/** * `spectral login` — interactive authentication against the Aexol MCP backend. * * Flow: * 1. Choose auth method: Team API key or OAuth (browser). * 2a. API key: prompt for team API key (masked input). Verify the * sk-aexol-team- prefix locally so we don't send obviously-wrong * credentials. The API URL is taken from env or the hard default. * 2b. OAuth: open browser for Aexol Studio authorization. * 3. Verify reachability + auth by calling tools/list against the URL. * 4. On success: persist to ~/.spectral/config.json (mode 0600). * 5. Chain OAuth to also obtain a user JWT for Studio features. * * Exits non-zero on any failure so shell scripts can detect it. * * NOTE: pure logic lives in `performLogin` — the interactive `runLogin` * wrapper delegates to it after collecting prompts. Tests target * `performLogin` directly so we don't have to drive `@inquirer/prompts`. */ export interface PerformLoginOptions { apiUrl: string; teamApiKey: string; } export interface PerformLoginResult { toolCount: number; } /** * Pure login logic. Throws `Error` with one of these stable message prefixes: * - "Invalid API key prefix" — local validation failed * - "Invalid token" — server returned 401/403 * - "Authentication failed" — server rejected the request (other 4xx/5xx) * - "Could not reach" — network error (DNS, refused connection, timeout) * * Tests assert on these substrings. */ export declare function performLogin(opts: PerformLoginOptions): Promise; export declare function runLogin(): Promise; //# sourceMappingURL=login.d.ts.map