@@ -38941,6 +39596,53 @@ pub enum SessionLogLevel {
Unknown,
}
+/// A channel accepted by managedSettings.compose.
+///
+///
+///
+/// **Experimental.** This type is part of an experimental wire-protocol surface
+/// and may change or be removed in future SDK or CLI releases.
+///
+///
+#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
+pub enum ManagedSettingsChannel {
+ /// Device policy, the strongest channel.
+ #[serde(rename = "device")]
+ Device,
+ /// Account or organization policy.
+ #[serde(rename = "server")]
+ Server,
+ /// Session-local helper output, the weakest channel.
+ #[serde(rename = "policyHelper")]
+ PolicyHelper,
+ /// Unknown variant for forward compatibility.
+ #[default]
+ #[serde(other)]
+ Unknown,
+}
+
+/// Severity of a managed-settings validation finding.
+///
+///
+///
+/// **Experimental.** This type is part of an experimental wire-protocol surface
+/// and may change or be removed in future SDK or CLI releases.
+///
+///
+#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
+pub enum ManagedSettingsDiagnosticSeverity {
+ /// The runtime rejects the document.
+ #[serde(rename = "error")]
+ Error,
+ /// The runtime accepts the document but ignores the flagged content.
+ #[serde(rename = "warning")]
+ Warning,
+ /// Unknown variant for forward compatibility.
+ #[default]
+ #[serde(other)]
+ Unknown,
+}
+
/// Allowed values for the `McpAppsHostContextDetailsAvailableDisplayMode` enumeration.
///
///
@@ -39890,6 +40592,28 @@ pub enum McpPlanInstallResult {
Unavailable(CatalogUnavailableError),
}
+/// The sender role of an MCP prompt message.
+///
+///
+///
+/// **Experimental.** This type is part of an experimental wire-protocol surface
+/// and may change or be removed in future SDK or CLI releases.
+///
+///
+#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
+pub enum McpPromptRole {
+ /// A message from the user.
+ #[serde(rename = "user")]
+ User,
+ /// A message from the assistant.
+ #[serde(rename = "assistant")]
+ Assistant,
+ /// Unknown variant for forward compatibility.
+ #[default]
+ #[serde(other)]
+ Unknown,
+}
+
/// Outcome of the sampling inference. 'success' produced a response; 'failure' encountered an error (including agent-side rejection by content filter or criteria); 'cancelled' the caller cancelled this execution via cancelSamplingExecution.
///
///
diff --git a/rust/src/generated/rpc.rs b/rust/src/generated/rpc.rs
index 3c810588ab..cf87a42bd1 100644
--- a/rust/src/generated/rpc.rs
+++ b/rust/src/generated/rpc.rs
@@ -1352,7 +1352,7 @@ pub struct ClientRpcManagedSettings<'a> {
}
impl<'a> ClientRpcManagedSettings<'a> {
- /// Discovers device-managed settings from production MDM and managed-file sources, validates them against the runtime-owned managed-settings schema, and returns the canonical JSON without requiring a session.
+ /// Discovers device-managed settings from production MDM and managed-file sources, validates them against the runtime-owned managed-settings schema, and returns the canonical JSON without requiring a session. `managedSettings.resolve` returns the same device settings together with the account's server policy.
///
/// Wire method: `managedSettings.read`.
///
@@ -1376,7 +1376,7 @@ impl<'a> ClientRpcManagedSettings<'a> {
Ok(serde_json::from_value(_value)?)
}
- /// Force-refreshes enterprise managed settings for every account: wipes the persistent server-policy cache (the whole `
/managed-settings` directory) and drops this runtime process's in-memory retained server policy. It does not itself fetch policy — the effect is that the next time a session resolves managed settings for an account, that resolution re-fetches the account's org policy from the network instead of serving a cached response. Note that `managedSettings.read` returns only device/MDM settings and never triggers the account server-policy fetch, so a host implementing "sync account policy" should start a fresh session resolution rather than treat a subsequent `managedSettings.read` as the refreshed org policy. Mirrors the invalidation a sign-out performs, broadened from the one signing-out account to all of them; device/MDM layers describe the machine, not the account, and are left untouched. Rejects if the on-disk cache cannot be removed.
+ /// Force-refreshes enterprise managed settings for every account: wipes the persistent server-policy cache (the whole `/managed-settings` directory) and drops this runtime process's in-memory retained server policy. It does not itself fetch policy — the effect is that the next time a session resolves managed settings for an account, that resolution re-fetches the account's org policy from the network instead of serving a cached response. Note that `managedSettings.read` returns only device/MDM settings and never triggers the account server-policy fetch, so a host implementing "sync account policy" should call `managedSettings.resolve` or start a fresh session resolution rather than treat a subsequent `managedSettings.read` as the refreshed org policy. Mirrors the invalidation a sign-out performs, broadened from the one signing-out account to all of them; device/MDM layers describe the machine, not the account, and are left untouched. Rejects if the on-disk cache cannot be removed.
///
/// Wire method: `managedSettings.clearCache`.
///
@@ -1395,6 +1395,147 @@ impl<'a> ClientRpcManagedSettings<'a> {
.await?;
Ok(())
}
+
+ /// Resolves the effective enterprise managed settings without a session, from the device channel and, when an account is available, the account's server policy through the same per-account cache sessions use. A cached server policy less than an hour old is used without a fetch; otherwise the policy is fetched, and when the fetch fails a cached policy up to 24 hours old is used instead, unless `forceRemoteSettingsRefresh` requires a live fetch. With no account requested or signed in, it reports device policy only; signing out removes the account's cached policy. It can fetch server policy over the network when the cache is stale, so call it off latency-critical paths such as startup rather than before listing models. The policy helper is not run. `layers` lists each channel's document before merging, and `values` and `meta` carry typed effective values and their lock state for the keys typed so far.
+ ///
+ /// Wire method: `managedSettings.resolve`.
+ ///
+ /// # Returns
+ ///
+ /// Effective enterprise managed settings for an account, resolved without a session.
+ ///
+ ///
+ ///
+ /// **Experimental.** This API is part of an experimental wire-protocol surface
+ /// and may change or be removed in future SDK or CLI releases. Pin both the
+ /// SDK and CLI versions if your code depends on it.
+ ///
+ ///
+ pub async fn resolve(&self) -> Result {
+ let wire_params = serde_json::json!({});
+ let _value = self
+ .client
+ .call(rpc_methods::MANAGEDSETTINGS_RESOLVE, Some(wire_params))
+ .await?;
+ Ok(serde_json::from_value(_value)?)
+ }
+
+ /// Resolves the effective enterprise managed settings without a session, from the device channel and, when an account is available, the account's server policy through the same per-account cache sessions use. A cached server policy less than an hour old is used without a fetch; otherwise the policy is fetched, and when the fetch fails a cached policy up to 24 hours old is used instead, unless `forceRemoteSettingsRefresh` requires a live fetch. With no account requested or signed in, it reports device policy only; signing out removes the account's cached policy. It can fetch server policy over the network when the cache is stale, so call it off latency-critical paths such as startup rather than before listing models. The policy helper is not run. `layers` lists each channel's document before merging, and `values` and `meta` carry typed effective values and their lock state for the keys typed so far.
+ ///
+ /// Wire method: `managedSettings.resolve`.
+ ///
+ /// # Parameters
+ ///
+ /// * `params` - Optional opaque account selection or GitHub token whose managed settings are resolved.
+ ///
+ /// # Returns
+ ///
+ /// Effective enterprise managed settings for an account, resolved without a session.
+ ///
+ ///
+ ///
+ /// **Experimental.** This API is part of an experimental wire-protocol surface
+ /// and may change or be removed in future SDK or CLI releases. Pin both the
+ /// SDK and CLI versions if your code depends on it.
+ ///
+ ///
+ pub async fn resolve_with_params(
+ &self,
+ params: ManagedSettingsResolveRequest,
+ ) -> Result {
+ let wire_params = serde_json::to_value(params)?;
+ let _value = self
+ .client
+ .call(rpc_methods::MANAGEDSETTINGS_RESOLVE, Some(wire_params))
+ .await?;
+ Ok(serde_json::from_value(_value)?)
+ }
+
+ /// Returns the managed-settings authoring JSON schema with descriptive `x-composition` annotations aligned with the shared settings-engine vocabulary. These annotations are not a complete runtime composition contract: model, effortLevel, and contextTier remain coupled. Use `managedSettings.compose` for the runtime's effective result. Performs no I/O.
+ ///
+ /// Wire method: `managedSettings.schema`.
+ ///
+ /// # Returns
+ ///
+ /// The authoring JSON schema for managed settings recognized by this runtime.
+ ///
+ ///
+ ///
+ /// **Experimental.** This API is part of an experimental wire-protocol surface
+ /// and may change or be removed in future SDK or CLI releases. Pin both the
+ /// SDK and CLI versions if your code depends on it.
+ ///
+ ///
+ pub async fn schema(&self) -> Result {
+ let wire_params = serde_json::json!({});
+ let _value = self
+ .client
+ .call(rpc_methods::MANAGEDSETTINGS_SCHEMA, Some(wire_params))
+ .await?;
+ Ok(serde_json::from_value(_value)?)
+ }
+
+ /// Validates a candidate managed-settings document the way the runtime validates delivered policy, without applying it. Reports errors that would reject the document, warnings for content the runtime ignores, and the canonical document it would apply. Document text nested more than 64 levels deep is rejected. Performs no I/O.
+ ///
+ /// Wire method: `managedSettings.validate`.
+ ///
+ /// # Parameters
+ ///
+ /// * `params` - A candidate managed-settings document to validate without applying it.
+ ///
+ /// # Returns
+ ///
+ /// Result of validating a managed-settings document.
+ ///
+ ///
+ ///
+ /// **Experimental.** This API is part of an experimental wire-protocol surface
+ /// and may change or be removed in future SDK or CLI releases. Pin both the
+ /// SDK and CLI versions if your code depends on it.
+ ///
+ ///
+ pub async fn validate(
+ &self,
+ params: ManagedSettingsValidateRequest,
+ ) -> Result {
+ let wire_params = serde_json::to_value(params)?;
+ let _value = self
+ .client
+ .call(rpc_methods::MANAGEDSETTINGS_VALIDATE, Some(wire_params))
+ .await?;
+ Ok(serde_json::from_value(_value)?)
+ }
+
+ /// Merges candidate managed-settings documents for the device, server, and policy-helper channels into the effective settings the runtime would enforce on this host, using the same precedence and composition rules as live resolution, without applying them. Like live resolution, a server's advisory sandbox force-enable is declined on a host that cannot run the sandbox. Does not fetch policy or read policy files, but may perform blocking OS or subprocess probes for sandbox support. Preview documents are limited to 1 MiB and 64 levels of nesting.
+ ///
+ /// Wire method: `managedSettings.compose`.
+ ///
+ /// # Parameters
+ ///
+ /// * `params` - Candidate managed-settings documents to merge without applying them.
+ ///
+ /// # Returns
+ ///
+ /// The effective managed settings the runtime would enforce for the given documents, in the same shape `managedSettings.resolve` returns.
+ ///
+ ///
+ ///
+ /// **Experimental.** This API is part of an experimental wire-protocol surface
+ /// and may change or be removed in future SDK or CLI releases. Pin both the
+ /// SDK and CLI versions if your code depends on it.
+ ///
+ ///
+ pub async fn compose(
+ &self,
+ params: ManagedSettingsComposeRequest,
+ ) -> Result {
+ let wire_params = serde_json::to_value(params)?;
+ let _value = self
+ .client
+ .call(rpc_methods::MANAGEDSETTINGS_COMPOSE, Some(wire_params))
+ .await?;
+ Ok(serde_json::from_value(_value)?)
+ }
}
/// `mcp.*` RPCs.
@@ -5820,6 +5961,34 @@ impl<'a> SessionRpcConnectors<'a> {
Ok(serde_json::from_value(_value)?)
}
+ /// Returns the session account selection, or null.
+ ///
+ /// Wire method: `session.connectors.getAccount`.
+ ///
+ /// # Returns
+ ///
+ /// Session account selection, or null.
+ ///
+ ///
+ ///
+ /// **Experimental.** This API is part of an experimental wire-protocol surface
+ /// and may change or be removed in future SDK or CLI releases. Pin both the
+ /// SDK and CLI versions if your code depends on it.
+ ///
+ ///
+ pub async fn get_account(&self) -> Result {
+ let wire_params = serde_json::json!({ "sessionId": self.session.id() });
+ let _value = self
+ .session
+ .client()
+ .call(
+ rpc_methods::SESSION_CONNECTORS_GETACCOUNT,
+ Some(wire_params),
+ )
+ .await?;
+ Ok(serde_json::from_value(_value)?)
+ }
+
/// Returns authoritative session Connector state from current availability, pinned account selection, cached catalog, and live MCP projection without performing a Connector service request.
///
/// Wire method: `session.connectors.getStatus`.
@@ -6082,6 +6251,41 @@ impl<'a> SessionRpcConnectors<'a> {
Ok(serde_json::from_value(_value)?)
}
+ /// Reconciles the authoritative cached or freshly requested Connector catalog into the session Connector MCP projection and returns live status.
+ ///
+ /// Wire method: `session.connectors.reconcile`.
+ ///
+ /// # Parameters
+ ///
+ /// * `params` - Requests authoritative Connector-to-MCP reconciliation for the pinned account.
+ ///
+ /// # Returns
+ ///
+ /// Authoritative session connector state. Account IDs are opaque routing identifiers and credentials are never included.
+ ///
+ ///
+ ///
+ /// **Experimental.** This API is part of an experimental wire-protocol surface
+ /// and may change or be removed in future SDK or CLI releases. Pin both the
+ /// SDK and CLI versions if your code depends on it.
+ ///
+ ///
+ ///
+ /// Accepts [`ConnectorReconcileOptions`], including inputs added after [`ConnectorReconcileRequest`].
+ pub async fn reconcile_with_options(
+ &self,
+ params: ConnectorReconcileOptions,
+ ) -> Result {
+ let mut wire_params = serde_json::to_value(params)?;
+ wire_params["sessionId"] = serde_json::Value::String(self.session.id().to_string());
+ let _value = self
+ .session
+ .client()
+ .call(rpc_methods::SESSION_CONNECTORS_RECONCILE, Some(wire_params))
+ .await?;
+ Ok(serde_json::from_value(_value)?)
+ }
+
/// Reconciles the authoritative Connector catalog into the session MCP projection during startup with a bounded deadline and fail-closed cleanup.
///
/// Wire method: `session.connectors.reconcileForStartup`.
@@ -7452,7 +7656,7 @@ impl<'a> SessionRpcManagedSettings<'a> {
///
/// # Returns
///
- /// Enterprise managed-settings resolution: the effective managed settings the session applied and which channels contributed, so SDK clients can show users what is enterprise-managed. Fires whenever managed policy is (re)applied — at session start, on resume, and on account switch. This is an ephemeral live snapshot (delivered to subscribers but not persisted to the session event log), because at session start it resolves before `session.start` is emitted. Device values take precedence over server values, then the policy helper, per ordinary key, while permissions compose restrictively across device, server, policy-helper, and SDK-client layers. The account-scoped `getManagedSettings()` API does not include session-local client injection. Marked experimental while the managed-settings surface stabilizes.
+ /// Effective enterprise managed settings and contributing channels. Session events report applied policy; sessionless resolve reports an account/device snapshot, and compose reports a non-applying preview of candidate documents. Device values take precedence over server values, then the policy helper, per ordinary key, while permissions compose restrictively. Session-local SDK-client policy is included only in session results. Marked experimental while the managed-settings surface stabilizes.
///
///
///
@@ -7500,6 +7704,13 @@ impl<'a> SessionRpcMcp<'a> {
}
}
+ /// `session.mcp.prompts.*` sub-namespace.
+ pub fn prompts(&self) -> SessionRpcMcpPrompts<'a> {
+ SessionRpcMcpPrompts {
+ session: self.session,
+ }
+ }
+
/// `session.mcp.resources.*` sub-namespace.
pub fn resources(&self) -> SessionRpcMcpResources<'a> {
SessionRpcMcpResources {
@@ -8550,7 +8761,7 @@ impl<'a> SessionRpcMcpOauth<'a> {
///
/// # Parameters
///
- /// * `params` - Remote MCP server name and optional overrides controlling reauthentication, OAuth client display name, callback success-page copy, and static OAuth client selection.
+ /// * `params` - Remote MCP server name and optional overrides controlling reauthentication, OAuth client display name, callback handling, and static OAuth client selection.
///
/// # Returns
///
@@ -8580,7 +8791,7 @@ impl<'a> SessionRpcMcpOauth<'a> {
///
/// # Parameters
///
- /// * `params` - Remote MCP server name and optional overrides controlling reauthentication, OAuth client display name, callback success-page copy, and static OAuth client selection.
+ /// * `params` - Remote MCP server name and optional overrides controlling reauthentication, OAuth client display name, callback handling, and static OAuth client selection.
///
/// # Returns
///
@@ -8609,6 +8820,32 @@ impl<'a> SessionRpcMcpOauth<'a> {
Ok(serde_json::from_value(_value)?)
}
+ /// Completes a runtime-managed MCP OAuth login after the authorization server redirects to a host-managed callback URL.
+ ///
+ /// Wire method: `session.mcp.oauth.complete`.
+ ///
+ /// # Parameters
+ ///
+ /// * `params` - Host-delivered callback for a runtime-managed MCP OAuth login.
+ ///
+ ///
+ ///
+ /// **Experimental.** This API is part of an experimental wire-protocol surface
+ /// and may change or be removed in future SDK or CLI releases. Pin both the
+ /// SDK and CLI versions if your code depends on it.
+ ///
+ ///
+ pub async fn complete(&self, params: McpOauthCompleteRequest) -> Result<(), Error> {
+ let mut wire_params = serde_json::to_value(params)?;
+ wire_params["sessionId"] = serde_json::Value::String(self.session.id().to_string());
+ let _value = self
+ .session
+ .client()
+ .call(rpc_methods::SESSION_MCP_OAUTH_COMPLETE, Some(wire_params))
+ .await?;
+ Ok(())
+ }
+
/// Passively probes a configured remote MCP server to classify whether OAuth is required or a cached/override token is accepted. Does not start OAuth, emit pending OAuth requests, or mutate MCP connection state.
///
/// Wire method: `session.mcp.oauth.probe`.
@@ -8744,6 +8981,74 @@ impl<'a> SessionRpcMcpOauth<'a> {
}
}
+/// `session.mcp.prompts.*` RPCs.
+#[derive(Clone, Copy)]
+pub struct SessionRpcMcpPrompts<'a> {
+ pub(crate) session: &'a Session,
+}
+
+impl<'a> SessionRpcMcpPrompts<'a> {
+ /// Enumerate one page of prompts a connected MCP server exposes (proxies MCP `prompts/list`). Pass `cursor` to continue from a prior result's `nextCursor`.
+ ///
+ /// Wire method: `session.mcp.prompts.list`.
+ ///
+ /// # Parameters
+ ///
+ /// * `params` - MCP server whose prompts to enumerate.
+ ///
+ /// # Returns
+ ///
+ /// One page of prompts advertised by the named MCP server.
+ ///
+ ///
+ ///
+ /// **Experimental.** This API is part of an experimental wire-protocol surface
+ /// and may change or be removed in future SDK or CLI releases. Pin both the
+ /// SDK and CLI versions if your code depends on it.
+ ///
+ ///
+ pub async fn list(&self, params: McpPromptsListRequest) -> Result
{
+ let mut wire_params = serde_json::to_value(params)?;
+ wire_params["sessionId"] = serde_json::Value::String(self.session.id().to_string());
+ let _value = self
+ .session
+ .client()
+ .call(rpc_methods::SESSION_MCP_PROMPTS_LIST, Some(wire_params))
+ .await?;
+ Ok(serde_json::from_value(_value)?)
+ }
+
+ /// Get a prompt's messages from a connected MCP server (proxies MCP `prompts/get`). Content is preserved as opaque JSON. Does not send messages to the model, execute tools, or fetch referenced resources.
+ ///
+ /// Wire method: `session.mcp.prompts.get`.
+ ///
+ /// # Parameters
+ ///
+ /// * `params` - MCP server, prompt name, and optional string-valued arguments.
+ ///
+ /// # Returns
+ ///
+ /// Prompt messages returned by the MCP server without sending them to the model.
+ ///
+ ///
+ ///
+ /// **Experimental.** This API is part of an experimental wire-protocol surface
+ /// and may change or be removed in future SDK or CLI releases. Pin both the
+ /// SDK and CLI versions if your code depends on it.
+ ///
+ ///
+ pub async fn get(&self, params: McpPromptsGetRequest) -> Result {
+ let mut wire_params = serde_json::to_value(params)?;
+ wire_params["sessionId"] = serde_json::Value::String(self.session.id().to_string());
+ let _value = self
+ .session
+ .client()
+ .call(rpc_methods::SESSION_MCP_PROMPTS_GET, Some(wire_params))
+ .await?;
+ Ok(serde_json::from_value(_value)?)
+ }
+}
+
/// `session.mcp.resources.*` RPCs.
#[derive(Clone, Copy)]
pub struct SessionRpcMcpResources<'a> {
@@ -12363,17 +12668,17 @@ pub struct SessionRpcShell<'a> {
}
impl<'a> SessionRpcShell<'a> {
- /// Starts a shell command and streams output through session notifications. The command runs as the leader of its own process group (POSIX) or in a dedicated job object (Windows), so a forced termination — via "shell.kill", the request timeout, or session disposal — signals that whole group/job rather than only the direct child. Two gaps are worth planning for: a command that exits on its own does not trigger that teardown, and on POSIX a descendant that moves itself into a new session or process group (for example via "setsid") leaves the signalled group, so either can leave a background process running.
+ /// Starts a shell command, returning an RPC error if it cannot be spawned. The command runs as the leader of its own process group (POSIX) or in a dedicated job object (Windows), so a forced termination — via "shell.kill", the request timeout, or session disposal — signals that whole group/job rather than only the direct child. Two gaps are worth planning for: a command that exits on its own does not trigger that teardown, and on POSIX a descendant that moves itself into a new session or process group (for example via "setsid") leaves the signalled group, so either can leave a background process running.
///
/// Wire method: `session.shell.exec`.
///
/// # Parameters
///
- /// * `params` - Shell command to run, with optional working directory and timeout in milliseconds.
+ /// * `params` - Shell command to run, with optional working directory and timeout in milliseconds. Spawn failures return an RPC error.
///
/// # Returns
///
- /// Identifier of the spawned process, used to correlate streamed output and exit notifications.
+ /// Identifier of the spawned shell process, usable with shell.kill while the process is running.
///
///
///
diff --git a/rust/src/generated/session_events.rs b/rust/src/generated/session_events.rs
index 2d7992d30b..00a479147a 100644
--- a/rust/src/generated/session_events.rs
+++ b/rust/src/generated/session_events.rs
@@ -3749,6 +3749,10 @@ pub struct PromptCacheBreakData {
#[doc(hidden)]
#[serde(skip_serializing_if = "Option::is_none")]
pub(crate) tools_redefined: Option>,
+ /// Changed definition parts of redefined tools, as `tool:part` entries; property-level parts only for telemetry-safe tools, whose other names are hashed
+ #[doc(hidden)]
+ #[serde(skip_serializing_if = "Option::is_none")]
+ pub(crate) tools_redefined_parts: Option