/** * AI Connection Encryption Service * * Provides AES-256-GCM encryption/decryption for AI connection secrets * (`apiKey`, `googleCredentialsBase64`). Secrets are encrypted before storage in * Neo4j and decrypted only when the resolver builds a candidate — they are never * serialised back over the API. * * Mirrors {@link TotpEncryptionService} (the in-package AES-256-GCM canonical), * keyed from `encryption.key` (ENCRYPTION_KEY) instead of the TOTP key. * * Format: IV (12 bytes) + AuthTag (16 bytes) + Ciphertext (base64 encoded) */ export declare class AiConnectionEncryptionService { private readonly algorithm; private readonly ivLength; private readonly authTagLength; /** * Whether a key is configured at all. Writing a secret without one must fail * loudly at the admin API (fail-closed on write, fail-open on read). */ isConfigured(): boolean; /** * Get the encryption key from config. * The key must be exactly 32 bytes (256 bits) for AES-256. */ private getKey; /** * Encrypt an AI connection secret using AES-256-GCM. * * @param plaintext - The secret to encrypt (API key or base64 GCP credentials) * @returns The encrypted secret as a base64-encoded string containing IV, auth tag, and ciphertext */ encrypt(plaintext: string): string; /** * Decrypt an AI connection secret encrypted with AES-256-GCM. * * @param ciphertext - The base64-encoded encrypted secret (IV + AuthTag + Ciphertext) * @returns The decrypted secret * @throws Error if decryption fails (invalid key, corrupted data, or tampered data) */ decrypt(ciphertext: string): string; /** * Verify that the encryption system is properly configured. * Performs a round-trip encryption/decryption test. * * @returns true if encryption is working correctly * @throws Error if encryption is not properly configured */ verify(): boolean; } //# sourceMappingURL=ai-connection-encryption.service.d.ts.map