description":"Window width in DIP.\n","type":"integer"},"window_id":{"description":"Browser window identifier.\n","type":"integer"},"window_state":{"$ref":"#/components/schemas/BrowserCdpWindowState","description":"Window state requested (`normal`, `minimized`, `maximized`, `fullscreen`). A value the protocol does not define is reported as `other`.\n"}},"required":["method","window_id"],"type":"object"},"BrowserCdpCommandEvent":{"description":"A browser-control command a client sent over the CDP WebSocket proxy: input gestures, navigation, dialog handling, file selection and screenshots. Configuration commands and the DOM/Runtime traffic a client library issues on the caller's behalf are not reported.\nOne event per browser-control command that reached the browser. The command stream is not sampled, coalesced or reordered. An event is lost only when the method is excluded by telemetry configuration, when the command's arguments do not decode, or when classification cannot keep up. Exclusions are counted in `cdp_disconnect.telemetry_excluded`; the rest in `cdp_disconnect.telemetry_dropped`.\n","properties":{"category":{"const":"control","type":"string"},"data":{"$ref":"#/components/schemas/BrowserCdpCommandEventData"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"cdp_command","type":"string"}},"required":["ts","type","category","source","data"],"type":"object"},"BrowserCdpCommandEventData":{"description":"Per-command payload for `cdp_command` events, discriminated by `method`. Each variant carries only the arguments approved for that command: values that could hold a secret — typed and composition text, URLs, referrers, scripts, templates, file paths, drag contents and autofill values — are replaced by a length, a count, a presence flag, an enum or a URL scheme and host.\n","discriminator":{"mapping":{"Autofill.trigger":"#/components/schemas/BrowserCdpAutofillTriggerCommandData","Browser.cancelDownload":"#/components/schemas/BrowserCdpBrowserCancelDownloadCommandData","Browser.close":"#/components/schemas/BrowserCdpBrowserCloseCommandData","Browser.setContentsSize":"#/components/schemas/BrowserCdpBrowserSetContentsSizeCommandData","Browser.setWindowBounds":"#/components/schemas/BrowserCdpBrowserSetWindowBoundsCommandData","DOM.focus":"#/components/schemas/BrowserCdpDomFocusCommandData","DOM.scrollIntoViewIfNeeded":"#/components/schemas/BrowserCdpDomScrollIntoViewIfNeededCommandData","DOM.setFileInputFiles":"#/components/schemas/BrowserCdpDomSetFileInputFilesCommandData","Input.cancelDragging":"#/components/schemas/BrowserCdpInputCancelDraggingCommandData","Input.dispatchDragEvent":"#/components/schemas/BrowserCdpInputDispatchDragEventCommandData","Input.dispatchKeyEvent":"#/components/schemas/BrowserCdpInputDispatchKeyEventCommandData","Input.dispatchMouseEvent":"#/components/schemas/BrowserCdpInputDispatchMouseEventCommandData","Input.dispatchTouchEvent":"#/components/schemas/BrowserCdpInputDispatchTouchEventCommandData","Input.emulateTouchFromMouseEvent":"#/components/schemas/BrowserCdpInputEmulateTouchFromMouseEventCommandData","Input.imeSetComposition":"#/components/schemas/BrowserCdpInputImeSetCompositionCommandData","Input.insertText":"#/components/schemas/BrowserCdpInputInsertTextCommandData","Input.synthesizePinchGesture":"#/components/schemas/BrowserCdpInputSynthesizePinchGestureCommandData","Input.synthesizeScrollGesture":"#/components/schemas/BrowserCdpInputSynthesizeScrollGestureCommandData","Input.synthesizeTapGesture":"#/components/schemas/BrowserCdpInputSynthesizeTapGestureCommandData","Page.bringToFront":"#/components/schemas/BrowserCdpPageBringToFrontCommandData","Page.captureScreenshot":"#/components/schemas/BrowserCdpPageCaptureScreenshotCommandData","Page.captureSnapshot":"#/components/schemas/BrowserCdpPageCaptureSnapshotCommandData","Page.close":"#/components/schemas/BrowserCdpPageCloseCommandData","Page.handleJavaScriptDialog":"#/components/schemas/BrowserCdpPageHandleJavaScriptDialogCommandData","Page.navigate":"#/components/schemas/BrowserCdpPageNavigateCommandData","Page.navigateToHistoryEntry":"#/components/schemas/BrowserCdpPageNavigateToHistoryEntryCommandData","Page.printToPDF":"#/components/schemas/BrowserCdpPagePrintToPdfCommandData","Page.reload":"#/components/schemas/BrowserCdpPageReloadCommandData","Page.setWebLifecycleState":"#/components/schemas/BrowserCdpPageSetWebLifecycleStateCommandData","Page.startScreencast":"#/components/schemas/BrowserCdpPageStartScreencastCommandData","Page.stopLoading":"#/components/schemas/BrowserCdpPageStopLoadingCommandData","Page.stopScreencast":"#/components/schemas/BrowserCdpPageStopScreencastCommandData","Target.activateTarget":"#/components/schemas/BrowserCdpTargetActivateTargetCommandData","Target.closeTarget":"#/components/schemas/BrowserCdpTargetCloseTargetCommandData","Target.createBrowserContext":"#/components/schemas/BrowserCdpTargetCreateBrowserContextCommandData","Target.createTarget":"#/components/schemas/BrowserCdpTargetCreateTargetCommandData","Target.disposeBrowserContext":"#/components/schemas/BrowserCdpTargetDisposeBrowserContextCommandData","Target.openDevTools":"#/components/schemas/BrowserCdpTargetOpenDevToolsCommandData"},"propertyName":"method"},"oneOf":[{"$ref":"#/components/schemas/BrowserCdpInputDispatchMouseEventCommandData"},{"$ref":"#/components/schemas/BrowserCdpInputDispatchKeyEventCommandData"},{"$ref":"#/components/schemas/BrowserCdpInputInsertTextCommandData"},{"$ref":"#/components/schemas/BrowserCdpInputImeSetCompositionCommandData"},{"$ref":"#/components/schemas/BrowserCdpInputDispatchTouchEventCommandData"},{"$ref":"#/components/schemas/BrowserCdpInputDispatchDragEventCommandData"},{"$ref":"#/components/schemas/BrowserCdpInputCancelDraggingCommandData"},{"$ref":"#/components/schemas/BrowserCdpInputEmulateTouchFromMouseEventCommandData"},{"$ref":"#/components/schemas/BrowserCdpInputSynthesizePinchGestureCommandData"},{"$ref":"#/components/schemas/BrowserCdpInputSynthesizeScrollGestureCommandData"},{"$ref":"#/components/schemas/BrowserCdpInputSynthesizeTapGestureCommandData"},{"$ref":"#/components/schemas/BrowserCdpDomSetFileInputFilesCommandData"},{"$ref":"#/components/schemas/BrowserCdpDomFocusCommandData"},{"$ref":"#/components/schemas/BrowserCdpDomScrollIntoViewIfNeededCommandData"},{"$ref":"#/components/schemas/BrowserCdpPageBringToFrontCommandData"},{"$ref":"#/components/schemas/BrowserCdpPageCaptureScreenshotCommandData"},{"$ref":"#/components/schemas/BrowserCdpPageCaptureSnapshotCommandData"},{"$ref":"#/components/schemas/BrowserCdpPageHandleJavaScriptDialogCommandData"},{"$ref":"#/components/schemas/BrowserCdpPageNavigateCommandData"},{"$ref":"#/components/schemas/BrowserCdpPageNavigateToHistoryEntryCommandData"},{"$ref":"#/components/schemas/BrowserCdpPageReloadCommandData"},{"$ref":"#/components/schemas/BrowserCdpPagePrintToPdfCommandData"},{"$ref":"#/components/schemas/BrowserCdpPageStartScreencastCommandData"},{"$ref":"#/components/schemas/BrowserCdpPageStopScreencastCommandData"},{"$ref":"#/components/schemas/BrowserCdpPageStopLoadingCommandData"},{"$ref":"#/components/schemas/BrowserCdpPageCloseCommandData"},{"$ref":"#/components/schemas/BrowserCdpPageSetWebLifecycleStateCommandData"},{"$ref":"#/components/schemas/BrowserCdpTargetActivateTargetCommandData"},{"$ref":"#/components/schemas/BrowserCdpTargetCloseTargetCommandData"},{"$ref":"#/components/schemas/BrowserCdpTargetCreateTargetCommandData"},{"$ref":"#/components/schemas/BrowserCdpTargetCreateBrowserContextCommandData"},{"$ref":"#/components/schemas/BrowserCdpTargetDisposeBrowserContextCommandData"},{"$ref":"#/components/schemas/BrowserCdpTargetOpenDevToolsCommandData"},{"$ref":"#/components/schemas/BrowserCdpBrowserCancelDownloadCommandData"},{"$ref":"#/components/schemas/BrowserCdpBrowserCloseCommandData"},{"$ref":"#/components/schemas/BrowserCdpBrowserSetWindowBoundsCommandData"},{"$ref":"#/components/schemas/BrowserCdpBrowserSetContentsSizeCommandData"},{"$ref":"#/components/schemas/BrowserCdpAutofillTriggerCommandData"}]},"BrowserCdpCommandMethod":{"description":"A browser-control CDP method the proxy reports. The set covers the commands an agent drives the browser with; configuration, DOM and Runtime bookkeeping, and Chrome-specific UI commands are outside it. Canonical definitions: devtools-protocol@2d019e73.\n","enum":["Input.dispatchMouseEvent","Input.dispatchKeyEvent","Input.insertText","Input.imeSetComposition","Input.dispatchTouchEvent","Input.dispatchDragEvent","Input.cancelDragging","Input.emulateTouchFromMouseEvent","Input.synthesizePinchGesture","Input.synthesizeScrollGesture","Input.synthesizeTapGesture","DOM.setFileInputFiles","DOM.focus","DOM.scrollIntoViewIfNeeded","Page.bringToFront","Page.captureScreenshot","Page.captureSnapshot","Page.handleJavaScriptDialog","Page.navigate","Page.navigateToHistoryEntry","Page.reload","Page.printToPDF","Page.startScreencast","Page.stopScreencast","Page.stopLoading","Page.close","Page.setWebLifecycleState","Target.activateTarget","Target.closeTarget","Target.createTarget","Target.createBrowserContext","Target.disposeBrowserContext","Target.openDevTools","Browser.cancelDownload","Browser.close","Browser.setWindowBounds","Browser.setContentsSize","Autofill.trigger"],"type":"string"},"BrowserCdpConnectEvent":{"description":"An external client (e.g. customer SDK, Playwright, Puppeteer) connected to the CDP WebSocket proxy on this VM.","properties":{"category":{"const":"connection","type":"string"},"data":{"additionalProperties":false,"properties":{"connection_id":{"description":"Identifies this CDP proxy connection, matching the connection_id on the cdp_command events that arrived on it. Two clients driving the same browser are told apart by this.","maxLength":128,"type":"string"}},"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"cdp_connect","type":"string"}},"required":["ts","type","category","source"],"type":"object"},"BrowserCdpDisconnectEvent":{"description":"An external client disconnected from the CDP WebSocket proxy on this VM. Pair with the immediately preceding cdp_connect on the same stream.","properties":{"category":{"const":"connection","type":"string"},"data":{"additionalProperties":false,"properties":{"connection_id":{"description":"Identifies this CDP proxy connection, matching the connection_id on the cdp_command events that arrived on it. Two clients driving the same browser are told apart by this.","maxLength":128,"type":"string"},"duration_ms":{"description":"Wall-clock duration of the connection in milliseconds.","type":"number"},"message_count":{"description":"Number of CDP messages relayed across the connection in either direction.","type":"integer"},"reason":{"description":"Why the connection ended. client_close: the client initiated the close. upstream_changed: Chromium restarted mid-session and the proxy tore down so the client could reconnect against the new upstream. upstream_error: upstream dial or message pump errored. context_cancelled: the request context was cancelled (typically server shutdown).","enum":["client_close","upstream_changed","upstream_error","context_cancelled"],"type":"string","x-go-type":"string"},"telemetry_dropped":{"description":"Number of forwarded client frames the classifier never saw, because it could not keep up or because classification failed. An upper bound on lost commands rather than a count: a saturated queue turns away whatever arrives next, which may be library traffic that would have produced no event. Telemetry loss only; every command was still relayed to the browser. Absent on events from a browser image predating the field, which is not the same as zero.","type":"integer"},"telemetry_excluded":{"description":"Number of forwarded client commands that produced no cdp_command event because their method is listed in control.cdp.excluded_methods. Configuration rather than loss, so it is counted apart from telemetry_dropped.","type":"integer"}},"required":["duration_ms","message_count","reason"],"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"cdp_disconnect","type":"string"}},"required":["ts","type","category","source"],"type":"object"},"BrowserCdpDomFocusCommandData":{"additionalProperties":false,"description":"Sanitized `DOM.focus` arguments. Canonical input: `DOM.focus` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"backend_node_id":{"description":"Opaque backend DOM node identifier the command targeted.\n","type":"integer"},"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"DOM.focus","type":"string"},"node_id":{"description":"Opaque DOM node identifier the command targeted.\n","type":"integer"},"object_id":{"description":"Opaque Runtime remote object identifier the command targeted. Clipped to 128 characters; a longer value is not a real identifier.\n","maxLength":128,"type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method"],"type":"object"},"BrowserCdpDomScrollIntoViewIfNeededCommandData":{"additionalProperties":false,"description":"Sanitized `DOM.scrollIntoViewIfNeeded` arguments. Canonical input: `DOM.scrollIntoViewIfNeeded` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"backend_node_id":{"description":"Opaque backend DOM node identifier the command targeted.\n","type":"integer"},"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"DOM.scrollIntoViewIfNeeded","type":"string"},"node_id":{"description":"Opaque DOM node identifier the command targeted.\n","type":"integer"},"object_id":{"description":"Opaque Runtime remote object identifier the command targeted. Clipped to 128 characters; a longer value is not a real identifier.\n","maxLength":128,"type":"string"},"rect_height":{"description":"Height of the rect the command scrolled to.\n","format":"double","type":"number"},"rect_width":{"description":"Width of the rect the command scrolled to.\n","format":"double","type":"number"},"rect_x":{"description":"X offset of the rect the command scrolled to, relative to the node.\n","format":"double","type":"number"},"rect_y":{"description":"Y offset of the rect the command scrolled to, relative to the node.\n","format":"double","type":"number"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method"],"type":"object"},"BrowserCdpDomSetFileInputFilesCommandData":{"additionalProperties":false,"description":"Sanitized `DOM.setFileInputFiles` arguments. Canonical input: `DOM.setFileInputFiles` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"backend_node_id":{"description":"Opaque backend DOM node identifier the command targeted.\n","type":"integer"},"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"file_count":{"description":"Number of files handed to the input. File paths are never captured.\n","type":"integer"},"method":{"const":"DOM.setFileInputFiles","type":"string"},"node_id":{"description":"Opaque DOM node identifier the command targeted.\n","type":"integer"},"object_id":{"description":"Opaque Runtime remote object identifier the command targeted. Clipped to 128 characters; a longer value is not a real identifier.\n","maxLength":128,"type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method","file_count"],"type":"object"},"BrowserCdpDragEventType":{"description":"Drag event phase. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["dragEnter","dragOver","drop","dragCancel","other"],"type":"string","x-enum-varnames":["BrowserCdpDragEventTypeDragEnter","BrowserCdpDragEventTypeDragOver","BrowserCdpDragEventTypeDrop","BrowserCdpDragEventTypeDragCancel","BrowserCdpDragEventTypeOther"]},"BrowserCdpDragMimeCategory":{"description":"Top-level MIME category of a drag item, from the IANA registry rather than the protocol; a drag item's subtype names the file, so only the category is reported. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["text","image","audio","video","application","font","model","multipart","message","other"],"type":"string","x-enum-varnames":["BrowserCdpDragMimeCategoryText","BrowserCdpDragMimeCategoryImage","BrowserCdpDragMimeCategoryAudio","BrowserCdpDragMimeCategoryVideo","BrowserCdpDragMimeCategoryApplication","BrowserCdpDragMimeCategoryFont","BrowserCdpDragMimeCategoryModel","BrowserCdpDragMimeCategoryMultipart","BrowserCdpDragMimeCategoryMessage","BrowserCdpDragMimeCategoryOther"]},"BrowserCdpGestureSourceType":{"description":"Input source a synthesized gesture emulates. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["default","touch","mouse","other"],"type":"string","x-enum-varnames":["BrowserCdpGestureSourceTypeDefault","BrowserCdpGestureSourceTypeTouch","BrowserCdpGestureSourceTypeMouse","BrowserCdpGestureSourceTypeOther"]},"BrowserCdpInputCancelDraggingCommandData":{"additionalProperties":false,"description":"Sanitized `Input.cancelDragging` arguments. Canonical input: `Input.cancelDragging` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"Input.cancelDragging","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method"],"type":"object"},"BrowserCdpInputDispatchDragEventCommandData":{"additionalProperties":false,"description":"Sanitized `Input.dispatchDragEvent` arguments. Canonical input: `Input.dispatchDragEvent` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"drag_file_count":{"description":"Number of files in the drag payload. File paths are never captured.\n","type":"integer"},"drag_item_count":{"description":"Number of items in the drag payload. Item contents are never captured.\n","type":"integer"},"drag_mime_categories":{"description":"Distinct top-level MIME categories of the drag items (e.g. `text`, `image`, `application`). Subtypes and contents are never captured. A value the protocol does not define is reported as `other`.\n","items":{"$ref":"#/components/schemas/BrowserCdpDragMimeCategory"},"type":"array"},"drag_operations_mask":{"description":"Bit field of allowed drag operations (1=copy, 2=link, 16=move).\n","type":"integer"},"event_type":{"$ref":"#/components/schemas/BrowserCdpDragEventType","description":"Drag event phase: `dragEnter`, `dragOver`, `drop` or `dragCancel`. A value the protocol does not define is reported as `other`.\n"},"method":{"const":"Input.dispatchDragEvent","type":"string"},"modifiers":{"description":"Bit field of held modifier keys (1=Alt, 2=Ctrl, 4=Meta, 8=Shift).\n","type":"integer"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"true":{"description":"Viewport y coordinate in CSS pixels.\n","format":"double","type":"number"},"x":{"description":"Viewport x coordinate in CSS pixels.\n","format":"double","type":"number"}},"required":["method","event_type"],"type":"object"},"BrowserCdpInputDispatchKeyEventCommandData":{"additionalProperties":false,"description":"Sanitized `Input.dispatchKeyEvent` arguments. Canonical input: `Input.dispatchKeyEvent` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"auto_repeat":{"description":"Whether the event was generated by key repeat.\n","type":"boolean"},"command_count":{"description":"Number of editing commands (e.g. `selectAll`) carried by the event.\n","type":"integer"},"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"event_type":{"$ref":"#/components/schemas/BrowserCdpKeyEventType","description":"Key event phase: `keyDown`, `keyUp`, `rawKeyDown` or `char`. A value the protocol does not define is reported as `other`.\n"},"is_keypad":{"description":"Whether the key is on the numeric keypad.\n","type":"boolean"},"is_system_key":{"description":"Whether the event is a system key event.\n","type":"boolean"},"location":{"description":"Keyboard location (1=left, 2=right, 3=numpad).\n","type":"integer"},"method":{"const":"Input.dispatchKeyEvent","type":"string"},"modifiers":{"description":"Bit field of held modifier keys (1=Alt, 2=Ctrl, 4=Meta, 8=Shift).\n","type":"integer"},"named_key":{"description":"Key that commands the page rather than typing into it (e.g. `Enter`, `Tab`, `ArrowDown`, `F5`). Keys that produce a character are never captured; those are counted by `text_length`.\n","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"text_length":{"description":"Number of characters the command submitted. The text itself is never captured.\n","type":"integer"}},"required":["method","event_type"],"type":"object"},"BrowserCdpInputDispatchMouseEventCommandData":{"additionalProperties":false,"description":"Sanitized `Input.dispatchMouseEvent` arguments. Canonical input: `Input.dispatchMouseEvent` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"button":{"$ref":"#/components/schemas/BrowserCdpMouseButton","description":"Button named by the command (`none`, `left`, `middle`, `right`, `back`, `forward`). A value the protocol does not define is reported as `other`.\n"},"buttons":{"description":"Bit field of buttons held down. Non-zero on a `mouseMoved` means the move is a drag path.\n","type":"integer"},"click_count":{"description":"Number of times the button was clicked (2 is a double click).\n","type":"integer"},"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"delta_x":{"description":"Horizontal scroll delta, for `mouseWheel`.\n","format":"double","type":"number"},"delta_y":{"description":"Vertical scroll delta, for `mouseWheel`.\n","format":"double","type":"number"},"event_type":{"$ref":"#/components/schemas/BrowserCdpMouseEventType","description":"Mouse event phase: `mousePressed`, `mouseReleased`, `mouseMoved` or `mouseWheel`. A value the protocol does not define is reported as `other`.\n"},"force":{"description":"Normalized pressure, 0 to 1.\n","format":"double","type":"number"},"method":{"const":"Input.dispatchMouseEvent","type":"string"},"modifiers":{"description":"Bit field of held modifier keys (1=Alt, 2=Ctrl, 4=Meta, 8=Shift).\n","type":"integer"},"pointer_type":{"$ref":"#/components/schemas/BrowserCdpPointerType","description":"Pointer that generated the event (`mouse` or `pen`). A value the protocol does not define is reported as `other`.\n"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"tangential_pressure":{"description":"Normalized tangential pressure, -1 to 1.\n","format":"double","type":"number"},"tilt_x":{"description":"Pen tilt from the Y-Z plane, in degrees.\n","format":"double","type":"number"},"tilt_y":{"description":"Pen tilt from the X-Z plane, in degrees.\n","format":"double","type":"number"},"true":{"description":"Viewport y coordinate in CSS pixels.\n","format":"double","type":"number"},"twist":{"description":"Pen clockwise rotation, in degrees.\n","type":"integer"},"x":{"description":"Viewport x coordinate in CSS pixels.\n","format":"double","type":"number"}},"required":["method","event_type"],"type":"object"},"BrowserCdpInputDispatchTouchEventCommandData":{"additionalProperties":false,"description":"Sanitized `Input.dispatchTouchEvent` arguments. Canonical input: `Input.dispatchTouchEvent` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"event_type":{"$ref":"#/components/schemas/BrowserCdpTouchEventType","description":"Touch event phase: `touchStart`, `touchEnd`, `touchMove` or `touchCancel`. A value the protocol does not define is reported as `other`.\n"},"force":{"description":"Normalized pressure of the first touch point, 0 to 1.\n","format":"double","type":"number"},"method":{"const":"Input.dispatchTouchEvent","type":"string"},"modifiers":{"description":"Bit field of held modifier keys (1=Alt, 2=Ctrl, 4=Meta, 8=Shift).\n","type":"integer"},"radius_x":{"description":"Horizontal radius of the first touch point.\n","format":"double","type":"number"},"radius_y":{"description":"Vertical radius of the first touch point.\n","format":"double","type":"number"},"rotation_angle":{"description":"Rotation of the first touch point, in degrees.\n","format":"double","type":"number"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"tangential_pressure":{"description":"Normalized tangential pressure of the first touch point, -1 to 1.\n","format":"double","type":"number"},"tilt_x":{"description":"Tilt of the first touch point from the Y-Z plane, in degrees.\n","format":"double","type":"number"},"tilt_y":{"description":"Tilt of the first touch point from the X-Z plane, in degrees.\n","format":"double","type":"number"},"touch_point_count":{"description":"Number of active touch points the command carried.\n","type":"integer"},"true":{"description":"Viewport y coordinate of the first touch point.\n","format":"double","type":"number"},"twist":{"description":"Clockwise rotation of the first touch point, in degrees.\n","type":"integer"},"x":{"description":"Viewport x coordinate of the first touch point. Touch coordinates live inside `touchPoints`, so this is the primary point rather than a command-level argument.\n","format":"double","type":"number"}},"required":["method","event_type","touch_point_count"],"type":"object"},"BrowserCdpInputEmulateTouchFromMouseEventCommandData":{"additionalProperties":false,"description":"Sanitized `Input.emulateTouchFromMouseEvent` arguments. Canonical input: `Input.emulateTouchFromMouseEvent` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"button":{"$ref":"#/components/schemas/BrowserCdpMouseButton","description":"Button named by the command. A value the protocol does not define is reported as `other`.\n"},"click_count":{"description":"Number of times the button was clicked.\n","type":"integer"},"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"delta_x":{"description":"Horizontal scroll delta.\n","format":"double","type":"number"},"delta_y":{"description":"Vertical scroll delta.\n","format":"double","type":"number"},"event_type":{"$ref":"#/components/schemas/BrowserCdpMouseEventType","description":"Mouse event phase being emulated as touch. A value the protocol does not define is reported as `other`.\n"},"method":{"const":"Input.emulateTouchFromMouseEvent","type":"string"},"modifiers":{"description":"Bit field of held modifier keys (1=Alt, 2=Ctrl, 4=Meta, 8=Shift).\n","type":"integer"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"true":{"description":"Viewport y coordinate in CSS pixels.\n","format":"double","type":"number"},"x":{"description":"Viewport x coordinate in CSS pixels.\n","format":"double","type":"number"}},"required":["method","event_type"],"type":"object"},"BrowserCdpInputImeSetCompositionCommandData":{"additionalProperties":false,"description":"Sanitized `Input.imeSetComposition` arguments. Canonical input: `Input.imeSetComposition` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"Input.imeSetComposition","type":"string"},"replacement_end":{"description":"Replacement range end offset.\n","type":"integer"},"replacement_start":{"description":"Replacement range start offset.\n","type":"integer"},"selection_end":{"description":"Selection end offset within the composition.\n","type":"integer"},"selection_start":{"description":"Selection start offset within the composition.\n","type":"integer"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"text_length":{"description":"Number of characters in the composition. The text itself is never captured.\n","type":"integer"}},"required":["method","text_length"],"type":"object"},"BrowserCdpInputInsertTextCommandData":{"additionalProperties":false,"description":"Sanitized `Input.insertText` arguments. Canonical input: `Input.insertText` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"Input.insertText","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"text_length":{"description":"Number of characters inserted. The text itself is never captured.\n","type":"integer"}},"required":["method","text_length"],"type":"object"},"BrowserCdpInputSynthesizePinchGestureCommandData":{"additionalProperties":false,"description":"Sanitized `Input.synthesizePinchGesture` arguments. Canonical input: `Input.synthesizePinchGesture` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"gesture_source_type":{"$ref":"#/components/schemas/BrowserCdpGestureSourceType","description":"Input source the synthesized gesture emulates. A value the protocol does not define is reported as `other`.\n"},"method":{"const":"Input.synthesizePinchGesture","type":"string"},"relative_speed":{"description":"Relative pointer speed, in pixels per second.\n","type":"integer"},"scale_factor":{"description":"Relative scale of the pinch (\u003e1 zooms in).\n","format":"double","type":"number"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"true":{"description":"Viewport y coordinate in CSS pixels.\n","format":"double","type":"number"},"x":{"description":"Viewport x coordinate in CSS pixels.\n","format":"double","type":"number"}},"required":["method"],"type":"object"},"BrowserCdpInputSynthesizeScrollGestureCommandData":{"additionalProperties":false,"description":"Sanitized `Input.synthesizeScrollGesture` arguments. Canonical input: `Input.synthesizeScrollGesture` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"gesture_source_type":{"$ref":"#/components/schemas/BrowserCdpGestureSourceType","description":"Input source the synthesized gesture emulates. A value the protocol does not define is reported as `other`.\n"},"method":{"const":"Input.synthesizeScrollGesture","type":"string"},"prevent_fling":{"description":"Whether fling was suppressed.\n","type":"boolean"},"repeat_count":{"description":"Number of additional repeats of the scroll.\n","type":"integer"},"repeat_delay_ms":{"description":"Delay between repeats, in milliseconds.\n","type":"integer"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"speed":{"description":"Swipe speed in pixels per second.\n","type":"integer"},"true":{"description":"Viewport y coordinate in CSS pixels.\n","format":"double","type":"number"},"x":{"description":"Viewport x coordinate in CSS pixels.\n","format":"double","type":"number"},"x_distance":{"description":"Horizontal scroll distance in CSS pixels; positive scrolls left.\n","format":"double","type":"number"},"x_overscroll":{"description":"Additional horizontal distance scrolled past the end.\n","format":"double","type":"number"},"y_distance":{"description":"Vertical scroll distance in CSS pixels; positive scrolls up.\n","format":"double","type":"number"},"y_overscroll":{"description":"Additional vertical distance scrolled past the end.\n","format":"double","type":"number"}},"required":["method"],"type":"object"},"BrowserCdpInputSynthesizeTapGestureCommandData":{"additionalProperties":false,"description":"Sanitized `Input.synthesizeTapGesture` arguments. Canonical input: `Input.synthesizeTapGesture` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"duration":{"description":"Duration between touchdown and touchup, in milliseconds.\n","type":"integer"},"gesture_source_type":{"$ref":"#/components/schemas/BrowserCdpGestureSourceType","description":"Input source the synthesized gesture emulates. A value the protocol does not define is reported as `other`.\n"},"method":{"const":"Input.synthesizeTapGesture","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"tap_count":{"description":"Number of times to tap (2 is a double tap).\n","type":"integer"},"true":{"description":"Viewport y coordinate in CSS pixels.\n","format":"double","type":"number"},"x":{"description":"Viewport x coordinate in CSS pixels.\n","format":"double","type":"number"}},"required":["method"],"type":"object"},"BrowserCdpKeyEventType":{"description":"Key event phase. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["keyDown","keyUp","rawKeyDown","char","other"],"type":"string","x-enum-varnames":["BrowserCdpKeyEventTypeKeyDown","BrowserCdpKeyEventTypeKeyUp","BrowserCdpKeyEventTypeRawKeyDown","BrowserCdpKeyEventTypeChar","BrowserCdpKeyEventTypeOther"]},"BrowserCdpMouseButton":{"description":"Mouse button named by a command. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["none","left","middle","right","back","forward","other"],"type":"string","x-enum-varnames":["BrowserCdpMouseButtonNone","BrowserCdpMouseButtonLeft","BrowserCdpMouseButtonMiddle","BrowserCdpMouseButtonRight","BrowserCdpMouseButtonBack","BrowserCdpMouseButtonForward","BrowserCdpMouseButtonOther"]},"BrowserCdpMouseEventType":{"description":"Mouse event phase. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["mousePressed","mouseReleased","mouseMoved","mouseWheel","other"],"type":"string","x-enum-varnames":["BrowserCdpMouseEventTypeMousePressed","BrowserCdpMouseEventTypeMouseReleased","BrowserCdpMouseEventTypeMouseMoved","BrowserCdpMouseEventTypeMouseWheel","BrowserCdpMouseEventTypeOther"]},"BrowserCdpPageBringToFrontCommandData":{"additionalProperties":false,"description":"Sanitized `Page.bringToFront` arguments. Canonical input: `Page.bringToFront` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"Page.bringToFront","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method"],"type":"object"},"BrowserCdpPageCaptureScreenshotCommandData":{"additionalProperties":false,"description":"Sanitized `Page.captureScreenshot` arguments. Canonical input: `Page.captureScreenshot` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"capture_beyond_viewport":{"description":"Whether the capture extended past the viewport.\n","type":"boolean"},"clip_height":{"description":"Clip region height in CSS pixels.\n","format":"double","type":"number"},"clip_scale":{"description":"Clip region page scale factor.\n","format":"double","type":"number"},"clip_width":{"description":"Clip region width in CSS pixels.\n","format":"double","type":"number"},"clip_x":{"description":"Clip region x offset in CSS pixels.\n","format":"double","type":"number"},"clip_y":{"description":"Clip region y offset in CSS pixels.\n","format":"double","type":"number"},"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"format":{"$ref":"#/components/schemas/BrowserCdpScreenshotFormat","description":"Image format requested (`jpeg`, `png` or `webp`). A value the protocol does not define is reported as `other`.\n"},"from_surface":{"description":"Whether the capture was taken from the surface rather than the view.\n","type":"boolean"},"method":{"const":"Page.captureScreenshot","type":"string"},"optimize_for_speed":{"description":"Whether encoding favored speed over size.\n","type":"boolean"},"quality":{"description":"Compression quality, 0 to 100, for lossy formats.\n","type":"integer"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method"],"type":"object"},"BrowserCdpPageCaptureSnapshotCommandData":{"additionalProperties":false,"description":"Sanitized `Page.captureSnapshot` arguments. Canonical input: `Page.captureSnapshot` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"format":{"$ref":"#/components/schemas/BrowserCdpSnapshotFormat","description":"Snapshot format requested (`mhtml`). A value the protocol does not define is reported as `other`.\n"},"method":{"const":"Page.captureSnapshot","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method"],"type":"object"},"BrowserCdpPageCloseCommandData":{"additionalProperties":false,"description":"Sanitized `Page.close` arguments. Canonical input: `Page.close` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"Page.close","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method"],"type":"object"},"BrowserCdpPageHandleJavaScriptDialogCommandData":{"additionalProperties":false,"description":"Sanitized `Page.handleJavaScriptDialog` arguments. Canonical input: `Page.handleJavaScriptDialog` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"accept":{"description":"Whether the dialog was accepted or dismissed.\n","type":"boolean"},"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"Page.handleJavaScriptDialog","type":"string"},"prompt_text_length":{"description":"Number of characters entered into a prompt dialog. The text itself is never captured.\n","type":"integer"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method","accept"],"type":"object"},"BrowserCdpPageNavigateCommandData":{"additionalProperties":false,"description":"Sanitized `Page.navigate` arguments. Canonical input: `Page.navigate` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"frame_id":{"description":"Opaque frame identifier. Clipped to 128 characters; a longer value is not a real identifier.\n","maxLength":128,"type":"string"},"method":{"const":"Page.navigate","type":"string"},"referrer_policy":{"$ref":"#/components/schemas/BrowserCdpReferrerPolicy","description":"Referrer policy named by the command. A value the protocol does not define is reported as `other`.\n"},"referrer_present":{"description":"Whether the command carried a referrer. The referrer itself is never captured.\n","type":"boolean"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"transition_type":{"$ref":"#/components/schemas/BrowserCdpTransitionType","description":"Navigation reason reported by the caller (e.g. `link`, `typed`, `reload`). A value the protocol does not define is reported as `other`.\n"},"url_scheme":{"description":"Scheme of the destination URL (e.g. `https`, `about`, `data`). The rest of the URL is never captured.\n","maxLength":32,"type":"string"}},"required":["method"],"type":"object"},"BrowserCdpPageNavigateToHistoryEntryCommandData":{"additionalProperties":false,"description":"Sanitized `Page.navigateToHistoryEntry` arguments. Canonical input: `Page.navigateToHistoryEntry` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"entry_id":{"description":"History entry the command navigated to.\n","type":"integer"},"method":{"const":"Page.navigateToHistoryEntry","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method","entry_id"],"type":"object"},"BrowserCdpPagePrintToPdfCommandData":{"additionalProperties":false,"description":"Sanitized `Page.printToPDF` arguments. Canonical input: `Page.printToPDF` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"display_header_footer":{"description":"Whether a header and footer were rendered.\n","type":"boolean"},"footer_template_present":{"description":"Whether a footer template was supplied. The template itself is never captured.\n","type":"boolean"},"generate_document_outline":{"description":"Whether a document outline was embedded.\n","type":"boolean"},"generate_tagged_pdf":{"description":"Whether a tagged (accessible) PDF was requested.\n","type":"boolean"},"header_template_present":{"description":"Whether a header template was supplied. The template itself is never captured.\n","type":"boolean"},"landscape":{"description":"Whether the page was laid out in landscape.\n","type":"boolean"},"margin_bottom":{"description":"Bottom margin in inches.\n","format":"double","type":"number"},"margin_left":{"description":"Left margin in inches.\n","format":"double","type":"number"},"margin_right":{"description":"Right margin in inches.\n","format":"double","type":"number"},"margin_top":{"description":"Top margin in inches.\n","format":"double","type":"number"},"method":{"const":"Page.printToPDF","type":"string"},"page_ranges_present":{"description":"Whether a page range was supplied.\n","type":"boolean"},"paper_height":{"description":"Paper height in inches.\n","format":"double","type":"number"},"paper_width":{"description":"Paper width in inches.\n","format":"double","type":"number"},"prefer_css_page_size":{"description":"Whether the CSS page size was preferred over the paper size.\n","type":"boolean"},"print_background":{"description":"Whether background graphics were printed.\n","type":"boolean"},"scale":{"description":"Page render scale.\n","format":"double","type":"number"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"transfer_mode":{"$ref":"#/components/schemas/BrowserCdpPdfTransferMode","description":"How the PDF was returned (`ReturnAsBase64` or `ReturnAsStream`). A value the protocol does not define is reported as `other`.\n"}},"required":["method"],"type":"object"},"BrowserCdpPageReloadCommandData":{"additionalProperties":false,"description":"Sanitized `Page.reload` arguments. Canonical input: `Page.reload` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"ignore_cache":{"description":"Whether the reload bypassed the cache.\n","type":"boolean"},"loader_id":{"description":"Opaque document loader identifier. Clipped to 128 characters; a longer value is not a real identifier.\n","maxLength":128,"type":"string"},"method":{"const":"Page.reload","type":"string"},"script_length":{"description":"Number of characters in the injected script.\n","type":"integer"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method"],"type":"object"},"BrowserCdpPageSetWebLifecycleStateCommandData":{"additionalProperties":false,"description":"Sanitized `Page.setWebLifecycleState` arguments. Canonical input: `Page.setWebLifecycleState` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"Page.setWebLifecycleState","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"state":{"$ref":"#/components/schemas/BrowserCdpWebLifecycleState","description":"Lifecycle state applied (`frozen` or `active`). A value the protocol does not define is reported as `other`.\n"}},"required":["method","state"],"type":"object"},"BrowserCdpPageStartScreencastCommandData":{"additionalProperties":false,"description":"Sanitized `Page.startScreencast` arguments. Canonical input: `Page.startScreencast` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"every_nth_frame":{"description":"Frame sampling interval.\n","type":"integer"},"format":{"$ref":"#/components/schemas/BrowserCdpScreencastFormat","description":"Frame format requested (`jpeg` or `png`). A value the protocol does not define is reported as `other`.\n"},"max_height":{"description":"Maximum frame height in pixels.\n","type":"integer"},"max_width":{"description":"Maximum frame width in pixels.\n","type":"integer"},"method":{"const":"Page.startScreencast","type":"string"},"quality":{"description":"Compression quality, 0 to 100.\n","type":"integer"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method"],"type":"object"},"BrowserCdpPageStopLoadingCommandData":{"additionalProperties":false,"description":"Sanitized `Page.stopLoading` arguments. Canonical input: `Page.stopLoading` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"Page.stopLoading","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method"],"type":"object"},"BrowserCdpPageStopScreencastCommandData":{"additionalProperties":false,"description":"Sanitized `Page.stopScreencast` arguments. Canonical input: `Page.stopScreencast` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"Page.stopScreencast","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method"],"type":"object"},"BrowserCdpPdfTransferMode":{"description":"How a generated PDF is returned. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["ReturnAsBase64","ReturnAsStream","other"],"type":"string","x-enum-varnames":["BrowserCdpPdfTransferModeReturnAsBase64","BrowserCdpPdfTransferModeReturnAsStream","BrowserCdpPdfTransferModeOther"]},"BrowserCdpPointerType":{"description":"Pointer that generated an input event. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["mouse","pen","other"],"type":"string","x-enum-varnames":["BrowserCdpPointerTypeMouse","BrowserCdpPointerTypePen","BrowserCdpPointerTypeOther"]},"BrowserCdpReferrerPolicy":{"description":"Referrer policy named by a navigation. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["noReferrer","noReferrerWhenDowngrade","origin","originWhenCrossOrigin","sameOrigin","strictOrigin","strictOriginWhenCrossOrigin","unsafeUrl","other"],"type":"string","x-enum-varnames":["BrowserCdpReferrerPolicyNoReferrer","BrowserCdpReferrerPolicyNoReferrerWhenDowngrade","BrowserCdpReferrerPolicyOrigin","BrowserCdpReferrerPolicyOriginWhenCrossOrigin","BrowserCdpReferrerPolicySameOrigin","BrowserCdpReferrerPolicyStrictOrigin","BrowserCdpReferrerPolicyStrictOriginWhenCrossOrigin","BrowserCdpReferrerPolicyUnsafeUrl","BrowserCdpReferrerPolicyOther"]},"BrowserCdpScreencastFormat":{"description":"Frame format requested for a screencast. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["jpeg","png","other"],"type":"string","x-enum-varnames":["BrowserCdpScreencastFormatJpeg","BrowserCdpScreencastFormatPng","BrowserCdpScreencastFormatOther"]},"BrowserCdpScreenshotFormat":{"description":"Image format requested for a screenshot. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["jpeg","png","webp","other"],"type":"string","x-enum-varnames":["BrowserCdpScreenshotFormatJpeg","BrowserCdpScreenshotFormatPng","BrowserCdpScreenshotFormatWebp","BrowserCdpScreenshotFormatOther"]},"BrowserCdpSnapshotFormat":{"description":"Format requested for a page snapshot. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["mhtml","other"],"type":"string","x-enum-varnames":["BrowserCdpSnapshotFormatMhtml","BrowserCdpSnapshotFormatOther"]},"BrowserCdpTargetActivateTargetCommandData":{"additionalProperties":false,"description":"Sanitized `Target.activateTarget` arguments. Canonical input: `Target.activateTarget` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"Target.activateTarget","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"target_id":{"description":"Opaque target identifier. Clipped to 128 characters; a longer value is not a real identifier.\n","maxLength":128,"type":"string"}},"required":["method","target_id"],"type":"object"},"BrowserCdpTargetCloseTargetCommandData":{"additionalProperties":false,"description":"Sanitized `Target.closeTarget` arguments. Canonical input: `Target.closeTarget` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"Target.closeTarget","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"target_id":{"description":"Opaque target identifier. Clipped to 128 characters; a longer value is not a real identifier.\n","maxLength":128,"type":"string"}},"required":["method","target_id"],"type":"object"},"BrowserCdpTargetCreateBrowserContextCommandData":{"additionalProperties":false,"description":"Sanitized `Target.createBrowserContext` arguments. Canonical input: `Target.createBrowserContext` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"dispose_on_detach":{"description":"Whether the context is disposed when the debugging session detaches.\n","type":"boolean"},"method":{"const":"Target.createBrowserContext","type":"string"},"proxy_bypass_list_present":{"description":"Whether a proxy bypass list was configured.\n","type":"boolean"},"proxy_server_present":{"description":"Whether a proxy was configured. The proxy address is never captured.\n","type":"boolean"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"universal_network_access_origin_count":{"description":"Number of origins granted universal network access. The origins themselves are never captured.\n","type":"integer"}},"required":["method"],"type":"object"},"BrowserCdpTargetCreateTargetCommandData":{"additionalProperties":false,"description":"Sanitized `Target.createTarget` arguments. Canonical input: `Target.createTarget` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"background":{"description":"Whether the target was created in the background.\n","type":"boolean"},"browser_context_id":{"description":"Opaque browser context identifier. Clipped to 128 characters; a longer value is not a real identifier.\n","maxLength":128,"type":"string"},"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"enable_begin_frame_control":{"description":"Whether BeginFrame control was enabled (headless only).\n","type":"boolean"},"focus":{"description":"Whether the new target was focused.\n","type":"boolean"},"for_tab":{"description":"Whether a tab target rather than a page target was created.\n","type":"boolean"},"height":{"description":"Window height in DIP.\n","type":"integer"},"hidden":{"description":"Whether the target was created hidden.\n","type":"boolean"},"left":{"description":"Window x position in screen coordinates.\n","type":"integer"},"method":{"const":"Target.createTarget","type":"string"},"new_window":{"description":"Whether a new window was requested.\n","type":"boolean"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"top":{"description":"Window y position in screen coordinates.\n","type":"integer"},"url_scheme":{"description":"Scheme of the destination URL (e.g. `https`, `about`, `data`). The rest of the URL is never captured.\n","maxLength":32,"type":"string"},"width":{"description":"Window width in DIP.\n","type":"integer"},"window_state":{"$ref":"#/components/schemas/BrowserCdpWindowState","description":"Window state requested (`normal`, `minimized`, `maximized`, `fullscreen`). A value the protocol does not define is reported as `other`.\n"}},"required":["method"],"type":"object"},"BrowserCdpTargetDisposeBrowserContextCommandData":{"additionalProperties":false,"description":"Sanitized `Target.disposeBrowserContext` arguments. Canonical input: `Target.disposeBrowserContext` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"browser_context_id":{"description":"Opaque browser context identifier. Clipped to 128 characters; a longer value is not a real identifier.\n","maxLength":128,"type":"string"},"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"Target.disposeBrowserContext","type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"}},"required":["method","browser_context_id"],"type":"object"},"BrowserCdpTargetOpenDevToolsCommandData":{"additionalProperties":false,"description":"Sanitized `Target.openDevTools` arguments. Canonical input: `Target.openDevTools` in devtools-protocol@2d019e73, pinned at https://github.com/ChromeDevTools/devtools-protocol/blob/2d019e73eb371d1d6985d26d395d78bd8f8a22ba/json/browser_protocol.json. Every argument of this command has a retained or redacted decision in lib/devtoolsproxy/testdata/cdp_arguments.yaml.\n","properties":{"command_id":{"description":"The command's JSON-RPC id, so the command can be joined to the result the browser returned for it. Absent when the client sent none.\n","format":"int64","type":"integer"},"connection_id":{"description":"Identifies the CDP proxy connection the command arrived on, matching `cdp_connect` and `cdp_disconnect`. Two clients driving the same browser are told apart by this.\n","maxLength":128,"type":"string"},"method":{"const":"Target.openDevTools","type":"string"},"panel_id":{"description":"DevTools panel opened. Clipped to 128 characters; a longer value is not a real identifier.\n","maxLength":128,"type":"string"},"session_id":{"description":"CDP session identifier the command was addressed to. Absent for browser-level commands. Clipped to 128 characters.\n","maxLength":128,"type":"string"},"target_id":{"description":"Opaque target identifier. Clipped to 128 characters; a longer value is not a real identifier.\n","maxLength":128,"type":"string"}},"required":["method","target_id"],"type":"object"},"BrowserCdpTouchEventType":{"description":"Touch event phase. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["touchStart","touchEnd","touchMove","touchCancel","other"],"type":"string","x-enum-varnames":["BrowserCdpTouchEventTypeTouchStart","BrowserCdpTouchEventTypeTouchEnd","BrowserCdpTouchEventTypeTouchMove","BrowserCdpTouchEventTypeTouchCancel","BrowserCdpTouchEventTypeOther"]},"BrowserCdpTransitionType":{"description":"Navigation reason reported by the caller. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["link","typed","address_bar","auto_bookmark","auto_subframe","manual_subframe","generated","auto_toplevel","form_submit","reload","keyword","keyword_generated","other"],"type":"string","x-enum-varnames":["BrowserCdpTransitionTypeLink","BrowserCdpTransitionTypeTyped","BrowserCdpTransitionTypeAddressBar","BrowserCdpTransitionTypeAutoBookmark","BrowserCdpTransitionTypeAutoSubframe","BrowserCdpTransitionTypeManualSubframe","BrowserCdpTransitionTypeGenerated","BrowserCdpTransitionTypeAutoToplevel","BrowserCdpTransitionTypeFormSubmit","BrowserCdpTransitionTypeReload","BrowserCdpTransitionTypeKeyword","BrowserCdpTransitionTypeKeywordGenerated","BrowserCdpTransitionTypeOther"]},"BrowserCdpWebLifecycleState":{"description":"Page lifecycle state applied. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["frozen","active","other"],"type":"string","x-enum-varnames":["BrowserCdpWebLifecycleStateFrozen","BrowserCdpWebLifecycleStateActive","BrowserCdpWebLifecycleStateOther"]},"BrowserCdpWindowState":{"description":"Browser window state requested. Canonical values from devtools-protocol@2d019e73. `other` stands for a value outside that set, so a client cannot put an arbitrary string into the stream.\n","enum":["normal","minimized","maximized","fullscreen","other"],"type":"string","x-enum-varnames":["BrowserCdpWindowStateNormal","BrowserCdpWindowStateMinimized","BrowserCdpWindowStateMaximized","BrowserCdpWindowStateFullscreen","BrowserCdpWindowStateOther"]},"BrowserConsoleErrorEvent":{"description":"A browser console error or uncaught JavaScript exception event. Emitted from two distinct CDP sources with different data shapes. Runtime.consoleAPICalled (console.error calls) produces level, text, args, and stack_trace. Runtime.exceptionThrown (uncaught exceptions) produces text, line, column, source_url, and stack_trace. Fields not applicable to the source are absent.\n","properties":{"category":{"const":"console","type":"string"},"data":{"allOf":[{"$ref":"#/components/schemas/BrowserEventContext"},{"properties":{"args":{"description":"All console arguments coerced to strings. Present only when sourced from Runtime.consoleAPICalled.","items":{"type":"string"},"type":"array"},"column":{"description":"Column number in the script where the exception was thrown. Present only when sourced from Runtime.exceptionThrown.","type":"integer"},"level":{"description":"CDP console type value, always \"error\". Present only when sourced from Runtime.consoleAPICalled.","type":"string"},"line":{"description":"Line number in the script where the exception was thrown. Present only when sourced from Runtime.exceptionThrown.","type":"integer"},"source_url":{"description":"URL of the script file that threw the exception. Present only when sourced from Runtime.exceptionThrown.","type":"string"},"stack_trace":{"$ref":"#/components/schemas/BrowserCallStack"},"text":{"description":"Human-readable error text, as the browser console would display it. For console.error() calls, the first argument coerced to a string. For uncaught exceptions, the prefix and error message, e.g. \"Uncaught Error: boom\" or \"Uncaught (in promise) TypeError: x is not a function\".\n","type":"string"}},"required":["text"],"type":"object"}]},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"console_error","type":"string"}},"required":["ts","type","category","source"],"title":"console_error","type":"object"},"BrowserConsoleLogEvent":{"description":"A browser console log event (console.log, console.info, console.warn, etc.).","properties":{"category":{"const":"console","type":"string"},"data":{"allOf":[{"$ref":"#/components/schemas/BrowserEventContext"},{"properties":{"args":{"description":"All console arguments coerced to strings.","items":{"type":"string"},"type":"array"},"level":{"description":"CDP Runtime.consoleAPICalled type, passed through unfiltered from Chrome. error is routed to console_error events instead; all other CDP console types appear here. See CDP spec for the full enum.","type":"string"},"stack_trace":{"$ref":"#/components/schemas/BrowserCallStack"},"text":{"description":"First console argument coerced to string.","type":"string"}},"type":"object"}]},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"console_log","type":"string"}},"required":["ts","type","category","source"],"title":"console_log","type":"object"},"BrowserCurlRequest":{"additionalProperties":false,"description":"Request to make an HTTP request through the browser's network stack.","properties":{"body":{"description":"Request body (for POST/PUT/PATCH).","type":"string"},"headers":{"additionalProperties":{"type":"string"},"description":"Custom headers merged with browser defaults.","type":"object"},"method":{"default":"GET","description":"HTTP method.","enum":["GET","HEAD","POST","PUT","PATCH","DELETE","OPTIONS"],"type":"string"},"response_encoding":{"default":"utf8","description":"Encoding for the response body. Use base64 for binary content.","enum":["utf8","base64"],"type":"string"},"timeout_ms":{"default":30000,"description":"Request timeout in milliseconds.","maximum":60000,"minimum":1000,"type":"integer"},"url":{"description":"Target URL (must be http or https).","type":"string"}},"required":["url"],"type":"object"},"BrowserCurlResult":{"additionalProperties":false,"description":"Structured response from the browser curl request.","properties":{"body":{"description":"Response body (UTF-8 string or base64 depending on request).","type":"string"},"duration_ms":{"description":"Total request duration in milliseconds.","type":"integer"},"headers":{"additionalProperties":{"items":{"type":"string"},"type":"array"},"description":"Response headers (multi-value).","type":"object"},"status":{"description":"HTTP status code from target.","type":"integer"}},"required":["status","headers","body","duration_ms"],"type":"object"},"BrowserCurlTransportError":{"additionalProperties":false,"description":"Transport-level error when the request could not complete.","properties":{"code":{"$ref":"#/components/schemas/InstanceProxyErrorCode"},"message":{"description":"Human-readable error description.","type":"string"},"net_error":{"description":"Chromium net error code.","type":"integer"},"net_error_name":{"description":"Chromium net error name.","type":"string"}},"required":["code","message"],"type":"object"},"BrowserEventContext":{"description":"Browser event context stamped by the browser monitor onto all CDP-sourced events. Identifies the target, frame, and navigation epoch in which the event occurred.","properties":{"frame_id":{"description":"CDP frame identifier within the target.","type":"string"},"loader_id":{"description":"CDP document loader identifier, reset on each navigation.","type":"string"},"nav_seq":{"description":"Monotonically increasing navigation sequence number, incremented on each top-level navigation within the target.","format":"int64","type":"integer"},"session_id":{"description":"CDP session identifier for the target connection.","type":"string"},"target_id":{"description":"Browser target identifier (stable across navigations within a tab).","type":"string"},"target_type":{"$ref":"#/components/schemas/BrowserTargetType"},"url":{"description":"URL relevant to this event — page URL for navigation and page events, request URL for network events.","type":"string"}},"type":"object"},"BrowserEventSource":{"description":"Provenance metadata identifying which producer emitted the event.","properties":{"event":{"description":"Producer-specific event name (e.g. Runtime.consoleAPICalled for CDP-sourced console events, Runtime.exceptionThrown for uncaught exceptions).","type":"string"},"kind":{"description":"Event producer. cdp: Chrome DevTools Protocol events from the browser. kernel_api: Kernel API server. extension: injected Chrome extension. local_process: system process running alongside the browser.","enum":["cdp","kernel_api","extension","local_process"],"type":"string"},"metadata":{"additionalProperties":{"type":"string"},"description":"Producer-specific context (e.g. CDP target/session/frame IDs).","type":"object"}},"required":["kind"],"type":"object"},"BrowserExtension":{"description":"Extension selection for the browser session. Provide either id or name of an extension uploaded to Kernel.\n","oneOf":[{"required":["id"]},{"required":["name"]}],"properties":{"id":{"description":"Extension ID to load for this browser session","type":"string"},"name":{"description":"Extension name to load for this browser session (instead of id). Must be 1-255 characters, using letters, numbers, dots, underscores, or hyphens.","maxLength":255,"minLength":1,"pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"}},"type":"object"},"BrowserHttpHeaders":{"additionalProperties":true,"description":"HTTP headers map forwarded as-is from CDP without normalization. Values are typically strings but may be any JSON type.","type":"object"},"BrowserInteractionClickEvent":{"description":"A browser user click event captured via injected page script.","properties":{"category":{"const":"interaction","type":"string"},"data":{"allOf":[{"$ref":"#/components/schemas/BrowserEventContext"},{"properties":{"selector":{"description":"CSS selector path to the clicked element.","type":"string"},"tag":{"description":"HTML tag name of the clicked element in uppercase (e.g. BUTTON, A, DIV).","type":"string"},"text":{"description":"Visible text content of the clicked element, trimmed.","type":"string"},"true":{"description":"Viewport y-coordinate of the click in CSS pixels.","type":"integer"},"x":{"description":"Viewport x-coordinate of the click in CSS pixels.","type":"integer"}},"type":"object"}]},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"interaction_click","type":"string"}},"required":["ts","type","category","source"],"title":"interaction_click","type":"object"},"BrowserInteractionKeyEvent":{"description":"A browser keyboard event captured via injected page script.","properties":{"category":{"const":"interaction","type":"string"},"data":{"allOf":[{"$ref":"#/components/schemas/BrowserEventContext"},{"properties":{"key":{"description":"Key value from the KeyboardEvent (e.g. Enter, Backspace, a).","type":"string"},"selector":{"description":"CSS selector path to the element that had focus when the key was pressed.","type":"string"},"tag":{"description":"HTML tag name of the focused element in uppercase (e.g. INPUT, TEXTAREA, DIV).","type":"string"}},"type":"object"}]},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"interaction_key","type":"string"}},"required":["ts","type","category","source"],"title":"interaction_key","type":"object"},"BrowserInteractionScrollSettledEvent":{"description":"A browser scroll settled event emitted after scroll position stops changing, captured via injected page script.","properties":{"category":{"const":"interaction","type":"string"},"data":{"allOf":[{"$ref":"#/components/schemas/BrowserEventContext"},{"properties":{"from_x":{"description":"Scroll x-position at the start of the scroll gesture in CSS pixels.","type":"integer"},"from_y":{"description":"Scroll y-position at the start of the scroll gesture in CSS pixels.","type":"integer"},"target_selector":{"description":"CSS selector path to the scrolled element.","type":"string"},"to_x":{"description":"Final scroll x-position after the gesture settled in CSS pixels.","type":"integer"},"to_y":{"description":"Final scroll y-position after the gesture settled in CSS pixels.","type":"integer"}},"type":"object"}]},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"interaction_scroll_settled","type":"string"}},"required":["ts","type","category","source"],"title":"interaction_scroll_settled","type":"object"},"BrowserLiveViewConnectEvent":{"description":"A live view client connected to the headful browser's WebRTC server. Headful only; not emitted for headless images.","properties":{"category":{"const":"connection","type":"string"},"data":{"additionalProperties":false,"properties":{"session_id":{"description":"Live view session identifier. Stable across reconnects, so a transient network blip can emit two events with the same session_id.","type":"string"}},"required":["session_id"],"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"live_view_connect","type":"string"}},"required":["ts","type","category","source"],"type":"object"},"BrowserLiveViewDisconnectEvent":{"description":"A live view client disconnected from the headful browser's WebRTC server. Pair with live_view_connect by session_id.","properties":{"category":{"const":"connection","type":"string"},"data":{"additionalProperties":false,"properties":{"duration_ms":{"description":"Wall-clock duration of the connection in milliseconds.","type":"number"},"session_id":{"description":"Live view session identifier; matches the corresponding live_view_connect event.","type":"string"}},"required":["session_id","duration_ms"],"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"live_view_disconnect","type":"string"}},"required":["ts","type","category","source"],"type":"object"},"BrowserMemory":{"description":"Memory allocated to the browser session.","enum":["1GiB","2GiB","6GiB","8GiB","16GiB"],"example":"8GiB","type":"string"},"BrowserMemoryRequest":{"default":"8GiB","description":"Memory requested for a headful, non-GPU browser session.","enum":["8GiB","16GiB"],"example":"8GiB","type":"string"},"BrowserMonitorDisconnectedEvent":{"description":"The CDP connection to Chrome was lost. Telemetry events may be dropped until monitor_reconnected arrives. In-progress computed state is discarded rather than paused, so computed events still pending for the current navigation (network_idle, page_layout_settled, page_navigation_settled) never fire. monitor_reconnected does not restore them. After reattachment a fresh state machine starts, so computed events can resume before the next navigation and carry empty navigation context until one occurs.","properties":{"category":{"const":"monitor","type":"string"},"data":{"additionalProperties":false,"properties":{"reason":{"description":"Reason for the disconnection. chrome_restarted: Chrome process restarted.","enum":["chrome_restarted"],"type":"string"}},"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"monitor_disconnected","type":"string"}},"required":["ts","type","category","source"],"title":"monitor_disconnected","type":"object"},"BrowserMonitorInitFailedEvent":{"description":"The CDP session could not be initialized.","properties":{"category":{"const":"monitor","type":"string"},"data":{"additionalProperties":false,"properties":{"step":{"description":"The CDP method or initialization step that failed (e.g. Target.setAutoAttach).","type":"string"}},"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"monitor_init_failed","type":"string"}},"required":["ts","type","category","source"],"title":"monitor_init_failed","type":"object"},"BrowserMonitorReconnectFailedEvent":{"description":"The CDP connection to Chrome could not be re-established after exhausting all reconnection attempts. No further telemetry events will arrive on this session.","properties":{"category":{"const":"monitor","type":"string"},"data":{"additionalProperties":false,"properties":{"reason":{"description":"Reason for the reconnection failure. reconnect_exhausted: all retry attempts were used up without successfully restoring the CDP connection.","enum":["reconnect_exhausted"],"type":"string"}},"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"monitor_reconnect_failed","type":"string"}},"required":["ts","type","category","source"],"title":"monitor_reconnect_failed","type":"object"},"BrowserMonitorReconnectedEvent":{"description":"The CDP connection to Chrome was successfully re-established after a disconnection. Events emitted during the gap are lost. Computed state is reset, so navigation and network tracking restart fresh from this point.","properties":{"category":{"const":"monitor","type":"string"},"data":{"additionalProperties":false,"properties":{"reconnect_duration_ms":{"description":"Wall-clock time in milliseconds taken to reconnect after the disconnection.","format":"int64","type":"integer"}},"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"monitor_reconnected","type":"string"}},"required":["ts","type","category","source"],"title":"monitor_reconnected","type":"object"},"BrowserMonitorScreenshotEvent":{"description":"A periodic screenshot of the browser viewport.","properties":{"category":{"const":"screenshot","type":"string"},"data":{"additionalProperties":false,"properties":{"png":{"contentEncoding":"base64","description":"Base64-encoded PNG screenshot of the browser viewport.","type":"string"}},"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"monitor_screenshot","type":"string"}},"required":["ts","type","category","source"],"title":"monitor_screenshot","type":"object"},"BrowserNetworkConfig":{"description":"Network configuration for a browser session or browser pool.\n","properties":{"private_hosts":{"description":"Destinations the browser reaches directly through the session's own network instead of through Kernel-managed egress — for private hosts reachable over a VPN or tunnel the session has joined (e.g. a Tailscale tailnet). By default, private IP ranges already route directly: RFC1918 (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), CGNAT/Tailscale (100.64.0.0/10), and IPv6 ULA (fc00::/7). An explicitly supplied list replaces those defaults with exactly the entries given, and an empty list ([]) disables them so all traffic uses Kernel-managed egress; omit private_hosts to keep the defaults. Entries are hostname patterns (\"*.example.ts.net\", \"preview.internal\") or IP/CIDR literals (\"100.64.0.0/10\", \"10.1.30.63\"). IP and CIDR entries only match URLs written with a literal IP address; they never match hostnames that resolve into the range, so private DNS names need a hostname entry even when they resolve inside the default ranges. CIDRs must be in canonical masked form (host bits zero), and only the private ranges listed above are accepted; public, loopback, link-local, and unspecified ranges are rejected. Exact IPv6 addresses must be bracketed (\"[fd00::1]\"); IPv6 CIDR ranges are unbracketed (\"fd00::/8\"). Wildcards are limited to one leading \"*.\" over a suffix with at least two labels that is not a public suffix (so \"*.co.uk\" or \"*.ts.net\" are rejected, while \"*.example.ts.net\" is accepted). Hostname and IP entries may carry a port; CIDR ranges may not. Hostname entries are not resolved during validation, so callers must ensure they identify private destinations. Not related to a proxy's bypass_hosts, which selects between upstream-proxy and Kernel-managed direct egress and cannot reach into a VPN.\n","example":["*.example.ts.net","100.64.0.0/10"],"items":{"maxLength":255,"type":"string"},"maxItems":32,"type":"array"},"proxy_routes":{"description":"Per-destination proxy routes for a browser session. After setup, a destination hostname is matched against every route's hosts, regardless of port; route order does not matter. An exact hostname beats a wildcard, and a longer wildcard suffix beats a shorter one (for a.b.example.com: \"a.b.example.com\" \u003e \"*.b.example.com\" \u003e \"*.example.com\"). A host pattern may appear in only one route. \"*.example.com\" matches subdomains only, not example.com. A matched request selects the route's proxy instead of the session's top-level proxy (including mode: direct); the route proxy's own bypass_hosts still apply. If the route proxy becomes unavailable, matched requests fail closed without falling back. Requests that match no route use the session's default egress from the top-level proxy field (or the browser default when proxy is omitted: stealth proxy or direct egress). Routes take effect once the session is created; start_url and other traffic during browser setup use the top-level proxy. Setting routes requires proxy v3. Not supported on browser pools.\n","items":{"$ref":"#/components/schemas/BrowserProxyRoute"},"maxItems":10,"type":"array"}},"type":"object"},"BrowserNetworkIdleEvent":{"description":"A browser network idle event emitted after a 500ms quiet period with no in-flight HTTP requests.","properties":{"category":{"const":"network","type":"string"},"data":{"$ref":"#/components/schemas/BrowserEventContext"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"network_idle","type":"string"}},"required":["ts","type","category","source"],"title":"network_idle","type":"object"},"BrowserNetworkLoadingFailedEvent":{"description":"A browser network loading failed event. If the request was already in flight when CDP attached (no prior network_request was emitted for it), url, frame_id, loader_id, and resource_type are absent; BrowserEventContext is partially populated in that case.","properties":{"category":{"const":"network","type":"string"},"data":{"allOf":[{"$ref":"#/components/schemas/BrowserEventContext"},{"properties":{"canceled":{"description":"True if the request was canceled by the browser or page script.","type":"boolean"},"error_text":{"description":"Network error description (e.g. net::ERR_CONNECTION_REFUSED).","type":"string"},"request_id":{"description":"CDP request identifier matching the originating network_request event.","type":"string"},"resource_type":{"description":"CDP Network.ResourceType for the request, passed through as-is from Chrome. Known values include Document, Fetch, XHR, Script, Stylesheet, Image, Media, Font, TextTrack, EventSource, WebSocket, Manifest, Prefetch, Other, and more.","type":"string"}},"type":"object"}]},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"network_loading_failed","type":"string"}},"required":["ts","type","category","source"],"title":"network_loading_failed","type":"object"},"BrowserNetworkRequestEvent":{"description":"A browser network request sent event.","properties":{"category":{"const":"network","type":"string"},"data":{"allOf":[{"$ref":"#/components/schemas/BrowserEventContext"},{"properties":{"document_url":{"description":"URL of the document that initiated the request.","type":"string"},"headers":{"$ref":"#/components/schemas/BrowserHttpHeaders","description":"Request headers."},"initiator_type":{"description":"CDP Initiator.type indicating what caused the request, passed through as-is from Chrome. Known values include script, parser, preload, and other.","type":"string"},"is_redirect":{"description":"True if this request is the result of a redirect.","type":"boolean"},"method":{"description":"HTTP method as sent on the wire (e.g. GET, POST).","type":"string"},"post_data":{"description":"Request body for POST/PUT requests, if available.","type":"string"},"redirect_url":{"description":"Original URL before the redirect, present when is_redirect is true.","type":"string"},"request_id":{"description":"CDP request identifier, unique within the session.","type":"string"},"resource_type":{"description":"CDP Network.ResourceType for the request, passed through as-is from Chrome. Known values include Document, Fetch, XHR, Script, Stylesheet, Image, Media, Font, TextTrack, EventSource, WebSocket, Manifest, Prefetch, Other, and more.","type":"string"}},"type":"object"}]},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"network_request","type":"string"}},"required":["ts","type","category","source"],"title":"network_request","type":"object"},"BrowserNetworkResponseEvent":{"description":"A browser network response received event. Fired after the response body is fully received, not when headers arrive.","properties":{"category":{"const":"network","type":"string"},"data":{"allOf":[{"$ref":"#/components/schemas/BrowserEventContext"},{"properties":{"body":{"description":"Truncated response body, present only for text MIME types.","type":"string"},"headers":{"$ref":"#/components/schemas/BrowserHttpHeaders","description":"Response headers."},"method":{"description":"HTTP method of the original request.","type":"string"},"mime_type":{"description":"MIME type of the response (e.g. text/html, application/json).","type":"string"},"request_id":{"description":"CDP request identifier matching the originating network_request event.","type":"string"},"resource_type":{"description":"CDP Network.ResourceType for the request, passed through as-is from Chrome. Known values include Document, Fetch, XHR, Script, Stylesheet, Image, Media, Font, TextTrack, EventSource, WebSocket, Manifest, Prefetch, Other, and more.","type":"string"},"status":{"description":"HTTP response status code.","type":"integer"},"status_text":{"description":"HTTP response status text (e.g. OK, Not Found).","type":"string"}},"type":"object"}]},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"network_response","type":"string"}},"required":["ts","type","category","source"],"title":"network_response","type":"object"},"BrowserPageCrashedEvent":{"description":"A page's renderer process crashed (an \"Aw, Snap!\" failure) while the browser process itself stayed alive. Reported on the crashed page's session, with the session and target ids on `source.metadata`. Captured only while the `page` category is enabled.\n","properties":{"category":{"const":"page","type":"string"},"data":{"additionalProperties":false,"properties":{"target_id":{"description":"CDP target identifier of the crashed page.","type":"string"},"target_type":{"$ref":"#/components/schemas/BrowserTargetType"},"url":{"description":"URL the page was on when its renderer process crashed.","type":"string"}},"required":["target_id","target_type","url"],"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"page_crashed","type":"string"}},"required":["ts","type","category","source"],"title":"page_crashed","type":"object"},"BrowserPageDomContentLoadedEvent":{"description":"A browser DOMContentLoaded event (CDP Page.domContentEventFired).","properties":{"category":{"const":"page","type":"string"},"data":{"allOf":[{"$ref":"#/components/schemas/BrowserEventContext"},{"properties":{"cdp_timestamp":{"description":"Chrome monotonic clock value in seconds at which DOMContentLoaded fired, relative to browser process start (not Unix epoch). Use ts for wall-clock time.","type":"number"}},"type":"object"}]},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"page_dom_content_loaded","type":"string"}},"required":["ts","type","category","source"],"title":"page_dom_content_loaded","type":"object"},"BrowserPageLayoutSettledEvent":{"description":"A browser layout settled event emitted 1 second after page load with no intervening layout shifts, indicating visual stability. Each layout shift resets the 1-second timer.","properties":{"category":{"const":"page","type":"string"},"data":{"$ref":"#/components/schemas/BrowserEventContext"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"page_layout_settled","type":"string"}},"required":["ts","type","category","source"],"title":"page_layout_settled","type":"object"},"BrowserPageLayoutShiftEvent":{"description":"A browser cumulative layout shift (CLS) event from the Performance Timeline API.","properties":{"category":{"const":"page","type":"string"},"data":{"allOf":[{"$ref":"#/components/schemas/BrowserEventContext"},{"properties":{"duration":{"description":"Duration of the layout shift entry in milliseconds (always 0 for layout shifts per spec).","type":"number"},"layout_shift_details":{"additionalProperties":false,"description":"PerformanceLayoutShift attributes from the Performance Timeline entry.","properties":{"had_recent_input":{"description":"True if the layout shift was preceded by user input within 500ms, excluding it from CLS.","type":"boolean"},"value":{"description":"Layout shift score for this entry (contribution to CLS).","type":"number"}},"type":"object"},"source_frame_id":{"description":"CDP frame identifier of the frame where the layout shift occurred.","type":"string"},"time":{"description":"Performance Timeline timestamp of the layout shift in milliseconds.","type":"number"}},"type":"object"}]},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"page_layout_shift","type":"string"}},"required":["ts","type","category","source"],"title":"page_layout_shift","type":"object"},"BrowserPageLcpEvent":{"description":"A browser Largest Contentful Paint (LCP) event from the Performance Timeline API.","properties":{"category":{"const":"page","type":"string"},"data":{"allOf":[{"$ref":"#/components/schemas/BrowserEventContext"},{"properties":{"lcp_details":{"additionalProperties":false,"description":"LargestContentfulPaint attributes from the Performance Timeline entry.","properties":{"element_id":{"description":"id attribute of the LCP element, if present.","type":"string"},"load_time":{"description":"Load time of the LCP element in milliseconds.","type":"number"},"node_id":{"description":"CDP DOM node identifier of the LCP element.","type":"integer"},"render_time":{"description":"Render time of the LCP element in milliseconds; 0 for cross-origin images without Timing-Allow-Origin.","type":"number"},"size":{"description":"Visible area of the LCP element in pixels squared.","type":"number"},"url":{"description":"URL of the LCP element for image or video elements.","type":"string"}},"type":"object"},"source_frame_id":{"description":"CDP frame identifier of the frame where the LCP element was rendered.","type":"string"},"time":{"description":"Performance Timeline timestamp of the LCP entry in milliseconds.","type":"number"}},"type":"object"}]},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"page_lcp","type":"string"}},"required":["ts","type","category","source"],"title":"page_lcp","type":"object"},"BrowserPageLoadEvent":{"description":"A browser page load event (CDP Page.loadEventFired).","properties":{"category":{"const":"page","type":"string"},"data":{"allOf":[{"$ref":"#/components/schemas/BrowserEventContext"},{"properties":{"cdp_timestamp":{"description":"Chrome monotonic clock value in seconds at which the load event fired, relative to browser process start (not Unix epoch). Use ts for wall-clock time.","type":"number"}},"type":"object"}]},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"page_load","type":"string"}},"required":["ts","type","category","source"],"title":"page_load","type":"object"},"BrowserPageNavigationEvent":{"description":"A browser page navigation started event (CDP Page.frameNavigated). Carries nav context fields inline but not nav_seq, as this event resets the navigation epoch.","properties":{"category":{"const":"page","type":"string"},"data":{"additionalProperties":false,"properties":{"frame_id":{"description":"CDP frame identifier of the navigated frame.","type":"string"},"loader_id":{"description":"New CDP document loader identifier assigned for this navigation.","type":"string"},"parent_frame_id":{"description":"Parent frame identifier for subframe navigations; absent for top-level navigations.","type":"string"},"session_id":{"description":"CDP session identifier.","type":"string"},"target_id":{"description":"Browser target identifier.","type":"string"},"target_type":{"$ref":"#/components/schemas/BrowserTargetType"},"url":{"description":"URL navigated to.","type":"string"}},"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"page_navigation","type":"string"}},"required":["ts","type","category","source"],"title":"page_navigation","type":"object"},"BrowserPageNavigationSettledEvent":{"description":"Emitted when page_dom_content_loaded and page_layout_settled have both fired for the same navigation, indicating the page is loaded and visually stable. Independent of network_idle; a single pending request does not block it.","properties":{"category":{"const":"page","type":"string"},"data":{"$ref":"#/components/schemas/BrowserEventContext"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"page_navigation_settled","type":"string"}},"required":["ts","type","category","source"],"title":"page_navigation_settled","type":"object"},"BrowserPageTabOpenedEvent":{"description":"A new browser tab or target was opened (CDP Target.attachedToTarget for page targets). Fires before a CDP session is attached to the new target, so session_id, frame_id, loader_id, and nav_seq are absent; this event does not compose BrowserEventContext. Consumers reading context fields generically should treat it as a special case.","properties":{"category":{"const":"page","type":"string"},"data":{"additionalProperties":false,"properties":{"opener_id":{"description":"Target identifier of the tab that opened this one, if any.","type":"string"},"target_id":{"description":"CDP target identifier for the newly opened tab.","type":"string"},"target_type":{"$ref":"#/components/schemas/BrowserTargetType"},"title":{"description":"Initial page title of the new tab.","type":"string"},"url":{"description":"Initial URL of the new tab.","type":"string"}},"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"page_tab_opened","type":"string"}},"required":["ts","type","category","source"],"title":"page_tab_opened","type":"object"},"BrowserPlatformApiCallEvent":{"description":"An HTTP call that manages the browser VM rather than driving the browser, handled by the in-VM API server — recording lifecycle, filesystem and process management, telemetry and browser configuration. Mostly platform-induced (e.g. profile save, replay capture) rather than agent actions.","properties":{"category":{"const":"platform","type":"string"},"data":{"additionalProperties":false,"properties":{"duration_ms":{"description":"Wall-clock duration of the handler in milliseconds.","type":"number"},"operation_id":{"description":"Matched route's operation, named as the in-VM API names its handler (e.g. ProcessExec, StartRecording).","type":"string"},"request_id":{"description":"Per-request identifier from the in-VM API request middleware.","type":"string"},"status":{"description":"HTTP response status code.","type":"integer"}},"required":["request_id","operation_id","status","duration_ms"],"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"platform_api_call","type":"string"}},"required":["ts","type","category","source"],"type":"object"},"BrowserPool":{"description":"A browser pool containing multiple identically configured browsers.","properties":{"acquired_count":{"description":"Number of browsers currently acquired from the pool","example":15,"type":"integer"},"available_count":{"description":"Number of browsers currently available in the pool","example":85,"type":"integer"},"browser_pool_config":{"$ref":"#/components/schemas/BrowserPoolConfig","description":"Configuration used to create all browsers in this pool"},"created_at":{"description":"Timestamp when the browser pool was created","format":"date-time","type":"string"},"extension_ids":{"description":"Resolved extension IDs attached to the pool, in configured load order. Empty when no extensions are attached. Authoritative for programmatic consumers; the extensions inside `browser_pool_config` reflect the configured selector (echoed as sent on create).","items":{"type":"string"},"type":"array"},"id":{"description":"Unique identifier for the browser pool","example":"iv25ujqf37x3j07dwoffegqr","type":"string"},"name":{"description":"Browser pool name, if set","example":"my-pool","type":"string"},"profile_id":{"description":"Resolved profile ID the pool is attached to. Omitted when no profile is attached. Authoritative for programmatic consumers; the profile inside `browser_pool_config` reflects the configured selector (echoed as sent on create).","example":"iv25ujqf37x3j07dwoffegqr","type":"string"},"region":{"$ref":"#/components/schemas/Region","description":"Geographic region of the browser pool. Fixed once the pool is created.\n"}},"required":["id","available_count","acquired_count","created_at","region","browser_pool_config","extension_ids"],"type":"object"},"BrowserPoolAcquireRequest":{"description":"Request body for acquiring a browser from the pool.","properties":{"acquire_timeout_seconds":{"description":"Maximum number of seconds to wait for a browser to be available. Defaults to the calculated time it would take to fill the pool at the currently configured fill rate.","type":"integer"},"name":{"description":"Optional human-readable name for the acquired browser session, used to find it later in the dashboard. Must be unique among active sessions within the pool's project. Applies to this lease only and is cleared when the browser is released back to the pool.\n","example":"checkout-flow-1","maxLength":255,"minLength":1,"pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"},"profile":{"allOf":[{"$ref":"#/components/schemas/BrowserProfile"}],"description":"Optional profile to load before returning the acquired browser. The pool itself must not\nalready have a profile configured. A browser loaded with an acquire-time profile is destroyed\nand replaced on release instead of being reused, so profile state cannot leak into another\nlease. Set save_changes to persist changes when that browser is destroyed.\n"},"start_url":{"description":"Optional URL to navigate the acquired browser to. Overrides the pool's start_url for this acquire only. Best-effort: failures to navigate do not fail the acquire.","example":"https://example.com","type":"string"},"tags":{"$ref":"#/components/schemas/Tags","description":"Optional user-defined key-value tags for the acquired browser session, used to find and group sessions later. Applies to this lease only and are cleared when the browser is released back to the pool. Up to 50 pairs.\n"},"telemetry":{"$ref":"#/components/schemas/BrowserTelemetryRequestConfig","description":"Telemetry override for the acquired browser, applied to this lease only. Merges onto the browser's current (pool-inherited) telemetry using the same per-category semantics as PATCH /browsers: provided categories override the current configuration, omitted categories are inherited. Set enabled to true to resolve the config fresh from the default set, or enabled to false to stop capture. When the browser is released back to the pool with reuse, its telemetry is reset to the pool's baseline, so the override does not carry over to the next lease.\n","nullable":true}},"required":[],"type":"object"},"BrowserPoolConfig":{"description":"Effective browser pool configuration returned by the API.\n","properties":{"chrome_policy":{"additionalProperties":true,"description":"Custom Chrome enterprise policy overrides applied to all browsers in this pool. Keys are Chrome enterprise policy names; values must match their expected types. Blocked: kernel-managed policies (extensions, proxy, CDP/automation). See https://chromeenterprise.google/policies/ The serialized JSON payload is capped at 5 MiB.\n","type":"object"},"extensions":{"description":"List of browser extensions to load into the session. Provide each by id or name.","items":{"$ref":"#/components/schemas/BrowserExtension"},"maxItems":20,"type":"array"},"fill_rate_per_minute":{"description":"Percentage of the pool to fill per minute. The cap is 25 for most organizations but can be raised per-organization, so only the lower bound is enforced here.","minimum":0,"type":"integer"},"headless":{"description":"If true, launches the browser using a headless image.","example":false,"type":"boolean"},"kiosk_mode":{"description":"If true, launches the browser in kiosk mode to hide address bar and tabs in live view.","example":true,"type":"boolean"},"memory":{"allOf":[{"$ref":"#/components/schemas/BrowserMemory"}],"description":"Memory allocated to newly-warmed browsers in this pool."},"name":{"description":"Optional name for the browser pool. Must be unique within the project.","example":"my-pool","pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"},"network":{"$ref":"#/components/schemas/BrowserNetworkConfig","description":"Network configuration applied to browsers in this pool, if any. Omitted when the pool has no network configuration."},"profile":{"allOf":[{"$ref":"#/components/schemas/BrowserPoolProfile"}],"description":"Profile selection for browsers in the pool."},"proxy_id":{"description":"Optional proxy associated to the browser session. References a proxy in the same project as the browser session.","type":"string"},"refresh_on_profile_update":{"description":"When true, flush idle browsers when the profile the pool uses is updated, so pool browsers\npick up the latest profile data. When a profile is provided during creation, this defaults\nto true. Requires a profile to be set on the pool.\n","example":true,"type":"boolean"},"size":{"description":"Number of browsers maintained in the pool. The maximum size is determined by your\norganization's pooled sessions limit (the sum of all pool sizes cannot exceed your limit).\n","example":10,"minimum":1,"type":"integer"},"start_url":{"description":"Optional URL to navigate to when a new browser is warmed into the pool. Best-effort:\nfailures to navigate do not fail pool fill. Only applied to newly-warmed browsers;\nbrowsers reused via release/acquire keep whatever URL the previous lease left them on.\nAccepts any URL Chromium can resolve, including chrome:// pages.\n","example":"https://example.com","maxLength":2048,"type":"string"},"stealth":{"description":"If true, launches the browser in stealth mode to reduce detection by anti-bot mechanisms.","example":true,"type":"boolean"},"telemetry":{"$ref":"#/components/schemas/BrowserTelemetryConfig","description":"Active telemetry configuration applied to browsers warmed into this pool, if any.","nullable":true},"timeout_seconds":{"description":"Default idle timeout in seconds for browsers acquired from this pool before they are destroyed. Minimum 10, maximum 259200 (72 hours).","maximum":259200,"minimum":10,"type":"integer"},"viewport":{"allOf":[{"$ref":"#/components/schemas/BrowserViewport"}],"description":"Browser viewport used for newly-warmed browsers in this pool."}},"required":["size"],"type":"object"},"BrowserPoolCreateRequest":{"description":"Parameters for creating a browser pool. All browsers in the pool will be created with the same configuration.\n","properties":{"chrome_policy":{"additionalProperties":true,"description":"Custom Chrome enterprise policy overrides applied to all browsers in this pool. Keys are Chrome enterprise policy names; values must match their expected types. Blocked: kernel-managed policies (extensions, proxy, CDP/automation). See https://chromeenterprise.google/policies/ The serialized JSON payload is capped at 5 MiB.\n","type":"object"},"extensions":{"description":"List of browser extensions to load into the session. Provide each by id or name.","items":{"$ref":"#/components/schemas/BrowserExtension"},"maxItems":20,"type":"array"},"fill_rate_per_minute":{"default":25,"description":"Percentage of the pool to fill per minute. Defaults to 25. The cap is 25 for most organizations but can be raised per-organization, so only the lower bound is enforced here.","minimum":0,"type":"integer"},"headless":{"default":false,"description":"If true, launches the browser using a headless image. Defaults to false.","example":false,"type":"boolean"},"kiosk_mode":{"default":false,"description":"If true, launches the browser in kiosk mode to hide address bar and tabs in live view. Defaults to false.","example":true,"type":"boolean"},"memory":{"$ref":"#/components/schemas/BrowserMemoryRequest","description":"Memory requested for headful browsers in this pool."},"name":{"description":"Optional name for the browser pool. Must be unique within the project.","example":"my-pool","pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"},"network":{"$ref":"#/components/schemas/BrowserNetworkConfig","description":"Network configuration applied to browsers in this pool.\n"},"profile":{"allOf":[{"$ref":"#/components/schemas/BrowserPoolProfile"}],"description":"Profile selection for browsers in the pool."},"proxy_id":{"description":"Optional proxy to associate to the browser session. Must reference a proxy in the same project as the browser session.","type":"string"},"refresh_on_profile_update":{"default":false,"description":"When true, flush idle browsers when the profile the pool uses is updated, so pool browsers\npick up the latest profile data. When a profile is provided during creation, this defaults\nto true. Requires a profile to be set on the pool.\n","example":true,"type":"boolean"},"region":{"$ref":"#/components/schemas/Region","description":"Geographic region for the browser pool. It is fixed once the pool is created. Region selection requires a Start-Up or Enterprise plan, defaults to us-east when omitted on create.\n"},"size":{"description":"Number of browsers to maintain in the pool. The maximum size is determined by your\norganization's pooled sessions limit (the sum of all pool sizes cannot exceed your limit).\n","example":10,"minimum":1,"type":"integer"},"start_url":{"description":"Optional URL to navigate to when a new browser is warmed into the pool. Best-effort:\nfailures to navigate do not fail pool fill. Only applied to newly-warmed browsers;\nbrowsers reused via release/acquire keep whatever URL the previous lease left them on.\nAccepts any URL Chromium can resolve, including chrome:// pages.\n","example":"https://example.com","maxLength":2048,"type":"string"},"stealth":{"default":false,"description":"If true, launches the browser in stealth mode to reduce detection by anti-bot mechanisms. Defaults to false.","example":true,"type":"boolean"},"telemetry":{"$ref":"#/components/schemas/BrowserTelemetryRequestConfig","description":"Telemetry configuration applied to browsers warmed into this pool. Set enabled to true to start capture using the default set, or provide browser category settings. If omitted, null, set to an empty object ({}), set to enabled: false without browser category settings, or all four CDP categories are explicitly disabled, no telemetry is configured on the pool. Only applied to newly-warmed browsers.\n","nullable":true},"timeout_seconds":{"default":600,"description":"Default idle timeout in seconds for browsers acquired from this pool before they are destroyed. Defaults to 600 seconds. Minimum 10, maximum 259200 (72 hours).","maximum":259200,"minimum":10,"type":"integer"},"viewport":{"allOf":[{"$ref":"#/components/schemas/BrowserViewport"}],"description":"Browser viewport used for newly-warmed browsers in this pool."}},"required":["size"],"type":"object"},"BrowserPoolDeleteRequest":{"description":"Parameters for deleting a browser pool.\n","properties":{"force":{"default":false,"description":"If true, force delete even if browsers are currently leased. Leased browsers will be terminated.","type":"boolean"}},"required":[],"type":"object"},"BrowserPoolProfile":{"description":"Profile configuration for browsers in a pool. Provide either id or name. Profiles must\nbe created beforehand. Unlike single browser sessions, pools load the profile read-only\nand never persist changes back to it, so save_changes is omitted here. Any save_changes\nvalue sent on a pool profile is silently ignored rather than rejected.\n","oneOf":[{"required":["id"]},{"required":["name"]}],"properties":{"id":{"description":"Profile ID to load for browsers in this pool","type":"string"},"name":{"description":"Profile name to load for browsers in this pool (instead of id). Must be 1-255 characters, using letters, numbers, dots, underscores, or hyphens.","maxLength":255,"minLength":1,"pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"}},"type":"object"},"BrowserPoolRef":{"description":"Browser pool this session was acquired from, if any.","properties":{"id":{"description":"Browser pool ID","type":"string"},"name":{"description":"Browser pool name, if set","type":"string"}},"required":["id"],"type":"object"},"BrowserPoolReleaseRequest":{"description":"Request body for releasing a browser back to the pool.","properties":{"reuse":{"default":true,"description":"Whether to reuse the browser instance or destroy it and create a new one. Defaults to true. A reused browser keeps the configuration it was created with, so it does not pick up pool configuration changes made while it was in use. Release with `reuse: false`, or flush the pool afterward, to rebuild it with the current configuration. Browsers loaded with an acquire-time profile are always destroyed and replaced, even when reuse is true.","example":false,"type":"boolean"},"session_id":{"description":"Browser session ID to release back to the pool","example":"ts8iy3sg25ibheguyni2lg9t","type":"string"}},"required":["session_id"],"type":"object"},"BrowserPoolUpdateRequest":{"description":"Parameters for updating a browser pool. Omitted fields leave existing values unchanged.\n","properties":{"chrome_policy":{"additionalProperties":true,"description":"If provided, replaces the custom Chrome enterprise policy overrides applied to all browsers in this pool. Empty object clears any previously-set policy. Keys are Chrome enterprise policy names; values must match their expected types. Blocked: kernel-managed policies (extensions, proxy, CDP/automation). See https://chromeenterprise.google/policies/ The serialized JSON payload is capped at 5 MiB.\n","type":"object"},"discard_all_idle":{"default":false,"description":"Whether to discard all idle browsers and rebuild them immediately with the new configuration. Defaults to false. Only browsers that are idle when the update runs are rebuilt. A browser that is in use during the update keeps its original configuration, and if it is later released with `reuse: true` it returns to the pool with that stale configuration until it is discarded (by this flag on a later update, or by flushing the pool).","example":false,"type":"boolean"},"extensions":{"description":"If provided, replaces the extension list. Empty array clears all previously-selected\nextensions. Omit this field to leave extensions unchanged.\n","items":{"$ref":"#/components/schemas/BrowserExtension"},"maxItems":20,"type":"array"},"fill_rate_per_minute":{"description":"If provided, replaces the percentage of the pool to fill per minute. The cap is 25\nfor most organizations but can be raised per-organization, so only the lower bound\nis enforced here.\n","minimum":0,"type":"integer"},"headless":{"description":"If provided, replaces whether browsers launch using a headless image.","example":false,"type":"boolean"},"kiosk_mode":{"description":"If provided, replaces whether browsers launch in kiosk mode.","example":true,"type":"boolean"},"memory":{"description":"Memory requested for newly-warmed headful browsers in this pool. Existing browsers retain their original allocation. Use discard_all_idle to replace idle browsers.\n","enum":["8GiB","16GiB"],"type":"string","x-go-type":"BrowserMemoryRequest"},"name":{"description":"If provided, replaces the pool name. Empty string is a no-op; the pool name cannot\nbe cleared or reset to empty once assigned.\n","example":"my-pool","pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"},"network":{"$ref":"#/components/schemas/BrowserNetworkConfig","description":"If provided, replaces the pool's network configuration. Omit to leave the existing configuration unchanged; an empty object ({}) removes it, while network: {private_hosts: []} sets an explicit empty list. Only applied to browsers created in the pool after the update; browsers already in the pool keep their configuration until discarded (see discard_all_idle).\n"},"profile":{"allOf":[{"$ref":"#/components/schemas/BrowserPoolProfile"}],"description":"If provided, replaces the previously-selected profile. To clear the profile reference,\nsend `{ \"id\": \"\" }` or `{ \"name\": \"\" }`. An empty object (no id or name) is rejected\nas 400.\n"},"proxy_id":{"description":"Empty string clears the previously-selected proxy. Omit this field to leave the proxy unchanged.","type":"string"},"refresh_on_profile_update":{"description":"If provided, replaces whether idle browsers are flushed when the profile the pool uses\nis updated. When the pool's profile reference is changed (including newly attached) and\nthis field is omitted, it defaults to true. Re-sending the same profile reference leaves\nthis setting unchanged. Clearing the profile also disables this setting. Requires a\nprofile to be set on the pool.\n","example":true,"type":"boolean"},"size":{"description":"If provided, replaces the number of browsers to maintain in the pool. The maximum\nsize is determined by your organization's pooled sessions limit (the sum of all\npool sizes cannot exceed your limit).\n","example":10,"minimum":1,"type":"integer"},"start_url":{"description":"If provided, replaces the URL to navigate to when a new browser is warmed into the pool.\nEmpty string clears the previously-set URL. Omit this field to leave it unchanged.\n","example":"https://example.com","maxLength":2048,"type":"string"},"stealth":{"description":"If provided, replaces whether browsers launch in stealth mode.","example":true,"type":"boolean"},"telemetry":{"$ref":"#/components/schemas/BrowserTelemetryRequestConfig","description":"If provided, updates the pool's telemetry configuration. Omit, set to null, or set to an empty object ({}) to leave the existing configuration unchanged. Set enabled to true to enable capture using the default set. Set enabled to false to clear the pool's telemetry. Provide browser category settings for per-category updates, merged onto the pool's current configuration. Only applied to browsers warmed after the update; browsers already in the pool keep their configuration until discarded.\n","nullable":true},"timeout_seconds":{"description":"If provided, replaces the default idle timeout in seconds for browsers acquired from this pool before they are destroyed. Minimum 10, maximum 259200 (72 hours).","maximum":259200,"minimum":10,"type":"integer"},"viewport":{"allOf":[{"$ref":"#/components/schemas/BrowserViewport"}],"description":"If provided, replaces the viewport with the new width/height/refresh_rate. Because\nwidth and height are required and must be positive, the viewport cannot be cleared;\nomit this field to leave it unchanged.\n"}},"type":"object"},"BrowserProfile":{"description":"Profile selection for the browser session. Provide either id or name. If specified, the\nmatching profile will be loaded into the browser session. Profiles must be created beforehand.\n","oneOf":[{"required":["id"]},{"required":["name"]}],"properties":{"id":{"description":"Profile ID to load for this browser session","type":"string"},"name":{"description":"Profile name to load for this browser session (instead of id). Must be 1-255 characters, using letters, numbers, dots, underscores, or hyphens.","maxLength":255,"minLength":1,"pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"},"save_changes":{"default":false,"description":"If true, save changes made during the session back to the profile when the session ends.","type":"boolean"}},"type":"object"},"BrowserProxy":{"additionalProperties":false,"description":"Resolved proxy configuration for a browser session. Selected proxies are returned by stable ID.","oneOf":[{"required":["mode"]},{"required":["id"]},{"required":["name"]}],"properties":{"id":{"description":"Selected proxy ID.","minLength":1,"type":"string"},"mode":{"$ref":"#/components/schemas/BrowserProxyMode"},"name":{"description":"Selected proxy name.","minLength":1,"type":"string"}},"type":"object"},"BrowserProxyConfig":{"additionalProperties":false,"description":"Browser proxy configuration. Provide exactly one of mode, id, or name; an empty object is invalid.\nSet mode to direct for no proxy regardless of stealth. Set mode to default to use the browser's stealth-derived default: Kernel's default stealth proxy when stealth=true, or direct egress when stealth=false.\nSelect id or name to use that proxy regardless of stealth. The selected proxy must be in the same project as the browser. Names must match exactly one active proxy; use id for stable references.\nProxy configuration changes only egress and does not change stealth or CAPTCHA solver behavior. A stealth browser using mode=direct still runs in stealth mode with the CAPTCHA solver enabled.\nWhen proxy is omitted on browser creation, stealth browsers use Kernel's default stealth proxy and non-stealth browsers use direct egress. When omitted on update, the current configuration is unchanged.\n","oneOf":[{"required":["mode"]},{"required":["id"]},{"required":["name"]}],"properties":{"id":{"description":"Proxy ID.","minLength":1,"type":"string"},"mode":{"$ref":"#/components/schemas/BrowserProxyMode"},"name":{"description":"Proxy name. Must match exactly one active proxy in the project.","minLength":1,"type":"string"}},"type":"object"},"BrowserProxyErrorEvent":{"description":"A branded proxy-layer failure observed by the browser. Emitted when the metro egress host-proxy serves a branded 5xx error page whose response carries the X-Kernel-Proxy-Error header. Low-volume and carries a typed code. Its value is per-session and per-URL attribution for sessions that already capture the network stream: proxy failures are only observable while the CDP network collector is running, so this is an opt-in refinement of the raw network events rather than a default-on alerting signal.\n","properties":{"category":{"const":"network","type":"string"},"data":{"allOf":[{"$ref":"#/components/schemas/BrowserEventContext"},{"properties":{"code":{"description":"Proxy-layer error code: the X-Kernel-Proxy-Error response header value from a branded 5xx error page served by the metro egress host-proxy. Values mirror what the proxy emits: destination_blocked, destination_route_unavailable, provider_blacklisted, provider_unreachable, provider_rejected, origin_tls_timeout, origin_response_incomplete, proxy_unavailable, restricted_route_unavailable, upstream_timeout, upstream_dns_failure, upstream_connect_failed. A header value the browser image does not recognize is reported as unknown, with the header value in raw_code.\n","enum":["destination_blocked","destination_route_unavailable","provider_blacklisted","provider_unreachable","provider_rejected","origin_tls_timeout","origin_response_incomplete","proxy_unavailable","restricted_route_unavailable","upstream_timeout","upstream_dns_failure","upstream_connect_failed","unknown"],"type":"string","x-enum-varnames":["BrowserProxyErrorEventDataCodeDestinationBlocked","BrowserProxyErrorEventDataCodeDestinationRouteUnavailable","BrowserProxyErrorEventDataCodeProviderBlacklisted","BrowserProxyErrorEventDataCodeProviderUnreachable","BrowserProxyErrorEventDataCodeProviderRejected","BrowserProxyErrorEventDataCodeOriginTLSTimeout","BrowserProxyErrorEventDataCodeOriginResponseIncomplete","BrowserProxyErrorEventDataCodeProxyUnavailable","BrowserProxyErrorEventDataCodeRestrictedRouteUnavailable","BrowserProxyErrorEventDataCodeUpstreamTimeout","BrowserProxyErrorEventDataCodeUpstreamDNSFailure","BrowserProxyErrorEventDataCodeUpstreamConnectFailed","BrowserProxyErrorEventDataCodeUnknown"]},"method":{"description":"HTTP method of the failed request, when known.","type":"string"},"raw_code":{"description":"Sanitized X-Kernel-Proxy-Error header value, present only when code is unknown. Surrounding whitespace is removed, the value is lowercased, characters outside [a-z0-9_] are replaced with _, and the result is truncated to at most 64 characters.\n","maxLength":64,"pattern":"^[a-z0-9_]*$","type":"string"},"request_id":{"description":"CDP request identifier matching the originating request.","type":"string"},"resource_type":{"description":"CDP Network.ResourceType for the request, when known.","type":"string"},"status":{"description":"HTTP response status of the branded error page (502).","type":"integer"}},"required":["request_id","code","status"],"type":"object"}]},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"proxy_error","type":"string"}},"required":["ts","type","category","source"],"title":"proxy_error","type":"object"},"BrowserProxyMode":{"description":"Proxy egress mode. direct forces no proxy regardless of stealth. default uses the browser's stealth-derived default: Kernel's default stealth proxy when stealth=true, or direct egress when stealth=false.\ndefault is primarily useful on browser update to restore the browser default after selected-proxy egress.\n","enum":["direct","default"],"type":"string","x-enum-varnames":["Direct","Default"]},"BrowserProxyRoute":{"additionalProperties":false,"properties":{"hosts":{"description":"Exact hostnames or leading *. wildcard patterns (subdomains only); patterns cannot include ports, and matching ignores the destination port. Hosts not matched by any route use the session's top-level proxy (or the browser default when proxy is omitted).\n","items":{"maxLength":253,"type":"string"},"maxItems":50,"minItems":1,"type":"array"},"proxy":{"$ref":"#/components/schemas/BrowserProxyRouteTarget"}},"required":["hosts","proxy"],"type":"object"},"BrowserProxyRouteTarget":{"additionalProperties":false,"description":"Select an active non-direct proxy by ID or name. Responses always use ID.","oneOf":[{"required":["id"]},{"required":["name"]}],"properties":{"id":{"minLength":1,"type":"string"},"name":{"minLength":1,"type":"string"}},"type":"object"},"BrowserReplContent":{"description":"Ordered discriminated union of Browser REPL output items.","discriminator":{"mapping":{"image":"#/components/schemas/BrowserReplImageContent","text":"#/components/schemas/BrowserReplTextContent"},"propertyName":"type"},"oneOf":[{"$ref":"#/components/schemas/BrowserReplTextContent"},{"$ref":"#/components/schemas/BrowserReplImageContent"}]},"BrowserReplImageContent":{"additionalProperties":false,"properties":{"data_b64":{"contentEncoding":"base64","type":"string"},"mime_type":{"pattern":"^image/","type":"string"},"type":{"enum":["image"],"type":"string","x-enum-varnames":["BrowserReplImageContentTypeImage"]}},"required":["type","mime_type","data_b64"],"type":"object"},"BrowserReplRequest":{"additionalProperties":false,"description":"Request to execute code in the persistent Browser REPL.","properties":{"code":{"description":"JavaScript evaluated in a persistent Node.js runtime. Top-level bindings\npersist until the browser VM's API process exits, the REPL is reset, or\nthe REPL is terminated after a crash or timeout. Static top-level imports\nare unsupported; use dynamic `import()`. Expression values are ignored;\nemit output with `repl.write(...)`, console methods, or\n`repl.emitImage(...)`. May be empty only when `reset` is true.\n","type":"string"},"reset":{"default":false,"description":"Terminate the current REPL, start a fresh one, and then evaluate code.","type":"boolean"},"timeout_sec":{"default":60,"description":"Maximum execution time in seconds. Default is 60.","maximum":300,"minimum":1,"type":"integer"}},"required":["code"],"type":"object"},"BrowserReplResult":{"additionalProperties":false,"description":"Result of Browser REPL code execution.","properties":{"content":{"description":"Optional ordered text/image output produced by the execution.","items":{"$ref":"#/components/schemas/BrowserReplContent"},"type":"array"},"content_truncated":{"description":"True if text or image output was dropped or truncated due to response limits.","type":"boolean"},"duration_ms":{"description":"Wall-clock execution time in milliseconds.","type":"integer"},"error":{"description":"Error message if execution failed.","type":"string"},"repl_id":{"description":"CUID2 identifying the exact state-holding REPL process used for this\nexecution. Stable across calls and Chromium reconnects; changes after\nan API restart, explicit reset, execution timeout, or REPL crash.\n","type":"string"},"repl_terminated":{"description":"True if the REPL identified by `repl_id` was terminated by this request.\nThe next request lazily starts a fresh REPL with a new `repl_id`.\n","type":"boolean"},"stack":{"description":"Stack trace if execution failed.","type":"string"},"success":{"description":"Whether the code executed successfully.","type":"boolean"}},"required":["success","repl_id"],"type":"object"},"BrowserReplTextContent":{"additionalProperties":false,"properties":{"channel":{"description":"`write` is emitted by `repl.write`; `stdout` and `stderr` are emitted by console methods.","enum":["write","stdout","stderr"],"type":"string","x-enum-varnames":["BrowserReplTextContentChannelWrite","BrowserReplTextContentChannelStdout","BrowserReplTextContentChannelStderr"]},"text":{"type":"string"},"type":{"enum":["text"],"type":"string","x-enum-varnames":["BrowserReplTextContentTypeText"]}},"required":["type","channel","text"],"type":"object"},"BrowserReplay":{"description":"Information about a browser replay recording.","properties":{"finished_at":{"description":"Timestamp when replay finished","format":"date-time","nullable":true,"type":"string"},"replay_id":{"description":"Unique identifier for the replay recording.","type":"string"},"replay_view_url":{"description":"URL for viewing the replay recording.","example":"https://api.onkernel.com/browser/replays?jwt=eyJ0eXAi...\u0026replay_id=7e2c1a9f-1234-4cde-9abc-ffeedd001122","type":"string"},"started_at":{"description":"Timestamp when replay started","format":"date-time","nullable":true,"type":"string"}},"required":["replay_id"],"type":"object"},"BrowserRequest":{"description":"Parameters for creating a browser session.\n","properties":{"chrome_policy":{"additionalProperties":true,"description":"Custom Chrome enterprise policy overrides applied to this browser session. Keys are Chrome enterprise policy names; values must match their expected types. Blocked: kernel-managed policies (extensions, proxy, CDP/automation). See https://chromeenterprise.google/policies/\n","type":"object"},"extensions":{"description":"List of browser extensions to load into the session. Provide each by id or name.","items":{"$ref":"#/components/schemas/BrowserExtension"},"maxItems":20,"type":"array"},"gpu":{"description":"If true, enables GPU acceleration for the browser session. Requires Start-Up or Enterprise plan, headless=false, and region=us-east.","example":false,"type":"boolean"},"headless":{"description":"If true, launches the browser using a headless image (no VNC/GUI). Defaults to false.","example":false,"type":"boolean"},"invocation_id":{"description":"action invocation ID","example":"rr33xuugxj9h0bkf1rdt2bet","type":"string"},"kiosk_mode":{"description":"If true, launches the browser in kiosk mode to hide address bar and tabs in live view.","example":true,"type":"boolean"},"memory":{"$ref":"#/components/schemas/BrowserMemoryRequest","description":"Memory for a headful, non-GPU browser session. Defaults to 8GiB."},"name":{"description":"Optional human-readable name for the browser session, used to find it later in the dashboard. Must be unique among active sessions within the project. Can be changed later via PATCH /browsers/{id_or_name}.\n","example":"checkout-flow-1","maxLength":255,"minLength":1,"pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"},"network":{"$ref":"#/components/schemas/BrowserNetworkConfig","description":"Network configuration for the browser session. Cannot be changed after creation.\n"},"profile":{"$ref":"#/components/schemas/BrowserProfile"},"proxy":{"$ref":"#/components/schemas/BrowserProxyConfig","description":"Proxy configuration for the browser session. Cannot be combined with proxy_id.\nOmit to use the browser default: stealth browsers use Kernel's default stealth proxy, while non-stealth browsers use direct egress.\nSet mode to direct to force direct egress regardless of stealth. Set mode to default to explicitly use the browser default: Kernel's default stealth proxy when stealth=true, or direct egress when stealth=false.\nSelect id or name to use that proxy regardless of stealth. Proxy selection does not change stealth or CAPTCHA solver behavior.\n"},"proxy_id":{"deprecated":true,"description":"Optional proxy to associate to the browser session. Must reference a proxy in the same project as the browser session. Deprecated in favor of proxy.","type":"string","x-deprecated-reason":"Use proxy instead."},"region":{"$ref":"#/components/schemas/Region","description":"Geographic region for the browser session. It is fixed once the session is created. Region selection requires a Start-Up or Enterprise plan, defaults to us-east when omitted on create.\n"},"start_url":{"description":"Optional URL to open when the browser session is created. Navigation is best-effort, so navigation failures do not prevent the session from being created.","example":"https://example.com","type":"string"},"stealth":{"description":"If true, launches the browser in stealth mode and enables the CAPTCHA solver. Defaults to false.\nWhen proxy is omitted, stealth browsers use Kernel's default stealth proxy and non-stealth browsers use direct egress.\nAn explicit proxy configuration changes only egress; it does not enable or disable stealth or the CAPTCHA solver.\n","example":true,"type":"boolean"},"tags":{"$ref":"#/components/schemas/Tags","description":"Optional user-defined key-value tags for the browser session, used to find and group sessions later. Can be changed later via PATCH /browsers/{id_or_name}. Up to 50 pairs.\n"},"telemetry":{"$ref":"#/components/schemas/BrowserTelemetryRequestConfig","description":"Telemetry configuration for the browser session. Set enabled to true to start capture using VM defaults, or provide browser category settings. If omitted, null, set to an empty object ({}), set to enabled: false without browser category settings, or all four categories are explicitly disabled, capture is not started.\n","nullable":true},"timeout_seconds":{"description":"The number of seconds of inactivity before the browser session is terminated. Activity includes CDP connections and live view connections. Defaults to 60 seconds. Minimum allowed is 10 seconds. Maximum allowed is 259200 (72 hours). We check for inactivity every 5 seconds, so the actual timeout behavior you will see is +/- 5 seconds around the specified value.","maximum":259200,"minimum":10,"type":"integer"},"vaults":{"description":"Project-scoped vaults to link to the browser session. Links are immutable after creation.","items":{"$ref":"#/components/schemas/VaultReference"},"maxItems":20,"type":"array"},"viewport":{"$ref":"#/components/schemas/BrowserViewport"}},"required":[],"type":"object"},"BrowserServiceCrashedEvent":{"description":"A managed service exited unexpectedly. Intentional stops do not produce this event; only unexpected exits and terminal restart-give-up transitions do.","properties":{"category":{"const":"system","type":"string"},"data":{"additionalProperties":false,"properties":{"phase":{"description":"Lifecycle phase the crash occurred in. startup: the process died before reaching a healthy running state. running: a previously healthy process died unexpectedly. gave_up: the process manager exhausted its restart attempts and stopped trying.","enum":["startup","running","gave_up"],"type":"string","x-go-type":"string"},"pid":{"description":"PID of the crashed process. Absent when the process manager gave up after exhausting restart attempts.","type":"integer"},"service_name":{"description":"Program name of the crashed service (e.g. chromium, mutter, kernel-images-api).","type":"string"}},"required":["service_name","phase"],"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"service_crashed","type":"string"}},"required":["ts","type","category","source"],"type":"object"},"BrowserSystemOomKillEvent":{"description":"The Linux kernel OOM-killer terminated a process inside the VM. Fires for any process killed by the kernel due to memory exhaustion, including Chrome renderer subprocesses that are not supervised.","properties":{"category":{"const":"system","type":"string"},"data":{"additionalProperties":false,"properties":{"constraint":{"description":"Why the kernel decided to OOM-kill. none means global memory exhaustion; memcg means a cgroup memory limit was hit; cpuset / memory_policy are NUMA/policy-driven kills. Absent on kernels older than 5.0.","enum":["none","memcg","cpuset","memory_policy"],"type":"string","x-go-type":"string"},"mem_free_kb":{"description":"Free system memory in KiB at the time of the kill. Assumes a 4 KiB page size. Does not include reclaimable caches. Absent if the kernel did not emit a parseable Mem-Info section.","type":"integer"},"mem_total_kb":{"description":"Total system memory in KiB at the time of the kill. Assumes a 4 KiB page size. Absent if the kernel did not emit a parseable Mem-Info section.","type":"integer"},"pid":{"description":"PID of the killed process.","type":"integer"},"process_name":{"description":"Comm of the killed process as reported by the kernel (max 15 chars, truncated by the kernel).","type":"string"},"rss_kb":{"description":"Resident set size of the killed process in KiB (sum of anon-rss, file-rss, and shmem-rss).","type":"integer"},"top_tasks":{"description":"Top processes by resident-set-size at the moment of the kill, sorted descending. Empty if the kernel did not emit the Tasks state table. Capped at 5 entries.","items":{"additionalProperties":false,"properties":{"name":{"description":"Comm of the process (max 15 chars, truncated by the kernel).","type":"string"},"pid":{"description":"PID of the process.","type":"integer"},"rss_kb":{"description":"Resident set size in KiB at the moment of the kill.","type":"integer"}},"required":["pid","name","rss_kb"],"type":"object"},"maxItems":5,"type":"array"},"trigger_pid":{"description":"PID of the triggering process. Absent if the kernel did not emit the standard header line.","type":"integer"},"trigger_process_name":{"description":"Comm of the process whose allocation request caused the kernel to invoke the OOM-killer. Often the same as process_name but can differ. Max 15 chars.","type":"string"}},"required":["process_name","pid","rss_kb"],"type":"object"},"source":{"$ref":"#/components/schemas/BrowserEventSource"},"truncated":{"description":"True if the data field was truncated due to size limits.","type":"boolean"},"ts":{"description":"Event timestamp in Unix microseconds.","format":"int64","type":"integer"},"type":{"const":"system_oom_kill","type":"string"}},"required":["ts","type","category","source"],"type":"object"},"BrowserTargetType":{"description":"CDP target type of the page that produced the event.","enum":["page","iframe","worker","background_page","service_worker","shared_worker","other"],"type":"string"},"BrowserTelemetryCategoriesConfig":{"description":"Per-category telemetry capture settings layered onto the default set. The operational signals (control, connection, system, captcha) are on by default and are opt-out: set one to enabled=false to stop capturing it. The CDP categories (console, network, page, interaction), screenshot and platform are off by default and are opt-in: set enabled=true to capture them.","properties":{"captcha":{"$ref":"#/components/schemas/BrowserTelemetryCategoryConfig","description":"Captcha solver tasks and visible challenge outcomes. On by default."},"connection":{"$ref":"#/components/schemas/BrowserTelemetryCategoryConfig","description":"Client attach/detach lifecycle for the CDP proxy and live view. On by default."},"console":{"$ref":"#/components/schemas/BrowserTelemetryCategoryConfig","description":"Console output (log, warn, error) and uncaught exceptions. CDP category; off by default."},"control":{"$ref":"#/components/schemas/BrowserTelemetryControlConfig","description":"Agent-driven actions against the browser — computer-control calls, Playwright code execution, screenshots, clipboard access, and browser-control commands sent over the CDP proxy. On by default."},"interaction":{"$ref":"#/components/schemas/BrowserTelemetryCategoryConfig","description":"User interaction events including clicks, keydowns, and scroll-settled events. CDP category; off by default."},"network":{"$ref":"#/components/schemas/BrowserTelemetryCategoryConfig","description":"HTTP request and response metadata including URL, method, status code, and timing. Request post data is forwarded as-is from CDP. Text response bodies are truncated at 8 KB for structured types (JSON, XML, form data) and 4 KB for other text types. Binary responses (images, fonts, media) are excluded. CDP category; off by default."},"page":{"$ref":"#/components/schemas/BrowserTelemetryCategoryConfig","description":"Page lifecycle events including navigation, DOMContentLoaded, load, layout shifts, and LCP. CDP category; off by default."},"platform":{"$ref":"#/components/schemas/BrowserTelemetryCategoryConfig","description":"In-VM API calls that manage the browser VM rather than drive the browser (recording, filesystem, process, telemetry and browser configuration). Mostly platform-induced; off by default and must be opted into."},"screenshot":{"$ref":"#/components/schemas/BrowserTelemetryCategoryConfig","description":"Periodic base64-encoded viewport screenshots. High volume; off by default and must be opted into."},"system":{"$ref":"#/components/schemas/BrowserTelemetryCategoryConfig","description":"Browser VM health, such as out-of-memory kills and managed-service crashes. On by default."}},"type":"object"},"BrowserTelemetryCategoryConfig":{"description":"Per-category telemetry configuration.","properties":{"enabled":{"description":"Whether this category is captured. Operational categories (control, connection, system, captcha) default to true; set false to opt out. CDP categories (console, network, page, interaction), screenshot and platform default to false; set true to opt in.","type":"boolean"}},"type":"object"},"BrowserTelemetryCdpControlConfig":{"description":"Settings for the cdp_command events the CDP proxy reports.","properties":{"excluded_methods":{"description":"Methods to leave out of the cdp_command stream. Omit the list to keep the current one; send an empty list to report every supported method again. Exclusion is a telemetry setting only: an excluded command is still relayed to the browser unchanged, it simply produces no event. Use it to drop the highest-volume methods — Input.dispatchMouseEvent during a humanized cursor path, or Page.captureScreenshot under a screencast — without turning the whole category off. Excluded commands are counted in cdp_disconnect.telemetry_excluded.","items":{"$ref":"#/components/schemas/BrowserCdpCommandMethod"},"type":"array"}},"type":"object"},"BrowserTelemetryConfig":{"description":"Active telemetry configuration for a browser session.","properties":{"browser":{"$ref":"#/components/schemas/BrowserTelemetryCategoriesConfig","description":"Per-category enable/disable flags."},"export":{"$ref":"#/components/schemas/BrowserTelemetryExportConfig","description":"Where the session's captured telemetry is being exported. Omitted when the export state is unknown."},"storage":{"$ref":"#/components/schemas/BrowserTelemetryStorageConfig","description":"Whether the session's captured telemetry is persisted to Kernel storage. Omitted for browsers created before this setting existed, which persist it."}},"type":"object"},"BrowserTelemetryControlConfig":{"description":"Configuration for the control category. Same enabled semantics as any other category, plus settings for the browser-control commands the CDP proxy reports.","properties":{"cdp":{"$ref":"#/components/schemas/BrowserTelemetryCdpControlConfig","description":"Settings for the cdp_command events the CDP proxy reports. Merged independently of enabled, so a later update that only sets enabled keeps the current exclusion list."},"enabled":{"description":"Whether this category is captured. Control is on by default; set false to opt out.","type":"boolean"}},"type":"object"},"BrowserTelemetryEvent":{"description":"Union type representing any browser telemetry event. Discriminated on `type`. Each event's `category` determines when it is captured. The CDP collector-health events (monitor_disconnected, monitor_reconnected, monitor_reconnect_failed, monitor_init_failed) use the `monitor` category, which is not user-configurable: it flows automatically whenever any CDP category (console, network, page, interaction) is captured, and is silent otherwise. monitor_screenshot uses the opt-in `screenshot` category. All other event types are controlled by their per-category enable/disable flags.\n","discriminator":{"mapping":{"api_call":"#/components/schemas/BrowserApiCallEvent","captcha_challenge_result":"#/components/schemas/BrowserCaptchaChallengeResultEvent","captcha_solve_result":"#/components/schemas/BrowserCaptchaSolveResultEvent","captcha_solve_started":"#/components/schemas/BrowserCaptchaSolveStartedEvent","cdp_command":"#/components/schemas/BrowserCdpCommandEvent","cdp_connect":"#/components/schemas/BrowserCdpConnectEvent","cdp_disconnect":"#/components/schemas/BrowserCdpDisconnectEvent","console_error":"#/components/schemas/BrowserConsoleErrorEvent","console_log":"#/components/schemas/BrowserConsoleLogEvent","interaction_click":"#/components/schemas/BrowserInteractionClickEvent","interaction_key":"#/components/schemas/BrowserInteractionKeyEvent","interaction_scroll_settled":"#/components/schemas/BrowserInteractionScrollSettledEvent","live_view_connect":"#/components/schemas/BrowserLiveViewConnectEvent","live_view_disconnect":"#/components/schemas/BrowserLiveViewDisconnectEvent","monitor_disconnected":"#/components/schemas/BrowserMonitorDisconnectedEvent","monitor_init_failed":"#/components/schemas/BrowserMonitorInitFailedEvent","monitor_reconnect_failed":"#/components/schemas/BrowserMonitorReconnectFailedEvent","monitor_reconnected":"#/components/schemas/BrowserMonitorReconnectedEvent","monitor_screenshot":"#/components/schemas/BrowserMonitorScreenshotEvent","network_idle":"#/components/schemas/BrowserNetworkIdleEvent","network_loading_failed":"#/components/schemas/BrowserNetworkLoadingFailedEvent","network_request":"#/components/schemas/BrowserNetworkRequestEvent","network_response":"#/components/schemas/BrowserNetworkResponseEvent","page_crashed":"#/components/schemas/BrowserPageCrashedEvent","page_dom_content_loaded":"#/components/schemas/BrowserPageDomContentLoadedEvent","page_layout_settled":"#/components/schemas/BrowserPageLayoutSettledEvent","page_layout_shift":"#/components/schemas/BrowserPageLayoutShiftEvent","page_lcp":"#/components/schemas/BrowserPageLcpEvent","page_load":"#/components/schemas/BrowserPageLoadEvent","page_navigation":"#/components/schemas/BrowserPageNavigationEvent","page_navigation_settled":"#/components/schemas/BrowserPageNavigationSettledEvent","page_tab_opened":"#/components/schemas/BrowserPageTabOpenedEvent","platform_api_call":"#/components/schemas/BrowserPlatformApiCallEvent","proxy_error":"#/components/schemas/BrowserProxyErrorEvent","service_crashed":"#/components/schemas/BrowserServiceCrashedEvent","system_oom_kill":"#/components/schemas/BrowserSystemOomKillEvent"},"propertyName":"type"},"oneOf":[{"$ref":"#/components/schemas/BrowserConsoleLogEvent"},{"$ref":"#/components/schemas/BrowserConsoleErrorEvent"},{"$ref":"#/components/schemas/BrowserNetworkRequestEvent"},{"$ref":"#/components/schemas/BrowserNetworkResponseEvent"},{"$ref":"#/components/schemas/BrowserNetworkLoadingFailedEvent"},{"$ref":"#/components/schemas/BrowserNetworkIdleEvent"},{"$ref":"#/components/schemas/BrowserProxyErrorEvent"},{"$ref":"#/components/schemas/BrowserPageNavigationEvent"},{"$ref":"#/components/schemas/BrowserPageDomContentLoadedEvent"},{"$ref":"#/components/schemas/BrowserPageLoadEvent"},{"$ref":"#/components/schemas/BrowserPageTabOpenedEvent"},{"$ref":"#/components/schemas/BrowserPageCrashedEvent"},{"$ref":"#/components/schemas/BrowserPageLayoutShiftEvent"},{"$ref":"#/components/schemas/BrowserPageLcpEvent"},{"$ref":"#/components/schemas/BrowserPageLayoutSettledEvent"},{"$ref":"#/components/schemas/BrowserPageNavigationSettledEvent"},{"$ref":"#/components/schemas/BrowserInteractionClickEvent"},{"$ref":"#/components/schemas/BrowserInteractionKeyEvent"},{"$ref":"#/components/schemas/BrowserInteractionScrollSettledEvent"},{"$ref":"#/components/schemas/BrowserMonitorScreenshotEvent"},{"$ref":"#/components/schemas/BrowserMonitorDisconnectedEvent"},{"$ref":"#/components/schemas/BrowserMonitorReconnectedEvent"},{"$ref":"#/components/schemas/BrowserMonitorReconnectFailedEvent"},{"$ref":"#/components/schemas/BrowserMonitorInitFailedEvent"},{"$ref":"#/components/schemas/BrowserApiCallEvent"},{"$ref":"#/components/schemas/BrowserPlatformApiCallEvent"},{"$ref":"#/components/schemas/BrowserCdpCommandEvent"},{"$ref":"#/components/schemas/BrowserCdpConnectEvent"},{"$ref":"#/components/schemas/BrowserCdpDisconnectEvent"},{"$ref":"#/components/schemas/BrowserLiveViewConnectEvent"},{"$ref":"#/components/schemas/BrowserLiveViewDisconnectEvent"},{"$ref":"#/components/schemas/BrowserCaptchaSolveStartedEvent"},{"$ref":"#/components/schemas/BrowserCaptchaSolveResultEvent"},{"$ref":"#/components/schemas/BrowserCaptchaChallengeResultEvent"},{"$ref":"#/components/schemas/BrowserSystemOomKillEvent"},{"$ref":"#/components/schemas/BrowserServiceCrashedEvent"}]},"BrowserTelemetryEventEnvelope":{"additionalProperties":false,"description":"Envelope wrapping a browser telemetry event with its monotonic sequence number. Each SSE data: frame carries one envelope as JSON. The seq value is also emitted as the SSE id: field so clients can pass it as Last-Event-ID on reconnect.\n","properties":{"event":{"$ref":"#/components/schemas/BrowserTelemetryEvent"},"seq":{"description":"Process-monotonic sequence number assigned by the browser VM. Pass as Last-Event-ID on reconnect to resume without gaps. Gaps in received seq values indicate dropped events.\n","format":"int64","minimum":1,"type":"integer"}},"required":["seq","event"],"type":"object"},"BrowserTelemetryExportConfig":{"description":"Active export state for a session's captured telemetry, by protocol.","properties":{"otlp":{"$ref":"#/components/schemas/BrowserTelemetryOTLPExportConfig","description":"Active OTLP export state."}},"type":"object"},"BrowserTelemetryExportRequestConfig":{"description":"Export destinations for a session's captured telemetry, by protocol. Honored when creating a browser, including the browser a managed auth connection creates for a login. Browser pools do not support export and reject it; on a browser update it is ignored, so the session keeps the destination it was created with.","properties":{"otlp":{"$ref":"#/components/schemas/BrowserTelemetryOTLPExportRequestConfig","description":"Export captured telemetry over OTLP to one of the org's configured destinations."}},"type":"object"},"BrowserTelemetryOTLPExportConfig":{"description":"Active OTLP export state for a browser session.","properties":{"destination":{"description":"ID of the OTLP destination the session is bound to. Omitted when the session is not exporting.","type":"string"},"enabled":{"description":"Whether the session is exporting captured telemetry over OTLP.","type":"boolean"}},"type":"object"},"BrowserTelemetryOTLPExportRequestConfig":{"description":"OTLP export settings for a browser session.","properties":{"destination":{"$ref":"#/components/schemas/OTLPDestinationRef","description":"OTLP destination to export this session's captured telemetry to. Provide either id or name. Requires telemetry capture to be enabled."},"enabled":{"description":"Whether to export captured telemetry over OTLP. Setting destination implies enabled=true, so this only needs to be set explicitly to disable export (enabled=false with a destination is rejected).","type":"boolean"}},"type":"object"},"BrowserTelemetryRequestConfig":{"description":"Telemetry request configuration for a browser session.","properties":{"browser":{"$ref":"#/components/schemas/BrowserTelemetryCategoriesConfig","description":"Per-category capture flags. The operational categories (control, connection, system, captcha) are captured whenever telemetry is enabled; set one to enabled=false to opt out. The CDP categories (console, network, page, interaction), screenshot and platform are off by default; set enabled=true to opt in. On create, provided categories layer onto the default set. On update, provided categories merge onto the session's current config; when no telemetry is active this falls back to the default set (matching create). If browser is omitted or empty, the default set is used. A browser config that disables every category stops capture on update and starts no capture on create."},"enabled":{"description":"Request shortcut for browser telemetry capture. True enables capture; with no browser category settings it captures the default set (control, connection, system, captcha), and any browser category settings are layered onto that default set. On update, enabled=true resolves the config fresh from the default set plus any provided categories, replacing the session's current selection rather than merging onto it; omit enabled to merge categories onto the current selection instead. False stops capture on update and starts no capture on create. enabled=false cannot be combined with browser category settings.","type":"boolean"},"export":{"$ref":"#/components/schemas/BrowserTelemetryExportRequestConfig","description":"Where to export this session's captured telemetry. Omit to capture without exporting."},"storage":{"$ref":"#/components/schemas/BrowserTelemetryStorageRequestConfig","description":"Whether to persist this session's captured telemetry to Kernel storage."}},"type":"object"},"BrowserTelemetryStorageConfig":{"description":"Kernel storage state for a session's captured telemetry.","properties":{"enabled":{"description":"Whether captured telemetry is persisted to Kernel storage. When off, the session's events are only available on the live stream and through any configured export.","type":"boolean"}},"type":"object"},"BrowserTelemetryStorageRequestConfig":{"description":"Kernel storage settings for a session's captured telemetry.","properties":{"enabled":{"description":"Whether captured telemetry is persisted to Kernel storage. Defaults to true. Setting false requires an OTLP destination and cannot be changed after the browser is created.","type":"boolean"}},"type":"object"},"BrowserUpdateRequest":{"description":"Request body for updating a browser session.","properties":{"disable_default_proxy":{"deprecated":true,"description":"If true, stealth browsers connect directly instead of using the default stealth proxy. Deprecated in favor of proxy.mode.","type":"boolean","x-deprecated-reason":"Use proxy.mode instead."},"name":{"description":"Human-readable name for the browser session. Omit to leave unchanged, set to an empty string to clear the name. When set, must be unique among active sessions within the project.\n","example":"checkout-flow-1","maxLength":255,"minLength":1,"nullable":true,"pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"},"profile":{"$ref":"#/components/schemas/BrowserProfile","description":"Profile to load into the browser session. Only allowed if the session does not already have a profile loaded."},"proxy":{"$ref":"#/components/schemas/BrowserProxyConfig","description":"Proxy configuration to apply. Omit to leave the current configuration unchanged. Cannot be combined with proxy_id or disable_default_proxy.\nSet mode to direct to switch to direct egress regardless of stealth. Set mode to default to restore the browser default after using a selected proxy: Kernel's default stealth proxy for a stealth browser, or direct egress for a non-stealth browser.\nUpdating proxy does not change stealth or CAPTCHA solver behavior.\n"},"proxy_id":{"deprecated":true,"description":"ID of the proxy to use. Omit to leave unchanged, set to empty string to remove proxy. Deprecated in favor of proxy.","nullable":true,"type":"string","x-deprecated-reason":"Use proxy instead."},"start_url":{"description":"Optional URL to navigate the browser to after applying this update. When a profile is loaded in the same update, this overrides the profile's restored tabs. Navigation is best-effort, so failures do not fail the update. Omit or set to an empty string to leave the current page unchanged.\n","example":"https://example.com","maxLength":2048,"type":"string"},"tags":{"$ref":"#/components/schemas/Tags","description":"User-defined key-value tags for the browser session. Omit to leave unchanged. Provide a map to replace the entire tag set (full replace, not a merge). Set to an empty object ({}) to clear all tags. Up to 50 pairs.\n","nullable":true},"telemetry":{"$ref":"#/components/schemas/BrowserTelemetryRequestConfig","description":"Telemetry configuration. Omit, set to null, or set to an empty object ({}) to leave the existing configuration unchanged. Set enabled to true to enable capture using VM defaults. Set enabled to false to stop capture. Provide browser category settings for per-category updates. Explicitly disabling all four categories also stops capture.\n","nullable":true},"viewport":{"$ref":"#/components/schemas/BrowserViewportUpdate","description":"Viewport configuration to apply to the browser session."}},"type":"object"},"BrowserUsage":{"description":"Session usage metrics.","properties":{"uptime_ms":{"description":"Time in milliseconds the session was actively running.","type":"integer"}},"required":["uptime_ms"],"type":"object"},"BrowserUsageStatus":{"description":"Whether final usage billing is still pending or complete. Only present for deleted sessions.","enum":["pending","ready"],"type":"string","x-enum-varnames":["BrowserUsageStatusPending","BrowserUsageStatusReady"]},"BrowserViewport":{"description":"Initial browser window size in pixels with optional refresh rate.\nIf omitted, image defaults apply (1920x1080@25).\nFor GPU images, the default is 1920x1080@60.\nArbitrary viewport dimensions and refresh rates are accepted.\nKnown-good presets include:\n2560x1440@10, 1920x1080@25, 1920x1200@25, 1440x900@25, 1280x800@60, 1024x768@60, 1200x800@60, 768x1024@60, 390x844@60.\nFor GPU images, recommended presets use one of these resolutions with refresh rates 60, 30, 25, or 10:\n800x600, 960x720, 1024x576, 1024x768, 1152x648, 1200x800, 1280x720, 1368x768, 1440x900, 1600x900, 1920x1080, 1920x1200, 390x844, 360x250, 768x1024, 800x1600.\nViewports outside this list may exhibit unstable live view or recording behavior.\nIf refresh_rate is not provided, it will be automatically determined based on the resolution\n(higher resolutions use lower refresh rates to keep bandwidth reasonable).\n","properties":{"height":{"description":"Browser window height in pixels. Any positive integer is accepted.","example":800,"minimum":1,"type":"integer"},"refresh_rate":{"description":"Display refresh rate in Hz. Any positive integer is accepted; if omitted, automatically determined from width and height.","example":60,"minimum":1,"type":"integer"},"width":{"description":"Browser window width in pixels. Any positive integer is accepted.","example":1280,"minimum":1,"type":"integer"}},"required":["width","height"],"type":"object"},"BrowserViewportUpdate":{"allOf":[{"$ref":"#/components/schemas/BrowserViewport"},{"properties":{"force":{"default":false,"description":"If true, allow the viewport change even when a live view or recording/replay is active.\nActive recordings will be gracefully stopped and restarted at the new resolution as\nseparate segments. If false (default), the resize is refused when a live view or recording is active.\n","type":"boolean"}},"type":"object"}],"description":"Viewport configuration for updating a browser session. Extends BrowserViewport with update-only options."},"CardEnrollmentAction":{"additionalProperties":false,"properties":{"name":{"enum":["card_enrollment"],"type":"string"},"url":{"format":"uri","type":"string"}},"required":["name","url"],"type":"object"},"CardVaultItem":{"additionalProperties":false,"properties":{"action":{"$ref":"#/components/schemas/VaultItemAction"},"available_expansions":{"items":{"$ref":"#/components/schemas/AvailableVaultItemExpansion"},"type":"array"},"available_operations":{"items":{"$ref":"#/components/schemas/AvailableVaultItemOperation"},"type":"array"},"created_at":{"format":"date-time","type":"string"},"expires_at":{"format":"date-time","type":"string"},"id":{"type":"string"},"key":{"description":"Immutable item key assigned when the item is created.","type":"string"},"spec":{"$ref":"#/components/schemas/CardVaultItemSpec"},"state":{"$ref":"#/components/schemas/CardVaultItemState"},"type":{"enum":["card"],"type":"string"},"updated_at":{"format":"date-time","type":"string"}},"required":["id","key","type","spec","state","available_operations","available_expansions","created_at","updated_at"],"type":"object"},"CardVaultItemRequest":{"additionalProperties":false,"properties":{"spec":{"$ref":"#/components/schemas/CardVaultItemSpec"},"type":{"enum":["card"],"type":"string"}},"required":["type","spec"],"type":"object"},"CardVaultItemSpec":{"discriminator":{"mapping":{"agentcard":"#/components/schemas/AgentCardCardVaultItemSpec","link":"#/components/schemas/LinkCardVaultItemSpec"},"propertyName":"provider"},"oneOf":[{"$ref":"#/components/schemas/LinkCardVaultItemSpec"},{"$ref":"#/components/schemas/AgentCardCardVaultItemSpec"}]},"CardVaultItemState":{"discriminator":{"mapping":{"agentcard":"#/components/schemas/AgentCardCardState","link":"#/components/schemas/LinkCardState"},"propertyName":"provider"},"oneOf":[{"$ref":"#/components/schemas/LinkCardState"},{"$ref":"#/components/schemas/AgentCardCardState"}]},"CardVaultItemUpdateRequest":{"additionalProperties":false,"properties":{"spec":{"$ref":"#/components/schemas/CardVaultItemSpec"},"type":{"enum":["card"],"type":"string","x-go-type-skip-optional-pointer":true}},"required":["spec"],"type":"object"},"ClickMouseRequest":{"additionalProperties":false,"properties":{"button":{"description":"Mouse button to interact with","enum":["left","right","middle","back","forward"],"type":"string"},"click_type":{"description":"Type of click action","enum":["down","up","click"],"type":"string"},"hold_keys":{"description":"Modifier keys to hold during the click","items":{"type":"string"},"type":"array"},"num_clicks":{"default":1,"description":"Number of times to repeat the click","type":"integer"},"true":{"description":"Y coordinate of the click position","type":"integer"},"x":{"description":"X coordinate of the click position","type":"integer"}},"required":["x",true],"type":"object"},"ClipboardContent":{"additionalProperties":false,"properties":{"text":{"description":"Current clipboard text content","type":"string"}},"required":["text"],"type":"object"},"CollectAction":{"additionalProperties":false,"properties":{"name":{"enum":["collect"],"type":"string"}},"required":["name"],"type":"object"},"CollectVaultItemOperationRequest":{"additionalProperties":false,"description":"Return the credential item with its collection action. Supported for ready\nand pending_collection credential items. Always render the same form from\nevery form-supported field; totp fields have no form input and are omitted.\nNo caller-selected field subsets or form overrides are accepted.\nReuse an active Kernel-hosted session or renew an expired session atomically.\nCustomer-hosted forms use their own backend and ordinary item GET/PATCH. Opening\nthe form does not clear values or change readiness or item version.\nTo observe edits on a ready item, record its version and poll GET without\nwait until the version changes, then reconcile the returned state. Version\nchanges may also come from PATCH; they do not identify a particular form\nsubmission. Customer-hosted apps use their own submission callback, including\nfor unchanged forms. The wait parameter waits for readiness, not edits.\n","properties":{"type":{"enum":["collect"],"type":"string"}},"required":["type"],"type":"object"},"ComputerAction":{"additionalProperties":false,"description":"A single computer action to execute as part of a batch. The `type` field selects which\naction to perform, and the corresponding field contains the action parameters.\nExactly one action field matching the type must be provided.\n","properties":{"click_mouse":{"$ref":"#/components/schemas/ClickMouseRequest"},"drag_mouse":{"$ref":"#/components/schemas/DragMouseRequest"},"move_mouse":{"$ref":"#/components/schemas/MoveMouseRequest"},"press_key":{"$ref":"#/components/schemas/PressKeyRequest"},"scroll":{"$ref":"#/components/schemas/ScrollRequest"},"set_cursor":{"$ref":"#/components/schemas/SetCursorRequest"},"sleep":{"$ref":"#/components/schemas/SleepAction"},"type":{"description":"The type of action to perform.","enum":["click_mouse","move_mouse","type_text","press_key","scroll","drag_mouse","set_cursor","sleep"],"type":"string"},"type_text":{"$ref":"#/components/schemas/TypeTextRequest"}},"required":["type"],"type":"object"},"ConfigRegistryAnalysis":{"properties":{"created_at":{"description":"Time the analysis was created.","format":"date-time","type":"string"},"expires_at":{"description":"Deadline after which a still-running analysis becomes expired.","format":"date-time","type":"string"},"failure":{"allOf":[{"$ref":"#/components/schemas/Error"}],"description":"Present for failed, canceled, or expired analyses. Messages contain safe retry guidance rather than internal workflow errors.","nullable":true},"finished_at":{"description":"Time the analysis reached a terminal status. Null while it is running.","format":"date-time","nullable":true,"type":"string"},"id":{"description":"Discovery run ID used to poll analysis status.","type":"string"},"intent":{"description":"The workload description supplied for this analysis. Null when the analysis only tested connectivity.","nullable":true,"type":"string"},"status":{"$ref":"#/components/schemas/ConfigRegistryAnalysisStatus"}},"required":["id","status","failure","created_at","expires_at","finished_at"],"type":"object"},"ConfigRegistryAnalysisInProgressError":{"additionalProperties":false,"properties":{"analysis_id":{"description":"ID of the running analysis to poll before retrying.","type":"string"},"code":{"const":"analysis_in_progress","type":"string"},"message":{"description":"Human-readable explanation of the conflict.","type":"string"}},"required":["code","message","analysis_id"],"type":"object"},"ConfigRegistryAnalysisStatus":{"description":"Lifecycle status of a background analysis.","enum":["running","completed","failed","canceled","expired"],"type":"string","x-enum-varnames":["ConfigRegistryAnalysisStatusRunning","ConfigRegistryAnalysisStatusCompleted","ConfigRegistryAnalysisStatusFailed","ConfigRegistryAnalysisStatusCanceled","ConfigRegistryAnalysisStatusExpired"]},"ConfigRegistryAnalysisSummary":{"properties":{"analysis":{"$ref":"#/components/schemas/ConfigRegistryAnalysis"},"target":{"$ref":"#/components/schemas/ConfigRegistryTarget"}},"required":["target","analysis"],"type":"object"},"ConfigRegistryBrowser":{"description":"Browser settings that can be passed directly to `POST /browsers`.","properties":{"gpu":{"type":"boolean"},"headless":{"type":"boolean"},"stealth":{"type":"boolean"},"viewport":{"$ref":"#/components/schemas/BrowserViewport"}},"required":["stealth","headless","gpu","viewport"],"type":"object"},"ConfigRegistryDirectProxy":{"additionalProperties":false,"description":"Direct egress recipe. Pass `{ \"mode\": \"direct\" }` as the browser's `proxy`.\n","properties":{"mode":{"enum":["direct"],"type":"string","x-enum-varnames":["ConfigRegistryDirectProxyModeDirect"]}},"required":["mode"],"type":"object"},"ConfigRegistryEvidence":{"properties":{"accessed":{"minimum":0,"type":"integer"},"blocked":{"minimum":0,"type":"integer"},"inconclusive":{"minimum":0,"type":"integer"},"last_observed_at":{"description":"Most recent contributing observation. Recommendations remain eligible regardless of age and can be returned while a new analysis refreshes them.","format":"date-time","type":"string"},"last_supported_at":{"description":"Most recent contributing run whose evidence supported recommending this configuration. Omitted when no individual run independently met the recommendation threshold.","format":"date-time","nullable":true,"type":"string"},"run_count":{"minimum":0,"type":"integer"},"sample_size":{"description":"Number of judged trials.","minimum":0,"type":"integer"},"success_rate":{"description":"Accessed trials divided by judged trials. Inconclusive trials are excluded.","maximum":1,"minimum":0,"type":"number"}},"required":["success_rate","sample_size","accessed","blocked","inconclusive","run_count","last_observed_at"],"type":"object"},"ConfigRegistryLookupRequest":{"properties":{"allowed_proxy_countries":{"description":"ISO 3166 country codes Kernel may use when returning a proxy configuration. When omitted, Kernel uses its default country selection.","example":["US"],"items":{"type":"string"},"maxItems":10,"minItems":1,"type":"array"},"url":{"description":"Public HTTP(S) URL to look up.","format":"uri","maxLength":2048,"type":"string"}},"required":["url"],"type":"object"},"ConfigRegistryLookupResponse":{"properties":{"guidance":{"description":"Short advisory markdown to facilitate navigating this target. Returned even when no configuration reached the target, since knowing what prevented success is useful without a configuration. Not verified against this target. Null when nothing applicable was observed or no notes exist.","nullable":true,"type":"string"},"recommendation":{"allOf":[{"$ref":"#/components/schemas/ConfigRegistryRecommendationResult"}],"description":"Recommendation or structured no-recommendation result from current knowledge. Only the proxy_restricted code is reported here. Null for every other outcome, including a target analyzed without a working configuration.","nullable":true},"target":{"$ref":"#/components/schemas/ConfigRegistryTarget"},"working_configurations":{"description":"Working configurations for the target, ordered with the recommended configuration first.","items":{"$ref":"#/components/schemas/ConfigRegistryRecommendation"},"type":"array"}},"required":["target","recommendation","working_configurations"],"type":"object"},"ConfigRegistryManagedProxy":{"additionalProperties":false,"description":"Managed proxy recipe. `create` is a non-idempotent `POST /proxies` payload:\ncreate the resource once, retain its ID, and reuse that ID as the browser's\n`proxy.id`. Do not submit this recipe before every browser session.\n","properties":{"create":{"$ref":"#/components/schemas/ProxyCreateRequest"},"mode":{"enum":["managed"],"type":"string","x-enum-varnames":["ConfigRegistryManagedProxyModeManaged"]}},"required":["mode","create"],"type":"object"},"ConfigRegistryNoRecommendation":{"additionalProperties":false,"properties":{"code":{"description":"Machine-readable reason Kernel cannot currently provide a config recommendation.\n","enum":["proxy_restricted","target_not_evaluable","no_working_configuration","inconclusive"],"type":"string","x-enum-varnames":["ConfigRegistryNoRecommendationCodeProxyRestricted","ConfigRegistryNoRecommendationCodeTargetNotEvaluable","ConfigRegistryNoRecommendationCodeNoWorkingConfiguration","ConfigRegistryNoRecommendationCodeInconclusive"]},"message":{"description":"Human-readable explanation suitable for display.","type":"string"},"type":{"const":"no_recommendation","type":"string"}},"required":["type","code","message"],"type":"object"},"ConfigRegistryProxy":{"description":"Proxy recipe for the recommended browser.","discriminator":{"mapping":{"direct":"#/components/schemas/ConfigRegistryDirectProxy","managed":"#/components/schemas/ConfigRegistryManagedProxy"},"propertyName":"mode"},"oneOf":[{"$ref":"#/components/schemas/ConfigRegistryDirectProxy"},{"$ref":"#/components/schemas/ConfigRegistryManagedProxy"}]},"ConfigRegistryRecommendation":{"properties":{"browser":{"$ref":"#/components/schemas/ConfigRegistryBrowser"},"evidence":{"$ref":"#/components/schemas/ConfigRegistryEvidence"},"match_scope":{"description":"Specificity of knowledge matched for this recommendation. Exact matches use knowledge for the requested target; host and domain matches use broader fallback knowledge.","enum":["exact","host","domain"],"type":"string","x-enum-varnames":["ConfigRegistryRecommendationMatchScopeExact","ConfigRegistryRecommendationMatchScopeHost","ConfigRegistryRecommendationMatchScopeDomain"]},"matched_target":{"description":"Target value that supplied the recommendation.","type":"string"},"proxy":{"$ref":"#/components/schemas/ConfigRegistryProxy"},"type":{"const":"recommendation","type":"string"}},"required":["type","browser","proxy","match_scope","matched_target","evidence"],"type":"object"},"ConfigRegistryRecommendationResult":{"description":"A recommendation or a structured no-recommendation result.","discriminator":{"mapping":{"no_recommendation":"#/components/schemas/ConfigRegistryNoRecommendation","recommendation":"#/components/schemas/ConfigRegistryRecommendation"},"propertyName":"type"},"oneOf":[{"$ref":"#/components/schemas/ConfigRegistryRecommendation"},{"$ref":"#/components/schemas/ConfigRegistryNoRecommendation"}]},"ConfigRegistryRecommendationSummary":{"properties":{"analysis_id":{"description":"ID of the most recently requested analysis for this exact target.","type":"string"},"analysis_status":{"$ref":"#/components/schemas/ConfigRegistryAnalysisStatus","description":"Lifecycle status of the most recently requested analysis for this exact target."},"last_requested_at":{"description":"Most recent time the selected project requested an analysis for this exact target.","format":"date-time","type":"string"},"recommendation":{"allOf":[{"$ref":"#/components/schemas/ConfigRegistryRecommendation"}],"description":"Recommendation produced by the latest analysis. Null when that analysis did not produce one.","nullable":true},"recommended_config_label":{"description":"Display label for the recommended browser configuration.","nullable":true,"type":"string"},"success_rate":{"description":"Success rate for the recommended configuration. Null when the latest analysis did not produce one.","maximum":1,"minimum":0,"nullable":true,"type":"number"},"target":{"description":"Normalized exact target previously analyzed by the selected project, including scheme, host, port, and path.","type":"string"}},"required":["target","analysis_id","analysis_status","recommendation","recommended_config_label","last_requested_at","success_rate"],"type":"object"},"ConfigRegistryResolveRequest":{"properties":{"allowed_proxy_countries":{"description":"ISO 3166 country codes Kernel may use when searching for or returning a proxy configuration. Kernel may test a subset of allowed countries. When omitted, Kernel uses its default country selection.","example":["US"],"items":{"type":"string"},"maxItems":10,"minItems":1,"type":"array"},"intent":{"description":"Plain-language description of the workload you intend to run against this target, in a sentence or two. Requires an https target, because the pass treats any non-HTTPS destination as off-site and will not drive an http one. Kernel uses it to drive the browser further into the site, where it can observe protections that only appear once a session interacts. When this target already has a recommended configuration, the run confirms that one instead of re-deriving the whole matrix, so supplying an intent narrows what can be recommended.","example":"search for a black hoodie and add it to the cart","maxLength":300,"type":"string"},"url":{"description":"Public HTTP(S) URL to refresh.","format":"uri","maxLength":2048,"type":"string"}},"required":["url"],"type":"object"},"ConfigRegistryResponse":{"properties":{"analysis":{"allOf":[{"$ref":"#/components/schemas/ConfigRegistryAnalysis"}],"description":"Pollable analysis after workflow submission is acknowledged. Null when no refresh was submitted.","nullable":true},"guidance":{"description":"Short advisory markdown to facilitate navigating this target. Returned even when no configuration reached the target, since knowing what prevented success is useful without a configuration. Not verified against this target. Null when nothing applicable was observed or no notes exist.","nullable":true,"type":"string"},"recommendation":{"allOf":[{"$ref":"#/components/schemas/ConfigRegistryRecommendationResult"}],"description":"Recommendation or structured no-recommendation result for a completed analysis. Null before the analysis produces an outcome.","nullable":true},"target":{"$ref":"#/components/schemas/ConfigRegistryTarget"},"working_configurations":{"description":"Working configurations for the target, ordered with the recommended configuration first.","items":{"$ref":"#/components/schemas/ConfigRegistryRecommendation"},"type":"array"},"workload_outcome":{"description":"How far the workload pass got, when an intent was supplied and a pass ran. A run outcome rather than advice, so it is reported whether or not any guidance could be assembled. Null when no intent was supplied or no pass ran.","enum":["completed","turn_limit","auth_required","payment_required","blocked","error"],"nullable":true,"type":"string"}},"required":["target","analysis","recommendation","working_configurations"],"type":"object"},"ConfigRegistryTarget":{"properties":{"domain":{"description":"Registrable domain.","type":"string"},"host":{"description":"Full hostname, including subdomain.","type":"string"},"normalized":{"description":"Exact normalized scheme, host, port, and path used for lookup.","type":"string"}},"required":["normalized","host","domain"],"type":"object"},"CreateApiKeyRequest":{"properties":{"days_to_expire":{"description":"Number of days until expiry, up to 3650. Use null for never.","example":30,"maximum":3650,"minimum":1,"nullable":true,"type":"integer"},"name":{"description":"Label for the API key (1-255 characters). API keys are not addressable by name.","example":"staging","maxLength":255,"minLength":1,"type":"string"},"project_id":{"description":"Unique project identifier","example":"proj_abc123","nullable":true,"type":"string"}},"required":["name"],"type":"object"},"CreateAuditLogExportDestinationRequest":{"additionalProperties":false,"properties":{"bucket":{"maxLength":63,"minLength":3,"type":"string"},"format":{"enum":["jsonl.gz"],"type":"string"},"kms_key_id":{"maxLength":2048,"type":"string"},"prefix":{"maxLength":512,"type":"string"},"region":{"maxLength":128,"minLength":1,"type":"string"},"role_arn":{"maxLength":2048,"minLength":1,"type":"string"},"type":{"enum":["s3"],"type":"string"}},"required":["type","region","bucket","prefix","role_arn","format"],"type":"object"},"CreateCredentialProviderRequest":{"additionalProperties":false,"description":"Request to create an external credential provider","properties":{"cache_ttl_seconds":{"default":300,"description":"How long to cache credential lists (default 300 seconds)","example":300,"type":"integer"},"name":{"description":"Human-readable name for this provider instance (unique per org). Surrounding whitespace is trimmed and the trimmed value must be non-empty.","example":"my-1password","minLength":1,"pattern":"\\S","type":"string"},"provider_type":{"description":"Type of credential provider","enum":["onepassword"],"example":"onepassword","type":"string"},"token":{"description":"Service account token for the provider (e.g., 1Password service account token)","example":"ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...","type":"string"}},"required":["provider_type","name","token"],"type":"object"},"CreateCredentialRequest":{"additionalProperties":false,"description":"Request to create a new credential","properties":{"domain":{"description":"Target domain this credential is for","example":"netflix.com","type":"string"},"name":{"description":"Unique name for the credential within the project","example":"my-netflix-login","type":"string"},"sso_provider":{"description":"If set, indicates this credential should be used with the specified SSO provider (e.g., google, github, microsoft). When the target site has a matching SSO button, it will be clicked first before filling credential values on the identity provider's login page.","example":"google","type":"string"},"totp_algorithm":{"description":"HMAC algorithm used to generate TOTP codes. Defaults to SHA1 and is ignored when an `otpauth://` URI supplies the algorithm.","enum":["SHA1","SHA256","SHA512"],"example":"SHA1","type":"string"},"totp_digits":{"description":"Number of digits in generated TOTP codes. Defaults to 6 and is ignored when an `otpauth://` URI supplies the digit count.","example":6,"maximum":9,"minimum":6,"type":"integer"},"totp_period":{"description":"TOTP rotation period in seconds. Defaults to 30 and is ignored when an `otpauth://` URI supplies the period.","example":30,"maximum":300,"minimum":15,"type":"integer"},"totp_secret":{"description":"Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...` URI. The range accepts existing shorter seeds and longer seeds regardless of HMAC algorithm; RFC 6238 recommends unpadded base32 lengths of 32/52/103 for SHA1/SHA256/SHA512. Only URI parameters present override the corresponding explicit TOTP fields. Used for automatic 2FA during login.","example":"JBSWY3DPEHPK3PXP","type":"string"},"values":{"additionalProperties":{"type":"string"},"description":"Field name to value mapping (e.g., username, password)","example":{"password":"mysecretpassword","username":"user@example.com"},"type":"object"}},"required":["name","domain","values"],"type":"object"},"CreateCustomProxyConfig":{"description":"Configuration for a custom proxy (e.g., private proxy server).","properties":{"ca_bundle":{"description":"PEM-encoded CA certificate bundle the proxy re-signs upstream TLS with. Provide when the proxy terminates TLS (MITM) so the browser trusts its certificates. May contain multiple concatenated certificates.","example":"-----BEGIN CERTIFICATE-----\nMIIB...\n-----END CERTIFICATE-----\n","maxLength":65536,"type":"string"},"host":{"description":"Proxy host address or IP.","example":"127.0.0.1","type":"string"},"password":{"description":"Password for proxy authentication.","example":"secret","maxLength":4096,"type":"string"},"port":{"description":"Proxy port.","example":8080,"type":"integer"},"username":{"description":"Username for proxy authentication.","example":"user123","type":"string"}},"required":["host","port"],"title":"Custom","type":"object"},"CreateDirectoryRequest":{"additionalProperties":false,"properties":{"mode":{"description":"Optional directory mode (octal string, e.g. 755). Defaults to 755.","pattern":"^[0-7]{3,4}$","type":"string"},"path":{"description":"Absolute directory path to create.","pattern":"^/.*","type":"string"}},"required":["path"],"type":"object"},"CreateProjectRequest":{"properties":{"name":{"description":"Project name (1-255 Unicode code points; cannot contain `/` or `%`)","example":"staging","maxLength":255,"minLength":1,"type":"string"}},"required":["name"],"type":"object"},"CreatedApiKey":{"allOf":[{"$ref":"#/components/schemas/ApiKey"},{"properties":{"key":{"description":"Plaintext API key. Only returned once when the key is created.","example":"sk_1234abcd","type":"string"}},"required":["key"],"type":"object"}],"description":"API key returned immediately after creation. Includes the plaintext key once."},"Credential":{"additionalProperties":false,"description":"A stored credential for automatic re-authentication","properties":{"created_at":{"description":"When the credential was created","example":"2025-01-15T10:30:00Z","format":"date-time","type":"string"},"domain":{"description":"Target domain this credential is for","example":"netflix.com","type":"string"},"has_totp_secret":{"description":"Whether this credential has a TOTP secret configured for automatic 2FA","example":false,"type":"boolean"},"has_values":{"description":"Whether this credential has stored values (email, password, etc.)","example":true,"type":"boolean"},"id":{"description":"Unique identifier for the credential","example":"cred_abc123xyz","type":"string"},"name":{"description":"Unique name for the credential within the project","example":"my-netflix-login","type":"string"},"sso_provider":{"description":"If set, indicates this credential should be used with the specified SSO provider (e.g., google, github, microsoft). When the target site has a matching SSO button, it will be clicked first before filling credential values on the identity provider's login page.","example":"google","nullable":true,"type":"string"},"totp_algorithm":{"description":"HMAC algorithm used to generate TOTP codes. Defaults to SHA1 for credentials created before this metadata was stored.","enum":["SHA1","SHA256","SHA512"],"example":"SHA1","type":"string"},"totp_code":{"description":"Current TOTP code. Only included in create/update responses when totp_secret was just set.","example":"847291","type":"string"},"totp_code_expires_at":{"description":"When the totp_code expires. Only included when totp_code is present.","example":"2025-01-15T10:30:30Z","format":"date-time","type":"string"},"totp_digits":{"description":"Number of digits in generated TOTP codes. Defaults to 6 for credentials created before this metadata was stored.","example":6,"maximum":9,"minimum":6,"type":"integer"},"totp_period":{"description":"TOTP rotation period in seconds. Defaults to 30 for credentials created before this metadata was stored.","example":30,"maximum":300,"minimum":15,"type":"integer"},"updated_at":{"description":"When the credential was last updated","example":"2025-01-15T10:30:00Z","format":"date-time","type":"string"},"value_keys":{"description":"The field names stored in this credential's values (e.g., username, password). Values themselves are never returned. Included on single-credential responses (create, get by id or name, update); omitted from list responses.","example":["username","password"],"items":{"type":"string"},"type":"array"}},"required":["id","name","domain","created_at","updated_at"],"type":"object"},"CredentialAccountVaultItem":{"additionalProperties":false,"properties":{"action":{"$ref":"#/components/schemas/OnePasswordOAuthAction"},"available_expansions":{"items":{"$ref":"#/components/schemas/AvailableVaultItemExpansion"},"maxItems":0,"type":"array"},"available_operations":{"description":"Advertises 1pw_recover when Kernel can recover a failed account link. Recovery is unavailable while authorization is pending or after the connection has already been reset.","items":{"$ref":"#/components/schemas/AvailableVaultItemOperation"},"maxItems":1,"type":"array"},"created_at":{"format":"date-time","type":"string"},"expires_at":{"format":"date-time","type":"string"},"id":{"type":"string"},"key":{"description":"Immutable item key assigned when the item is created.","type":"string"},"spec":{"$ref":"#/components/schemas/OnePasswordCredentialAccountSpec"},"state":{"$ref":"#/components/schemas/OnePasswordCredentialAccountState"},"type":{"enum":["credential_account"],"type":"string"},"updated_at":{"format":"date-time","type":"string"}},"required":["id","key","type","spec","state","available_operations","available_expansions","created_at","updated_at"],"type":"object"},"CredentialAccountVaultItemRequest":{"additionalProperties":false,"properties":{"spec":{"$ref":"#/components/schemas/OnePasswordCredentialAccountSpec"},"type":{"enum":["credential_account"],"type":"string"}},"required":["type","spec"],"type":"object"},"CredentialCollectionAction":{"additionalProperties":false,"description":"One schema-derived form for the item, available in ready or pending_collection\nstate. Render every form-supported field as editable; omit totp fields and\npreserve their stored seeds. Prefill non-sensitive values,\nand allow existing sensitive values to be preserved or replaced without ever\nrevealing them. No field subsets or per-request form configuration exist.\nValidate required fields against the resulting values, including preserved\nsecrets. Submit changed values only, using the version used to render the form.\nScoped hosted submission rejects totp edits; seed writes require the ordinary\nauthenticated item API. Customer forms likewise omit totp from their payloads.\nSave edits atomically. A successful hosted submission increments the version,\nmarks ready, and consumes the session; an empty edit may complete collection\nwhile preserving values. A customer form uses PATCH for changed values and\ndoes not send an empty PATCH when nothing changed.\nKernel-hosted bearer sessions require no Kernel account and are bound to the\nitem version. Expired, superseded, consumed, or deleted-item sessions cannot\nsubmit. Authenticated item GET renews expired active sessions for ready or pending items; pending\nitems always receive an action. A ready item with no active session omits the\naction until collect is invoked. Concurrent renewals return the same link.\nRenewal changes neither values nor item version. An expired link cannot renew\nitself. The hosted form handles its collection protocol; callers only open\nthe returned URL and do not extract or submit its token through the public API.\nFor customer-hosted forms, use @onkernel/vault-react and an authenticated\ncustomer backend calling the ordinary item GET/PATCH API. Kernel does not\nstore customer collection URLs or authenticate the customer's end users.\nTreat URLs and submitted values as secrets and exclude them from logs,\ntraces, and errors.\n","properties":{"expires_at":{"description":"Expiry of the Kernel-hosted collection link (30 minutes after issuance).","format":"date-time","type":"string"},"name":{"enum":["collect"],"type":"string"},"url":{"description":"Time-scoped hosted form URL (vault.kernel.sh in production). Open this URL as returned; treat it as a secret.","format":"uri","type":"string"}},"required":["name","url","expires_at"],"type":"object"},"CredentialProvider":{"additionalProperties":false,"description":"An external credential provider (e.g., 1Password) for automatic credential lookup","properties":{"created_at":{"description":"When the credential provider was created","example":"2025-01-15T10:30:00Z","format":"date-time","type":"string"},"enabled":{"description":"Whether the provider is enabled for credential lookups","example":true,"type":"boolean"},"id":{"description":"Unique identifier for the credential provider","example":"credprov_abc123xyz","type":"string"},"name":{"description":"Human-readable name for this provider instance","example":"my-1password","type":"string"},"priority":{"description":"Priority order for credential lookups (lower numbers are checked first)","example":0,"type":"integer"},"provider_type":{"description":"Type of credential provider","enum":["onepassword"],"example":"onepassword","type":"string"},"updated_at":{"description":"When the credential provider was last updated","example":"2025-01-15T10:30:00Z","format":"date-time","type":"string"}},"required":["id","provider_type","name","enabled","priority","created_at","updated_at"],"type":"object"},"CredentialProviderItem":{"additionalProperties":false,"description":"A credential item from an external provider (e.g., a 1Password login item)","properties":{"id":{"description":"Unique identifier for the item within the provider","example":"abc123xyz","type":"string"},"path":{"description":"Path to reference this item (VaultName/ItemTitle format)","example":"Engineering/Netflix Login","type":"string"},"title":{"description":"Display name of the credential item","example":"Netflix Login","type":"string"},"urls":{"description":"URLs associated with this credential","example":["https://netflix.com","https://www.netflix.com"],"items":{"type":"string"},"type":"array"},"vault_id":{"description":"ID of the vault containing this item","example":"vault_abc123","type":"string"},"vault_name":{"description":"Name of the vault containing this item","example":"Engineering","type":"string"}},"required":["id","title","vault_id","vault_name","path"],"type":"object"},"CredentialProviderTestResult":{"additionalProperties":false,"description":"Result of testing a credential provider connection","properties":{"error":{"description":"Error message if the test failed","example":"Invalid token","type":"string"},"success":{"description":"Whether the connection test was successful","example":true,"type":"boolean"},"vaults":{"description":"List of vaults accessible by the service account","items":{"properties":{"id":{"description":"Vault ID","example":"abc123xyz","type":"string"},"name":{"description":"Vault name","example":"Shared Logins","type":"string"}},"required":["id","name"],"type":"object"},"type":"array"}},"required":["success","vaults"],"type":"object"},"CredentialReference":{"additionalProperties":false,"description":"Reference to credentials for the auth connection. Use one of:\n- { name } for Kernel credentials\n- { provider, path } for external provider item\n- { provider, auto: true } for external provider domain lookup\n","properties":{"auto":{"description":"If true, lookup by domain from the specified provider","example":true,"type":"boolean"},"name":{"description":"Kernel credential name","example":"my-netflix-creds","type":"string"},"path":{"description":"Provider-specific path (e.g., \"VaultName/ItemName\" for 1Password)","example":"Personal/Netflix","type":"string"},"provider":{"description":"External provider name (e.g., \"my-1p\")","example":"my-1p","type":"string"}},"type":"object"},"CredentialVaultFieldDefinition":{"additionalProperties":false,"properties":{"label":{"description":"Optional human-readable display label. It is returned as non-secret metadata and never affects value keys, updates, or browser fills. Use single-line, trimmed display text without control or formatting characters. The server enforces a 128-byte UTF-8 limit.","maxLength":128,"minLength":1,"pattern":"^\\S(?:.*\\S)?$","type":"string"},"name":{"description":"Stable field name used to key values, updates, and browser fills.","pattern":"^[a-zA-Z][a-zA-Z0-9_]{0,63}$","type":"string"},"required":{"description":"Whether a nonempty value is required for readiness and form submission.","type":"boolean"},"sensitive":{"description":"Whether the value is omitted from every item response. Reserve true for secrets such as passwords, API tokens, and TOTP seeds. Ordinary usernames and email addresses should be false so the form can display and prefill them.","type":"boolean"},"type":{"$ref":"#/components/schemas/CredentialVaultFieldType"}},"required":["name","type","required","sensitive"],"type":"object"},"CredentialVaultFieldInput":{"additionalProperties":false,"properties":{"label":{"description":"Optional human-readable display label. It is returned as non-secret metadata and never affects value keys, updates, or browser fills. Use single-line, trimmed display text without control or formatting characters. The server enforces a 128-byte UTF-8 limit.","maxLength":128,"minLength":1,"pattern":"^\\S(?:.*\\S)?$","type":"string"},"name":{"description":"Unique stable field name used to key values, updates, and browser fills.","pattern":"^[a-zA-Z][a-zA-Z0-9_]{0,63}$","type":"string"},"required":{"default":true,"type":"boolean"},"sensitive":{"default":true,"description":"Set false explicitly for ordinary usernames, email addresses, and other non-secret identifiers. Reserve true for secrets such as passwords, API tokens, and TOTP seeds. Password and totp fields must be true. Omission defaults to true for safety; do not rely on that default for every field. False permits API reads and form prefilling.","type":"boolean"},"type":{"$ref":"#/components/schemas/CredentialVaultFieldType"},"value":{"description":"Optional initial value satisfying the declared type, at most 16 KiB in UTF-8 bytes. Omit to leave unset; null and empty strings are rejected on creation. Sensitive values are encrypted and never copied into the returned spec.","maxLength":16384,"minLength":1,"type":"string"}},"required":["name","type"],"type":"object"},"CredentialVaultFieldState":{"additionalProperties":false,"properties":{"has_value":{"type":"boolean"},"value":{"description":"Present exactly when has_value is true and the field is not sensitive. Reflects the latest developer or human edit. For totp, has_value indicates a stored seed; neither the seed nor a generated code is returned.","minLength":1,"type":"string"}},"required":["has_value"],"type":"object"},"CredentialVaultFieldType":{"description":"Text, email, and password have form inputs; totp does not and is omitted from\nboth Kernel-hosted and customer React forms. Password and totp must be sensitive.\nA totp value is an RFC 4648 Base32 generator seed (case-insensitive, optional\ntrailing padding), not an otpauth URI or current code. Reject invalid or empty\ndecoded seeds. Browser fill generates an RFC 6238 code at execution time using\nHMAC-SHA1, 6 digits, and a 30-second period. Preserve leading zeros; never fill\nthe seed. Custom algorithms, digits, periods, and form enrollment are unsupported.\n","enum":["text","email","password","totp"],"type":"string"},"CredentialVaultFieldUpdate":{"additionalProperties":false,"properties":{"value":{"description":"Replacement value (at most 16 KiB in UTF-8 bytes), or null or an empty string to immediately clear the stored value. Clearing a required form-supported field reopens collection; clearing an optional field does not prevent readiness. Values must satisfy the declared field type. For totp, value is the generator seed, never a current code. Clearing a required totp field returns 400 because it cannot be collected in a form.","maxLength":16384,"type":["string","null"]}},"required":["value"],"type":"object"},"CredentialVaultItem":{"additionalProperties":false,"properties":{"action":{"$ref":"#/components/schemas/CredentialVaultItemAction"},"available_expansions":{"items":{"$ref":"#/components/schemas/AvailableVaultItemExpansion"},"maxItems":0,"type":"array"},"available_operations":{"description":"Kernel credentials advertise collect and fill when eligible. 1Password credentials advertise 1pw_create_access_request until a request is made, 1pw_access_request_status while its approval is pending, and 1pw_fill after access is granted.","items":{"$ref":"#/components/schemas/AvailableVaultItemOperation"},"type":"array"},"created_at":{"format":"date-time","type":"string"},"id":{"type":"string"},"key":{"description":"Immutable item key assigned when the item is created.","type":"string"},"spec":{"$ref":"#/components/schemas/CredentialVaultItemSpec"},"state":{"$ref":"#/components/schemas/CredentialVaultItemState"},"type":{"enum":["credential"],"type":"string"},"updated_at":{"format":"date-time","type":"string"},"version":{"description":"Starts at 1 and increments on PATCH and successful hosted submission, but not collection-link renewal.","minimum":1,"type":"integer"}},"required":["id","key","type","version","spec","state","available_operations","available_expansions","created_at","updated_at"],"type":"object"},"CredentialVaultItemAction":{"discriminator":{"mapping":{"1password_access_approval":"#/components/schemas/OnePasswordAccessApprovalAction","collect":"#/components/schemas/CredentialCollectionAction"},"propertyName":"name"},"oneOf":[{"$ref":"#/components/schemas/CredentialCollectionAction"},{"$ref":"#/components/schemas/OnePasswordAccessApprovalAction"}]},"CredentialVaultItemRequest":{"additionalProperties":false,"description":"Ask the end-user whether to link their site credential through 1Password.\nIf they choose 1Password, connect their account and request access to a login\nin their own non-shared vault; passkeys are not supported. If they decline\nor that path fails, collect a Kernel-hosted credential item instead. Never\nautomatically retry an uncertain 1Password request or fill.\nDo not use credential items for credit card data. Use wallet and card item types instead.\nKernel credentials declare fields and may enter pending_collection.\n1Password credentials either reference a connected credential_account or\nstore a supplied access token and integration key encrypted on the item.\nThey store no login values or selectors. Repeating the original creation\nrequest returns the current item without overwriting later state. A\ndifferent request at the same key returns 409.\n","properties":{"spec":{"$ref":"#/components/schemas/CredentialVaultItemSpecInput"},"type":{"enum":["credential"],"type":"string"}},"required":["type","spec"],"type":"object"},"CredentialVaultItemSpec":{"discriminator":{"mapping":{"1password":"#/components/schemas/OnePasswordCredentialVaultItemSpec","kernel":"#/components/schemas/KernelCredentialVaultItemSpec"},"propertyName":"provider"},"oneOf":[{"$ref":"#/components/schemas/KernelCredentialVaultItemSpec"},{"$ref":"#/components/schemas/OnePasswordCredentialVaultItemSpec"}]},"CredentialVaultItemSpecInput":{"discriminator":{"mapping":{"1password":"#/components/schemas/OnePasswordCredentialVaultItemSpecInput","kernel":"#/components/schemas/KernelCredentialVaultItemSpecInput"},"propertyName":"provider"},"oneOf":[{"$ref":"#/components/schemas/KernelCredentialVaultItemSpecInput"},{"$ref":"#/components/schemas/OnePasswordCredentialVaultItemSpecInput"}]},"CredentialVaultItemSpecUpdate":{"additionalProperties":false,"minProperties":1,"properties":{"description":{"description":"Recognizable site or service name used as the form title, without suffixes such as sign-in credentials. An empty string clears it. Display text only, not an enforced destination policy. The server also enforces a 16 KiB UTF-8 byte limit.","maxLength":16384,"type":"string"},"fields":{"additionalProperties":{"$ref":"#/components/schemas/CredentialVaultFieldUpdate"},"maxProperties":32,"minProperties":1,"type":"object"}},"type":"object"},"CredentialVaultItemState":{"discriminator":{"mapping":{"1password":"#/components/schemas/OnePasswordCredentialVaultItemState","kernel":"#/components/schemas/KernelCredentialVaultItemState"},"propertyName":"provider"},"oneOf":[{"$ref":"#/components/schemas/KernelCredentialVaultItemState"},{"$ref":"#/components/schemas/OnePasswordCredentialVaultItemState"}]},"CredentialVaultItemUpdateRequest":{"additionalProperties":false,"description":"Atomically update description and selected values. Omitted properties are\npreserved. Field names, types, required flags, and sensitivity cannot change.\nUnknown field names return 400; stale versions or mismatched item types\nreturn 409 without changing the item. A successful update increments version\nand invalidates outstanding Kernel-hosted collection sessions. If required\nvalues remain missing, return pending_collection and a fresh collection\naction. Otherwise return ready without an action; collect can open the form\nagain without clearing values. Customer URLs have no Kernel-managed expiry.\n","properties":{"expected_item_id":{"description":"Optional immutable item ID precondition. Returns 409 if the key now identifies a different item. Accepted writes target this immutable ID, preventing replacement-key races. Supply this when submitting a form bound to a previously read item.","minLength":1,"type":"string"},"spec":{"$ref":"#/components/schemas/CredentialVaultItemSpecUpdate"},"type":{"enum":["credential"],"type":"string"},"version":{"description":"Expected current item version from the latest read.","minimum":1,"type":"integer"}},"required":["type","version","spec"],"type":"object"},"CustomProxyConfig":{"description":"Configuration for a custom proxy (e.g., private proxy server).","properties":{"has_ca_bundle":{"description":"Whether the proxy has a custom CA bundle configured.","example":true,"type":"boolean"},"has_password":{"description":"Whether the proxy has a password.","example":true,"type":"boolean"},"host":{"description":"Proxy host address or IP.","example":"127.0.0.1","type":"string"},"port":{"description":"Proxy port.","example":8080,"type":"integer"},"username":{"description":"Username for proxy authentication.","example":"user123","type":"string"}},"required":["host","port"],"title":"Custom","type":"object"},"CustomWebMCPDefinition":{"additionalProperties":false,"properties":{"id":{"pattern":"^ct_[a-z][a-z0-9]{23}$","type":"string"},"kind":{"pattern":"^(page|cdp)$","type":"string"},"match":{"$ref":"#/components/schemas/CustomWebMCPMatch"},"namespace":{"type":"string"},"tool":{"$ref":"#/components/schemas/WebMCPToolMetadata"}},"required":["id","namespace","kind","match","tool"],"type":"object"},"CustomWebMCPMatch":{"additionalProperties":false,"properties":{"url_patterns":{"items":{"type":"string"},"minItems":1,"type":"array"}},"required":["url_patterns"],"type":"object"},"CustomWebMCPToolsResponse":{"additionalProperties":false,"properties":{"tools":{"items":{"$ref":"#/components/schemas/CustomWebMCPDefinition"},"type":"array"}},"required":["tools"],"type":"object"},"CustomerManagedOAuthClient":{"additionalProperties":false,"properties":{"provider_config":{"$ref":"#/components/schemas/VaultProviderConfigReference"},"type":{"enum":["customer_managed"],"type":"string"}},"required":["type","provider_config"],"type":"object"},"DatacenterProxyConfig":{"description":"Configuration for a datacenter proxy.","properties":{"country":{"description":"ISO 3166 country code. Defaults to US if not provided.","example":"US","type":"string"}},"title":"Datacenter","type":"object"},"DeletePathRequest":{"additionalProperties":false,"properties":{"path":{"description":"Absolute path to delete.","pattern":"^/.*","type":"string"}},"required":["path"],"type":"object"},"Deployment":{"description":"Deployment record information.","properties":{"created_at":{"description":"Timestamp when the deployment was created","format":"date-time","type":"string"},"entrypoint_rel_path":{"description":"Relative path to the application entrypoint","example":"src/app.py","type":"string"},"env_vars":{"additionalProperties":{"type":"string"},"description":"Environment variables configured for this deployment. Values are redacted for API key, OAuth, and managed-auth callers, which receive every key with an empty string value. Only dashboard sessions receive the actual values.","type":"object"},"id":{"description":"Unique identifier for the deployment","example":"rr33xuugxj9h0bkf1rdt2bet","type":"string"},"region":{"const":"aws.us-east-1a","description":"Deployment region code","example":"aws.us-east-1a","type":"string"},"source_checksum":{"description":"Hex-encoded SHA-256 checksum of the source archive. For file uploads, this hashes the uploaded archive; for GitHub-sourced deployments, this hashes the GitHub archive downloaded by the API. Omitted for deployments created before this field was recorded.","example":"3f4d0ea1bd2c5c1a1a1f0e9d8c7b6a5948372615049382716a5b4c3d2e1f0a9b","type":"string"},"source_path":{"description":"For GitHub-sourced deployments, the subpath within the repository that was used as the deploy root. Omitted when the repo root was used or for file uploads.","example":"apps/api","type":"string"},"source_ref":{"description":"For GitHub-sourced deployments, the git ref as requested at deploy time (branch, tag, or commit SHA — not resolved to a commit). Omitted for file uploads.","example":"main","type":"string"},"source_type":{"description":"Origin of the deployed source code. This is read-only response provenance; `file` indicates an uploaded archive and `github` indicates a repository fetched by the API.","enum":["file","github"],"example":"github","type":"string","x-go-type-name":"DeploymentSourceOrigin"},"source_url":{"description":"For GitHub-sourced deployments, the repository URL that was fetched. Omitted for file uploads.","example":"https://github.com/org/repo","type":"string"},"status":{"description":"Current status of the deployment","enum":["queued","in_progress","running","failed","stopped"],"example":"queued","type":"string"},"status_reason":{"description":"Status reason","example":"Deployment in progress","type":"string"},"updated_at":{"description":"Timestamp when the deployment was last updated","format":"date-time","nullable":true,"type":"string"}},"required":["id","status","region","created_at"],"type":"object"},"DeploymentEvent":{"description":"Union type representing any deployment event.","discriminator":{"mapping":{"app_version_summary":"#/components/schemas/AppVersionSummary","deployment_state":"#/components/schemas/DeploymentStateEvent","error":"#/components/schemas/InternalError","log":"#/components/schemas/LogEvent","sse_heartbeat":"#/components/schemas/SSEHeartbeatEvent"},"propertyName":"event"},"oneOf":[{"$ref":"#/components/schemas/LogEvent"},{"$ref":"#/components/schemas/DeploymentStateEvent"},{"$ref":"#/components/schemas/AppVersionSummaryEvent"},{"$ref":"#/components/schemas/ErrorEvent"},{"$ref":"#/components/schemas/SSEHeartbeatEvent"}]},"DeploymentRequest":{"description":"App deployment request. Provide either file+entrypoint_rel_path or source.","oneOf":[{"required":["file","entrypoint_rel_path"]},{"required":["source"]}],"properties":{"entrypoint_rel_path":{"description":"Relative path to the entrypoint of the application","example":"src/app.py","type":"string"},"env_vars":{"additionalProperties":{"type":"string"},"description":"Map of environment variables to set for the deployed application. Each key-value pair represents an environment variable.","type":"object"},"file":{"description":"ZIP file containing the application source directory","example":"@path/to/file.zip","format":"binary","type":"string"},"force":{"default":false,"description":"Allow overwriting an existing app version","example":false,"type":"boolean"},"region":{"const":"aws.us-east-1a","default":"aws.us-east-1a","description":"Region for deployment. Currently we only support \"aws.us-east-1a\"","example":"aws.us-east-1a","type":"string"},"source":{"$ref":"#/components/schemas/DeploymentSource"},"version":{"default":"latest","description":"Version of the application. Can be any string.","example":"1.0.0","type":"string"}},"type":"object"},"DeploymentSource":{"description":"Source from which to fetch application code.","properties":{"auth":{"description":"Authentication for private repositories.","properties":{"method":{"description":"Auth method","enum":["github_token"],"example":"github_token","type":"string"},"token":{"description":"GitHub PAT or installation access token","example":"ghs_***","format":"password","type":"string"}},"required":["method","token"],"type":"object"},"entrypoint":{"description":"Relative path to the application entrypoint within the selected path.","example":"src/index.ts","type":"string"},"path":{"description":"Path within the repo to deploy (omit to use repo root).","example":"apps/api","type":"string"},"ref":{"description":"Git ref (branch, tag, or commit SHA) to fetch.","example":"main","type":"string"},"type":{"description":"Source type identifier.","enum":["github"],"example":"github","type":"string"},"url":{"description":"Base repository URL (without blob/tree suffixes).","example":"https://github.com/org/repo","type":"string"}},"required":["type","url","ref","entrypoint"],"type":"object"},"DeploymentStateEvent":{"description":"An event representing the current state of a deployment.","properties":{"deployment":{"$ref":"#/components/schemas/Deployment"},"event":{"const":"deployment_state","description":"Event type identifier (always \"deployment_state\").","type":"string"},"timestamp":{"description":"Time the state was reported.","format":"date-time","type":"string"}},"required":["event","deployment","timestamp"],"type":"object"},"DiscoveredField":{"additionalProperties":false,"description":"A discovered form field","properties":{"hint":{"description":"Contextual help text near the field that tells the user what to enter (e.g., \"Enter the phone ending in (***) ***-**92\")","example":"Enter the phone ending in (***) ***-**92","type":"string"},"label":{"description":"Field label","example":"Email address","type":"string"},"linked_mfa_type":{"$ref":"#/components/schemas/MFAType","description":"If this field is associated with an MFA option, the type of that option (e.g., password field linked to \"Enter password\" option)","nullable":true},"name":{"description":"Field name","example":"email","type":"string"},"placeholder":{"description":"Field placeholder","example":"you@example.com","type":"string"},"required":{"default":true,"description":"Whether field is required","example":true,"type":"boolean"},"selector":{"description":"CSS selector for the field","example":"input#email","type":"string"},"type":{"description":"Field type","enum":["text","email","password","tel","number","url","code","totp"],"example":"email","type":"string"}},"required":["name","type","label","selector"],"type":"object"},"DragMouseRequest":{"additionalProperties":false,"properties":{"button":{"description":"Mouse button to drag with","enum":["left","middle","right"],"type":"string"},"delay":{"default":0,"description":"Delay in milliseconds between button down and starting to move along the path.","minimum":0,"type":"integer"},"duration_ms":{"description":"Target total duration in milliseconds for the entire drag movement when smooth=true. Omit for automatic timing based on total path length.","maximum":10000,"minimum":50,"type":"integer"},"hold_keys":{"description":"Modifier keys to hold during the drag","items":{"type":"string"},"type":"array"},"path":{"description":"Ordered list of [x, y] coordinate pairs to move through while dragging. Must contain at least 2 points.","items":{"items":{"type":"integer"},"maxItems":2,"minItems":2,"type":"array"},"minItems":2,"type":"array"},"smooth":{"default":true,"description":"Use human-like Bezier curves between path waypoints instead of linear interpolation. When true, steps_per_segment and step_delay_ms are ignored.","type":"boolean"},"step_delay_ms":{"default":50,"description":"Delay in milliseconds between relative steps while dragging (not the initial delay).","minimum":0,"type":"integer"},"steps_per_segment":{"default":10,"description":"Number of relative move steps per segment in the path. Minimum 1.","minimum":1,"type":"integer"}},"required":["path"],"type":"object"},"EmbeddedCeremonyAction":{"additionalProperties":false,"properties":{"name":{"enum":["embedded_ceremony"],"type":"string"}},"required":["name"],"type":"object"},"Error":{"properties":{"code":{"description":"Application-specific error code (machine-readable)","example":"bad_request","type":"string"},"details":{"description":"Additional error details (for multiple errors)","items":{"$ref":"#/components/schemas/ErrorDetail"},"type":"array"},"inner_error":{"$ref":"#/components/schemas/ErrorDetail"},"message":{"description":"Human-readable error description for debugging","example":"Missing required field: app_name","type":"string"}},"required":["code","message"],"type":"object"},"ErrorDetail":{"properties":{"code":{"description":"Lower-level error code providing more specific detail","example":"invalid_input","type":"string"},"message":{"description":"Further detail about the error","example":"Provided version string is not semver compliant","type":"string"}},"type":"object"},"ErrorEvent":{"description":"An error event from the application.","properties":{"error":{"$ref":"#/components/schemas/Error"},"event":{"const":"error","description":"Event type identifier (always \"error\").","type":"string"},"timestamp":{"description":"Time the error occurred.","format":"date-time","type":"string"}},"required":["event","timestamp","error"],"type":"object"},"ExecutePlaywrightRequest":{"additionalProperties":false,"description":"Request to execute Playwright code","properties":{"code":{"description":"TypeScript/JavaScript code to execute. The code has access to 'page', 'context', and 'browser' variables.\nIt runs within a function, so you can use a return statement at the end to return a value.\nThis value is returned as the `result` property in the response.\nExample: \"await page.goto('https://example.com'); return await page.title();\"\n","type":"string"},"timeout_sec":{"default":60,"description":"Maximum execution time in seconds. Default is 60.","maximum":300,"minimum":1,"type":"integer"}},"required":["code"],"type":"object"},"ExecutePlaywrightResult":{"additionalProperties":false,"description":"Result of Playwright code execution","properties":{"error":{"description":"Error message if execution failed","type":"string"},"result":{"description":"The value returned by the code (if any)"},"stderr":{"description":"Standard error from the execution","type":"string"},"stdout":{"description":"Standard output from the execution","type":"string"},"success":{"description":"Whether the code executed successfully","type":"boolean"}},"required":["success"],"type":"object"},"Extension":{"description":"A browser extension uploaded to Kernel.","properties":{"checksum":{"description":"SHA-256 checksum, encoded as lowercase hexadecimal, of the exact uploaded extension archive bytes. This is not a normalized checksum of the extension contents; archive metadata, file ordering, and compression can change the checksum for otherwise identical contents. Omitted for legacy rows and server-repackaged Chrome Web Store extensions.","maxLength":64,"minLength":64,"nullable":true,"type":"string"},"created_at":{"description":"Timestamp when the extension was created","format":"date-time","type":"string"},"id":{"description":"Unique identifier for the extension","type":"string"},"last_used_at":{"description":"Timestamp when the extension was last used","format":"date-time","nullable":true,"type":"string"},"name":{"description":"Optional, easier-to-reference name for the extension. Must be unique within the project.","nullable":true,"type":"string"},"size_bytes":{"description":"Size of the extension archive in bytes","type":"integer"}},"required":["id","created_at","size_bytes"],"type":"object"},"FileInfo":{"properties":{"is_dir":{"description":"Whether the path is a directory.","type":"boolean"},"mod_time":{"description":"Last modification time.","format":"date-time","type":"string"},"mode":{"description":"File mode bits (e.g., \"drwxr-xr-x\" or \"-rw-r--r--\").","type":"string"},"name":{"description":"Base name of the file or directory.","type":"string"},"path":{"description":"Absolute path.","type":"string"},"size_bytes":{"description":"Size in bytes. 0 for directories.","type":"integer"}},"required":["name","path","size_bytes","is_dir","mod_time","mode"],"type":"object"},"FileSystemEvent":{"description":"Filesystem change event.","properties":{"is_dir":{"description":"Whether the affected path is a directory.","type":"boolean"},"name":{"description":"Base name of the file or directory affected.","type":"string"},"path":{"description":"Absolute path of the file or directory.","type":"string"},"type":{"description":"Event type.","enum":["CREATE","WRITE","DELETE","RENAME"],"type":"string"}},"required":["type","path"],"type":"object"},"FillVaultItemOperationRequest":{"additionalProperties":false,"description":"Fill selected fields from one ready credential or ready, unexpired Link card\ninto a browser linked to its vault.\nOnly invoke when the item advertises `fill`. Browser and vault must belong\nto the same project. Kernel checks access and allowed destinations before\nfilling; providing a page URL does not authorize a destination.\n\nFind exactly one open page matching `page_url`. Credential items may omit\n`page_url` to require exactly one open page; cards require an HTTPS page URL.\nCredentials have no destination allowlist. TOTP fields generate a current\ncode immediately before writing; their seeds never enter the browser. For each selector, search\nthe main frame and all descendant frames for editable inputs or selects\nmatched directly or contained within matching elements. Each selector must\nresolve to one unique editable element across all frames; zero or multiple\ncandidates fail. Count each element once, even if multiple matching\ncontainers contain it. Validate all bindings before filling.\nSelect elements match an option by its value, not its label.\nIf the page navigates or a target disappears during filling, stop rather\nthan selecting a different page or element.\n\nFill in request order and stop on the first failure. This operation is\nnot atomic: previously filled fields are not rolled back. Never submit\nthe form or click buttons, though input/change events may trigger site\nbehavior. Link cards use fill for browser checkout and do not expose\naliases or support egress substitution. Do not automatically retry a\nfailed or indeterminate operation.\n\nSecret values are never returned or included in operation logs, traces,\naudit events, or error details. This does not prevent an agent with\nunrestricted browser access from reading values from the page or other\nbrowser observation surfaces.\n","example":{"browser_id":"browser-session-id","fields":[{"field":"number","selector":"#card-number"},{"field":"exp_month","selector":"#expiry-month"},{"field":"exp_year","selector":"#expiry-year"},{"field":"cvc","selector":"#security-code"}],"page_url":"https://shop.example/checkout","type":"fill"},"properties":{"browser_id":{"description":"Browser session ID, not a reusable browser name.","minLength":1,"type":"string"},"fields":{"description":"Field bindings for this step. No two bindings may resolve to the same element.","items":{"$ref":"#/components/schemas/VaultFillField"},"maxItems":32,"minItems":1,"type":"array"},"page_url":{"description":"Exact current top-level page URL, including path, query, and fragment. Must match exactly one open page in the browser; zero or multiple matches fail. No prefix or glob matching. Required for cards, which must use HTTPS without embedded credentials. Optional for credentials, where omission requires exactly one open page.","format":"uri","pattern":"^\\S+$","type":"string","x-go-type-skip-optional-pointer":true},"timeout_ms":{"default":10000,"description":"Total operation deadline in milliseconds, not a per-field timeout.","maximum":30000,"minimum":1,"type":"integer"},"type":{"enum":["fill"],"type":"string"}},"required":["type","browser_id","fields"],"type":"object"},"FillVaultItemOperationResult":{"additionalProperties":false,"properties":{"fields":{"description":"Exactly one result per request binding, in request order. After the first failed or unknown field, all remaining fields are not_attempted.","items":{"$ref":"#/components/schemas/VaultFillFieldResult"},"maxItems":32,"minItems":1,"type":"array"},"status":{"description":"Completed only when all fields were filled. Failed when execution stopped with known outcomes. Unknown when any field's outcome cannot be determined. None of these statuses confirms payment or merchant acceptance.","enum":["completed","failed","unknown"],"type":"string"},"type":{"enum":["fill"],"type":"string"}},"required":["type","status","fields"],"type":"object"},"ImportedLinkAuthorizationInput":{"additionalProperties":false,"description":"The customer's backend completes Link OAuth and supplies the resulting tokens. For a new wallet, Kernel verifies the access token can access Link payment methods without consuming or rotating the refresh token. Valid access creates a wallet with state.status=connected. An expired, invalid, revoked, or insufficiently scoped access token returns 400 and no wallet is created. Refresh expired tokens in your backend before importing them. A failed import does not modify existing wallets.\nAfter successful import, Kernel owns subsequent refresh-token rotation; the customer must stop refreshing this grant. Import does not verify the refresh token: if it or the configured client credentials are rejected during a later refresh, the imported wallet becomes degraded. An unknown refresh outcome also leaves it degraded; Kernel does not retry a refresh token that may already have been consumed. There is no in-place reauthorization operation for an imported wallet.\nIf this imported wallet's credentials become unusable, obtain a fresh Link OAuth grant in your backend and create a wallet under a NEW wallet key. Use the new wallet for NEW cards and payments, not to retry an old payment whose outcome is uncertain. This does not replace the old grant, rebind existing cards, or resolve their payment outcomes. Retain the old wallet and its cards while reconciling any uncertain payments with the provider or support. Do not repeat an uncertain payment on the new wallet, and do not treat deletion as evidence that it did not execute. Deletion of the old wallet can remain blocked by unresolved child cards.\nRepeating a create for the same item key and non-secret spec returns the existing wallet without replacing tokens, even if they have rotated or the wallet needs reconnection. ID and name references resolving to the same config are equivalent. A different config or non-secret spec returns 409. This create operation does not replace an existing grant.","properties":{"client":{"$ref":"#/components/schemas/CustomerManagedOAuthClient"},"method":{"enum":["oauth"],"type":"string"},"tokens":{"allOf":[{"$ref":"#/components/schemas/LinkWalletTokenInput"}],"writeOnly":true}},"required":["method","client","tokens"],"type":"object"},"InstanceProxyError":{"properties":{"code":{"$ref":"#/components/schemas/InstanceProxyErrorCode"},"message":{"description":"Human-readable error description for debugging","type":"string"}},"required":["code","message"],"type":"object"},"InstanceProxyErrorCode":{"description":"Canonical error code returned by browser instance API proxy routes","enum":["invalid_request","unauthorized","forbidden","session_not_leased","not_found","conflict","session_gone","rate_limit_exceeded","internal_error","browser_unavailable"],"type":"string"},"Invocation":{"properties":{"action_name":{"description":"Name of the action invoked","example":"analyze","type":"string"},"app_name":{"description":"Name of the application","example":"my-app","type":"string"},"finished_at":{"description":"RFC 3339 Nanoseconds timestamp when the invocation finished (null if still running)","example":"2024-05-19T15:30:05.000000000Z07:00","format":"date-time","nullable":true,"type":"string"},"id":{"description":"ID of the invocation","example":"rr33xuugxj9h0bkf1rdt2bet","type":"string"},"output":{"description":"The action result or detailed failure output. Often a JSON-encoded value, but failures may contain plain text. May contain sensitive application data.","example":"{\"result\":\"success\",\"data\":\"processed input\"}","type":"string"},"payload":{"description":"Payload provided to the invocation. This is a string that can be parsed as JSON.","example":"{\"data\":\"example input\"}","type":"string"},"started_at":{"description":"RFC 3339 Nanoseconds timestamp when the invocation started","example":"2024-05-19T15:30:00.000000000Z07:00","format":"date-time","type":"string"},"status":{"description":"Status of the invocation","enum":["queued","running","succeeded","failed"],"example":"succeeded","type":"string"},"status_reason":{"description":"A nonempty, customer-safe summary of the recorded failure output, always present when status is failed and omitted otherwise, including in the first failed invocation_state event. Recognized messages receive a specific summary; other failures receive a generic summary. Message matching does not establish whether the failure originated in the platform or action code. Does not include raw action output or internal error details. Available for historical invocations as well. Human-readable text, not a stable identifier for retry logic.","example":"Invocation timed out after 900 seconds.","minLength":1,"type":"string"},"version":{"description":"Version label for the application","example":"1.0.0","type":"string"}},"required":["id","app_name","version","action_name","started_at","status"],"type":"object"},"InvocationEvent":{"description":"Union type representing any invocation event.","discriminator":{"mapping":{"error":"#/components/schemas/ErrorEvent","invocation_state":"#/components/schemas/InvocationStateEvent","log":"#/components/schemas/LogEvent","sse_heartbeat":"#/components/schemas/SSEHeartbeatEvent"},"propertyName":"event"},"oneOf":[{"$ref":"#/components/schemas/LogEvent"},{"$ref":"#/components/schemas/InvocationStateEvent"},{"$ref":"#/components/schemas/ErrorEvent"},{"$ref":"#/components/schemas/SSEHeartbeatEvent"}]},"InvocationStateEvent":{"description":"An event representing the current state of an invocation.","properties":{"event":{"const":"invocation_state","description":"Event type identifier (always \"invocation_state\").","type":"string"},"invocation":{"$ref":"#/components/schemas/Invocation"},"timestamp":{"description":"Time the state was reported.","format":"date-time","type":"string"}},"required":["event","invocation","timestamp"],"type":"object"},"InvocationUpdateRequest":{"description":"Request body for updating an invocation.","properties":{"output":{"description":"Updated output of the invocation rendered as JSON string.","type":"string"},"status":{"description":"New status for the invocation.","enum":["succeeded","failed"],"type":"string"}},"required":["status"],"type":"object"},"InvokeResponse":{"properties":{"action_name":{"description":"Name of the action invoked","example":"analyze","type":"string"},"id":{"description":"ID of the invocation","example":"rr33xuugxj9h0bkf1rdt2bet","type":"string"},"output":{"description":"The action result or detailed failure output. Often a JSON-encoded value, but failures may contain plain text. May contain sensitive application data.","example":"{\"result\":\"success\",\"data\":\"processed input\"}","type":"string"},"status":{"description":"Status of the invocation","enum":["queued","running","succeeded","failed"],"example":"queued","type":"string"},"status_reason":{"description":"A nonempty, customer-safe summary of the recorded failure output, always present when status is failed and omitted otherwise. Recognized messages receive a specific summary; other failures receive a generic summary. Message matching does not establish whether the failure originated in the platform or action code. Does not include raw action output or internal error details. Human-readable text, not a stable identifier for retry logic.","example":"Invocation timed out after 900 seconds.","minLength":1,"type":"string"}},"required":["id","action_name","status"],"type":"object"},"IspProxyConfig":{"description":"Configuration for an ISP proxy.","properties":{"country":{"description":"ISO 3166 country code. Supported countries are US, GB, FR, DE, and SG. Defaults to US if not provided.","example":"US","type":"string"}},"title":"ISP","type":"object"},"KernelCredentialVaultItemSpec":{"additionalProperties":false,"properties":{"description":{"description":"Recognizable site or service name displayed verbatim as the form title, without suffixes such as sign-in credentials. Display text only, not an enforced destination policy.","maxLength":16384,"type":"string"},"fields":{"description":"Ordered field definitions rendered in this order by credential collection forms.","items":{"$ref":"#/components/schemas/CredentialVaultFieldDefinition"},"maxItems":32,"minItems":1,"type":"array"},"provider":{"enum":["kernel"],"type":"string"}},"required":["provider","fields"],"type":"object"},"KernelCredentialVaultItemSpecInput":{"additionalProperties":false,"description":"Credential fields are for login and other non-payment credentials. Do not store, collect, or fill credit card data in credential items. Use wallet and card item types for credit cards and payment checkout instead. Field order is preserved in the user-facing collection form, so list fields in the same top-to-bottom order as the website.","properties":{"description":{"description":"The site's recognizable display name, used verbatim as the user-facing form title (for example, Hacker News). Use only the site or service name; do not append sign-in, login, credentials, or task instructions. This is display text, not an enforced destination policy. At most 16 KiB in UTF-8 bytes.","maxLength":16384,"type":"string"},"fields":{"description":"Ordered field definitions. Use the website's top-to-bottom field order; the collection form renders this order unchanged.","items":{"$ref":"#/components/schemas/CredentialVaultFieldInput"},"maxItems":32,"minItems":1,"type":"array"},"provider":{"enum":["kernel"],"type":"string"}},"required":["provider","fields"],"type":"object"},"KernelCredentialVaultItemState":{"additionalProperties":false,"properties":{"fields":{"additionalProperties":{"$ref":"#/components/schemas/CredentialVaultFieldState"},"description":"Exactly one entry for each declared field.","minProperties":1,"type":"object"},"provider":{"enum":["kernel"],"type":"string"},"status":{"description":"Ready means all required fields have values, not that a login succeeded. Optional fields may remain unset.","enum":["pending_collection","ready"],"type":"string"}},"required":["provider","status","fields"],"type":"object"},"KernelManagedLinkAuthorizationInput":{"additionalProperties":false,"description":"Kernel starts and completes the user's Link authorization flow.","properties":{"client":{"$ref":"#/components/schemas/KernelManagedOAuthClient"},"method":{"enum":["oauth"],"type":"string"}},"required":["method","client"],"type":"object"},"KernelManagedOAuthClient":{"additionalProperties":false,"properties":{"type":{"enum":["kernel_managed"],"type":"string"}},"required":["type"],"type":"object"},"LinkCardState":{"additionalProperties":false,"description":"Issued Link cards retain encrypted card material for the fill operation. Link cards do not expose aliases or support egress substitution.","properties":{"domains":{"items":{"type":"string"},"type":"array"},"masks":{"$ref":"#/components/schemas/VaultItemMasks"},"provider":{"enum":["link"],"type":"string"},"status":{"description":"recovery_required means an original provider operation has an unresolved outcome. Do not retry, delete, or replace it. Known references may be observed safely, but unknown creation without an ID and uncertain card-material retrieval require manual reconciliation with the provider or support. There is no reset or caller-asserted reconciliation operation.","enum":["requested","pending_authorization","ready","consumed","expired","declined","recovery_required"],"type":"string"},"status_reason":{"type":"string"}},"required":["provider","status"],"type":"object"},"LinkCardVaultItemSpec":{"additionalProperties":false,"description":"Live payment card. Test-mode card creation is not supported.","properties":{"amount":{"description":"Integer amount in minor currency units. Link permits at most 50000 per spend request.","maximum":50000,"minimum":1,"type":"integer"},"context":{"minLength":100,"type":"string"},"currency":{"maxLength":3,"minLength":3,"pattern":"^[A-Za-z]{3}$","type":"string"},"expires_at":{"format":"int64","type":"integer"},"line_items":{"items":{"$ref":"#/components/schemas/LinkLineItem"},"type":"array"},"merchant_name":{"maxLength":255,"minLength":1,"type":"string"},"merchant_url":{"format":"uri","type":"string"},"metadata":{"additionalProperties":{"type":"string"},"type":"object"},"payment_method_id":{"description":"Payment-method ID returned by the referenced wallet's payment-method listing. The provider decides whether the selected funding method can satisfy the card request.","minLength":1,"type":"string"},"provider":{"enum":["link"],"type":"string"},"totals":{"items":{"$ref":"#/components/schemas/LinkTotal"},"type":"array"},"wallet":{"description":"Wallet item key used to mint this card.","type":"string"}},"required":["provider","wallet","payment_method_id","amount","currency","merchant_name","merchant_url","context"],"type":"object"},"LinkLineItem":{"additionalProperties":false,"properties":{"description":{"type":"string"},"image_url":{"type":"string"},"name":{"type":"string"},"product_url":{"type":"string"},"quantity":{"minimum":1,"type":"integer"},"sku":{"type":"string"},"totals":{"items":{"$ref":"#/components/schemas/LinkTotal"},"type":"array"},"unit_amount":{"description":"Unit amount in minor currency units.","type":"integer"},"url":{"type":"string"}},"required":["name"],"type":"object"},"LinkOAuthAction":{"additionalProperties":false,"properties":{"name":{"enum":["link_oauth"],"type":"string"},"url":{"format":"uri","type":"string"}},"required":["name","url"],"type":"object"},"LinkOAuthAuthorization":{"additionalProperties":false,"properties":{"client":{"$ref":"#/components/schemas/LinkOAuthClient"},"method":{"enum":["oauth"],"type":"string"}},"required":["method","client"],"type":"object"},"LinkOAuthClient":{"discriminator":{"mapping":{"customer_managed":"#/components/schemas/CustomerManagedOAuthClient","kernel_managed":"#/components/schemas/KernelManagedOAuthClient"},"propertyName":"type"},"oneOf":[{"$ref":"#/components/schemas/KernelManagedOAuthClient"},{"$ref":"#/components/schemas/CustomerManagedOAuthClient"}]},"LinkTotal":{"additionalProperties":false,"properties":{"amount":{"description":"Total amount in minor currency units.","type":"integer"},"display_text":{"type":"string"},"type":{"type":"string"}},"required":["type","display_text","amount"],"type":"object"},"LinkWalletState":{"additionalProperties":false,"properties":{"provider":{"enum":["link"],"type":"string"},"status":{"enum":["pending_authorization","connected","declined","reconnect_required","degraded"],"type":"string"},"status_reason":{"type":"string"}},"required":["provider","status"],"type":"object"},"LinkWalletTokenInput":{"additionalProperties":false,"description":"Send the token pair from your backend. Both tokens must be from the same Link grant under the referenced client. Supply a currently valid access token. Kernel refreshes when needed after import and uses the expiry returned by Link for subsequent tokens. Tokens are never returned in wallet responses, events, or logs.","properties":{"access_token":{"minLength":1,"type":"string","writeOnly":true},"refresh_token":{"minLength":1,"type":"string","writeOnly":true}},"required":["access_token","refresh_token"],"type":"object"},"LinkWalletVaultItemRequestSpec":{"additionalProperties":false,"properties":{"authorization":{"oneOf":[{"$ref":"#/components/schemas/KernelManagedLinkAuthorizationInput"},{"$ref":"#/components/schemas/ImportedLinkAuthorizationInput"}]},"provider":{"enum":["link"],"type":"string"}},"required":["provider","authorization"],"type":"object"},"LinkWalletVaultItemSpec":{"additionalProperties":false,"properties":{"authorization":{"$ref":"#/components/schemas/LinkOAuthAuthorization"},"provider":{"enum":["link"],"type":"string"}},"required":["provider","authorization"],"type":"object"},"ListFiles":{"description":"Array of file or directory information entries.","items":{"$ref":"#/components/schemas/FileInfo"},"type":"array"},"LogEvent":{"description":"A log entry from the application.","properties":{"event":{"const":"log","description":"Event type identifier (always \"log\").","type":"string"},"message":{"description":"Log message text.","type":"string"},"timestamp":{"description":"Time the log entry was produced.","format":"date-time","type":"string"}},"required":["event","message","timestamp"],"type":"object"},"LoginRequest":{"additionalProperties":false,"description":"Request to start a login flow","properties":{"browser":{"$ref":"#/components/schemas/ManagedAuthBrowserConfig","description":"Browser configuration override for this login. Omitted properties inherit the connection defaults."},"browser_telemetry":{"$ref":"#/components/schemas/BrowserTelemetryRequestConfig","deprecated":true,"description":"Deprecated. Use browser.telemetry. Retained during migration for existing clients.","nullable":true},"proxy":{"$ref":"#/components/schemas/ProxyRef","deprecated":true,"description":"Deprecated. Use browser.proxy. Retained during migration for existing clients."},"record_session":{"description":"Override the connection's default for recording this login's browser session. When omitted, the connection's record_session default is used.","example":true,"type":"boolean"},"skill_mode":{"description":"Controls whether this login reads and writes learned domain skills. Automatic reauths inherit the selected mode until a later accepted login sets enabled or omits this field. Defaults to enabled when omitted.","enum":["enabled","disabled"],"type":"string","x-enum-varnames":["LoginRequestSkillModeEnabled","LoginRequestSkillModeDisabled"]}},"type":"object"},"LoginResponse":{"additionalProperties":false,"description":"Response from starting a login flow","properties":{"flow_expires_at":{"description":"When the login flow expires","example":"2025-11-05T20:00:00Z","format":"date-time","type":"string"},"flow_type":{"description":"Type of login flow started","enum":["LOGIN","REAUTH"],"example":"LOGIN","type":"string"},"handoff_code":{"description":"One-time code for handoff (internal use)","example":"aBcD123EfGh456IjKl789MnOp012QrStUvWxYzAbCdEf","type":"string"},"hosted_url":{"description":"URL to redirect user to for login","example":"https://auth.kernel.com/login/abc123xyz","format":"uri","type":"string"},"id":{"description":"Auth connection ID","example":"ma_abc123xyz","type":"string"},"live_view_url":{"description":"Browser live view URL for watching the login flow","example":"https://live.onkernel.com/abc123xyz","format":"uri","type":"string"}},"required":["id","flow_type","hosted_url","flow_expires_at"],"type":"object"},"MFAOption":{"additionalProperties":false,"description":"An MFA method option for verification","properties":{"description":{"description":"Additional instructions from the site","example":"We'll send a 6-digit code to your phone","nullable":true,"type":"string"},"label":{"description":"The visible option text","example":"Text me a code","type":"string"},"target":{"description":"The masked destination (phone/email) if shown","example":"***-***-5678","nullable":true,"type":"string"},"type":{"$ref":"#/components/schemas/MFAType"}},"required":["type","label"],"type":"object"},"MFAType":{"description":"The MFA delivery method type. Includes 'password' for auth method selection pages and 'switch' for generic method-switcher links like \"Use another method\" that do not name a specific method.","enum":["sms","call","email","totp","push","password","switch"],"example":"sms","type":"string"},"ManagedAuth":{"additionalProperties":false,"description":"Managed authentication that keeps a profile logged into a specific domain. Flow fields (flow_status, flow_step, discovered_fields, mfa_options) reflect the most recent login flow and are null when no flow has been initiated.","properties":{"allowed_domains":{"description":"Additional hostname roots valid for this auth flow, besides the primary domain. Each value allows credential entry on that exact hostname and its subdomains. Leading `www.` and `*.` labels are normalized away. When omitted or empty, credential entry is unrestricted.\n\nThe following SSO/OAuth provider domains are automatically allowed by default and do not need to be specified:\n- Google: accounts.google.com\n- Microsoft/Azure AD: login.microsoftonline.com, login.live.com\n- Okta: *.okta.com, *.oktapreview.com\n- Auth0: *.auth0.com, *.us.auth0.com, *.eu.auth0.com, *.au.auth0.com\n- Apple: appleid.apple.com\n- GitHub: github.com\n- Facebook/Meta: www.facebook.com\n- LinkedIn: www.linkedin.com\n- Amazon Cognito: *.amazoncognito.com\n- OneLogin: *.onelogin.com\n- Ping Identity: *.pingone.com, *.pingidentity.com\n","example":["login.netflix.com","auth.netflix.com"],"items":{"type":"string"},"type":"array"},"auto_reauth":{"description":"Whether automatic re-authentication is permitted for this connection. This is an opt-in\nflag only — it does not check whether re-auth is actually feasible. Even when true,\nre-auth only runs when the system has what it needs to perform it (for example, saved\ncredentials for the required login fields), and only after a scheduled health check\ndetects an expired session — so this flag has no effect when `health_checks` is false.\nWhen false, expired sessions detected by a health check are marked as `NEEDS_AUTH`\ninstead of attempting re-auth.\n","example":true,"type":"boolean"},"browser":{"$ref":"#/components/schemas/ManagedAuthBrowserConfig","description":"Default browser configuration for login, reauthentication, and health-check sessions."},"browser_session_id":{"description":"ID of the underlying browser session driving the current flow (present when flow in progress).\nUse this to inspect or terminate the browser session via the `/browsers` API.\n","example":"bs_abc123xyz","nullable":true,"type":"string"},"browser_telemetry":{"$ref":"#/components/schemas/BrowserTelemetryRequestConfig","deprecated":true,"description":"Deprecated. Use browser.telemetry. Retained during migration for existing clients.","nullable":true},"can_reauth":{"description":"Whether this connection's stored requirements are eligible for unattended re-authentication. A true value can represent either fully satisfiable requirements or a best-effort attempt. It does not account for whether automatic re-authentication is enabled or parent workflow state such as an active flow or circuit-breaker cooldown, so it does not guarantee an attempt on the next health check. See `can_reauth_reason` for the specific outcome.","example":true,"type":"boolean"},"can_reauth_reason":{"description":"Machine-readable reason for the current value of `can_reauth`.\nAffirmative values (requirements are eligible for unattended re-authentication):\n  - `external_credential` — an external credential provider is attached\n  - `cua_has_credential` — CUA flow with a stored credential\n  - `has_credential` — Kernel credential is attached (optimistic; plan viability not checked)\n  - `viable_plans_found` — at least one stored login plan can be replayed\n  - `no_requirements_recorded` — no recorded credential requirements to fail against\n  - `totp_reauth_allowed` — TOTP is the only recorded requirement and a stored secret can generate the code\n  - `optimistic_totp_attempt` — TOTP was previously required but no reusable secret is stored; the connection remains eligible for a circuit-breaker-bounded attempt because the site may not challenge returning sessions\n  - `requirements_satisfiable` — recorded requirements contain no recognized blocker\n\nNegative values (a human must complete the login flow):\n  - `no_prior_successful_login` — connection has never completed a successful login\n  - `no_credential` — no Kernel or external credential attached\n  - `no_viable_plans` — credential attached but no replayable login plan exists yet\n  - `viable_plans_require_external_action` — stored plans need an external step (email link, push, etc.)\n  - `requires_external_action` — recorded requirements include an external step\n  - `requires_totp_without_secret` — flow needs a TOTP code but no TOTP secret is stored\n  - `requires_sms_code` — flow needs an SMS code that cannot be received automatically\n  - `requires_email_code` — flow needs an email code that cannot be received automatically\n  - `requires_customer_input` — flow needs another field or choice that is unavailable during unattended re-authentication","enum":["external_credential","cua_has_credential","has_credential","viable_plans_found","no_requirements_recorded","totp_reauth_allowed","optimistic_totp_attempt","requirements_satisfiable","no_prior_successful_login","no_credential","no_viable_plans","viable_plans_require_external_action","requires_external_action","requires_totp_without_secret","requires_sms_code","requires_email_code","requires_customer_input"],"example":"has_credential","type":"string"},"choices":{"description":"Canonical choices awaiting selection. Prefer this over pending_sso_buttons, mfa_options, and sign_in_options when present.","items":{"$ref":"#/components/schemas/ManagedAuthChoice"},"nullable":true,"type":"array"},"credential":{"$ref":"#/components/schemas/CredentialReference"},"discovered_fields":{"description":"Fields awaiting input (present when flow_step=awaiting_input; may also be present with awaiting_external_action as fallback actions)","items":{"$ref":"#/components/schemas/DiscoveredField"},"nullable":true,"type":"array"},"domain":{"description":"Target domain for authentication","example":"netflix.com","type":"string"},"error_code":{"description":"Machine-readable error code (present when flow_status=failed)","nullable":true,"type":"string"},"error_message":{"description":"Error message (present when flow_status=failed)","example":"Invalid password","nullable":true,"type":"string"},"external_action_message":{"description":"Instructions for external action (present when flow_step=awaiting_external_action)","example":"Tap 'Yes' on the Google prompt on your phone","nullable":true,"type":"string"},"fields":{"description":"Canonical fields awaiting input. Prefer this over discovered_fields when present.","items":{"$ref":"#/components/schemas/ManagedAuthField"},"nullable":true,"type":"array"},"flow_expires_at":{"description":"When the current flow expires (null when no flow in progress). A flow past this timestamp is no longer valid and its `flow_status` will be `EXPIRED`. Clients may start a new login to supersede a stale `IN_PROGRESS` flow past this timestamp.","example":"2025-11-05T20:00:00Z","format":"date-time","nullable":true,"type":"string"},"flow_status":{"description":"Current flow status (null when no flow in progress)","enum":["IN_PROGRESS","SUCCESS","FAILED","EXPIRED","CANCELED"],"example":"IN_PROGRESS","nullable":true,"type":"string"},"flow_step":{"description":"Current step in the flow (null when no flow in progress)","enum":["DISCOVERING","AWAITING_INPUT","AWAITING_EXTERNAL_ACTION","SUBMITTING","COMPLETED"],"example":"AWAITING_INPUT","nullable":true,"type":"string"},"flow_type":{"description":"Type of the current flow (null when no flow in progress)","enum":["LOGIN","REAUTH"],"example":"LOGIN","nullable":true,"type":"string"},"health_check_interval":{"description":"Interval in seconds between automatic health checks. When set, the system periodically\nverifies the authentication status and triggers re-authentication if needed.\nMaximum is 86400 (24 hours). Default is 3600 (1 hour) or your plan minimum, whichever\nis larger. The minimum depends on your plan: Enterprise: 300 (5 minutes), Startup: 1200\n(20 minutes), Hobbyist: 3600 (1 hour), Free: 21600 (6 hours).\n","example":3600,"maximum":86400,"minimum":300,"nullable":true,"type":"integer"},"health_check_unavailable_reason":{"description":"Why health checks cannot verify this connection. Present when health checks are enabled but no auth check URL is available; a recent last_auth_check_at is not evidence of a valid session.","enum":["no_auth_check_url"],"type":"string"},"health_checks":{"description":"Whether periodic health checks are enabled for this connection. When false, the system\nwill not automatically verify authentication status, and `auto_reauth` has no effect on\nthe automatic flow (since re-auth is only triggered by a failed scheduled health check).\nManually triggering a health check via the API still works regardless of this setting.\n","example":true,"type":"boolean"},"hosted_url":{"description":"URL to redirect user to for hosted login (present when flow in progress)","example":"https://auth.kernel.com/login/abc123xyz","format":"uri","nullable":true,"type":"string"},"id":{"description":"Unique identifier for the auth connection","example":"ma_abc123xyz","type":"string"},"interaction_id":{"description":"Opaque identifier for the current canonical interaction. Required when submitting fields or choices and changes for each new actionable pause.","example":"mai_abc123xyz","nullable":true,"type":"string"},"last_auth_at":{"deprecated":true,"description":"Deprecated alias for `last_auth_check_at`. Despite the name, this is the last health-check timestamp, not the last successful authentication. Use `last_auth_check_at` instead.","example":"2025-01-15T10:30:00Z","format":"date-time","type":"string"},"last_auth_check_at":{"description":"When the most recent auth health check ran for this connection, regardless of outcome. Updated on every health check and does not by itself indicate that the profile is currently authenticated - use `status` for that. May be newer than `flow_expires_at` when a flow is still in progress because health checks continue to run in parallel.","example":"2025-01-15T10:30:00Z","format":"date-time","type":"string"},"live_view_url":{"description":"Browser live view URL for debugging (present when flow in progress)","example":"https://live.kernel.com/abc123xyz","format":"uri","nullable":true,"type":"string"},"login_url":{"description":"Optional login page URL to skip discovery","example":"https://example.com/login","format":"uri","type":"string"},"mfa_options":{"description":"MFA method options (present when flow_step=awaiting_input; may also be present with awaiting_external_action as fallback actions)","items":{"$ref":"#/components/schemas/MFAOption"},"nullable":true,"type":"array"},"pending_sso_buttons":{"description":"SSO buttons available (present when flow_step=awaiting_input; may also be present with awaiting_external_action as fallback actions)","items":{"$ref":"#/components/schemas/SSOButton"},"nullable":true,"type":"array"},"post_login_url":{"description":"URL where the browser landed after successful login","example":"https://www.netflix.com/browse","format":"uri","type":"string"},"profile_name":{"description":"Name of the profile associated with this auth connection","example":"my-netflix-profile","type":"string"},"proxy_id":{"deprecated":true,"description":"Deprecated. Read browser.proxy instead. Retained during migration for existing clients.","type":"string"},"record_session":{"description":"Whether to record browser session replays for this connection by default. Useful for debugging login flows. Can be overridden per-login.","example":false,"type":"boolean"},"save_credentials":{"description":"Whether credentials are saved after every successful login. One-time codes (TOTP, SMS, etc.) are not saved.","example":true,"type":"boolean"},"sign_in_options":{"description":"Non-MFA choices presented during the auth flow, such as account selection or org pickers (present when flow_step=awaiting_input; may also be present with awaiting_external_action as fallback actions).","items":{"$ref":"#/components/schemas/SignInOption"},"nullable":true,"type":"array"},"sso_provider":{"description":"SSO provider being used (e.g., google, github, microsoft)","example":"google","nullable":true,"type":"string"},"status":{"description":"Last known authentication status of the managed profile. An inconclusive health check preserves this status and does not verify the current session.","enum":["AUTHENTICATED","NEEDS_AUTH"],"example":"AUTHENTICATED","type":"string"},"website_error":{"description":"Visible error message from the website (e.g., 'Incorrect password'). Present when the website displays an error during login.","nullable":true,"type":"string"}},"required":["id","profile_name","domain","status","save_credentials","record_session"],"type":"object"},"ManagedAuthBrowserConfig":{"additionalProperties":false,"description":"Browser configuration applied to browser sessions created for a managed auth connection. Managed auth controls the profile, headless mode, timeout, start URL, kiosk mode, and viewport.","properties":{"proxy":{"$ref":"#/components/schemas/BrowserProxyConfig","description":"Proxy configuration for managed auth browser sessions. Omit on create to derive the default from stealth, or on update and login to preserve or inherit the connection default."},"region":{"$ref":"#/components/schemas/Region","description":"Browser region. Omit on create to use us-east, on update to keep the current region, or on login to inherit it. Login overrides apply only to that login. Non-default regions require an eligible plan and organization access.\n"},"stealth":{"description":"Whether managed auth browser sessions use stealth mode. Defaults to true when omitted.","example":false,"type":"boolean"},"telemetry":{"$ref":"#/components/schemas/BrowserTelemetryRequestConfig","description":"Browser telemetry configuration using the same semantics as browser create.","nullable":true}},"type":"object"},"ManagedAuthChoice":{"additionalProperties":false,"description":"Canonical auth-flow choice awaiting user selection.","properties":{"context":{"description":"Context captured for a choice.","nullable":true,"type":"string"},"description":{"description":"Additional context for the choice.","nullable":true,"type":"string"},"display_text":{"description":"Display text captured for a choice.","nullable":true,"type":"string"},"id":{"description":"Stable choice identifier for canonical submit.","example":"google","type":"string"},"label":{"description":"Human-readable choice label.","example":"Google","type":"string"},"masked_destination":{"description":"Masked phone number or email address shown for an MFA choice.","nullable":true,"type":"string"},"mfa_type":{"$ref":"#/components/schemas/ManagedAuthMFAMethod","description":"Semantic MFA method. Choice id remains the stable identity of the exact option selected.","nullable":true},"observed_selector":{"description":"Selector for the visible choice, when available.","example":"button:has-text(\"Google\")","nullable":true,"type":"string"},"type":{"description":"Choice type.","enum":["mfa_method","sso_provider","sign_in_method","auth_method","identifier_method","account","other"],"example":"sso_provider","type":"string","x-enum-varnames":["ManagedAuthChoiceTypeMfaMethod","ManagedAuthChoiceTypeSsoProvider","ManagedAuthChoiceTypeSignInMethod","ManagedAuthChoiceTypeAuthMethod","ManagedAuthChoiceTypeIdentifierMethod","ManagedAuthChoiceTypeAccount","ManagedAuthChoiceTypeOther"]}},"required":["id","type","label"],"type":"object"},"ManagedAuthCreateRequest":{"additionalProperties":false,"description":"Request to create an auth connection for a profile and domain","properties":{"allowed_domains":{"description":"Additional hostname roots valid for this auth flow, besides the primary domain. Each value allows credential entry on that exact hostname and its subdomains. Leading `www.` and `*.` labels are normalized away. When omitted or empty, credential entry is unrestricted.\n\nThe following SSO/OAuth provider domains are automatically allowed by default and do not need to be specified:\n- Google: accounts.google.com\n- Microsoft/Azure AD: login.microsoftonline.com, login.live.com\n- Okta: *.okta.com, *.oktapreview.com\n- Auth0: *.auth0.com, *.us.auth0.com, *.eu.auth0.com, *.au.auth0.com\n- Apple: appleid.apple.com\n- GitHub: github.com\n- Facebook/Meta: www.facebook.com\n- LinkedIn: www.linkedin.com\n- Amazon Cognito: *.amazoncognito.com\n- OneLogin: *.onelogin.com\n- Ping Identity: *.pingone.com, *.pingidentity.com\n","example":["login.netflix.com","auth.netflix.com"],"items":{"type":"string"},"type":"array"},"auto_reauth":{"default":true,"description":"Whether to permit automatic re-authentication when a scheduled health check detects an\nexpired session. This is an opt-in flag only — it does not check whether re-auth is\nactually feasible. Even when true, re-auth only runs when the system has what it needs\nto perform it (for example, saved credentials for the required login fields), and only\nafter a scheduled health check detects an expired session — so this flag has no effect\nwhen `health_checks` is false. When false, expired sessions are marked as `NEEDS_AUTH`\ninstead of attempting re-auth. Defaults to true.\n","example":true,"type":"boolean"},"browser":{"$ref":"#/components/schemas/ManagedAuthBrowserConfig","description":"Default browser configuration for login, reauthentication, and health-check sessions."},"browser_telemetry":{"$ref":"#/components/schemas/BrowserTelemetryRequestConfig","deprecated":true,"description":"Deprecated. Use browser.telemetry. Retained during migration for existing clients.","nullable":true},"credential":{"$ref":"#/components/schemas/CredentialReference"},"domain":{"description":"Domain for authentication","example":"netflix.com","type":"string"},"health_check_interval":{"description":"Interval in seconds between automatic health checks. When set, the system periodically\nverifies the authentication status and triggers re-authentication if needed.\nMaximum is 86400 (24 hours). Default is 3600 (1 hour) or your plan minimum, whichever\nis larger. The minimum depends on your plan: Enterprise: 300 (5 minutes), Startup: 1200\n(20 minutes), Hobbyist: 3600 (1 hour), Free: 21600 (6 hours).\n","example":3600,"maximum":86400,"minimum":300,"type":"integer"},"health_checks":{"default":true,"description":"Whether to enable periodic health checks. When false, the system will not automatically\nverify authentication status, and `auto_reauth` has no effect on the automatic flow\n(since re-auth is only triggered by a failed scheduled health check). Defaults to true.\n","example":true,"type":"boolean"},"login_url":{"description":"Optional login page URL to skip discovery","example":"https://netflix.com/login","format":"uri","type":"string"},"profile_name":{"description":"Name of the profile to manage authentication for. If the profile does not exist, it is created automatically.","example":"user-123","type":"string"},"proxy":{"$ref":"#/components/schemas/ProxyRef","deprecated":true,"description":"Deprecated. Use browser.proxy. Retained during migration for existing clients."},"record_session":{"default":false,"description":"Whether to record browser sessions for this connection by default. Useful for debugging. Can be overridden per-login. Defaults to false.","example":false,"type":"boolean"},"save_credentials":{"default":true,"description":"Whether to save credentials after every successful login. Defaults to true. One-time codes (TOTP, SMS, etc.) are not saved.","example":true,"type":"boolean"}},"required":["domain","profile_name"],"type":"object"},"ManagedAuthError":{"description":"Extended error response for managed auth operations with recovery context","properties":{"code":{"description":"Machine-readable error code for programmatic handling","enum":["login_form_not_found","navigation_confused","domain_not_allowed","stuck_in_loop","max_attempts_reached","website_error","network_error","element_not_found","credentials_invalid","mfa_required","external_action_required","unsupported_auth_method","bot_detected","captcha_blocked","session_expired","no_active_flow","flow_failed","awaiting_input_timeout","external_action_timeout","flow_timeout","max_steps_exceeded","browser_error","provider_unavailable","internal_error"],"example":"login_form_not_found","type":"string"},"details":{"description":"Additional technical details for debugging (not shown to end users)","example":"Searched for login forms at https://example.com/login, found 0 form elements","type":"string"},"doc_url":{"description":"Link to documentation about this error","example":"https://docs.onkernel.com/errors/login_form_not_found","format":"uri","type":"string"},"message":{"description":"Human-readable error message suitable for display","example":"We couldn't find a login form on this page. The website may have changed its layout, or the login URL might be incorrect.","type":"string"},"recoverable":{"description":"Whether the user can retry or take action to resolve this error","example":true,"type":"boolean"}},"required":["code","message"],"type":"object"},"ManagedAuthEvent":{"description":"Union type representing any managed auth event.","discriminator":{"mapping":{"error":"#/components/schemas/ErrorEvent","managed_auth_state":"#/components/schemas/ManagedAuthStateEvent","sse_heartbeat":"#/components/schemas/SSEHeartbeatEvent"},"propertyName":"event"},"oneOf":[{"$ref":"#/components/schemas/ManagedAuthStateEvent"},{"$ref":"#/components/schemas/ErrorEvent"},{"$ref":"#/components/schemas/SSEHeartbeatEvent"}]},"ManagedAuthExchangeRequest":{"additionalProperties":false,"description":"Request to exchange handoff code for JWT","properties":{"code":{"description":"Handoff code from start endpoint","example":"abc123xyz","type":"string"}},"required":["code"],"type":"object"},"ManagedAuthExchangeResponse":{"additionalProperties":false,"description":"Response from exchange endpoint","properties":{"invocation_id":{"description":"Invocation ID","example":"abc123xyz","type":"string"},"jwt":{"description":"JWT token with invocation_id claim (30 minute TTL)","example":"eyJ0eXAi...","type":"string"}},"required":["invocation_id","jwt"],"type":"object"},"ManagedAuthField":{"additionalProperties":false,"description":"Canonical field awaiting user input.","properties":{"hint":{"description":"Context shown near the field, including a masked code destination.","type":"string"},"id":{"description":"Stable field identifier for canonical submit.","example":"field_email","type":"string"},"input_mode":{"description":"Virtual keyboard hint, independent of field type and browser validation.","enum":["text","email","tel","numeric"],"example":"email","type":"string","x-enum-varnames":["ManagedAuthFieldInputModeText","ManagedAuthFieldInputModeEmail","ManagedAuthFieldInputModeTel","ManagedAuthFieldInputModeNumeric"]},"label":{"description":"Human-readable label shown to the user.","example":"Email address","type":"string"},"observed_selector":{"description":"Selector for the visible field, when available.","example":"input[name=\"identifier\"]","nullable":true,"type":"string"},"reason":{"description":"Why the field requires user input.","enum":["missing","rejected"],"example":"missing","type":"string","x-enum-varnames":["ManagedAuthFieldReasonMissing","ManagedAuthFieldReasonRejected"]},"ref":{"description":"Credential reference name to store the submitted value under.","example":"email","type":"string"},"required":{"default":true,"description":"Whether this field is required.","type":"boolean"},"type":{"description":"Managed-auth field type.","enum":["identifier","password","code","totp_code","totp_secret","text"],"example":"identifier","type":"string","x-enum-varnames":["ManagedAuthFieldTypeIdentifier","ManagedAuthFieldTypePassword","ManagedAuthFieldTypeCode","ManagedAuthFieldTypeTotpCode","ManagedAuthFieldTypeTotpSecret","ManagedAuthFieldTypeText"]}},"required":["id","ref","type","reason"],"type":"object"},"ManagedAuthMFAMethod":{"description":"Canonical MFA method, independent of a site's stable choice identifier.","enum":["sms","call","email","totp","push","password","passkey","switch","other"],"example":"sms","type":"string"},"ManagedAuthStateEvent":{"description":"An event representing the current state of a managed auth flow.","properties":{"choices":{"description":"Canonical choices awaiting selection. Prefer this over pending_sso_buttons, mfa_options, and sign_in_options when present.","items":{"$ref":"#/components/schemas/ManagedAuthChoice"},"type":"array"},"discovered_fields":{"description":"Fields awaiting input (present when flow_step=AWAITING_INPUT; may also be present with AWAITING_EXTERNAL_ACTION as fallback actions).","items":{"$ref":"#/components/schemas/DiscoveredField"},"type":"array"},"error_code":{"description":"Machine-readable error code (present when flow_status=FAILED).","type":"string"},"error_message":{"description":"Error message (present when flow_status=FAILED).","type":"string"},"event":{"const":"managed_auth_state","description":"Event type identifier (always \"managed_auth_state\").","type":"string"},"external_action_message":{"description":"Instructions for external action (present when flow_step=AWAITING_EXTERNAL_ACTION).","type":"string"},"fields":{"description":"Canonical fields awaiting input. Prefer this over discovered_fields when present.","items":{"$ref":"#/components/schemas/ManagedAuthField"},"type":"array"},"flow_status":{"description":"Current flow status.","enum":["IN_PROGRESS","SUCCESS","FAILED","EXPIRED","CANCELED"],"type":"string"},"flow_step":{"description":"Current step in the flow.","enum":["DISCOVERING","AWAITING_INPUT","AWAITING_EXTERNAL_ACTION","SUBMITTING","COMPLETED"],"type":"string"},"flow_type":{"description":"Type of the current flow.","enum":["LOGIN","REAUTH"],"type":"string"},"hosted_url":{"description":"URL to redirect user to for hosted login.","format":"uri","type":"string"},"interaction_id":{"description":"Opaque identifier for the current canonical interaction. Required when submitting fields or choices and changes for each new actionable pause.","example":"mai_abc123xyz","type":"string"},"live_view_url":{"description":"Browser live view URL for debugging.","format":"uri","type":"string"},"mfa_options":{"description":"MFA method options (present when flow_step=AWAITING_INPUT; may also be present with AWAITING_EXTERNAL_ACTION as fallback actions).","items":{"$ref":"#/components/schemas/MFAOption"},"type":"array"},"pending_sso_buttons":{"description":"SSO buttons available (present when flow_step=AWAITING_INPUT; may also be present with AWAITING_EXTERNAL_ACTION as fallback actions).","items":{"$ref":"#/components/schemas/SSOButton"},"type":"array"},"post_login_url":{"description":"URL where the browser landed after successful login.","format":"uri","type":"string"},"sign_in_options":{"description":"Non-MFA choices presented during the auth flow, such as account selection or org pickers (present when flow_step=AWAITING_INPUT; may also be present with AWAITING_EXTERNAL_ACTION as fallback actions).","items":{"$ref":"#/components/schemas/SignInOption"},"type":"array"},"timestamp":{"description":"Time the state was reported.","format":"date-time","type":"string"},"website_error":{"description":"Visible error message from the website (e.g., 'Incorrect password'). Present when the website displays an error during login.","type":"string"}},"required":["event","timestamp","flow_status","flow_step"],"type":"object"},"ManagedAuthTimelineEvent":{"description":"A single event in an auth connection's history — a login attempt, an automatic re-auth attempt, or a health check.","properties":{"browser_session_id":{"description":"Browser session that produced the event, if one was created.","type":"string"},"completed_at":{"description":"When the login/reauth attempt first reached a terminal status. Stable across retries and subsequent cleanup writes. Absent for in-progress attempts, health checks, and historical attempts without a recorded completion time.","format":"date-time","type":"string"},"error_code":{"description":"Machine-readable error code. Present when a login/reauth event failed.","type":"string"},"error_message":{"description":"Human-readable error message. Present when a login/reauth event failed.","type":"string"},"id":{"description":"Identifier of the underlying login/reauth session or health check.","type":"string"},"previous_status":{"description":"The session state observed before this event. Present for health_check events that recorded a prior state.","enum":["AUTHENTICATED","NEEDS_AUTH"],"type":"string"},"replay_id":{"description":"Replay recording ID for the event's browser session, if session recording was enabled.","type":"string"},"status":{"description":"Outcome of the event. For login/reauth events this is the flow status\n(IN_PROGRESS, SUCCESS, EXPIRED, CANCELED, FAILED). For health_check events\nit is the observed session state (AUTHENTICATED, NEEDS_AUTH).\n","enum":["IN_PROGRESS","SUCCESS","EXPIRED","CANCELED","FAILED","AUTHENTICATED","NEEDS_AUTH"],"type":"string"},"step":{"description":"The step the flow reached. Present for login/reauth events.","enum":["INITIALIZED","DISCOVERING","AWAITING_INPUT","AWAITING_EXTERNAL_ACTION","AWAITING_HUMAN_INTERVENTION","SUBMITTING","COMPLETED","EXPIRED"],"type":"string"},"telemetry_captured":{"description":"Whether browser telemetry capture started for this event's browser session.","type":"boolean"},"timestamp":{"description":"When the event occurred.","format":"date-time","type":"string"},"type":{"description":"The kind of event. \"login\" and \"reauth\" are authentication attempts; \"health_check\" is a periodic session-validity check.","enum":["login","reauth","health_check"],"type":"string"},"updated_at":{"description":"When the event was last updated. Present for login/reauth events.","format":"date-time","type":"string"},"website_error":{"description":"Visible error message from the website (e.g., 'Incorrect password'). Present when the website displayed an error during the attempt.","type":"string"}},"required":["type","id","timestamp","status"],"type":"object"},"ManagedAuthUpdateRequest":{"additionalProperties":false,"description":"Request to update an auth connection's configuration","properties":{"allowed_domains":{"description":"Additional hostname roots valid for this auth flow. Each value allows credential entry on that exact hostname and its subdomains; leading `www.` and `*.` labels are normalized away. An empty list leaves credential entry unrestricted. Replaces the existing list.","example":["login.netflix.com","auth.netflix.com"],"items":{"type":"string"},"type":"array"},"auto_reauth":{"description":"Whether automatic re-authentication is permitted for this connection. This is an opt-in\nflag only — it does not check whether re-auth is actually feasible. Even when true,\nre-auth only runs when the system has what it needs to perform it (for example, saved\ncredentials for the required login fields), and only after a scheduled health check\ndetects an expired session — so this flag has no effect when `health_checks` is false.\nWhen false, expired sessions detected by a health check are marked as `NEEDS_AUTH`\ninstead of attempting re-auth.\n","example":true,"type":"boolean"},"browser":{"$ref":"#/components/schemas/ManagedAuthBrowserConfig","description":"Browser configuration updates for future login, reauthentication, and health-check sessions. Omitted properties remain unchanged."},"browser_telemetry":{"$ref":"#/components/schemas/BrowserTelemetryRequestConfig","deprecated":true,"description":"Deprecated. Use browser.telemetry. Retained during migration for existing clients.","nullable":true},"credential":{"$ref":"#/components/schemas/CredentialReference"},"health_check_interval":{"description":"Interval in seconds between automatic health checks","example":3600,"maximum":86400,"minimum":300,"type":"integer"},"health_checks":{"description":"Whether periodic health checks are enabled. When set to false, the system will not\nautomatically verify authentication status, and `auto_reauth` has no effect on the\nautomatic flow (since re-auth is only triggered by a failed scheduled health check).\n","example":true,"type":"boolean"},"login_url":{"description":"Login page URL. Set to empty string to clear.","example":"https://netflix.com/login","format":"uri","type":"string"},"proxy":{"$ref":"#/components/schemas/ProxyRef","deprecated":true,"description":"Deprecated. Use browser.proxy. Retained during migration for existing clients."},"record_session":{"description":"Whether to record browser sessions for this connection by default","example":false,"type":"boolean"},"save_credentials":{"description":"Whether to save credentials after every successful login","example":true,"type":"boolean"}},"type":"object"},"MfaAction":{"additionalProperties":false,"properties":{"name":{"enum":["mfa"],"type":"string"}},"required":["name"],"type":"object"},"MobileProxyConfig":{"description":"Configuration for mobile proxies.","properties":{"city":{"description":"Provider city alias. Mobile carrier routing can make observed geo vary.","example":"brooklyn","type":"string"},"country":{"description":"ISO 3166 country code. If omitted, the proxy uses the global pool without country targeting.","example":"US","type":"string"},"state":{"description":"US-only state code. Mobile carrier routing can make observed geo vary.","example":"NY","type":"string"}},"title":"Mobile","type":"object"},"MousePositionResponse":{"additionalProperties":false,"properties":{"true":{"description":"Y coordinate of the cursor","type":"integer"},"x":{"description":"X coordinate of the cursor","type":"integer"}},"required":["x",true],"type":"object"},"MoveMouseRequest":{"additionalProperties":false,"properties":{"duration_ms":{"description":"Target total duration in milliseconds for the mouse movement when smooth=true. Omit for automatic timing based on distance.","maximum":5000,"minimum":50,"type":"integer"},"hold_keys":{"description":"Modifier keys to hold during the move","items":{"type":"string"},"type":"array"},"smooth":{"default":true,"description":"Use human-like Bezier curve path instead of instant mouse movement.","type":"boolean"},"true":{"description":"Y coordinate to move the cursor to","type":"integer"},"x":{"description":"X coordinate to move the cursor to","type":"integer"}},"required":["x",true],"type":"object"},"MovePathRequest":{"additionalProperties":false,"properties":{"dest_path":{"description":"Absolute destination path.","pattern":"^/.*","type":"string"},"src_path":{"description":"Absolute source path.","pattern":"^/.*","type":"string"}},"required":["src_path","dest_path"],"type":"object"},"OTLPDestination":{"description":"An OTLP endpoint to export browser session telemetry to. Reference one from `telemetry.export.otlp.destination` when creating a browser to export that session's captured telemetry to it.","properties":{"consecutive_failures":{"description":"Failed deliveries since the last success, as observed by the relay process that wrote the latest outcome. Zero means the most recently recorded outcome succeeded.","format":"int32","minimum":0,"type":"integer"},"created_at":{"format":"date-time","type":"string"},"description":{"maxLength":1024,"type":"string"},"endpoint":{"description":"OTLP/HTTP endpoint telemetry is sent to.","maxLength":2048,"type":"string"},"headers":{"additionalProperties":{"type":"string"},"description":"Headers sent with each export request. Names are returned in canonical form (`Authorization`, not `authorization`). Non-dashboard reads return values redacted as empty strings, so the keys are visible but the credentials are not. Dashboard reads return the stored values.","type":"object"},"id":{"maxLength":128,"type":"string"},"last_error":{"description":"Sanitized class of the delivery failure recorded at `last_error_at`. It is retained after a later success, so its presence does not mean the destination is currently failing. Response bodies, endpoint URLs, credentials, and raw transport errors are never returned.","maxLength":512,"type":"string"},"last_error_at":{"description":"Timestamp of the most recent failed delivery. It is retained after a later success, so it can predate `last_export_at`. Read `consecutive_failures` to tell whether the destination is currently failing.","format":"date-time","type":"string"},"last_export_at":{"description":"Timestamp of the most recent successful delivery. Moves only on success.","format":"date-time","type":"string"},"name":{"description":"Unique within the organization. Usable in place of the ID when selecting a destination, so it cannot be shaped like an ID.","pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"},"updated_at":{"format":"date-time","type":"string"}},"required":["id","name","endpoint","headers","consecutive_failures","created_at","updated_at"],"type":"object"},"OTLPDestinationCreateRequest":{"properties":{"description":{"maxLength":1024,"type":"string"},"endpoint":{"description":"Base endpoint of the OTLP/HTTP collector, without a signal path. Kernel appends the signal path itself, so pass `https://api.honeycomb.io` rather than `https://api.honeycomb.io/v1/logs`. If your provider's docs give you a signal-specific URL, drop the trailing `/v1/logs`, `/v1/traces`, or `/v1/metrics` — an endpoint that already carries one is rejected.\n\nMust be http or https, must resolve to a public address, and must carry no query string or fragment. Examples: `https://api.honeycomb.io`, `https://otlp-gateway-prod-us-east-0.grafana.net/otlp`, `https://otlp.datadoghq.com` (Datadog's OTLP intake for US1, not its logs intake).","maxLength":2048,"minLength":1,"type":"string"},"headers":{"additionalProperties":{"type":"string"},"description":"Headers sent with each export request, typically an ingestion key. Encrypted at rest and returned redacted. Names and values must be valid HTTP header tokens, and the names and values together cannot exceed 8192 bytes. Names are matched case-insensitively and stored canonicalized, so supplying two spellings of one header is rejected.","maxProperties":32,"type":"object"},"name":{"description":"Unique within the organization.","pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"}},"required":["name","endpoint"],"type":"object"},"OTLPDestinationRef":{"description":"OTLP destination selection. Provide either id or name. The destination\nmust be customer-visible in the authenticated organization. A\nproject-scoped credential can select any such destination for workloads\nin its project.\n","oneOf":[{"required":["id"]},{"required":["name"]}],"properties":{"id":{"description":"OTLP destination ID","type":"string"},"name":{"description":"OTLP destination name","type":"string"}},"type":"object"},"OTLPDestinationUpdateRequest":{"description":"Fields to update. Omitted fields are left unchanged.","properties":{"description":{"maxLength":1024,"type":"string"},"endpoint":{"description":"Base endpoint of the OTLP/HTTP collector, without a signal path. Same rules as on create.","maxLength":2048,"minLength":1,"type":"string"},"headers":{"additionalProperties":{"nullable":true,"type":"string"},"description":"Edits stored headers key by key rather than replacing the map. A string value adds or replaces that header, `null` deletes it, and any key you omit is left as it is. Names are matched case-insensitively, so `authorization` replaces a stored `Authorization` rather than adding a second entry. This is the credential rotation path; sessions already exporting pick up the new values without restarting. Names and values must be valid HTTP header tokens, and the names and values together cannot exceed 8192 bytes.","maxProperties":32,"type":"object"},"name":{"pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"}},"type":"object"},"OkResponse":{"additionalProperties":false,"description":"Generic OK response.","properties":{"ok":{"default":true,"description":"Indicates success.","type":"boolean"}},"required":["ok"],"type":"object"},"OnePasswordAccessApprovalAction":{"additionalProperties":false,"properties":{"instructions":{"description":"Steps for the agent to hand approval to the human and poll the resulting decision.","type":"string"},"name":{"enum":["1password_access_approval"],"type":"string"},"url":{"description":"Native 1Password approval link. Present it to the account owner without modifying it; it does not grant access until they approve in their app.","format":"uri","pattern":"^onepassword://grant-brokered-access\\?access_request_reference=","type":"string"}},"required":["name","url","instructions"],"type":"object"},"OnePasswordAccessRequestState":{"additionalProperties":false,"description":"Non-secret broker state. Granted credential references stay encrypted server-side and can only be used by the fill operation.","properties":{"createdAt":{"description":"Provider-created timestamp as returned by the broker.","type":"string"},"entries":{"description":"Login entries returned directly on accessRequest by the observed extension build. Omitted when the provider does not supply them.","items":{"$ref":"#/components/schemas/OnePasswordReturnedRequestEntry"},"type":"array"},"goal":{"description":"Goal echoed by the observed createAccessRequest response when present.","type":"string"},"granted_count":{"minimum":0,"type":"integer"},"has_autofill_token":{"type":"boolean"},"id":{"type":"string"},"identity":{"description":"Opaque provider identity returned by the broker.","type":"string"},"path":{"description":"Provider path if supplied in the broker response.","type":"string"},"request":{"$ref":"#/components/schemas/OnePasswordReturnedRequest"},"state":{"description":"One of pending, resolved, denied, or failed.","type":"string"}},"required":["id","state","has_autofill_token"],"type":"object"},"OnePasswordCredentialAccountSpec":{"additionalProperties":false,"properties":{"authorization":{"$ref":"#/components/schemas/OnePasswordOAuthAuthorization"},"provider":{"enum":["1password"],"type":"string"}},"required":["provider","authorization"],"type":"object"},"OnePasswordCredentialAccountState":{"additionalProperties":false,"properties":{"provider":{"enum":["1password"],"type":"string"},"status":{"enum":["pending_authorization","connected","reconnect_required","declined"],"type":"string"},"status_reason":{"type":"string"}},"required":["provider","status"],"type":"object"},"OnePasswordCredentialRequestEntry":{"additionalProperties":false,"properties":{"keywords":{"items":{"maxLength":50,"minLength":1,"type":"string"},"maxItems":5,"minItems":1,"type":"array"},"parameters":{"additionalProperties":false,"properties":{"website":{"format":"uri","maxLength":2083,"pattern":"^https://","type":"string"}},"required":["website"],"type":"object"},"reason":{"maxLength":100,"type":"string"},"type":{"description":"Must be login.","type":"string"}},"required":["type","parameters"],"type":"object"},"OnePasswordCredentialRequests":{"additionalProperties":false,"description":"Credential Request v2 input sent to the extension. A credential item may request up to five login entries.","properties":{"entries":{"items":{"$ref":"#/components/schemas/OnePasswordCredentialRequestEntry"},"maxItems":5,"minItems":1,"type":"array"},"goal":{"maxLength":140,"type":"string"},"version":{"description":"Must be 2.","type":"integer"}},"required":["version","entries"],"type":"object"},"OnePasswordCredentialVaultItemSpec":{"additionalProperties":false,"description":"Stored-token credentials omit account and never return access_token or integration_key.","properties":{"access_token_expires_at":{"description":"Customer-supplied expiry metadata, if provided.","format":"date-time","type":"string"},"account":{"type":"string"},"provider":{"enum":["1password"],"type":"string"},"requests":{"$ref":"#/components/schemas/OnePasswordCredentialRequests"}},"required":["provider","requests"],"type":"object"},"OnePasswordCredentialVaultItemSpecInput":{"additionalProperties":false,"description":"A login request backed by a connected 1Password account or by a customer-supplied access token and matching integration key. Supply either account or both secrets, never both. Supplied secrets are write-only and never returned. Supply requests for new items; website remains supported for existing account-backed callers.","properties":{"access_token":{"description":"Customer-supplied 1Password broker token. Requires integration_key; stored encrypted on this item. Omit if providing a connected credential_account item via the account field.","maxLength":16384,"minLength":1,"type":"string"},"access_token_expires_at":{"description":"Optional supplied token expiry metadata for stored-token credentials. Omit if providing a connected credential_account item via the account field.","format":"date-time","type":"string"},"account":{"description":"Key of a connected credential_account item in the same vault. Omit for stored-token credentials.","minLength":1,"type":"string"},"integration_key":{"description":"Matching customer-supplied integration key. Requires access_token; stored encrypted on this item. Omit if providing a connected credential_account item via the account field.","maxLength":16384,"minLength":1,"type":"string"},"provider":{"enum":["1password"],"type":"string"},"requests":{"$ref":"#/components/schemas/OnePasswordCredentialRequests"},"website":{"deprecated":true,"description":"Legacy single-login shorthand. Supply requests instead.","format":"uri","maxLength":2083,"pattern":"^https://","type":"string"}},"required":["provider"],"type":"object"},"OnePasswordCredentialVaultItemState":{"additionalProperties":false,"properties":{"access_request":{"$ref":"#/components/schemas/OnePasswordAccessRequestState"},"access_request_id":{"description":"Opaque request ID returned by the 1Password broker after a successful createAccessRequest call.","type":"string"},"provider":{"enum":["1password"],"type":"string"},"status":{"enum":["pending_authorization","ready","declined","failed"],"type":"string"},"status_reason":{"type":"string"}},"required":["provider","status"],"type":"object"},"OnePasswordFillVaultItemOperationRequest":{"additionalProperties":false,"description":"Fill and submit an approved 1Password login in the selected browser page. The page must share the selected entry's login origin. Supply entry_id when more than one approved entry matches the page origin. The extension selects fields; callers cannot supply selectors or secret values. Submission does not confirm website authentication.","properties":{"browser_id":{"description":"Browser session ID, not a reusable browser name.","minLength":1,"type":"string"},"entry_id":{"description":"ID of an approved request entry. Required when several approved entries have the page's origin.","minLength":1,"type":"string"},"page_url":{"description":"Exact current top-level page URL. Must match exactly one open page in the browser.","format":"uri","pattern":"^\\S+$","type":"string"},"timeout_ms":{"default":30000,"maximum":30000,"minimum":1,"type":"integer"},"type":{"enum":["1pw_fill"],"type":"string","x-go-type":"VaultItemOperationType"}},"required":["type","browser_id","page_url"],"type":"object"},"OnePasswordFillVaultItemOperationResult":{"additionalProperties":false,"description":"The submission result reported by the 1Password extension when available. Kernel returns fill_unknown if the extension call has no conclusive result. Inspect the page to determine successful authentication on the website.","properties":{"error_code":{"description":"Present only for a conclusive fill_failed response. These are allowlisted 1Password extension codes, never raw errors, secrets, or page content.","enum":["fillFailed","autosubmitFailed","noExistingCredentials","authenticationFailed"],"type":"string"},"status":{"description":"Kernel's outcome of the extension call. fill_submitted means the extension reported submission, not website authentication. fill_failed means the extension returned a known failure and may include error_code. fill_unknown means submission may have happened without a conclusive response; it has no error_code and must not be retried in the same browser.","enum":["fill_submitted","fill_failed","fill_unknown"],"type":"string"},"type":{"enum":["1pw_fill"],"type":"string"}},"required":["type","status"],"type":"object"},"OnePasswordOAuthAction":{"additionalProperties":false,"properties":{"name":{"enum":["1password_oauth"],"type":"string"},"url":{"description":"1Password-hosted OAuth authorization URL for the human to open.","format":"uri","type":"string"}},"required":["name","url"],"type":"object"},"OnePasswordOAuthAuthorization":{"additionalProperties":false,"properties":{"client":{"$ref":"#/components/schemas/KernelManagedOAuthClient"},"method":{"enum":["oauth"],"type":"string"}},"required":["method","client"],"type":"object"},"OnePasswordPollAccessVaultItemOperationRequest":{"additionalProperties":false,"description":"Retrieve the status of a 1Password access request after presenting the approval link. On a confirmed failed status, ask the end-user before deleting and recreating the credential item for at most one new request. Do not retry an uncertain dispatched request. The response remains non-secret; approved references are retained only for fill.","properties":{"browser_id":{"minLength":1,"type":"string"},"timeout_seconds":{"default":10,"maximum":120,"minimum":0,"type":"integer"},"type":{"enum":["1pw_access_request_status"],"type":"string","x-go-type":"VaultItemOperationType"}},"required":["type","browser_id"],"type":"object"},"OnePasswordRecoverVaultItemOperationRequest":{"additionalProperties":false,"description":"Kernel encountered a recoverable error while linking this 1Password account. Use this action to get a new link to recover the connection. After recovery completes, start a new authorization on the same item.","properties":{"type":{"enum":["1pw_recover"],"type":"string","x-go-type":"VaultItemOperationType"}},"required":["type"],"type":"object"},"OnePasswordRequestAccessVaultItemOperationRequest":{"additionalProperties":false,"description":"Request access to login entries in the end-user's own, non-shared 1Password vault through the browser extension, auto-loaded into the browser. The end-user approves access in the 1Password app. Shared-vault items and passkeys are not supported. Per-entry reason and keywords overrides are only supported for a single login entry.","properties":{"browser_id":{"description":"Kernel browser session used to invoke the extension.","minLength":1,"type":"string"},"goal":{"maxLength":140,"type":"string"},"keywords":{"items":{"maxLength":50,"minLength":1,"type":"string"},"maxItems":5,"minItems":1,"type":"array"},"reason":{"maxLength":100,"type":"string"},"type":{"enum":["1pw_create_access_request"],"type":"string","x-go-type":"VaultItemOperationType"}},"required":["type","browser_id"],"type":"object"},"OnePasswordReturnedRequest":{"additionalProperties":false,"description":"The request object if returned by the extension. The observed create response may omit entries; no entry IDs are invented.","properties":{"entries":{"items":{"$ref":"#/components/schemas/OnePasswordReturnedRequestEntry"},"type":"array"},"goal":{"type":"string"},"version":{"type":"integer"}},"type":"object"},"OnePasswordReturnedRequestEntry":{"additionalProperties":false,"properties":{"id":{"type":"string"},"keywords":{"items":{"type":"string"},"type":"array"},"parameters":{"additionalProperties":false,"properties":{"website":{"format":"uri","type":"string"}},"type":"object"},"reason":{"type":"string"},"type":{"type":"string"}},"type":"object"},"OnePasswordUpdateAccessTokenVaultItemOperationRequest":{"additionalProperties":false,"description":"Replace only the access token on a stored-token 1Password credential. Preserves its integration key, request and approved references. Does not invoke 1Password or retry a pending/uncertain operation.","properties":{"access_token":{"maxLength":16384,"minLength":1,"type":"string","writeOnly":true},"access_token_expires_at":{"description":"Optional supplied expiry. Omit to clear the old expiry.","format":"date-time","type":"string"},"type":{"enum":["1pw_update_access_token"],"type":"string","x-go-type":"VaultItemOperationType"}},"required":["type","access_token"],"type":"object"},"OrgBrowserExtensionEntitlement":{"additionalProperties":false,"properties":{"enabled":{"description":"Whether browser extensions are available.","example":true,"type":"boolean"},"max_stored_per_org":{"description":"Maximum active custom extensions the organization may store. Null means unlimited. Loading stored extensions into a browser is not plan-limited.","example":null,"minimum":1,"nullable":true,"type":"integer"}},"required":["enabled","max_stored_per_org"],"type":"object"},"OrgBrowserReplayEntitlement":{"additionalProperties":false,"properties":{"enabled":{"description":"Whether browser replay recording is available.","example":true,"type":"boolean"},"retention_days":{"description":"Number of days browser replays are retained, matching the replay reaper policy.","example":30,"minimum":0,"type":"integer"}},"required":["enabled","retention_days"],"type":"object"},"OrgEntitlementFeature":{"additionalProperties":false,"properties":{"enabled":{"description":"Whether the organization is entitled to use this feature.","example":true,"type":"boolean"}},"required":["enabled"],"type":"object"},"OrgEntitlementFeatures":{"additionalProperties":false,"properties":{"browser_extensions":{"$ref":"#/components/schemas/OrgBrowserExtensionEntitlement"},"browser_pools":{"$ref":"#/components/schemas/OrgEntitlementFeature"},"browser_replays":{"$ref":"#/components/schemas/OrgBrowserReplayEntitlement"},"credential_providers":{"$ref":"#/components/schemas/OrgEntitlementFeature"},"credentials":{"$ref":"#/components/schemas/OrgEntitlementFeature"},"custom_proxies":{"$ref":"#/components/schemas/OrgEntitlementFeature"},"file_io":{"$ref":"#/components/schemas/OrgEntitlementFeature"},"gpu":{"$ref":"#/components/schemas/OrgEntitlementFeature"},"managed_auth":{"$ref":"#/components/schemas/OrgManagedAuthEntitlement"},"managed_proxies":{"$ref":"#/components/schemas/OrgEntitlementFeature"},"profiles":{"$ref":"#/components/schemas/OrgEntitlementFeature"},"proxy_bypass_hosts":{"$ref":"#/components/schemas/OrgEntitlementFeature"},"search":{"$ref":"#/components/schemas/OrgEntitlementFeature","description":"Whether the Search API is enabled for the organization by its rollout feature flag."},"vaults":{"$ref":"#/components/schemas/OrgEntitlementFeature","description":"Whether the organization can access vaults, using the same access check as vault API routes."}},"required":["profiles","file_io","browser_replays","browser_extensions","browser_pools","managed_auth","credentials","credential_providers","managed_proxies","custom_proxies","proxy_bypass_hosts","gpu","vaults","search"],"type":"object"},"OrgEntitlementLimits":{"additionalProperties":false,"properties":{"default_max_concurrent_invocations_per_app":{"description":"Effective org-level default concurrent invocation ceiling for apps without an app-specific override. App-specific overrides are not represented here.","example":20,"minimum":1,"type":"integer"},"max_concurrent_browsers":{"description":"Effective organization-wide ceiling shared by on-demand browsers and browser pool reservations.","example":150,"minimum":1,"type":"integer"},"max_concurrent_invocations":{"description":"Effective organization-wide concurrent app invocation ceiling.","example":50,"minimum":1,"type":"integer"},"max_vaults":{"description":"Maximum non-deleted vaults allowed org-wide across all projects. Null means unlimited. The vaults feature flag still controls access.","example":3,"nullable":true,"type":"integer"}},"required":["max_vaults","max_concurrent_browsers","max_concurrent_invocations","default_max_concurrent_invocations_per_app"],"type":"object"},"OrgEntitlementPlan":{"additionalProperties":false,"properties":{"effective_id":{"description":"The plan used to resolve plan-based access. Active trials resolve to START_UP regardless of the contractual plan.","enum":["FREE","HOBBYIST","START_UP","ENTERPRISE"],"example":"START_UP","type":"string"},"id":{"description":"The organization's contractual plan identifier. Use the resolved feature and limit values, not this field, for access decisions.","enum":["FREE","HOBBYIST","START_UP","ENTERPRISE"],"example":"START_UP","type":"string"},"is_trialing":{"description":"Whether the organization is currently within its trial period.","example":false,"type":"boolean"},"status":{"description":"Current billing status of the contractual plan, or null when no billing status is recorded. Status-sensitive feature values already account for it.","enum":["NEEDS_PAYMENT_METHOD","ACTIVE","CANCELED","UNPAID"],"example":"ACTIVE","nullable":true,"type":"string"},"trial_ends_at":{"description":"Configured trial end timestamp, or null when the organization has no trial. A past timestamp may be returned when is_trialing is false.","example":null,"format":"date-time","nullable":true,"type":"string"}},"required":["id","effective_id","status","is_trialing","trial_ends_at"],"type":"object"},"OrgEntitlements":{"additionalProperties":false,"description":"Effective feature access and constraints for the authenticated organization. Values already include trial treatment, plan status, and organization-specific overrides; consumers should use these resolved values instead of comparing plan IDs.","properties":{"features":{"$ref":"#/components/schemas/OrgEntitlementFeatures"},"limits":{"$ref":"#/components/schemas/OrgEntitlementLimits"},"plan":{"$ref":"#/components/schemas/OrgEntitlementPlan"}},"required":["plan","features","limits"],"type":"object"},"OrgLimits":{"properties":{"auth_connections_used":{"description":"The organization's current non-deleted managed auth connections, counted org-wide across every project. Compare against max_auth_connections to show remaining capacity before a create is rejected with 403 insufficient_plan.","example":2,"type":"integer"},"concurrent_sessions_available":{"description":"Number of concurrent browser slots currently available to the organization. This is the effective concurrency limit minus active on-demand sessions and browser pool reservations, floored at zero. Null when usage cannot be read.","example":488,"nullable":true,"type":"integer"},"concurrent_sessions_used":{"description":"Current organization-wide concurrent browser usage, including active on-demand sessions and browser pool reservations. Null when usage cannot be read.","example":12,"nullable":true,"type":"integer"},"default_project_max_concurrent_sessions":{"description":"Default maximum concurrent browsers applied to every project that has no explicit per-project override. Null means no org-level default, so such projects are uncapped (only the org-wide limit applies). Applies to existing and newly created projects.","example":10,"nullable":true,"type":"integer"},"max_auth_connections":{"description":"Maximum managed auth connections the organization's plan allows. Null means unlimited. Counted org-wide, so it cannot be multiplied across projects.","example":3,"nullable":true,"type":"integer"},"max_concurrent_sessions":{"description":"The organization's effective concurrency limit — the maximum browsers running at once, covering both on-demand sessions and browser pool reservations — from its plan or an override. Read-only and shared across all projects in the org; a per-project default cannot exceed it.","example":500,"type":"integer"},"max_vaults":{"description":"Maximum non-deleted vaults allowed org-wide across all projects. Null means unlimited.","example":3,"nullable":true,"type":"integer"},"min_health_check_interval_seconds":{"description":"Smallest health_check_interval the organization's plan accepts on a managed auth connection. Requests below this are rejected with 400. Existing connections stored below the floor are grandfathered until edited.","example":21600,"type":"integer"},"vaults_used":{"description":"Current non-deleted vault count across all projects in the organization.","example":2,"type":"integer"}},"required":["max_auth_connections","auth_connections_used","max_vaults","vaults_used","min_health_check_interval_seconds","concurrent_sessions_used","concurrent_sessions_available"],"type":"object"},"OrgManagedAuthEntitlement":{"additionalProperties":false,"properties":{"enabled":{"description":"Whether managed auth is available.","example":true,"type":"boolean"},"health_check_interval_default_seconds":{"description":"Effective interval in seconds used when a connection is created without an explicit health-check interval.","example":3600,"minimum":1,"type":"integer"},"health_check_interval_max_seconds":{"description":"Maximum accepted managed auth health-check interval in seconds.","example":86400,"minimum":1,"type":"integer"},"health_check_interval_min_seconds":{"description":"Minimum accepted managed auth health-check interval in seconds.","example":1200,"minimum":1,"type":"integer"},"max_connections":{"description":"Maximum active managed auth connections in the organization. Null means unlimited.","example":null,"minimum":1,"nullable":true,"type":"integer"}},"required":["enabled","max_connections","health_check_interval_min_seconds","health_check_interval_default_seconds","health_check_interval_max_seconds"],"type":"object"},"PrepareCheckoutVaultItemOperationRequest":{"additionalProperties":false,"description":"Prepare an unused AgentCard card for a supported checkout. Deliver the returned approval URL and keep the approval page open. Poll the item until ready_to_submit, then submit native Pay before preparation.expires_at. Readiness lasts at most 30 seconds. Unused preparations expire automatically. Preparations are single-use even after failure or expiry; do not automatically retry and reconcile uncertain outcomes with the merchant.","properties":{"checkout":{"$ref":"#/components/schemas/VaultCheckoutContext"},"type":{"enum":["prepare_checkout"],"type":"string","x-go-type":"VaultItemOperationType"}},"required":["type","checkout"],"type":"object"},"PressKeyRequest":{"additionalProperties":false,"properties":{"duration":{"default":0,"description":"Duration to hold the keys down in milliseconds. If omitted or 0, keys are tapped.","minimum":0,"type":"integer"},"hold_keys":{"description":"Optional modifier keys to hold during the key press sequence.","items":{"type":"string"},"type":"array"},"keys":{"description":"List of key symbols to press. Each item should be a key symbol supported by xdotool\n(see X11 keysym definitions). Examples include \"Return\", \"Shift\", \"Ctrl\", \"Alt\", \"F5\".\nItems in this list could also be combinations, e.g. \"Ctrl+t\" or \"Ctrl+Shift+Tab\".\nUse X11 names for punctuation in combinations, such as \"Ctrl+minus\" or \"Ctrl+plus\".\nA literal hyphen is also accepted as an alias, so \"Ctrl+-\" is normalized to \"Ctrl+minus\".\n","items":{"type":"string"},"type":"array"}},"required":["keys"],"type":"object"},"ProcessExecRequest":{"additionalProperties":false,"description":"Request to execute a command synchronously.","properties":{"args":{"default":[],"description":"Command arguments.","items":{"type":"string"},"type":"array"},"as_root":{"default":false,"description":"Run the process with root privileges.","type":"boolean"},"as_user":{"description":"Run the process as this user.","nullable":true,"type":"string"},"command":{"description":"Executable or shell command to run.","type":"string"},"cwd":{"description":"Working directory (absolute path) to run the command in.","nullable":true,"pattern":"^/.*","type":"string"},"env":{"additionalProperties":{"type":"string"},"default":{},"description":"Environment variables to set for the process.","type":"object"},"timeout_sec":{"description":"Maximum execution time in seconds.","nullable":true,"type":"integer"}},"required":["command"],"type":"object"},"ProcessExecResult":{"additionalProperties":false,"description":"Result of a synchronous command execution.","properties":{"duration_ms":{"description":"Execution duration in milliseconds.","type":"integer"},"exit_code":{"description":"Process exit code.","type":"integer"},"stderr_b64":{"description":"Base64-encoded stderr buffer.","type":"string"},"stdout_b64":{"description":"Base64-encoded stdout buffer.","type":"string"}},"type":"object"},"ProcessKillRequest":{"additionalProperties":false,"description":"Signal to send to the process.","properties":{"signal":{"default":"TERM","description":"Signal to send.","enum":["TERM","KILL","INT","HUP"],"type":"string"}},"required":["signal"],"type":"object"},"ProcessResizeRequest":{"additionalProperties":false,"description":"Resize a PTY-backed process terminal.","properties":{"cols":{"description":"New terminal columns.","maximum":65535,"minimum":1,"type":"integer"},"rows":{"description":"New terminal rows.","maximum":65535,"minimum":1,"type":"integer"}},"required":["rows","cols"],"type":"object"},"ProcessSpawnRequest":{"allOf":[{"$ref":"#/components/schemas/ProcessExecRequest"},{"properties":{"allocate_tty":{"default":false,"description":"Allocate a pseudo-terminal (PTY) for interactive shells.","type":"boolean"},"cols":{"description":"Initial terminal columns. Only used when allocate_tty is true.","maximum":65535,"minimum":1,"type":"integer"},"rows":{"description":"Initial terminal rows. Only used when allocate_tty is true.","maximum":65535,"minimum":1,"type":"integer"}},"type":"object"}]},"ProcessSpawnResult":{"additionalProperties":false,"description":"Information about a spawned process.","properties":{"pid":{"description":"OS process ID.","type":"integer"},"process_id":{"description":"Server-assigned identifier for the process.","format":"uuid","type":"string"},"started_at":{"description":"Timestamp when the process started.","format":"date-time","type":"string"}},"type":"object"},"ProcessStatus":{"additionalProperties":false,"description":"Current status of a process.","properties":{"cpu_pct":{"description":"Estimated CPU usage percentage.","type":"number"},"exit_code":{"description":"Exit code if the process has exited.","nullable":true,"type":"integer"},"mem_bytes":{"description":"Estimated resident memory usage in bytes.","type":"integer"},"state":{"description":"Process state.","enum":["running","exited"],"type":"string"}},"type":"object"},"ProcessStdinRequest":{"additionalProperties":false,"description":"Data to write to the process standard input.","properties":{"data_b64":{"description":"Base64-encoded data to write.","type":"string"}},"required":["data_b64"],"type":"object"},"ProcessStdinResult":{"additionalProperties":false,"description":"Result of writing to stdin.","properties":{"written_bytes":{"description":"Number of bytes written.","type":"integer"}},"type":"object"},"ProcessStreamEvent":{"additionalProperties":false,"description":"SSE payload representing process output or lifecycle events.","properties":{"data_b64":{"description":"Base64-encoded data from the process stream.","type":"string"},"event":{"description":"Lifecycle event type.","enum":["exit"],"type":"string"},"exit_code":{"description":"Exit code when the event is \"exit\".","type":"integer"},"stream":{"description":"Source stream of the data chunk.","enum":["stdout","stderr"],"type":"string"}},"type":"object"},"Profile":{"description":"Browser profile metadata.","properties":{"created_at":{"description":"Timestamp when the profile was created","format":"date-time","type":"string"},"id":{"description":"Unique identifier for the profile","type":"string"},"last_used_at":{"description":"Timestamp when the profile was last used","format":"date-time","type":"string"},"name":{"description":"Optional, easier-to-reference name for the profile","nullable":true,"type":"string"},"updated_at":{"description":"Timestamp when the profile was last updated","format":"date-time","type":"string"}},"required":["id","created_at"],"type":"object"},"ProfileRequest":{"description":"Request body for creating a profile.","properties":{"name":{"description":"Optional name of the profile. Must be unique within the logical project; during the default-project migration, unscoped profiles and profiles in the org default project are treated as the same project.","type":"string"}},"required":[],"type":"object"},"ProfileUpdateRequest":{"properties":{"name":{"description":"New profile name. Must be unique within the logical project; during the default-project migration, unscoped profiles and profiles in the org default project are treated as the same project.","example":"my-renamed-profile","maxLength":255,"minLength":1,"type":"string"}},"required":["name"],"type":"object"},"Project":{"properties":{"created_at":{"description":"When the project was created","format":"date-time","type":"string"},"id":{"description":"Unique project identifier","example":"proj_abc123","type":"string"},"name":{"description":"Project name","example":"production","type":"string"},"status":{"description":"Project status","enum":["active","archived"],"example":"active","type":"string"},"updated_at":{"description":"When the project was last updated","format":"date-time","type":"string"}},"required":["id","name","status","created_at","updated_at"],"type":"object"},"ProjectLimits":{"properties":{"max_concurrent_invocations":{"description":"Maximum concurrent app invocations for this project. Null means no project-level cap.","example":20,"nullable":true,"type":"integer"},"max_concurrent_sessions":{"description":"Maximum concurrent browsers for this project, covering both on-demand sessions (`browsers.create()`) and browser pool reservations. Null means no project-level cap.","example":10,"nullable":true,"type":"integer"},"max_pooled_sessions":{"deprecated":true,"description":"Deprecated: pooled browsers now count toward `max_concurrent_sessions`. Always null.","example":50,"nullable":true,"type":"integer"}},"type":"object"},"Proxy":{"description":"Configuration for routing traffic through a proxy.","discriminator":{"mapping":{"custom":"#/components/schemas/CustomProxyConfig","datacenter":"#/components/schemas/DatacenterProxyConfig","isp":"#/components/schemas/IspProxyConfig","mobile":"#/components/schemas/MobileProxyConfig","residential":"#/components/schemas/ResidentialProxyConfig"},"propertyName":"type"},"properties":{"bypass_hosts":{"description":"Hostnames that should bypass the parent proxy and connect directly.","items":{"type":"string"},"type":"array"},"config":{"description":"Configuration specific to the selected proxy `type`.","oneOf":[{"$ref":"#/components/schemas/DatacenterProxyConfig"},{"$ref":"#/components/schemas/IspProxyConfig"},{"$ref":"#/components/schemas/ResidentialProxyConfig"},{"$ref":"#/components/schemas/MobileProxyConfig"},{"$ref":"#/components/schemas/CustomProxyConfig"}]},"id":{"type":"string"},"ip_address":{"description":"IP address that the proxy uses when making requests.","example":"192.168.1.1","type":"string"},"last_checked":{"description":"Timestamp of the last health check performed on this proxy.","format":"date-time","type":"string"},"name":{"description":"Readable name of the proxy.","type":"string"},"protocol":{"default":"https","description":"Protocol to use for the proxy connection.","enum":["http","https"],"type":"string"},"status":{"description":"Current health status of the proxy.","enum":["available","unavailable"],"type":"string"},"type":{"description":"Proxy type to use. In terms of quality for avoiding bot-detection, from best to worst: `mobile` \u003e `residential` \u003e `isp` \u003e `datacenter`.\n","enum":["datacenter","isp","residential","mobile","custom"],"type":"string"}},"required":["type"],"type":"object"},"ProxyCheckRequest":{"description":"Optional parameters for the proxy health check.","properties":{"url":{"description":"An optional URL to test reachability against. If provided, the proxy check will test connectivity to this URL instead of the default test URLs. Only HTTP and HTTPS schemes are allowed, and the URL must resolve to a public IP address. For ISP and datacenter proxies, the exit IP is stable, so a successful check reliably indicates that subsequent browser sessions will reach the target site with the same IP. For residential and mobile proxies, the exit node changes between requests, so a successful check validates proxy configuration but does not guarantee that a subsequent browser session will use the same exit IP or reach the same site — it is useful for verifying credentials and connectivity, not for predicting site-specific behavior. When provided, the check result does not update the proxy's health status, since a failure may indicate a problem with the target site rather than the proxy itself.","example":"https://example.com","type":"string"}},"type":"object"},"ProxyCreateRequest":{"description":"Configuration for routing traffic through a proxy.","discriminator":{"mapping":{"custom":"#/components/schemas/CustomProxyConfig","datacenter":"#/components/schemas/DatacenterProxyConfig","isp":"#/components/schemas/IspProxyConfig","mobile":"#/components/schemas/MobileProxyConfig","residential":"#/components/schemas/ResidentialProxyConfig"},"propertyName":"type"},"properties":{"bypass_hosts":{"description":"Hostnames that should bypass the parent proxy and connect directly.","items":{"type":"string"},"type":"array"},"config":{"description":"Configuration specific to the selected proxy `type`.","oneOf":[{"$ref":"#/components/schemas/DatacenterProxyConfig"},{"$ref":"#/components/schemas/IspProxyConfig"},{"$ref":"#/components/schemas/ResidentialProxyConfig"},{"$ref":"#/components/schemas/MobileProxyConfig"},{"$ref":"#/components/schemas/CreateCustomProxyConfig"}]},"name":{"description":"Readable name of the proxy.","type":"string"},"protocol":{"default":"https","description":"Protocol to use for the proxy connection.","enum":["http","https"],"type":"string"},"type":{"description":"Proxy type to use. In terms of quality for avoiding bot-detection, from best to worst: `mobile` \u003e `residential` \u003e `isp` \u003e `datacenter`.\n","enum":["datacenter","isp","residential","mobile","custom"],"type":"string"}},"required":["type"],"type":"object"},"ProxyRef":{"description":"Proxy selection. Provide either id or name. The proxy must be in the same project as the resource referencing it.\nWhen selecting by name, the name must match exactly one active proxy in the project. Ambiguous names return a 400; use id for stable references.\n","oneOf":[{"required":["id"]},{"required":["name"]}],"properties":{"id":{"description":"Proxy ID","type":"string"},"name":{"description":"Proxy name","type":"string"}},"type":"object"},"ProxyUpdateRequest":{"properties":{"name":{"description":"New proxy name. Proxy names are trimmed and length-checked only; duplicates are allowed because proxies are updated by ID, not by name.","example":"my-renamed-proxy","maxLength":255,"minLength":1,"type":"string"}},"required":["name"],"type":"object"},"PushApprovalAction":{"additionalProperties":false,"properties":{"name":{"enum":["push_approval"],"type":"string"}},"required":["name"],"type":"object"},"Region":{"description":"Geographic region for hosting browser sessions or pools.\n","enum":["us-east","eu-west","ap-southeast"],"type":"string"},"ResidentialProxyConfig":{"description":"Configuration for residential proxies.","properties":{"asn":{"description":"Autonomous system number. See https://bgp.potaroo.net/cidr/autnums.html","example":"AS15169","type":"string"},"city":{"description":"City name (no spaces, e.g. `sanfrancisco`). If provided, `country` must also be provided.","example":"sanfrancisco","type":"string"},"country":{"description":"ISO 3166 country code. If omitted, the proxy uses the global pool without country targeting.","example":"US","type":"string"},"os":{"deprecated":true,"description":"Operating system of the residential device.","enum":["windows","macos","android"],"type":"string","x-deprecated-reason":"os selection not supported by proxy provider"},"state":{"description":"Two-letter state code.","example":"CA","type":"string"},"zip":{"description":"US ZIP code.","example":"94107","type":"string"}},"title":"Residential","type":"object"},"RotateApiKeyRequest":{"properties":{"days_to_expire":{"description":"Lifetime in days for the new key, up to 3650. Omit to reuse the rotated key's original lifetime, or never-expires if it had none.","example":30,"maximum":3650,"minimum":1,"nullable":true,"type":"integer"},"expire_in_days":{"description":"Grace period in days before the rotated key expires. Use 0 to expire it immediately. Omit for the default grace period of 7 days.","example":7,"maximum":3650,"minimum":0,"nullable":true,"type":"integer"}},"type":"object"},"SSEHeartbeatEvent":{"description":"Heartbeat event sent periodically to keep SSE connection alive.","properties":{"event":{"const":"sse_heartbeat","description":"Event type identifier (always \"sse_heartbeat\").","type":"string"},"timestamp":{"description":"Time the heartbeat was sent.","format":"date-time","type":"string"}},"required":["event","timestamp"],"type":"object"},"SSOButton":{"additionalProperties":false,"description":"An SSO button for signing in with an external identity provider","properties":{"label":{"description":"Visible button text","example":"Continue with Google","type":"string"},"provider":{"description":"Identity provider name","example":"google","type":"string"},"selector":{"description":"XPath selector for the button","example":"xpath=//button[contains(text(), 'Continue with Google')]","type":"string"}},"required":["selector","provider","label"],"type":"object"},"ScreenshotRegion":{"additionalProperties":false,"properties":{"height":{"description":"Height of the region in pixels","type":"integer"},"true":{"description":"Y coordinate of the region's top-left corner","type":"integer"},"width":{"description":"Width of the region in pixels","type":"integer"},"x":{"description":"X coordinate of the region's top-left corner","type":"integer"}},"required":["x",true,"width","height"],"type":"object"},"ScreenshotRequest":{"additionalProperties":false,"properties":{"region":{"$ref":"#/components/schemas/ScreenshotRegion"}},"type":"object"},"ScrollRequest":{"additionalProperties":false,"properties":{"delta_x":{"default":0,"description":"Horizontal scroll amount in xdotool \"wheel units.\" Positive scrolls right, negative scrolls left.","type":"integer"},"delta_y":{"default":0,"description":"Vertical scroll amount in xdotool \"wheel units.\" Positive scrolls down, negative scrolls up.","type":"integer"},"hold_keys":{"description":"Modifier keys to hold during the scroll","items":{"type":"string"},"type":"array"},"true":{"description":"Y coordinate at which to perform the scroll","type":"integer"},"x":{"description":"X coordinate at which to perform the scroll","type":"integer"}},"required":["x",true],"type":"object"},"Search":{"description":"Retained search results and provider attempt history.","properties":{"answer":{"description":"Provider-generated answer when requested (e.g. via Tavily include_answer or Perplexity). Preserved independently of include_raw.","type":"string"},"attempts":{"items":{"$ref":"#/components/schemas/SearchAttempt"},"type":"array"},"expires_at":{"description":"Expiration of result IDs for deferred retrieval. Results expire 24 hours\nafter search completion.\n","format":"date-time","type":"string"},"id":{"description":"Search resource ID. Request tracing uses X-Request-Id.","example":"srch_abc123","type":"string"},"provider":{"description":"Concrete serving provider, never auto or fallback.","type":"string"},"query":{"description":"Echo of the query. Native multi-query inputs are visible in the selected strategy target and the optional raw response.","type":"string"},"raw":{"description":"Full serving-provider response, including top-level metadata that does not belong to a result. Present only with include_raw=true; untrusted provider data."},"results":{"items":{"$ref":"#/components/schemas/SearchResult"},"type":"array"},"usage":{"$ref":"#/components/schemas/SearchUsage"},"warnings":{"items":{"$ref":"#/components/schemas/SearchWarning"},"type":"array"}},"required":["id","expires_at","provider","results","attempts","warnings","query","usage"],"type":"object"},"SearchAttempt":{"properties":{"duration_ms":{"minimum":0,"type":"integer"},"error_code":{"type":"string"},"outcome":{"enum":["success","empty","error","timeout"],"type":"string","x-enum-varnames":["SearchAttemptOutcomeSuccess","SearchAttemptOutcomeEmpty","SearchAttemptOutcomeError","SearchAttemptOutcomeTimeout"]},"provider":{"type":"string"},"retryable":{"type":"boolean"}},"required":["provider","outcome","duration_ms"],"type":"object"},"SearchAutoStrategy":{"additionalProperties":false,"properties":{"fallback_on":{"$ref":"#/components/schemas/SearchFallbackConditions"},"provider_options":{"$ref":"#/components/schemas/SearchProviderOptions"},"type":{"const":"auto","description":"Let Kernel choose an eligible provider by capability fit.","type":"string"}},"required":["type"],"type":"object"},"SearchBraveOptions":{"additionalProperties":false,"properties":{"count":{"description":"Provider-native count. Lower-only alias for max_results; cannot raise the effective result cap.","minimum":1,"type":"integer"},"extra_snippets":{"description":"Request additional snippets from Brave.","type":"boolean"},"goggles":{"description":"Goggles re-ranking definition URL.","type":"string"},"goggles_id":{"deprecated":true,"description":"Deprecated Brave Goggle identifier. Prefer goggles.","type":"string"},"include_fetch_metadata":{"description":"Include Brave's fetch metadata.","type":"boolean"},"offset":{"description":"Page offset supported by Brave.","maximum":9,"minimum":0,"type":"integer"},"operators":{"description":"Brave search operators.","type":"string"},"result_filter":{"description":"Comma-separated result types to include, e.g. \"web,news\".","type":"string"},"search_lang":{"description":"Language of the search, e.g. \"en\".","type":"string"},"spellcheck":{"description":"Apply Brave's query spellcheck.","type":"boolean"},"ui_lang":{"description":"Language for UI strings in the response.","type":"string"},"units":{"description":"Measurement units.","enum":["metric","imperial"],"type":"string","x-enum-varnames":["SearchBraveOptionsUnitsMetric","SearchBraveOptionsUnitsImperial"]}},"type":"object"},"SearchBraveTarget":{"additionalProperties":false,"properties":{"options":{"$ref":"#/components/schemas/SearchBraveOptions"},"provider":{"const":"brave","type":"string"}},"required":["provider"],"type":"object"},"SearchBrowserOptions":{"additionalProperties":false,"properties":{"browser_id":{"description":"Existing browser session ID authorized for the caller and selected\nproject. Reuses its cookies, proxy, and browser configuration; requests\nfollow that browser's existing network access behavior, with no additional\ndestination allowlist in this endpoint. Kernel does not delete a caller-supplied\nbrowser. Render mode uses a temporary tab; website activity may still change\nshared cookies and storage.\nWhen omitted and any result needs browser retrieval, Kernel creates one temporary\nbrowser for the request using the dashboard launch defaults (headful, stealth,\ndefault proxy), tags it with search_id, and deletes it when the request finishes.\nIt is billed and counts toward browser concurrency like any other browser. A\nconcurrency rejection returns 429 for source=browser; for source=auto, results\nwith retained content are still returned and the rest report the rejection.\n","type":"string"},"mode":{"default":"curl","description":"Curl uses the browser HTTP stack without navigation or JavaScript\nexecution. Render navigates a temporary page and extracts from its\nDOM. The selected mode is used for the retrieval.\n","enum":["curl","render"],"type":"string","x-enum-varnames":["SearchBrowserModeCurl","SearchBrowserModeRender"]}},"type":"object"},"SearchContentCacheStatus":{"description":"Kernel content cache outcome. Kernel has no content cache yet: responses report bypass or\nunknown, and hit and miss are reserved. Provider-internal cache behavior may be unknown.\n","enum":["hit","miss","bypass","unknown"],"type":"string","x-enum-varnames":["SearchContentCacheStatusHit","SearchContentCacheStatusMiss","SearchContentCacheStatusBypass","SearchContentCacheStatusUnknown"]},"SearchContentCapabilities":{"properties":{"freshness_control":{"description":"Can enforce the requested maximum content age.","type":"boolean"},"inline":{"description":"Supports content retrieval with the search request.","type":"boolean"},"post_hoc":{"description":"Supports content retrieval after the search completes.","type":"boolean"}},"required":["inline","post_hoc","freshness_control"],"type":"object"},"SearchContentCompleteness":{"description":"Describes source coverage before max_chars truncation. Full_page\nmeans main-page content, not every dynamic element or linked page.\n","enum":["full_page","excerpt","unknown"],"type":"string","x-enum-varnames":["SearchContentCompletenessFullPage","SearchContentCompletenessExcerpt","SearchContentCompletenessUnknown"]},"SearchContentError":{"properties":{"code":{"description":"Machine-readable retrieval failure code.","type":"string"},"message":{"description":"Human-readable failure description.","type":"string"},"retryable":{"type":"boolean"}},"required":["code","message","retryable"],"type":"object"},"SearchContentFormat":{"enum":["markdown","text"],"type":"string","x-enum-varnames":["SearchContentFormatMarkdown","SearchContentFormatText"]},"SearchContentMethod":{"description":"Original retrieval method.","enum":["provider","browser_curl","browser_render"],"type":"string","x-enum-varnames":["SearchContentMethodProvider","SearchContentMethodBrowserCurl","SearchContentMethodBrowserRender"]},"SearchContentOptions":{"additionalProperties":false,"properties":{"browser":{"$ref":"#/components/schemas/SearchBrowserOptions","description":"Requires source=auto or source=browser in deferred retrieval."},"format":{"$ref":"#/components/schemas/SearchContentFormat","default":"markdown"},"max_age_hours":{"default":24,"description":"For source=auto, maximum acceptable age of retained provider content, measured from when the search received it from the provider. A value of 0 disables reuse of retained content, so every result is fetched through a browser. source=provider reuses retained provider content without freshness validation. source=browser always fetches through a browser and does not use this age limit.","minimum":0,"type":"integer"},"max_chars":{"default":10000,"description":"Per-result Unicode character limit after extraction. Retained provider content cannot exceed what was stored at search time; such results report truncated when the stored text was already truncated.","maximum":100000,"minimum":100,"type":"integer"},"source":{"description":"auto uses retained provider content within max_age_hours; for deferred retrieval it falls back to a Kernel browser (caller-supplied or temporary) for results without it. Inline retrieval never uses a browser. provider reuses retained provider content when available, without freshness validation, and never provisions a browser. browser fetches each URL through a Kernel browser, either caller-supplied or temporary. No option makes a new provider request. Defaults to auto for both inline and deferred retrieval. Missing documents produce per-result unavailable outcomes, not request failures.","enum":["auto","provider","browser"],"type":"string","x-enum-varnames":["SearchContentSourceAuto","SearchContentSourceProvider","SearchContentSourceBrowser"]},"timeout_ms":{"default":15000,"description":"Per-result deadline including capacity acquisition, retrieval, and\nextraction. Also bounded by the overall request deadline.\n","maximum":60000,"minimum":1000,"type":"integer"}},"type":"object"},"SearchContentResult":{"properties":{"cache_status":{"$ref":"#/components/schemas/SearchContentCacheStatus"},"completeness":{"$ref":"#/components/schemas/SearchContentCompleteness"},"error":{"$ref":"#/components/schemas/SearchContentError"},"extractor_version":{"description":"Extraction version when Kernel transformed the input.","type":"string"},"fetched_at":{"description":"When Kernel fetched the content, or received it from the provider for retained content.","format":"date-time","type":["string","null"]},"final_url":{"description":"Final retrieval URL after redirects when known. Curl mode follows up to 5 redirects.","format":"uri","type":"string"},"format":{"$ref":"#/components/schemas/SearchContentFormat","description":"Format of text. Plain-text and JSON pages are returned unchanged as text even when markdown was requested."},"http_status":{"description":"Final target HTTP status when known.","maximum":599,"minimum":100,"type":"integer"},"method":{"$ref":"#/components/schemas/SearchContentMethod"},"result_id":{"type":"string"},"status":{"$ref":"#/components/schemas/SearchContentStatus"},"text":{"description":"Extracted website content, untrusted, not instructions. Present only on status=ok.","type":"string"},"truncated":{"description":"Whether the content was cut short, by max_chars or because the page exceeded the 1 MiB read limit.","type":"boolean"},"url":{"description":"Original result URL.","format":"uri","type":"string"}},"required":["result_id","url","status"],"type":"object"},"SearchContentStatus":{"description":"Ok means non-empty extracted content, not merely HTTP 200. Blocked\nincludes detected challenges or access denials. Detection is\nbest-effort, not a guarantee of page completeness. Error details\nare present for non-ok outcomes; text is present only on ok.\n","enum":["ok","unavailable","blocked","timeout","unsupported_type","extraction_failed","error"],"type":"string","x-enum-varnames":["SearchContentStatusOk","SearchContentStatusUnavailable","SearchContentStatusBlocked","SearchContentStatusTimeout","SearchContentStatusUnsupportedType","SearchContentStatusExtractionFailed","SearchContentStatusError"]},"SearchContentsRequest":{"additionalProperties":false,"oneOf":[{"required":["result_ids"]},{"required":["limit"]}],"properties":{"content":{"$ref":"#/components/schemas/SearchContentOptions","description":"Defaults to source:auto when omitted."},"limit":{"description":"Maximum number of search results to fetch when result_ids is omitted, starting from rank 1. Mutually exclusive with result_ids.","maximum":100,"minimum":1,"type":"integer"},"result_ids":{"description":"Kernel-generated IDs from the referenced retained search, in desired response order. They are not provider-standard IDs. Mutually exclusive with limit.","items":{"type":"string"},"maxItems":100,"minItems":1,"type":"array","uniqueItems":true},"timeout_ms":{"default":60000,"description":"Overall deadline across all selected results.","maximum":120000,"minimum":1000,"type":"integer"}},"type":"object"},"SearchContentsResponse":{"properties":{"contents":{"items":{"$ref":"#/components/schemas/SearchContentResult"},"type":"array"},"search_id":{"type":"string"},"usage":{"$ref":"#/components/schemas/SearchUsage"},"warnings":{"items":{"$ref":"#/components/schemas/SearchWarning"},"type":"array"}},"required":["search_id","contents","warnings","usage"],"type":"object"},"SearchContextMarkdownOptions":{"additionalProperties":false,"properties":{"enabled":{"type":"boolean"},"includeFrames":{"type":"boolean"},"includeImages":{"type":"boolean"},"includeLinks":{"type":"boolean"},"maxAgeMs":{"minimum":0,"type":"integer"},"pdf":{"additionalProperties":false,"properties":{"shouldParse":{"type":"boolean"}},"type":"object"},"shortenBase64Images":{"type":"boolean"},"timeoutMS":{"maximum":300000,"minimum":1000,"type":"integer"},"useMainContentOnly":{"type":"boolean"},"waitForMs":{"minimum":0,"type":"integer"}},"type":"object"},"SearchContextOptions":{"additionalProperties":false,"properties":{"country":{"description":"ISO 3166-1 alpha-2 country code.","maxLength":2,"minLength":2,"type":"string"},"excludeDomains":{"description":"Blocklist of result domains.","items":{"type":"string"},"type":"array"},"freshness":{"description":"Restrict results to content published within this window.","enum":["last_24_hours","last_week","last_month","last_year"],"type":"string"},"includeDomains":{"description":"Allowlist of result domains.","items":{"type":"string"},"type":"array"},"markdownOptions":{"$ref":"#/components/schemas/SearchContextMarkdownOptions"},"numResults":{"description":"Number of results to request from Context.dev.","maximum":100,"minimum":10,"type":"integer"},"queryFanout":{"description":"Expand the query into multiple parallel variants.","type":"boolean"},"tags":{"description":"Usage tracking tags.","items":{"maxLength":50,"minLength":1,"type":"string"},"maxItems":20,"type":"array"},"timeoutMS":{"description":"Context.dev request timeout in milliseconds.","maximum":300000,"minimum":1000,"type":"integer"}},"type":"object"},"SearchContextTarget":{"additionalProperties":false,"properties":{"options":{"$ref":"#/components/schemas/SearchContextOptions"},"provider":{"const":"context","type":"string"}},"required":["provider"],"type":"object"},"SearchExaOptions":{"additionalProperties":false,"properties":{"category":{"description":"Provider data-category hint.","type":"string"},"compliance":{"description":"Provider-native compliance controls. Requires support and authorization on the provider account.","type":"string"},"contents":{"$ref":"#/components/schemas/SearchExaOptionsContents"},"maxAgeHours":{"description":"Provider-native cache-age control. Unlike content.max_age_hours, this retains Exa semantics, including any native sentinel values. It does not imply a cross-provider freshness guarantee.","type":"number"},"numResults":{"description":"Provider-native count. Lower-only alias for max_results.","minimum":1,"type":"integer"},"type":{"default":"auto","description":"Search mode supported by Exa.","enum":["auto","fast","instant"],"type":"string","x-enum-varnames":["SearchExaOptionsTypeAuto","SearchExaOptionsTypeFast","SearchExaOptionsTypeInstant"]}},"type":"object"},"SearchExaOptionsContents":{"additionalProperties":false,"description":"Provider-native content retrieval. Available without requesting Kernel browser retrieval; may incur provider retrieval charges.","properties":{"highlights":{"description":"Return query-relevant provider excerpts.","type":"boolean"},"text":{"description":"Return provider page text.","type":"boolean"}},"type":"object"},"SearchExaTarget":{"additionalProperties":false,"properties":{"options":{"$ref":"#/components/schemas/SearchExaOptions"},"provider":{"const":"exa","type":"string"}},"required":["provider"],"type":"object"},"SearchFallbackCondition":{"enum":["error","timeout","empty"],"type":"string","x-enum-varnames":["SearchFallbackConditionError","SearchFallbackConditionTimeout","SearchFallbackConditionEmpty"]},"SearchFallbackConditions":{"default":["error","timeout"],"description":"Conditions that advance to the next provider under auto routing or an explicit providers chain. Ignored when provider pins a single provider. error means a retryable provider failure, including rate limiting, not invalid caller input or caller quotas. empty means zero results after required filtering. An empty list disables fallback. If every attempt is empty or fails, the response is the first valid empty response with the full attempt trail, or a 502 if none succeeded.","items":{"$ref":"#/components/schemas/SearchFallbackCondition"},"type":"array","uniqueItems":true},"SearchFallbackStrategy":{"additionalProperties":false,"properties":{"fallback_on":{"$ref":"#/components/schemas/SearchFallbackConditions"},"providers":{"description":"Ordered provider targets. Provider names must be unique.","items":{"$ref":"#/components/schemas/SearchProviderTarget"},"maxItems":8,"minItems":1,"type":"array"},"type":{"const":"fallback","description":"Try providers in order and advance when fallback_on matches the outcome.","type":"string"}},"required":["type","providers"],"type":"object"},"SearchOctenOptions":{"additionalProperties":false,"properties":{"count":{"maximum":100,"minimum":1,"type":"integer"},"end_time":{"format":"date-time","type":"string"},"exclude_domains":{"items":{"maxLength":60,"type":"string"},"maxItems":1200,"type":"array"},"exclude_text":{"items":{"maxLength":30,"type":"string"},"maxItems":5,"type":"array"},"format":{"enum":["markdown","text"],"type":"string"},"full_content":{"additionalProperties":false,"properties":{"enable":{"type":"boolean"},"max_tokens":{"maximum":100000,"minimum":100,"type":"integer"}},"type":"object"},"highlight":{"additionalProperties":false,"properties":{"enable":{"type":"boolean"},"max_tokens":{"maximum":20000,"minimum":100,"type":"integer"}},"type":"object"},"include_domains":{"items":{"maxLength":60,"type":"string"},"maxItems":1200,"type":"array"},"include_images":{"type":"boolean"},"include_text":{"items":{"maxLength":30,"type":"string"},"maxItems":5,"type":"array"},"language":{"items":{"type":"string"},"type":"array"},"safesearch":{"enum":["off","strict"],"type":"string"},"start_time":{"format":"date-time","type":"string"},"time_basis":{"enum":["auto","published","crawled"],"type":"string"},"time_range":{"enum":["day","week","month","year","d","w","m",true],"type":"string"},"topic":{"enum":["general","news"],"type":"string"}},"type":"object"},"SearchOctenTarget":{"additionalProperties":false,"properties":{"options":{"$ref":"#/components/schemas/SearchOctenOptions"},"provider":{"const":"octen","type":"string"}},"required":["provider"],"type":"object"},"SearchParallelOptions":{"additionalProperties":false,"properties":{"advanced_settings":{"$ref":"#/components/schemas/SearchParallelOptionsAdvancedSettings"},"client_model":{"description":"Client model hint.","type":"string"},"max_chars_total":{"description":"Cap total characters returned.","type":"integer"},"mode":{"default":"basic","description":"Search mode. Basic is used when omitted; each mode can have different latency and charges.","enum":["turbo","fast","basic","advanced"],"type":"string","x-enum-varnames":["SearchParallelOptionsModeTurbo","SearchParallelOptionsModeFast","SearchParallelOptionsModeBasic","SearchParallelOptionsModeAdvanced"]},"objective":{"description":"The goal behind the search, stated separately from the query.","minLength":1,"type":"string"},"search_queries":{"description":"Provider-native multi-query search. Defaults to [query] for this provider.","items":{"maxLength":2000,"minLength":1,"type":"string"},"maxItems":20,"minItems":1,"type":"array"},"session_id":{"description":"Group related searches.","type":"string"}},"type":"object"},"SearchParallelOptionsAdvancedSettings":{"additionalProperties":false,"description":"Explicit search settings. Unified search parameters are re-applied to overlapping settings; native result counts are lower-only.","properties":{"excerpt_settings":{"$ref":"#/components/schemas/SearchParallelOptionsAdvancedSettingsExcerptSettings"},"fetch_policy":{"$ref":"#/components/schemas/SearchParallelOptionsAdvancedSettingsFetchPolicy"},"location":{"description":"Native ISO 3166-1 alpha-2 location preference.","type":["string","null"]},"max_results":{"description":"Native count; lower-only alias for unified max_results.","minimum":1,"type":["integer","null"]},"source_policy":{"$ref":"#/components/schemas/SearchParallelOptionsAdvancedSettingsSourcePolicy"}},"type":"object"},"SearchParallelOptionsAdvancedSettingsExcerptSettings":{"additionalProperties":false,"properties":{"max_chars_per_result":{"type":["integer","null"]}},"type":"object"},"SearchParallelOptionsAdvancedSettingsFetchPolicy":{"additionalProperties":false,"properties":{"disable_cache_fallback":{"default":false,"description":"When false, the provider may return cached content after live fetching fails.","type":"boolean"},"max_age_seconds":{"description":"Native live-fetch trigger; minimum 600 seconds. Not the unified hard-freshness control.","minimum":600,"type":["integer","null"]},"timeout_seconds":{"description":"Native live-fetch timeout, bounded by the remaining overall deadline.","type":["number","null"]}},"type":"object"},"SearchParallelOptionsAdvancedSettingsSourcePolicy":{"additionalProperties":false,"properties":{"after_date":{"description":"Native publication-date lower bound.","format":"date","type":["string","null"]},"exclude_domains":{"description":"Native exclusions; the provider ignores these when native include_domains is non-empty.","items":{"type":"string"},"type":"array"},"include_domains":{"description":"Native domain/path restrictions. Explicit unified domain parameters take precedence. Combined include/exclude native lists cannot exceed 200 entries.","items":{"type":"string"},"type":"array"}},"type":"object"},"SearchParallelTarget":{"additionalProperties":false,"properties":{"options":{"$ref":"#/components/schemas/SearchParallelOptions"},"provider":{"const":"parallel","type":"string"}},"required":["provider"],"type":"object"},"SearchParameterCapabilities":{"additionalProperties":false,"properties":{"country":{"$ref":"#/components/schemas/SearchParameterCapability"},"end_date":{"$ref":"#/components/schemas/SearchParameterCapability"},"exclude_domains":{"$ref":"#/components/schemas/SearchParameterCapability"},"include_domains":{"$ref":"#/components/schemas/SearchParameterCapability"},"language":{"$ref":"#/components/schemas/SearchParameterCapability"},"recency":{"$ref":"#/components/schemas/SearchParameterCapability"},"safe_search":{"$ref":"#/components/schemas/SearchParameterCapability"},"start_date":{"$ref":"#/components/schemas/SearchParameterCapability"}},"required":["country","language","include_domains","exclude_domains","start_date","end_date","recency","safe_search"],"type":"object"},"SearchParameterCapability":{"properties":{"notes":{"description":"Translation behavior, limitations, and precision.","type":"string"},"support":{"enum":["native","emulated","unsupported"],"type":"string","x-enum-varnames":["SearchParameterSupportNative","SearchParameterSupportEmulated","SearchParameterSupportUnsupported"]}},"required":["support"],"type":"object"},"SearchPerplexityOptions":{"additionalProperties":false,"properties":{"last_updated_after_filter":{"description":"MM/DD/YYYY. Filters by last-updated date, not published date.","type":"string"},"last_updated_before_filter":{"description":"MM/DD/YYYY upper bound on last-updated date.","type":"string"},"max_results":{"description":"Provider-native count. Lower-only alias for max_results.","minimum":1,"type":"integer"},"max_tokens":{"description":"Values outside the documented range are rejected.","maximum":1000000,"minimum":1,"type":"integer"},"max_tokens_per_page":{"description":"Per-page token cap.","maximum":1000000,"minimum":1,"type":"integer"},"query":{"description":"Provider-native multi-query form, applied only to Perplexity. Other fallback providers receive the top-level query. Each query may incur a separate provider charge.","items":{"maxLength":2000,"minLength":1,"type":"string"},"maxItems":50,"minItems":1,"type":"array"},"search_context_size":{"description":"Provider context size supported by the selected model.","enum":["low","medium","high"],"type":"string","x-enum-varnames":["SearchPerplexityOptionsSearchContextSizeLow","SearchPerplexityOptionsSearchContextSizeMedium","SearchPerplexityOptionsSearchContextSizeHigh"]},"search_language_filter":{"description":"ISO 639-1 language codes, max 20.","items":{"type":"string"},"maxItems":20,"type":"array"}},"type":"object"},"SearchPerplexityTarget":{"additionalProperties":false,"properties":{"options":{"$ref":"#/components/schemas/SearchPerplexityOptions"},"provider":{"const":"perplexity","type":"string"}},"required":["provider"],"type":"object"},"SearchPinnedStrategy":{"additionalProperties":false,"properties":{"provider":{"$ref":"#/components/schemas/SearchProviderTarget"},"type":{"const":"pinned","description":"Use exactly the selected provider with no cross-provider fallback.","type":"string"}},"required":["type","provider"],"type":"object"},"SearchProvider":{"properties":{"content":{"$ref":"#/components/schemas/SearchContentCapabilities"},"max_results_cap":{"minimum":1,"type":"integer"},"notes":{"description":"Provider-specific limitations, conditional filter support, and warnings about search modes.","items":{"type":"string"},"type":"array"},"params":{"$ref":"#/components/schemas/SearchParameterCapabilities"},"provider_options":{"$ref":"#/components/schemas/SearchProviderOptionsDiscovery"},"slug":{"type":"string"}},"required":["slug","max_results_cap","params","content","provider_options"],"type":"object"},"SearchProviderOptions":{"description":"Provider targets available to auto routing, each paired with typed native options. Provider names must be unique.","items":{"$ref":"#/components/schemas/SearchProviderTarget"},"maxItems":10,"type":"array"},"SearchProviderOptionsDiscovery":{"additionalProperties":false,"properties":{"examples":{"items":{"additionalProperties":true,"type":"object"},"type":"array"},"schema":{"additionalProperties":true,"description":"JSON Schema for the provider-native options accepted by POST /search.","type":"object"},"schema_ref":{"description":"OpenAPI component name for the matching typed provider-options schema.","type":"string"}},"required":["schema_ref","schema"],"type":"object"},"SearchProviderSlug":{"description":"Concrete search provider. Matches the slugs returned by GET /search/providers.","enum":["brave","exa","perplexity","context","parallel","valyu","octen","you","tavily","serpapi"],"type":"string","x-enum-varnames":["SearchProviderSlugBrave","SearchProviderSlugExa","SearchProviderSlugPerplexity","SearchProviderSlugContext","SearchProviderSlugParallel","SearchProviderSlugValyu","SearchProviderSlugOcten","SearchProviderSlugYou","SearchProviderSlugTavily","SearchProviderSlugSerpapi"]},"SearchProviderTarget":{"description":"Provider name paired with its typed native options.","discriminator":{"mapping":{"brave":"#/components/schemas/SearchBraveTarget","context":"#/components/schemas/SearchContextTarget","exa":"#/components/schemas/SearchExaTarget","octen":"#/components/schemas/SearchOctenTarget","parallel":"#/components/schemas/SearchParallelTarget","perplexity":"#/components/schemas/SearchPerplexityTarget","serpapi":"#/components/schemas/SearchSerpApiTarget","tavily":"#/components/schemas/SearchTavilyTarget","valyu":"#/components/schemas/SearchValyuTarget","you":"#/components/schemas/SearchYouTarget"},"propertyName":"provider"},"oneOf":[{"$ref":"#/components/schemas/SearchBraveTarget"},{"$ref":"#/components/schemas/SearchExaTarget"},{"$ref":"#/components/schemas/SearchPerplexityTarget"},{"$ref":"#/components/schemas/SearchContextTarget"},{"$ref":"#/components/schemas/SearchParallelTarget"},{"$ref":"#/components/schemas/SearchValyuTarget"},{"$ref":"#/components/schemas/SearchOctenTarget"},{"$ref":"#/components/schemas/SearchYouTarget"},{"$ref":"#/components/schemas/SearchTavilyTarget"},{"$ref":"#/components/schemas/SearchSerpApiTarget"}]},"SearchRequest":{"additionalProperties":false,"properties":{"content":{"description":"Optional portable content retrieval. Pass true for defaults or an options object. Omission never starts Kernel browser work; provider-supplied content is still returned when available, including when requested through native options. Both inline and deferred retrieval use the same options schema.","oneOf":[{"description":"Pass true to enable default portable content retrieval (auto source, markdown format, 10,000 char cap).","enum":[true],"type":"boolean"},{"$ref":"#/components/schemas/SearchContentOptions"}]},"country":{"description":"ISO 3166-1 alpha-2 search locale preference.","pattern":"^[A-Za-z]{2}$","type":"string"},"end_date":{"description":"Inclusive publication-date upper bound; must not precede start_date. If recency is also supplied, recency takes precedence with a warning. Unsupported or approximated filtering is reported, or rejected under strict_params.","format":"date","type":"string"},"exclude_domains":{"description":"Hostname exclusions, with the same best-effort/strict behavior as include_domains. Provider-specific combinations that cannot be represented are reported via warnings or rejected in strict mode.","items":{"type":"string"},"maxItems":100,"type":"array","uniqueItems":true},"include_domains":{"description":"Hostname inclusion preference, matching a hostname and its subdomains. Empty means unrestricted. Translated, emulated, or dropped with a warning according to provider capability unless strict_params is true. Native boost modes remain advisory and are identified in warnings.","items":{"type":"string"},"maxItems":100,"type":"array","uniqueItems":true},"include_raw":{"default":false,"description":"Include untouched per-result payloads and the full serving-provider response in raw fields. Off by default; native top-level outputs such as answer remain available without it.","type":"boolean"},"language":{"description":"BCP 47 search language preference.","type":"string"},"max_results":{"default":10,"description":"Requested result count from 1 through 100. The effective count is clamped to the serving provider's cap with a warning. Effective native counts are the lower of this limit and supplied provider-native count aliases. Strict mode rejects unsupported counts.","maximum":100,"minimum":1,"type":"integer"},"query":{"description":"Primary search query. A provider-native multi-query option applies only to that provider; other providers in a fallback chain receive this query.","maxLength":2048,"minLength":1,"type":"string"},"recency":{"description":"Relative search window. Takes precedence over start_date/end_date with a warning if both are set. Provider-native recency behavior is retained, including documented hour-to-day widening. Unsupported filters are rejected only in strict mode.","enum":["hour","day","week","month","year"],"type":"string","x-enum-varnames":["SearchRecencyHour","SearchRecencyDay","SearchRecencyWeek","SearchRecencyMonth","SearchRecencyYear"]},"safe_search":{"description":"Optional safety preference. Omit to use provider defaults. Unsupported values are dropped with a warning unless strict_params is true. A search filter is not an authorization boundary.","enum":["off","moderate","strict"],"type":"string","x-enum-varnames":["SearchSafeSearchOff","SearchSafeSearchModerate","SearchSafeSearchStrict"]},"start_date":{"description":"Inclusive publication-date lower bound. If recency is also supplied, recency takes precedence with a warning. Provider date semantics, precision, and unsupported filters are reported; unknown source dates are not fabricated or universally post-filtered.","format":"date","type":"string"},"strategy":{"$ref":"#/components/schemas/SearchStrategy","default":{"type":"auto"},"description":"Omitted strategy defaults to auto."},"strict_params":{"default":false,"description":"When false, unsupported portable parameters are omitted and approximations are described in warnings. When true, every supplied portable parameter must be honored exactly. Requests that cannot be served with those parameters are rejected. This does not guarantee identical rankings or document timestamps across indexes. Authentication and project isolation are always enforced.","type":"boolean"},"timeout_ms":{"default":30000,"description":"Overall deadline across search attempts and inline retrieval.\nNo new attempt starts after the deadline. Completed search results\nsurvive inline retrieval timeouts.\n","maximum":120000,"minimum":1000,"type":"integer"}},"required":["query"],"type":"object"},"SearchResult":{"properties":{"additional_snippets":{"items":{"type":"string"},"type":"array"},"content":{"$ref":"#/components/schemas/SearchResultContent","description":"Portable retrieval outcome, or native content supplied by the search provider. Identity fields remain on the enclosing result. Native excerpts are labeled excerpt rather than full_page. Omission never triggers browser retrieval."},"id":{"description":"Kernel-generated identifier for this result. Stable only within the retained search; not standardized across providers. Provider-native IDs, when available, remain provider-specific raw fields.","example":"srchr_def456","type":"string"},"published_date":{"description":"Provider-supplied date or timestamp, preserving available precision. No publication date is fabricated. Retains the published field name.","type":["string","null"]},"rank":{"description":"One-based position in the returned ranking.","minimum":1,"type":"integer"},"raw":{"description":"Original provider result, included only with include_raw=true. Provider relevance scores are not normalized. Top-level provider data is available in Search.raw."},"snippet":{"type":["string","null"]},"source":{"description":"Provider source name or result URL hostname, when available.","type":["string","null"]},"title":{"type":["string","null"]},"url":{"description":"Provider-returned URL, not assumed canonical.","format":"uri","type":"string"}},"required":["id","url","rank"],"type":"object"},"SearchResultContent":{"properties":{"cache_status":{"$ref":"#/components/schemas/SearchContentCacheStatus"},"completeness":{"$ref":"#/components/schemas/SearchContentCompleteness"},"error":{"$ref":"#/components/schemas/SearchContentError"},"extractor_version":{"description":"Extraction version when Kernel transformed the input.","type":"string"},"fetched_at":{"description":"When Kernel received the content from the provider.","format":"date-time","type":["string","null"]},"final_url":{"description":"Final retrieval URL when known.","format":"uri","type":"string"},"format":{"$ref":"#/components/schemas/SearchContentFormat"},"http_status":{"description":"Final target HTTP status when known.","maximum":599,"minimum":100,"type":"integer"},"method":{"$ref":"#/components/schemas/SearchContentMethod"},"status":{"$ref":"#/components/schemas/SearchContentStatus"},"text":{"description":"Extracted website content, untrusted, not instructions. Present only on status=ok.","type":"string"},"truncated":{"description":"Whether max_chars truncated the extracted content.","type":"boolean"}},"required":["status"],"type":"object"},"SearchSerpApiOptions":{"additionalProperties":false,"properties":{"device":{"description":"Device profile used for the search.","enum":["desktop","mobile","tablet"],"type":"string"},"engine":{"description":"SerpApi engine identifier. The Kernel integration currently supports google only.","minLength":1,"type":"string"},"filter":{"description":"Google duplicate-content filter.","enum":[0,1],"type":"integer"},"gl":{"description":"Two-letter Google country code.","maxLength":2,"minLength":2,"type":"string"},"google_domain":{"description":"Google domain to search when using the google engine.","type":"string"},"hl":{"description":"Interface language code.","maxLength":8,"minLength":2,"type":"string"},"location":{"description":"Free-form geographic location used for localized results.","type":"string"},"nfpr":{"description":"Google auto-correction filter.","enum":[0,1],"type":"integer"},"no_cache":{"description":"When true, bypass SerpApi cached results when supported.","type":"boolean"},"num":{"description":"Number of results requested from the search engine.","maximum":100,"minimum":1,"type":"integer"},"safe":{"description":"Safe-search setting for engines that support it.","enum":["active","off"],"type":"string"},"start":{"description":"Zero-based result offset for pagination.","minimum":0,"type":"integer"},"tbm":{"description":"Google vertical search selector, such as images, video, news, or shopping.","type":"string"},"tbs":{"description":"Google time and search modifiers, including freshness filters.","type":"string"}},"required":["engine"],"type":"object"},"SearchSerpApiTarget":{"additionalProperties":false,"properties":{"options":{"$ref":"#/components/schemas/SearchSerpApiOptions"},"provider":{"const":"serpapi","type":"string"}},"required":["provider"],"type":"object"},"SearchStrategy":{"description":"Typed provider selection and routing strategy.","discriminator":{"mapping":{"auto":"#/components/schemas/SearchAutoStrategy","fallback":"#/components/schemas/SearchFallbackStrategy","pinned":"#/components/schemas/SearchPinnedStrategy"},"propertyName":"type"},"oneOf":[{"$ref":"#/components/schemas/SearchAutoStrategy"},{"$ref":"#/components/schemas/SearchPinnedStrategy"},{"$ref":"#/components/schemas/SearchFallbackStrategy"}]},"SearchTavilyOptions":{"additionalProperties":false,"properties":{"auto_parameters":{"description":"Allow the provider to choose search parameters. May select a different billing tier; explicit caller values retain provider-native precedence.","type":"boolean"},"chunks_per_source":{"description":"Provider excerpts per source, up to 500 characters each.","maximum":3,"minimum":1,"type":"integer"},"exact_match":{"description":"Require the quoted phrases in the query verbatim, bypassing semantic matches.","type":"boolean"},"filter_by_language":{"description":"Strictly filter non-matching languages. Requires `language`.","type":"boolean"},"include_answer":{"anyOf":[{"type":"boolean"},{"enum":["basic","advanced"],"type":"string","x-enum-varnames":["SearchTavilyOptionsIncludeAnswerVariant1Basic","SearchTavilyOptionsIncludeAnswerVariant1Advanced"]}],"description":"Request the provider's generated answer. Returned as answer on the search response, independently of include_raw."},"include_domains_mode":{"description":"Native filter versus ranking boost semantics. Boost influences ranking rather than restricting results to the listed domains. Requires include_domains.","enum":["filter","boost"],"type":"string","x-enum-varnames":["SearchTavilyOptionsIncludeDomainsModeFilter","SearchTavilyOptionsIncludeDomainsModeBoost"]},"include_favicon":{"description":"Favicon URL per result.","type":"boolean"},"include_image_descriptions":{"description":"Describe each image. Needs include_images.","type":"boolean"},"include_images":{"description":"Query-related images plus per-result images.","type":"boolean"},"include_raw_content":{"anyOf":[{"type":"boolean"},{"enum":["markdown","text"],"type":"string","x-enum-varnames":["SearchTavilyOptionsIncludeRawContentVariant1Markdown","SearchTavilyOptionsIncludeRawContentVariant1Text"]}],"description":"Request native full-page content. Defaults to markdown when omitted for this provider, False disables that native retrieval; it does not disable explicitly requested Kernel browser retrieval."},"language":{"description":"ISO 639-1 code or English language name. Ranking boost unless filter_by_language.","type":"string"},"max_results":{"description":"Provider-native count. Lower-only alias for max_results.","minimum":1,"type":"integer"},"search_depth":{"description":"Provider relevance and latency tier. Some tiers cannot be combined with native safe search; conflicts are described in warnings.","enum":["advanced","basic","fast","ultra-fast"],"type":"string","x-enum-varnames":["SearchTavilyOptionsSearchDepthAdvanced","SearchTavilyOptionsSearchDepthBasic","SearchTavilyOptionsSearchDepthFast","SearchTavilyOptionsSearchDepthUltraFast"]},"topic":{"description":"Provider corpus selector. Publication metadata depends on the selected topic.","enum":["general","news","finance"],"type":"string","x-enum-varnames":["SearchTavilyOptionsTopicGeneral","SearchTavilyOptionsTopicNews","SearchTavilyOptionsTopicFinance"]}},"type":"object"},"SearchTavilyTarget":{"additionalProperties":false,"properties":{"options":{"$ref":"#/components/schemas/SearchTavilyOptions"},"provider":{"const":"tavily","type":"string"}},"required":["provider"],"type":"object"},"SearchUsage":{"properties":{"content_fetches":{"description":"Number of result URLs for which a Kernel browser retrieval received a response from the target, excluding cache-only hits.","minimum":0,"type":"integer"},"cost":{"description":"Total customer charge in USD when billing data is available.","minimum":0,"type":"number"},"results_count":{"description":"Number of result entries returned, including failed entries on the contents endpoint.","minimum":0,"type":"integer"}},"required":["results_count","content_fetches"],"type":"object"},"SearchValyuOptions":{"additionalProperties":false,"properties":{"fast_mode":{"description":"Trade depth for latency.","type":"boolean"},"historical_cache":{"description":"Allow historical cached results.","type":"boolean"},"include_abstracts":{"description":"Include abstracts for academic sources.","type":"boolean"},"instructions":{"description":"Natural-language retrieval guidance.","type":"string"},"is_tool_call":{"description":"Mark the search as an agent tool call.","type":"boolean"},"max_num_results":{"description":"Provider-native count. Lower-only alias for max_results.","minimum":1,"type":"integer"},"max_price":{"description":"Provider-native USD-per-thousand-results price ceiling. Forwarded to Valyu.","type":"number"},"relevance_threshold":{"description":"Provider-native minimum relevance threshold. Not a normalized cross-provider score.","type":"number"},"response_length":{"description":"Provider result-content length preset.","enum":["short","medium","large","max"],"type":"string","x-enum-varnames":["SearchValyuOptionsResponseLengthShort","SearchValyuOptionsResponseLengthMedium","SearchValyuOptionsResponseLengthLarge","SearchValyuOptionsResponseLengthMax"]},"search_type":{"description":"Corpus selector, including all, web, proprietary, and news. Provider corpus choice may change billing; Kernel does not force web-only searches.","type":"string"},"source_biases":{"description":"Bias retrieval toward these sources.","items":{"type":"string"},"type":"array"},"url_only":{"description":"Return URLs without content.","type":"boolean"}},"type":"object"},"SearchValyuTarget":{"additionalProperties":false,"properties":{"options":{"$ref":"#/components/schemas/SearchValyuOptions"},"provider":{"const":"valyu","type":"string"}},"required":["provider"],"type":"object"},"SearchWarning":{"properties":{"code":{"description":"Examples: param_unsupported, preference_unsupported, max_results_clamped, domains_truncated, recency_emulated, filter_emulated, date_filter_overridden, provider_ineligible, fallback_failed, content_partial.","type":"string"},"message":{"type":"string"},"param":{"type":"string"},"provider":{"type":"string"},"result_id":{"type":"string"}},"required":["code","message"],"type":"object"},"SearchYouOptions":{"additionalProperties":false,"properties":{"boost_domains":{"description":"Prefer these domains without excluding others. Cannot be combined with include_domains if the provider does not accept the combination.","items":{"type":"string"},"type":"array"},"count":{"description":"Provider-native per-section count. Lower-only alias for max_results. Web and news sections may produce more rows than Kernel returns.","minimum":1,"type":"integer"},"crawl_timeout":{"description":"Native extraction timeout in seconds, bounded by the remaining Kernel request deadline.","type":"integer"},"extraction":{"$ref":"#/components/schemas/SearchYouOptionsExtraction"},"knowledge":{"description":"Request licensed-data output. URL-less knowledge entries are not converted into web results; include_raw exposes the full provider response separately.","enum":["core"],"type":"string","x-enum-varnames":["SearchYouOptionsKnowledgeCore"]},"language":{"description":"BCP 47 result language from You.com's 51-value enum, e.g. \"EN\", \"JA\". Default EN.","type":"string"},"offset":{"description":"Page offset supported by You.com.","maximum":9,"minimum":0,"type":"integer"}},"type":"object"},"SearchYouOptionsExtraction":{"additionalProperties":false,"description":"Provider-native page extraction. Both modes may incur per-row charges; full_page may retrieve web and news rows.","properties":{"extraction_mode":{"enum":["highlights","full_page"],"type":"string","x-enum-varnames":["SearchYouOptionsExtractionExtractionModeHighlights","SearchYouOptionsExtractionExtractionModeFullPage"]},"full_page":{"$ref":"#/components/schemas/SearchYouOptionsExtractionFullPage"}},"required":["extraction_mode"],"type":"object"},"SearchYouOptionsExtractionFullPage":{"additionalProperties":false,"properties":{"extraction_formats":{"items":{"$ref":"#/components/schemas/SearchYouOptionsExtractionFullPageExtractionFormatsItem"},"type":"array"}},"type":"object"},"SearchYouOptionsExtractionFullPageExtractionFormatsItem":{"enum":["html","markdown"],"type":"string","x-enum-varnames":["SearchYouOptionsExtractionFullPageExtractionFormatsItemHtml","SearchYouOptionsExtractionFullPageExtractionFormatsItemMarkdown"]},"SearchYouTarget":{"additionalProperties":false,"properties":{"options":{"$ref":"#/components/schemas/SearchYouOptions"},"provider":{"const":"you","type":"string"}},"required":["provider"],"type":"object"},"SetCursorRequest":{"additionalProperties":false,"properties":{"hidden":{"description":"Whether the cursor should be hidden or visible","type":"boolean"}},"required":["hidden"],"type":"object"},"SetFilePermissionsRequest":{"additionalProperties":false,"properties":{"group":{"description":"New group name or GID.","type":"string"},"mode":{"description":"File mode bits (octal string, e.g. 644).","pattern":"^[0-7]{3,4}$","type":"string"},"owner":{"description":"New owner username or UID.","type":"string"},"path":{"description":"Absolute path whose permissions are to be changed.","pattern":"^/.*","type":"string"}},"required":["path","mode"],"type":"object"},"SignInOption":{"additionalProperties":false,"description":"A non-MFA choice presented during the auth flow (e.g. account selection, org picker)","properties":{"description":{"description":"Additional context such as email address or org name","example":"user@company.com","nullable":true,"type":"string"},"id":{"description":"Unique identifier for this option (used to submit selection back)","example":"work-account","type":"string"},"label":{"description":"Display text for the option","example":"Work Account (user@company.com)","type":"string"}},"required":["id","label"],"type":"object"},"SleepAction":{"additionalProperties":false,"description":"Pause execution for a specified duration.","properties":{"duration_ms":{"description":"Duration to sleep in milliseconds.","maximum":30000,"minimum":0,"type":"integer"}},"required":["duration_ms"],"type":"object"},"SpendApprovalAction":{"additionalProperties":false,"properties":{"name":{"enum":["spend_approval"],"type":"string"},"url":{"format":"uri","type":"string"}},"required":["name","url"],"type":"object"},"StartFsWatchRequest":{"additionalProperties":false,"properties":{"path":{"description":"Directory to watch.","type":"string"},"recursive":{"default":false,"description":"Whether to watch recursively.","type":"boolean"}},"required":["path"],"type":"object"},"SubmitFieldsRequest":{"additionalProperties":false,"description":"Request to submit field values, click an SSO button, select an MFA method, or select a sign-in option. Prefer canonical selected_choice_id/field_values when the API returns fields/choices; legacy fields/sso_button_selector/sso_provider/mfa_option_id/sign_in_option_id remain supported during deprecation.","properties":{"field_values":{"additionalProperties":{"type":"string"},"description":"Canonical map of field ID to submitted value.","example":{"field_email":"user@example.com","field_password":"secret"},"type":"object"},"fields":{"additionalProperties":{"type":"string"},"description":"Map of field name to value","example":{"email":"user@example.com","password":"secret"},"type":"object"},"interaction_id":{"description":"Opaque interaction ID returned with canonical fields and choices. Required for canonical submissions.","example":"mai_abc123xyz","type":"string"},"mfa_option_id":{"description":"The MFA method type to select (when mfa_options were returned)","example":"sms","type":"string"},"selected_choice_id":{"description":"Canonical choice ID selected by the user.","example":"google","type":"string"},"sign_in_option_id":{"description":"The sign-in option ID to select (when sign_in_options were returned)","example":"work-account","type":"string"},"sso_button_selector":{"description":"XPath selector for the SSO button to click (ODA). Use sso_provider instead for CUA.","example":"xpath=//button[contains(text(), 'Continue with Google')]","type":"string"},"sso_provider":{"description":"SSO provider to click, matching the provider field from pending_sso_buttons (e.g., \"google\", \"github\"). Cannot be used with sso_button_selector.","example":"google","type":"string"}},"type":"object"},"SubmitFieldsResponse":{"additionalProperties":false,"description":"Response from submitting field values","properties":{"accepted":{"description":"Whether the submission was accepted for processing","type":"boolean"}},"required":["accepted"],"type":"object"},"Tags":{"additionalProperties":{"maxLength":256,"minLength":0,"pattern":"^[A-Za-z0-9 _.:/=+@-]*$","type":"string"},"description":"User-defined key-value tags.","example":{"env":"staging","team":"backend"},"maxProperties":50,"propertyNames":{"maxLength":128,"minLength":1,"pattern":"^[A-Za-z0-9 _.:/=+@-]+$","type":"string"},"type":"object"},"TypeTextRequest":{"additionalProperties":false,"properties":{"delay":{"default":0,"description":"Delay in milliseconds between keystrokes","minimum":0,"type":"integer"},"text":{"description":"Text to type on the browser instance","type":"string"}},"required":["text"],"type":"object"},"UpdateApiKeyRequest":{"properties":{"name":{"description":"New API key name","example":"new-api-name","maxLength":255,"minLength":1,"type":"string"}},"required":["name"],"type":"object"},"UpdateAuditLogExportDestinationRequest":{"additionalProperties":false,"properties":{"bucket":{"maxLength":63,"minLength":3,"type":"string"},"kms_key_id":{"description":"KMS key ID, alias, or ARN. Set to an empty string to remove the configured KMS key; omit or send null to leave unchanged.","maxLength":2048,"type":"string"},"prefix":{"maxLength":512,"type":"string"},"region":{"maxLength":128,"minLength":1,"type":"string"},"role_arn":{"maxLength":2048,"minLength":1,"type":"string"},"status":{"enum":["active","paused"],"type":"string"}},"type":"object"},"UpdateCredentialProviderRequest":{"additionalProperties":false,"description":"Request to update a credential provider","properties":{"cache_ttl_seconds":{"description":"How long to cache credential lists","example":300,"type":"integer"},"enabled":{"description":"Whether the provider is enabled for credential lookups","example":true,"type":"boolean"},"name":{"description":"Human-readable name for this provider instance. Surrounding whitespace is trimmed and the trimmed value must be non-empty.","example":"my-1password","minLength":1,"pattern":"\\S","type":"string"},"priority":{"description":"Priority order for credential lookups (lower numbers are checked first)","example":0,"type":"integer"},"token":{"description":"New service account token (to rotate credentials)","example":"ops_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...","type":"string"}},"type":"object"},"UpdateCredentialRequest":{"additionalProperties":false,"description":"Request to update an existing credential","properties":{"name":{"description":"New name for the credential","example":"my-updated-login","type":"string"},"remove_value_keys":{"description":"Field names to remove from the credential's stored values. Removals are applied before `values` are merged, so a key present in both is kept with its new value.","example":["old_field"],"items":{"type":"string"},"type":"array"},"sso_provider":{"description":"If set, indicates this credential should be used with the specified SSO provider. Set to empty string or null to remove.","example":"google","nullable":true,"type":"string"},"totp_algorithm":{"description":"HMAC algorithm used to generate TOTP codes. Requires totp_secret and is ignored when an `otpauth://` URI supplies the algorithm.","enum":["SHA1","SHA256","SHA512"],"example":"SHA1","type":"string"},"totp_digits":{"description":"Number of digits in generated TOTP codes. Requires totp_secret and is ignored when an `otpauth://` URI supplies the digit count.","example":6,"maximum":9,"minimum":6,"type":"integer"},"totp_period":{"description":"TOTP rotation period in seconds. Requires totp_secret and is ignored when an `otpauth://` URI supplies the period.","example":30,"maximum":300,"minimum":15,"type":"integer"},"totp_secret":{"description":"Accepts a 16-128 character base32-encoded TOTP secret or an `otpauth://totp/...` URI. Only URI parameters present override the corresponding explicit TOTP fields. When rotating a raw secret, omitted fields preserve their existing values; a new URI defaults unspecified fields to SHA1/6/30. Set to empty string to remove the secret and its metadata.","example":"JBSWY3DPEHPK3PXP","type":"string"},"values":{"additionalProperties":{"type":"string"},"description":"Field name to value mapping. Values are merged with existing values (new keys added, existing keys overwritten).","example":{"password":"newpassword","username":"user@example.com"},"type":"object"}},"type":"object"},"UpdateOrgLimitsRequest":{"properties":{"default_project_max_concurrent_sessions":{"description":"Default maximum concurrent browsers for projects without an explicit override. Set to 0 to remove the default; omit to leave unchanged. Cannot exceed the organization's concurrency limit.","nullable":true,"type":"integer"}},"type":"object"},"UpdateProjectLimitsRequest":{"properties":{"max_concurrent_invocations":{"description":"Maximum concurrent app invocations for this project. Set to 0 to remove the cap; omit to leave unchanged.","nullable":true,"type":"integer"},"max_concurrent_sessions":{"description":"Maximum concurrent browsers for this project, covering both on-demand sessions and browser pool reservations. Set to 0 to remove the cap; omit to leave unchanged.","nullable":true,"type":"integer"},"max_pooled_sessions":{"deprecated":true,"description":"Deprecated: pooled browsers now count toward `max_concurrent_sessions`. Requests that set this field are rejected with a 400.","nullable":true,"type":"integer"}},"type":"object"},"UpdateProjectRequest":{"properties":{"name":{"description":"New project name (1-255 Unicode code points; cannot contain `/` or `%`)","maxLength":255,"minLength":1,"type":"string"},"status":{"description":"New project status","enum":["active","archived"],"type":"string"}},"type":"object"},"Vault":{"additionalProperties":false,"properties":{"created_at":{"format":"date-time","type":"string"},"id":{"type":"string"},"name":{"description":"Immutable name assigned when the vault is created.","type":"string"},"updated_at":{"format":"date-time","type":"string"}},"required":["id","name","created_at","updated_at"],"type":"object"},"VaultAgentCardProviderClientCredentials":{"$ref":"#/components/schemas/VaultOAuthClientCredentials"},"VaultAgentCardProviderConfig":{"additionalProperties":false,"description":"Response schema for an AgentCard configuration, without secret credentials. Kernel generates the ID and timestamps and introspects test_mode from the credentials. Configuration creation uses VaultAgentCardProviderConfigRequest.","properties":{"client_id":{"type":"string"},"created_at":{"format":"date-time","readOnly":true,"type":"string"},"id":{"readOnly":true,"type":"string"},"name":{"pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"},"provider":{"enum":["agentcard"],"type":"string"},"test_mode":{"description":"Introspected mode of the selected credential; true means sandbox objects.","readOnly":true,"type":"boolean"},"updated_at":{"format":"date-time","readOnly":true,"type":"string"}},"required":["id","name","provider","client_id","test_mode","created_at","updated_at"],"type":"object"},"VaultAgentCardProviderConfigRequest":{"additionalProperties":false,"description":"Register application credentials for AgentCard wallet enrollment and checkout approvals. Kernel obtains application access tokens using client_credentials.","properties":{"credentials":{"$ref":"#/components/schemas/VaultAgentCardProviderClientCredentials","writeOnly":true},"name":{"description":"Unique within the organization.","pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"},"provider":{"enum":["agentcard"],"type":"string"}},"required":["name","provider","credentials"],"type":"object"},"VaultCardAliases":{"additionalProperties":false,"properties":{"cvc":{"pattern":"^\\d{3}$","type":"string"},"exp_month":{"pattern":"^\\d{2}$","type":"string"},"exp_year":{"pattern":"^\\d{4}$","type":"string"},"number":{"pattern":"^\\d{16}$","type":"string"}},"readOnly":true,"required":["number","cvc","exp_month","exp_year"],"type":"object"},"VaultCardExpirationFillField":{"additionalProperties":false,"description":"Combined expiration derived from the stored month and year; not a separate stored secret.","example":{"field":"expiration","format":"MM/YY","selector":"#expiry"},"properties":{"field":{"enum":["expiration"],"type":"string"},"format":{"enum":["MM/YY","MM/YYYY"],"type":"string"},"selector":{"description":"CSS selector for an editable input or select, or a containing element. Must resolve to one unique editable element across all page frames.","minLength":1,"type":"string"}},"required":["field","format","selector"],"type":"object"},"VaultCardFillField":{"oneOf":[{"$ref":"#/components/schemas/VaultCardStoredFillField"},{"$ref":"#/components/schemas/VaultCardExpirationFillField"}]},"VaultCardStoredFillField":{"additionalProperties":false,"properties":{"field":{"description":"Field in the decrypted card, not an alias. Number and CVC preserve leading zeros; month uses two digits and year uses four digits. Billing fields use the provider's stored billing address (name, line1, line2, city, state, postal_code, country) without reformatting. Request only needed billing fields. An absent or empty requested billing field returns 400 field_unavailable before any browser writes; it does not make other card fields unavailable.","enum":["number","exp_month","exp_year","cvc","billing_name","billing_line1","billing_line2","billing_city","billing_state","billing_postal_code","billing_country"],"type":"string"},"selector":{"description":"CSS selector for an editable input or select, or a containing element. Must resolve to one unique editable element across all page frames.","minLength":1,"type":"string"}},"required":["field","selector"],"type":"object"},"VaultCheckoutContext":{"additionalProperties":false,"description":"Required when preparing an unused AgentCard card for a supported checkout processor. Consent is bound to this browser and declared merchant origin, not a tab. Wait for the item's ready_to_submit status before native Pay and submit within its readiness deadline. Unused preparations expire automatically; every preparation is single-use, including after failure or expiry.","properties":{"browser_id":{"description":"Active browser session with this vault bound to it.","type":"string"},"environment":{"description":"Use production or sandbox for Square, Braintree, Worldpay and Adyen; shared for Bambora and Mercado Pago. Shared endpoints do not establish test mode. Merchant credentials/configuration determine processor test mode, independently of the AgentCard credential mode.","enum":["production","sandbox","shared"],"type":"string"},"merchant_origin":{"description":"Canonical HTTPS origin of the top-level merchant document, not a processor iframe. HTTP localhost is accepted for tests.","type":"string"},"psp":{"$ref":"#/components/schemas/AgentCardPreparedProcessor","description":"Checkout processor. Omit for Square compatibility. Adyen supports fresh-card Sessions requests on Adyen hosts only. Use public dummy card fields, not vault aliases. The unique armed preparation is associated with the subsequent eligible request from this browser and declared merchant origin; competing preparations are rejected."}},"required":["browser_id","merchant_origin","environment"],"type":"object"},"VaultFillField":{"additionalProperties":false,"properties":{"field":{"description":"A declared credential field name or a supported card field. Unset credential fields cannot be filled.","minLength":1,"type":"string"},"format":{"description":"Required only for a card's combined expiration field. Forbidden for other card fields and all credential fields.","enum":["MM/YY","MM/YYYY"],"type":"string"},"selector":{"minLength":1,"type":"string"}},"required":["field","selector"],"type":"object"},"VaultFillFieldResult":{"additionalProperties":false,"properties":{"error_code":{"description":"Present only for failed or unknown fields. Never includes secret values, DOM content, or raw browser errors.","enum":["target_changed","element_not_found","ambiguous_selector","element_not_editable","option_not_found","timeout","execution_failed"],"type":"string"},"index":{"description":"Zero-based index into the request fields array.","maximum":31,"minimum":0,"type":"integer"},"status":{"description":"Filled means the fill action completed, not that the website retained or accepted the value.","enum":["filled","failed","not_attempted","unknown"],"type":"string"}},"required":["index","status"],"type":"object"},"VaultItem":{"discriminator":{"mapping":{"card":"#/components/schemas/CardVaultItem","credential":"#/components/schemas/CredentialVaultItem","credential_account":"#/components/schemas/CredentialAccountVaultItem","wallet":"#/components/schemas/WalletVaultItem"},"propertyName":"type"},"oneOf":[{"$ref":"#/components/schemas/WalletVaultItem"},{"$ref":"#/components/schemas/CardVaultItem"},{"$ref":"#/components/schemas/CredentialAccountVaultItem"},{"$ref":"#/components/schemas/CredentialVaultItem"}]},"VaultItemAction":{"discriminator":{"mapping":{"1password_oauth":"#/components/schemas/OnePasswordOAuthAction","card_enrollment":"#/components/schemas/CardEnrollmentAction","collect":"#/components/schemas/CollectAction","embedded_ceremony":"#/components/schemas/EmbeddedCeremonyAction","link_oauth":"#/components/schemas/LinkOAuthAction","mfa":"#/components/schemas/MfaAction","push_approval":"#/components/schemas/PushApprovalAction","spend_approval":"#/components/schemas/SpendApprovalAction"},"propertyName":"name"},"oneOf":[{"$ref":"#/components/schemas/LinkOAuthAction"},{"$ref":"#/components/schemas/OnePasswordOAuthAction"},{"$ref":"#/components/schemas/SpendApprovalAction"},{"$ref":"#/components/schemas/PushApprovalAction"},{"$ref":"#/components/schemas/CollectAction"},{"$ref":"#/components/schemas/MfaAction"},{"$ref":"#/components/schemas/EmbeddedCeremonyAction"},{"$ref":"#/components/schemas/CardEnrollmentAction"}]},"VaultItemEvent":{"additionalProperties":false,"properties":{"browser_id":{"description":"Browser session associated with the event, when applicable.","type":"string"},"created_at":{"format":"date-time","type":"string"},"data":{"additionalProperties":true,"type":"object"},"id":{"type":"string"},"name":{"type":"string"}},"required":["id","name","created_at"],"type":"object"},"VaultItemExpanded":{"additionalProperties":false,"description":"Live, non-persisted data requested through the item GET expand parameter.","properties":{"payment_methods":{"items":{"$ref":"#/components/schemas/VaultPaymentMethod"},"type":"array"}},"type":"object"},"VaultItemExpansionType":{"enum":["payment_methods"],"type":"string"},"VaultItemMasks":{"additionalProperties":{"type":"string"},"properties":{"brand":{"type":"string"},"last4":{"maxLength":4,"minLength":4,"type":"string"}},"type":"object"},"VaultItemOperationRequest":{"discriminator":{"mapping":{"1pw_access_request_status":"#/components/schemas/OnePasswordPollAccessVaultItemOperationRequest","1pw_create_access_request":"#/components/schemas/OnePasswordRequestAccessVaultItemOperationRequest","1pw_fill":"#/components/schemas/OnePasswordFillVaultItemOperationRequest","1pw_recover":"#/components/schemas/OnePasswordRecoverVaultItemOperationRequest","1pw_update_access_token":"#/components/schemas/OnePasswordUpdateAccessTokenVaultItemOperationRequest","authorize":"#/components/schemas/AuthorizeVaultItemOperationRequest","collect":"#/components/schemas/CollectVaultItemOperationRequest","fill":"#/components/schemas/FillVaultItemOperationRequest","prepare_checkout":"#/components/schemas/PrepareCheckoutVaultItemOperationRequest"},"propertyName":"type"},"oneOf":[{"$ref":"#/components/schemas/AuthorizeVaultItemOperationRequest"},{"$ref":"#/components/schemas/CollectVaultItemOperationRequest"},{"$ref":"#/components/schemas/PrepareCheckoutVaultItemOperationRequest"},{"$ref":"#/components/schemas/FillVaultItemOperationRequest"},{"$ref":"#/components/schemas/OnePasswordRequestAccessVaultItemOperationRequest"},{"$ref":"#/components/schemas/OnePasswordPollAccessVaultItemOperationRequest"},{"$ref":"#/components/schemas/OnePasswordFillVaultItemOperationRequest"},{"$ref":"#/components/schemas/OnePasswordRecoverVaultItemOperationRequest"},{"$ref":"#/components/schemas/OnePasswordUpdateAccessTokenVaultItemOperationRequest"}]},"VaultItemOperationResponse":{"oneOf":[{"$ref":"#/components/schemas/VaultItem"},{"$ref":"#/components/schemas/FillVaultItemOperationResult"},{"$ref":"#/components/schemas/OnePasswordFillVaultItemOperationResult"}]},"VaultItemOperationType":{"enum":["authorize","collect","prepare_checkout","fill","1pw_create_access_request","1pw_access_request_status","1pw_fill","1pw_recover","1pw_update_access_token"],"type":"string"},"VaultItemRequest":{"discriminator":{"mapping":{"card":"#/components/schemas/CardVaultItemRequest","credential":"#/components/schemas/CredentialVaultItemRequest","credential_account":"#/components/schemas/CredentialAccountVaultItemRequest","wallet":"#/components/schemas/WalletVaultItemRequest"},"propertyName":"type"},"oneOf":[{"$ref":"#/components/schemas/WalletVaultItemRequest"},{"$ref":"#/components/schemas/CardVaultItemRequest"},{"$ref":"#/components/schemas/CredentialAccountVaultItemRequest"},{"$ref":"#/components/schemas/CredentialVaultItemRequest"}]},"VaultItemUpdateRequest":{"description":"Type must match the stored item; an update cannot change item type. Legacy card updates may omit type. Credential updates require explicit type and version. Wallet updates are unsupported.","oneOf":[{"$ref":"#/components/schemas/CardVaultItemUpdateRequest"},{"$ref":"#/components/schemas/CredentialVaultItemUpdateRequest"}]},"VaultLinkProviderClientCredentials":{"additionalProperties":false,"properties":{"client_id":{"minLength":1,"type":"string"},"client_secret":{"minLength":1,"type":"string","writeOnly":true},"publishable_key":{"description":"Stripe publishable key for the account that owns the Link OAuth client. Link requires it as the bearer credential when Kernel refreshes or revokes imported wallet grants; without it, those wallets stop working when the imported access token expires.","pattern":"^pk_(live|test)_[A-Za-z0-9]+$","type":"string"}},"required":["client_id","client_secret"],"type":"object"},"VaultLinkProviderConfig":{"additionalProperties":false,"description":"Response schema for a Link configuration, without secret credentials. Kernel generates the ID and timestamps. Configuration creation uses VaultLinkProviderConfigRequest.","properties":{"client_id":{"description":"OAuth client identity; immutable. Secret credentials are never returned.","type":"string"},"created_at":{"format":"date-time","readOnly":true,"type":"string"},"id":{"readOnly":true,"type":"string"},"name":{"description":"Unique within the organization.","pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"},"provider":{"enum":["link"],"type":"string"},"publishable_key":{"description":"Stripe publishable key sent to Link when refreshing and revoking wallet grants. Omitted when not configured.","type":"string"},"updated_at":{"format":"date-time","readOnly":true,"type":"string"}},"required":["id","name","provider","client_id","created_at","updated_at"],"type":"object"},"VaultLinkProviderConfigRequest":{"additionalProperties":false,"description":"Register a customer-owned Link OAuth client for refreshing and revoking imported wallet grants. The customer is responsible for initiating OAuth flows to connect a user's wallet and handling the redirect to obtain a Link access token and refresh token.","properties":{"credentials":{"allOf":[{"$ref":"#/components/schemas/VaultLinkProviderClientCredentials"}],"writeOnly":true},"name":{"description":"Unique within the organization.","pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"},"provider":{"enum":["link"],"type":"string"}},"required":["name","provider","credentials"],"type":"object"},"VaultOAuthClientCredentials":{"additionalProperties":false,"properties":{"client_id":{"minLength":1,"type":"string"},"client_secret":{"minLength":1,"type":"string","writeOnly":true}},"required":["client_id","client_secret"],"type":"object"},"VaultPaymentMethod":{"additionalProperties":false,"properties":{"capabilities":{"$ref":"#/components/schemas/VaultPaymentMethodCapabilities"},"display":{"$ref":"#/components/schemas/VaultPaymentMethodDisplay"},"id":{"type":"string"},"is_default":{"type":"boolean"},"provider":{"description":"Provider that issued this payment-method ID.","type":"string"},"type":{"description":"Provider-neutral payment-method type normalized to lowercase.","type":"string"}},"required":["id","provider","type","is_default","display","capabilities"],"type":"object"},"VaultPaymentMethodCapabilities":{"additionalProperties":false,"description":"Provider-reported advisory capabilities. A missing capability is unknown, not ineligible; only eligible=false is an explicit negative signal.","properties":{"single_use_card":{"$ref":"#/components/schemas/VaultPaymentMethodCapability"}},"type":"object"},"VaultPaymentMethodCapability":{"additionalProperties":false,"properties":{"eligible":{"type":"boolean"},"reasons":{"items":{"type":"string"},"type":"array"}},"required":["eligible","reasons"],"type":"object"},"VaultPaymentMethodDisplay":{"additionalProperties":false,"properties":{"brand":{"type":"string"},"label":{"type":"string"},"last4":{"type":"string"}},"type":"object"},"VaultProviderConfig":{"discriminator":{"mapping":{"agentcard":"#/components/schemas/VaultAgentCardProviderConfig","link":"#/components/schemas/VaultLinkProviderConfig"},"propertyName":"provider"},"oneOf":[{"$ref":"#/components/schemas/VaultLinkProviderConfig"},{"$ref":"#/components/schemas/VaultAgentCardProviderConfig"}]},"VaultProviderConfigReference":{"additionalProperties":false,"description":"Select a provider config by ID or name. Responses return the ID. Renaming a config does not change existing wallet bindings; an item cannot switch to a different config after creation.","oneOf":[{"required":["id"]},{"required":["name"]}],"properties":{"id":{"minLength":1,"type":"string"},"name":{"pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"}},"type":"object"},"VaultProviderConfigRequest":{"description":"Provider-specific settings and credentials for a configuration shared across the organization's projects.","discriminator":{"mapping":{"agentcard":"#/components/schemas/VaultAgentCardProviderConfigRequest","link":"#/components/schemas/VaultLinkProviderConfigRequest"},"propertyName":"provider"},"oneOf":[{"$ref":"#/components/schemas/VaultLinkProviderConfigRequest"},{"$ref":"#/components/schemas/VaultAgentCardProviderConfigRequest"}]},"VaultProviderConfigUpdateRequest":{"additionalProperties":false,"description":"Update a provider configuration. Omitted fields are left unchanged. Renaming preserves item bindings. Credential updates apply to all wallets using this configuration. Provider and client ID are immutable; changing clients requires a new configuration. The selected configuration determines how credentials are validated; its identity and mode must not change during secret rotation.","properties":{"credentials":{"additionalProperties":false,"description":"Fields to update. Omitted credentials are left unchanged. A rejected update leaves existing credentials unchanged.","properties":{"client_secret":{"minLength":1,"type":"string","writeOnly":true},"publishable_key":{"description":"Link configurations only. Stripe publishable key sent to Link when refreshing and revoking wallet grants.","pattern":"^pk_(live|test)_[A-Za-z0-9]+$","type":"string"}},"type":"object","writeOnly":true},"name":{"description":"Unique within the organization.","pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"}},"type":"object"},"VaultReference":{"additionalProperties":false,"description":"Reference to a project-scoped vault. Provide exactly one of id or name.","properties":{"id":{"type":"string"},"name":{"maxLength":255,"minLength":1,"type":"string"}},"type":"object"},"VaultRequest":{"additionalProperties":false,"properties":{"name":{"description":"Immutable name used to create or retrieve the vault.","maxLength":255,"minLength":1,"pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"}},"required":["name"],"type":"object"},"WalletVaultItem":{"additionalProperties":false,"properties":{"action":{"$ref":"#/components/schemas/VaultItemAction"},"available_expansions":{"items":{"$ref":"#/components/schemas/AvailableVaultItemExpansion"},"type":"array"},"available_operations":{"items":{"$ref":"#/components/schemas/AvailableVaultItemOperation"},"type":"array"},"created_at":{"format":"date-time","type":"string"},"expanded":{"$ref":"#/components/schemas/VaultItemExpanded"},"expires_at":{"format":"date-time","type":"string"},"id":{"type":"string"},"key":{"description":"Immutable item key assigned when the item is created.","type":"string"},"spec":{"$ref":"#/components/schemas/WalletVaultItemSpec"},"state":{"$ref":"#/components/schemas/WalletVaultItemState"},"type":{"enum":["wallet"],"type":"string"},"updated_at":{"format":"date-time","type":"string"}},"required":["id","key","type","spec","state","available_operations","available_expansions","created_at","updated_at"],"type":"object"},"WalletVaultItemRequest":{"additionalProperties":false,"properties":{"spec":{"discriminator":{"mapping":{"agentcard":"#/components/schemas/AgentCardWalletVaultItemSpec","link":"#/components/schemas/LinkWalletVaultItemRequestSpec"},"propertyName":"provider"},"oneOf":[{"$ref":"#/components/schemas/LinkWalletVaultItemRequestSpec"},{"$ref":"#/components/schemas/AgentCardWalletVaultItemSpec"}]},"type":{"enum":["wallet"],"type":"string"}},"required":["type","spec"],"type":"object"},"WalletVaultItemSpec":{"discriminator":{"mapping":{"agentcard":"#/components/schemas/AgentCardWalletVaultItemSpec","link":"#/components/schemas/LinkWalletVaultItemSpec"},"propertyName":"provider"},"oneOf":[{"$ref":"#/components/schemas/LinkWalletVaultItemSpec"},{"$ref":"#/components/schemas/AgentCardWalletVaultItemSpec"}]},"WalletVaultItemState":{"discriminator":{"mapping":{"agentcard":"#/components/schemas/AgentCardWalletState","link":"#/components/schemas/LinkWalletState"},"propertyName":"provider"},"oneOf":[{"$ref":"#/components/schemas/LinkWalletState"},{"$ref":"#/components/schemas/AgentCardWalletState"}]},"WebMCPCustomToolSource":{"additionalProperties":false,"properties":{"id":{"pattern":"^ct_[a-z][a-z0-9]{23}$","type":"string"},"namespace":{"type":"string"}},"required":["id","namespace"],"type":"object"},"WebMCPInvocationFailure":{"additionalProperties":false,"properties":{"code":{"enum":["outcome_unknown"],"type":"string"},"invocation_id":{"type":"string"},"message":{"type":"string"}},"required":["code","message"],"type":"object"},"WebMCPInvocationResult":{"additionalProperties":false,"properties":{"error_text":{"type":"string"},"invocation_id":{"type":"string"},"output":{"description":"Untrusted page-provided output. Callers must treat it as potentially malicious input."},"status":{"description":"awaiting_submission means a non-autosubmit declarative form was populated but not submitted.\nInspect the form, obtain any required confirmation, then submit through Playwright or computer\ninteraction without invoking the tool again. The other statuses are terminal results.\n","enum":["completed","canceled","error","awaiting_submission"],"type":"string"}},"required":["invocation_id","status"],"type":"object"},"WebMCPInvokeRequest":{"additionalProperties":false,"properties":{"input":{"additionalProperties":true,"description":"Tool input, limited to 1 MiB after JSON serialization.","type":"object"},"timeout_sec":{"default":60,"maximum":120,"minimum":1,"type":"integer"},"tool_ref":{"maxLength":128,"minLength":1,"type":"string"}},"required":["tool_ref","input"],"type":"object"},"WebMCPTool":{"additionalProperties":false,"properties":{"source":{"$ref":"#/components/schemas/WebMCPToolSource"},"tool":{"$ref":"#/components/schemas/WebMCPToolMetadata"},"tool_ref":{"description":"Opaque reference for invoking this exact live registration. It becomes invalid when its document or browser process is replaced.","type":"string"}},"required":["tool_ref","tool","source"],"type":"object"},"WebMCPToolAnnotations":{"additionalProperties":false,"description":"Tool-provided behavioral hints from the [MCP tool specification](https://modelcontextprotocol.io/specification/2025-11-25/server/tools#tool)\nand the [WebMCP ToolAnnotations definition](https://webmachinelearning.github.io/webmcp/#dictdef-toolannotations).\nThese hints are untrusted and are not enforced by Kernel.\n","properties":{"autosubmit":{"type":"boolean"},"consequentialHint":{"type":"boolean"},"destructiveHint":{"type":"boolean"},"idempotentHint":{"type":"boolean"},"openWorldHint":{"type":"boolean"},"readOnlyHint":{"type":"boolean"},"untrustedContentHint":{"type":"boolean"}},"type":"object"},"WebMCPToolFrame":{"additionalProperties":false,"properties":{"frame_id":{"description":"Monotonically increasing identifier for this embedded frame during the current browser process.","minimum":1,"type":"integer"},"url":{"description":"Current frame URL with the fragment omitted.","type":"string"}},"required":["frame_id","url"],"type":"object"},"WebMCPToolMetadata":{"additionalProperties":false,"description":"Tool metadata follows the [MCP Tool definition](https://modelcontextprotocol.io/specification/2025-11-25/server/tools#tool)\nand the [WebMCP RegisteredTool definition](https://webmachinelearning.github.io/webmcp/#dictdef-registeredtool).\noutputSchema is optional for page and custom tools.\n","properties":{"annotations":{"$ref":"#/components/schemas/WebMCPToolAnnotations"},"description":{"type":"string"},"inputSchema":{"additionalProperties":true,"type":"object"},"name":{"type":"string"},"outputSchema":{"additionalProperties":true,"type":"object"},"title":{"type":"string"}},"required":["name","description","inputSchema"],"type":"object"},"WebMCPToolSource":{"additionalProperties":false,"properties":{"custom":{"$ref":"#/components/schemas/WebMCPCustomToolSource"},"frame":{"allOf":[{"$ref":"#/components/schemas/WebMCPToolFrame"}],"description":"Embedded frame that registered the tool, or null when the top-level page registered it.","nullable":true},"page_title":{"description":"Current title of the top-level page.","type":"string"},"page_url":{"description":"Current URL of the top-level page with the fragment omitted.","type":"string"},"tab_id":{"description":"Monotonically increasing identifier for the tab during the current browser process.","minimum":1,"type":"integer"},"target_id":{"description":"CDP target ID for a custom tool's registration tab; omitted for page-provided tools.","type":"string"},"window_id":{"description":"Monotonically increasing identifier for the browser window during the current browser process.","minimum":1,"type":"integer"}},"required":["window_id","tab_id","page_title","page_url","frame"],"type":"object"},"WebMCPToolsResponse":{"additionalProperties":false,"properties":{"tools":{"items":{"$ref":"#/components/schemas/WebMCPTool"},"type":"array"}},"required":["tools"],"type":"object"},"WriteClipboardRequest":{"additionalProperties":false,"properties":{"text":{"description":"Text to write to the system clipboard","type":"string"}},"required":["text"],"type":"object"}},"securitySchemes":{"bearerAuth":{"scheme":"bearer","type":"http"}}},"info":{"description":"Developer tools and cloud infrastructure for AI agents to use web browsers","title":"Kernel API","version":"0.1.0"},"openapi":"3.1.0","paths":{"/apps":{"get":{"description":"List applications. Optionally filter by app name and/or version label.","operationId":"getApps","parameters":[{"description":"Filter results by application name.","in":"query","name":"app_name","required":false,"schema":{"type":"string"}},{"description":"Filter results by version label.","in":"query","name":"version","required":false,"schema":{"type":"string"}},{"description":"Limit the number of apps to return.","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"description":"Offset the number of apps to return.","in":"query","name":"offset","required":false,"schema":{"default":0,"minimum":0,"type":"integer"}},{"description":"Search apps by name.","in":"query","name":"query","required":false,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/AppVersionSummary"},"type":"array"}}},"description":"List of apps.","headers":{"X-Has-More":{"description":"Whether there are more apps to fetch.","schema":{"default":false,"type":"boolean"}},"X-Limit":{"description":"Limit the number of apps to return.","schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"nullable":true,"type":"integer"}},"X-Offset":{"description":"The offset of apps to return.","schema":{"default":0,"minimum":0,"type":"integer"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List apps","tags":["Apps"]}},"/audit-logs":{"get":{"description":"API for searching audit logs. Limited to at most 30 day search, returns up to 100 records per page. Not recommended for bulk export.","operationId":"getAuditLogs","parameters":[{"description":"Lower bound (inclusive) for the audit record timestamp.","in":"query","name":"start","required":true,"schema":{"example":"2026-01-01T00:00:00Z","format":"date-time","type":"string"}},{"description":"Upper bound (exclusive) for the audit record timestamp.","in":"query","name":"end","required":true,"schema":{"example":"2026-01-02T00:00:00Z","format":"date-time","type":"string"}},{"description":"Filter by authentication strategy.","in":"query","name":"auth_strategy","required":false,"schema":{"type":"string"}},{"description":"Filter by service name.","in":"query","name":"service","required":false,"schema":{"type":"string"}},{"description":"Filter by HTTP method.","in":"query","name":"method","required":false,"schema":{"type":"string"}},{"description":"Filter out results by HTTP method.","explode":false,"in":"query","name":"exclude_method","required":false,"schema":{"items":{"type":"string"},"maxItems":10,"type":"array"},"style":"form"},{"description":"Free-text search over path, user ID, email, client IP, and status.","in":"query","name":"search","required":false,"schema":{"type":"string"}},{"description":"Additional user IDs to OR into free-text search.","explode":false,"in":"query","name":"search_user_id","required":false,"schema":{"items":{"type":"string"},"maxItems":100,"type":"array"},"style":"form"},{"description":"Maximum number of results to return.","in":"query","name":"limit","required":false,"schema":{"default":100,"maximum":100,"minimum":1,"type":"integer"}},{"description":"Opaque page token from X-Next-Page-Token for the next page of older records.","in":"query","name":"page_token","required":false,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/AuditLogEntry"},"type":"array"}}},"description":"A list of audit log records.","headers":{"X-Has-More":{"description":"Whether there are more records available beyond this page.","schema":{"default":false,"type":"boolean"}},"X-Limit":{"description":"The limit applied to the returned records.","schema":{"maximum":100,"minimum":1,"type":"integer"}},"X-Next-Page-Token":{"description":"Page token for the next page of older records, omitted when no more results.","schema":{"type":"string"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List audit logs","tags":["Audit Logs"]}},"/audit-logs/export/chunk":{"get":{"description":"Download an organization's audit log records for a time range as a file, for archival, compliance, or offline analysis. For interactive browsing, use GET /audit-logs.","operationId":"getAuditLogsExportChunk","parameters":[{"description":"Lower bound (inclusive) for the audit record timestamp.","in":"query","name":"start","required":true,"schema":{"example":"2026-01-01T00:00:00Z","format":"date-time","type":"string"}},{"description":"Upper bound (exclusive) for the audit record timestamp.","in":"query","name":"end","required":true,"schema":{"example":"2026-01-02T00:00:00Z","format":"date-time","type":"string"}},{"description":"Filter by authentication strategy.","in":"query","name":"auth_strategy","required":false,"schema":{"type":"string"}},{"description":"Filter by service name.","in":"query","name":"service","required":false,"schema":{"type":"string"}},{"description":"Filter by HTTP method.","in":"query","name":"method","required":false,"schema":{"type":"string"}},{"description":"Filter out results by HTTP method.","explode":false,"in":"query","name":"exclude_method","required":false,"schema":{"items":{"type":"string"},"maxItems":10,"type":"array"},"style":"form"},{"description":"Free-text search over path, user ID, email, client IP, and status.","in":"query","name":"search","required":false,"schema":{"type":"string"}},{"description":"Additional user IDs to OR into free-text search.","explode":false,"in":"query","name":"search_user_id","required":false,"schema":{"items":{"type":"string"},"maxItems":100,"type":"array"},"style":"form"},{"description":"Opaque cursor from X-Next-Cursor for the next chunk of older records.","in":"query","name":"cursor","required":false,"schema":{"type":"string"}},{"description":"Maximum number of records to return in this chunk.","in":"query","name":"limit","required":false,"schema":{"default":50000,"maximum":50000,"minimum":1,"type":"integer"}},{"description":"Encoding for the returned chunk.","in":"query","name":"format","required":false,"schema":{"default":"jsonl.gz","enum":["jsonl","jsonl.gz"],"type":"string"}}],"responses":{"200":{"content":{"application/octet-stream":{"schema":{"format":"binary","type":"string"}}},"description":"One chunk of audit log records.","headers":{"X-Content-Sha256":{"description":"Hex SHA-256 of the response body.","schema":{"pattern":"^[a-f0-9]{64}$","type":"string"}},"X-Has-More":{"description":"Whether more records remain beyond this chunk.","schema":{"default":false,"type":"boolean"}},"X-Next-Cursor":{"description":"Cursor for the next chunk of older records, empty when no more results.","schema":{"type":"string"}},"X-Row-Count":{"description":"Number of records in this chunk.","schema":{"maximum":50000,"minimum":0,"type":"integer"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Download an audit-log export chunk","tags":["Audit Logs"]}},"/audit-logs/export/destinations":{"get":{"description":"List audit log export destinations for the organization with pagination support.","operationId":"getAuditLogExportDestinations","parameters":[{"description":"Limit the number of destinations to return.","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"description":"Offset the number of destinations to return.","in":"query","name":"offset","required":false,"schema":{"default":0,"minimum":0,"type":"integer"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/AuditLogExportDestination"},"type":"array"}}},"description":"Audit log export destinations for the organization","headers":{"X-Has-More":{"description":"Whether there are more destinations to fetch.","schema":{"default":false,"type":"boolean"}},"X-Limit":{"description":"Limit the number of destinations to return.","schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"nullable":true,"type":"integer"}},"X-Offset":{"description":"The offset of destinations to return.","schema":{"default":0,"minimum":0,"type":"integer"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List audit log export destinations","tags":["Audit Logs"]},"post":{"description":"Create a paused destination. Activate it with a status update once the destination test passes. Requires an active Enterprise plan.","operationId":"postAuditLogExportDestinations","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateAuditLogExportDestinationRequest"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/AuditLogExportDestination"}}},"description":"Audit log export destination created"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Create an audit log export destination","tags":["Audit Logs"]}},"/audit-logs/export/destinations/{id}":{"delete":{"description":"Soft delete the destination and prevent new delivery attempts. An S3 upload already in progress may complete after the response.","operationId":"deleteAuditLogExportDestinationsById","responses":{"204":{"description":"Audit log export destination deleted"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete an audit log export destination","tags":["Audit Logs"]},"get":{"description":"Retrieve details for a single audit log export destination by its ID.","operationId":"getAuditLogExportDestinationsById","responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/AuditLogExportDestination"}}},"description":"Audit log export destination"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Retrieve an audit log export destination","tags":["Audit Logs"]},"parameters":[{"in":"path","name":"id","required":true,"schema":{"maxLength":128,"type":"string"}}],"patch":{"description":"Apply a partial update to a destination. Requires an active Enterprise plan. Returns 409 when the destination was changed concurrently, because the merged configuration this request validated is no longer the one that would be stored; retry against fresh state. Pausing prevents new delivery attempts, but an S3 upload already in progress may complete after the response.","operationId":"patchAuditLogExportDestinationsById","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/UpdateAuditLogExportDestinationRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/AuditLogExportDestination"}}},"description":"Audit log export destination updated"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update an audit log export destination","tags":["Audit Logs"]}},"/audit-logs/export/destinations/{id}/test":{"post":{"description":"Verify the destination is writable by assuming the configured role and uploading a temporary probe object with the same request metadata as a real delivery. Requires an active Enterprise plan.","operationId":"testAuditLogExportDestinationById","parameters":[{"in":"path","name":"id","required":true,"schema":{"maxLength":128,"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/AuditLogExportDestinationTestResult"}}},"description":"Audit log export destination test result"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Test an audit log export destination","tags":["Audit Logs"]}},"/auth/connections":{"get":{"description":"List auth connections with optional filters for profile_name and domain.","operationId":"getAuthConnections","parameters":[{"description":"Filter by profile name","in":"query","name":"profile_name","required":false,"schema":{"type":"string"}},{"description":"Filter by domain","in":"query","name":"domain","required":false,"schema":{"type":"string"}},{"description":"Maximum number of results to return","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"type":"integer"}},{"description":"Number of results to skip","in":"query","name":"offset","required":false,"schema":{"default":0,"type":"integer"}},{"description":"Search auth connections by ID, domain, or profile name.","in":"query","name":"query","required":false,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/ManagedAuth"},"type":"array"}}},"description":"List of auth connections","headers":{"X-Has-More":{"description":"Whether there are more results","schema":{"type":"boolean"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"type":"integer"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List auth connections","tags":["Managed Auth"]},"post":{"description":"Creates an auth connection for a profile and domain combination. If the provided profile_name does not exist, it is created automatically. Returns 409 Conflict if an auth connection already exists for the given profile and domain.","operationId":"postAuthConnections","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ManagedAuthCreateRequest"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ManagedAuth"}}},"description":"Auth connection created"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"409":{"content":{"application/json":{"schema":{"properties":{"code":{"example":"already_exists","type":"string"},"existing_id":{"description":"ID of the existing auth connection","type":"string"},"message":{"example":"Auth connection already exists for this profile and domain","type":"string"}},"required":["code","message","existing_id"],"type":"object"}}},"description":"Auth connection already exists for this profile and domain"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Create auth connection","tags":["Managed Auth"]}},"/auth/connections/{id}":{"delete":{"description":"Deletes an auth connection and terminates its workflow. This will:\n- Delete the auth connection record\n- Terminate the Temporal workflow\n- Cancel any in-progress login flows\n","operationId":"deleteAuthConnectionsById","parameters":[{"description":"Auth connection ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"Auth connection deleted successfully"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete auth connection","tags":["Managed Auth"]},"get":{"description":"Retrieve an auth connection by its ID. Includes current flow state if a login is in progress.","operationId":"getAuthConnectionsById","parameters":[{"description":"Auth connection ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ManagedAuth"}}},"description":"Auth connection details"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get auth connection","tags":["Managed Auth"]},"patch":{"description":"Update an auth connection's configuration. Only the fields provided will be updated.","operationId":"patchAuthConnectionsById","parameters":[{"description":"Auth connection ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ManagedAuthUpdateRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ManagedAuth"}}},"description":"Auth connection updated successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update auth connection","tags":["Managed Auth"]}},"/auth/connections/{id}/events":{"get":{"description":"Establishes a Server-Sent Events (SSE) stream that delivers real-time\nlogin flow state updates. The stream terminates automatically once\nthe flow reaches a terminal state (SUCCESS, FAILED, EXPIRED, CANCELED).\n","operationId":"getAuthConnectionsEventsById","parameters":[{"description":"The auth connection ID to follow.","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"text/event-stream":{"schema":{"$ref":"#/components/schemas/ManagedAuthEvent"}}},"description":"SSE stream of auth connection state updates.","headers":{"X-SSE-Content-Type":{"description":"Media type of SSE data events (always application/json).","schema":{"const":"application/json","type":"string"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Stream login flow events via SSE","tags":["Managed Auth"]}},"/auth/connections/{id}/exchange":{"post":{"description":"Validates the handoff code and returns a JWT token for subsequent requests. Used by the hosted login UI.","operationId":"postAuthConnectionsExchange","parameters":[{"description":"Auth connection ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ManagedAuthExchangeRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ManagedAuthExchangeResponse"}}},"description":"Exchange successful, JWT returned"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"410":{"$ref":"#/components/responses/Gone"},"500":{"$ref":"#/components/responses/InternalError"}},"summary":"Exchange handoff code for JWT","tags":["Managed Auth"],"x-cli-skip":true,"x-hidden":true,"x-stainless-skip":true}},"/auth/connections/{id}/login":{"post":{"description":"Starts a login flow for the auth connection. Returns immediately with a hosted URL for the user to complete authentication, or triggers automatic re-auth if credentials are stored.","operationId":"postAuthConnectionsLogin","parameters":[{"description":"Auth connection ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/LoginRequest"}}},"required":false},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/LoginResponse"}}},"description":"Login flow started"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Login flow already in progress"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Start login flow","tags":["Managed Auth"]}},"/auth/connections/{id}/submit":{"post":{"description":"Submits field values for the login form. Poll the auth connection to track progress and get results.","operationId":"postAuthConnectionsSubmit","parameters":[{"description":"Auth connection ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/SubmitFieldsRequest"}}},"required":true},"responses":{"202":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/SubmitFieldsResponse"}}},"description":"Submission accepted for processing"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"422":{"$ref":"#/components/responses/BadRequest"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Submit field values","tags":["Managed Auth"]}},"/auth/connections/{id}/timeline":{"get":{"description":"Returns a chronological timeline of events for an auth connection —\nlogin attempts, automatic re-auth attempts, and health checks. Events\nare returned newest-first.\n","operationId":"getAuthConnectionsTimelineById","parameters":[{"description":"Auth connection ID","in":"path","name":"id","required":true,"schema":{"type":"string"}},{"description":"Filter the timeline to a single event type.","in":"query","name":"type","required":false,"schema":{"enum":["login","reauth","health_check"],"type":"string"}},{"description":"Maximum number of events to return","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"type":"integer"}},{"description":"Number of events to skip","in":"query","name":"offset","required":false,"schema":{"default":0,"type":"integer"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/ManagedAuthTimelineEvent"},"type":"array"}}},"description":"Event timeline for the auth connection","headers":{"X-Has-More":{"description":"Whether there are more results","schema":{"type":"boolean"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"type":"integer"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get auth connection event timeline","tags":["Managed Auth"]}},"/auth/context":{"get":{"description":"Returns the authenticated principal, organization, credential scope, and effective request scope. The response is derived from the verified request context and does not expose credential secrets.","operationId":"getAuthContext","responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/AuthContext"}}},"description":"Authentication context for the current request","headers":{"Cache-Control":{"schema":{"example":"private, no-store","type":"string"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get authentication context","tags":["Authentication"]}},"/browser_pools":{"get":{"description":"List browser pools in the resolved project.","operationId":"getBrowserPools","parameters":[{"description":"Limit the number of browser pools to return.","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"description":"Offset the number of browser pools to return.","in":"query","name":"offset","required":false,"schema":{"default":0,"minimum":0,"type":"integer"}},{"description":"Case-insensitive substring match against browser pool name. IDs match by exact value.","in":"query","name":"query","required":false,"schema":{"type":"string"}},{"description":"Exact-match filter on browser pool name using the database collation. In production, matching is case- and accent-insensitive. During the default-project migration, unscoped requests prefer a concrete default-project browser pool over a legacy unscoped browser pool with the same name.","in":"query","name":"name","required":false,"schema":{"type":"string"}},{"description":"Filter pools by geographic region. Omit to list pools in all regions.","in":"query","name":"region","required":false,"schema":{"$ref":"#/components/schemas/Region"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/BrowserPool"},"type":"array"}}},"description":"List of browser pools","headers":{"X-Has-More":{"description":"Whether there are more browser pools to fetch.","schema":{"default":false,"type":"boolean"}},"X-Limit":{"description":"Limit the number of browser pools to return.","schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"nullable":true,"type":"integer"}},"X-Offset":{"description":"The offset of browser pools to return.","schema":{"default":0,"minimum":0,"type":"integer"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List browser pools","tags":["Browser Pools"]},"post":{"description":"Create a new browser pool with the specified configuration and size.\nPooled browsers load their profile read-only: any save_changes on the profile is ignored\n(not rejected), so pooled browsers never persist changes back to the profile.\n","operationId":"postBrowserPools","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserPoolCreateRequest"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserPool"}}},"description":"Browser pool created successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"409":{"$ref":"#/components/responses/Conflict"},"429":{"$ref":"#/components/responses/TooManyRequests"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Create a browser pool","tags":["Browser Pools"]}},"/browser_pools/{id_or_name}":{"delete":{"description":"Delete a browser pool and all browsers in it. By default, deletion is blocked if browsers are currently leased. Use force=true to terminate leased browsers.","operationId":"deleteBrowserPoolsByIdOrName","parameters":[{"description":"Browser pool ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserPoolDeleteRequest"}}},"required":false},"responses":{"204":{"description":"Browser pool deleted successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete a browser pool","tags":["Browser Pools"]},"get":{"description":"Retrieve details for a single browser pool by its ID or name.","operationId":"getBrowserPoolsByIdOrName","parameters":[{"description":"Browser pool ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserPool"}}},"description":"Browser pool details"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get browser pool details","tags":["Browser Pools"]},"patch":{"description":"Updates the configuration used to create browsers in the pool.\nAs with creation, save_changes on the pool profile is ignored (not rejected); pooled\nbrowsers never persist changes back to the profile.\nTo clear the profile reference, send `profile: { \"id\": \"\" }`. Clearing the profile\nalso disables `refresh_on_profile_update`.\n","operationId":"updateBrowserPoolsByIdOrName","parameters":[{"description":"Browser pool ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserPoolUpdateRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserPool"}}},"description":"Browser pool details"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"429":{"$ref":"#/components/responses/TooManyRequests"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update a browser pool","tags":["Browser Pools"]}},"/browser_pools/{id_or_name}/acquire":{"post":{"description":"Long-polling endpoint to acquire a browser from the pool. Returns immediately when a browser\nis available, or returns 204 No Content when the poll times out. The client should retry\nthe request to continue waiting for a browser. The acquired browser will use the pool's\ntimeout_seconds for its idle timeout.\n","operationId":"acquireFromBrowserPoolByIdOrName","parameters":[{"description":"Browser pool ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserPoolAcquireRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Browser"}}},"description":"Browser acquired successfully"},"204":{"description":"Poll timed out, no browser available. Retry the request to continue waiting."},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Acquire a browser from the pool","tags":["Browser Pools"]}},"/browser_pools/{id_or_name}/flush":{"post":{"description":"Destroys all idle browsers in the pool; leased browsers are not affected.","operationId":"flushBrowserPoolByIdOrName","parameters":[{"description":"Browser pool ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"Pool flushed successfully"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Flush all idle browsers in the pool","tags":["Browser Pools"]}},"/browser_pools/{id_or_name}/release":{"post":{"description":"Release a browser back to the pool, optionally recreating the browser instance.","operationId":"releaseToBrowserPoolByIdOrName","parameters":[{"description":"Browser pool ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserPoolReleaseRequest"}}},"required":true},"responses":{"204":{"description":"Browser released successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Release a browser back to the pool","tags":["Browser Pools"]}},"/browsers":{"get":{"description":"List all browser sessions with pagination support. Use status parameter to filter by session state.","operationId":"getBrowsers","parameters":[{"description":"Filter sessions by status. \"active\" returns only active sessions (default), \"deleted\" returns only soft-deleted sessions, \"all\" returns both.","in":"query","name":"status","required":false,"schema":{"default":"active","enum":["active","deleted","all"],"type":"string","x-enum-varnames":["GetBrowsersParamsStatusActive","GetBrowsersParamsStatusDeleted","GetBrowsersParamsStatusAll"]}},{"deprecated":true,"description":"Deprecated: Use status=all instead. When true, includes soft-deleted browser sessions in the results alongside active sessions.","in":"query","name":"include_deleted","required":false,"schema":{"default":false,"type":"boolean"}},{"description":"Maximum number of results to return. Defaults to 20, maximum 100.","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"description":"Number of results to skip. Defaults to 0.","in":"query","name":"offset","required":false,"schema":{"default":0,"minimum":0,"type":"integer"}},{"description":"Search browsers by name, session ID, profile name or ID, proxy ID, or pool name.","in":"query","name":"query","required":false,"schema":{"type":"string"}},{"description":"Filter sessions by tag key-value pairs using deepObject style, e.g. ?tags[team]=backend\u0026tags[env]=staging. Multiple pairs are ANDed: a session must match every supplied pair exactly.\n","explode":true,"in":"query","name":"tags","required":false,"schema":{"additionalProperties":{"type":"string"},"type":"object"},"style":"deepObject"},{"description":"Filter sessions by geographic region. Omit to list sessions in all regions.","in":"query","name":"region","required":false,"schema":{"$ref":"#/components/schemas/Region"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/Browser"},"type":"array"}}},"description":"List of browsers","headers":{"X-Has-More":{"description":"Whether more results are available","schema":{"type":"boolean"}},"X-Limit":{"description":"The limit used for pagination","schema":{"type":"integer"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"type":"integer"}},"X-Offset":{"description":"The offset used for pagination","schema":{"type":"integer"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List browser sessions","tags":["Browsers"]},"post":{"description":"Create a new browser session from within an action.","operationId":"postBrowsers","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserRequest"}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Browser"}}},"description":"Successful response"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"409":{"$ref":"#/components/responses/Conflict"},"429":{"$ref":"#/components/responses/TooManyRequests"},"500":{"$ref":"#/components/responses/InternalError"},"529":{"$ref":"#/components/responses/CapacityExhausted"}},"security":[{"bearerAuth":[]}],"summary":"Create a browser session","tags":["Browsers"]}},"/browsers/{id_or_name}":{"delete":{"description":"Delete a browser session by ID or name","operationId":"deleteBrowsersByIdOrName","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"Browser session deleted successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete a browser session by ID or name.","tags":["Browsers"]},"get":{"description":"Get information about a browser session.","operationId":"getBrowsersByIdOrName","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"description":"When true, includes soft-deleted browser sessions in the lookup.","in":"query","name":"include_deleted","required":false,"schema":{"default":false,"type":"boolean"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Browser"}}},"description":"Browser session retrieved successfully"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get browser session details","tags":["Browsers"]},"patch":{"description":"Update a browser session.","operationId":"patchBrowsersByIdOrName","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserUpdateRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Browser"}}},"description":"Browser session updated successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update browser session","tags":["Browsers"]}},"/browsers/{id_or_name}/computer/batch":{"post":{"description":"Send an array of computer actions to execute in order on the browser instance.\nExecution stops on the first error. This reduces network latency compared to\nsending individual action requests.\n","operationId":"batchComputerAction","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BatchComputerActionRequest"}}},"required":true},"responses":{"200":{"description":"All actions executed successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Execute a batch of computer actions sequentially","tags":["Browser Computer Controls"]}},"/browsers/{id_or_name}/computer/click_mouse":{"post":{"operationId":"clickMouse","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ClickMouseRequest"}}},"required":true},"responses":{"200":{"description":"Mouse action performed"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Simulate a mouse click action on the browser instance","tags":["Browser Computer Controls"]}},"/browsers/{id_or_name}/computer/clipboard/read":{"post":{"operationId":"readClipboard","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ClipboardContent"}}},"description":"Clipboard content read successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Read text from the clipboard on the browser instance","tags":["Browser Computer Controls"]}},"/browsers/{id_or_name}/computer/clipboard/write":{"post":{"operationId":"writeClipboard","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/WriteClipboardRequest"}}},"required":true},"responses":{"200":{"description":"Text written to clipboard successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Write text to the clipboard on the browser instance","tags":["Browser Computer Controls"]}},"/browsers/{id_or_name}/computer/cursor":{"post":{"operationId":"setCursor","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/SetCursorRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/OkResponse"}}},"description":"Cursor visibility set"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Set cursor visibility","tags":["Browser Computer Controls"]}},"/browsers/{id_or_name}/computer/drag_mouse":{"post":{"operationId":"dragMouse","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/DragMouseRequest"}}},"required":true},"responses":{"200":{"description":"Drag performed"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Drag the mouse along a path","tags":["Browser Computer Controls"]}},"/browsers/{id_or_name}/computer/get_mouse_position":{"post":{"operationId":"getMousePosition","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/MousePositionResponse"}}},"description":"Current mouse position"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Get the current mouse cursor position on the browser instance","tags":["Browser Computer Controls"]}},"/browsers/{id_or_name}/computer/move_mouse":{"post":{"operationId":"moveMouse","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/MoveMouseRequest"}}},"required":true},"responses":{"200":{"description":"Mouse cursor moved"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Move the mouse cursor to the specified coordinates on the browser instance","tags":["Browser Computer Controls"]}},"/browsers/{id_or_name}/computer/press_key":{"post":{"operationId":"pressKey","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/PressKeyRequest"}}},"required":true},"responses":{"200":{"description":"Keys pressed successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Press one or more keys on the host computer","tags":["Browser Computer Controls"]}},"/browsers/{id_or_name}/computer/screenshot":{"post":{"operationId":"takeScreenshot","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ScreenshotRequest"}}},"required":false},"responses":{"200":{"content":{"image/png":{"schema":{"format":"binary","type":"string"}}},"description":"Screenshot image"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Capture a screenshot of the browser instance","tags":["Browser Computer Controls"]}},"/browsers/{id_or_name}/computer/scroll":{"post":{"operationId":"scroll","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ScrollRequest"}}},"required":true},"responses":{"200":{"description":"Scroll performed"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Scroll the mouse wheel at a position on the host computer","tags":["Browser Computer Controls"]}},"/browsers/{id_or_name}/computer/type":{"post":{"operationId":"typeText","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/TypeTextRequest"}}},"required":true},"responses":{"200":{"description":"Text typed successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Type text on the browser instance","tags":["Browser Computer Controls"]}},"/browsers/{id_or_name}/curl":{"post":{"description":"Sends an HTTP request through Chrome's HTTP request stack, inheriting\nthe browser's TLS fingerprint, cookies, proxy configuration, and headers.\nReturns a structured JSON response with status, headers, body, and timing.\n","operationId":"browserCurl","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserCurlRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserCurlResult"}}},"description":"Response from target URL"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"502":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserCurlTransportError"}}},"description":"Upstream transport failure"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Make an HTTP request through the browser's network stack","tags":["Browsers"]}},"/browsers/{id_or_name}/extensions":{"post":{"description":"Loads one or more unpacked extensions using live CDP activation when eligible. Chromium restarts when enterprise policy requires it or live activation fails.","operationId":"uploadExtensionsToBrowser","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"multipart/form-data":{"schema":{"properties":{"extensions":{"description":"List of extensions to upload and activate","items":{"properties":{"name":{"description":"Folder name to place the extension under /home/kernel/extensions/\u003cname\u003e","maxLength":255,"minLength":1,"pattern":"^[a-zA-Z0-9._-]{1,255}$","type":"string"},"zip_file":{"description":"Zip archive containing an unpacked Chromium extension (must include manifest.json)","format":"binary","type":"string"}},"required":["zip_file","name"],"type":"object"},"type":"array"}},"required":["extensions"],"type":"object"}}},"required":true},"responses":{"201":{"description":"Extensions uploaded, Chromium restarted, and DevTools is ready"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Ad-hoc upload one or more unpacked extensions to a running browser instance.","tags":["Browsers"]}},"/browsers/{id_or_name}/fs/create_directory":{"put":{"operationId":"createDirectory","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateDirectoryRequest"}}},"required":true},"responses":{"201":{"description":"Directory created successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Create a new directory","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/fs/delete_directory":{"put":{"operationId":"deleteDirectory","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/DeletePathRequest"}}},"required":true},"responses":{"200":{"description":"Directory deleted"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Delete a directory","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/fs/delete_file":{"put":{"operationId":"deleteFile","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/DeletePathRequest"}}},"required":true},"responses":{"200":{"description":"File deleted"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Delete a file","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/fs/download_dir_zip":{"get":{"description":"Returns a ZIP file containing the contents of the specified directory.","operationId":"downloadDirZip","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"description":"Absolute directory path to archive and download.","in":"query","name":"path","required":true,"schema":{"pattern":"^/.*","type":"string"}}],"responses":{"200":{"content":{"application/zip":{"schema":{"format":"binary","type":"string"}}},"description":"ZIP archive of the requested directory"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Download a directory as a ZIP archive","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/fs/file_info":{"get":{"operationId":"fileInfo","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"description":"Absolute path of the file or directory.","in":"query","name":"path","required":true,"schema":{"pattern":"^/.*","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/FileInfo"}}},"description":"File information"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Get information about a file or directory","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/fs/list_files":{"get":{"operationId":"listFiles","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"description":"Absolute directory path.","in":"query","name":"path","required":true,"schema":{"pattern":"^/.*","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ListFiles"}}},"description":"Directory listing"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"List files in a directory","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/fs/move":{"put":{"operationId":"movePath","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/MovePathRequest"}}},"required":true},"responses":{"200":{"description":"Move successful"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Move or rename a file or directory","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/fs/read_file":{"get":{"operationId":"readFile","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"description":"Absolute file path to read.","in":"query","name":"path","required":true,"schema":{"pattern":"^/.*","type":"string"}}],"responses":{"200":{"content":{"application/octet-stream":{"schema":{"format":"binary","type":"string"}}},"description":"File read successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Read file contents","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/fs/set_file_permissions":{"put":{"operationId":"setFilePermissions","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/SetFilePermissionsRequest"}}},"required":true},"responses":{"200":{"description":"Permissions updated"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Set file or directory permissions/ownership","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/fs/upload":{"post":{"description":"Allows uploading single or multiple files to the remote filesystem.","operationId":"uploadFiles","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"multipart/form-data":{"schema":{"properties":{"files":{"items":{"properties":{"dest_path":{"description":"Absolute destination path to write the file.","pattern":"^/.*","type":"string"},"file":{"format":"binary","type":"string"}},"required":["file","dest_path"],"type":"object"},"type":"array"}},"required":["files"],"type":"object"}}},"required":true},"responses":{"201":{"description":"Files uploaded successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Upload one or more files","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/fs/upload_zip":{"post":{"description":"Upload a zip file and extract its contents to the specified destination path.","operationId":"uploadZip","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"multipart/form-data":{"schema":{"properties":{"dest_path":{"description":"Absolute destination directory to extract the archive to.","pattern":"^/.*","type":"string"},"zip_file":{"format":"binary","type":"string"}},"required":["zip_file","dest_path"],"type":"object"}}},"required":true},"responses":{"201":{"description":"Zip uploaded and extracted successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Upload a zip archive and extract it","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/fs/watch":{"post":{"operationId":"startFsWatch","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/StartFsWatchRequest"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"properties":{"watch_id":{"description":"Unique identifier for the directory watch","type":"string"}},"type":"object"}}},"description":"Watch started successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Watch a directory for changes","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/fs/watch/{watch_id}":{"delete":{"operationId":"stopFsWatch","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"in":"path","name":"watch_id","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"Watch stopped successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Stop watching a directory","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/fs/watch/{watch_id}/events":{"get":{"operationId":"streamFsEvents","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"in":"path","name":"watch_id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"text/event-stream":{"schema":{"$ref":"#/components/schemas/FileSystemEvent"}}},"description":"SSE stream of filesystem events","headers":{"X-SSE-Content-Type":{"description":"Media type of SSE data events (application/json)","schema":{"const":"application/json","type":"string"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Stream filesystem events for a watch","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/fs/write_file":{"put":{"operationId":"writeFile","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"description":"Destination absolute file path.","in":"query","name":"path","required":true,"schema":{"pattern":"^/.*","type":"string"}},{"description":"Optional file mode (octal string, e.g. 644). Defaults to 644.","in":"query","name":"mode","required":false,"schema":{"pattern":"^[0-7]{3,4}$","type":"string"}}],"requestBody":{"content":{"application/octet-stream":{"schema":{"format":"binary","type":"string"}}},"required":true},"responses":{"201":{"description":"File written successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Write or create a file","tags":["Browser Filesystem"]}},"/browsers/{id_or_name}/logs/stream":{"get":{"operationId":"logsStream","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"in":"query","name":"source","required":true,"schema":{"enum":["path","supervisor"],"type":"string"}},{"in":"query","name":"follow","required":false,"schema":{"default":true,"type":"boolean"}},{"description":"only required if source is path","in":"query","name":"path","required":false,"schema":{"type":"string"}},{"description":"only required if source is supervisor","in":"query","name":"supervisor_process","required":false,"schema":{"type":"string"}}],"responses":{"200":{"content":{"text/event-stream":{"schema":{"$ref":"#/components/schemas/LogEvent"}}},"description":"SSE stream of logs","headers":{"X-SSE-Content-Type":{"description":"Media type of SSE data events (application/json)","schema":{"const":"application/json","type":"string"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Stream log files on the browser instance via SSE","tags":["Browser Logs"]}},"/browsers/{id_or_name}/playwright/execute":{"post":{"description":"Execute arbitrary Playwright code in a fresh execution context against the browser.\nThe code runs in the same VM as the browser, minimizing latency and maximizing throughput.\nIt has access to 'page', 'context', 'browser', and 'webmcp' variables.\nUse 'webmcp.listTools()' to discover browser-wide WebMCP tools and\n'webmcp.invokeTool(toolRef, input?, { timeoutSec? })' to invoke an exact registration.\nIt can `return` a value, and this value is returned in the response.\n","operationId":"executePlaywrightCode","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ExecutePlaywrightRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ExecutePlaywrightResult"}}},"description":"Code executed successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Execute Playwright/TypeScript code against the browser","tags":["Browser Playwright"]}},"/browsers/{id_or_name}/process/exec":{"post":{"operationId":"processExec","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProcessExecRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProcessExecResult"}}},"description":"Execution result"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Execute a command synchronously","tags":["Browser Processes"]}},"/browsers/{id_or_name}/process/spawn":{"post":{"operationId":"processSpawn","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProcessSpawnRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProcessSpawnResult"}}},"description":"Spawned"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Execute a command asynchronously","tags":["Browser Processes"]}},"/browsers/{id_or_name}/process/{process_id}/kill":{"post":{"operationId":"processKill","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"in":"path","name":"process_id","required":true,"schema":{"format":"uuid","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProcessKillRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/OkResponse"}}},"description":"OK"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Send signal to process","tags":["Browser Processes"]}},"/browsers/{id_or_name}/process/{process_id}/resize":{"post":{"operationId":"processResize","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"in":"path","name":"process_id","required":true,"schema":{"format":"uuid","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProcessResizeRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/OkResponse"}}},"description":"OK"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Resize a PTY-backed process terminal","tags":["Browser Processes"]}},"/browsers/{id_or_name}/process/{process_id}/status":{"get":{"operationId":"processStatus","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"in":"path","name":"process_id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProcessStatus"}}},"description":"Status"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Get process status","tags":["Browser Processes"]}},"/browsers/{id_or_name}/process/{process_id}/stdin":{"post":{"operationId":"processStdin","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"in":"path","name":"process_id","required":true,"schema":{"format":"uuid","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProcessStdinRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProcessStdinResult"}}},"description":"Bytes written"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Write to process stdin","tags":["Browser Processes"]}},"/browsers/{id_or_name}/process/{process_id}/stdout/stream":{"get":{"operationId":"processStdoutStream","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"in":"path","name":"process_id","required":true,"schema":{"format":"uuid","type":"string"}}],"responses":{"200":{"content":{"text/event-stream":{"schema":{"$ref":"#/components/schemas/ProcessStreamEvent"}}},"description":"SSE stream of process output and lifecycle events","headers":{"X-SSE-Content-Type":{"description":"Media type of SSE data events (application/json)","schema":{"const":"application/json","type":"string"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Stream process stdout via SSE","tags":["Browser Processes"]}},"/browsers/{id_or_name}/repl":{"post":{"description":"Execute JavaScript in a persistent Node.js runtime inside the browser VM.\nTop-level bindings, closures, mutations, and dynamically imported modules persist\nacross calls until the REPL is reset or replaced. Start with `repl.help()` to list\navailable methods, or call `repl.help(\"click\")` for detailed help.\n\nExpression values are ignored. Emit ordered text or image output with\n`repl.write(...)`, console methods, or `repl.emitImage(...)`. The runtime also\nexposes browser-control helpers, WebMCP, Patchright, Playwright, and raw CDP.\n\nExecutions are serialized. A timeout, crash, OOM, or protocol failure terminates\nthe REPL and changes its `repl_id`. This is unrestricted code execution inside the\nbrowser VM and is not sandboxed.\n","operationId":"executeBrowserRepl","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserReplRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserReplResult"}}},"description":"Code executed with either a successful result or a structured JavaScript failure."},"400":{"$ref":"#/components/responses/BadRequest"},"413":{"$ref":"#/components/responses/BadRequest"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Execute JavaScript in the persistent Browser REPL","tags":["Browser REPL"]}},"/browsers/{id_or_name}/replays":{"get":{"description":"List all replays for the specified browser session.","operationId":"listBrowsersReplays","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/BrowserReplay"},"type":"array"}}},"description":"List of replays retrieved successfully."},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List browser session replays","tags":["Browser Replays"]},"post":{"description":"Start recording the browser session and return a replay ID.","operationId":"startBrowserReplayRecording","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"properties":{"framerate":{"description":"Recording framerate in fps. Values above 20 require GPU to be enabled on the browser session.","maximum":60,"minimum":1,"type":"integer"},"max_duration_in_seconds":{"description":"Maximum recording duration in seconds.","minimum":1,"type":"integer"},"record_audio":{"default":false,"description":"Record audio in addition to video. When false (the default), the recording is video-only.","type":"boolean"}},"type":"object"}}},"required":false},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BrowserReplay"}}},"description":"Recording started successfully."},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Start a browser session replay recording","tags":["Browser Replays"]}},"/browsers/{id_or_name}/replays/{replay_id}":{"get":{"description":"Download or stream the specified replay recording.","operationId":"getBrowsersReplaysById","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"description":"Replay recording identifier","in":"path","name":"replay_id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"video/mp4":{"schema":{"format":"binary","type":"string"}}},"description":"Replay recording retrieved successfully."},"202":{"description":"Replay recording is still in progress, please try again later","headers":{"Retry-After":{"description":"Suggested wait time in seconds before retrying","schema":{"minimum":1,"type":"integer"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Download a replay recording","tags":["Browser Replays"]}},"/browsers/{id_or_name}/replays/{replay_id}/stop":{"post":{"description":"Stop the specified replay recording and persist the video.","operationId":"stopBrowserReplayRecording","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"description":"Replay recording identifier","in":"path","name":"replay_id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"Recording stopped successfully."},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Stop a browser session replay recording","tags":["Browser Replays"]}},"/browsers/{id_or_name}/telemetry/events":{"get":{"description":"Reads a page of telemetry events for the browser session. To page through results, pass the X-Next-Offset value from the previous response as offset and repeat while X-Has-More is true. The category and type filters apply within each page, so a filtered page may be empty while X-Has-More is true. Returns an empty list when telemetry data is unavailable.\n","operationId":"readBrowserTelemetryEvents","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"description":"Opaque pagination cursor: pass the X-Next-Offset value from the previous response to fetch the next page. When set, paging continues from this cursor and since is ignored, while until still bounds the page. It is not an event's seq field, so do not derive it from the response body.\n","in":"query","name":"offset","required":false,"schema":{"minimum":0,"type":"integer"}},{"description":"Start of the window: an RFC-3339 timestamp, or a duration like 5m meaning that long ago. Defaults to 5m. Ignored when offset is set.\n","in":"query","name":"since","required":false,"schema":{"type":"string"}},{"description":"End of the window (exclusive): an RFC-3339 timestamp, or a duration like 5m meaning that long ago.\n","in":"query","name":"until","required":false,"schema":{"type":"string"}},{"description":"Maximum number of events per page. Defaults to 20.","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"description":"Restrict results to these event categories. Repeat the parameter for multiple values.","in":"query","name":"category","required":false,"schema":{"items":{"enum":["console","network","page","interaction","control","platform","connection","system","screenshot","captcha","monitor"],"type":"string"},"type":"array"}},{"description":"Restrict results to these event types, such as page_crashed or captcha_challenge_result. Repeat the parameter for multiple values. Combines with category: when both are set an event must match both.\n","in":"query","name":"type","required":false,"schema":{"items":{"type":"string"},"type":"array"}},{"description":"Read direction. asc (default) reads oldest first, starting from since or the offset cursor. desc reads newest first: each request returns one page of up to limit records ending at the offset cursor (or until, or the newest archived event); combining desc with since is rejected with a 400.\n","in":"query","name":"order","required":false,"schema":{"default":"asc","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/BrowserTelemetryEventEnvelope"},"type":"array"}}},"description":"A page of telemetry events.","headers":{"X-Has-More":{"description":"Whether more results are available","schema":{"type":"boolean"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"type":"integer"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Read telemetry events for a browser session","tags":["Browser Telemetry"]}},"/browsers/{id_or_name}/telemetry/stream":{"get":{"description":"Streams browser telemetry events as a server-sent events (SSE) stream. The stream closes when the browser session terminates. Each event frame includes an id: field containing a monotonically increasing sequence number; pass it as Last-Event-ID on reconnect to resume without gaps. The event: field is never set; all frames carry JSON in the data: field. A keepalive comment frame is sent every 15 seconds when no events arrive. Returns 404 if the browser session does not exist. If telemetry was not enabled on the session, the stream opens but no events are delivered. Fresh connections only see new events; pass replay=all to start from the oldest retained event instead.\n","operationId":"streamBrowserTelemetry","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"description":"Last event sequence number for SSE reconnection (sent by SSE clients on reconnect). Takes precedence over replay when both are present, so reconnect resumes instead of re-replaying.","in":"header","name":"Last-Event-ID","schema":{"type":"string"}},{"description":"Pass `all` to start from the oldest retained event instead of only new events; any other value is treated as from-now. The buffer is bounded, so the first event id may be greater than 1 if older events were evicted.","in":"query","name":"replay","schema":{"type":"string"}}],"responses":{"200":{"content":{"text/event-stream":{"schema":{"$ref":"#/components/schemas/BrowserTelemetryEventEnvelope"}}},"description":"SSE stream of telemetry events","headers":{"X-SSE-Content-Type":{"description":"Media type of SSE data events (always application/json).","schema":{"const":"application/json","type":"string"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Stream telemetry events via SSE","tags":["Browser Telemetry"]}},"/browsers/{id_or_name}/webmcp/custom-tools":{"get":{"description":"Returns every registered custom tool with its generated ID, namespace, matcher, and MCP tool metadata.","operationId":"listCustomWebMCPTools","responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CustomWebMCPToolsResponse"}}},"description":"Current custom WebMCP tools"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"List custom WebMCP tools","tags":["Browser WebMCP"]},"parameters":[{"description":"Browser session ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"post":{"description":"Add a namespaced batch of custom tools. A custom tool can be page-backed or CDP-backed.\nPage-backed tools execute in the page via JavaScript. CDP-backed tools execute via CDP and\ncan use all browser REPL tools (see `/repl`). The source must evaluate to a non-empty array\nof definitions with URL matchers, tool metadata (including an optional output schema), and\nexecute functions. The batch is added atomically. Matchers apply to top-level documents and\nnested frames, including out-of-process iframes; each matching tool is exposed once on the\ntab's top-level document and appears in the WebMCP tool snapshot.\n\nTo update one tool, list the tools, delete its ID, and add its replacement. Set\nforce_overwrite_namespace to replace every existing tool in the namespace atomically;\nomitted or false adds tools without replacing existing ones. Existing invocations continue.\n","operationId":"addCustomWebMCPTools","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/AddCustomWebMCPToolsRequest"}}},"description":"Source is limited to 8000000 UTF-8 bytes; the raw JSON body is limited to 8000000 bytes plus 4 KiB before decoding.","required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CustomWebMCPToolsResponse"}}},"description":"Custom tools added. Contains only the newly added tools."},"400":{"$ref":"#/components/responses/BadRequest"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Add custom WebMCP tools","tags":["Browser WebMCP"]}},"/browsers/{id_or_name}/webmcp/custom-tools/{id}":{"delete":{"description":"Removes one custom tool by generated ID. An invocation already in progress is not canceled.","operationId":"removeCustomWebMCPTool","parameters":[{"description":"Browser session ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"in":"path","name":"id","required":true,"schema":{"pattern":"^ct_[a-z][a-z0-9]{23}$","type":"string"}}],"responses":{"204":{"description":"Custom tool removed"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Remove a custom WebMCP tool","tags":["Browser WebMCP"]}},"/browsers/{id_or_name}/webmcp/invoke":{"post":{"description":"Invokes the exact live registration identified by tool_ref. Non-autosubmit declarative form\ntools return after their fields are populated with an awaiting_submission status. Other tools\nwait for a terminal result, including across navigation. Inspect a populated form, obtain any\nrequired confirmation, then submit through Playwright or computer interaction without invoking\nthe tool again. If the tab or embedded frame disappears, or the request times out after invocation\nbegins, the response reports outcome_unknown and the tool is not retried.\nCDP-backed custom tool outputs above 240 KiB return an error rather than a truncated result.\n","operationId":"invokeWebMCPTool","parameters":[{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/WebMCPInvokeRequest"}}},"description":"The raw JSON request body is limited to 1 MiB plus 4 KiB of envelope overhead before decoding.","required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/WebMCPInvocationResult"}}},"description":"The populated non-autosubmit form state or the tool's terminal result"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"504":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/WebMCPInvocationFailure"}}},"description":"Invocation began, but its final outcome could not be observed"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Invoke a discovered WebMCP tool","tags":["Browser WebMCP"]}},"/browsers/{id_or_name}/webmcp/tools":{"get":{"description":"Returns a snapshot of native and custom WebMCP tools available across every open tab and\nembedded frame in the browser. Each tool includes an opaque tool_ref for invoking that exact\nlive registration, nested tool metadata, and source information. Custom tools include their\ngenerated ID, namespace, and CDP target_id in source. Tools disappear when their document\ncloses or navigates away. Use exclude_custom to return only page-provided tools.\n","operationId":"listWebMCPTools","parameters":[{"description":"Exclude custom tools when true.","in":"query","name":"exclude_custom","required":false,"schema":{"default":false,"type":"boolean"}},{"description":"Browser session ID or name","example":"htzv5orfit78e1m2biiifpbv","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/WebMCPToolsResponse"}}},"description":"Current browser-wide WebMCP tool snapshot"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"default":{"$ref":"#/components/responses/BrowserProxyError"}},"security":[{"bearerAuth":[]}],"summary":"Discover WebMCP tools across the browser","tags":["Browser WebMCP"]}},"/config-registry":{"get":{"description":"Lists unique exact targets previously analyzed by the selected project with the recommendation produced by each target's latest analysis.","operationId":"getConfigRegistry","parameters":[{"in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"in":"query","name":"offset","required":false,"schema":{"default":0,"minimum":0,"type":"integer"}},{"description":"Case-insensitive substring search over normalized targets, including domain, subdomain, and path.","in":"query","name":"search","required":false,"schema":{"maxLength":2048,"type":"string"}},{"in":"query","name":"sort_by","required":false,"schema":{"default":"last_requested_at","enum":["target","analysis_status","recommended_config","last_requested_at","success_rate"],"type":"string","x-enum-varnames":["ConfigRegistrySortByTarget","ConfigRegistrySortByAnalysisStatus","ConfigRegistrySortByRecommendedConfig","ConfigRegistrySortByLastRequestedAt","ConfigRegistrySortBySuccessRate"]}},{"in":"query","name":"sort_order","required":false,"schema":{"default":"desc","enum":["asc","desc"],"type":"string","x-enum-varnames":["ConfigRegistrySortOrderAsc","ConfigRegistrySortOrderDesc"]}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/ConfigRegistryRecommendationSummary"},"type":"array"}}},"description":"Project-scoped recommended configurations.","headers":{"X-Has-More":{"description":"Whether more results are available.","schema":{"type":"boolean"}},"X-Limit":{"description":"The limit used for pagination.","schema":{"type":"integer"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"type":"integer"}},"X-Offset":{"description":"The offset used for pagination.","schema":{"type":"integer"}},"X-Total-Count":{"description":"Total unique exact targets matching the current project and search.","schema":{"type":"integer"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"summary":"List configs","tags":["Config Registry"],"x-cli-skip":true}},"/config-registry/analyses":{"get":{"description":"Lists analyses for the selected project, newest first.","operationId":"getConfigRegistryAnalyses","parameters":[{"in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"in":"query","name":"offset","required":false,"schema":{"default":0,"minimum":0,"type":"integer"}},{"description":"Case-insensitive substring search over requested URLs.","in":"query","name":"search","required":false,"schema":{"maxLength":2048,"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/ConfigRegistryAnalysisSummary"},"type":"array"}}},"description":"Project-scoped analysis history.","headers":{"X-Has-More":{"description":"Whether more results are available.","schema":{"type":"boolean"}},"X-Limit":{"description":"The limit used for pagination.","schema":{"type":"integer"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"type":"integer"}},"X-Offset":{"description":"The offset used for pagination.","schema":{"type":"integer"}},"X-Total-Count":{"description":"Total analyses matching the current project and search.","schema":{"type":"integer"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"summary":"List config analyses","tags":["Config Registry"],"x-cli-skip":true}},"/config-registry/analyses/{id}":{"get":{"description":"Returns a project-scoped historical analysis and the recommendation outcome concluded by that run. Later knowledge does not change this response.","operationId":"getConfigRegistryAnalysesById","parameters":[{"in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConfigRegistryResponse"}}},"description":"Analysis state and the recommendation outcome concluded by that historical run."},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"summary":"Get a config analysis","tags":["Config Registry"],"x-cli-skip":true}},"/config-registry/analyses/{id}/cancel":{"post":{"description":"Requests cancellation of a running project-scoped analysis. Cancellation is asynchronous; poll the analysis until its status becomes canceled. Repeating the request after the analysis reaches a terminal state returns the existing outcome.","operationId":"postConfigRegistryAnalysesByIdCancel","parameters":[{"in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConfigRegistryResponse"}}},"description":"The analysis had already reached a terminal state."},"202":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConfigRegistryResponse"}}},"description":"Cancellation was requested. Poll the analysis to observe the canceled outcome."},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Cancellation could not be requested."}},"summary":"Cancel a config analysis","tags":["Config Registry"],"x-cli-skip":true}},"/config-registry/lookup":{"post":{"description":"Returns current global knowledge without resolving DNS, creating an analysis, or updating config registry data.","operationId":"postConfigRegistryLookup","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConfigRegistryLookupRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConfigRegistryLookupResponse"}}},"description":"Current recommendation, or a null recommendation when no eligible knowledge exists."},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"summary":"Look up a config","tags":["Config Registry"],"x-cli-skip":true}},"/config-registry/resolve":{"post":{"description":"Explicitly starts or retries a project-scoped background analysis while preserving current global knowledge when available. Use `/config-registry/lookup` for side-effect-free reads.","operationId":"postConfigRegistryResolve","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConfigRegistryResolveRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConfigRegistryResponse"}}},"description":"Current recommendation returned. Analysis is null if DNS validation or workflow submission prevented the requested refresh."},"202":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConfigRegistryResponse"}}},"description":"Analysis is running without a current recommendation."},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConfigRegistryAnalysisInProgressError"}}},"description":"An analysis for this target is already running with a different workload intent. Poll the returned analysis ID and retry once it reaches a terminal status."},"429":{"$ref":"#/components/responses/TooManyRequests"},"500":{"$ref":"#/components/responses/InternalError"},"503":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Analysis could not be submitted."}},"summary":"Resolve a config","tags":["Config Registry"],"x-cli-skip":true}},"/credentials":{"get":{"description":"List credentials in the resolved project. Credential values are not returned.","operationId":"getCredentials","parameters":[{"description":"Filter by domain","in":"query","name":"domain","required":false,"schema":{"type":"string"}},{"description":"Maximum number of results to return","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"type":"integer"}},{"description":"Number of results to skip","in":"query","name":"offset","required":false,"schema":{"default":0,"type":"integer"}},{"description":"Case-insensitive substring match against credential name or domain. IDs match by exact value.","in":"query","name":"query","required":false,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/Credential"},"type":"array"}}},"description":"List of credentials","headers":{"X-Has-More":{"description":"Whether there are more results","schema":{"type":"boolean"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"type":"integer"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List credentials","tags":["Credentials"],"x-hidden":true},"post":{"description":"Create a new credential for storing login information.","operationId":"postCredentials","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateCredentialRequest"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Credential"}}},"description":"Credential created successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Create a credential","tags":["Credentials"],"x-hidden":true}},"/credentials/{id_or_name}":{"delete":{"description":"Delete a credential by its ID or name.","operationId":"deleteCredentialByIdOrName","parameters":[{"description":"Credential ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"Credential deleted successfully"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete credential","tags":["Credentials"],"x-hidden":true},"get":{"description":"Retrieve a credential by its ID or name. Credential values are not returned.","operationId":"getCredentialByIdOrName","parameters":[{"description":"Credential ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Credential"}}},"description":"Credential details"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get credential by ID or name","tags":["Credentials"],"x-hidden":true},"patch":{"description":"Update a credential's name or values. When values are provided, they are merged with existing values (new keys are added, existing keys are overwritten).","operationId":"patchCredentialByIdOrName","parameters":[{"description":"Credential ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/UpdateCredentialRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Credential"}}},"description":"Credential updated successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update credential","tags":["Credentials"],"x-hidden":true}},"/credentials/{id_or_name}/totp-code":{"get":{"description":"Returns the current 6-digit TOTP code for a credential with a configured totp_secret. Use this to complete 2FA setup on sites or when you need a fresh code.","operationId":"getCredentialTotpCodeByIdOrName","parameters":[{"description":"Credential ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"code":{"description":"Current 6-digit TOTP code","example":"847291","type":"string"},"expires_at":{"description":"When this code expires (ISO 8601 timestamp)","example":"2025-01-15T10:30:30Z","format":"date-time","type":"string"}},"required":["code","expires_at"],"type":"object"}}},"description":"TOTP code generated successfully"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Credential not found or has no TOTP secret configured"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Generate TOTP code","tags":["Credentials"],"x-hidden":true}},"/deployments":{"get":{"description":"List deployments. Optionally filter by application name and version.","operationId":"getDeployments","parameters":[{"description":"Filter results by application name.","in":"query","name":"app_name","required":false,"schema":{"type":"string"}},{"description":"Filter results by application version. Requires app_name to be set.","in":"query","name":"app_version","required":false,"schema":{"type":"string"}},{"description":"Limit the number of deployments to return.","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"description":"Offset the number of deployments to return.","in":"query","name":"offset","required":false,"schema":{"default":0,"minimum":0,"type":"integer"}},{"description":"Search deployments by ID or app name.","in":"query","name":"query","required":false,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/Deployment"},"type":"array"}}},"description":"List of deployments.","headers":{"X-Has-More":{"description":"Whether there are more deployments to fetch.","schema":{"default":false,"type":"boolean"}},"X-Limit":{"description":"Limit the number of deployments to return.","schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"nullable":true,"type":"integer"}},"X-Offset":{"description":"The offset of deployments to return.","schema":{"default":0,"minimum":0,"type":"integer"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List deployments","tags":["Deployments"]},"post":{"description":"Create a new deployment.","operationId":"postDeployments","requestBody":{"content":{"multipart/form-data":{"encoding":{"source":{"contentType":"application/json"}},"examples":{"github_private":{"summary":"Deploy from private GitHub repo","value":{"source":{"auth":{"method":"github_token","token":"ghs_***"},"entrypoint":"index.ts","path":"apps/service","ref":"main","type":"github","url":"https://github.com/org/private-repo"},"version":"latest"}},"github_public":{"summary":"Deploy from GitHub source","value":{"env_vars":{"FOO":"bar"},"force":false,"region":"aws.us-east-1a","source":{"entrypoint":"src/index.ts","path":"apps/api","ref":"main","type":"github","url":"https://github.com/org/repo"},"version":"1.0.0"}},"upload_zip":{"summary":"Upload a ZIP file","value":{"entrypoint_rel_path":"src/app.py","env_vars":{"FOO":"bar"},"file":"\u003cbinary\u003e","force":false,"region":"aws.us-east-1a","version":"1.0.0"}}},"schema":{"$ref":"#/components/schemas/DeploymentRequest"}}},"description":"App deployment data","required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Deployment"}}},"description":"Deployment created successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Create a deployment","tags":["Deployments"]}},"/deployments/{id}":{"delete":{"description":"Stops a running deployment and marks it for deletion. If the deployment is already in a terminal state (stopped or failed), returns immediately.","operationId":"deleteDeploymentsById","parameters":[{"description":"Deployment ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"Deployment deleted successfully"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete a deployment","tags":["Deployments"]},"get":{"description":"Get information about a deployment's status.","operationId":"getDeploymentsById","parameters":[{"description":"Deployment ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Deployment"}}},"description":"Deployment retrieved successfully"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get deployment details","tags":["Deployments"]}},"/deployments/{id}/events":{"get":{"description":"Establishes a Server-Sent Events (SSE) stream that delivers real-time logs and\nstatus updates for a deployment. The stream terminates automatically\nonce the deployment reaches a terminal state.\n","operationId":"getDeploymentsEventsById","parameters":[{"description":"The deployment ID to follow.","in":"path","name":"id","required":true,"schema":{"type":"string"}},{"description":"Show logs since the given time (RFC timestamps or durations like 5m).","in":"query","name":"since","required":false,"schema":{"example":"2025-06-20T12:00:00Z","type":"string"}}],"responses":{"200":{"content":{"text/event-stream":{"schema":{"$ref":"#/components/schemas/DeploymentEvent"}}},"description":"SSE stream of deployment state updates and logs.","headers":{"X-SSE-Content-Type":{"description":"Media type of SSE data events (always application/json).","schema":{"const":"application/json","type":"string"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Stream deployment events via SSE","tags":["Deployments"],"x-hidden":false}},"/extensions":{"get":{"description":"List extensions in the resolved project.","operationId":"getExtensions","parameters":[{"description":"Limit the number of extensions to return.","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"description":"Offset the number of extensions to return.","in":"query","name":"offset","required":false,"schema":{"default":0,"minimum":0,"type":"integer"}},{"description":"Case-insensitive substring match against extension name. IDs match by exact value.","in":"query","name":"query","required":false,"schema":{"type":"string"}},{"description":"Exact-match filter on extension name using the database collation. In production, matching is case- and accent-insensitive. During the default-project migration, unscoped requests prefer a concrete default-project extension over a legacy unscoped extension with the same name.","in":"query","name":"name","required":false,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/Extension"},"type":"array"}}},"description":"List of extensions","headers":{"X-Has-More":{"description":"Whether there are more extensions to fetch.","schema":{"default":false,"type":"boolean"}},"X-Limit":{"description":"Limit the number of extensions to return.","schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"nullable":true,"type":"integer"}},"X-Offset":{"description":"The offset of extensions to return.","schema":{"default":0,"minimum":0,"type":"integer"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List browser extensions","tags":["Extensions"]},"post":{"description":"Upload a zip file containing an unpacked browser extension. Optionally provide a unique name for later reference.","operationId":"postExtensions","requestBody":{"content":{"multipart/form-data":{"schema":{"properties":{"file":{"description":"ZIP file containing the browser extension.","example":"@path/to/extension.zip","format":"binary","type":"string"},"name":{"description":"Optional unique name within the project to reference this extension.","pattern":"^[A-Za-z0-9._-]{1,255}$","type":"string"}},"required":["file"],"type":"object"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Extension"}}},"description":"Extension uploaded successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Upload a browser extension","tags":["Extensions"]}},"/extensions/from_chrome_store":{"get":{"description":"Returns a ZIP archive containing the unpacked extension fetched from the Chrome Web Store.","operationId":"getExtensionsFromChromeStore","parameters":[{"description":"Chrome Web Store URL for the extension.","in":"query","name":"url","required":true,"schema":{"type":"string"}},{"description":"Target operating system for the extension package. Defaults to linux.","in":"query","name":"os","required":false,"schema":{"default":"linux","enum":["win","mac","linux"],"type":"string"}}],"responses":{"200":{"content":{"application/octet-stream":{"schema":{"format":"binary","type":"string"}}},"description":"Extension ZIP archive"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Download unpacked extension from Chrome Web Store","tags":["Extensions"]}},"/extensions/{id_or_name}":{"delete":{"description":"Delete an extension by its ID or by its name.","operationId":"deleteExtensionByIdOrName","parameters":[{"description":"Extension ID or extension name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"Extension deleted successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete extension by ID or name","tags":["Extensions"]},"get":{"description":"Download the extension as a ZIP archive by ID or name.","operationId":"getExtensionByIdOrName","parameters":[{"description":"Extension ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/octet-stream":{"schema":{"format":"binary","type":"string"}}},"description":"Extension ZIP archive"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Download extension archive","tags":["Extensions"]}},"/extensions/{id_or_name}/metadata":{"get":{"description":"Get an extension's metadata (name, size, timestamps) by ID or name, without downloading the archive.","operationId":"getExtensionByIdOrNameMetadata","parameters":[{"description":"Extension ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Extension"}}},"description":"Extension metadata"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get extension metadata","tags":["Extensions"]}},"/invocations":{"get":{"description":"List invocations. Optionally filter by application name, action name, status, deployment ID, or start time.","operationId":"getInvocations","parameters":[{"description":"Filter results by application name.","in":"query","name":"app_name","required":false,"schema":{"type":"string"}},{"description":"Filter results by application version.","in":"query","name":"version","required":false,"schema":{"type":"string"}},{"description":"Filter results by action name.","in":"query","name":"action_name","required":false,"schema":{"type":"string"}},{"description":"Filter results by deployment ID.","in":"query","name":"deployment_id","required":false,"schema":{"type":"string"}},{"description":"Filter results by invocation status.","in":"query","name":"status","required":false,"schema":{"enum":["queued","running","succeeded","failed"],"type":"string"}},{"description":"Show invocations that have started since the given time (RFC timestamps or durations like 5m).","in":"query","name":"since","required":false,"schema":{"example":"2025-06-20T12:00:00Z","type":"string"}},{"description":"Limit the number of invocations to return.","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"description":"Offset the number of invocations to return.","in":"query","name":"offset","required":false,"schema":{"default":0,"minimum":0,"type":"integer"}},{"description":"Search invocations by ID, app name, or action name.","in":"query","name":"query","required":false,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/Invocation"},"type":"array"}}},"description":"A list of invocations.","headers":{"X-Has-More":{"description":"Whether there are more invocations to fetch.","schema":{"default":false,"type":"boolean"}},"X-Limit":{"description":"The limit of invocations returned.","schema":{"type":"integer"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"nullable":true,"type":"integer"}},"X-Offset":{"description":"The offset of invocations returned.","schema":{"type":"integer"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List invocations","tags":["Invocations"]},"post":{"description":"Invoke an action.","operationId":"postInvocations","requestBody":{"content":{"application/json":{"schema":{"properties":{"action_name":{"description":"Name of the action to invoke","example":"analyze","type":"string"},"app_name":{"description":"Name of the application","example":"my-app","type":"string"},"async":{"default":false,"description":"If true, invoke asynchronously. When set, the API responds 202 Accepted with status \"queued\".","example":true,"type":"boolean"},"async_timeout_seconds":{"default":900,"description":"Timeout in seconds for async invocations (min 10, max 3600). Only applies when async is true.","example":600,"maximum":3600,"minimum":10,"type":"integer"},"payload":{"description":"Input data for the action, sent as a JSON string.","example":"{\"data\":\"example input\"}","type":"string"},"version":{"default":"latest","description":"Version of the application","example":"1.0.0","type":"string"}},"required":["app_name","version","action_name"],"type":"object"}}},"description":"Invocation parameters","required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InvokeResponse"}}},"description":"Invocation created successfully"},"202":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InvokeResponse"}}},"description":"Invocation queued successfully (asynchronous invocation)"},"400":{"$ref":"#/components/responses/BadRequest"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"429":{"$ref":"#/components/responses/TooManyRequests"},"500":{"$ref":"#/components/responses/InternalError"},"529":{"$ref":"#/components/responses/CapacityExhausted"}},"security":[{"bearerAuth":[]}],"summary":"Invoke an action","tags":["Invocations"]}},"/invocations/{id}":{"get":{"description":"Get details about an invocation's status and output.","operationId":"getInvocationsById","parameters":[{"description":"The invocation ID","example":"rr33xuugxj9h0bkf1rdt2bet","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Invocation"}}},"description":"App invocation retrieved successfully"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get invocation details","tags":["Invocations"]},"patch":{"description":"Update an invocation's status or output. This can be used to cancel an invocation by setting the status to \"failed\".","operationId":"patchInvocationsById","parameters":[{"description":"Invocation ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InvocationUpdateRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Invocation"}}},"description":"Invocation updated successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update invocation","tags":["Invocations"]}},"/invocations/{id}/browsers":{"delete":{"description":"Delete all browser sessions created within the specified invocation.","operationId":"deleteInvocationsBrowsersById","parameters":[{"description":"Invocation ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"Browser sessions deleted successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete browser sessions for an invocation","tags":["Invocations"]},"get":{"description":"Returns all active browser sessions created within the specified invocation.","operationId":"getInvocationsBrowsersById","parameters":[{"description":"Invocation ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"browsers":{"items":{"$ref":"#/components/schemas/Browser"},"type":"array"}},"required":["browsers"],"type":"object"}}},"description":"List of browsers for this invocation"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List browsers for an invocation","tags":["Invocations"]}},"/invocations/{id}/events":{"get":{"description":"Establishes a Server-Sent Events (SSE) stream that delivers real-time logs and\nstatus updates for an invocation. The stream terminates automatically\nonce the invocation reaches a terminal state.\n","operationId":"getInvocationsEventsById","parameters":[{"description":"The invocation ID to follow.","in":"path","name":"id","required":true,"schema":{"type":"string"}},{"description":"Show logs since the given time (RFC timestamps or durations like 5m).","in":"query","name":"since","required":false,"schema":{"example":"2025-06-20T12:00:00Z","type":"string"}}],"responses":{"200":{"content":{"text/event-stream":{"schema":{"$ref":"#/components/schemas/InvocationEvent"}}},"description":"SSE stream of invocation state updates and logs.","headers":{"X-SSE-Content-Type":{"description":"Media type of SSE data events (always application/json).","schema":{"const":"application/json","type":"string"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Stream invocation events via SSE","tags":["Invocations"],"x-hidden":false}},"/mpp/browsers":{"post":{"description":"Buys a stealth headful browser for the duration in the offer with a Machine Payments Protocol (MPP) payment, without a Kernel account. A request without an `Authorization: Payment` credential gets a 402 challenge; the paid retry returns the browser and a `Payment-Receipt` header. A challenge can be paid until its `expires` time, 30 minutes after it is issued by default. A challenge buys one browser. Resending the same paid credential is intentional and safe: it returns the same browser without charging again until the session expires, even after the challenge has expired, so an agent can retry after a timeout. After the session expires it gets a 402 with a fresh challenge and `code: session_expired`. A different payment for a challenge that was already charged is rejected with a 402 before any charge.","operationId":"postMppBrowsers","requestBody":{"content":{"application/json":{"schema":{"properties":{"email":{"description":"Optional address for the Stripe receipt. When omitted, the billing email shared with the payment token is used, if any. A malformed address is rejected with a 400 before any challenge or charge.","format":"email","type":"string"}},"type":"object"}}},"required":false},"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"access":{"properties":{"type":{"enum":["session_urls"],"type":"string"}},"required":["type"],"type":"object"},"browser_live_view_url":{"type":"string"},"cdp_ws_url":{"type":"string"},"created_at":{"format":"date-time","type":"string"},"duration_minutes":{"type":"integer"},"expires_at":{"format":"date-time","type":"string"},"headless":{"type":"boolean"},"payment":{"properties":{"amount":{"description":"Amount in cents","type":"integer"},"currency":{"type":"string"},"reference":{"description":"Stripe PaymentIntent ID","type":"string"}},"required":["reference","amount","currency"],"type":"object"},"session_id":{"type":"string"},"stealth":{"type":"boolean"},"webdriver_ws_url":{"type":"string"}},"required":["session_id","cdp_ws_url","webdriver_ws_url","headless","stealth","duration_minutes","created_at","expires_at","payment","access"],"type":"object"}}},"description":"The purchased browser session.","headers":{"Payment-Receipt":{"description":"Base64url-encoded MPP receipt.","schema":{"type":"string"}}}},"400":{"content":{"application/problem+json":{"schema":{"type":"object"}}},"description":"The request body is not a JSON object, or `email` is malformed."},"402":{"content":{"application/problem+json":{"schema":{"properties":{"challengeId":{"type":"string"},"code":{"enum":["session_expired"],"type":"string"},"detail":{"type":"string"},"expires_at":{"format":"date-time","type":"string"},"status":{"type":"integer"},"title":{"type":"string"},"type":{"type":"string"}},"type":"object"}}},"description":"Payment required. The `WWW-Authenticate` header carries a fresh Payment challenge; the body is RFC 9457 problem details. When the session this credential bought has expired, the problem type is `invalid-challenge` with `code: session_expired` and `expires_at`.","headers":{"WWW-Authenticate":{"description":"MPP Payment challenge.","schema":{"type":"string"}}}},"429":{"description":"Too many requests from this client."},"503":{"content":{"application/problem+json":{"schema":{"type":"object"}}},"description":"Paid browsers are unavailable, at capacity, or the browser could not be created (payment refunded)."}},"security":[],"summary":"Buy a browser session with a machine payment","tags":["Browsers"],"x-cli-skip":true,"x-hidden":true,"x-payment-info":{"offers":[{"amount":"50","currency":"usd","description":"Kernel stealth headful browser, 30 minutes","intent":"charge","method":"stripe"}]},"x-stainless-skip":true}},"/org/api_keys":{"get":{"description":"List API keys for the authenticated organization. API keys are masked.","operationId":"listApiKeys","parameters":[{"description":"Maximum number of results to return","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"type":"integer"}},{"description":"Number of results to skip","in":"query","name":"offset","required":false,"schema":{"default":0,"type":"integer"}},{"description":"Case-insensitive substring match against API key name, creator, and project. API key identifiers and masked keys match by exact value or prefix.","in":"query","name":"query","required":false,"schema":{"type":"string"}},{"description":"Exact-match filter on API key name using the database collation. In production, matching is case- and accent-insensitive. Names are not required to be unique, so multiple keys may match. When status=all or include_deleted=true is set, soft-deleted keys with the same name may also match.","in":"query","name":"name","required":false,"schema":{"type":"string"}},{"description":"Field to sort API keys by.","in":"query","name":"sort_by","required":false,"schema":{"default":"created_at","enum":["created_at","name","expires_at"],"type":"string"}},{"description":"Sort direction for API keys.","in":"query","name":"sort_direction","required":false,"schema":{"default":"desc","enum":["asc","desc"],"type":"string"}},{"description":"Filter API keys by status. \"active\" returns keys that are not deleted (default; expired-but-not-deleted keys are still included), \"deleted\" returns only soft-deleted keys, \"all\" returns both.","in":"query","name":"status","required":false,"schema":{"default":"active","enum":["active","deleted","all"],"type":"string","x-enum-varnames":["ListApiKeysParamsStatusActive","ListApiKeysParamsStatusDeleted","ListApiKeysParamsStatusAll"]}},{"deprecated":true,"description":"Deprecated: use status=all instead. When true, include deleted (soft-deleted) API keys in the results for audit purposes.","in":"query","name":"include_deleted","required":false,"schema":{"default":false,"type":"boolean"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/ApiKey"},"type":"array"}}},"description":"List of API keys","headers":{"X-Has-More":{"description":"Whether there are more results","schema":{"type":"boolean"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"type":"integer"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List API keys","tags":["API Keys"]},"post":{"description":"Create a new API key within the authenticated organization.","operationId":"postApiKeys","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateApiKeyRequest"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreatedApiKey"}}},"description":"API key created successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Create an API key","tags":["API Keys"]}},"/org/api_keys/{id}":{"delete":{"description":"Delete an API key. A key cannot delete itself; use a different key to delete this one.","operationId":"deleteApiKeysById","parameters":[{"description":"API key ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"API key deleted."},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete an API key","tags":["API Keys"]},"get":{"description":"Retrieve an API key by ID for the authenticated organization. API keys are masked.","operationId":"getApiKeysById","parameters":[{"description":"API key ID","in":"path","name":"id","required":true,"schema":{"type":"string"}},{"description":"When true, return the API key even if it has been deleted (soft-deleted), for audit purposes. Defaults to false, which returns 404 for a deleted key.","in":"query","name":"include_deleted","required":false,"schema":{"default":false,"type":"boolean"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApiKey"}}},"description":"API key details"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get an API key","tags":["API Keys"]},"patch":{"description":"Update an API key's name.","operationId":"patchApiKeysById","parameters":[{"description":"API key ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/UpdateApiKeyRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApiKey"}}},"description":"API key updated"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update an API key","tags":["API Keys"]}},"/org/api_keys/{id}/rotate":{"post":{"description":"Rotate an API key. Issues a new key that copies the name and project of the rotated key, and schedules the rotated key to expire after a grace period so in-flight callers can swap over. The new plaintext key is returned once.","operationId":"rotateApiKey","parameters":[{"description":"API key ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/RotateApiKeyRequest"}}},"required":false},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreatedApiKey"}}},"description":"New API key created from the rotation"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Rotate an API key","tags":["API Keys"]}},"/org/credential_providers":{"get":{"description":"List external credential providers configured for the organization.","operationId":"getCredentialProviders","parameters":[{"description":"Limit the number of credential providers to return.","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"description":"Offset the number of credential providers to return.","in":"query","name":"offset","required":false,"schema":{"default":0,"minimum":0,"type":"integer"}},{"description":"Case-insensitive substring match against credential provider name. IDs match by exact value.","in":"query","name":"query","required":false,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/CredentialProvider"},"type":"array"}}},"description":"List of credential providers","headers":{"X-Has-More":{"description":"Whether there are more credential providers to fetch.","schema":{"default":false,"type":"boolean"}},"X-Limit":{"description":"Limit the number of credential providers to return.","schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"nullable":true,"type":"integer"}},"X-Offset":{"description":"The offset of credential providers to return.","schema":{"default":0,"minimum":0,"type":"integer"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List credential providers","tags":["Credential Providers"],"x-hidden":true},"post":{"description":"Configure an external credential provider (e.g., 1Password) for automatic credential lookup.","operationId":"postCredentialProviders","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateCredentialProviderRequest"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CredentialProvider"}}},"description":"Credential provider created successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Create a credential provider","tags":["Credential Providers"],"x-hidden":true}},"/org/credential_providers/{id}":{"delete":{"description":"Delete a credential provider by its ID.","operationId":"deleteCredentialProvidersById","parameters":[{"description":"Credential provider ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"Credential provider deleted successfully"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete credential provider","tags":["Credential Providers"],"x-hidden":true},"get":{"description":"Retrieve a credential provider by its ID.","operationId":"getCredentialProvidersById","parameters":[{"description":"Credential provider ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CredentialProvider"}}},"description":"Credential provider details"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get credential provider by ID","tags":["Credential Providers"],"x-hidden":true},"patch":{"description":"Update a credential provider's configuration.","operationId":"patchCredentialProvidersById","parameters":[{"description":"Credential provider ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/UpdateCredentialProviderRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CredentialProvider"}}},"description":"Credential provider updated successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update credential provider","tags":["Credential Providers"],"x-hidden":true}},"/org/credential_providers/{id}/items":{"get":{"description":"Returns available credential items (e.g., 1Password login items) from the provider.","operationId":"getCredentialProviderItems","parameters":[{"description":"Credential provider ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"items":{"items":{"$ref":"#/components/schemas/CredentialProviderItem"},"type":"array"}},"type":"object"}}},"description":"List of credential items"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List items from a credential provider","tags":["Credential Providers"],"x-hidden":true}},"/org/credential_providers/{id}/test":{"post":{"description":"Validate the credential provider's token and list accessible vaults.","operationId":"testCredentialProviderById","parameters":[{"description":"Credential provider ID","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CredentialProviderTestResult"}}},"description":"Connection test successful"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Test credential provider connection","tags":["Credential Providers"],"x-hidden":true}},"/org/entitlements":{"get":{"description":"Get the authenticated organization's effective feature access and constraints after applying its plan, active trial treatment, plan status, and organization-specific overrides. Null constraint values mean unlimited.","operationId":"getOrgEntitlements","responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/OrgEntitlements"}}},"description":"Effective organization entitlements"},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get organization entitlements","tags":["Organization"]}},"/org/limits":{"get":{"description":"Get the organization's effective limits and current concurrency, managed auth, and vault usage.","operationId":"getOrgLimits","responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/OrgLimits"}}},"description":"Organization limits"},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get organization limits","tags":["Organization"]},"patch":{"description":"Set the default per-project concurrency cap applied to projects without an explicit override. Set the value to 0 to remove the default; omit to leave it unchanged. The default cannot exceed the organization's concurrency limit.","operationId":"patchOrgLimits","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/UpdateOrgLimitsRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/OrgLimits"}}},"description":"Organization limits updated"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update organization limits","tags":["Organization"]}},"/org/projects":{"get":{"description":"List projects for the authenticated organization.","operationId":"getOrgProjects","parameters":[{"description":"Maximum number of results to return","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"type":"integer"}},{"description":"Number of results to skip","in":"query","name":"offset","required":false,"schema":{"default":0,"type":"integer"}},{"description":"Case-insensitive substring match against project name","in":"query","name":"query","required":false,"schema":{"type":"string"}},{"description":"Exact-match filter on project name using the database collation. In production, matching is case- and accent-insensitive.","in":"query","name":"name","required":false,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/Project"},"type":"array"}}},"description":"List of projects","headers":{"X-Has-More":{"description":"Whether there are more results","schema":{"type":"boolean"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"type":"integer"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List projects","tags":["Projects"]},"post":{"description":"Create a new project within the authenticated organization.","operationId":"postOrgProjects","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateProjectRequest"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Project"}}},"description":"Project created successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Create a project","tags":["Projects"]}},"/org/projects/{id_or_name}":{"delete":{"description":"Soft-delete a project. The project must be empty (no active resources).","operationId":"deleteOrgProjectsId","parameters":[{"description":"Project ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"Project deleted"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Project deletion conflict. Returns `project_not_empty` when active\nresources remain; remove them and retry. Returns `last_active_project`\nwhen deletion would remove the organization's final active project.\n"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete a project by ID or name","tags":["Projects"]},"get":{"description":"Get a project by its ID or by its name. Names are unique within an organization.","operationId":"getOrgProjectsId","parameters":[{"description":"Project ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Project"}}},"description":"Project details"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get a project by ID or name","tags":["Projects"]},"patch":{"description":"Update a project's name or status.","operationId":"patchOrgProjectsId","parameters":[{"description":"Project ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/UpdateProjectRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Project"}}},"description":"Project updated"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update a project by ID or name","tags":["Projects"]}},"/org/projects/{id_or_name}/limits":{"get":{"description":"Get the resource limit overrides for a project. Null values mean no project-level cap (org limit applies).","operationId":"getOrgProjectLimits","parameters":[{"description":"Project ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProjectLimits"}}},"description":"Project limits"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get project limits by ID or name","tags":["Projects"]},"patch":{"description":"Update resource limit overrides for a project. Only fields present in the request are modified. Set a field to 0 to remove that limit cap; omit a field to leave it unchanged.","operationId":"patchOrgProjectLimits","parameters":[{"description":"Project ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/UpdateProjectLimitsRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProjectLimits"}}},"description":"Project limits updated"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update project limits by ID or name","tags":["Projects"]}},"/profiles":{"get":{"description":"List profiles with optional filtering and pagination.","operationId":"getProfiles","parameters":[{"description":"Limit the number of profiles to return.","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"description":"Offset the number of profiles to return.","in":"query","name":"offset","required":false,"schema":{"default":0,"minimum":0,"type":"integer"}},{"description":"Case-insensitive substring match against profile name or ID.","in":"query","name":"query","required":false,"schema":{"type":"string"}},{"description":"Exact-match filter on profile name using the database collation. In production, matching is case- and accent-insensitive. During the default-project migration, unscoped requests prefer a concrete default-project profile over a legacy unscoped profile with the same name.","in":"query","name":"name","required":false,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/Profile"},"type":"array"}}},"description":"List of profiles","headers":{"X-Has-More":{"description":"Whether there are more profiles to fetch.","schema":{"default":false,"type":"boolean"}},"X-Limit":{"description":"Limit the number of profiles to return.","schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"nullable":true,"type":"integer"}},"X-Offset":{"description":"The offset of profiles to return.","schema":{"default":0,"minimum":0,"type":"integer"}}}},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List profiles","tags":["Profiles"]},"post":{"description":"Create a browser profile that can be used to load state into future browser sessions.","operationId":"postProfiles","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProfileRequest"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Profile"}}},"description":"Profile created successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Create a new profile","tags":["Profiles"]}},"/profiles/{id_or_name}":{"delete":{"description":"Delete a profile by its ID or by its name.","operationId":"deleteProfileByIdOrName","parameters":[{"description":"Profile ID or profile name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"Profile deleted successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete profile by ID or name","tags":["Profiles"]},"get":{"description":"Retrieve details for a single profile by its ID or name.","operationId":"getProfileByIdOrName","parameters":[{"description":"Profile ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Profile"}}},"description":"Profile details"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get profile by ID or name","tags":["Profiles"]},"patch":{"description":"Update a profile's name. Names must be unique within the logical project; during the default-project migration, unscoped profiles and profiles in the org default project are treated as the same project. Duplicate-name conflicts are checked before update but are best-effort because there is no backing unique index. Renaming a profile while a browser session references it by name may prevent that session's changes from saving; prefer renaming when the profile is not in use.","operationId":"patchProfileByIdOrName","parameters":[{"description":"Profile ID or profile name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProfileUpdateRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Profile"}}},"description":"Profile updated"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Rename profile by ID or name","tags":["Profiles"]}},"/profiles/{id_or_name}/download":{"get":{"description":"Downloads the profile in its stored format by default. Current profiles are returned as\nzstd-compressed tar archives, while legacy profiles remain JSON. Set `format=tar` to\ndecompress current profiles during download; legacy profiles remain JSON.\n","operationId":"downloadProfileByIdOrName","parameters":[{"description":"Profile ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"description":"Response format for current profile archives. Legacy profiles are always returned as JSON.","in":"query","name":"format","required":false,"schema":{"default":"tar.zst","enum":["tar.zst","tar"],"type":"string"}}],"responses":{"200":{"content":{"application/octet-stream":{"schema":{"format":"binary","type":"string"}},"application/x-tar":{"schema":{"format":"binary","type":"string"}},"application/zstd":{"schema":{"format":"binary","type":"string"}}},"description":"Profile data in the requested format, or JSON for a legacy profile.","headers":{"Content-Disposition":{"description":"Attachment filename matching the returned profile format.","schema":{"type":"string"}}}},"202":{"description":"Profile exists but has not yet captured any state. Use it in a browser session first to capture state."},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Download profile archive","tags":["Profiles"]}},"/projects":{"get":{"deprecated":true,"description":"Deprecated: use `GET /org/projects` instead. This route will be removed on 2026-11-24.\n\nList projects for the authenticated organization.\n","operationId":"getProjects","parameters":[{"description":"Maximum number of results to return","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"type":"integer"}},{"description":"Number of results to skip","in":"query","name":"offset","required":false,"schema":{"default":0,"type":"integer"}},{"description":"Case-insensitive substring match against project name","in":"query","name":"query","required":false,"schema":{"type":"string"}},{"description":"Exact-match filter on project name using the database collation. In production, matching is case- and accent-insensitive.","in":"query","name":"name","required":false,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/Project"},"type":"array"}}},"description":"List of projects","headers":{"X-Has-More":{"description":"Whether there are more results","schema":{"type":"boolean"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"type":"integer"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List projects","tags":["Projects"]},"post":{"deprecated":true,"description":"Deprecated: use `POST /org/projects` instead. This route will be removed on 2026-11-24.\n\nCreate a new project within the authenticated organization.\n","operationId":"postProjects","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CreateProjectRequest"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Project"}}},"description":"Project created successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Create a project","tags":["Projects"]}},"/projects/{id_or_name}":{"delete":{"deprecated":true,"description":"Deprecated: use `DELETE /org/projects/{id_or_name}` instead. This route will be removed on 2026-11-24.\n\nSoft-delete a project. The project must be empty (no active resources).\n","operationId":"deleteProjectsId","parameters":[{"description":"Project ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"Project deleted"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete a project by ID or name","tags":["Projects"]},"get":{"deprecated":true,"description":"Deprecated: use `GET /org/projects/{id_or_name}` instead. This route will be removed on 2026-11-24.\n\nGet a project by ID or name.\n","operationId":"getProjectsId","parameters":[{"description":"Project ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Project"}}},"description":"Project details"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get a project by ID or name","tags":["Projects"]},"patch":{"deprecated":true,"description":"Deprecated: use `PATCH /org/projects/{id_or_name}` instead. This route will be removed on 2026-11-24.\n\nUpdate a project's name or status.\n","operationId":"patchProjectsId","parameters":[{"description":"Project ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/UpdateProjectRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Project"}}},"description":"Project updated"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update a project by ID or name","tags":["Projects"]}},"/projects/{id_or_name}/limits":{"get":{"deprecated":true,"description":"Deprecated: use `GET /org/projects/{id_or_name}/limits` instead. This route will be removed on 2026-11-24.\n\nGet the resource limit overrides for a project. Null values mean no project-level cap (org limit applies).\n","operationId":"getProjectLimits","parameters":[{"description":"Project ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProjectLimits"}}},"description":"Project limits"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get project limits by ID or name","tags":["Projects"]},"patch":{"deprecated":true,"description":"Deprecated: use `PATCH /org/projects/{id_or_name}/limits` instead. This route will be removed on 2026-11-24.\n\nUpdate resource limit overrides for a project. Only fields present in the request are modified. Set a field to 0 to remove that limit cap; omit a field to leave it unchanged.\n","operationId":"patchProjectLimits","parameters":[{"description":"Project ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/UpdateProjectLimitsRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProjectLimits"}}},"description":"Project limits updated"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update project limits by ID or name","tags":["Projects"]}},"/proxies":{"get":{"description":"List proxies in the resolved project.","operationId":"getProxies","parameters":[{"description":"Limit the number of proxies to return.","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"description":"Offset the number of proxies to return.","in":"query","name":"offset","required":false,"schema":{"default":0,"minimum":0,"type":"integer"}},{"description":"Case-insensitive substring match against proxy name, host, or IP address. IDs match by exact value.","in":"query","name":"query","required":false,"schema":{"type":"string"}},{"description":"Exact-match filter on proxy name using the database collation. In production, matching is case- and accent-insensitive. Names are not required to be unique, so multiple proxies may match.","in":"query","name":"name","required":false,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/Proxy"},"type":"array"}}},"description":"List of proxies","headers":{"X-Has-More":{"description":"Whether there are more proxies to fetch.","schema":{"default":false,"type":"boolean"}},"X-Limit":{"description":"Limit the number of proxies to return.","schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"nullable":true,"type":"integer"}},"X-Offset":{"description":"The offset of proxies to return.","schema":{"default":0,"minimum":0,"type":"integer"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List proxies","tags":["Proxies"]},"post":{"description":"Create a new proxy configuration in the resolved project.","operationId":"postProxies","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProxyCreateRequest"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Proxy"}}},"description":"Proxy created successfully"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Create a proxy","tags":["Proxies"]}},"/proxies/{id}":{"delete":{"description":"Soft delete a proxy. Session records referencing it are not modified. If egress binding polling is enabled, existing tunnels for active sessions using the proxy are terminated within one polling interval; subsequent connections through the deleted proxy are rejected.\n","operationId":"deleteProxiesById","parameters":[{"in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"Proxy deleted"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete proxy by ID","tags":["Proxies"]},"get":{"description":"Retrieve a proxy in the resolved project by ID.","operationId":"getProxiesById","parameters":[{"in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Proxy"}}},"description":"Proxy retrieved"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get proxy by ID","tags":["Proxies"]},"patch":{"description":"Update a proxy's name. Proxy names are not unique and are not ID-or-name addressable on this endpoint; duplicate names are allowed. Name-based session-create lookups can remain ambiguous until callers resolve proxies by ID or the API adds a stronger uniqueness contract.","operationId":"patchProxiesById","parameters":[{"in":"path","name":"id","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProxyUpdateRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Proxy"}}},"description":"Proxy updated"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Rename proxy by ID","tags":["Proxies"]}},"/proxies/{id}/check":{"post":{"description":"Run a health check on the proxy to verify it's working. Optionally specify a URL to test reachability against a specific target. For ISP and datacenter proxies, this reliably tests whether the target site is reachable from the proxy's stable exit IP. For residential and mobile proxies, the exit node varies between requests, so this validates proxy configuration and connectivity rather than guaranteeing site-specific reachability.","operationId":"postProxiesByIdCheck","parameters":[{"in":"path","name":"id","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProxyCheckRequest"}}},"required":false},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Proxy"}}},"description":"Health check completed"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"422":{"$ref":"#/components/responses/UnprocessableEntity"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Check proxy health","tags":["Proxies"]}},"/search":{"post":{"description":"Returns ranked results from one serving provider. The default strategy selects a provider that supports the requested options. The fallback strategy tries providers in the supplied order. Results are not blended across providers. Portable filters may be approximated or omitted according to provider capabilities; warnings describe those outcomes unless strict_params is true. Native options apply only to their selected provider.","operationId":"postSearch","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/SearchRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Search"}}},"description":"Completed search, including valid zero-result responses. Inline\nretrieval failures are reported per result. Arrays are never null.\n"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"422":{"$ref":"#/components/responses/UnprocessableEntity"},"429":{"$ref":"#/components/responses/TooManyRequests"},"500":{"$ref":"#/components/responses/InternalError"},"502":{"$ref":"#/components/responses/SearchProviderError"},"503":{"$ref":"#/components/responses/SearchUnavailable"},"504":{"$ref":"#/components/responses/SearchTimeout"}},"security":[{"bearerAuth":[]}],"summary":"Search the web","tags":["Search"]}},"/search/providers":{"get":{"description":"Lists providers, capabilities, and machine-readable native-option schemas. Auto and fallback\nare strategies, not provider entries. The list is not paginated and contains no latency\nbenchmarks. X-Request-Id identifies the request.\n","operationId":"getSearchProviders","parameters":[{"description":"Optional concrete provider slug filter. Omit to list every provider. A slug that is not listed returns an empty array.","in":"query","name":"slug","required":false,"schema":{"$ref":"#/components/schemas/SearchProviderSlug"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/SearchProvider"},"type":"array"}}},"description":"List of available search providers. Returns an empty array, never null."},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"503":{"$ref":"#/components/responses/SearchUnavailable"}},"security":[{"bearerAuth":[]}],"summary":"List search providers","tags":["Search"]}},"/search/{id}":{"get":{"description":"Returns the retained search resource exactly as it was returned by\nPOST /search: results, attempts, warnings, usage, and expires_at. No\nprovider is called and nothing is billed. Use it to look up a search\nby ID for debugging, cost review, or to recover result IDs before\ncalling the contents endpoint. Inline content fetched at search time\nis included; content fetched later through the contents endpoint is\nnot merged in. Missing, expired, or inaccessible searches return 404.\n","operationId":"getSearch","parameters":[{"description":"Search resource ID returned by POST /search.","example":"srch_abc123","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Search"}}},"description":"The retained search."},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"},"503":{"$ref":"#/components/responses/SearchUnavailable"}},"security":[{"bearerAuth":[]}],"summary":"Retrieve a search","tags":["Search"]}},"/search/{id}/contents":{"post":{"description":"Retrieves selected results from a retained search. Provide exactly one of\nresult_ids or limit; the latter fetches the top results. Content defaults to\nsource:auto. Responses preserve result_ids order. Unknown result IDs are rejected before retrieval starts.\nMissing, expired, or inaccessible searches return 404. Once retrieval begins,\nreturn one outcome per selected result, including timeout entries for work\nunfinished at the overall deadline. Browser retrievals run sequentially in\nresult order, so later results may time out when earlier pages are slow.\nX-Request-Id identifies this request separately from the search resource.\n","operationId":"postSearchContents","parameters":[{"description":"Search resource ID returned by POST /search.","example":"srch_abc123","in":"path","name":"id","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/SearchContentsRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/SearchContentsResponse"}}},"description":"One outcome per selected result, even if every fetch fails. Arrays are never null."},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"429":{"$ref":"#/components/responses/TooManyRequests"},"500":{"$ref":"#/components/responses/InternalError"},"503":{"$ref":"#/components/responses/SearchUnavailable"}},"security":[{"bearerAuth":[]}],"summary":"Fetch search result content","tags":["Search"]}},"/telemetry/destinations":{"get":{"description":"List customer-visible OTLP export destinations in the authenticated organization. Project-scoped credentials can list these destinations for selection by workloads in their project. Non-dashboard reads return header values redacted.","operationId":"getTelemetryDestinations","parameters":[{"description":"Limit the number of destinations to return.","in":"query","name":"limit","required":false,"schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"description":"Offset the number of destinations to return.","in":"query","name":"offset","required":false,"schema":{"default":0,"minimum":0,"type":"integer"}},{"description":"Case-insensitive substring match against destination name or endpoint. IDs match by exact value.","in":"query","name":"query","required":false,"schema":{"type":"string"}},{"description":"Exact-match filter on destination name using the database collation. In production, matching is case- and accent-insensitive.","in":"query","name":"name","required":false,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/OTLPDestination"},"type":"array"}}},"description":"List of OTLP destinations","headers":{"X-Has-More":{"description":"Whether there are more destinations to fetch.","schema":{"default":false,"type":"boolean"}},"X-Limit":{"description":"Limit the number of destinations to return.","schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},"X-Next-Offset":{"description":"The offset where the next page starts. 0 when there are no more results.","schema":{"nullable":true,"type":"integer"}},"X-Offset":{"description":"The offset of destinations to return.","schema":{"default":0,"minimum":0,"type":"integer"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List OTLP destinations","tags":["Browser Telemetry"]},"post":{"description":"Create an OTLP export destination in the authenticated organization. Names must be unique within the organization. Requires an organization-scoped credential or dashboard authentication; project-scoped credentials receive a 403.","operationId":"postTelemetryDestinations","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/OTLPDestinationCreateRequest"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/OTLPDestination"}}},"description":"OTLP destination created"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Create an OTLP destination","tags":["Browser Telemetry"]}},"/telemetry/destinations/{id_or_name}":{"delete":{"description":"Delete an OTLP destination. Sessions bound to it are still exporting, so the delete is refused with a 409 while any exist; either wait for those sessions to end or delete them first. It is refused the same way while a managed auth connection still selects it, because that connection re-resolves the destination on every login, and while a managed auth login using it is still in progress. Requires an organization-scoped credential or dashboard authentication; project-scoped credentials receive a 403.","operationId":"deleteTelemetryDestinationByIdOrName","parameters":[{"description":"OTLP destination ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"OTLP destination deleted"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete OTLP destination by ID or name","tags":["Browser Telemetry"]},"get":{"description":"Retrieve a customer-visible OTLP destination in the authenticated organization by its ID or name. Project-scoped credentials can retrieve these destinations for selection by workloads in their project. Non-dashboard reads return header values redacted.","operationId":"getTelemetryDestinationByIdOrName","parameters":[{"description":"OTLP destination ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/OTLPDestination"}}},"description":"OTLP destination details"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get OTLP destination by ID or name","tags":["Browser Telemetry"]},"patch":{"description":"Update an OTLP destination. Sessions already exporting to it pick up the new values without restarting, which makes this the way to rotate credentials without interrupting export.\n\nNames must be unique within the organization. Renaming is refused with a 409 while a managed auth connection selects this destination by name, since that connection resolves the name on every login. Every other field, including `headers`, stays editable. Requires an organization-scoped credential or dashboard authentication; project-scoped credentials receive a 403.","operationId":"patchTelemetryDestinationByIdOrName","parameters":[{"description":"OTLP destination ID or name","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/OTLPDestinationUpdateRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/OTLPDestination"}}},"description":"OTLP destination updated"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update OTLP destination by ID or name","tags":["Browser Telemetry"]}},"/vault-provider-configs":{"get":{"description":"Secret credentials are never returned.","operationId":"getVaultProviderConfigs","parameters":[{"in":"query","name":"limit","schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"in":"query","name":"offset","schema":{"default":0,"minimum":0,"type":"integer"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/VaultProviderConfig"},"type":"array"}}},"description":"Provider configurations","headers":{"X-Has-More":{"schema":{"type":"boolean"}},"X-Next-Offset":{"schema":{"type":"integer"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List provider configurations in the organization","tags":["Vaults"]},"post":{"description":"Register a configuration shared across the organization's projects. Names are unique within the organization; duplicate names return 409 without replacing credentials. A configuration serves many wallets. Secret credentials are never returned. Requires an organization-scoped credential or dashboard authentication; project-scoped credentials receive 403.","operationId":"postVaultProviderConfig","requestBody":{"content":{"application/json":{"examples":{"agentcard":{"value":{"credentials":{"client_id":"example-client-id","client_secret":"example-client-secret"},"name":"my-agentcard","provider":"agentcard"}},"link":{"value":{"credentials":{"client_id":"example-client-id","client_secret":"example-client-secret","publishable_key":"pk_live_example"},"name":"my-link-client","provider":"link"}}},"schema":{"$ref":"#/components/schemas/VaultProviderConfigRequest"}}},"required":true},"responses":{"201":{"content":{"application/json":{"examples":{"agentcard":{"$ref":"#/components/examples/ExampleAgentCardConfig"},"link":{"$ref":"#/components/examples/ExampleLinkConfig"}},"schema":{"$ref":"#/components/schemas/VaultProviderConfig"}}},"description":"Provider configuration registered"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Register a provider configuration","tags":["Vaults"]}},"/vault-provider-configs/{id_or_name}":{"delete":{"description":"Delete a configuration in the organization. Returns 409 while any non-deleted vault item references the configuration, regardless of connection status. Does not delete the external OAuth client or revoke unrelated grants. Requires an organization-scoped credential or dashboard authentication; project-scoped credentials receive 403.","operationId":"deleteVaultProviderConfig","responses":{"204":{"description":"Provider configuration deleted"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete an unused provider configuration","tags":["Vaults"]},"get":{"description":"Look up a configuration by ID or name. Returns 404 when it does not exist in the organization.","operationId":"getVaultProviderConfig","responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/VaultProviderConfig"}}},"description":"Provider configuration without secret credentials"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get a provider configuration","tags":["Vaults"]},"parameters":[{"description":"Provider configuration ID or name in the organization.","in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}],"patch":{"description":"Update the supplied fields; omitted fields remain unchanged. Names must remain unique within the organization. Requires an organization-scoped credential or dashboard authentication; project-scoped credentials receive 403.","operationId":"patchVaultProviderConfig","requestBody":{"content":{"application/json":{"examples":{"agentcard":{"summary":"Rotate the secret of the AgentCard configuration selected in the path","value":{"credentials":{"client_secret":"example-rotated-client-secret"}}},"link":{"summary":"Rename the Link configuration selected in the path","value":{"name":"renamed-link-client"}},"link_publishable_key":{"summary":"Set the Stripe publishable key of the Link configuration selected in the path","value":{"credentials":{"publishable_key":"pk_live_example"}}}},"schema":{"$ref":"#/components/schemas/VaultProviderConfigUpdateRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"examples":{"agentcard":{"$ref":"#/components/examples/ExampleAgentCardConfigRotated"},"link":{"$ref":"#/components/examples/ExampleLinkConfigRenamed"}},"schema":{"$ref":"#/components/schemas/VaultProviderConfig"}}},"description":"Provider configuration updated without returning secrets"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update a provider configuration","tags":["Vaults"]}},"/vaults":{"get":{"operationId":"getVaults","parameters":[{"in":"query","name":"limit","schema":{"default":20,"maximum":100,"minimum":1,"type":"integer"}},{"in":"query","name":"offset","schema":{"default":0,"minimum":0,"type":"integer"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/Vault"},"type":"array"}}},"description":"List of vaults","headers":{"X-Has-More":{"schema":{"type":"boolean"}},"X-Next-Offset":{"schema":{"type":"integer"}}}},"401":{"$ref":"#/components/responses/Unauthorized"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List vaults in the current project","tags":["Vaults"]},"post":{"description":"Free organizations can store up to 3 non-deleted vaults across all projects. Paid plans and active trials have no vault cap. Retrieving an existing vault by name succeeds even at the limit.","operationId":"postVaults","requestBody":{"content":{"application/json":{"examples":{"checkout":{"summary":"Create a provider-neutral vault; repeating this name retrieves it","value":{"name":"checkout"}}},"schema":{"$ref":"#/components/schemas/VaultRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"examples":{"checkout":{"$ref":"#/components/examples/ExampleVault"}},"schema":{"$ref":"#/components/schemas/Vault"}}},"description":"Existing vault"},"201":{"content":{"application/json":{"examples":{"checkout":{"$ref":"#/components/examples/ExampleVault"}},"schema":{"$ref":"#/components/schemas/Vault"}}},"description":"Vault created"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Create or retrieve a vault by immutable name","tags":["Vaults"]}},"/vaults/{id_or_name}":{"delete":{"description":"Unresolved payment operations block deletion. Reconcile the original attempt with the provider or support first; deleting or recreating an item is not proof that a payment did not occur.","operationId":"deleteVaultByIdOrName","responses":{"204":{"description":"Vault deleted"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete a vault and invalidate its items","tags":["Vaults"]},"get":{"operationId":"getVaultByIdOrName","responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Vault"}}},"description":"Vault"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get a vault","tags":["Vaults"]},"parameters":[{"in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}]},"/vaults/{id_or_name}/items":{"get":{"description":"Credential entries include safe field metadata and non-sensitive values. Listing never creates or renews collection sessions; only an existing unexpired active session is included. Use single-item GET or collect to obtain a fresh link.","operationId":"getVaultItems","responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/VaultItem"},"type":"array"}}},"description":"Vault items"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List vault items without secret values","tags":["Vaults"]},"parameters":[{"in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}}]},"/vaults/{id_or_name}/items/{key}":{"delete":{"description":"Unresolved payment operations normally block deletion, including operations on child cards of a wallet. An AgentCard card in recovery_required whose checkout create response returned no authorization ID may be explicitly abandoned by deleting that card directly; deleting its wallet or vault remains blocked. Deleting or recreating an item is not proof that a payment did not occur.","operationId":"deleteVaultItem","responses":{"204":{"description":"Vault item deleted"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Delete a vault item and invalidate its secret value","tags":["Vaults"]},"get":{"description":"The response advertises operations that are valid in the item's current state and live data that can be requested through `expand`. Read each operation's description before using it. Expanded data is fetched from the provider and is not persisted in the vault item. Requesting an unavailable expansion returns 409 instead of a partial item. Pending credential items return a collection action. Kernel-hosted active collection links are renewed atomically on expiry for ready or pending items without changing the item version. Invoke collect to open a form for a ready item without clearing values. Sensitive credential values are never returned.","operationId":"getVaultItem","parameters":[{"description":"Hold for up to this many seconds while the item is pending authorization, approval, or credential collection. Return the current item when ready or when the wait elapses. This does not wait for edits to an already-ready credential; poll GET without wait and compare version to observe changes after collect.","in":"query","name":"wait","schema":{"default":0,"maximum":60,"minimum":0,"type":"integer"}},{"description":"Live fields advertised by `available_expansions` to include in `expanded`.","explode":false,"in":"query","name":"expand","schema":{"items":{"$ref":"#/components/schemas/VaultItemExpansionType"},"type":"array","uniqueItems":true},"style":"form"}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/VaultItem"}}},"description":"Vault item"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Get a vault item, its currently available operations, and optionally expanded live data","tags":["Vaults"]},"parameters":[{"in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"in":"path","name":"key","required":true,"schema":{"maxLength":255,"minLength":1,"type":"string"}}],"patch":{"description":"Credential updates require type credential and the current version, and change only values or description; omitted values are preserved, nonempty strings replace, and null or empty strings clear supported fields. Clearing required text/email/password values returns pending_collection; browser forms still require nonempty required inputs. Card updates may omit type for compatibility with legacy requests. Requested cards accept a replacement specification. Pending issuance requests may update provider-supported fields on their existing request, subject to atomic provider approval checks; omitted optional fields remain unchanged and explicit empty lists clear them. Wallet/provider binding and unsupported fields cannot change after authorization starts. An uncertain update enters recovery_required and must not be retried. Checkout cards may be edited between authorizations.","operationId":"patchVaultItem","requestBody":{"content":{"application/json":{"examples":{"agentcard":{"$ref":"#/components/examples/ExampleAgentCardCardEdit"},"link":{"$ref":"#/components/examples/ExampleLinkCardEdit"}},"schema":{"$ref":"#/components/schemas/VaultItemUpdateRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"examples":{"agentcard":{"$ref":"#/components/examples/ExampleAgentCardCardUpdated"},"link":{"$ref":"#/components/examples/ExampleLinkCardUpdated"}},"schema":{"$ref":"#/components/schemas/VaultItem"}}},"description":"Vault item updated"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Update a card specification or credential values","tags":["Vaults"]},"put":{"description":"Create an item under a key unique within its vault, or retrieve the existing item when its specification matches. An identical card PUT returns the existing card in any lifecycle state without polling the provider, reauthorizing, replacing aliases, or resetting recovery. Conflicting specifications return 409. Provider-specific authorization requirements and retry behavior are described in the item's request schema. Do not use credential items to store, collect, or fill credit card data, including card numbers (PANs), security codes (CVV/CVC), or expiration dates. Use wallet and card item types for credit cards and payment checkout instead.","operationId":"putVaultItem","requestBody":{"content":{"application/json":{"examples":{"agentcard_card":{"$ref":"#/components/examples/ExampleAgentCardCardInput"},"customer_managed_agentcard":{"summary":"Create a wallet using customer-owned AgentCard credentials","value":{"spec":{"provider":"agentcard","provider_config":{"name":"my-agentcard"}},"type":"wallet"}},"imported_link":{"summary":"Import a grant from a customer-owned Link client","value":{"spec":{"authorization":{"client":{"provider_config":{"name":"my-link-client"},"type":"customer_managed"},"method":"oauth","tokens":{"access_token":"example-access-token","refresh_token":"example-refresh-token"}},"provider":"link"},"type":"wallet"}},"kernel_managed_agentcard":{"summary":"Start hosted enrollment with Kernel-managed credentials","value":{"spec":{"provider":"agentcard"},"type":"wallet"}},"kernel_managed_link":{"summary":"Start Kernel-managed Link authorization","value":{"spec":{"authorization":{"client":{"type":"kernel_managed"},"method":"oauth"},"provider":"link"},"type":"wallet"}},"link_card":{"$ref":"#/components/examples/ExampleLinkCardInput"}},"schema":{"$ref":"#/components/schemas/VaultItemRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"examples":{"agentcard_card":{"$ref":"#/components/examples/ExampleAgentCardCard"},"imported_link":{"$ref":"#/components/examples/ExampleImportedLinkWallet"},"link_card":{"$ref":"#/components/examples/ExampleLinkCard"}},"schema":{"$ref":"#/components/schemas/VaultItem"}}},"description":"Existing matching item; card retries preserve identity and state"},"201":{"content":{"application/json":{"examples":{"agentcard_card":{"$ref":"#/components/examples/ExampleAgentCardCard"},"customer_managed_agentcard":{"$ref":"#/components/examples/ExampleConfiguredAgentCardWallet"},"imported_link":{"$ref":"#/components/examples/ExampleImportedLinkWallet"},"kernel_managed_agentcard":{"$ref":"#/components/examples/ExampleManagedAgentCardWallet"},"kernel_managed_link":{"$ref":"#/components/examples/ExampleManagedLinkWallet"},"link_card":{"$ref":"#/components/examples/ExampleLinkCard"}},"schema":{"$ref":"#/components/schemas/VaultItem"}}},"description":"Item created"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"Create or retrieve an identical vault item by immutable key","tags":["Vaults"]}},"/vaults/{id_or_name}/items/{key}/events":{"get":{"operationId":"getVaultItemEvents","parameters":[{"in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"in":"path","name":"key","required":true,"schema":{"type":"string"}},{"description":"Return events after this event ID.","in":"query","name":"after","required":false,"schema":{"type":"string"}},{"description":"Long-poll for new events for up to this many seconds.","in":"query","name":"wait","required":false,"schema":{"default":0,"maximum":60,"minimum":0,"type":"integer"}}],"responses":{"200":{"content":{"application/json":{"schema":{"items":{"$ref":"#/components/schemas/VaultItemEvent"},"type":"array"}}},"description":"Ordered vault item audit events"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"404":{"$ref":"#/components/responses/NotFound"},"500":{"$ref":"#/components/responses/InternalError"}},"security":[{"bearerAuth":[]}],"summary":"List immutable audit events for a vault item","tags":["Vaults"]}},"/vaults/{id_or_name}/items/{key}/operations":{"post":{"description":"Retrieve the item first and invoke only an operation listed in\n`available_operations`, following its natural-language description.\nAvailability is rechecked at execution time; unavailable operations return 409.\nAuthorization and preparation may call an external provider and return updated state.\nLink cards advertise authorize without checkout context. Eligible unused\nAgentCard cards advertise prepare_checkout, which requires checkout context\nand obtains device approval before native Square Pay. Keep the returned\napproval page open, poll until ready_to_submit, then submit before\npreparation.expires_at. Unused preparations expire automatically and cannot\nbe reused. If spend-request creation is rejected with a non-retryable\nprovider error, the card item is deleted and the provider's error code and\nmessage are returned. Rate limits return HTTP 429 and retain the card item;\nstop, back off, and retry the same authorize operation.\n\nFill returns a value-free execution result. Validation failures before\nwriting return 400 (invalid request or targets), 403 (access or destination\ndenied), 404 (resource not found), or 409 (item or browser not ready).\nOnce writing starts, known partial failures and indeterminate field outcomes\nreturn 200 with status `failed` or `unknown`, not an automatic-retry signal.\nA transport error may leave the outcome unknown; do not automatically retry.\n","operationId":"postVaultItemOperation","parameters":[{"in":"path","name":"id_or_name","required":true,"schema":{"type":"string"}},{"in":"path","name":"key","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"examples":{"agentcard_prepare_checkout":{"summary":"Prepare an unused AgentCard card that advertises this operation","value":{"checkout":{"browser_id":"browser-session-id","environment":"production","merchant_origin":"https://shop.example.com"},"type":"prepare_checkout"}},"link_authorize":{"summary":"Authorize a Link card that advertises this operation","value":{"type":"authorize"}},"one_password_fill":{"summary":"Fill and submit an approved 1Password login","value":{"browser_id":"browser-session-id","page_url":"https://example.com/login","type":"1pw_fill"}},"one_password_recover":{"summary":"Recover a failed 1Password account link","value":{"type":"1pw_recover"}},"one_password_request_access":{"summary":"Request a 1Password credential through a Kernel browser","value":{"browser_id":"browser-session-id","goal":"Manage a SaaS subscription","keywords":["personal"],"reason":"Cancel the subscription","type":"1pw_create_access_request"}}},"schema":{"$ref":"#/components/schemas/VaultItemOperationRequest"}}},"required":true},"responses":{"200":{"content":{"application/json":{"examples":{"link_authorize":{"$ref":"#/components/examples/ExampleLinkApproval"}},"schema":{"$ref":"#/components/schemas/VaultItemOperationResponse"}}},"description":"Authorization or preparation completed or resumed, or fill execution outcomes returned"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"404":{"$ref":"#/components/responses/NotFound"},"409":{"$ref":"#/components/responses/Conflict"},"429":{"$ref":"#/components/responses/TooManyRequests"},"500":{"$ref":"#/components/responses/InternalError"},"503":{"$ref":"#/components/responses/ServiceUnavailable"}},"security":[{"bearerAuth":[]}],"summary":"Perform an operation advertised by a vault item","tags":["Vaults"]}}},"security":[{"bearerAuth":[]}],"servers":[{"description":"API Server","url":"https://api.onkernel.com"}],"tags":[{"description":"Search the web and retrieve content for selected results.","name":"Search"},{"description":"Create and manage browser sessions.","name":"Browsers"},{"description":"Control mouse, keyboard, and screen on the browser instance.","name":"Browser Computer Controls"},{"description":"Execute Playwright code against the browser instance.","name":"Browser Playwright"},{"description":"Execute JavaScript in the browser instance's persistent Browser REPL.","name":"Browser REPL"},{"description":"Discover and invoke native page tools across the browser instance.","name":"Browser WebMCP"},{"description":"Read, write, and manage files on the browser instance.","name":"Browser Filesystem"},{"description":"Execute and manage processes on the browser instance.","name":"Browser Processes"},{"description":"Record and manage browser session video replays.","name":"Browser Replays"},{"description":"Stream logs from the browser instance.","name":"Browser Logs"},{"description":"Stream live telemetry events from a browser session, and manage the destinations sessions export them to.","name":"Browser Telemetry"},{"description":"Create, list, retrieve, and delete browser profiles.","name":"Profiles"},{"description":"Create and manage proxy configurations for routing browser traffic.","name":"Proxies"},{"description":"Create, list, retrieve, and delete browser extensions.","name":"Extensions"},{"description":"Create and manage browser pools for acquiring and releasing browsers.","name":"Browser Pools"},{"description":"Inspect the identity and authorization context for the current request.","name":"Authentication"},{"description":"Create and manage auth connections for automated credential capture and login.","name":"Managed Auth"},{"description":"Create and manage credentials for authentication.","name":"Credentials"},{"description":"Configure external credential providers like 1Password.","name":"Credential Providers"},{"description":"List applications and versions.","name":"Apps"},{"description":"Create and manage app deployments and stream deployment events.","name":"Deployments"},{"description":"Invoke actions and stream or query invocation status and events.","name":"Invocations"},{"description":"Read and manage organization-level limits.","name":"Organization"},{"description":"Create and manage projects for resource isolation within an organization.\nWhen projects are disabled for the organization, project operations return\n`404` with code `projects_disabled`.\n","name":"Projects"},{"description":"Create and manage API keys for organization and project-scoped access.","name":"API Keys"},{"description":"Read audit log records for the authenticated organization.","name":"Audit Logs"},{"description":"Resolve browser and proxy recommendations for bot-protected sites.","name":"Config Registry"}],"x-service-info":{"categories":["browsers"],"docs":{"apiReference":"https://www.kernel.sh/docs","homepage":"https://www.kernel.sh","llms":"https://api.onkernel.com/llms.txt"}}}