{"version":3,"file":"cloudflare-ai-binding.d.ts","sourceRoot":"","sources":["../../src/api/cloudflare-ai-binding.ts"],"names":[],"mappings":"AAAA;;;;;;;;;;;;;;;;;;;;;;;;;;;GA2BG;AAEH,OAAO,KAAK,EAAE,aAAa,EAAE,MAAM,aAAa,CAAC;AAEjD;;;;;;;;;GASG;AACH,MAAM,WAAW,SAAS;IACzB,cAAc,EAAE,MAAM,GAAG,IAAI,CAAC;IAC9B,KAAK,CAAC,CAAC,KAAK,EAAE,OAAO,GAAG,MAAM,GAAG,GAAG,EAAE,IAAI,CAAC,EAAE,WAAW,GAAG,OAAO,CAAC,QAAQ,CAAC,CAAC;CAC7E;AAED;;;;;;;;;GASG;AACH,eAAO,MAAM,wCAAwC,+BAA+B,CAAC;AAErF;;;;;;;;;;;;;;;;;;;;GAoBG;AACH,wBAAgB,oBAAoB,CAAC,OAAO,EAAE,SAAS,GAAG,aAAa,CAUtE","sourcesContent":["/**\n * AI Gateway transport over the Workers AI binding.\n *\n * pi's Cloudflare AI Gateway support speaks HTTPS\n * (`gateway.ai.cloudflare.com/v1/{account}/{gateway}/{provider}/...`, see `api/cloudflare.ts`),\n * which needs a Cloudflare API token even when the caller is a Worker in the gateway's own\n * account.\n *\n * A Worker avoids that token by talking to the gateway through the AI binding's `fetch`\n * passthrough (`env.AI.fetch()`), which serves the gateway's provider passthrough at\n * `https://workers-binding.ai/ai-gateway/gateways/{gateway}/{provider}/{endpoint...}` — the same\n * shape as the HTTPS URL, minus the account id (the binding channel carries identity). Binding\n * calls are pre-authenticated in-account and return the provider's native wire format as a\n * regular (streaming) `Response`, so API implementations behave identically over either\n * transport.\n *\n * A model whose `baseUrl` names that route therefore needs no translation: point it there and\n * pass {@link createAiBindingFetch} as the request `fetch`. Nothing is rewritten, buffered or\n * re-encoded — method, headers, query string and the body stream go to the binding as they\n * arrive, so every method, non-JSON body and streaming request body works.\n *\n * The only thing this module adds over calling `env.AI.fetch()` yourself is a type: `Ai#fetch`\n * exists at runtime (`workerd/src/cloudflare/internal/ai-api.ts:158`) but\n * `@cloudflare/workers-types`' `Ai` class does not declare it yet, so calling it directly means\n * casting the binding at every call site. {@link AiBinding} takes the cast instead — declare\n * `fetch` optional, check it once at construction — so `env.AI` can be passed as-is. Once\n * workers-types declares `fetch`, the optional marker and the runtime check both go away.\n */\n\nimport type { FetchFunction } from \"../types.ts\";\n\n/**\n * The Workers AI binding (`env.AI`), described structurally so this module does not depend on\n * `@cloudflare/workers-types`.\n *\n * `fetch` is optional only because the published `Ai` type doesn't declare it yet — every real\n * binding has it at runtime. `aiGatewayLogId` is here to pin the type to the AI binding: it is\n * the one member unique to `Ai`, so without it this interface would also accept an `AiGateway`\n * or any hand-rolled `{ fetch }` object, which is exactly the mistake the runtime check reports\n * late.\n */\nexport interface AiBinding {\n\taiGatewayLogId: string | null;\n\tfetch?(input: Request | string | URL, init?: RequestInit): Promise<Response>;\n}\n\n/**\n * Placeholder value for auth headers on binding-routed requests. API implementations\n * require an API key or a recognized auth header (`authorization`, `x-api-key`,\n * `cf-aig-authorization`) before dispatch; binding calls are pre-authenticated, so pass\n * `cf-aig-authorization: Bearer ${CLOUDFLARE_GATEWAY_BINDING_AUTH_SENTINEL}` to satisfy\n * the check. The gateway ignores (and strips) `cf-aig-authorization` on binding-routed\n * requests. Pair it with `Authorization: null` / `x-api-key: null` so the SDKs' placeholder\n * auth headers never reach the gateway, which would treat a request-supplied auth header as a\n * BYOK provider key that overrides its stored keys — the same as it would over HTTPS.\n */\nexport const CLOUDFLARE_GATEWAY_BINDING_AUTH_SENTINEL = \"cloudflare-gateway-binding\";\n\n/**\n * Create a `fetch` backed by the AI binding, for models whose `baseUrl` already names a route\n * the binding serves — including the gateway's provider passthrough,\n * `https://workers-binding.ai/ai-gateway/gateways/{gateway}/{provider}/...`. Requests pass\n * through untouched.\n *\n * ```ts\n * const model = {\n *   // ...\n *   baseUrl: `https://workers-binding.ai/ai-gateway/gateways/${gateway}/anthropic`,\n * };\n * await models.complete(model, context, {\n *   headers: {\n *     \"cf-aig-authorization\": `Bearer ${CLOUDFLARE_GATEWAY_BINDING_AUTH_SENTINEL}`,\n *     Authorization: null,\n *     \"x-api-key\": null,\n *   },\n *   fetch: createAiBindingFetch(env.AI),\n * });\n * ```\n */\nexport function createAiBindingFetch(binding: AiBinding): FetchFunction {\n\t// `fetch` is optional on the type, so its presence is checked here — early, rather than as a\n\t// confusing failure on the first inference request.\n\tif (typeof binding.fetch !== \"function\") {\n\t\tthrow new TypeError(\"createAiBindingFetch: the AI binding does not expose fetch()\");\n\t}\n\t// Bound eagerly: `fetch` is a mutable property, so the narrowing above would not survive into\n\t// the returned closure.\n\tconst bindingFetch = binding.fetch.bind(binding);\n\treturn (input, init) => bindingFetch(input, init);\n}\n"]}