import { ProcessorCostEstimateBasis, BillingProfileResponse, ProjectResponse, ShopResponse, PaymentResponse, RefundStatus, SettlementCostPeriod, VaultEnvironment, RequestFn, AuthResponse, SignUpWithMerchantIdRequest, JsonExportOptions, ExportEnvelope, BinaryExportOptions, ExportOptions, PaymentAttemptsListResponse, PaymentStatusHistoryResponse, RefundListResponse, AnalyticsScopeRequest, AnalyticsScopeResponse, ClientAnalyticsRequest, DevicesAnalyticsResponse, GeoAnalyticsResponse, GeoDrillRequest, DrillResponse, DeviceDrillRequest, ScopeDrillRequest, SubscriptionAnalyticsRequest, SubscriptionAnalyticsResponse, SubscriptionDrillRequest, MerchantAccountResponse, MerchantAccountUpdateRequest, ProfileResponse, SellToRestrictionsResponse, CheckoutBrowserInfoScopeResponse, UpdateCheckoutBrowserInfoScopeRequest, PaymentsDeleteResponse, PaymentClientContextListResponse, ProcessorCostEventsResponse, ProcessorCostScheduleResponse, CreateProcessorCostScheduleRequest, BulkCreateProcessorCostSchedulesRequest, UpdateProcessorCostScheduleRequest, ReplaceProcessorCostScheduleRequest, SettlementStatementListParams, SettlementStatementListResponse, FeeStatementDetail, StatementPdfParams, RequestExtras, SettlementOverviewParams, SettlementOverviewResponse, SettlementCurrentParams, SettlementCurrentResponse, PlatformFeeRuleInput, PlatformFeeRuleRecord, FeeRulePreviewRequest, FeeRulePreviewResponse, FeeScheduleCreateRequest, FeeScheduleResponse, FeeScheduleUpdateRequest, Delopay } from './index.js'; export { AIRWALLEX_AUTOFILL_TREATMENTS, AIRWALLEX_CARD_LAYOUTS, AIRWALLEX_CARD_PRESETS, AIRWALLEX_CARD_PRESET_FALLBACK, AIRWALLEX_FIELD_CHROMES, AIRWALLEX_FIELD_FONT_SIZES, AIRWALLEX_FIELD_WEIGHTS, AIRWALLEX_FOCUS_RINGS, AIRWALLEX_LABEL_STYLES, AIRWALLEX_NETWORK_MARKS, ALL_CUSTOM_FIELD_CONDITION_SOURCES, ALL_CUSTOM_FIELD_OPERATORS, ALL_CUSTOM_FIELD_TYPES, APPLE_PAY_BUTTON_STYLES, APPLE_PAY_BUTTON_TYPES, AcceptInvitationsPreAuthRequest, AddUserRequest, AddUserResponse, Address, AddressDetails, AdoptSubscriptionRequest, AdoptSubscriptionResponse, AirwallexApplePayDomainResult, AirwallexApplePayDomainStatus, AirwallexApplePayDomainsRegisterRequest, AirwallexApplePayDomainsRegisterResponse, AirwallexAutofillTreatment, AirwallexCardField, AirwallexCardLayout, AirwallexCardPreset, AirwallexFieldChrome, AirwallexFieldFontSize, AirwallexFieldWeight, AirwallexFocusRing, AirwallexLabelStyle, AirwallexNetworkMark, AllocationListResponse, AllocationResponse, AllocationTransferRequest, AllocationTransferResponse, AmountFilter, AmountRange, Analytics, AnalyticsChannel, AnalyticsChild, AnalyticsConnectorDay, AnalyticsConnectorSeries, AnalyticsDashboard, AnalyticsDayBucket, AnalyticsExclusionKind, AnalyticsExclusionRequest, AnalyticsExclusionResponse, AnalyticsExclusionSurface, AnalyticsExclusionsResponse, AnalyticsGranularity, AnalyticsMethodSlice, AnalyticsOutcome, ApiKeyCreateRequest, ApiKeyCreateResponse, ApiKeyExpiration, ApiKeyListConstraints, ApiKeyResponse, ApiKeyRevokeResponse, ApiKeyUpdateRequest, ApplePayButtonStyle, ApplePayButtonType, ApplePayVerificationRequest, ApplePayVerificationResponse, ApplePayVerifiedDomainsResponse, AttemptStatus, Audit, AuthenticationCreateRequest, AuthenticationResponse, AuthenticationStatus, AuthenticationType, AutoRechargeConfig, AutoRechargeUpdateRequest, AvailabilityOverrideCreateRequest, AvailabilityOverrideResponse, AvailabilityOverrides, AvailabilityPreviewMethod, AvailabilityPreviewParams, AvailabilityPreviewResponse, AvailableCheckoutMethod, BRANDING_EXPORT_FORMAT, BRANDING_EXPORT_VERSION, BankCodeResponse, BankDebitTypes, BankTransferTypes, BillingCompleteSetupRequest, BillingSetupRequest, BillingSetupResponse, BlockedAttempt, BlockedAttemptListParams, BlockedAttemptListResponse, BlocklistAddRequest, BlocklistDataKind, BlocklistResponse, BrandingExport, BrandingSource, BrowserInfoScopeSetting, BuiltInRegionGroupResponse, BusinessPaymentLinkConfig, CARD_FIELD_CHROMES, CARD_FIELD_FONT_SIZES, CARD_FIELD_WEIGHTS, CARD_FOCUS_RINGS, CHECKBOX_CHECKED, CHECKBOX_UNCHECKED, CHECKOUT_EVENT_KINDS, CHECKOUT_LOCALES, CUSTOM_CSS_MAX_LENGTH, CUSTOM_FIELDS_MAX, CUSTOM_FIELD_CONDITIONS_MAX, CUSTOM_FIELD_KEY_PATTERN, CUSTOM_FIELD_OPERATORS_BY_SOURCE, CUSTOM_FIELD_VALUELESS_OPERATORS, CancelModeOutcome, CancelSubscriptionRequest, CancelSubscriptionResponse, CaptureMethod, CardDetail, CardDetailFromLocker, CardFieldChrome, CardFieldFontSize, CardFieldWeight, CardFocusRing, CardIssuingCountryEnforcement, CardNetworkTypes, CardReference, CardSpecificFeatures, Cards, ChangePasswordRequest, CheckoutBranding, CheckoutBrandingResponse, CheckoutBrandingUpdate, CheckoutCustomField, CheckoutDataResponse, CheckoutEventKind, CheckoutHeadingAlign, CheckoutHeadingLine, CheckoutHeadingTextCase, CheckoutHeadingTextSize, CheckoutHeadingTextTone, CheckoutHeadingTextWeight, CheckoutLocale, CheckoutMethodAccount, CheckoutMethodCoverage, CheckoutMethodHiddenReason, CheckoutMethodItem, CheckoutMethodKind, CheckoutMethodLayout, CheckoutMethodLayoutSource, CheckoutMethodOpenTarget, CheckoutMethodView, CheckoutMethodVisibility, CheckoutMethods, CheckoutMethodsResetResponse, CheckoutMethodsResponse, CheckoutMethodsUpdateRequest, CheckoutMethodsView, CheckoutNotice, CheckoutSession, CheckoutSessionOptions, CheckoutThemeComparisonSide, CheckoutThemeConversionCaveat, CheckoutThemeConversionCell, CheckoutThemeConversionComparison, CheckoutThemeConversionQuery, CheckoutThemeConversionResponse, CheckoutThemeConversionSegment, CheckoutThemeDenominatorBasis, CheckoutThemeDimension, CheckoutThemeOutput, CheckoutThemeProgram, CheckoutThemeProgramRequest, CheckoutThemeProgramResponse, CheckoutThemeRule, CheckoutThemeSampleVerdict, CheckoutWalletButtonColor, CheckoutWalletButtonType, ClientAnalyticsCaveat, ClientAnalyticsFilters, ClientDrillSortKey, ConditionNode, ConfirmSubscriptionPaymentDetails, ConfirmSubscriptionRequest, ConfirmSubscriptionResponse, Connector, ConnectorCapUnit, ConnectorCapWindow, ConnectorCapability, ConnectorCapabilityState, ConnectorCloneRequest, ConnectorCreateRequest, ConnectorFeatureMatrixEntry, ConnectorHealthCheck, ConnectorHealthCheckStatus, ConnectorHealthRequirements, ConnectorHealthResponse, ConnectorHealthState, ConnectorHealthUnknownReason, ConnectorIntegrationStatus, ConnectorListResponse, ConnectorOwnership, ConnectorResponse, ConnectorRisk, ConnectorSandboxMechanism, ConnectorSelection, ConnectorSettlementAttempt, ConnectorSettlementStatus, ConnectorType, ConnectorUpdateRequest, ConnectorVolumeSplit, ConnectorWebhookEntry, ConnectorWebhookEventType, ConnectorWebhookListResponse, ConnectorWebhookRegisterRequest, ConnectorWebhookRegisterResponse, ConnectorWebhookSyncResponse, ConnectorWebhookSyncResult, CornerRadius, CostRules, CreateAndConfirmSubscriptionRequest, CreateMerchantCostRuleRequest, CreateSubscriptionPaymentDetails, CreateSubscriptionRequest, Currency, CurrencyRevenue, CustomFieldCondition, CustomFieldConditionSource, CustomFieldContext, CustomFieldOperator, CustomFieldOption, CustomFieldTranslations, CustomFieldType, CustomFieldVisibility, CustomerCreateRequest, CustomerListParams, CustomerListResponse, CustomerListWithCountParams, CustomerPaymentMethodsListParams, CustomerPaymentMethodsListResponse, CustomerResponse, CustomerUpdateRequest, DEFAULT_BADGES, DEFAULT_BADGES_DARK, DEFAULT_BRANDING, DEFAULT_BRANDING_DARK, DEFAULT_NOTICES, DecidePendingOperationRequest, DeleteAccountRequest, DeleteEvidenceRequest, DeleteUserRoleRequest, DelopayAuthenticationError, DelopayConnectorCategory, DelopayError, DelopayLogger, DelopayOptions, DeviceAnalyticsChild, DeviceAnalyticsTotals, DeviceBrowserSlice, DeviceChannelBucket, DeviceClassSlice, DeviceDrillBase, DeviceDrillTarget, DeviceModelSlice, DevicePlatformSlice, DeviceSessionBucket, DisputeEvidenceBlock, DisputeEvidenceRequest, DisputeEvidenceType, DisputeExportRecord, DisputeListParams, DisputeOutcomeReporting, DisputeRefundAssociation, DisputeRefundAssociationRequest, DisputeRefundAssociationsResponse, DisputeRefundDeclaration, DisputeResponse, DisputeStage, DisputeStatus, DisputeWorkspaceAggregate, DisputeWorkspaceExport, DisputeWorkspaceFilters, DisputeWorkspaceRequest, DisputeWorkspaceResponse, DisputeWorkspaceRow, DownloadProgressEvent, DrillListControls, DrillPayment, DrillSortKey, DrillSummary, DynamicExportOptions, DynamicWorkspaceExportOptions, EncodedBranding, EntityType, EpayoutsCatalogEntry, EpayoutsCatalogResponse, EpayoutsLocality, EpayoutsMethod, EpayoutsMethodsOptions, EpayoutsMethodsResponse, EpayoutsPaypalCaptureReport, EpayoutsPaypalCaptureRequest, EpayoutsPaypalCaptureResponse, EpayoutsPaypalCaptureStatus, EpayoutsPaypalFundingSource, EpayoutsPaypalOrderResponse, EpayoutsPaypalProgressReport, EpayoutsRail, EphemeralKeyCreateRequest, EphemeralKeyCreateResponse, EuclidComparison, EuclidComparisonType, EuclidIfStatement, EuclidValue, EventClass, EventDeliveryAttemptResponse, EventDetailResponse, EventListParams, EventListResponse, EventManualTriggerRequest, EventManualTriggerResponse, EventResponse, EventType, ExpenseAllocation, Export, ExportFormat, ExportPhase, ExportPresentation, ExportPresentationFilter, ExportProgress, ExportReportWord, ExportTransferOptions, ExternalRecordCapabilities, ExternalRecordCreateSupport, ExternalRecordEnvironment, ExternalRecordKindCapability, ExternalRecordMarker, ExternalRecordRequest, ExternalRecordResource, ExternalRecordResponse, ExternalRecordTarget, ExternalRecords, FeatureMatrix, FeatureMatrixResponse, FeatureStatus, FeeOwner, FeeProgramBuilder, FeeRuleConditions, FeeRuleDefaultPrecedence, FeeRuleInput, FeeSpecInput, FeeStatementSummary, FeeType, Files, FocusedCheckoutUrlParams, FontFamily, FontWeight, Forex, ForgotPasswordRequest, FromEmailRequest, FutureUsage, GOOGLE_PAY_BUTTON_COLORS, GOOGLE_PAY_BUTTON_TYPES, GatewayConnectRequest, GatewayResponse, GeoAnalyticsChild, GeoAnalyticsTotals, GeoCitySlice, GeoCountrySlice, GeoLanguageSlice, GetSubscriptionItemsParams, GetSubscriptionItemsResponse, GlobalSearchRequest, GooglePayButtonColor, GooglePayButtonType, GroupNode, HostingFeeTerm, ImpersonateEmployeeRequest, IntentStatus, InvitationEntity, InviteUsersRequest, InviteUsersResponse, InvoiceAmountState, InvoiceOutcomes, InvoiceStatus, InvokeSdkClientNextAction, IpCountryEnforcement, IpCountryResolution, LOCALIZABLE_COPY_FIELDS, LabelStyle, LayoutStyle, LeafNode, LedgerEntry, LedgerListParams, LedgerResponse, LifecycleDetails, LifecycleWebhook, LimitedOperation, LinkedRoutingConfigRetrieveResponse, ListInvitableRolesParams, ListUsersInLineageParams, LocalizableCopyField, LoginHistoryEntry, LoginHistoryParams, LoginHistoryResponse, LogoShape, LogoSize, MAX_SECTION_LABEL_LENGTH, MAX_SECTION_ORDER, METHOD_SECTIONS, MIN_SECTION_ORDER, MandateListParams, MandateResponse, MandateRevokedResponse, MandateStatus, MandateType, ManualTriggerEventType, MarginQuality, MerchantAccountCreateRequest, MerchantAccountType, MerchantAuditActorInfo, MerchantAuditActorKind, MerchantAuditImpersonationKind, MerchantAuditLogEntry, MerchantAuditLogExportRecord, MerchantAuditLogListParams, MerchantAuditLogListResponse, MerchantAuditSessionInfo, MerchantCheckoutBrowserInfoResponse, MerchantConnectorInfo, MerchantConnectorWebhookDetailsUpdate, MerchantCostRuleCategory, MerchantCostRuleDeleteResponse, MerchantCostRuleResponse, MerchantOverviewResponse, MerchantOverviewStat, MerchantRisk, MerchantRoutingAlgorithm, MethodSectionLabels, MethodSectionOrder, MethodSectionSpec, MethodSurcharge, MinimalRoleInfo, NATIVE_ELEMENT_POSITIONS, NATIVE_PANES_MAX, NATIVE_PANE_CATEGORY_KEYS, NATIVE_PANE_ICON_KEYS, NOMUPAY_FORM_STYLES, NOTICES_PER_SECTION, NOTICE_ICONS, NOTICE_ICON_FALLBACK, NOTICE_ICON_PATHS, NOTICE_LABEL_MAX_LENGTH, NOTICE_SECTIONS, NativeElementPosition, NativePaneCapability, NativePaneMethodInfo, NativePaneNativeElement, NativePaneOpenTarget, NativePaneRail, NativePaneView, NativePaneVisibility, NativePanesCatalogResponse, NativePanesConnectorCatalog, NativeSettlementAccountFees, NativeSettlementFeeBasis, NativeSettlementFeeComponent, NativeSettlementFeeEvidence, NativeSettlementFeeRefreshRequest, NativeSettlementFeeRefreshResponse, NativeSettlementFeeTerm, NativeSettlementListRequest, NativeSettlementPayout, NativeSettlementPayoutCreateRequest, NativeSettlementPayoutListResponse, NativeSettlementPdfRequest, NativeSettlementPreviewRequest, NativeSettlementPreviewResponse, NativeSettlementQuality, NativeSettlementReport, NativeSettlementReportCreateRequest, NativeSettlementReportExport, NativeSettlementReportListResponse, NativeSettlementReportSummary, NativeSettlementSource, NativeSettlementTotals, NextActionCall, NextActionDataType, NomupayCardAuthorizationRequest, NomupayCardAuthorizationResponse, NomupayFormStyle, NomupayOppwaApplePay, NomupayOppwaCheckoutData, NomupayOppwaGooglePay, NonPillRadius, NoticeIcon, NoticeSection, OperationLimitOnExceeded, OperationLimitRule, OperationLimitRuleDeleteResponse, OperationLimitRuleListParams, OperationLimitScope, OperationLimitSettings, OperationLimitWindowMode, OperationLimits, OtherNextAction, OverrideAction, OverrideScope, PANES_MAX, PANE_CATEGORY_KEYS, PANE_ICON_KEYS, PAYPAL_CARD_LAYOUTS, PAYPAL_LABEL_STYLES, Pane, PaneCapability, PaneDisplayDefaults, PaneIssue, PaneIssueCode, PaneMethodInfo, PaneNativeElement, PaneOpenTarget, PanePresetCapability, PaneRail, PaneSurcharge, PaneView, PaneVisibility, PanesCatalogResponse, PanesConnectorCatalog, ParentGroup, ParentGroupInfo, PauseSubscriptionRequest, PauseSubscriptionResponse, PaymentAbandonAttemptResponse, PaymentAttemptResponse, PaymentCancelRequest, PaymentCaptureRequest, PaymentClientContextEntry, PaymentConfirmRequest, PaymentConnectorSettlementResponse, PaymentCreateRequest, PaymentErrorDetails, PaymentExperience, PaymentExperienceTypes, PaymentIdFormatConfig, PaymentIdStyle, PaymentIntentStateMetadata, PaymentLayout, PaymentLinkBackgroundImageConfig, PaymentLinkConfigRequest, PaymentLinkDetails, PaymentLinkListParams, PaymentLinkListResponse, PaymentLinkResponse, PaymentLinkStatusDetails, PaymentLinkTransactionDetails, PaymentListFilterConstraints, PaymentListFilteredResponse, PaymentListFiltersExt, PaymentListOrder, PaymentListParams, PaymentListResponse, PaymentMethod, PaymentMethodAmountLimits, PaymentMethodCreateRequest, PaymentMethodDeleteResponse, PaymentMethodDisplayInfo, PaymentMethodListInstallmentAmountDetails, PaymentMethodListInstallmentOption, PaymentMethodListInstallmentPlan, PaymentMethodListIntentData, PaymentMethodListParams, PaymentMethodListResponse, PaymentMethodResponse, PaymentMethodType, PaymentMethodUpdateRequest, PaymentRetrieveOptions, PaymentRoutingDecisionsResponse, PaymentStatusHistoryEntityType, PaymentStatusHistoryEvent, PaymentUpdateRequest, PaymentsDeletePolicyResponse, PaymentsPostSessionTokensNextAction, PaymentsPostSessionTokensRequest, PaymentsPostSessionTokensResponse, PayoutCreateRequest, PayoutExportRecord, PayoutListParams, PayoutListResponse, PayoutResponse, PayoutStatus, PayoutType, PayoutUpdateRequest, PaypalCardLayout, PaypalDisputeAction, PaypalDisputeActionRecord, PaypalDisputeActionRequest, PaypalDisputeActionResponse, PaypalDisputeCase, PaypalDisputeDocument, PaypalDisputeDownloadRequest, PaypalDisputeImportRequest, PaypalDisputeImportResponse, PaypalDisputeListRequest, PaypalDisputes, PaypalLabelStyle, PdfExportOptions, PendingApprovalErrorDetails, PendingOperation, PendingOperationLimitContext, PendingOperationListParams, PendingOperationListResponse, PendingOperationStatus, PendingOperationSummary, PerMethodSurchargeItem, PeriodExpenseTerm, PermissionScope, PhoneDetails, PhoneOtpRequest, PhoneOtpResponse, PhoneOtpVerifyRequest, PhoneOtpVerifyResponse, PlanSlice, PlatformFeeKind, PlatformFeeOutput, PlatformFeeProgram, PlatformFeeRule, PlatformFeeRuleOutput, PlatformFeeRuleRequest, PollStatus, PollStatusResponse, ProcessorCostBasis, ProcessorCostBucket, ProcessorCostEventBucket, ProcessorCostEventSource, ProcessorCostEventTerm, ProcessorCostEventsRequest, ProcessorCostMethodBucket, ProcessorCostNativeBucket, ProcessorCostPeriodBucket, ProcessorCostPeriodRequest, ProcessorCostPeriodResponse, ProcessorCostSource, ProcessorCosts, ProcessorFeeMovement, ProcessorSlice, ProductAliasKind, ProductAliasResponse, ProductConnectorReferenceResponse, ProductCreateRequest, ProductKind, ProductListParams, ProductListResponse, ProductMappingMode, ProductPriceCreateRequest, ProductPriceInterval, ProductPriceResponse, ProductPriceUpdateRequest, ProductResponse, ProductStatus, ProductUpdateRequest, Products, ProfileAcquirerCreateRequest, ProfileAcquirerResponse, ProfileAcquirerUpdateRequest, ProfileCreateRequest, ProfileDefaultRoutingConfig, ProfileDeniedConnectorsResponse, ProfileLogoUploadResponse, ProfilePaymentListFilterConstraints, ProfileUpdateRequest, ProfitCostTerm, ProgramConnectorSelection, ProjectCreateRequest, ProjectStats, ProjectStatsResponse, ProjectUpdateRequest, PublishableKey, RTL_CHECKOUT_LOCALES, RecordCheckoutEventRequest, RecordCheckoutEventResponse, RecoveryCodesResponse, RefundAggregateResponse, RefundCreateRequest, RefundExportRecord, RefundListParams, RefundResponse, RefundType, RefundUpdateRequest, RegionCountriesResponse, RegionCreateRequest, RegionResponse, RegionSetCountriesRequest, RegionUpdateRequest, Regions, RelayRequest, RelayResponse, RelayStatus, RelayType, ReplayIngestRequest, ReplayIngestResponse, ReplayPlaybackResponse, ReplaySliceInfo, ReplaySliceResponse, RequestOptions, RequiredFieldInfo, ResetPasswordRequest, ResponsePaymentMethodTypes, ResponsePaymentMethodsEnabled, ResumeSubscriptionRequest, ResumeSubscriptionResponse, RevenueBasis, Risk, RoleConnectorGrant, RoleConnectorGrantEntry, RoutableConnectorChoice, RoutingActivatePayload, RoutingAlgorithmKind, RoutingApproach, RoutingApproachFilter, RoutingCandidateOrigin, RoutingConfigCreateRequest, RoutingConfigDeleteResponse, RoutingConfigHistoryResponse, RoutingConfigResponse, RoutingConfigUpdateRequest, RoutingConfigVersion, RoutingConnectorAmountCap, RoutingConnectorCap, RoutingConnectorCaps, RoutingConnectorPaymentCap, RoutingDeactivateRequest, RoutingDecision, RoutingDecisionAttempt, RoutingDecisionCandidate, RoutingDecisionKind, RoutingDecisionVolumeCounter, RoutingDecisionVolumeSplitEntry, RoutingDictionary, RoutingDictionaryRecord, RoutingHistoryParams, RoutingVolumeCounter, RoutingVolumeCounters, RoutingVolumeScope, RoutingVolumeWindow, RuleConnectorSelection, SECTION_ALIASES, STRIPE_FALLBACK_PANE_CATALOG, STRIPE_FALLBACK_PANE_METHODS, STRIPE_INPUT_STYLES, STRIPE_LABEL_PLACEMENTS, STRIPE_NATIVE_PANE_METHODS, STRIPE_SPACINGS, STRIPE_THEMES, SURCHARGE_BORDER_STYLES, SURCHARGE_BORDER_WIDTHS, SURCHARGE_FIGURE_MODES, SURCHARGE_LABEL_MODES, SURCHARGE_POSITIONS, SURCHARGE_SHAPES, SURCHARGE_SIGNS, SURCHARGE_SIZES, SURCHARGE_STYLES, SURCHARGE_WEIGHTS, SalesRevenueTerm, ScopeDrillBase, ScopeDrillCohort, ScopeDrillSortKey, ScopeDrillTarget, SdkNextActionData, Search, SearchGroupResponse, SearchIndex, SearchStatus, SearchTimeRange, SellToRestrictionCapabilitiesResponse, SellToRestrictionDecisionResponse, SellToRestrictionDecisionsResponse, SellToRestrictionPolicy, SellToRestrictionPolicyRequest, SellToRestrictionRail, SellToRestrictionRailCapability, SellToRestrictionSignal, SellToRestrictionSource, SellToRestrictionStage, SellToRestrictions, SetUserPreferenceRequest, Settlement, SettlementAdvanceListRequest, SettlementAdvanceListResponse, SettlementBackfillRequest, SettlementBackfillResponse, SettlementBucket, SettlementCostParams, SettlementCostResponse, SettlementLine, SettlementLineBase, SettlementLineListParams, SettlementLineListResponse, SettlementLineWithProcessorCost, SettlementLineWithoutProcessorCost, SettlementPayoutStatus, ShopCreateRequest, ShopFeeConfigEntry, ShopFeeConfigParams, ShopFeeConfigResponse, ShopRisk, ShopSellToRestriction, ShopSettlementOverview, ShopStats, ShopStatsResponse, ShopUpdateRequest, ShopVisibilityResponse, ShopVisibilityUpdateRequest, ShownNotice, SignInRequest, SignUpRequest, SignUpWithMerchantRequest, SizeScale, SpacingScale, StatementAdjustment, StatementAdjustmentCreateRequest, StatementAdjustmentListResponse, StatementAdvance, StatementAdvanceRecordRequest, StatementGenerateRequest, StatementPayout, StatementPayoutListResponse, StatementPayoutRecordRequest, StatementPayoutUpdateRequest, StaticRoutingAlgorithm, StatsPeriod, StripeConnectAccountRequest, StripeConnectAccountResponse, StripeConnectLinkRequest, StripeConnectLinkResponse, StripeHostedConfirmDecline, StripeHostedConfirmRequest, StripeHostedConfirmResponse, StripeInputStyle, StripeLabelPlacement, StripeNativePane, StripePaymentMethodDomainResult, StripePaymentMethodDomainStatus, StripePaymentMethodDomainsRegisterRequest, StripePaymentMethodDomainsRegisterResponse, StripeSpacing, StripeTheme, SubscriptionBillingProcessorResponse, SubscriptionBucket, SubscriptionCaveat, SubscriptionChild, SubscriptionDisputeWebhook, SubscriptionDrillBase, SubscriptionDrillSortKey, SubscriptionDrillTarget, SubscriptionEstimateParams, SubscriptionEstimateResponse, SubscriptionExportRecord, SubscriptionFilters, SubscriptionInvoice, SubscriptionInvoiceListParams, SubscriptionInvoiceListResponse, SubscriptionItem, SubscriptionItemPrice, SubscriptionItemType, SubscriptionLifecycleEventType, SubscriptionLineItem, SubscriptionListParams, SubscriptionMovement, SubscriptionPaymentData, SubscriptionPaymentDetails, SubscriptionPaymentLink, SubscriptionPaymentLookupRequest, SubscriptionPaymentLookupResponse, SubscriptionPeriodUnit, SubscriptionProcessors, SubscriptionResponse, SubscriptionStatus, SubscriptionTotals, SubscriptionWebhookContent, Subscriptions, SummaryPosition, SupportedPaymentMethod, SurchargeAmountOperator, SurchargeBorderStyle, SurchargeBorderWidth, SurchargeCondition, SurchargeConditionSource, SurchargeCurrencyOperator, SurchargeDetailsResponse, SurchargeDirection, SurchargeFigureMode, SurchargeFigurePart, SurchargeFigurePlan, SurchargeLabelMode, SurchargeMetadataOperator, SurchargeOperator, SurchargePosition, SurchargeResponse, SurchargeRuleRequest, SurchargeRuleResponse, SurchargeShape, SurchargeSign, SurchargeSize, SurchargeStyle, SurchargeWeight, SurfaceStyle, SwitchMerchantRequest, SwitchProfileRequest, TermBearer, Terminate2faQueryParams, ThemeBrowserLanguage, ThemeCheckoutChannel, ThemeChoice, ThemeCondition, ThemeDeviceClass, ThemeEnumCondition, ThemeIfStatement, ThemeMetadataCondition, ThemeNumberCondition, ThemeTrafficSource, ThreeDSDecision, ThreeDsRuleExecuteRequest, ThreeDsRuleResponse, TierSummary, TimeToPayBucket, TimeToPayBucketLabel, TimeToPayStats, TokenPurpose, TokenResponse, TopupRequest, TopupResponse, TotpResponse, TransactionExportRecord, TransactionType, TrustBadge, UNKNOWN_SECTION_ORDER, UpdateMerchantCostRuleRequest, UpdateMetadataRequest, UpdateOperationLimitSettingsRequest, UpdateRoleConnectorGrantParams, UpdateSubscriptionRequest, UpdateUserDetailsRequest, UpdateUserRoleRequest, UpsertOperationLimitRuleRequest, UpsertRefundLimitRuleRequest, UpsertSettlementAdjustmentLimitRuleRequest, UpsertSettlementPayoutLimitRuleRequest, UserInLineage, UserInvitation, UserPreferenceResponse, UserResponse, UserSessionEntry, UserSessionListResponse, UserSessionRevokeResponse, VaultCheck, VaultCheckId, VaultCheckStatus, VaultCollectSessionResponse, VaultPaymentMethodRequest, VaultPaymentMethodResponse, VaultRouteApplyVerification, VaultRouteChange, VaultRouteChangeKind, VaultRouteFieldChange, VaultRouteIds, VaultRoutePurpose, VaultRouteWarning, VaultRouteWarningCode, VaultRoutesApplyRequest, VaultRoutesApplyResponse, VaultRoutesFingerprint, VaultRoutesPreviewRequest, VaultRoutesPreviewResponse, VaultVerificationResponse, VaultVerifyRequest, VerifyTotpRequest, WCAG_AA_TEXT, WCAG_AA_UI, WebhookContent, WebhookDeliveryAttempt, WebhookDeliveryTerminalReason, WebhookDetails, WebhookEvent, WebhookRefundStatus, WebhookRegistrationEnvironment, Webhooks, airwallexCardLayout, airwallexCardLayoutIsCoherent, airwallexCellWeight, airwallexFieldFontPx, airwallexFieldWeightValue, allOf, anyOf, applyBrandingVariables, asAirwallexCardPreset, buildBrandingExport, buttonPadValue, canonicalSectionId, cardFieldFontPx, cardFieldWeightValue, checkoutCopy, checkoutLocaleDir, cloneBranding, cloneCustomField, cloneNativePane, cloneNotice, clonePane, compareSections, contrastRatio, copyTranslationsKey, customFieldContextFromMetadata, customFieldIsTextLike, customFieldOperatorTakesValue, customFieldOptionLabel, customFieldText, decodeBadges, decodeBranding, decodeCustomFields, decodeMethodSectionLabels, decodeMethodSectionOrder, decodeNativePanes, decodeNotices, decodePanes, defaultBranding, defaultCustomFieldVisibility, defaultMethodSectionOrder, defaultNativePane, defaultNotices, defaultOperatorForSource, defaultPane, emptyPaneCatalog, encodeBadges, encodeBranding, encodeCustomFields, encodeMethodSectionLabels, encodeMethodSectionOrder, encodeNativePanes, encodeNotices, encodePanes, evaluateCustomFieldCondition, evaluateCustomFieldVisibility, feeProgram, focusedCheckoutUrl, fontStack, fontWeightValue, inputPadValue, isCheckboxChecked, isDarkSurface, isDefaultBadgeSet, isHexColor, isNoticeIcon, isSubscriptionDisputeWebhook, isSubscriptionLifecycleWebhook, knownSectionLabelKey, leaf, logoDimensions, nativePaneMethodInfo, noticeText, noticesIn, offerablePaneMethods, paneCatalogFor, paneDisplayDefaults, paneMethodInfo, paneRailAllowed, paneViewVisibility, parseCustomFieldsLoose, parseImportedBranding, parseNoticesLoose, programToTree, radiusValue, readableInkOn, resolveAirwallexCardPreset, resolveAirwallexLabelStyle, resolveApplePayButtonStyle, resolveGooglePayButtonColor, resolveNoticesAndBadges, resolveStripeTheme, ruleMatchToTree, sanitizeCustomCss, sectionLabel, sectionOrderOf, shadowFor, shownNotices, stripeSpacingValues, surchargeFigurePlan, surchargeShowsLabel, surchargeStyleDrawsAShape, surchargeWordFor, surfacePadValue, validSectionOrder, validatePanes, verticalGapValue, visibleCustomFields } from './index.js'; /** * Internal-only type surface. Exposed via `'@delopay/sdk/internal'` only. * * Any type that describes an admin-plane operation (bootstrap admin * signup, platform analytics, audit log read, card-issuer program mgmt, * GSM routing rules, …) lives here rather than in the public types * barrel — otherwise merchants importing from `'@delopay/sdk'` could * autocomplete or destructure shapes that hint at the admin API. * * Types that are genuinely shared between merchant and admin resources * (e.g. `FeeSchedule*`, `ProjectResponse`, `PaymentResponse`) stay in * `src/types.ts` and are imported here where needed. */ /** Internal transaction fee report filters. The payment is selected by the path. */ type AdminProcessorCostEventsParams = { /** Omit to include every reporting partition of the selected payment. */ test_mode?: boolean; limit?: number; offset?: number; force_sync?: boolean; } & SettlementCostPeriod; interface AdminSignInRequest { email: string; password: string; } /** * Response returned by admin signup/signin endpoints. * * The admin flow is passwordless-after-signup: the endpoint triggers an * email (confirmation or sign-in link) and `is_email_sent` indicates whether * delivery was attempted successfully. */ interface AuthorizeResponse { is_email_sent: boolean; } /** Create a new internal DeloPay admin user. Requires the server admin API key. */ interface CreateInternalUserRequest { name: string; email: string; password: string; /** Predefined internal role id (e.g. `internal_view_only`). Cannot be `internal_admin`. */ role_id: string; } /** Create a new tenant-level admin user. Requires the server admin API key. */ interface CreateTenantUserRequest { name: string; email: string; password: string; } /** Bootstrap a new merchant: creates user, merchant account, project, profile, and API keys in one call. */ interface OnboardMerchantRequest { email: string; name: string; password: string; company_name: string; /** * Optional per-merchant override for the welcome promotional-credit amount * (minor units). Omit to use the global promo config. */ promo_credit_amount?: number; /** * Optional per-merchant override for the promotional-credit ledger message. * Omit to use the global promo config. */ promo_credit_message?: string; } /** All identifiers and keys produced by the onboard flow. */ interface OnboardMerchantResponse { merchant_id: string; user_id: string; user_email: string; project_id: string; profile_id: string; /** Secret API key (sk_…). Show once; store securely. */ api_key: string; /** Publishable key (pk_…) for client-side SDKs. */ publishable_key: string; } /** Toggle public signup on or off at runtime. */ interface SignupToggleRequest { enabled: boolean; } /** Current public-signup status. */ interface SignupToggleResponse { signup_enabled: boolean; } interface AdminCustomerListParams { search?: string | null; is_active?: boolean | null; offset?: number | null; limit?: number | null; /** * Comma-separated opt-in fields. Currently only `"billing"` is recognised — * adds `balance_amount`, `balance_currency`, `billing_status` to each * `CustomerSummary` at the cost of one extra DB lookup per row. Default * callers should omit this to keep list responses fast. */ include?: string | null; } interface CustomerSummary { customer_id: string; organization_id: string; shop_count: number; is_active: boolean; created_at: string; customer_name?: string | null; email?: string | null; /** Populated only when the request opted in via `include=billing`. */ balance_amount?: number | null; /** Populated only when the request opted in via `include=billing`. */ balance_currency?: string | null; /** * Populated only when the request opted in via `include=billing`. Values: * `active`, `pending_setup`, `delinquent`, `suspended`. Null when the * merchant has never been onboarded to billing. */ billing_status?: string | null; } interface AdminCustomerListResponse { customers: CustomerSummary[]; total_count: number; offset: number; limit: number; } /** Page bounds for `adminPortal.listUnresolvedRefunds`. */ interface AdminUnresolvedRefundListParams { /** Page size, clamped server-side to `1..=100`. Default 20. */ limit?: number | null; /** Rows to skip. Default 0. */ offset?: number | null; } /** * One refund no sync can advance, as the operator list shows it. * * Not a `RefundResponse`: that carries no `merchant_id`, which a * cross-merchant list cannot do without. `sync_reason` is why the row is * here, lifted out of the stored marker — e.g. * `connector_reads_no_refund_by_id`. */ interface AdminUnresolvedRefund { merchant_id: string; profile_id?: string | null; payment_id: string; refund_id: string; /** The connector the payment and the refund went through (e.g. `creem`). */ connector: string; /** The connector's own id for the refund, as the webhook delivered it. */ connector_refund_id?: string | null; /** Refunded amount in the minor unit of `currency`. */ amount: number; currency: string; /** The status the row is stuck at — `pending` or `review`. */ status: RefundStatus; /** The connector's stated reason for the refund, when it gave one. */ reason?: string | null; /** Why no sync can advance this row, as written at mirror time. */ sync_reason?: string | null; created_at: string; updated_at: string; } /** * Refunds of every merchant that were mirrored from a connector webhook at a * non-terminal status and that no sync can advance: the connector emits no * later event for them and reads no refund object by id. Newest first; * `total_count` is the size of the whole set before paging. */ interface AdminUnresolvedRefundListResponse { data: AdminUnresolvedRefund[]; total_count: number; offset: number; limit: number; } interface CustomerUser { user_id: string; email?: string | null; name?: string | null; role_id?: string | null; /** Optional: older API versions may omit this field. */ is_verified?: boolean | null; is_active: boolean; created_at: string; } interface AdminCreateUserForMerchantRequest { name: string; email: string; password: string; /** Predefined merchant role id (e.g. `merchant_admin`, `merchant_view_only`). */ role_id: string; } interface AdminUpdateUserRequest { name?: string | null; is_verified?: boolean | null; is_active?: boolean | null; /** Predefined merchant role id. Requires `merchant_id`. */ role_id?: string | null; /** Merchant scope for the role change. Required iff `role_id` is set. */ merchant_id?: string | null; /** * New password (validated against signup policy). Existing JWTs are * blacklisted on change so the user is forced to log in fresh. */ password?: string | null; /** When true, wipes the user's TOTP state so they re-enroll on next login. */ reset_2fa?: boolean | null; } interface AdminUserResponse { user_id: string; email: string; name: string; is_verified: boolean; is_active: boolean; } /** * Which requested change the last-administrator guard refused. * * Rides in `error.data.route` of a `UR_66` so the caller can say *what* was * refused from its own translations — the message is generic on purpose and * should not be displayed. */ type LastAdministratorRoute = /** `is_active: false` on the last administrator. */ 'deactivate' /** * `role_id` moving the last administrator onto a role that cannot manage * the merchant's users. */ | 'demote' /** * `is_verified: false` on the last administrator. Not an immediate lockout * — the sign-in flow allows a grace window after `created_at` — but one that * has long since closed for an established account. */ | 'unverify' /** `DELETE` on the last administrator. */ | 'delete'; /** * `error.data` of a `UR_66`: `updateUser` / `deleteUser` refused a change * because it would leave `merchant_id` with nobody who can manage its users. * * "Administrator" means an active account whose active role binding at the * merchant resolves to a role holding user-write permission at merchant scope * — resolved through the role's permission groups, so a custom role counts the * same as `merchant_admin`. A user who is inactive, or whose role binding is * still a pending invitation, is not one. * * Narrow a caught `DelopayError` onto this by checking `code === 'UR_66'`; * `data` is absent against a router that predates the guard. */ interface LastAdministratorRefusal { merchant_id: string; route: LastAdministratorRoute; } interface AdminCustomerDetail { customer_id: string; organization_id: string; employee_count: number; created_at: string; customer_name?: string | null; projects: ProjectResponse[]; shops: ShopResponse[]; users: CustomerUser[]; } interface AdminTransactionListParams { /** Exclude DeloPay internal-organization traffic before pagination and count. */ exclude_internal?: boolean | null; /** General case-insensitive search across plaintext transaction fields. */ search?: string | null; merchant_id?: string | null; shop_id?: string | null; payment_id?: string | null; connector_transaction_id?: string | null; connector_response_reference_id?: string | null; connector_request_reference_id?: string | null; connector_capture_id?: string | null; /** * The buyer device that made the payment — the `dp_did` recorded on its * client-context observations. Prefix-matched from 3 characters. */ device_id?: string | null; /** * The buyer's client IP: a host, a CIDR network, or a partial prefix * (`203.0.113.`), matched by address containment rather than as text. A * value that is not an address selects nothing rather than being ignored. */ client_ip?: string | null; status?: string | null; statuses?: string[] | null; /** Exact match on the active attempt's connector (e.g. `stripe`). */ connector?: string | null; connectors?: string[] | null; /** Exact match on the active attempt's payment method (e.g. `card`). */ payment_method?: string | null; payment_methods?: string[] | null; /** Exact match on the active attempt's method sub-type (e.g. `apple_pay`). */ payment_method_type?: string | null; payment_method_types?: string[] | null; currencies?: string[] | null; merchant_connector_ids?: string[] | null; connector_settlement_statuses?: string[] | null; routing_approaches?: string[] | null; /** `true` = test only, `false` = live only, omitted = both. */ test_mode?: boolean | null; /** Inclusive lower bound on the payment amount, in minor units. */ start_amount?: number | null; /** Inclusive upper bound on the payment amount, in minor units. */ end_amount?: number | null; /** `true` = deleted-only recovery view; false/omitted = active transactions. */ deleted?: boolean | null; start_date?: string | null; end_date?: string | null; offset?: number | null; limit?: number | null; /** Column to sort by: `amount`, `created`, `modified`, `status`, `shop`, * `customer`. Defaults to `created`. */ sort_on?: string | null; /** Sort direction: `asc` or `desc`. Defaults to `desc`. */ sort_by?: string | null; } interface AdminTransactionListResponse { data: PaymentResponse[]; total_count?: number | null; } /** * Filters of the admin transactions export * (`adminPortal.exportTransactions`): exactly the list's, minus the page. * * An export that understood fewer filters than the table it is taken from * would quietly widen the result set, so it takes the list's own; and the * absence of `limit` / `offset` is the point — the export is the match set, * not a page of it. */ type AdminTransactionExportParams = Omit; /** * One row of the admin transactions export: the twelve columns the admin * transactions table renders, in its order, then `test_mode`. */ interface AdminTransactionExportRecord { payment_id: string; merchant_id: string; /** The merchant's display name, or its id when the name cannot be resolved. */ merchant_name: string; shop_id: string | null; shop_name: string | null; connector: string | null; payment_method: string | null; payment_method_type: string | null; status: string; /** Minor units. */ amount: number; currency: string | null; /** ISO 8601, UTC. */ created_at: string; /** * The payment's environment. `null` when it never recorded one — which is * not `false`, although the `test_mode` filter counts it as live. A default * export spans both environments, so each row says which it is. */ test_mode: boolean | null; } interface AdminAnalyticsRequest { start_date?: string | null; end_date?: string | null; } interface OverviewStat { label: string; value: number; change_percent: number; } /** Fields common to every per-attempt processor-cost read. */ interface AdminAttemptProcessorCostBase { payment_id: string; attempt_id: string; /** * The processor's own method identifier the payment ran with (the e-Payouts * vendor code), as stamped on the line. Absent for other connectors and on * lines written before it was recorded. */ connector_method_code?: string | null; /** * What produced an `estimated` cost — the schedule and rates as they stood * when the line was priced, so the figure stays explicable after the * schedule is replaced or deleted. Absent on a `reported` cost, and on a * line carrying no figure at all. */ processor_cost_basis?: ProcessorCostEstimateBasis | null; } /** * No settlement line exists for the attempt — a merchant without hosting-fee * configuration, or a payment that never established a capture. Says nothing * about what the rail charged, so it can carry no figure. */ interface AdminAttemptProcessorCostUnrecorded extends AdminAttemptProcessorCostBase { line_recorded: false; processor_cost_source?: never; processor_cost_amount?: never; processor_cost_currency?: never; processor_cost_exponent?: never; } /** * A recorded line whose cost is known — the rail reported it, or a configured * schedule estimated it. Same contract as `SettlementLineWithProcessorCost`: * the amount is minor units at `processor_cost_exponent` of * `processor_cost_currency` (the rail's own settlement currency), and the * three arrive together or not at all — a figure does not decode without its * exponent, and the server derives and redacts them as one. */ interface AdminAttemptProcessorCostKnown extends AdminAttemptProcessorCostBase { line_recorded: true; processor_cost_source: 'reported' | 'estimated'; processor_cost_amount: number; processor_cost_currency: string; processor_cost_exponent: number; } /** * A recorded line with no figure — which is not a zero. A present * `'unavailable'` says the rail was asked and reports nothing; an absent * source says the line predates cost recording. Either way nothing here is a * number. */ interface AdminAttemptProcessorCostWithoutFigure extends AdminAttemptProcessorCostBase { line_recorded: true; processor_cost_source?: 'unavailable'; processor_cost_amount?: never; processor_cost_currency?: never; processor_cost_exponent?: never; } /** * What the rail charged for one attempt, read off the attempt's settlement * line (`fee_statement_line`) for the admin transaction detail. A * discriminated union on `line_recorded` and * `processor_cost_source`, so `processor_cost_amount` is a `number` only after * narrowing to a known cost — an unreported cost can never be read as a plain * number, and never as 0. Pinned by * `tests/internal/adminAttemptProcessorCost.test-d.ts`. */ type AdminAttemptProcessorCost = AdminAttemptProcessorCostUnrecorded | AdminAttemptProcessorCostKnown | AdminAttemptProcessorCostWithoutFigure; interface OverviewStatsResponse { total_accounts: OverviewStat; total_admins: OverviewStat; audit_events: OverviewStat; } /** * How much of a reported collected-fee total the aggregate could actually * see, and — when it could not see all of it — in which direction the figure * is wrong. * * - `exact` — the total covers every fee in the period. * - `lower_bound` — some fees could not be read, so the real total is this or * **higher**. Never present it as the figure. * - `unknown` — no direction can be established. * * Ordered by severity: folding several ledger groups together is a `max`, so * once a total is `unknown` no later group restores a direction. */ type FeeTotalBound = 'exact' | 'lower_bound' | 'unknown'; interface PlatformAnalyticsResponse { total_customers: number; total_shops: number; total_transactions: number; total_volume: number; total_fees_collected: number; /** * How much weight {@link total_fees_collected} carries. Absent on responses * from before the qualifier existed — which is not the same as `'exact'`, * so treat an absent value as unqualified rather than assuming the total is * complete. */ total_fees_bound?: FeeTotalBound; period_start: string; period_end: string; } interface PaymentAnalyticsRequest { /** Rolling window in days. Ignored when start_date is provided. */ period?: number | null; /** Naive ISO 8601 datetime (e.g. 2026-06-01T00:00:00). Takes precedence over period. */ start_date?: string | null; /** Naive ISO 8601 datetime. Defaults to now when only start_date is set. */ end_date?: string | null; /** Limit stats to a single customer/merchant. Omitted = platform-wide. */ merchant_id?: string | null; /** Limit stats to the shops of one project. Requires merchant_id. */ project_id?: string | null; /** Limit stats to a single shop. Requires merchant_id; wins over project_id. */ shop_id?: string | null; currency?: string | null; } /** * The four independent payment measures for one reporting window. Derived * figures (success rate, averages, period-over-period deltas) are computed * by the consumer. */ interface PaymentPeriodStats { /** Sum of all payment intent amounts, in major units. */ total_volume: number; /** Sum of succeeded payment intent amounts, in major units. */ successful_volume: number; /** Count of all payment intents. */ transactions: number; /** Count of succeeded payment intents. */ successful_transactions: number; /** Count of successful refunds created in the window. */ refunds: number; /** Sum of successful refund amounts created in the window, in major units. */ refund_volume: number; } interface PaymentAnalyticsResponse { /** Base measures for the requested window. */ current: PaymentPeriodStats; /** Base measures for the equal-length window immediately before it. */ previous: PaymentPeriodStats; currency: string; period_days: number; } /** Query for the platform ledger-analytics endpoint. */ interface AdminLedgerAnalyticsRequest { /** Trailing days for a rolling window. Default 30, capped at 90. */ days?: number | null; /** Naive ISO 8601 datetime for the window start (custom range; span ≤ 90 days). */ start_date?: string | null; /** Naive ISO 8601 datetime for the inclusive last day. Defaults to now. */ end_date?: string | null; /** * Comma-separated selector for which response blocks the server computes, so * a pinned card fetches only what it renders. Tokens: `summary` (total * balance, net change, account-status counts, the `current` aggregate + * `previous` window), `series` (the day-by-day flow) and `merchants` (the * biggest-top-ups donut — the only block paying the per-merchant * name-resolution cost). Omit for all blocks. Unrequested blocks come back * empty / zero. */ sections?: string | null; } /** One day of platform-wide ledger movement, in USD minor units. */ interface LedgerDayBucket { /** Balance merchants added by paying in (topup_credit), positive. */ topup_amount: number; topup_count: number; /** Platform fees collected (fee_debit + merchant_fee_debit), positive. */ fee_amount: number; fee_count: number; /** Other credits (admin_credit + promo_credit), positive. */ credit_amount: number; credit_count: number; /** Other debits (admin_debit), positive. */ debit_amount: number; debit_count: number; /** Net of every entry that day (signed) — the day's platform balance change. */ net_amount: number; } /** * A billing profile whose merchant account no longer exists. * * Deleting a merchant account does not delete its billing profile, and the * profile's `merchant_id` carries no foreign key, so the balance, the Stripe * customer and the saved payment method outlive the account that owned them. * The Merchants listing enumerates merchant accounts and skips a row whose * account cannot be loaded, so such a profile is **absent** from it rather * than shown as broken — which is why the platform balance total and the * visible account count can disagree. */ interface OrphanedBillingProfile { /** * The merchant id the profile is keyed on. The `/billing/{merchantId}` * routes still answer on it, which is the only way to reach this money. */ merchant_id: string; profile_id: string; /** * Balance in `balance_currency` minor units. Deliberately **not** normalised * to USD — this is a reconciliation listing, and a converted figure invites * summing rows that are not in the same currency. */ balance_amount: number; balance_currency: string; billing_status: string; is_free: boolean; /** A Stripe customer still exists for this profile. */ has_stripe_customer: boolean; /** A saved payment method is still attached to this profile. */ has_saved_card: boolean; /** * Ledger rows still live (not soft-deleted) against this merchant id. Zero * means the ledger was reset, not that there never was one. */ live_ledger_entries: number; created_at: string; } /** * A merchant account created **after** the billing profile it owns. * * The account therefore cannot be the one that caused the profile to exist, * so it may have taken over a previous owner's balance and saved payment * method. A candidate, not a finding: creating a ledger through the admin * route can also produce this ordering with no account involved, so confirm * against the audit log before acting on a row. * * The reverse ordering is not reported because it means nothing — a profile * created after its account is the ordinary case, since a merchant may set up * billing long after signing up. */ interface BillingProfileAdoptionCandidate { merchant_id: string; profile_id: string; balance_amount: number; balance_currency: string; has_saved_card: boolean; profile_created_at: string; account_created_at: string; } /** * Billing profiles no operator listing can reach, and merchant accounts that * may have taken one over. * * Both lists are **complete rather than paged**. The question this answers is * whether the set is empty, and a truncated answer to that question reads as * a clean bill of health. */ interface AdminOrphanedBillingProfilesResponse { /** Profiles whose merchant account is gone, oldest first. */ orphaned: OrphanedBillingProfile[]; /** * Accounts newer than the profile they own, newest first. These need * confirming before they are treated as findings. */ adoption_candidates: BillingProfileAdoptionCandidate[]; } /** * Platform ledger-analytics response. All money is in USD minor units * (`currency`). `series` is the current window day by day; `previous` is the * equal-length prior window aggregated, for deltas. */ interface AdminLedgerAnalyticsResponse { currency: string; days: number; end_date: string; /** Sum of every billing account's current balance (USD minor). */ total_balance: number; /** Net balance change over the window (USD minor) = balance now − at start. */ net_change: number; accounts_total: number; accounts_active: number; accounts_delinquent: number; accounts_suspended: number; /** * The current window aggregated into a single bucket (the sum of `series`), * so a totals-only card (e.g. fee revenue) reads `current.fee_amount` without * iterating `series`. Part of the `summary` section. */ current: LedgerDayBucket; series: LedgerDayBucket[]; /** * The previous period day by day, same length as `series`, for the over-time * period-over-period overlay (e.g. "top-ups over time"). Empty unless the * `series` section is requested. */ previous_series: LedgerDayBucket[]; previous: LedgerDayBucket; /** Merchants with the largest top-up totals this window (USD minor), capped. */ top_merchants: LedgerMerchant[]; /** Combined top-ups of merchants beyond the cap (USD minor). */ other_merchants_topup: number; /** How many merchants fell into `other_merchants_topup`. */ other_merchants_count: number; } /** One merchant's top-up total over the window (USD minor). */ interface LedgerMerchant { id: string; name: string; topup_amount: number; } interface AuditLogListParams { /** Filter by the effective actor — whoever the change appears to be by. */ user_id?: string | null; /** * Filter by the person really acting: "everything this admin did while * impersonating anyone". Differs from `user_id` only on impersonated rows. */ real_user_id?: string | null; merchant_id?: string | null; profile_id?: string | null; /** Filter to one sign-in — the changes made in a single session. */ session_id?: string | null; action?: string | null; entity_type?: string | null; /** Inclusive lower bound, ISO 8601 (`2026-03-12T00:00:00Z`). */ start_date?: string | null; /** Inclusive upper bound, ISO 8601. */ end_date?: string | null; offset?: number | null; limit?: number | null; } /** * What kind of party an actor is. * * `merchant_api_key` and `platform_api_key` are deliberately distinct: a * merchant's own key is not DeloPay, and rendering one as the other says * DeloPay made a change the merchant made. */ type AuditActorKind = 'user' | 'merchant_api_key' | 'platform_api_key' | 'system'; /** Who acted, resolved for display so a row needs no lookup to render. */ interface AuditActorInfo { /** The raw `user_id` value, for filtering and pivoting. */ id: string; kind: AuditActorKind; /** * A user's email, or the merchant an API key belongs to. `null` for the * platform key and system jobs, and for a user whose row no longer exists — * the log outlives the people in it. */ name?: string | null; } /** * Which relationship an impersonated change was made under. * * `null`/absent on an entry means **unknown** — a row written before this was * recorded — and is NOT the same as `self_acted`. */ type AuditImpersonationKind = 'self_acted' | 'admin_for_merchant' | 'merchant_for_team_member'; /** * The sign-in a change was made in: where the person was, and on what. * * Absent for API keys, internal jobs, and rows written before sessions were * recorded — and also when the session row has since been pruned, in which * case the change is still attributed and only the device and place are gone. */ interface AuditSessionInfo { id: string; ip_address?: string | null; /** Raw user agent; the dashboards parse it into "Chrome · macOS". */ user_agent?: string | null; country_code?: string | null; city?: string | null; /** Approximate — derived from the IP, so a neighbourhood, not an address. */ latitude?: number | null; longitude?: number | null; auth_method?: string | null; started_at?: string | null; last_seen_at?: string | null; revoked_at?: string | null; } interface AuditLogResponse { id: string; /** The effective actor's raw id. Unchanged in meaning since this shipped. */ user_id: string; actor: AuditActorInfo; /** * The person really at the keyboard, when that differs from `actor`. Absent * on a self-acted change and on rows written before impersonation was * recorded — read `impersonation_kind` to tell those two apart. */ real_actor?: AuditActorInfo | null; impersonation_kind?: AuditImpersonationKind | null; session?: AuditSessionInfo | null; action: string; entity_type: string; created_at: string; merchant_id?: string | null; profile_id?: string | null; entity_id?: string | null; /** * What the entity was called — the connector's label, the shop's name, the * API key's name, the user's email. Resolved server-side. * * `null` when the entity has since been deleted and no name was recorded * with the event: explicitly absent rather than blank, so a UI can say so * instead of rendering an empty cell. */ entity_name?: string | null; details?: unknown | null; ip_address?: string | null; user_agent?: string | null; } interface AuditLogListResponse { entries: AuditLogResponse[]; total_count: number; offset: number; limit: number; } interface AdminAdjustmentRequest { amount: number; description: string; /** * Client-supplied idempotency key. When set, the server derives a * deterministic ledger row id from it so a replay of the same body * collides on the ledger UNIQUE index and short-circuits instead of * double-crediting or double-debiting. Generate a fresh UUID per * intentional adjustment; reuse across retries of the same one. * Optional — omitted requests behave as before (no dedup). */ idempotency_key?: string; } interface AdminAdjustmentResponse { ledger_entry_id: string; new_balance: number; } /** * Admin-only edit of a single ledger entry. When `amount` is provided the * merchant balance is atomically adjusted by the difference from the old * amount; a `description`-only edit never touches the balance. Omitting both * is a no-op. */ interface UpdateLedgerEntryRequest { amount?: number; description?: string; } /** * The global welcome promotional-credit config, editable at runtime from the * admin dashboard. `amount` is in minor units of the default billing currency; * `message` is the ledger description written for the grant and may contain the * `{amount}` placeholder. */ interface PromoConfigResponse { amount: number; message: string; } /** Admin-only update of the global promo config. Omitted fields are unchanged. */ interface UpdatePromoConfigRequest { amount?: number; message?: string; } /** * Admin-only manual suspension of a merchant (e.g. confirmed fraud or ToS * violation), independent of balance. A `reason` is required for audit. * Rejected with 412 if the merchant is on the trusted list (clear the flag * first) or already suspended. */ interface AdminSuspendRequest { reason: string; } /** * Admin-only lift of a manual suspension. Restores the merchant to `active` * (or `delinquent` if the balance is at/below the hard floor) and resets the * recharge-failure counter. */ interface AdminUnsuspendRequest { /** Optional note recorded in the audit log. */ reason?: string; } /** * Admin-only toggle of the trusted (suspension-exempt) flag. Trusted * merchants cannot be suspended automatically or manually. Does not lift an * existing suspension — use unsuspend for that. */ interface AdminSetTrustedRequest { trusted: boolean; } /** * Admin-only: set the merchant's hard floor — the balance at or below which * the merchant stops being active. A negative value is a credit line ("this * merchant may run this far negative"); zero means no negative balance at * all. Setting it moves the suspension line, it does not remove it. * * Refused with 412 when `hard_floor_amount` is positive, when it exceeds the * maximum credit line of 10,000,000 minor units, or when `reason` is empty — * this is a credit decision, and the justification is written to the audit * log **before** the floor moves, so a 200 never means it was discarded. */ interface AdminSetHardFloorRequest { /** New floor in minor units of the balance currency. Zero or negative. */ hard_floor_amount: number; /** Why this merchant may run negative. Required; recorded in the audit log. */ reason: string; } /** * Admin-only: mark a merchant free (not billed), or put it back on the * prepaid model. * * A union rather than an optional `reason`, on the `SettlementCostPeriod` * precedent: `free: true` without a reason can only earn a 412, so that shape * must not typecheck. Marking free normalises a billing-caused status — `pending_setup`, `delinquent`, or an * `auto_recharge` suspension — to `active`. A sticky `admin` suspension is * refused with 412 until lifted explicitly: the flag must never quietly * unblock a merchant that was stopped for fraud. `free: false` re-derives the * status from the balance the way an unsuspend does. */ type AdminSetFreeRequest = { free: true; /** Why the merchant is not billed. Required: the router refuses `free: true` without one (412). */ reason: string; } | { free: false; /** Ignored when clearing the flag; accepted so a caller can carry one through. */ reason?: string; }; /** * Admin-only: delete a merchant's **entire** ledger. * Every live entry is soft-deleted (kept for replay protection), the balance * is set to zero and the status re-derived. Refused with 412 while the * merchant has shop allocations. */ interface AdminResetLedgerRequest { /** Human-readable reason, required for audit. */ reason: string; } interface AdminResetLedgerResponse { /** Live entries removed from the ledger. */ deleted_count: number; /** Signed sum of the removed entries' amounts, in the balance currency. */ deleted_amount: number; /** The balance before the reset; after it the balance is always zero. */ balance_before: number; /** The profile as it stands after the reset. */ profile: BillingProfileResponse; } /** * Admin-only: (re)create a merchant's ledger, optionally seeded with an * opening balance. Ensures the billing profile exists * (created without the welcome promo credit) and, when `opening_balance` is * set, writes one `opening_balance` entry. Refused with 412 while the * merchant still has live ledger entries, or a non-zero balance with none. * Does not clear the free flag. */ interface AdminCreateLedgerRequest { /** Opening balance in minor units of the balance currency. Omit or `0` for an empty ledger. */ opening_balance?: number; /** ISO-4217 currency for a profile that does not exist yet; must match an existing profile's. */ balance_currency?: string; /** Human-readable reason, required for audit; also the opening entry's description. */ reason: string; } interface AdminCreateLedgerResponse { /** The opening-balance entry, when one was written. */ ledger_entry_id?: string | null; /** The profile as it stands after the call. */ profile: BillingProfileResponse; } interface CardIssuerCreateRequest { issuer_name: string; } interface CardIssuerUpdateRequest { issuer_name: string; } interface CardIssuerResponse { id: string; issuer_name: string; } interface CardIssuerListResponse { issuers: CardIssuerResponse[]; } type GsmDecision = 'retry' | 'do_default'; interface GsmRuleCreateRequest { connector: string; flow: string; sub_flow: string; code: string; message: string; status: string; decision: GsmDecision; step_up_possible: boolean; clear_pan_possible: boolean; router_error?: string | null; unified_code?: string | null; unified_message?: string | null; } interface GsmRuleUpdateRequest { connector: string; flow: string; sub_flow: string; code: string; message: string; status?: string | null; router_error?: string | null; decision?: GsmDecision | null; step_up_possible?: boolean | null; unified_code?: string | null; unified_message?: string | null; } interface GsmRuleResponse { connector: string; flow: string; sub_flow: string; code: string; message: string; status: string; decision: GsmDecision; step_up_possible: boolean; clear_pan_possible: boolean; feature: string; feature_data: unknown; router_error?: string | null; unified_code?: string | null; unified_message?: string | null; } /** * Per-connector visibility mode. Default for connectors with no row is * `disabled` (default-closed) — to publicly launch a connector, ops * upserts a row with `public`. To pilot a connector with one or more * merchants before public launch, use `beta` plus * `allowed_merchant_ids`. */ type ConnectorVisibility = 'public' | 'beta' | 'disabled'; /** Body for `POST /admin/connector-restrictions` (upsert). */ interface UpsertConnectorRestrictionRequest { /** Connector name (snake_case, e.g. `'stripe'`, `'adyen'`). */ connector_name: string; /** Visibility mode. Defaults server-side to `'beta'` when omitted. */ visibility?: ConnectorVisibility; /** Merchant IDs allowed to attach this connector. Only consulted * when `visibility === 'beta'`; ignored for `'public'` / * `'disabled'` (collapsed to an empty array). */ allowed_merchant_ids: string[]; /** Merchant IDs blocked from attaching this connector. A DENY * override that beats both `visibility` (even `'public'`) and * `allowed_merchant_ids` — a denied merchant is always rejected. * Honored for every visibility mode. */ denied_merchant_ids?: string[]; /** Optional audit note (e.g. `"beta access — Marcel"`). */ reason?: string | null; } interface ConnectorRestrictionResponse { connector_name: string; visibility: ConnectorVisibility; allowed_merchant_ids: string[]; denied_merchant_ids: string[]; reason: string | null; /** ISO 8601 datetime. */ created_at: string; /** ISO 8601 datetime. */ modified_at: string; } /** Which level a restriction rule targets: a shop (business profile, the * `scope_id` is a `profile_id`) or a project (a `project_id` grouping of * shops, the `scope_id` is a `project_id`). */ type ConnectorRestrictionScope = 'profile' | 'project'; /** Whether a rule permits (whitelist) or forbids a connector for its scope. * A `deny` is never routed even if the connector is attached and enabled; * once a scope has any `allow` it becomes a whitelist. */ type ConnectorRestrictionRuleAction = 'allow' | 'deny'; /** Body for `POST /admin/connector-restriction-rules`. */ interface CreateConnectorRestrictionRuleRequest { /** Merchant the rule belongs to. */ merchant_id: string; /** Whether `scope_id` is a `profile_id` (shop) or a `project_id`. */ scope: ConnectorRestrictionScope; /** The `profile_id` or `project_id` the rule targets. */ scope_id: string; /** Connector name (snake_case, e.g. `'stripe'`). */ connector: string; /** Permit (whitelist) or forbid this connector for the scope. */ action: ConnectorRestrictionRuleAction; /** Optional audit note. */ reason?: string | null; } /** Body for `PATCH /admin/connector-restriction-rules/{id}`. Omitted fields * are left unchanged. */ interface UpdateConnectorRestrictionRuleRequest { action?: ConnectorRestrictionRuleAction; reason?: string | null; } /** Query for `GET /admin/connector-restriction-rules`. Provide **either** * `scope` + `scope_id` (one shop/project) **or** `merchant_id` (every rule * for a merchant). */ interface ListConnectorRestrictionRulesQuery { scope?: ConnectorRestrictionScope; scope_id?: string; merchant_id?: string; } /** One persisted per-shop/project connector restriction rule. */ interface ConnectorRestrictionRuleResponse { id: string; merchant_id: string; scope: ConnectorRestrictionScope; scope_id: string; connector: string; action: ConnectorRestrictionRuleAction; reason: string | null; /** ISO 8601 datetime. */ created_at: string; /** ISO 8601 datetime. */ modified_at: string; } /** * The global auto-close policy for payments stuck awaiting buyer action * (`requires_payment_method`, `requires_confirmation`, * `requires_customer_action`). When enabled, a background sweep expires * such payments once they are older than `hours`. */ interface PaymentAutoCloseConfigResponse { enabled: boolean; /** Age in hours after which an awaiting payment is expired (1..=720). */ hours: number; } /** * Update the global auto-close policy. PATCH semantics: omitted fields are * left unchanged, each field applies independently. */ interface UpdatePaymentAutoCloseConfigRequest { enabled?: boolean; hours?: number; } /** * One merchant's auto-close override plus the values that actually apply * to it (override field if set, else the global config). */ interface PaymentAutoCloseOverrideResponse { /** Per-merchant `enabled` override; `null` = inherit the global value. */ enabled: boolean | null; /** Per-merchant window override in hours; `null` = inherit the global value. */ hours: number | null; /** The values effectively applied to this merchant after layering. */ effective: PaymentAutoCloseConfigResponse; } /** * Replace a merchant's auto-close override. REPLACE semantics — the stored * override becomes exactly these two fields, and sending both as `null` * removes the override entirely (falling back to the global config). */ interface UpdatePaymentAutoCloseOverrideRequest { enabled?: boolean | null; hours?: number | null; } /** * What a replay-masking rule does to the elements it matches. * * Every variant hides something. There is deliberately no variant that reveals * anything: an "unmask" mode would make the union a difference, and one click * in an admin panel could then put cardholder data into a recording. The click * would be reversible and the recording would not. */ type ReplayMaskMode = 'mask' | 'block' | 'mask_text'; /** One extra element the session recorder must hide. */ interface ReplayMaskingRule { /** A CSS selector, evaluated by the recorder on the page being recorded. */ selector: string; mode: ReplayMaskMode; } /** * The effective masking configuration for a scope. `rules` are added to the * recorder's built-in floor, never substituted for it, so an empty list means * "nothing beyond the built-in masking" rather than "record everything". * * `degraded` is `true` when the stored configuration could not be read or * parsed, and the scope then runs **fail-closed: the maximal rule set is in * force**, not the floor. It is served rather than hidden because "everything * is masked" and "nothing is configured" are otherwise indistinguishable from * the outside, and an operator who cannot tell them apart will eventually read * a blanked recording as a broken recorder. Internal tooling should surface it * for the same reason. */ interface ReplayMaskingConfigResponse { rules: ReplayMaskingRule[]; degraded: boolean; } /** Replace the stored rules at one scope. An empty list clears them. */ interface UpdateReplayMaskingConfigRequest { rules: ReplayMaskingRule[]; } /** * The admin-facing global deletable-status policy: `statuses` is what * admins may currently delete (and what merchants inherit); `env_allowed` * is the deploy-time ceiling the UI may offer as options. */ interface TransactionDeleteConfigResponse { env_allowed: string[]; statuses: string[]; } /** * Replace the global deletable-status set. Must be a subset of the * deployment's env ceiling. */ interface UpdateTransactionDeleteConfigRequest { statuses: string[]; } /** * One merchant's deletable-status override. `statuses = null` means the * merchant inherits the global set; `effective` is what actually applies; * `admin_allowed` is the ceiling the admin may grant from. */ interface TransactionDeleteOverrideResponse { statuses: string[] | null; effective: string[]; admin_allowed: string[]; } /** * Replace one merchant's override. `statuses: null` removes the override * (inherit global); an empty list means "this merchant may delete nothing". */ interface UpdateTransactionDeleteOverrideRequest { statuses: string[] | null; } /** * Whether a merchant may attach the vault connector, reported as the three * independent facts the gate is built from rather than as one flag. A deny * overrides `public` visibility and overrides a `beta` allowlist entry. */ interface AdminVaultEntitlementState { /** Always `vgs` today; named so a second vendor cannot reuse the meaning. */ connector_name: string; /** * The resolved verdict. **`null` means the state could not be read**, not * "no" — render it as unknown, never as "not granted". */ granted: boolean | null; /** `public` / `beta` / `disabled`, or `null` when there is no restriction row. */ visibility: string | null; /** Whether this merchant is allowlisted (only decides under `beta`). */ allowlisted: boolean | null; /** Whether this merchant is denied. Beats everything else. */ denied: boolean | null; /** The operator-authored note stored on the restriction row, if any. */ reason: string | null; /** Set when, and only when, the entitlement could not be determined. */ unknown_reason: string | null; } /** One VGS environment a shop's vault account holds credentials for. */ interface AdminVaultEnvironmentState { environment: VaultEnvironment; /** The VGS tenant id (`tnt…`). Addressing, not a credential. */ vault_id: string | null; /** * Whether the vault *cloaks* in this environment (an outbound proxy URL in * this environment's credentials) rather than merely storing cards. */ cloaks: boolean; } /** What one shop's vault configuration looks like from the operator's side. */ interface AdminShopVaultState { profile_id: string; profile_name: string; /** The shop's `is_external_vault_enabled` switch (not the whole answer). */ is_external_vault_enabled: boolean; /** * Whether a vault account is provisioned for this shop at all. * **`null` means it could not be determined** — see `unknown_reason`. */ vault_provisioned: boolean | null; vault_connector_id: string | null; /** The vault vendor actually attached — not assumed to be `vgs`. */ vault_connector_name: string | null; /** Environments with credentials. Empty when nothing could be read. */ environments: AdminVaultEnvironmentState[]; /** Inbound (Collect) route id, needed only for browser-side capture. */ collect_route_id: string | null; vault_sdk: string | null; /** Connectors this shop vaults cards for. Absent or empty = every connector. */ enabled_for_connectors: string[] | null; /** * Whether the vault cloaks **in any environment**; `null` when unreadable. * `environments[].cloaks` is the per-environment truth. */ cloaking_enabled: boolean | null; /** Set when part of this shop's vault state could not be read. */ unknown_reason: string | null; } /** Vault state for one merchant: the entitlement, and every shop. */ interface AdminVaultStateResponse { merchant_id: string; entitlement: AdminVaultEntitlementState; shops: AdminShopVaultState[]; } /** * Attach a vault to one of a merchant's shops: creates the vault connector * account and points the profile at it in one request. */ interface AdminAttachVaultRequest { /** The shop to attach the vault to. Must belong to the merchant in the path. */ profile_id: string; /** VGS Collect service-account client id. */ service_account_id: string; /** * VGS Collect service-account secret. Must be write-only * (`aliases:write`) — the attach verifies this and refuses otherwise. */ service_account_secret: string; /** VGS vault (tenant) id, `tnt…`. */ vault_id: string; /** * Outbound forward-proxy URL including credentials. Its presence is what * makes the vault *cloak* rather than merely store. */ proxy_url?: string | null; /** * VGS **management** service-account client id for a merchant-owned * vault. A second, separate account — never the Collect account above. * Only valid as a pair with `mgmt_client_secret`. */ mgmt_client_id?: string | null; /** VGS management service-account secret. Required with `mgmt_client_id`. */ mgmt_client_secret?: string | null; /** Inbound (Collect) route id, needed for browser-side card capture. */ collect_route_id?: string | null; /** Connectors this shop should vault cards for. Absent or empty = all. */ enabled_for_connectors?: string[] | null; /** Label for the connector account. Defaults to `vgs_{profile_id}`. */ connector_label?: string | null; /** * `true` stores the credentials in the account's **sandbox** slot and * marks the account test-mode; absent or `false` uses the live slot. * Deliberately explicit rather than derived from the vault id. */ test_mode?: boolean | null; } /** The result of an attach, plus non-fatal findings. */ interface AdminAttachVaultResponse { merchant_connector_id: string; profile_id: string; is_external_vault_enabled: boolean; collect_route_id: string | null; vault_sdk: string | null; /** Configurations that will work now and bite later. Empty on a clean attach. */ warnings: string[]; } /** * One row of the platform audit-log export. * * The merchant-facing shape plus `merchant_id`, which is the column an * operator's log carries that a merchant's own does not. */ interface AdminAuditLogExportRecord { created_at: string; actor_kind: string; actor_id: string; actor_name: string | null; real_actor_id: string | null; real_actor_name: string | null; impersonation_kind: string | null; session_id: string | null; ip_address: string | null; user_agent: string | null; merchant_id: string | null; profile_id: string | null; action: string; entity_type: string; entity_id: string | null; entity_name: string | null; } /** * Which environment's rows to return. * * **`'all'` is never a default.** The page opens on `DEFAULT_ENV_FILTER` — * live on production, test on the sandbox tenant — and sends the value * explicitly. Omitting the field is read by the backend as `'live'`, not as * `'all'`: a caller that forgot to say gets the safer of the two, and a test * payment never appears in a view that reads as live. */ type DiagnosticEnvironment = 'all' | 'live' | 'test'; /** The window every tab reads over. ISO 8601, inclusive at both ends. */ interface DiagnosticWindow { start_time: string; end_time: string; } /** One page of a list. The console pages at 20; the backend caps `limit` at 200. */ interface DiagnosticPage { limit?: number; offset?: number; } /** * A paginated answer. * * `hidden_by_environment` is what lets the environment strip say "612 test-mode * rows are hidden". An operator who cannot see how much is being withheld * cannot tell an empty tab from a filtered one. */ interface DiagnosticList { rows: T[]; total_count: number; hidden_by_environment: number; } /** * Why a panel has no data, when the reason is not "there is none". * * The distinction this type exists for: **an unreachable log store must never * render as "no errors found"**. Loki being down and Loki answering zero lines * are opposite facts during an incident, and the second tells an operator to * stop looking. */ interface DiagnosticSourceUnavailable { /** `loki`, `alertmanager`, `analytics`, or a writer that is switched off. */ source: string; /** The endpoint that did not answer, so it can be reached directly. */ endpoint: string | null; reason: string; last_success: string | null; /** Where to go instead — Grafana, when one is configured. */ fallback_url: string | null; } /** * A panel that either has data or says why it does not. * * Deliberately not `T | null`: a caller cannot tell an absent value from an * absent source by looking at a nullable, and collapsing the two is how a dead * log store comes to read as a quiet one. */ type DiagnosticPanel = { status: 'available'; data: T; } | { status: 'unavailable'; data: DiagnosticSourceUnavailable; }; /** Filters shared by every list request. */ interface DiagnosticListParamsBase { window?: DiagnosticWindow; environment?: DiagnosticEnvironment; page?: DiagnosticPage; } interface DiagnosticIncomingWebhookListParams extends DiagnosticListParamsBase { merchant_id?: string; profile_id?: string; connector?: string[]; /** `applied` | `ignored` | `duplicate` | `rejected` | `dropped` | `error`. */ outcome?: string[]; provider_event_type?: string; mapped_event_type?: string; /** Any id the operator pasted, matched against every column it could be. */ object_id?: string; request_id?: string; /** * `false` selects rows that failed verification **or** never reached it. * "Show me what did not verify" must include the deliveries that failed * before verification was attempted. */ source_verified?: boolean; } interface DiagnosticIncomingWebhook { event_id: string; received_at: string; merchant_id: string; profile_id: string | null; merchant_connector_id: string | null; connector: string; request_id: string; /** * Their event string. `null` means it could not be read off the body, which * is an answer rather than a failure — there is no connector method that * hands back a provider's own event name. */ provider_event_type: string | null; provider_event_id: string | null; /** Ours. `null` is an unmapped event type, which the page tints amber. */ mapped_event_type: string | null; object_type: string | null; object_ref_id: string | null; resolved_payment_id: string | null; resolved_attempt_id: string | null; /** * `null` means verification was never attempted — a different fact from * `false`, which means it was attempted and did not match. */ source_verified: boolean | null; outcome: string; outcome_detail: string | null; response_status: number; latency_ms: number; /** * `true` only when the row is positively marked test. The TEST badge gates on * this and never on the absence of it. */ test_mode: boolean | null; } /** One delivery in full — what the row drawer draws. */ interface DiagnosticIncomingWebhookDetail extends DiagnosticIncomingWebhook { /** Masked. Credential headers were replaced before storage; signatures were not. */ headers: Record; /** Masked on read as well as encrypted at rest. */ body: Record; /** * Which secret verified, in which environment, and whether the entity * matched. Never the secret itself — the fingerprint is a digest. */ verification_detail: Record | null; /** * The router log lines for this delivery. `null` when the log store is * unreachable, which the drawer must render as *unavailable* rather than as * "the router logged nothing". */ router_logs: DiagnosticRouterLog[] | null; router_logs_unavailable: DiagnosticSourceUnavailable | null; } interface DiagnosticConnectorCallListParams extends DiagnosticListParamsBase { merchant_id?: string; connector?: string[]; flow?: string[]; payment_id?: string; attempt_id?: string; request_id?: string; /** Inclusive. `400` is "everything that failed". */ status_code_min?: number; /** Exclusive, so `[400, 500)` selects client errors alone. */ status_code_max_exclusive?: number; min_latency_ms?: number; } interface DiagnosticConnectorCall { id: string; started_at: string; merchant_id: string; connector: string; flow: string; method: string; url: string; status_code: number; latency_ms: number; payment_id: string | null; attempt_id: string | null; refund_id: string | null; dispute_id: string | null; request_id: string; test_mode: boolean | null; /** * Present on the single-call read only, and masked. List rows omit them so a * page of twenty does not ship twenty payloads the table never renders. */ request?: unknown; response?: unknown; error?: unknown; } interface DiagnosticRouterLogParams { window?: DiagnosticWindow; page?: DiagnosticPage; /** `router`, `scheduler`, `drainer`. */ service?: string[]; hostname?: string[]; level?: string[]; flow?: string; merchant_id?: string; request_id?: string; contains?: string; collapse_duplicates?: boolean; } interface DiagnosticRouterLog { time: string; level: string; service: string; hostname: string | null; flow: string | null; merchant_id: string | null; request_id: string | null; message: string; /** * How many identical messages this row stands for. `null` means one line — * never `1`, which the page would render as a count badge on every row. */ repeat: number | null; } interface DiagnosticPaymentListParams extends DiagnosticListParamsBase { merchant_id?: string; profile_id?: string; connector?: string[]; status?: string[]; error_code?: string; /** * Any id pasted into the console, matched against the payment and its * attempt. Without it this tab ignored the pivot while the page drew a chip * saying the filter was applied. */ object_id?: string; /** Non-terminal for at least this long. Omit to show failures alone. */ stuck_minutes?: number; } interface DiagnosticPayment { payment_id: string; merchant_id: string; profile_id: string | null; merchant_name: string | null; profile_name: string | null; connector: string | null; payment_method: string | null; payment_method_type: string | null; card_network: string | null; card_last4: string | null; amount: number; amount_captured: number | null; currency: string | null; status: string; attempt_count: number; error_code: string | null; error_message: string | null; /** * `null` when no `gateway_status_map` row maps the connector's code, which * the page renders amber: the merchant saw a raw processor string. */ unified_code: string | null; unified_message: string | null; created_at: string; modified_at: string; age_seconds: number; test_mode: boolean | null; } interface DiagnosticErrorCodeCount { code: string; count: number; /** * The same code over the previous window of equal length. `null` renders as * "new" — the code did not appear before, which zero would misreport as a * measured fall to nothing. */ previous_count: number | null; unmapped: boolean; } /** Which diagnostic writers are recording on this deployment. */ interface DiagnosticCaptureState { incoming_webhooks: boolean; connector_calls: boolean; router_logs: boolean; } interface DiagnosticOutgoingWebhookListParams extends DiagnosticListParamsBase { merchant_id?: string; profile_id?: string; object_id?: string; event_type?: string[]; delivery?: 'delivered' | 'retrying' | 'stopped'; } interface DiagnosticOutgoingAttempt { event_id: string; created_at: string; delivered: boolean | null; /** `events` records whether an attempt was notified, not what the shop answered. */ response_status: number | null; } interface DiagnosticOutgoingWebhook { event_id: string; initial_attempt_id: string | null; created_at: string; merchant_id: string | null; profile_id: string | null; event_type: string; object_id: string; object_type: string; /** Not carried on the event row — the URL lives on the profile and is re-read per attempt. */ endpoint: string | null; /** One entry per attempt, oldest first — the row of squares the page draws. */ attempts: DiagnosticOutgoingAttempt[]; delivered: boolean | null; /** * Why the chain stopped, when it did — `null` while it is still retrying. * * Named `terminal_reason` because that is what the router sends * (`OutgoingWebhookRow` in the OpenAPI spec). It was `delivery_terminal_reason` * here, which typechecks against nothing and reads `undefined` at runtime, so * every undelivered row looked like one still inside its retry budget and the * "endpoint rejected" state was unreachable. */ terminal_reason: string | null; test_mode: boolean | null; } interface DiagnosticOutgoingWebhookSummary { delivered_count: number; total_count: number; retrying_count: number; stopped_count: number; worst_endpoint: string | null; worst_endpoint_failures: number; } interface DiagnosticQueueListParams { page?: DiagnosticPage; name?: string[]; runner?: string[]; status?: string[]; overdue_only?: boolean; tracking_id?: string; } interface DiagnosticQueueItem { id: string; name: string | null; runner: string | null; tracking_id: string; retry_count: number; status: string; business_status: string; schedule_time: string; /** Negative when overdue — the case the page tints. */ due_in_seconds: number; created_at: string; } interface DiagnosticQueueSummary { pending_count: number; processing_count: number; retrying_count: number; finished_in_window: number; oldest_overdue_seconds: number | null; /** Approvals waiting on a person — a different queue with a different remedy. */ pending_approvals: number; } interface DiagnosticChangeListParams { window?: DiagnosticWindow; page?: DiagnosticPage; merchant_id?: string; kind?: string[]; } interface DiagnosticChange { id: string; occurred_at: string; /** `connector` | `routing` | `fees` | `access` | `config`. */ kind: string; summary: string; /** `null` for a change no person made — a scheduled job. A fact, not a gap. */ actor: string | null; merchant_id: string | null; profile_id: string | null; } type DiagnosticHealthState = 'healthy' | 'degraded' | 'failing' | 'unknown'; interface DiagnosticHealthTile { subject: string; state: DiagnosticHealthState; /** Already formatted — "4/4", "61.3%", "Stalled". The unit differs per tile. */ value: string; delta: string | null; note: string | null; spark: number[]; } type DiagnosticAttentionSeverity = 'critical' | 'warning' | 'watch'; interface DiagnosticAttentionItem { id: string; severity: DiagnosticAttentionSeverity; title: string; detail: string; scope: string; count: number; count_unit: string; amount_at_risk: number | null; currency: string | null; shops_touched: number; since_seconds: number | null; /** The filter set Investigate applies. Opaque to the backend. */ investigate: Record; } interface DiagnosticAttentionBoard { items: DiagnosticAttentionItem[]; computed_at: string; /** * What was checked, so an empty board reads as a verdict rather than as a * panel that failed to load. A check that could not run is absent from this * list rather than silently counted as clear. */ checks_run: string[]; vitals: DiagnosticHealthTile[]; } interface DiagnosticAttentionParams { window?: DiagnosticWindow; environment?: DiagnosticEnvironment; } interface DiagnosticFiringAlert { name: string; /** From the alert's own labels. This service does not re-rank Alertmanager. */ severity: string; summary: string; firing_since: string; labels: Record; } interface DiagnosticReplicaHealth { hostname: string; version: string | null; build: string | null; state: DiagnosticHealthState; dependencies: [string, string][]; } interface DiagnosticDependencyCard { subject: string; value: string; unit: string; fraction: number | null; state: DiagnosticHealthState; note: string | null; } interface DiagnosticInfrastructure { replicas: DiagnosticReplicaHealth[]; /** A finding in its own right: one replica answering differently explains a lot. */ build_mismatch: boolean; dependencies: DiagnosticDependencyCard[]; } interface DiagnosticNearMatch { id: string; kind: string; description: string; } interface DiagnosticEmptyReason { /** `outside_window` | `test_mode` | `typo`. */ code: string; /** The one-click fix. `null` for `typo`, which has none. */ fix: Record | null; } /** * What the search box decided a pasted id is. * * `kind` says what it looks like; `found` says whether a row exists. Different * answers, drawn differently: a well-shaped id that matches nothing gets the * three reasons and their fixes, never an empty table. */ interface DiagnosticResolvedId { id: string; kind: string | null; found: boolean; near_matches: DiagnosticNearMatch[]; reasons: DiagnosticEmptyReason[]; } interface DiagnosticTraceSpan { source: string; label: string; started_at: string; /** `null` for a span that has not finished — an enqueued job still unpicked. */ duration_ms: number | null; depth: number; failed: boolean; detail: Record | null; } interface DiagnosticTrace { resolved: DiagnosticResolvedId; payment_id: string | null; spans: DiagnosticTraceSpan[]; /** * Sources that could not be read. A waterfall with an unexplained gap reads * as a period when nothing happened, which is the wrong conclusion. */ unavailable_sources: DiagnosticSourceUnavailable[]; } /** * Unmask one field of one object. * * `reason` is required and stored verbatim on the audit row: an unmask nobody * can review afterwards is a timestamp, not a record. */ interface DiagnosticRevealRequest { /** `incoming_webhook` | `connector_call`. */ object_type: string; object_id: string; /** A JSON pointer into the stored document, e.g. `/data/object/customer`. */ field_path: string; reason: string; } interface DiagnosticRevealResponse { field_path: string; value: unknown; /** The audit row this reveal wrote. */ audit_log_id: string; } /** Scheduled connector health cadence configured by internal operators. */ interface ConnectorHealthConfig { interval_minutes: number; } declare class Admin { private readonly request; constructor(request: RequestFn); signIn(params: AdminSignInRequest): Promise; createInternalUser(params: CreateInternalUserRequest): Promise; createTenant(params: CreateTenantUserRequest): Promise; /** * Create a new merchant admin user and merchant account atomically. * * This is the correct endpoint for bootstrapping the first admin user in a * fresh deployment — `internal-signup`/`tenant-signup` both require * pre-existing merchant records that don't exist on a clean database. * * `POST /admin/signup-with-merchant-id` */ signupWithMerchantId(params: SignUpWithMerchantIdRequest): Promise; /** Toggle public signup on/off. `POST /admin/settings/signup` */ setSignupSettings(params: SignupToggleRequest): Promise; /** Read current public-signup status. `GET /admin/settings/signup` */ getSignupSettings(): Promise; /** Full merchant bootstrap — user + merchant + project + profile + keys. `POST /admin/onboard-merchant` */ onboardMerchant(params: OnboardMerchantRequest): Promise; } declare class AdminPortal { private readonly request; constructor(request: RequestFn); listCustomers(params?: AdminCustomerListParams): Promise; getCustomer(customerId: string): Promise; listTransactions(params?: AdminTransactionListParams): Promise; /** * The admin transaction search as a file. `GET /admin-portal/transactions/export` * * Takes the same filters as {@link AdminPortal.listTransactions}, sent the * same way, and returns the whole match set rather than a page — bounded at * 25,000 rows (500 for `pdf`) and refused past that with `DE_07` rather than * truncated. Every page of it is read inside one database snapshot, so a * payment updated while the file downloads is neither repeated nor skipped. * * `csv` and `json` are streamed and held to their `X-Delopay-Record-Count`; * see {@link ExportTransferOptions} for progress, cancellation and the * `EXPORT_INCOMPLETE` check. The format is negotiated by `Accept` and * defaults to `json`. */ exportTransactions(params?: AdminTransactionExportParams, options?: JsonExportOptions): Promise>; exportTransactions(params: AdminTransactionExportParams | undefined, options: BinaryExportOptions): Promise; exportTransactions(params: AdminTransactionExportParams | undefined, options: ExportOptions): Promise | Blob>; /** * Full detail for a single transaction of ANY merchant — the same * `PaymentResponse` the merchant `payments.retrieve` returns. Admin-scoped: * the JWT (or admin API key) does not need to belong to the payment's * merchant; the backend resolves the owning merchant and reads it read-only * (no connector sync). */ getTransaction(paymentId: string): Promise; /** * Per-attempt history (retries across connectors, decline reasons) for a * single transaction of ANY merchant. */ getTransactionAttempts(paymentId: string): Promise; /** * Status timeline (intent / attempt / refund / dispute transitions) for a * single transaction of ANY merchant. `complete: false` marks timelines * partially reconstructed from current records. */ getTransactionStatusHistory(paymentId: string): Promise; /** * Refunds for a single transaction of ANY merchant. */ getTransactionRefunds(paymentId: string): Promise; /** * Refunds of ANY merchant mirrored from a connector webhook at a * non-terminal status that no sync can advance. Newest first. */ listUnresolvedRefunds(params?: AdminUnresolvedRefundListParams): Promise; analytics(params: AdminAnalyticsRequest): Promise; overviewStats(): Promise; paymentAnalytics(params: PaymentAnalyticsRequest): Promise; /** * One drill level of the analytics dashboard: the scope's daily series + * processor mix and its direct children's series. Range / metric / donut * toggles apply client-side; only a drill (passing merchant_id / project_id * / shop_id) fetches the next level. */ analyticsScope(params?: AnalyticsScopeRequest): Promise; /** * Device analytics over the canonical client-context observation per * payment, rooted at all merchants and drillable via `merchant_id` / * `project_id` / `shop_id` like `analyticsScope`. Answers 200 with * `enabled: false` when the client-context optimisation-use switch is off. */ analyticsDevices(params?: ClientAnalyticsRequest): Promise; /** * Geo analytics over the canonical client-context observation per payment, * rooted at all merchants. `mode` selects the location claim (`ip` default, * `billing`). */ analyticsGeo(params?: ClientAnalyticsRequest): Promise; /** * The recent payments behind one clicked geo target (map country/city or * local-hours heatmap cell), rooted at all merchants. Capped at 50 rows, * newest first, with the full match count alongside. */ analyticsGeoTransactions(params: GeoDrillRequest): Promise; /** * The recent payments behind one clicked device target (browser/platform * family, device-model label or device class), rooted at all merchants. * 50 rows per page (`offset` for the next page), newest first. */ analyticsDeviceTransactions(params: DeviceDrillRequest): Promise; /** * The payments behind one clicked element of the admin payments dashboard * (processor / method slice, outcome segment, series bucket or breakdown * row), rooted at all merchants. Same contract as the merchant surface's * `analytics.scopeTransactions`. `GET /admin-portal/analytics/scope/transactions` */ analyticsScopeTransactions(params: ScopeDrillRequest): Promise; /** * Subscription analytics over `subscription` and `invoice`, rooted at all * merchants and drillable via `merchant_id` / `project_id` / `shop_id` like * `analyticsScope`. The `children` block at the root is the merchant * breakdown — there is no separate endpoint for it. * * Half the figures are **stocks** (a snapshot at the window's end, not a sum * over it), so `est_monthly_volume_usd` and `active` can match across a * 7-day and a 30-day window while `billed_volume_usd` does not. Day * granularity only. */ analyticsSubscriptions(params?: SubscriptionAnalyticsRequest): Promise; /** * The billing cycles behind one clicked element of the admin subscription * dashboard: an invoice outcome, a processor slice on either axis, a plan * row, a subscription status, a movement component, a series bucket or a * breakdown row. 50 rows per page (`offset` for the next), newest first, * with the full match count alongside. * * A cycle that never reached a payment is listed too — that is what "still * unpaid" means — and carries its invoice id as `payment_id` with * `invoice_id` set to the same value. */ analyticsSubscriptionsList(params: SubscriptionDrillRequest): Promise; /** * Platform billing dashboard: total balance across all ledger accounts (+ * the net change), top-ups, fees collected, and the day-by-day ledger flow. * All amounts are in USD minor units. */ ledgerAnalytics(params?: AdminLedgerAnalyticsRequest): Promise; /** * Billing profiles no operator listing can reach, and the accounts that may * have taken one over. * * Deleting a merchant account leaves its billing profile — with its * balance, its Stripe customer and its saved card — behind, and the * Merchants listing enumerates merchant accounts, so such a profile is * absent from every operator surface rather than flagged on one. This reads * from the billing side instead, so it finds them. * * Both lists come back complete rather than paged: the healthy answer is two * empty arrays, and a truncated answer to *"is the set empty"* would read as * a clean bill of health. * * `adoption_candidates` are candidates, not findings — confirm a row against * the audit log before acting on it. */ orphanedBillingProfiles(): Promise; /** * Retrieve a merchant account via the admin portal. Unlike * `merchantAccounts.retrieve`, this route accepts an admin JWT (or admin API * key) and does not require the JWT to be scoped to the target merchant. */ retrieveAccount(merchantId: string): Promise; /** * Update a merchant account via the admin portal. Authenticated via admin JWT * or admin API key. */ updateAccount(merchantId: string, params: MerchantAccountUpdateRequest): Promise; /** * Delete a merchant account via the admin portal. Authenticated via admin JWT * or admin API key. */ deleteAccount(merchantId: string): Promise; /** * Create a brand-new user attached to the given merchant. The user is * marked `is_verified = true` so the admin can hand off credentials * immediately — no email round-trip is sent. */ createUserForMerchant(customerId: string, body: AdminCreateUserForMerchantRequest): Promise; /** * Edit a user record. Any subset of fields may be supplied. `role_id` * requires `merchant_id`. `password` triggers a password reset (validated * against signup policy + JWT blacklist). `reset_2fa` clears TOTP state * so the user re-enrolls on next login. `is_active` supports both * directions: false soft-disables, true reactivates a soft-disabled user. * * Throws a `400` with `code === 'UR_66'` when the change would leave a * merchant with no administrator — `is_active: false` or `is_verified: * false` on, or a `role_id` demoting, the only active user whose role can * manage that merchant's users. Nothing is written. `error.data` carries a * {@link LastAdministratorRefusal} naming the merchant and which change was * refused; render that rather than the generic message. */ updateUser(userId: string, body: AdminUpdateUserRequest): Promise; /** * Soft-delete a user globally: deactivates the row, blacklists existing * JWTs, and wipes credentials. Distinct from `deleteUserRole`, which * removes a single role binding while leaving the user signed-in elsewhere. * * Throws the same `UR_66` as {@link updateUser} when the user is the last * administrator of any merchant they belong to, with `route: 'delete'`. */ deleteUser(userId: string): Promise; /** * Set a target merchant's shop iframe-allowed origins. Internal-admin * route — accepts an admin JWT or admin API key without requiring the * caller to be scoped to the target merchant. Pass `null` (or an empty * array) to clear the allowlist back to same-origin only. * * Server validates each origin: full origin (scheme + host[:port]), * no path/query/fragment, no wildcards. */ updateShopIframeOrigins(merchantId: string, profileId: string, origins: string[] | null): Promise; /** * Set (or clear) a target merchant shop's home country — the geo * dashboard's cross-border baseline. Internal-admin route. Pass `null` to * clear back to "international / no home country" (the default). * * `POST /admin-portal/accounts/{merchantId}/business-profile/{profileId}/home-country` */ updateShopHomeCountry(merchantId: string, profileId: string, homeCountry: string | null): Promise; /** * One merchant's sell-to restrictions — the merchant-wide policy and every * shop's effective policy. Read-only; staff change a policy through the * merchant routes. * * `GET /admin-portal/accounts/{merchantId}/sell-to-restrictions` */ getSellToRestrictions(merchantId: string): Promise; /** Admin setting for one merchant, independent of the merchant's own choice. */ getMerchantCheckoutBrowserInfo(merchantId: string): Promise; /** Replace the admin merchant setting. Any OFF remains final; changes are audited. */ updateMerchantCheckoutBrowserInfo(merchantId: string, body: UpdateCheckoutBrowserInfoScopeRequest): Promise; /** Platform-wide policy for delivery of the five device fields to one connector. */ getConnectorCheckoutBrowserInfo(connector: string): Promise; /** * Store the connector policy. OFF withholds the fields for every merchant * only on backends with connector-delivery enforcement deployed. Earlier * backends store this setting without enforcing it; a successful save alone * is not evidence that delivery is blocked. */ updateConnectorCheckoutBrowserInfo(connector: string, body: UpdateCheckoutBrowserInfoScopeRequest): Promise; /** * The deployment's replay-masking rules: extra page elements the session * recorder hides on top of the ones it always hides. * * `GET /admin-portal/replay-masking` */ getReplayMasking(): Promise; /** * Replace the deployment's replay-masking rules. Additive to the recorder's * built-in floor: a rule can widen what a recording leaves out and can never * reveal something the recorder hides unconditionally. * * `PUT /admin-portal/replay-masking` */ updateReplayMasking(params: UpdateReplayMaskingConfigRequest): Promise; /** * One merchant's replay-masking rules. * * `GET /admin-portal/accounts/{merchantId}/replay-masking` */ getMerchantReplayMasking(merchantId: string): Promise; /** * Replace one merchant's replay-masking rules. * * `PUT /admin-portal/accounts/{merchantId}/replay-masking` */ updateMerchantReplayMasking(merchantId: string, params: UpdateReplayMaskingConfigRequest): Promise; /** * One shop's replay-masking rules. * * `GET /admin-portal/accounts/{merchantId}/business-profile/{profileId}/replay-masking` */ getShopReplayMasking(merchantId: string, profileId: string): Promise; /** * Replace one shop's replay-masking rules. * * `PUT /admin-portal/accounts/{merchantId}/business-profile/{profileId}/replay-masking` */ updateShopReplayMasking(merchantId: string, profileId: string, params: UpdateReplayMaskingConfigRequest): Promise; /** * Soft-delete a transaction of ANY merchant. Only payments whose status * is in the admin delete policy can be deleted; the action is audited. * * `DELETE /admin-portal/transactions/{paymentId}` */ deleteTransaction(paymentId: string): Promise; /** * Recover (undelete) a soft-deleted transaction. Audited. * * `POST /admin-portal/transactions/{paymentId}/recover` */ recoverTransaction(paymentId: string): Promise; /** * Client/device observations captured while the buyer interacted with a * transaction of ANY merchant, oldest first. * * `GET /admin-portal/transactions/{paymentId}/client-context` */ getTransactionClientContext(paymentId: string): Promise; /** * What the rail charged for one attempt of a transaction of ANY merchant, * off the attempt's settlement line. `line_recorded: false` means * no line exists for the attempt; an absent amount is "no figure", never * zero. * * `GET /admin-portal/transactions/{paymentId}/attempts/{attemptId}/processor-cost` */ getTransactionAttemptProcessorCost(paymentId: string, attemptId: string): Promise; /** Read or refresh signed processor fees for a payment. Internal admin access required. */ getTransactionProcessorCostEvents(paymentId: string, params?: AdminProcessorCostEventsParams): Promise; /** * DeloPay's own processor cost schedules — our acquirer contract, which * prices every merchant that has no schedule of its own, except an account * a shop owner brought (that rate is in their contract, not ours, and lives * on the merchant surface). * * Never returned on the merchant surface: these rates are DeloPay's cost * base. The rows carry no merchant. * * `GET /admin-portal/processor-costs` */ listProcessorCostSchedules(): Promise; /** * Record a DeloPay-wide cost schedule — what a rail charges DeloPay, for * rails that report no fee on the payment itself. A cost derived from one * of these is marked `estimated` on the settlement line, never `reported`. * * `POST /admin-portal/processor-costs` */ createProcessorCostSchedule(params: CreateProcessorCostScheduleRequest): Promise; /** * Record several DeloPay-wide schedules at once, all or none — copy a price * list across methods. 1 to 200 entries; an invalid entry is answered `422` * naming its index and nothing is stored. The answer lists them in request * order. * * `POST /admin-portal/processor-costs/bulk` */ bulkCreateProcessorCostSchedules(params: BulkCreateProcessorCostSchedulesRequest): Promise; /** * Close a window, deactivate a DeloPay-wide schedule or annotate it. The * rate itself is not editable: it priced transactions that already * happened, and a new rate is a new row. * * `PUT /admin-portal/processor-costs/{scheduleId}` */ updateProcessorCostSchedule(scheduleId: string, params: UpdateProcessorCostScheduleRequest): Promise; /** * Close a DeloPay-wide schedule at `effective_from` and open its successor * with the same scope and the same end, in one step: no transaction is * priced by both rates, and none falls between them. Answers the successor. * * `POST /admin-portal/processor-costs/{scheduleId}/replace` */ replaceProcessorCostSchedule(scheduleId: string, params: ReplaceProcessorCostScheduleRequest): Promise; /** * Delete a DeloPay-wide schedule. Restates nothing: every figure it derived * is already stamped on the settlement lines it priced. * * `DELETE /admin-portal/processor-costs/{scheduleId}` */ deleteProcessorCostSchedule(scheduleId: string): Promise; /** Get the connector health polling interval. `GET /admin-portal/connector-health-config` */ getConnectorHealthConfig(): Promise; /** Update the connector health polling interval. `PUT /admin-portal/connector-health-config` */ updateConnectorHealthConfig(params: { interval_minutes: number; }): Promise; /** * The global payment auto-close policy. * `GET /admin-portal/auto-close-config` */ getAutoCloseConfig(): Promise; /** * Update the global payment auto-close policy. PATCH semantics — omitted * fields are left unchanged. * * `PUT /admin-portal/auto-close-config` */ updateAutoCloseConfig(params: UpdatePaymentAutoCloseConfigRequest): Promise; /** * One merchant's auto-close override plus the effective values. * `GET /admin-portal/accounts/{merchantId}/auto-close-config` */ getMerchantAutoCloseConfig(merchantId: string): Promise; /** * Replace one merchant's auto-close override. REPLACE semantics — sending * both fields as `null` removes the override entirely. * * `PUT /admin-portal/accounts/{merchantId}/auto-close-config` */ updateMerchantAutoCloseConfig(merchantId: string, params: UpdatePaymentAutoCloseOverrideRequest): Promise; /** * The global transaction soft-delete policy (statuses admins may delete, * plus the deploy-time env ceiling). * * `GET /admin-portal/transaction-delete-config` */ getTransactionDeleteConfig(): Promise; /** * Replace the global deletable-status set. Must be a subset of the env * ceiling. * * `PUT /admin-portal/transaction-delete-config` */ updateTransactionDeleteConfig(params: UpdateTransactionDeleteConfigRequest): Promise; /** * One merchant's deletable-status override plus the effective set. * `GET /admin-portal/accounts/{merchantId}/transaction-delete-config` */ getMerchantTransactionDeleteConfig(merchantId: string): Promise; /** * Replace one merchant's deletable-status override. `statuses: null` * removes the override; an empty list forbids deletion entirely. * * `PUT /admin-portal/accounts/{merchantId}/transaction-delete-config` */ updateMerchantTransactionDeleteConfig(merchantId: string, params: UpdateTransactionDeleteOverrideRequest): Promise; /** * A merchant's settlement statements. Same shapes as the merchant-facing * `settlement` resource, admin-authenticated. * * `GET /admin-portal/accounts/{merchantId}/settlement/statements` */ listSettlementStatements(merchantId: string, params: SettlementStatementListParams): Promise; /** * One settlement statement with its breakdown. * `GET /admin-portal/accounts/{merchantId}/settlement/statements/{statementId}` */ getSettlementStatement(merchantId: string, statementId: string): Promise; /** * Export a settlement statement as PDF. Returns the raw bytes as a `Blob` * with the same auth and error handling as every other call. `options` * takes a signal, a timeout and an `onDownloadProgress` listener for the * download's bytes (the PDF carries a `Content-Length`, so `total` is set). * * `GET /admin-portal/accounts/{merchantId}/settlement/statements/{statementId}/pdf` */ downloadSettlementStatementPdf(merchantId: string, statementId: string, params?: StatementPdfParams, options?: RequestExtras): Promise; /** * A merchant's per-shop settlement overview. * `GET /admin-portal/accounts/{merchantId}/settlement/overview` */ settlementOverview(merchantId: string, params: SettlementOverviewParams): Promise; /** * A merchant's live current-period settlement rollup. * `GET /admin-portal/accounts/{merchantId}/settlement/current` */ settlementCurrent(merchantId: string, params: SettlementCurrentParams): Promise; /** * A merchant's vault state: the attach entitlement, and the vault * configuration of every shop. * * `GET /admin-portal/accounts/{merchantId}/vault` */ getVaultState(merchantId: string): Promise; /** * Attach a vault to one of a merchant's shops — creates the vault * connector account and points the profile at it in one request. The * Collect credentials are verified write-only before anything is stored. * * `POST /admin-portal/accounts/{merchantId}/vault/attach` */ attachVault(merchantId: string, params: AdminAttachVaultRequest): Promise; /** * Fetch the global welcome promotional-credit config (amount + message) * granted to newly created billing profiles. Internal-admin route. */ getPromoConfig(): Promise; /** * Update the global welcome promotional-credit config. Any subset of * `amount` (minor units) / `message` may be supplied; omitted fields are * left unchanged. Returns the resulting config. Internal-admin route. */ updatePromoConfig(params: UpdatePromoConfigRequest): Promise; } declare class AuditLogs { private readonly request; constructor(request: RequestFn); list(params?: AuditLogListParams): Promise; retrieve(logId: string): Promise; /** * The platform audit log as a file. `GET /admin-portal/audit/export` * * Takes the same filters as {@link AuditLogs.list}, and returns the whole * match set rather than a page — bounded at 25,000 rows (500 for `pdf`), and * refused past that with `DE_07` rather than truncated. `csv` and `json` are * streamed and held to their `X-Delopay-Record-Count`; see * {@link ExportTransferOptions} for progress, cancellation and the * `EXPORT_INCOMPLETE` check. * * Columns answer the question an audit asks rather than mirroring the * dashboard table: the actor, the real actor behind an impersonation, the * action, its target, when, and from where. `details` is deliberately absent — * an unbounded per-action blob is unreadable in a spreadsheet cell. */ export(params?: AuditLogListParams, options?: JsonExportOptions): Promise>; export(params: AuditLogListParams | undefined, options: BinaryExportOptions): Promise; export(params: AuditLogListParams | undefined, options: ExportOptions): Promise | Blob>; } declare class Cache { private readonly request; constructor(request: RequestFn); /** Invalidate a cache entry by key. `POST /cache/invalidate/{key}` */ invalidate(key: string): Promise>; } declare class CardIssuers { private readonly request; constructor(request: RequestFn); create(params: CardIssuerCreateRequest): Promise; update(issuerId: string, params: CardIssuerUpdateRequest): Promise; list(): Promise; } declare class Configs { private readonly request; constructor(request: RequestFn); /** Create a config. `POST /configs` */ create(params: Record): Promise>; /** Retrieve a config by key. `GET /configs/{key}` */ retrieve(key: string): Promise>; /** Update a config. `PUT /configs/{key}` */ update(key: string, params: Record): Promise>; /** Delete a config. `DELETE /configs/{key}` */ delete(key: string): Promise>; } /** * Per-shop / per-project connector restriction rules. * * Distinct from `connectorRestrictions` (the merchant-tier attach gate): * these rules allow/deny a connector for one shop (`scope: 'profile'`) or * project (`scope: 'project'`) at routing time. A `deny` is never routed even * when the connector is attached and enabled; once a scope has any `allow` it * becomes a whitelist, and the project scope takes precedence over the shop * scope. Admin-only, under `/admin/connector-restriction-rules`; exposed only * via `'@delopay/sdk/internal'`. */ declare class ConnectorRestrictionRules { private readonly request; constructor(request: RequestFn); /** * Create one allow/deny rule. A duplicate * `(merchant_id, scope, scope_id, connector)` is rejected — update or delete * the existing rule instead. */ create(body: CreateConnectorRestrictionRuleRequest): Promise; /** * List rules for one scope (`scope` + `scope_id`) or a whole merchant * (`merchant_id`). Pass exactly one selector. */ list(query: ListConnectorRestrictionRulesQuery): Promise; /** Retrieve a single rule by ID. */ retrieve(id: string): Promise; /** Update a rule's action and/or reason. */ update(id: string, body: UpdateConnectorRestrictionRuleRequest): Promise; /** Delete a rule by ID. */ delete(id: string): Promise<{ id: string; deleted: boolean; }>; } /** * Admin-only allowlist for phased connector rollouts. * * Default-open semantics: a connector with no restriction row is * usable by every merchant (current behavior). A connector with a * row is gated — only merchants in `allowed_merchant_ids` can attach * a connector account. Enforced server-side at MCA-create time. */ declare class ConnectorRestrictions { private readonly request; constructor(request: RequestFn); /** * Idempotent upsert. If a row exists for `connector_name`, its * allowlist + reason are replaced. To open the connector to * everyone again, call `delete()`. */ upsert(body: UpsertConnectorRestrictionRequest): Promise; list(): Promise; retrieve(connectorName: string): Promise; /** Removing the row makes the connector public again. */ delete(connectorName: string): Promise<{ connector_name: string; deleted: boolean; }>; } /** * The diagnostic console — everything the router did, without a * shell. * * Cross-merchant by construction: one call answers across every merchant on the * deployment. The backend gates that on the `Diagnostic` permission, which is * granted to DeloPay's internal staff roles alone, which is why this lives in * `@delopay/sdk/internal` and never on the merchant-facing client. * * ## Two shapes worth knowing before you call anything * * **Lists answer {@link DiagnosticList}**, which carries `hidden_by_environment` * beside the rows. That number is what lets a UI say "612 test-mode rows are * hidden" rather than leaving an operator unable to tell an empty tab from a * filtered one. * * **Two reads answer {@link DiagnosticPanel} instead** — {@link routerLogs} and * {@link alerts} — because their sources can be down independently of the * router. A panel is `available` with data or `unavailable` with a reason, and * that distinction is the whole point: **an unreachable log store must never be * rendered as "no errors found"**, and a `T[]` gives a caller no way to tell the * two apart. * * ## The environment filter * * Every list takes `environment`. Omitting it is read by the backend as * `'live'`, never as `'all'` — a caller that forgot to say gets the safer of the * two, and a test payment never appears in a view that reads as live. */ declare class Diagnostic { private readonly request; constructor(request: RequestFn); /** * The ranked attention board — the page's landing state, with nothing typed. * * Always carries `checks_run` and `vitals`, so an empty `items` reads as * "checked these things at 14:02, all clear" rather than as a panel that * failed to load. A check that could not run is **absent** from `checks_run` * rather than silently counted as clear. */ attention(body?: DiagnosticAttentionParams): Promise; /** * Provider webhooks received, across every merchant. * * `source_verified: false` selects rows that failed verification **or** never * reached it — the deliveries that failed before verification was attempted * are exactly the ones an operator opens this tab for. */ listIncomingWebhooks(body?: DiagnosticIncomingWebhookListParams): Promise>; /** * One delivery in full: masked headers and body, the verification verdict, * and the router log lines for its request id. * * `router_logs` is `null` — not `[]` — when the log store is unreachable, and * `router_logs_unavailable` then says why. Render the first as *unavailable*, * never as "the router logged nothing". */ getIncomingWebhook(eventId: string): Promise; /** Shop webhooks sent, across every merchant, with each event's attempts folded in. */ listOutgoingWebhooks(body?: DiagnosticOutgoingWebhookListParams): Promise>; /** * The four tiles above the shop-webhooks table. * * Counted under the same window and environment as the table but **without** * its delivery filter — the tiles say what the window holds, and applying the * filter would make every tile agree with whichever one is selected. */ outgoingWebhookSummary(body?: DiagnosticOutgoingWebhookListParams): Promise; /** * Connector calls the router made. * * List rows carry no payload. Fetch one with {@link getConnectorCall} for the * masked request and response. */ listConnectorCalls(body?: DiagnosticConnectorCallListParams): Promise>; /** One connector call, with its masked payloads. */ getConnectorCall(id: string): Promise; /** * Router logs, proxied from the deployment's log store. * * Answers a {@link DiagnosticPanel}. Check `status` before reading `data`: * `'unavailable'` means the store did not answer, which is the opposite of * "there were no errors" and must be rendered as such. */ routerLogs(body?: DiagnosticRouterLogParams): Promise>>; /** * Payments that are stuck or failed. * * Stuck means non-terminal for longer than `stuck_minutes`; failed means it * ended without succeeding inside the window. Omitting `stuck_minutes` turns * the first arm off rather than widening it. */ listPayments(body?: DiagnosticPaymentListParams): Promise>; /** * The error codes in this window, each with its count in the previous window * of equal length. * * `previous_count: null` means the code did not appear before — render it as * "new" rather than as a fall to zero. */ paymentErrorCodes(body?: DiagnosticPaymentListParams): Promise; /** * Everything about one payment, in one call: the payment, its attempts, its * status history, its client context, and what it produced — connector calls, * webhooks both ways, and scheduler jobs. * * Read `diagnostic_capture` before rendering an empty section. A payment with * no connector calls and a deployment that never recorded any are different * facts, and the second must not read as the first. * * Typed loosely on purpose: the payment, attempts, status-history and * client-context halves are the merchant-facing shapes this package already * exports, and re-declaring them here would give consumers two names for one * thing that could then drift apart. */ getPayment(paymentId: string): Promise>; /** Scheduler tasks, most overdue first. */ listQueues(body?: DiagnosticQueueListParams): Promise>; /** * The four tiles above the queues table, plus the approvals count. * * `pending_approvals` is a **different** queue from `pending_count`: a stalled * scheduler needs a consumer, a full approvals queue needs a person, and * folding them into one number would point an operator at the wrong fix. */ queueSummary(): Promise; /** * Replicas and their dependencies. * * `build_mismatch` is computed server-side rather than left for a caller to * notice by comparing strings: one replica in four answering differently * explains a whole class of "it only fails sometimes" incident, and is * invisible unless something says it out loud. */ infrastructure(): Promise; /** * Firing alerts, proxied from Alertmanager. * * Answers a {@link DiagnosticPanel} for the same reason {@link routerLogs} * does: a strip that renders empty because Alertmanager is down says "nothing * is firing", which is the most dangerous sentence this page could print. */ alerts(): Promise>; /** Config edits and admin actions inside the window. */ listChanges(body?: DiagnosticChangeListParams): Promise>; /** * What a pasted id is, and whether we hold it. * * `kind` and `found` are separate answers on purpose. A well-shaped id that * matches nothing comes back `found: false` with the three `reasons` and * their fixes — render that, never an empty table, which reads as "no such * payment" when the real answer is "outside the window" or "it is a test * payment". */ resolveId(id: string): Promise; /** * One id across every source, as an ordered span list. * * Accepts a payment, attempt, event or request id. Sources that could not be * read are named in `unavailable_sources` rather than left out: a waterfall * with an unexplained gap reads as a period when nothing happened. */ trace(id: string): Promise; /** * Unmask one field of one object. * * **Writes an audit row** naming the operator, the field and the object, * before the value is returned — a reveal that could not be audited does not * happen. Needs a dashboard JWT holding `DiagnosticReveal`; an admin API key * cannot call it, because an API key names no person. * * `reason` is required and is stored verbatim. */ reveal(body: DiagnosticRevealRequest): Promise; } declare class Gsm { private readonly request; constructor(request: RequestFn); create(params: GsmRuleCreateRequest): Promise; retrieve(params: Record): Promise; update(params: GsmRuleUpdateRequest): Promise; delete(params: Record): Promise; } /** * Platform-level ledger adjustments on a merchant's balance. Admin-only * routes under `/billing/{merchantId}/admin/credit|debit`. Exposed only * via `'@delopay/sdk/internal'` so the public merchant SDK doesn't * advertise the admin adjustment path in autocomplete. */ declare class PlatformBilling { private readonly request; constructor(request: RequestFn); /** * Manually credit a merchant's balance (e.g. promotional credit, * dispute reversal, manual correction). * * @param merchantId - The merchant account ID. * @param params - Credit amount and reason. */ credit(merchantId: string, params: AdminAdjustmentRequest): Promise; /** * Manually debit a merchant's balance. * * @param merchantId - The merchant account ID. * @param params - Debit amount and reason. */ debit(merchantId: string, params: AdminAdjustmentRequest): Promise; /** * Edit a single ledger entry (amount and/or description), keeping the * merchant balance consistent: when `amount` changes, the balance is * atomically adjusted by the difference. Returns the entry id and new * balance. * * @param merchantId - The merchant account ID. * @param ledgerId - The ledger entry id to edit. * @param params - New amount / description (either optional). */ editLedgerEntry(merchantId: string, ledgerId: string, params: UpdateLedgerEntryRequest): Promise; /** * Delete a single ledger entry, reversing its amount from the merchant * balance. Returns the deleted entry id and the new balance. * * @param merchantId - The merchant account ID. * @param ledgerId - The ledger entry id to delete. */ deleteLedgerEntry(merchantId: string, ledgerId: string): Promise; /** * Manually suspend a merchant (e.g. confirmed fraud or ToS violation), * independent of balance. A `reason` is required for audit. Throws 412 if * the merchant is trusted (clear the flag first) or already suspended. * * @param merchantId - The merchant account ID. * @param params - Suspension reason. * @returns The updated billing profile. */ suspend(merchantId: string, params: AdminSuspendRequest): Promise; /** * Lift a suspension. Restores the merchant to `active` (or `delinquent` if * the balance is at/below the hard floor) and resets the recharge-failure * counter. Throws 412 if the merchant is not suspended. * * @param merchantId - The merchant account ID. * @param params - Optional audit note. * @returns The updated billing profile. */ unsuspend(merchantId: string, params?: AdminUnsuspendRequest): Promise; /** * Set or clear the trusted (suspension-exempt) flag. Trusted merchants * cannot be suspended automatically or manually. Does not lift an existing * suspension — use {@link PlatformBilling.unsuspend} for that. * * @param merchantId - The merchant account ID. * @param params - The desired trusted state. * @returns The updated billing profile. */ setTrusted(merchantId: string, params: AdminSetTrustedRequest): Promise; /** * Set the merchant's hard floor — the balance at or below which the * merchant stops being active. A negative value grants a credit line; zero * means no negative balance at all. This moves the suspension line, it does * not remove it. The value and the caller are written to the audit log * before the floor changes, so the change is always attributable. * * Refused (412) for a positive amount, for a floor beyond the maximum * credit line of 10,000,000 minor units, or for an empty `reason`. * * Requires a router that serves the hard-floor admin route; older ones * answer `404`. * * @param merchantId - The merchant account ID. * @param params - The new floor (zero or negative) and the audit reason. * @returns The updated billing profile. */ setHardFloor(merchantId: string, params: AdminSetHardFloorRequest): Promise; /** * Mark a merchant free (not billed), or put it back on the prepaid model. * While free, no platform fee is deducted, the payment gate never blocks on * billing status, top-ups are refused and auto-recharge is inert. Marking * free needs a `reason` and is refused (412) while an admin suspension is in * force — lift that first. * * Requires a router that supports the free flag; older ones answer `404`. * * @param merchantId - The merchant account ID. * @param params - The desired free state and, when marking free, the reason. * @returns The updated billing profile. */ setFree(merchantId: string, params: AdminSetFreeRequest): Promise; /** * Delete a merchant's **entire** ledger. Every live entry is soft-deleted — * kept, so a replayed fee deduction or top-up webhook still no-ops — the * balance is set to zero and the status re-derived (`active` for a free * merchant; an active paying merchant lands in `delinquent`). Refused (412) * while the merchant has shop allocations. Audited. * * Requires a router that serves the ledger admin routes; older ones answer * `404`. * * @param merchantId - The merchant account ID. * @param params - The reason, required for audit. * @returns What was removed and the post-reset profile. */ resetLedger(merchantId: string, params: AdminResetLedgerRequest): Promise; /** * (Re)create a merchant's ledger, optionally seeded with an opening * balance. Ensures the billing profile exists (created without the welcome * promo credit) and, when `opening_balance` is set, writes one * `opening_balance` entry through the same atomic helper an admin credit * uses. Refused (412) while live entries or a non-zero balance remain — * reset first. Does not clear the free flag. Audited. * * Requires a router that serves the ledger admin routes; older ones answer * `404`. * * @param merchantId - The merchant account ID. * @param params - Opening balance (minor units), currency for a new profile, and the reason. * @returns The opening entry id (if one was written) and the profile. */ createLedger(merchantId: string, params: AdminCreateLedgerRequest): Promise; } /** * Platform-wide fee schedule management. Admin-only routes under * `/admin/fees/*`. Exposed only via `'@delopay/sdk/internal'`. * * `platformFees.rules` manages the platform-owned Euclid fee-rule program per * merchant, which takes precedence over the flat platform schedules. Build the * program with `feeProgram()`. */ declare class PlatformFees { private readonly request; /** Platform-owned Euclid fee-rule program (`/admin/fees/rules`). */ readonly rules: PlatformFeeRulesManager; constructor(request: RequestFn); /** Create a platform fee schedule for a specific merchant. */ create(params: FeeScheduleCreateRequest, merchantId: string): Promise; /** List every platform fee schedule assigned to a merchant. */ list(merchantId: string): Promise; /** Retrieve a single platform fee schedule by ID. */ retrieve(feeId: string): Promise; /** Update a platform fee schedule. */ update(feeId: string, params: FeeScheduleUpdateRequest): Promise; /** Delete a platform fee schedule. */ delete(feeId: string): Promise; } /** * Manages a merchant's platform-owned Euclid fee-rule programs (admin surface), * merchant-wide or per-shop (one active program per scope; a shop-scoped * program wins for its shop, else the merchant-wide one applies). Build the * `algorithm` with `feeProgram()`. The SDK injects `fee_owner: 'platform'`; set * `profile_id` on the input to scope a program to a shop. */ declare class PlatformFeeRulesManager { private readonly request; constructor(request: RequestFn); /** Create or replace the platform fee-rule program for a merchant. */ upsert(params: PlatformFeeRuleInput, merchantId: string): Promise; /** * Retrieve the active platform fee-rule program for a scope, or `null`. * `profileId` omitted = merchant-wide program; set = that shop's program. */ retrieve(merchantId: string, profileId?: string): Promise; /** * Deactivate a platform fee-rule program. Idempotent. `profileId` omitted * targets the merchant-wide program; set targets only that shop's program. */ delete(merchantId: string, profileId?: string): Promise; /** * Dry-run a candidate fee-rule program against a sample transaction. * Returns the matched rule name, whether it fell through, and the computed fee. * Does not persist anything. */ preview(input: FeeRulePreviewRequest, merchantId: string): Promise; } /** * Internal-only Delopay client for DeloPay staff tooling (the admin * control-center, audit UIs, etc.). Extends the public `Delopay` surface * with admin-plane resources that must **not** be discoverable from the * merchant-facing package entry. * * Import path: `import { DelopayInternal } from '@delopay/sdk/internal'`. * The merchant-facing `import { Delopay } from '@delopay/sdk'` never * surfaces these. */ declare class DelopayInternal extends Delopay { /** Bootstrap admin endpoints — signup, signin, onboarding. */ readonly admin: Admin; /** Platform-wide customer, transaction, analytics, merchant-account ops. */ readonly adminPortal: AdminPortal; /** Audit log reads. */ readonly auditLogs: AuditLogs; /** Backend cache invalidation. */ readonly cache: Cache; /** Platform card-issuer program management. */ readonly cardIssuers: CardIssuers; /** Generic platform config store. */ readonly configs: Configs; /** Per-merchant connector allowlist for phased rollouts. */ readonly connectorRestrictions: ConnectorRestrictions; /** Per-shop / per-project connector allow-deny rules (routing-time). */ readonly connectorRestrictionRules: ConnectorRestrictionRules; /** * The diagnostic console — everything the router did, without a shell. * Cross-merchant, and gated on the staff-only `Diagnostic` permission. */ readonly diagnostic: Diagnostic; /** GSM (Gateway Status Mapping) routing rules. */ readonly gsm: Gsm; /** Admin-only ledger credits/debits against a merchant's balance. */ readonly platformBilling: PlatformBilling; /** Platform-wide fee schedules assigned to merchants. */ readonly platformFees: PlatformFees; constructor(...args: ConstructorParameters); } export { Admin, type AdminAdjustmentRequest, type AdminAdjustmentResponse, type AdminAnalyticsRequest, type AdminAttachVaultRequest, type AdminAttachVaultResponse, type AdminAttemptProcessorCost, type AdminAttemptProcessorCostBase, type AdminAttemptProcessorCostKnown, type AdminAttemptProcessorCostUnrecorded, type AdminAttemptProcessorCostWithoutFigure, type AdminAuditLogExportRecord, type AdminCreateLedgerRequest, type AdminCreateLedgerResponse, type AdminCreateUserForMerchantRequest, type AdminCustomerDetail, type AdminCustomerListParams, type AdminCustomerListResponse, type AdminLedgerAnalyticsRequest, type AdminLedgerAnalyticsResponse, type AdminOrphanedBillingProfilesResponse, AdminPortal, type AdminProcessorCostEventsParams, type AdminResetLedgerRequest, type AdminResetLedgerResponse, type AdminSetFreeRequest, type AdminSetHardFloorRequest, type AdminSetTrustedRequest, type AdminShopVaultState, type AdminSignInRequest, type AdminSuspendRequest, type AdminTransactionExportParams, type AdminTransactionExportRecord, type AdminTransactionListParams, type AdminTransactionListResponse, type AdminUnresolvedRefund, type AdminUnresolvedRefundListParams, type AdminUnresolvedRefundListResponse, type AdminUnsuspendRequest, type AdminUpdateUserRequest, type AdminUserResponse, type AdminVaultEntitlementState, type AdminVaultEnvironmentState, type AdminVaultStateResponse, AnalyticsScopeRequest, AnalyticsScopeResponse, type AuditActorInfo, type AuditActorKind, type AuditImpersonationKind, type AuditLogListParams, type AuditLogListResponse, type AuditLogResponse, AuditLogs, type AuditSessionInfo, AuthResponse, type AuthorizeResponse, type BillingProfileAdoptionCandidate, BillingProfileResponse, BinaryExportOptions, BulkCreateProcessorCostSchedulesRequest, Cache, type CardIssuerCreateRequest, type CardIssuerListResponse, type CardIssuerResponse, type CardIssuerUpdateRequest, CardIssuers, CheckoutBrowserInfoScopeResponse, ClientAnalyticsRequest, Configs, type ConnectorHealthConfig, type ConnectorRestrictionResponse, type ConnectorRestrictionRuleAction, type ConnectorRestrictionRuleResponse, ConnectorRestrictionRules, type ConnectorRestrictionScope, ConnectorRestrictions, type ConnectorVisibility, type CreateConnectorRestrictionRuleRequest, type CreateInternalUserRequest, CreateProcessorCostScheduleRequest, type CreateTenantUserRequest, type CustomerSummary, type CustomerUser, Delopay, DelopayInternal, DeviceDrillRequest, DevicesAnalyticsResponse, Diagnostic, type DiagnosticAttentionBoard, type DiagnosticAttentionItem, type DiagnosticAttentionParams, type DiagnosticAttentionSeverity, type DiagnosticCaptureState, type DiagnosticChange, type DiagnosticChangeListParams, type DiagnosticConnectorCall, type DiagnosticConnectorCallListParams, type DiagnosticDependencyCard, type DiagnosticEmptyReason, type DiagnosticEnvironment, type DiagnosticErrorCodeCount, type DiagnosticFiringAlert, type DiagnosticHealthState, type DiagnosticHealthTile, type DiagnosticIncomingWebhook, type DiagnosticIncomingWebhookDetail, type DiagnosticIncomingWebhookListParams, type DiagnosticInfrastructure, type DiagnosticList, type DiagnosticNearMatch, type DiagnosticOutgoingAttempt, type DiagnosticOutgoingWebhook, type DiagnosticOutgoingWebhookListParams, type DiagnosticOutgoingWebhookSummary, type DiagnosticPage, type DiagnosticPanel, type DiagnosticPayment, type DiagnosticPaymentListParams, type DiagnosticQueueItem, type DiagnosticQueueListParams, type DiagnosticQueueSummary, type DiagnosticReplicaHealth, type DiagnosticResolvedId, type DiagnosticRevealRequest, type DiagnosticRevealResponse, type DiagnosticRouterLog, type DiagnosticRouterLogParams, type DiagnosticSourceUnavailable, type DiagnosticTrace, type DiagnosticTraceSpan, type DiagnosticWindow, DrillResponse, ExportEnvelope, ExportOptions, FeeRulePreviewRequest, FeeRulePreviewResponse, FeeScheduleCreateRequest, FeeScheduleResponse, FeeScheduleUpdateRequest, FeeStatementDetail, type FeeTotalBound, GeoAnalyticsResponse, GeoDrillRequest, Gsm, type GsmDecision, type GsmRuleCreateRequest, type GsmRuleResponse, type GsmRuleUpdateRequest, JsonExportOptions, type LastAdministratorRefusal, type LastAdministratorRoute, type LedgerDayBucket, type LedgerMerchant, type ListConnectorRestrictionRulesQuery, MerchantAccountResponse, MerchantAccountUpdateRequest, type OnboardMerchantRequest, type OnboardMerchantResponse, type OrphanedBillingProfile, type OverviewStat, type OverviewStatsResponse, type PaymentAnalyticsRequest, type PaymentAnalyticsResponse, PaymentAttemptsListResponse, type PaymentAutoCloseConfigResponse, type PaymentAutoCloseOverrideResponse, PaymentClientContextListResponse, type PaymentPeriodStats, PaymentResponse, PaymentStatusHistoryResponse, PaymentsDeleteResponse, type PlatformAnalyticsResponse, PlatformBilling, PlatformFeeRuleInput, PlatformFeeRuleRecord, PlatformFees, ProcessorCostEstimateBasis, ProcessorCostEventsResponse, ProcessorCostScheduleResponse, ProfileResponse, ProjectResponse, type PromoConfigResponse, RefundListResponse, RefundStatus, ReplaceProcessorCostScheduleRequest, type ReplayMaskMode, type ReplayMaskingConfigResponse, type ReplayMaskingRule, RequestExtras, RequestFn, ScopeDrillRequest, SellToRestrictionsResponse, SettlementCostPeriod, SettlementCurrentParams, SettlementCurrentResponse, SettlementOverviewParams, SettlementOverviewResponse, SettlementStatementListParams, SettlementStatementListResponse, ShopResponse, SignUpWithMerchantIdRequest, type SignupToggleRequest, type SignupToggleResponse, StatementPdfParams, SubscriptionAnalyticsRequest, SubscriptionAnalyticsResponse, SubscriptionDrillRequest, type TransactionDeleteConfigResponse, type TransactionDeleteOverrideResponse, UpdateCheckoutBrowserInfoScopeRequest, type UpdateConnectorRestrictionRuleRequest, type UpdateLedgerEntryRequest, type UpdatePaymentAutoCloseConfigRequest, type UpdatePaymentAutoCloseOverrideRequest, UpdateProcessorCostScheduleRequest, type UpdatePromoConfigRequest, type UpdateReplayMaskingConfigRequest, type UpdateTransactionDeleteConfigRequest, type UpdateTransactionDeleteOverrideRequest, type UpsertConnectorRestrictionRequest, VaultEnvironment };