Skip to content

Models: S

  • data: list[kindgi.client.ScheduleRecord]
  • next_cursor: str | None (nextCursor on the wire) (optional)
  • has_more: bool (hasMore on the wire)
  • schedule_id: str (scheduleId on the wire)
  • trigger_id: str (triggerId on the wire)
  • flow_id: str (flowId on the wire)
  • flow_version: str (flowVersion on the wire)
  • cron_expression: str (cronExpression on the wire)
  • timezone: str | None (optional)
  • input: Any | None (optional)
  • label: str | None
  • status: Literal['active', 'paused']
  • next_fire_at: AwareDatetime | None (nextFireAt on the wire)
  • last_fired_at: AwareDatetime | None (lastFiredAt on the wire)
  • created_at: AwareDatetime (createdAt on the wire)
  • updated_at: AwareDatetime (updatedAt on the wire)
  • schedule_id: str (scheduleId on the wire)
  • unregistered: bool

Discriminated Scope primitive (Tenant / Org / Project). Source of truth: Scope in @kindgi/platform.

  • kind: Literal['tenant']
  • tenant_id: str (tenantId on the wire)

Discriminated Scope primitive (Tenant / Org / Project). Source of truth: Scope in @kindgi/platform.

  • kind: Literal['org']
  • tenant_id: str (tenantId on the wire)
  • org_id: str (orgId on the wire)

Discriminated Scope primitive (Tenant / Org / Project). Source of truth: Scope in @kindgi/platform.

  • kind: Literal['project']
  • tenant_id: str (tenantId on the wire)
  • project_id: str (projectId on the wire)
  • data: list[kindgi.client.SecretRecord]
  • next_cursor: str | None (nextCursor on the wire) (optional)
  • data: list[kindgi.client.SecretRecord]
  • next_cursor: str | None (nextCursor on the wire) (optional)
  • scope: kindgi.client.Scope1 | kindgi.client.Scope2 | kindgi.client.Scope3
  • env_name: str (envName on the wire)
  • name: str
  • current_version: int (currentVersion on the wire)
  • created_at: AwareDatetime (createdAt on the wire)
  • updated_at: AwareDatetime (updatedAt on the wire)
  • revoked_at: AwareDatetime | None (revokedAt on the wire) (optional)
  • revoke_reason: str | None (revokeReason on the wire) (optional)
  • tags: dict[str, str] | None (optional)
  • rotation_due_at: AwareDatetime | None (rotationDueAt on the wire) (optional)

The tenant secret holding the adapter's credential (an API key, a service-account key). Absent when the adapter needs none or finds its own (a cloud's default credentials).

  • env_name: str (envName on the wire)
  • name: str
  • name: str
  • version_id: int (versionId on the wire)
  • value: str
  • revoked: bool
  • hard: bool
  • revoked: bool
  • hard: bool
  • root: kindgi.client.SecretRotateOutcome1 | kindgi.client.SecretRotateOutcome2
  • kind: Literal['ok']
  • new_version_id: int (newVersionId on the wire)
  • old_version_id: int (oldVersionId on the wire)
  • old_version_revoked_at: AwareDatetime | None (oldVersionRevokedAt on the wire) (optional)
  • kind: Literal['rotation-pending']
  • resume_token: str (resumeToken on the wire)
  • provider: str
  • scope: kindgi.client.Scope1 | kindgi.client.Scope2 | kindgi.client.Scope3 | None (optional)
  • env_name: str | None (envName on the wire) (optional)
  • new_value: str | None (newValue on the wire) (optional)
  • revoke_old_after_ms: int | None (revokeOldAfterMs on the wire) (optional)
  • kind: Literal['async']
  • rotation_id: uuid.UUID (rotationId on the wire)
  • status_url: str (statusUrl on the wire)
  • events_url: str (eventsUrl on the wire)
  • kind: Literal['sync']
  • new_version_id: int (newVersionId on the wire)
  • old_version_id: int (oldVersionId on the wire)
  • old_version_revoked_at: AwareDatetime | None (oldVersionRevokedAt on the wire) (optional)
  • scope: kindgi.client.Scope1 | kindgi.client.Scope2 | kindgi.client.Scope3
  • env_name: str (envName on the wire)
  • name: str
  • value: str
  • write_mode: Literal['create-new', 'add-version'] (writeMode on the wire)
  • tags: dict[str, str] | None (optional)
  • rotation_due_at: AwareDatetime | None (rotationDueAt on the wire) (optional)
  • if_version: int | None (ifVersion on the wire) (optional)
  • root: kindgi.client.SecretSetOutcome1 | kindgi.client.SecretSetOutcome2 | kindgi.client.SecretSetOutcome3 | kindgi.client.SecretSetOutcome4
  • kind: Literal['ok']
  • record: kindgi.client.SecretRecord
  • version_id: int (versionId on the wire)
  • kind: Literal['already-exists']
  • record: kindgi.client.SecretRecord
  • kind: Literal['version-conflict']
  • current_version: int (currentVersion on the wire)
  • kind: Literal['error']
  • code: str
  • message: str
  • scope: kindgi.client.Scope1 | kindgi.client.Scope2 | kindgi.client.Scope3
  • env_name: str (envName on the wire)
  • name: str
  • value: str
  • write_mode: Literal['create-new', 'add-version'] (writeMode on the wire)
  • tags: dict[str, str] | None (optional)
  • rotation_due_at: AwareDatetime | None (rotationDueAt on the wire) (optional)
  • if_version: int | None (ifVersion on the wire) (optional)
  • record: kindgi.client.SecretRecord
  • version_id: int (versionId on the wire)
  • data: list[kindgi.client.SecretVersionRecord]
  • next_cursor: str | None (nextCursor on the wire) (optional)
  • scope: kindgi.client.Scope1 | kindgi.client.Scope2 | kindgi.client.Scope3
  • env_name: str (envName on the wire)
  • name: str
  • version_id: int (versionId on the wire)
  • created_at: AwareDatetime (createdAt on the wire)
  • value: str | None (optional)
  • revoked_at: AwareDatetime | None (revokedAt on the wire) (optional)
  • name: str
  • ref: str
  • name: str
  • value: str

Runtime-side signature attached at emission time (if the deployment signs on write). Independent of the export-time signature returned by the export route.

  • algorithm: Literal['ed25519']
  • key_id: str (keyId on the wire)
  • value: str
  • signed_at: AwareDatetime (signedAt on the wire)
  • algorithm: Literal['ed25519']
  • key_id: str (keyId on the wire)
  • value: str
  • signed_at: AwareDatetime (signedAt on the wire)

Signed exportable bundle. bundle is base64 of the exact bytes that were signed (sorted-key canonical JSON, no whitespace); verifiers can pass those bytes directly to verifyEd25519. Bundle body: { bundleSchemaVersion, tenantId, filter, records, recordCount, exportedAt }. Envelope shape identical to ExportProvenanceResult + audit-bundle — verifiers reuse one verifyEd25519 wrapper across all three surfaces.

  • bundle_schema_version: Literal['1.0.0'] (bundleSchemaVersion on the wire)
  • tenant_id: uuid.UUID (tenantId on the wire)
  • bundle: str
  • algorithm: Literal['ed25519']
  • signing_key_id: str (signingKeyId on the wire)
  • signature: str
  • public_key: str (publicKey on the wire)
  • canonicalization: Literal['sorted-key-json']
  • exported_at: AwareDatetime (exportedAt on the wire)
  • ttl_seconds: int | None (ttlSeconds on the wire) (optional)
  • last_verified_at: AwareDatetime | None (lastVerifiedAt on the wire) (optional)
  • etag: str | None (optional)
  • source_version: str | None (sourceVersion on the wire) (optional)
  • strategy: Literal['on-read', 'background', 'manual']
  • handler: str | None (optional)
  • priority: int | None (optional)

Exactly one of agentRef or flowRef MUST be supplied. dryRun: true returns a plan preview without invoking the subject.

  • project_id: uuid.UUID (projectId on the wire)
  • agent_ref: kindgi.client.EvalRunAgentRef | None (agentRef on the wire) (optional)
  • flow_ref: kindgi.client.EvalRunFlowRef | None (flowRef on the wire) (optional)
  • dry_run: bool | None (dryRun on the wire) (optional)
  • correlation_id: str | None (correlationId on the wire) (optional)
  • run_id: uuid.UUID (runId on the wire)
  • dry_run_preview: dict[str, Any] | None (dryRunPreview on the wire) (optional)
  • root: kindgi.client.StartRunBody1 | kindgi.client.StartRunBody2

Start a run. Exactly one of agent or flow MUST be supplied (single Run primitive).

  • agent: str
  • agent_version: str | None (agentVersion on the wire) (optional)
  • project_id: uuid.UUID | None (projectId on the wire) (optional)
  • input: Any
  • options: kindgi.client.Options | None (optional)

Start a run. Exactly one of agent or flow MUST be supplied (single Run primitive).

  • flow: str
  • flow_version: str | None (flowVersion on the wire) (optional)
  • project_id: uuid.UUID | None (projectId on the wire) (optional)
  • input: Any
  • options: kindgi.client.Options | None (optional)
  • dry_run: bool | None (dryRun on the wire) (optional)
  • wait: bool | None (optional)
  • kind: str | None (optional)
  • id: str | None (optional)

Body is optional — omit to accept every default. requiredRole overrides the auto-derivation (meta-fixes → senior). expiresAt sets the HITL approval deadline.

  • required_role: Optional[Literal['standard', 'senior', 'admin']] (requiredRole on the wire) (optional)
  • expires_at: AwareDatetime | None (expiresAt on the wire) (optional)
  • proposal: kindgi.client.FixProposal
  • approval_id: uuid.UUID (approvalId on the wire)
  • meta_fix: bool (metaFix on the wire)
  • min: int
  • max: int
  • fact_id: str (factId on the wire)
  • superseded: Literal[True]