/** * Masks a CLI AccessKey for user-visible authentication output. * Short or malformed values are fully redacted so invalid secrets are never echoed. */ export declare function maskCliAccessKey(value: unknown): string; /** * Creates a display-only copy of CLI config with credentials redacted. * * This intentionally handles only known CLI authentication paths. It must not * recursively scan arbitrary objects because those may contain business data * whose field happens to be named `accessKey`. */ export declare function redactCliConfigCredentials(config: Record): Record; /** Redacts a value only when it came from a known CLI credential config path. */ export declare function redactCliConfigValue(path: string, value: unknown): unknown;