/** * A stable, non-reversible identity for ONE (apiKey, baseUrl) pair. * * Two consumers, one derivation. The entitlements cache uses it as its key; * the org-config cache stores it so a later read can prove the record was * written by the credential now in hand. Both need exactly the same answer to * "is this the same credential?", and a second derivation of that answer is * the drift this module exists to prevent — the two caches sit in the same * state directory and would silently disagree at the edge. * * A hash, never the key itself: the org-config cache is a plaintext file on * disk, and the fingerprint is written into it. */ export declare function credentialFingerprint(apiKey: string, baseUrl: string): string;