Suna 0.12 adds per-session connector scoping, denied-secret enforcement, and a unified audit trail
Kortix shipped Suna 0.12.0 on August 1 and 0.12.1 on August 2, and the theme is agent least-privilege rather than capability. New sessions can start with an explicit opt-in scope over connectors and secrets; agents can require connector profiles, profiles carry an authorization strategy, and denied secrets never enter the sandbox at all. Approval prompts now show full tool arguments and approval policies match on arguments rather than just tool names — closing a real gap where approving "run_sql" approved every query. It also lands a centralized audit log of every API request and agent action with client attribution, per-session cost records, and sandboxes with a bounded lifetime billed against liveness evidence instead of wall clock.
↳ Follow the thread