import { DescopeMcpProviderOptions } from "./schemas/options.js"; import DescopeClient from "@descope/node-sdk"; /** * Read an environment variable. * * Trims beginning and trailing whitespace. * * Will return undefined if the environment variable doesn't exist or cannot be accessed. */ export declare const readEnv: (env: string) => string | undefined; /** * Configuration for Descope MCP endpoints */ interface DescopeEndpoints { issuer: URL; authorization: URL; token: URL; revocation: URL; } /** * Extract Descope project ID from an MCP Server or Inbound App issuer path. * * Supports: * - `/v1/apps/agentic//...` (MCP Server) * - `/v1/apps/` (legacy Inbound App issuer) */ export declare function parseDescopeProjectIdFromIssuerPath(pathname: string): string | undefined; /** * Supported issuer path shapes when setting `DESCOPE_MCP_SERVER_ISSUER` or * `DESCOPE_MCP_SERVER_WELL_KNOWN_URL` (issuer path after stripping `/.well-known/openid-configuration`): * * - MCP Server: `/v1/apps/agentic//` (and optional trailing segments) * - Inbound App: `/v1/apps/` (exactly; no extra path segments) */ export declare function isSupportedDescopeIssuerPath(pathname: string): boolean; export declare class DescopeMcpProvider { readonly descope: ReturnType; readonly projectId: string; readonly managementKey?: string; readonly baseUrl: string; readonly serverUrl: string; readonly descopeMcpServerIssuer?: string; readonly descopeMcpServerWellKnownUrl?: string; readonly descopeOAuthEndpoints: DescopeEndpoints; private readonly _options; constructor({ projectId, managementKey, baseUrl, serverUrl, descopeMcpServerIssuer, descopeMcpServerWellKnownUrl, ...opts }?: DescopeMcpProviderOptions); private initializeOptions; private getIssuerFromWellKnown; private initializeOAuthEndpoints; get options(): DescopeMcpProviderOptions; /** * Issuer advertised in OAuth Authorization Server metadata (`/.well-known/oauth-authorization-server`) * and in Protected Resource metadata (`authorization_servers`). * * **Legacy (project ID + base URL only):** matches historical SDK behavior — * `new URL(projectId, baseUrl)` → `https://api.descope.com/`. * * **When MCP discovery or explicit issuer URL is configured:** uses the resolved OAuth issuer * (`descopeOAuthEndpoints.issuer`), e.g. `https://api.descope.com/v1/apps/` or the MCP issuer URL. */ get oauthMetadataIssuer(): string; } export {}; //# sourceMappingURL=provider.d.ts.map