export interface Signature { keyId: string; alg: "ed25519"; /** base64 signature over the signed message (the object oid). */ sig: string; } export interface Keypair { publicKey: string; privateKey: string; } export declare function generateKeypair(): Keypair; /** * Recover the public half of an ed25519 keypair from its private PEM. * * A key file holds only the private key, so importing one used to leave the actor * "signable but not trusted" — nothing it signed could be honored (issue #96). ed25519 * private keys carry the public point, so the trusted record can be reconstructed rather * than shipped alongside; the SPKI/PEM encoding matches `generateKeypair`'s byte for byte. */ export declare function publicKeyFromPrivate(privateKeyPem: string): string; export declare function signMessage(privateKeyPem: string, message: string): string; export declare function verifyMessage(publicKeyPem: string, message: string, sigB64: string): boolean; export interface KeyRecord { keyId: string; publicKey: string; actorId: string; actorKind: "human" | "ai_agent" | "ci_bot"; } /** A registry of trusted public keys, keyed by keyId. */ export declare class Keyring { #private; register(rec: KeyRecord): void; get(keyId: string): KeyRecord | undefined; has(keyId: string): boolean; get size(): number; /** * Verify a signature over `oid`, claimed to come from `claimedActorId`. * Returns true only if the signing key is registered AND its registered actor * matches the claim — i.e. you cannot sign as ci_bot with ai_agent's key. */ verifyFor(claimedActorId: string, oid: string, sig: Signature | undefined): boolean; } //# sourceMappingURL=identity.d.ts.map