Skip to content

Commit 4595975

Browse files
eclairenclaude
andcommitted
Add August 13 changelog entry
Cover the MCP server OAuth and tooling work, the Vercel Connect registry connector, the nested browser proxy object, private browser networking, managed auth browser configuration, stealth fingerprint coherence, profile_save_changes, egress reliability fixes, and CLI v0.27.0-v0.29.0. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
1 parent 1c323c7 commit 4595975

1 file changed

Lines changed: 23 additions & 0 deletions

File tree

‎changelog.mdx‎

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,29 @@ import { YouTubeVideo } from '/snippets/youtube-video.mdx';
99
For API library updates, see the [Node SDK](https://github.com/onkernel/kernel-node-sdk/blob/main/CHANGELOG.md), [Python SDK](https://github.com/onkernel/kernel-python-sdk/blob/next/CHANGELOG.md), and [Go SDK](https://github.com/onkernel/kernel-go-sdk/blob/main/CHANGELOG.md) changelogs.
1010
</Note>
1111

12+
<Update label="August 13" tags={["Product", "Docs"]}>
13+
## Product updates
14+
15+
- Expanded the [MCP server](/reference/mcp-server) with a branded OAuth consent flow: PKCE is now required for new clients, project-scoped access tokens are supported, and the consent, scope-selection, and loading screens have all been polished. MCP tools now accept project name or ID (not just ID), project selection is optional for org-wide connections, and org-wide connections can select a project at connect time.
16+
- Improved the [MCP server](/reference/mcp-server): long-running browser operations no longer retry on transient errors, `manage_browsers get_telemetry` supports bounded raw page reads, and app invocations now return an invocation ID immediately instead of blocking, with a new `list_invocation_browsers` action that returns the session ID and live-view URL for browsers the invocation created. Every tool that creates, reads, or deletes a Kernel resource now follows the same lifecycle contract as the API, and a rejected credential returns `401` instead of `500`.
17+
- Kernel is now a connector in the [Vercel Connect](https://vercel.com/connect) registry. `vercel connect create kernel --connection-method mcp` pre-fills the MCP URL, auth type, and branding, and brokers per-user OAuth so no Kernel API key touches your app. Connectors created before the registry entry keep working.
18+
- Added a nested `proxy` object to the browser API, taking exactly one of `mode`, `id`, or `name`, with the resolved [proxy](/proxies/overview) state returned on browser responses. Egress and stealth are now independent: an explicit proxy changes only where traffic exits and never toggles stealth or the CAPTCHA solver, and `mode: "default"` restores the stealth-derived default. `proxy_id` and `disable_default_proxy` remain as deprecated aliases. Proxy routing is also now selectable in the dashboard.
19+
- Added [private browser networking](/browsers/private-networking): set `network.private_hosts` on a browser or browser pool to list the hosts and CIDRs Chrome should reach directly through the session's own network — for a VPN or tunnel running inside the VM — while all other traffic continues through Kernel-managed egress.
20+
- Expanded [managed auth](/auth/overview) with a nested `browser` configuration on connections covering `stealth`, `proxy`, and `telemetry`. Connection values become the defaults for login, re-auth, verification, and health-check browsers, and login-time values are session-only overrides. Setting `browser.stealth` to `false` lets a connection that doesn't need the CAPTCHA solver skip stealth mode entirely. The older `proxy`, `proxy_id`, and `browser_telemetry` fields are deprecated but still honored.
21+
- Improved fingerprint coherence in [stealth-mode browsers](/browsers/bot-detection/stealth): the WebGL renderer persona now applies on GPU-accelerated hosts as well as software-rendered ones, and storage quota, network information, and speech voices report plausible per-host values instead of fleet-wide constants.
22+
- Browser responses now include `profile_save_changes`, so you can tell which sessions loaded a [profile](/auth/profiles) read-write and coordinate a single writer instead of tracking that state yourself. Returned from browser create, list, get, and update.
23+
- Fixed several egress reliability issues: large downloads no longer truncate mid-body under backpressure, WebSocket upgrades and TURN traffic pass through unchanged so WebRTC media works, and origins that omit their intermediate certificate now verify by fetching the missing issuer the way Chrome does.
24+
- Extended the [CLI](https://github.com/kernel/cli) (v0.27.0–v0.29.0) with extension checksums in output, `--private-host` and `--clear-private-hosts` network flags, explicit clear controls for browser-pool proxy, profile, extensions, and Chrome policy (plus a preserved `--fill-rate 0`), and persistent OAuth project scope.
25+
26+
## Documentation updates
27+
28+
- Documented [private browser networking](/browsers/private-networking), including `private_hosts` semantics for browsers and browser pools.
29+
- Added [safe profile writes](/auth/profiles) and clarified the `save_changes` requirement for [per-user pool profiles](/browsers/pools).
30+
- Added a guide for [reading the static IP of an ISP proxy](/proxies/isp) via `ip_address`.
31+
- Switched managed auth examples to SSE and updated the Vercel Connect setup in the [Eve extension guide](/integrations/vercel/eve-extension) to use the Kernel connector registry entry. Also swapped the Claude Code integration to the official [Claude directory connector](/integrations/claude/claude-code-and-desktop).
32+
- Added kiosk mode as the first [viewport](/browsers/viewport) recommendation and clarified that viewport sets window size, not page viewport.
33+
</Update>
34+
1235
<Update label="August 7" tags={["Product", "Docs"]}>
1336
## Product updates
1437

0 commit comments

Comments
 (0)