# Kite Developer Docs > Kite is agentic payment infrastructure. Kite Agent Passport gives AI agents identity, delegated payment authority, and onchain settlement. ## Endpoints - Sharded full content (per collection): - https://docs.gokite.ai/llms/docs.txt - https://docs.gokite.ai/llms/changelog.txt - https://docs.gokite.ai/llms/api-reference.txt - https://docs.gokite.ai/llms/blog.txt - Full corpus (capped at 2 MiB): https://docs.gokite.ai/llms-full.txt - MCP server (read-only): https://docs.gokite.ai/mcp - Sitemap: https://docs.gokite.ai/sitemap.xml --- # Merchant fee estimates in session preflight URL: https://docs.gokite.ai/changelog/2026/2026-05-19-backend-v1-1-0 ## What changed When an agent constructs a session delegation, the preflight call now returns an `estimated_fees` object covering the catalog's known merchant fees, network gas, and Passport's own service margin. Approval pages can show users an itemized "up to ~$X" total instead of just a raw budget cap. This estimate is informational only — actual fees still come from the merchant at transaction time — but it makes high-budget sessions less surprising and reduces post-approval support questions. **Included changes:** - feat(session): return estimated_fees in preflight response - feat(catalog): track per-service fee metadata --- # Filter activity by date and merchant URL: https://docs.gokite.ai/changelog/2026/2026-05-19-cli-v1-3-4 ## What changed The `kpass activity` command previously returned the full event history with no way to narrow the result set. Agents asking "what did I spend on Amazon last week?" had to fetch everything and filter locally, which was slow on accounts with many sessions. You can now pass `--since YYYY-MM-DD`, `--until YYYY-MM-DD`, and `--merchant ` to filter on the server side. Results are paginated, and the JSON envelope adds a `truncated: true` flag when the result set hits the page limit. **Included changes:** - feat(activity): add --since/--until/--merchant flags - fix(activity): respect --output json with truncation indicator --- # request-session retries preflight on catalog errors URL: https://docs.gokite.ai/changelog/2026/2026-05-19-skills-v0-9-1 ## What changed `request-session` previously treated any non-200 response from the catalog preflight as a hard failure, which meant transient catalog blips would abort otherwise-valid session approvals. The skill now retries 503 and timeout responses up to three times with exponential backoff before propagating the error. Approval cancellations attributable to catalog flakiness should drop noticeably. Permanent errors (404 service-not-found, 403 unauthorized) are still surfaced immediately so agents don't waste time retrying. **Included changes:** - feat(request-session): retry preflight on 503/timeout - docs(request-session): document the retry behavior in SKILL.md --- # Estimated fees on session approval URL: https://docs.gokite.ai/changelog/2026/2026-05-19-web-v1-2-0 ## What changed The session approval page now renders the new `estimated_fees` field from the backend preflight. Users see the budget cap and an itemized "up to ~$X" estimate covering merchant fees, network gas, and Passport's service margin. The estimate is labeled as informational; the underlying budget cap still controls actual spending. We added a small "what counts as a fee?" tooltip to explain the breakdown. **Included changes:** - feat(approval): render estimated_fees breakdown - feat(approval): add fee-breakdown tooltip --- # Submit agent feedback from the CLI URL: https://docs.gokite.ai/changelog/2026/2026-05-27-cli-1-3-20 ## What changed The CLI now exposes a `kpass feedback submit` command that allows agents to send structured feedback without leaving the terminal. This is useful for programmatic reporting — an agent can flag a failed payment, unexpected behavior, or a feature request as part of its normal workflow. The command accepts a message payload and returns a confirmation from the server. A new `cmd/agent/feedback/` package handles input validation and the submission flow, while the API client layer has been extended with a dedicated feedback endpoint. The existing `kpass help` output has been updated to surface the new subcommand. **Included changes:** - feat: added agent feedback (#49) ([#49](https://github.com/gokite-ai/passport-cli/pull/49)) --- # Internal changelog workflow and dependency updates URL: https://docs.gokite.ai/changelog/2026/2026-05-28-cli-v1-3-21 ## What changed This release introduces a `changelog-on-release` GitHub Actions workflow that automates changelog entry generation when a new release tag is pushed. A Dependabot configuration file is also added to manage future automated dependency updates.\n\nThe only other changes are a patch bump to the npm package version and its corresponding lock file update. No CLI commands, flags, API client behavior, or output formats were modified. **Included changes:** - fix: bump version to 1.3.21 (#55) ([#55](https://github.com/gokite-ai/passport-cli/pull/55)) - fix(changelog): address code review comments - feat(changelog): update changelog workflow - feat: add changelog workflow --- # Passkey security overhaul: step-up, recovery, login history, USD session caps URL: https://docs.gokite.ai/changelog/2026/2026-06-04-backend-v1-3-0 ## What changed High-risk actions now require a fresh passkey assertion bound to the exact operation. `wallet.send`, `agent_session.approve`, `passkey.register.additional`, and `passkey.remove` each have a `/stepup` preflight that issues an HMAC token committing to action type, target resource, and a canonical parameter hash; the WebAuthn challenge is set to `SHA-256(token)` and a persisted step-up session prevents replay. Each enforcement point has a `Disable*StepUp` config flag for operator rollback, and all four step-ups emit activity events that drive a new `GET /v1/security/stepup-log` audit endpoint (filterable by `all`, `agent_approve`, `wallet`, `passkey`). Agent session caps are now USD-denominated. The `Assets` token allowlist is gone from session delegation — the agent never names a settlement token. Sessions carry a server-stamped `Currency` field (default `USD`), and the merchant chooses the settlement stablecoin at transaction time. Tool params and swagger have been reworded to USD/budget language; CLI and skill USD changes follow separately. Account recovery for the lost-passkey case ships behind `POST /v1/recovery/{start,cancel,complete}` and `GET /v1/recovery/status`. `start` flips the account to `recovery_pending` (which `GetUserPasskeyReadiness` exposes, naturally blocking high-risk actions), `complete` enforces a configurable delay (72h prod default, 10m in nonprod) and atomically revokes credentials plus other auth sessions in a single transaction. The recovery-started email carries a one-shot HMAC cancel link bound to the user and `RecoveryStartedAt`; clicking it lands on a confirmation page and cancellation happens via explicit POST so link previews and prefetch can't silently cancel. All five lifecycle events (passkey added/disabled, cooldown started, recovery started/completed) now render through a shared branded HTML template with a plain-text fallback. A `login_events` table now records every `/v1/login/verify` attempt with derived device, browser, and MaxMind-resolved city/country (IP is not stored). Users can read their own history via `GET /v1/security/login-log` with `since`/`until`/`limit`/`offset` and a 90-day default. On top of this, first-passkey enrollment now evaluates risk: when the registering session's device, browser, and country are all unseen versus the user's prior successful logins, enrollment is held (`403 ErrPasskeyEnrollmentRiskHold` at `POST /v1/passkey/register/options`, before WebAuthn options are returned) and a security email is sent. The hold lifts on a familiar re-login or after the cooldown window. `GET /v1/passkey` lists a user's credentials with a richer display name (`Platform passkey (synced, built-in) @ Mac · Chrome`), and `POST /v1/passkey/delete` soft-disables credentials so they stay in the audit trail but no longer count toward readiness. `GET /v1/me` now surfaces `passkey_readiness` so clients can drive gating from a single call. Both `login_events` and `first_passkey_risk` are gated by config flags and ship enabled in `base.yaml`; the GeoLite2-City database is bundled into the Docker image. **Included changes:** - refactor(agent): make session caps USD-denominated, drop token allowlist - chore(config): shorten recovery & first-passkey-risk cooldowns to 10m in nonprod - fix: address security review findings - feat(passkey): richer display name with humanized transports - docs(passkey): align login-history web surface with implemented columns - docs(recovery): align cancel-email subject with confirm flow + document GET landing - fix(recovery): require explicit POST to cancel recovery via email link - docs(passkey): correct stale step-up challenge comment and risk-hold endpoint - feat(passkey): derive and expose passkey display metadata - fix(recovery): accept cancel links without started_at - feat(security): brand security notification emails with shared HTML template - fix(passkey): use singular login_event table name in partial index migration - fix(passkey): review nits — empty cancel-URL fallback, doc comment, docs - fix(passkey): run first-passkey risk gate before the step-up check - fix(passkey): bind first-passkey risk to the exact session + gate at begin - docs(passkey): align remaining design docs with implemented risk model - feat(passkey): implement first-passkey enrollment risk hold + enable flags - fix(recovery): claim recovery atomically before destructive revoke - login_events: fix dev startup - default tag must quote the literal, make migration self-healing - config: add stepup + recovery default stanzas to base.yaml - login_events: review followups - close geoip on stop, partial email index, rune-safe truncate - login_events: P1/P2 review fixes (defaults, EOF whitespace, evaluator ctx) - go mod tidy: promote useragent + geoip2 to direct deps - login_events: schema + ingestion + GET /v1/security/login-log + first-passkey-risk flag - docs(passkey): add login-history + first-passkey-risk design + bundle GeoLite2 - passkey: soft-disable credentials on delete + load exclusions from DB - swagger: fix /mcp empty-responses + enum-tag ActivityEvent fields - address Round 12 review findings on passkey-improve - address 8 review findings on passkey-improve - release agent_session request claim on post-claim error - fix two findings: premature approved status, swagger drift - fix three race + state-persistence findings from 2026-05-26 review - fix three verified bugs from review 2026-05-26 - add DisableAgentSessionApproveStepUp config flag - send email notifications on passkey lifecycle + recovery, with cancel link - backend fixes from passkey-improve review (H1-3, M1, M5, L2-3) - bind passkey.register.additional and passkey.remove to WebAuthn - bind wallet.send to a persisted WebAuthn step-up session - enable wallet.send and additional-passkey step-up by default - add GET /v1/security/stepup-log for the Security page audit panel - add recovery flow for lost-passkey + email-in-hand case - add POST /v1/passkey/delete with passkey.remove step-up - persist passkey cooldown state on the user and consult it in readiness - require step-up to add another passkey when one already exists - add wallet.send step-up token flow - bind agent_session.approve to action-bound step-up token - add GET /v1/passkey to list user's registered passkeys - add step-up activity kinds and recordStepUpEvent helper - add pkg/stepup for action-bound HMAC tokens - add passkey trust state and account readiness computation - add prod design doc for passkey-improvement - refine syntax - add thread-model for current email-otp + passkey design - refine Account States - add passkey-based security evolution plan --- # Release 2026-06-11 URL: https://docs.gokite.ai/changelog/2026/2026-06-11-release ## New features - **Security: step-up verification, passkey management, and account recovery.** Sensitive actions — sending funds, approving agent sessions, adding or removing passkeys — now require a quick passkey re-confirmation. Lost your passkey? You can now recover your account via email, with a one-click cancel link if it wasn't you. Passkey changes trigger email notifications, and your passkeys now show device names so you can tell them apart. - **Sign-in and security history.** Review recent sign-ins (time, location, device) and a log of all security verifications, so unfamiliar activity is easy to spot. - **Protocol-agnostic session negotiation.** Sessions can now be created and used regardless of which payment protocol a target service advertises. The session layer negotiates the protocol from the service response at runtime, so your agent code does not need to change when a service adds or changes payment protocols. This applies to both the CLI and the skills runtime. - **Per-endpoint pricing in search results.** The search tool now surfaces pricing details at the individual endpoint level. You can see the cost of each specific endpoint before making a request, rather than only seeing aggregate service-level pricing. - **Agent feedback.** Agents can now send feedback to us directly — reporting what worked, what didn't, and anything that got in their way — so we can spot rough edges and improve the platform faster. ## Improvements - **Correct user-agent headers on outbound requests.** Both the CLI (`kpass`) and the search tool (`ksearch`) now send a properly identified user-agent header on all outbound HTTP requests, fixing request attribution on services that key on the user-agent for rate-limiting or analytics. - **Quickstart paths and examples corrected.** The quickstart guide now reflects current installation paths and removes stale code examples that would fail on a fresh install. - **Skill loading optimized.** The skills runtime now applies load-time optimization, reducing overhead for agents that use multiple skills. ## Bug fixes - **Bundled `ksearch` binary is now locatable without repository access.** In environments where the private repository is not accessible — such as CI pipelines, fresh installs, or contributor setups — the skills package previously failed to locate its bundled `ksearch` binary. It is now found via a relative path that does not require repository credentials. --- # Release 2026-06-17 URL: https://docs.gokite.ai/changelog/2026/2026-06-17-release ## Improvements - **Quickstart paths and examples corrected.** The quickstart guide now reflects current installation paths and removes stale examples that would fail on a fresh setup. ## Bug fixes - **Windows installer no longer fails when resolving the latest version.** On Windows, installing or upgrading could fail with a type error while the installer determined the latest available version. Version resolution is now handled correctly, so installs and upgrades complete as expected. If a previous install failed at this step, re-run the installer to pick up the fix. --- # Release 2026-06-23 URL: https://docs.gokite.ai/changelog/2026/2026-06-23-release ## New features - **Cloud-project provisioning.** You can now provision and manage a dedicated cloud project end to end. Create a project, fund it from your Kite wallet with a passkey approval, retrieve deploy credentials and a ready-to-run deploy command, then pause, resume, or delete it as needed. Spend is metered against the project's prepaid credit, so costs stay bounded. The `kpass cloud project` command group drives the full lifecycle from the CLI. - **Sandbox test mode.** A new isolated test environment lets you exercise agent payment flows without touching live data or real funds. Switching into sandbox mode gives you a testnet wallet and a faucet for test tokens, with sessions, payments, and activity kept fully separate from your production account — so you can validate an integration before going live. - **Step-up browser approval for wallet sends.** When sending funds requires step-up verification, you can now complete the passkey approval in your browser. The approval page shows the transfer amount, asset, recipient, and sending wallet before you confirm, then reports the outcome with the transaction hash. This works from both the web app and the CLI — the CLI hands off a browser approval link and reports the result back. To get the CLI flow, upgrade to the latest `kpass` (Bundle 32) via `cli.gokite.ai`. - **Connect Passport to ChatGPT over MCP.** A hosted MCP endpoint with OAuth lets you add Kite Passport as a connector in ChatGPT and other MCP clients. Once connected and authorized, your agent can discover and pay for x402 services and create and list spending sessions directly from the chat client. - **Solana settlement for x402 payments.** Agents can now pay merchants whose x402 services settle on Solana. Payment is collected from your Kite wallet as usual, and settlement to the merchant is handled automatically in USDC — extending paid-service reach beyond EVM with no change to how you authorize spend. ## Improvements - **13 new services reachable for x402 payments.** The x402 service catalog gained 13 newly allowlisted hosts, now live, so agents can pay them without requesting manual allowlisting. The additions span media generation (image and video, text-to-speech, memes), social and web data, file hosting, print-on-demand, travel data, IP geolocation, and crypto data. No action is needed — the new services are reachable now. --- # Release 2026-07-01 URL: https://docs.gokite.ai/changelog/2026/2026-07-01-release ## New features - **Redesigned dashboard.** The dashboard has been rebuilt around your spending sessions and now shows live data instead of static views. From one place you can review active sessions and their limits, see Transaction History for your account, and drill into a session's activity. Visiting `/dashboard` now sends you to the new `/overview`; the previous dashboard has been retired. - **Create and attach spending sessions from the browser.** A new create-session page lets you set up an attachable spending session directly in the dashboard. Sessions now surface whether they are attached or unattached, and their session id is one click to copy for use with an agent. - **Deploy a project to Google Cloud from a skill.** A new `cloud-deploy` skill provisions and deploys a local project to Google Cloud through `kpass cloud`, so an agent can take a project from your machine to a running cloud deployment end to end. To get the skill, upgrade to the latest `kpass`. ## Improvements - **Editable session budgets.** You can now edit a session's Max budget and Max-per-transaction limits directly in the dashboard instead of recreating the session. - **Activity categories and per-session filtering.** Account activity is now grouped into transaction, security, and lifecycle categories and can be filtered to a single session, making it easier to trace what an individual agent session did. - **Clearer merchant payment-decline details.** When a merchant declines an x402 payment, the response now carries the specific decline reason instead of an opaque error, so agents can react to and report why a payment did not go through. - **Test mode in the dashboard.** The sandbox test environment is now integrated into the dashboard, so you can switch into test mode and exercise payment flows with test funds without leaving the UI. ## Bug fixes - **Session spend now displays the correct dollar amount.** A session's spent total is now scaled by the settlement token's decimals, using the backend-provided display unit when available. Previously the amount could show raw token units rather than the actual dollar value. --- # Release 2026-07-08 URL: https://docs.gokite.ai/changelog/2026/2026-07-08-release ## New features - **Cross-chain payment routing.** x402 payments can now settle on a chain other than the one holding your funds — Passport automatically bridges and routes across Base, Tempo, and Solana, so you no longer have to move assets to the right chain before paying. - **Redesigned session dashboard with route timelines.** The dashboard has been rebuilt around your spending sessions and now shows a full timeline for routed payments — chain logos, bridged amounts, explorer links, and token logos for USDC and PYUSD — alongside session detail views. - **`kpass cloud` command group.** A new set of CLI commands drives the full cloud-project lifecycle — create, fund, provision, and deploy — directly from `kpass`. ## Improvements - **More reliable cross-chain routing.** Routing now considers the full set of bridge and swap candidates, treats a class of previously-fatal routing errors as transient and retryable, and applies a wider minimum cost-ratio cap for small cross-chain payments, so more small payments route successfully. - **Routing details in transaction history.** Transaction rows and account activity now show routing analytics and per-chain detail for routed payments. - **Per-chain activity in the CLI.** `kpass` activity logs now show which chain each transaction settled on, and CLI output detection is aligned with the server's responses. - **Skill docs updated for multichain.** The Passport skills bundle's docs and examples now reflect multichain payments and routing. ## Bug fixes - **Fixed cross-chain payments timing out on slow routes.** Payments routed through Solana or Tempo could occasionally fail with a gateway error when the cross-chain leg ran long. The write deadline has been restored so these payments now complete normally. - **Fixed incorrect activity rows for routed checkouts.** Activity entries for checkouts that used cross-chain routing now record correctly. - **Fixed dashboard overview clipping and sandbox balance display.** The overview page no longer clips content, and the sandbox environment now shows single-asset balances correctly. - **Restored sub-cent balance precision.** Balances that previously rounded away fractions of a cent now display full precision. - **Fixed CLI parsing when a colon command follows global flags.** `kpass` commands using the `resource:action` form now parse correctly when preceded by global flags. ## Important updates - **Passport now supports settlement on Base.** Direct-pay and cross-chain routing now handle settlement directly, replacing the treasury relay path. If your integration relied on the treasury relay or assumed Kite as the settlement chain, update it to expect Base settlement. - **Agent wallet USDC balances now show on Base.** As part of enabling Base support, USDC held by mainnet agent wallets was bridged 1:1 to each wallet's corresponding Base address. Check balances on your Base address going forward. - **Upgrade required for the CLI and skills bundle.** This release requires kpass 1.6.0 and skills bundle 35 or later. Upgrade with `curl -fsSL https://cli.gokite.ai/install.sh | bash`. --- # Release 2026-07-15 URL: https://docs.gokite.ai/changelog/2026/2026-07-15-release ## New features - **Deposit via Halliday.** A new onramp flow lets you deposit funds through Halliday. Deposits now appear in the account activity feed. - **Multi-offer merchant payments now complete end-to-end.** Passport parses 402 responses offering multiple payment options (e.g. Anthropic) and negotiates payment using the newer session protocol these merchants require. - **Binary merchant responses are now supported.** Raw binary media (audio, image, video) is returned as base64, and the CLI's `--output-file` flag saves it directly to disk. - **Vendor information on catalog pages.** API catalog pages now show vendor details for each listed service. - **Updated skill guidance for catalog-first, multichain workflows.** - **Agent session IDs are now abbreviated** (prefix…suffix) throughout the dashboard. ## Bug fixes - **Fixed paid requests stalling on wallet-identity challenges.** Merchants requiring a sign-in wallet-identity challenge before execution no longer stall the request — async jobs like video generation can poll for results without a second charge. - **Fixed deposits not appearing in balance immediately.** The balance cache now invalidates as soon as a settlement webhook confirms a deposit, fixing a display race. - **Fixed partner embed token delivery.** Embed tokens now pass via URL fragment and resolve with an `X-Embed-Token` header instead of a query parameter; reload behavior for embedded flows is documented. - **Fixed the session approval screen showing the requested TTL instead of the approved one.** - **Fixed error messages dropping the merchant's response body** on failed Tempo executions. - **Fixed per-transaction routing cap enforcement** to account for merchant and overhead costs. - **Fixed a scope-prefix matching bug** that could incorrectly match subtree scopes. - **Routed payment executes now return a normalized `payment_requirement`.** ## Important updates - **Upgrade the CLI.** This release requires Bundle 40 (kpass 1.9.0, ksearch 1.0.6, skills 1.6.3): `curl -fsSL https://cli.gokite.ai/install.sh | bash` --- # Release 2026-07-22 URL: https://docs.gokite.ai/changelog/2026/2026-07-22-release ## New features - **Robinhood Chain support, end-to-end.** Hold and send USDG on Robinhood Chain (chain ID 4663), with gas-sponsored sends/receives and automatic USDC→USDG routing. - **Guided first-run onboarding** for new dashboard users: welcome → install → guided tour. - **Active/History session tabs** in the dashboard. - **Richer catalog listings.** `service_endpoint` entries now include `example_request`, `probe_status`, and `pitfalls` fields. ## Improvements - **More precise headline balance**, now shown to two decimal places. - **Unattached-session guidance** in the dashboard for sessions not yet attached to an agent. - **Failed-route errors now include the merchant's response body** for easier debugging. - **Catalog data quality fixes**: merchant-info and facet fixes; fal.ai listings now correctly flagged image-only, with video-generation warnings. - **Passport Skills is now open source**, published from the public [gokite-ai/passport-skills](https://github.com/gokite-ai/passport-skills) repo, with new Robinhood wallet-ops docs. ## Bug fixes - **Fixed the Halliday deposit widget** — an unsupported wallet-type value was blocking deposits. - **Fixed a settlement-timing gap in agent-session payments** [security] that could allow repricing between detection and settlement; payments now settle in a single round trip. ## Important updates - **Passkey registration now requires a resident (discoverable) credential.** Existing passkeys may need re-registration; enrollment guidance to follow. - **Upgrade the CLI and skills bundle** to Bundle 42 (cli 1.9.2, ksearch 1.0.7, skills 1.7.1): `curl -fsSL https://cli.gokite.ai/install.sh | bash` --- # Release 2026-07-29 URL: https://docs.gokite.ai/changelog/2026/2026-07-29-release ## New features - **Clearer guidance on supported Receive assets.** Wallet Receive now shows which assets are supported for each network, making it easier to avoid sending unsupported deposits. - **Warnings against sending native gas tokens.** Receive flows now warn when a native gas token isn't supported for deposit, helping prevent lost transfers. - **Wallet-receive guidance extended to agent workflows.** Passport Skills now surface the same Receive guidance so agents get the same warnings as the dashboard. ## Improvements - **Backend dependency updates** improve reliability, security, and compatibility. - **More consistent wallet instructions** between the Passport web dashboard and the agent-facing Passport Skills guidance. ## Bug fixes - **Clarified the gas-sponsored Receive experience**, making it easier to confidently pick the correct asset and network for gas-sponsored deposits. ## Important updates - **Upgrade the CLI and skills bundle** to Bundle 43 (kpass 1.9.2, ksearch 1.0.7, skills 1.7.2): `curl -fsSL https://cli.gokite.ai/install.sh | bash`