manage_vault_cards reference the wallet by key.
Hosted connection and enrollment steps are for the user to complete. Never ask for card data or OAuth codes in chat.
Actions
Parameters
Link spec
For KERNEL-managed OAuth, the user completes the Link connection at the returneditem.action.url:
client.type to customer_managed, reference a provider configuration by exactly one id or name, and pass a tokens object with access_token and refresh_token from the same grant. Supply tokens from a trusted backend, never through chat. After import, KERNEL owns refresh-token rotation.
AgentCard spec
Pass{} to enroll with KERNEL-managed credentials. Optionally set provider_config to use your own configuration, or user_id (usr_...) to reuse an AgentCard user already enrolled under the same configuration.
Example
manage_vault_items (action: "get", wait: 30). Once it’s connected, list payment methods:
payment_method_id explicitly with the user; never choose the default automatically. Capabilities are advisory: an absent capability means unknown, not ineligible.
A duplicate create never replaces a wallet’s grant, and bindings can’t change. To reauthorize, obtain a fresh grant under a new wallet key for new payments, and keep the old wallet for reconciling unresolved payments.