add managed auth tools (manage_auth_connections, manage_credentials, manage_credential_providers)#104
add managed auth tools (manage_auth_connections, manage_credentials, manage_credential_providers)#104masnwilliams wants to merge 4 commits into
Conversation
…manage_credential_providers) Closes the largest agent-facing capability gap in the MCP server: setting up an authenticated browser session for a third-party site. Agents can now drive Kernel's managed auth flow end-to-end. - manage_auth_connections: create/list/get/delete connections; start login flows (returns hosted_url + live_view_url); submit MFA codes or SSO selections when a flow is awaiting input. - manage_credentials: read-only (list, get, totp_code). Credentials are created by humans via dashboard/CLI so the agent never sees raw secrets in its context — it references credentials by name. - manage_credential_providers: read-only (list, get) for external providers like 1Password. Same human-creates / agent-consumes pattern.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Monitoring Plan: Add managed-auth and credentials MCP toolsWhat this PR does: Registers three new MCP tool handlers — Intended effect: After deploy, AI agents using the MCP server can invoke these three tools. Successful calls will appear as spans on the already-active Kernel API backend endpoints ( Risks:
Status updates will be posted automatically on this PR as monitoring progresses. |
Cursor Bugbot caught that we were sending invalid credential payloads when only credential_path or credential_auto was provided without credential_provider. Add upfront validation so the agent gets a clear MCP-level error instead of a generic API rejection.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 4aa97f9. Configure here.
Cursor Bugbot follow-up: credential_auto=false was treated as a valid provider variant, and credential_path + credential_auto: true were silently allowed together. Only credential_auto: true now counts as a provider mode, and path/auto are enforced as mutually exclusive.

Summary
Closes the largest agent-facing capability gap in the MCP server: setting up an authenticated browser session for a third-party site. Agents can now drive Kernel's managed auth flow end-to-end without a human in the loop (beyond the one-time hosted login).
What's added
manage_auth_connections(full surface)create— start managing auth for a profile + domain (optionally referencing a pre-stored credential by name, or an external provider like 1Password)list/get/deletelogin— kicks off a hosted login flow. Returnshosted_url(share with the user to sign in) andlive_view_url(agent can watch). Triggers automatic re-auth if credentials are saved.submit— provide field values, an MFA option ID, or an SSO button selector when the flow isawaiting_input. Agent inspectsdiscovered_fields/mfa_optionsfromgetto know what's needed.manage_credentials(read-only)list/get(SDK never returns values) /totp_code(current 6-digit code)manage_credential_providers(read-only)list/getfor external providers (e.g. 1Password). Same human-creates / agent-consumes pattern.Agent flow
netflix-masoncredential in the Kernel dashboard.manage_auth_connections create domain=netflix.com profile_name=mason credential_name=netflix-masonmanage_auth_connections login id=<conn_id>→ shareshosted_urlwith user, or proceeds via re-auth.manage_auth_connections getuntilflow_status=SUCCESS(orflow_step=AWAITING_INPUTfor MFA).manage_credentials totp_code <name>→manage_auth_connections submit fields={mfa_code: "123456"}.manage_browsers create profile_name=masongets a logged-in session.Test plan
manage_auth_connections listreturns existing connections for the authed usermanage_auth_connections create+loginreturns a working hosted URLmanage_credentials listreturns names;totp_codereturns a 6-digit code for a TOTP-enabled credentialmanage_credential_providers listreturns configured providers (or empty list)Tool count
Bumps from 10 → 13.
Note
Medium Risk
New auth/credential/TOTP surfaces touch login and secrets handling; design limits agent writes to credentials but login/submit and totp_code still need careful API behavior in production.
Overview
Adds managed auth to the MCP server so agents can drive Kernel login flows for third-party sites on profiles, without agents storing secrets.
manage_auth_connectionswires toclient.auth.connections: create (profile + domain, optional Kernel credential name or external provider path/auto), list/get/delete, login (hosted URL + live view), and submit for MFA fields, MFA option, or SSO selector. Create validates mutually exclusive credential options and optional proxy routing.manage_credentialsis read-only (list,get,totp_code) — no create/update/delete so raw secrets stay out of agent context.manage_credential_providersis read-only (list,get) for org-configured providers (e.g. 1Password).README updates the advertised tool count from 10 → 13. The diff also includes minor formatting on existing
computer_actionschemas and error text.Reviewed by Cursor Bugbot for commit 9affca9. Bugbot is set up for automated code reviews on this repo. Configure here.