import { B as BaseXAAStateMachineConfig, X as XAAStateMachine, a as XAAFlowStep, b as XAAFlowState } from './model-sampling-support-BwZqY1MR.js'; export { A as AUTH_METHODS, c as AttributableEvidenceSource, d as AuthMethod, e as AuthorizationDiscoverySnapshot, f as AuthorizationPlanCapabilities, g as AuthorizationPlanInput, h as BrandColorCheck, C as CHECK_ERAS, i as CLAUDE_APP_CONTENT_DOMAIN_SUFFIX, j as CLAUDE_APP_DESIGN_BUDGETS, k as CLAUDE_APP_HTML_MIME, l as CLAUDE_ATTESTATIONS, m as CLAUDE_CALLBACK_URLS, n as CLAUDE_DATA_HANDLING_MODES, o as CLAUDE_DECLARED_AUTH_MODES, p as CLAUDE_DOCS_BASE_URL, q as CLAUDE_EVIDENCE_PROVENANCE, r as CLAUDE_FINDING_CLASSES, s as CLAUDE_HOST_PROFILE, t as CLAUDE_INTRUSIVENESS_LEVELS, u as CLAUDE_LATENCY_BUDGETS, v as CLAUDE_OBSERVATION_IDS, w as CLAUDE_OBSERVATION_KINDS, x as CLAUDE_OBSERVATION_SCHEMA_VERSION, y as CLAUDE_POLICY_MANIFEST, z as CLAUDE_POLICY_PAGES, D as CLAUDE_POLICY_SNAPSHOT_DATE, E as CLAUDE_READINESS_ENGINE_VERSION, F as CLAUDE_READINESS_LANES, G as CLAUDE_REQUIRED_LANES, H as CLAUDE_RUNNER_CAPABILITIES, I as CLAUDE_SUBMISSION_LIMITS, J as CONFORMANCE_CHECKER_VERSION, K as CONFORMANCE_CHECK_METADATA, L as CONFORMANCE_PROFILE_IDS, M as CONFORMANCE_RUN_SCHEMA_VERSION, N as CONFORMANCE_SUITE_KINDS, O as ClaudeAttestation, P as ClaudeCapabilityBadge, Q as ClaudeDataHandlingMode, R as ClaudeDeclaredAuthMode, S as ClaudeEvidenceProvenance, T as ClaudeExperienceObservations, U as ClaudeFindingClass, V as ClaudeFindingStatus, W as ClaudeIntrusiveness, Y as ClaudeLaneCoverage, Z as ClaudeLaneStatus, _ as ClaudeObservationId, $ as ClaudeObservationKind, a0 as ClaudeObservationState, a1 as ClaudePolicyPage, a2 as ClaudePolicySourceEntry, a3 as ClaudePolicySourceRef, a4 as ClaudeReadinessAuthMode, a5 as ClaudeReadinessFinding, a6 as ClaudeReadinessLane, a7 as ClaudeReadinessLaneResult, a8 as ClaudeReadinessResult, a9 as ClaudeReadinessRunContext, aa as ClaudeRunnerCapability, ab as ClaudeSubmissionProfile, ac as ClaudeSubmissionProfileParse, ad as CompletionSafeRedirectPlan, ae as ConformanceAdvisoryTier, af as ConformanceProfile, ag as ConformanceProfileId, ah as ConformanceProfileStamp, ai as ConformanceReport, aj as ConformanceReportCase, ak as ConformanceReportGroup, al as ConformanceRunOutcome, am as ConformanceRunReportV1, an as ConformanceScore, ao as ConformanceSkipReason, ap as ConformanceSuiteId, aq as ConformanceSuiteKind, ar as ConformanceSupport, as as DEFAULT_CONFORMANCE_SUITES, at as DEFAULT_IDENTITY_ASSERTION_FORMAT, au as DEFAULT_MCPJAM_CLIENT_ID_METADATA_URL, av as DEFAULT_NEGATIVE_TEST_MODE, aw as DEFAULT_REGISTRATION_MODE, ax as DEFAULT_REGISTRATION_STRATEGY, ay as DEFAULT_SUBJECT_IDENTIFIER_FORMAT, az as DEFAULT_XAA_CLIENT_AUTH, aA as DIRECTORY_OBSERVATION_CONFIDENCE, aB as DIRECTORY_OBSERVATION_FINDING_CLASSES, aC as DIRECTORY_OBSERVATION_LIMITS, aD as DIRECTORY_OBSERVATION_REASONS, aE as DIRECTORY_OBSERVATION_STATUSES, aF as DecodedJwtParts, aG as DerivedOAuthEmulation, aH as DescribeContext, aI as DigestVerification, aJ as DirectoryObservation, aK as DirectoryObservationConfidence, aL as DirectoryObservationEnvelope, aM as DirectoryObservationFindingClass, aN as DirectoryObservationReason, aO as DirectoryObservationState, aP as DirectoryObservationStatus, aQ as DynamicClientRegistrationCredentials, aR as DynamicClientRegistrationOutcome, aS as EMPTY_XAA_FLOW_STATE, aT as ERROR_CATALOG, aU as EVIDENCE_REUSE_REFUSALS, aV as EffectiveSandboxCsp, aW as EffectiveSandboxPermissions, aX as ErrorCatalogEntry, aY as ErrorCatalogSlug, aZ as ErrorOrigin, a_ as EvidenceReuse, a$ as EvidenceReuseExpectation, b0 as EvidenceReuseRefusal, b1 as FrontmatterIdentityCheck, b2 as IDENTITY_ASSERTION_FORMATS, b3 as ID_JAG_GRANT_PROFILE, b4 as ID_JAG_TOKEN_TYPE, b5 as ID_TOKEN_TOKEN_TYPE, b6 as IdJagClientMetadataEvaluation, b7 as IdJagMetadataEvidence, b8 as IdentityAssertionFormat, b9 as ImageDimensions, ba as ImageDimensionsResult, bb as JWT_BEARER_GRANT, bc as MCPAppsCheckId, bd as MCPCheckEra, be as MCPCheckId, bf as MCPJAM_CLIENT_URI, bg as MCPJAM_LOGO_URI, bh as MCPTasksCheckId, bi as MCP_APPS_CHECK_IDS, bj as MCP_CHECK_CATEGORIES, bk as MCP_CHECK_IDS, bl as MCP_DIRECT_IMAGE_MAX_BYTES, bm as MCP_IMAGE_MAX_MEDIA_PARTS, bn as MCP_IMAGE_MAX_TOTAL_BYTES, bo as MCP_INIT_ID, bp as MCP_LINKED_RESOURCE_MAX_READS, bq as MCP_PROTOCOL_VERSION, br as MCP_TASKS_CHECK_IDS, bs as MCP_UI_EXTENSION_ID, bt as MCP_UI_RESOURCE_MIME_TYPE, bu as McpInitializeRequest, bv as McpLinkedResourceReader, bw as McpModelOutputContent, bx as McpModelOutputContentPart, by as McpModelOutputOptions, bz as McpModelOutputWithLinkedResourcesOptions, bA as McpModelVisibleToolResultPolicy, bB as NEGATIVE_TEST_MODES, bC as NEGATIVE_TEST_MODE_DETAILS, bD as NOT_REQUESTED_OBSERVATIONS, bE as NegativeTestMode, bF as NormalizedError, bG as OAuthAuthorizationRequestResult, bH as OAuthConformanceCheckId, bI as OAuthProtocolMode, bJ as OAuthRedactedCredentialError, bK as OAuthRegistrationMode, bL as OAuthRegistrationStrategy, bM as OAuthStateMachineRunConfig, bN as OAuthStateMachineRunResult, bO as OAuthTraceProjectionContext, bP as OAuthTraceSnapshot, bQ as OAuthTraceStepSnapshot, bR as OAuthTraceStepStatus, bS as OPENAI_ARCHIVE_LIMITS, bT as OPENAI_ATTESTATIONS, bU as OPENAI_BRAND_COLOR_CONTRAST, bV as OPENAI_DATA_TYPES, bW as OPENAI_FIELD_LIMITS, bX as OPENAI_HEADLINE_STAGE, bY as OPENAI_HOST_PROFILE, bZ as OPENAI_IMAGE_CONSTRAINTS, b_ as OPENAI_LISTING_CATEGORIES, b$ as OPENAI_MCP_SKILL_LIMITS, c0 as OPENAI_OBSERVATION_IDS, c1 as OPENAI_OBSERVATION_KINDS, c2 as OPENAI_OBSERVATION_SCHEMA_VERSION, c3 as OPENAI_POLICY_MANIFEST, c4 as OPENAI_POLICY_PAGES, c5 as OPENAI_POLICY_SNAPSHOT_DATE, c6 as OPENAI_PORTAL_ERRORS, c7 as OPENAI_PORTAL_ERRORS_BY_ID, c8 as OPENAI_PORTAL_ERROR_CATEGORIES, c9 as OPENAI_READINESS_ENGINE_VERSION, ca as OPENAI_READINESS_INPUTS, cb as OPENAI_READINESS_LANES, cc as OPENAI_READINESS_STAGES, cd as OPENAI_RUNNER_CAPABILITIES, ce as OPENAI_STAGE_LANES, cf as OPENAI_SUBMISSION_MODES, cg as OPENAI_SUBMISSION_MODE_SHAPES, ch as OpenAIAgentMetadata, ci as OpenAIAgentMetadataIssue, cj as OpenAIAgentMetadataParse, ck as OpenAIArchiveObservations, cl as OpenAIAttestation, cm as OpenAICapabilityBadge, cn as OpenAIDataType, co as OpenAIExperienceObservations, cp as OpenAILaneCoverage, cq as OpenAILaneStatus, cr as OpenAIListingCategory, cs as OpenAIObservationId, ct as OpenAIObservationKind, cu as OpenAIObservationState, cv as OpenAIPluginPackageEvidence, cw as OpenAIPolicyPage, cx as OpenAIPolicySourceEntry, cy as OpenAIPolicySourceRef, cz as OpenAIPortalErrorCategory, cA as OpenAIPortalErrorDefinition, cB as OpenAIPortalIssue, cC as OpenAIReadinessFinding, cD as OpenAIReadinessLane, cE as OpenAIReadinessLaneResult, cF as OpenAIReadinessResult, cG as OpenAIReadinessRunContext, cH as OpenAIReadinessStage, cI as OpenAIReadinessStageResult, cJ as OpenAIRunnerCapability, cK as OpenAISubmissionMode, cL as OpenAISubmissionProfile, cM as OpenAISubmissionProfileParse, cN as OutcomeCheckLike, cO as PROTOCOL_VERSION_ERAS, cP as PROTOCOL_VERSION_INFO, cQ as ParsedDigest, cR as ProfileCheckLike, cS as REDACTED, cT as REGISTRATION_STRATEGIES, cU as RETRYABLE_NODE_ERROR_CODES, cV as RegistrationMode, cW as RegistrationStrategy, cX as ResolveSandboxCspArgs, cY as ResolveSandboxPermissionsArgs, cZ as ResolvedAuthorizationPlan, c_ as ResourceDeclaredCsp, c$ as RunServerDoctorInput, d0 as SAML2_TOKEN_TYPE, d1 as SUBJECT_IDENTIFIER_FORMATS, d2 as SandboxCspDomainSet, d3 as SandboxCspMode, d4 as SandboxCspPolicy, d5 as SandboxPermissionsMode, d6 as SandboxPermissionsPolicy, d7 as ScoredAdvisory, d8 as ServerDoctorDependencies, d9 as SkillIntegrityError, da as SubjectIdentifierFormat, db as SupportedDigestAlgorithm, dc as TASKS_DECLARATION_REQUIRED_ERROR_CODE, dd as TOKEN_EXCHANGE_GRANT, de as UNKNOWN_TASK_ERROR_CODE, df as UnsupportedCharacter, dg as XAACheckStatus, dh as XAACompatibilityCheck, di as XAACompatibilityReport, dj as XAACompatibilityVerdict, dk as XAADecodedJwt, dl as XAAHttpHistoryEntry, dm as XAAInfoLogEntry, dn as XAAJWTInspectionIssue, dp as XAARequestExecutor, dq as XAARequestResult, dr as XAAVendor, ds as XAAVendorHint, dt as XAAVendorVerdict, du as XAA_AS_METADATA_NAMES, dv as XAA_CLIENT_AUTH_METHODS, dw as XAA_DEBUG_CLIENT_ID_METADATA_URL, dx as XAA_DEBUG_IDP_CLIENT_ID, dy as XAA_ENTERPRISE_POLICY_EXTENSION, dz as XAA_ENTERPRISE_POLICY_IDPS, dA as XAA_IDP_KID, dB as XAA_MCP_EXTENSION, dC as XaaCapabilityEvidence, dD as XaaClientAuthMethod, dE as XaaDcrCredentialCache, dF as XaaEnterprisePolicy, dG as XaaEnterprisePolicyIdp, dH as XaaEnterprisePolicyState, dI as XaaEphemeralDcrCredentials, dJ as XaaRegistrationWarning, dK as XaaRegistrationWarningCode, dL as XaaTokenEndpointAuthMethod, dM as analyzeAsCompatibility, dN as applyRuntimeClientCapabilities, dO as assertOAuthResultCredentialsUnredacted, dP as buildAuthorizationServerMetadataCandidates, dQ as buildConformanceProfileStamp, dR as buildConformanceRunReport, dS as buildDynamicClientRegistrationRequest, dT as buildIssuerPublicationCandidates, dU as buildMcpInitializeRequest, dV as buildOutcomeSummary, dW as buildProtectedResourceMetadataCandidates, dX as buildXaaDcrCredentialCacheKey, dY as canRunConformance, dZ as canonicalSkillJson, d_ as canonicalizeMcpResource, d$ as checkBrandColor, e0 as checkFrontmatterDrift, e1 as checkSkillIdentity, e2 as claudePolicySource, e3 as claudeSubmissionProfileSchema, e4 as comparableAdvertisedFrontmatter, e5 as computeConformanceScore, e6 as computeSkillVersionHash, e7 as conformanceProfile, e8 as conformanceProfileDigest, e9 as createInitialXAAFlowState, ea as createOAuthStateMachine, eb as createOAuthTraceProjectionContext, ec as decideConformanceOutcome, ed as decideLaneStatus, ee as decodeJWT, ef as decodeJWTParts, eg as deriveCapabilityEvidence, eh as deriveOAuthEmulation, ei as describeAsSlug, ej as describeConformanceScore, ek as describeError, el as detectVendor, em as evaluateIdJagClientMetadata, en as evaluateMcpInitializeResponse, eo as executeDynamicClientRegistration, ep as extensionTaskToObservation, eq as extractNodeErrno, er as findListedResource, es as findUnsupportedCharacters, et as formatJWTTimestamp, eu as getBrowserDebugDynamicRegistrationMetadata, ev as getDefaultClientCapabilities, ew as getDefaultRegistrationStrategy, ex as getStepIndex, ey as getStepInfo, ez as getSupportedRegistrationStrategies, eA as getXaaConnectClientMetadata, eB as getXaaDebugClientMetadata, eC as groupPortalIssues, eD as hasBlockingPortalIssue, eE as hasSurroundingWhitespace, eF as isDispositiveClaudeFinding, eG as isHttpServerConfig, eH as isInapplicableCheck, eI as isInvalidRedirectUriRejection, eJ as isLaneApplicableInMode, eK as isListedResource, eL as isLoopbackClientMetadataUrl, eM as isLoopbackHost, eN as isNegativeTestMode, eO as isNormalizedError, eP as isOpenAIPolicyCorpusVerified, eQ as isOpenAIReadinessResult, eR as isPolicyCorpusVerified, eS as isPolicyDependentNegativeTestMode, eT as isSkillIntegrityError, eU as isSupportedText, eV as isTasksDeclarationRequiredError, eW as isUnknownTaskError, eX as isUnrunCheck, eY as isXaaDcrClientSecretExpired, eZ as legacyTaskToObservation, e_ as mcpCallToolResultToModelOutput, e$ as mcpCallToolResultToModelOutputWithLinkedResources, f0 as mcpInitializeExtensionEvidence, f1 as mergeClientCapabilities, f2 as modelRejectsTemperature, f3 as normalizeAuthMethod, f4 as normalizeClientCapabilities, f5 as normalizeConformanceSuites, f6 as normalizeIdentityAssertionFormat, f7 as normalizeRegistrationMode, f8 as normalizeRegistrationStrategy, f9 as normalizeSubjectIdentifierFormat, fa as normalizeXaaClientAuth, fb as openaiPolicySource, fc as openaiSubmissionProfileSchema, fd as originOf, fe as parseClaudeSubmissionProfile, ff as parseDigest, fg as parseHexColor, fh as parseOpenAIAgentMetadata, fi as parseOpenAISubmissionProfile, fj as parseRetryAfterMs, fk as partitionByProfile, fl as partitionByStamp, fm as planCompletionSafeRedirects, fn as pooledConformanceScore, fo as projectOAuthTraceSnapshot, fp as readImageDimensions, fq as readOpenAIPluginPackage, fr as readXaaEnterprisePolicy, fs as redactConformanceReportForSharing, ft as redactSharedServerUrl, fu as redactUrlSecrets, fv as resolveAuthorizationPlan, fw as resolveRegistrationStrategies, fx as resolveSandboxCsp, fy as resolveSandboxPermissions, fz as rollUpLaneStatus, fA as runOAuthStateMachine, fB as sameReadinessTarget, fC as scoreFromAppsResult, fD as scoreFromOAuthResult, fE as scoreFromProtocolResult, fF as scoreFromTasksResult, fG as selectTokenEndpointAuthMethod, fH as sha256HexOfBytes, fI as sha256HexOfText, fJ as skillNameFromUri, fK as sniffImageMimeType, fL as splitAdvertisedFrontmatter, fM as splitSkillMarkdown, fN as stageLanesFor, fO as summarizeLaneCoverage, fP as summarizeTestCases, fQ as toConformanceReport, fR as unscoredCheckIds, fS as validateClientIdMetadataUrl, fT as verifyDigest, fU as verifySkillMarkdown, fV as withSkillsExtensionCapability, fW as withXaaEnterprisePolicy, fX as withoutXaaEnterprisePolicy } from './model-sampling-support-BwZqY1MR.js'; export { r as redactForTelemetry, r as redactSensitiveValue } from './telemetry-redaction-DooVPae5.js'; export { B as BAGGAGE_META_KEY, e as BaseServerConfig, C as ClientCapabilityOptions, D as DecodedMcpHeaderValue, E as ExecuteToolArguments, f as HttpExchangeLogEvent, H as HttpServerConfig, L as ListToolsResult, g as MCPClientManagerConfig, h as MCPConnectionStatus, i as MCPGetPromptResult, j as MCPListTasksResult, b as MCPPrompt, k as MCPPromptListResult, l as MCPReadResourceResult, d as MCPResource, m as MCPResourceListResult, c as MCPResourceTemplate, n as MCPResourceTemplateListResult, M as MCPServerConfig, o as MCPTask, p as MCPTaskStatus, q as MCP_HEADER_SENTINEL_PREFIX, r as MCP_HEADER_SENTINEL_SUFFIX, s as MCP_PARAM_HEADER_PREFIX, t as McpHeaderAssessment, u as McpHeaderFamily, v as McpHeaderIssue, w as McpHeaderStatus, x as McpParamCrossCheck, y as MirroredBodyValues, P as ParsedTraceparent, S as ServerSummary, z as StdioServerConfig, T as TASK_ROUTED_METHODS, A as TRACEPARENT_META_KEY, F as TRACESTATE_META_KEY, G as TaskOptions, I as TraceContext, J as TraceContextProvider, X as XMcpHeaderDeclaration, K as XMcpHeaderScan, N as buildMcpParamHeaders, O as classifyMcpHeader, Q as decodeMcpHeaderValue, U as encodeMcpHeaderValue, V as evaluateMcpHeaders, W as extractTraceContext, Y as findMcpHeaderIssues, Z as isValidBaggage, _ as isValidTraceparent, $ as isValidTracestate, a0 as parseTraceparent, a1 as sanitizeTraceContext, a2 as scanXMcpHeaderDeclarations, a3 as stripXMcpHeaderAnnotations, a4 as traceContextToMeta } from './types-CI0Xyszt.js'; export { aH as CompatibleProtocol, C as CustomProvider, aI as Host, L as LLMProvider, aJ as LiveTasksWire, aK as MCPJAM_TASKS_POLICY_EXTENSION_ID, aL as MCP_SKILLS_EXTENSION_ID, S as SkillEntry, aM as SkillIdentityFrontmatter, aN as SkillResourceRef, aO as SkillsExtListResult, aP as SkillsSupport, aQ as TERMINAL_LIFECYCLE_STATUSES, aR as TaskLifecycleCallbacks, aS as TaskLifecycleEngine, aT as TaskLifecycleEngineOptions, aU as TaskLifecycleError, aV as TaskLifecycleIdentity, aW as TaskLifecycleObservation, aX as TaskLifecycleRecord, aY as TaskLifecycleSnapshot, aZ as TaskLifecycleStatus, a_ as TaskMode, a$ as TaskObservationSource, b0 as TaskSurface, b1 as TasksPolicy, b2 as clearTasksPolicy, b3 as clientDeclaresSkillsExtension, b4 as describeInvalidTasksPolicy, b5 as isTerminalLifecycleStatus, b6 as readTasksPolicy, b7 as resolveSkillsSupport, b8 as serverDeclaresSkillsExtension, b9 as setTasksPolicy, ba as skillsDirectoryReadEnabled, bb as surfaceMayDeclareTasks, bc as taskLifecycleKey, bd as taskModeForSurface, be as toTaskLifecycleSnapshot } from './index-fZyfLCHE.js'; import { OAuthClientProvider, AuthResult, AuthorizationServerMetadata, OpenIdProviderDiscoveryMetadata, OAuthMetadata, OAuthProtectedResourceMetadata, OAuthServerInfo, OAuthClientInformationMixed, OAuthTokens, OAuthClientMetadata, OAuthClientInformationFull } from '@modelcontextprotocol/client'; export { OAuthClientInformation, OAuthClientInformationFull, OAuthClientMetadata, OAuthClientProvider, OAuthDiscoveryState, OAuthMetadata, OAuthProtectedResourceMetadata, OAuthTokens } from '@modelcontextprotocol/client'; import { O as OAuthProtocolVersion, R as RegistrationStrategy2025_03_26, j as RegistrationStrategy2025_06_18, k as RegistrationStrategy2025_11_25, l as RegistrationStrategy2026_07_28, m as OAuthFlowState } from './server-doctor-core-DFaTigIr.js'; export { A as AUTHORIZATION_SERVER_METADATA_MISSING_ISSUER, C as ConnectedServerDoctorState, E as EMPTY_OAUTH_FLOW_STATE, n as EmulatedAuthAttempt, o as EmulatedRegistrationPreference, H as HttpHistoryEntry, I as InfoLogEntry, q as InfoLogLevel, L as LogErrorDetails, r as OAUTH_EMULATION_FIELDS, s as OAuthDynamicRegistrationMetadata, t as OAuthEmulationConfig, u as OAuthEmulationCoverage, v as OAuthEmulationDivergence, w as OAuthEmulationField, x as OAuthEmulationFieldStatus, y as OAuthFlowStep, z as OAuthRequestExecutor, B as OAuthRequestResult, D as OAuthStateMachine, P as ProbeHttpAttempt, a as ProbeInitializeInfo, b as ProbeMcpServerConfig, c as ProbeMcpServerResult, d as ProbeOAuthDetails, e as ProbeTransportResult, F as ResourceIndicatorDecision, G as ResourceIndicatorSource, J as ResourceIndicatorStatus, f as ServerDoctorCheck, g as ServerDoctorChecks, h as ServerDoctorConnection, i as ServerDoctorError, S as ServerDoctorResult, K as canonicalizeResourceUrl, M as evaluateResourceIndicator, N as resolveResourceIndicatorValue } from './server-doctor-core-DFaTigIr.js'; export { O as OAuthOutboundUrlBlockedError, a as assertOutboundOAuthUrlAllowed, i as isDisallowedIpAddress, b as isLoopbackOAuthUrl, c as isPrivateHost } from './ssrf-guard-BPxOTXTF.js'; export { o as CspDomainSet, c as HostStyleId, J as MCP_PROTOCOL_VERSIONS, j as McpAppsCapabilities, M as McpProtocolVersion, i as McpToolResultImageRenderPlacement, e as McpToolResultImageRendering, h as McpToolResultImageRenderingPolicy, d as ModelVisibleMcpToolResults, K as MrtrSupport, L as OpenAiAppsCapabilities, P as PaginationTraversalMode, S as ServerId, T as ToolParamHeaderMirroring, N as isKnownProtocolVersion, Q as isStatelessProtocolVersion, R as protocolVersionLabel } from './types-HXAijHji.js'; export { a as HostConnectionDefaults, b as HostInit, H as HostJson, c as HostMcp, d as HostServerOverride } from './public-types-CX8stXC3.js'; import 'zod'; import './types-m3TBGFFa.js'; import '@modelcontextprotocol/client/stdio'; import 'ai'; type FetchFn = typeof fetch; type DiscoverAuthorizationServerMetadataOptions = { fetchFn?: FetchFn; protocolVersion?: string; }; type DiscoverOAuthMetadataOptions = { authorizationServerUrl?: string | URL; protocolVersion?: string; }; type DiscoverProtectedResourceMetadataOptions = { resourceMetadataUrl?: string | URL; protocolVersion?: string; }; type DiscoverOAuthServerInfoOptions = { resourceMetadataUrl?: string | URL; fetchFn?: FetchFn; }; type StartAuthorizationOptions = { metadata?: OAuthMetadata | AuthorizationServerMetadata; clientInformation: OAuthClientInformationMixed; redirectUrl: string | URL; scope?: string; state?: string; resource?: URL | string; }; type ExchangeAuthorizationOptions = { metadata?: OAuthMetadata | AuthorizationServerMetadata; clientInformation: OAuthClientInformationMixed; authorizationCode: string; codeVerifier: string; redirectUri: string | URL; resource?: URL | string; addClientAuthentication?: OAuthClientProvider["addClientAuthentication"]; fetchFn?: FetchFn; }; type FetchTokenOptions = { metadata?: OAuthMetadata | AuthorizationServerMetadata; resource?: URL | string; authorizationCode?: string; scope?: string; fetchFn?: FetchFn; }; type RegisterClientOptions = { metadata?: OAuthMetadata | AuthorizationServerMetadata; clientMetadata: OAuthClientMetadata; scope?: string; fetchFn?: FetchFn; }; type OAuthServerMetadata = AuthorizationServerMetadata | OpenIdProviderDiscoveryMetadata; declare function refreshAuthorization(authorizationServerUrl: string | URL, { metadata, clientInformation, refreshToken, resource, addClientAuthentication, fetchFn, }: { metadata?: OAuthMetadata | AuthorizationServerMetadata; clientInformation: OAuthClientInformationMixed; refreshToken: string; resource?: URL | string; addClientAuthentication?: OAuthClientProvider["addClientAuthentication"]; fetchFn?: FetchFn; }): Promise<{ access_token: string; token_type: string; id_token?: string | undefined; expires_in?: number | undefined; scope?: string | undefined; refresh_token?: string | undefined; }>; declare function auth(provider: OAuthClientProvider, options: { serverUrl: string | URL; authorizationCode?: string; scope?: string; resourceMetadataUrl?: string | URL; fetchFn?: FetchFn; }): Promise; declare function selectResourceURL(serverUrl: string | URL, provider: OAuthClientProvider, resourceMetadata?: OAuthProtectedResourceMetadata): Promise; declare function discoverOAuthProtectedResourceMetadata(serverUrl: string | URL, opts?: DiscoverProtectedResourceMetadataOptions, fetchFn?: FetchFn): Promise; declare function discoverOAuthMetadata(issuer: string | URL, { authorizationServerUrl, protocolVersion, }?: DiscoverOAuthMetadataOptions, fetchFn?: FetchFn): Promise; declare function discoverAuthorizationServerMetadata(authorizationServerUrl: string | URL, { fetchFn, protocolVersion, }?: DiscoverAuthorizationServerMetadataOptions): Promise; declare function discoverOAuthServerInfo(serverUrl: string | URL, opts?: DiscoverOAuthServerInfoOptions): Promise; declare function startAuthorization(authorizationServerUrl: string | URL, { metadata, clientInformation, redirectUrl, scope, state, resource, }: StartAuthorizationOptions): Promise<{ authorizationUrl: URL; codeVerifier: string; }>; declare function exchangeAuthorization(authorizationServerUrl: string | URL, { metadata, clientInformation, authorizationCode, codeVerifier, redirectUri, resource, addClientAuthentication, fetchFn, }: ExchangeAuthorizationOptions): Promise; declare function fetchToken(provider: OAuthClientProvider, authorizationServerUrl: string | URL, { metadata, resource, authorizationCode, scope, fetchFn, }?: FetchTokenOptions): Promise; declare function registerClient(authorizationServerUrl: string | URL, { metadata, clientMetadata, scope, fetchFn, }: RegisterClientOptions): Promise; /** * Shared types for OAuth state machines */ /** * Action definition for sequence diagram * Used to build the visual representation of OAuth flow steps */ /** One `label: value` row under a diagram arrow. */ interface DiagramDetail { label: string; value: any; } interface DiagramAction { id: string; label: string; description: string; from: string; to: string; details?: DiagramDetail[]; } type OAuthSequenceActionInput = { protocolVersion: OAuthProtocolVersion; registrationStrategy: RegistrationStrategy2025_03_26 | RegistrationStrategy2025_06_18 | RegistrationStrategy2025_11_25 | RegistrationStrategy2026_07_28; flowState: OAuthFlowState; }; declare function buildOAuthSequenceActions({ protocolVersion, registrationStrategy, flowState, }: OAuthSequenceActionInput): DiagramAction[]; /** * OAuth 2.0 State Machine for MCP - 2026-07-28 Protocol * * This implementation follows the 2026-07-28 MCP OAuth specification: * - Registration priority: CIMD (SHOULD) > Pre-registered > DCR (MAY) * - Discovery: OAuth 2.0 (RFC8414) OR OpenID Connect Discovery 1.0 with path insertion priority * - PKCE: REQUIRED - MUST verify code_challenge_methods_supported * - Client ID Metadata Documents (CIMD) support per draft-parecki-oauth-client-id-metadata-document-03 */ type AuthorizationResponseIssuerCheck = /** `warning` is set when a mismatch was found but the era does not enforce it. */ { ok: true; warning?: string; } | { ok: false; reason: string; }; /** * RFC 9207 authorization-response `iss` validation — a 2026-07-28 requirement. * Four rows: * 1. `iss` present and equals the recorded issuer → ok * 2. `iss` present and differs → reject * 3. `iss` absent but the AS advertised * `authorization_response_iss_parameter_supported: true` → reject * 4. `iss` absent and not advertised → ok * A present-but-not-advertised `iss` is still validated (rows 1/2): if the AS * sends one, it must be correct. Comparison is exact — no normalization, same * discipline as the RFC 8414 §3.3 issuer check. On a mismatch the caller emits * a fixed diagnostic and MUST NOT surface any server-supplied `error*` callback * parameters. * * Row 2 names both issuers, because an exact comparison fails on differences * too small to see (trailing slash, scheme, port) and the mismatch is otherwise * undiagnosable — the gate returns before anything reaches the OAuth trace. The * RFC 9207 prohibition covers `error`/`error_description`, which carry AS-authored * prose; `iss` is the compared value itself, and quoting it is what makes the * rejection actionable. It is still attacker-controlled, hence `quoteUntrusted`. * * `enforcePresentIssMismatch` scopes row 2 to the era that actually mandates it. * SEP-2468 introduces `MUST validate a present iss` in the 2026-07-28 draft; * 2025-11-25 and earlier never mention `iss`, so a caller on those versions * passes `false` to downgrade row 2 to a `warning` and let the flow continue. * Defaults to enforcing: an omitted flag must fail closed, and the value that * carries the era lives with the caller, not here. * * "Absent" means `undefined`, `null`, or the empty string. `null` is what a * callback boundary produces when the param is missing (`URLSearchParams.get`), * so it MUST land in rows 3/4, never in the present-`iss` comparison — treating * it as present turns every spec-conformant AS that simply omits `iss` into a * hard mismatch (and `quoteUntrusted(null)` crashes). An empty `iss=` is * likewise treated as absent rather than compared: RFC 9207 gives the value * issuer-URL syntax, so an empty one carries no issuer claim to validate — but * it still fails closed via row 3 whenever the AS advertised iss support. */ declare function validateAuthorizationResponseIssuer(input: { recordedIssuer: string | undefined; returnedIss: string | null | undefined; issParameterSupported: boolean | undefined; enforcePresentIssMismatch?: boolean; }): AuthorizationResponseIssuerCheck; /** * SEP-2350 scope union. Returns the previously-requested scopes followed by any * newly-challenged scopes not already present — order-preserving (previous * first) and de-duplicated. This is the set a step-up re-authorization requests. */ declare function computeScopeUnion(previous?: string[], challenged?: string[]): string[]; interface InsufficientScopeChallenge { /** True only when the `WWW-Authenticate` header carries `error="insufficient_scope"`. */ isInsufficientScope: boolean; /** Scopes named by the challenge's `scope` parameter, if any. */ challengedScopes?: string[]; /** RFC 9728 `resource_metadata` pointer, if the challenge carried one. */ resourceMetadata?: string; } /** True when the header advertises a Bearer challenge, with or without auth-params. */ declare function hasBearerChallenge(header?: string): boolean; /** * What the unauthenticated `initialize` probe's status means for the flow: * - `challenged`: treat as an auth challenge and continue discovery. * `specCompliant` is false when the challenge arrived on a status MCP does not * allow here, which the debugger proceeds through but must report. * - `anonymous_allowed`: the server served the request without a token. * - `unexpected`: the flow cannot continue; `message` says why. */ type UnauthenticatedProbeOutcome = { kind: "challenged"; specCompliant: boolean; } | { kind: "anonymous_allowed"; } | { kind: "unexpected"; message: string; }; /** * Classify the unauthenticated probe. MCP requires 401 + `WWW-Authenticate` * here, but servers fronted by a CDN/WAF, and those treating anonymous access as * a scope failure (RFC 6750 §3.1 pairs 403 with `insufficient_scope`), answer * 403 instead. A 403 that still carries a Bearer challenge supplies everything * discovery needs, so the debugger continues and flags the violation rather than * dead-ending; a bare 403 carries nothing to continue from and almost always * means the request never reached the MCP server at all. */ declare function classifyUnauthenticatedProbe(input: { status: number; statusText?: string; wwwAuthenticateHeader?: string; serverMessage?: string; }): UnauthenticatedProbeOutcome; /** The flow step that sends the unauthenticated `initialize` probe. */ declare const UNAUTHENTICATED_PROBE_STEP = "request_without_token"; /** * True when a recorded exchange is the unauthenticated probe being answered * with an auth challenge — the outcome the debugger expects, so surfaces must * not paint it as a failure. Reads the same classification the step itself * gates on, so a 403 the flow continued from cannot render as an error beside * the warning explaining it. */ declare function isUnauthenticatedProbeChallenge(input: { step?: string; status?: number; statusText?: string; wwwAuthenticateHeader?: string; }): boolean; declare function parseInsufficientScopeChallenge(header?: string): InsufficientScopeChallenge; /** Where an insufficient-scope challenge is being handled — drives the policy split. */ type StepUpAuthMode = "interactive" | "m2m" | "debugger"; /** * What to do with an insufficient-scope challenge: * - `reauthorize`: run a fresh authorization requesting the scope union; * - `throw`: surface an `InsufficientScopeError` (no browser); * - `manual`: let the user inspect and advance the step explicitly (debugger). */ type StepUpAction = "reauthorize" | "throw" | "manual"; /** * §10.5 runtime step-up policy split with a bounded retry. `attempt` is the * number of step-up re-authorizations ALREADY performed for this persisted * client session (0 on the first challenge); once it reaches `maxRetries` the * interactive path stops re-authorizing and throws, preventing an infinite * cross-request loop (SDK per-request limits are not enough for a persisted * session). M2M never opens a browser; the debugger advances by hand. */ declare function resolveStepUpAction(input: { authMode: StepUpAuthMode; attempt: number; maxRetries?: number; }): StepUpAction; /** * The single owner of OAuth trace redaction. * * Everything that decides "is this field a secret" or "what does a redacted * value look like" lives here, in the SDK, and both the SDK's trace projection * and the inspector's own trace collection import it. Before this module the * same policy existed in six places and the copies had already drifted — the * SDK's sensitive-field set omitted `state`, the client's included it, and the * SDK's error-string redactor mangled "Bearer token is expired" while the * client's did not. * * ## What this is NOT for * * Nothing here may be applied to data an OAuth flow CONSUMES. A redaction * sentinel is a non-empty string: it passes every truthiness check and is then * spent as a credential. That is #3865, and the factory's executor guard exists * to make it loud. Redaction is a property of DISPLAY and PERSISTENCE, applied * once, at projection time. * * ## Telemetry is deliberately separate * * `redactForTelemetry` (`src/telemetry-redaction.ts`) over-redacts on purpose and is * length-capped for Sentry. Merging it with the display redactor would either * make traces useless or make telemetry leaky. */ /** * Field names whose VALUE is a secret wherever it appears — as an object key, * a header, or a query parameter. * * `state` is here on purpose. It is not a bearer credential, but a still-live * `state` is the CSRF correlation secret for an in-flight authorization: an * attacker who learns it can complete the flow with their own code. That it * also travels in an authorization URL does not make it publishable — the URL * is transient, a persisted or copied trace is not. Diagnostics that need to * talk about `state` use `describeOAuthStateMatch` below, which reports * presence and match rather than the nonce. */ declare const OAUTH_TRACE_SENSITIVE_FIELD_NAMES: ReadonlySet; declare function isSensitiveTraceFieldName(key: string): boolean; declare function isSensitiveHeaderName(key: string): boolean; declare function isSensitiveQueryParamName(key: string): boolean; /** * The display form of a redacted value: enough of the ends to correlate two * sightings of the same credential, never enough to use one. * * The exact shapes produced here — `[redacted]` and `abcd...[redacted]...yz` — * are what the factory's executor guard recognizes when one of them shows up * where a live credential belongs. */ declare function redactSensitiveTraceValue(value: unknown): string; /** * Is `value` — the token after a `Bearer`/`Basic` scheme word — a credential, * or is it part of the sentence the scheme word happens to start? * * The judgement, not just the rule: `\b(bearer|basic)\s+\w+` turns the very * common "Bearer token is expired" into "Bearer [redacted] is expired", * destroying the diagnostic word the redactors promise to keep — and it turns * the hosted 401's own copy, "Bearer token required", into nonsense the user * cannot act on. Keying on punctuation-or-length gets prose right but misses * short opaque credentials — `Basic dXNlcjpwYXNz` is a valid header value with * neither. So invert the test and ask whether the value could be a WORD * instead: anything carrying mixed case, a digit, or base64url punctuation is * credential-shaped, and a plain lowercase run is vocabulary. * * Exported because the display redactor below is not the only place that has * to make this call — telemetry redaction over-redacts by design and stays * separate, but "is this a credential or a noun" is one question with one * answer, and the copies of it had already drifted. */ declare function isCredentialShapedAuthValue(value: string): boolean; /** * Redact credential-shaped substrings from a free-form error message. * * Error strings interpolate whatever the server put in `error` / * `error_description`, and MCPJam is routinely pointed at half-built servers * that echo request context back into error bodies. Every shape a credential * plausibly arrives in is covered: * * 1. URL userinfo, with or without a scheme (`https://u:p@h`, `u:p@h`) * 2. credential-ish query/form parameters, by name * 3. `Authorization: Bearer|Basic ` echoed from a request * 4. JSON credential fields (`"client_secret": "..."`) * * Then a length cap, because an upstream body can be arbitrarily large. * * Deliberately over-redacts, with one hard constraint: it must not destroy the * diagnostic vocabulary it exists to preserve. "Bearer token is expired" is a * description, not a credential, and has to survive intact — which is why rule * 3b matches only credential-SHAPED values. The result also stays a * human-readable string; an error message must never be reshaped into an * object. */ declare function sanitizeTraceErrorMessage(message: string, options?: { /** * Output cap. Defaults to {@link MAX_REPORTED}, which suits one error * message. A caller with a genuinely multi-line payload (a stack trace) * raises it rather than redacting line by line — splitting first separates * a JSON credential's key from its value and defeats rule 4. */ maxLength?: number; /** Scan cap. Raise alongside `maxLength`; see {@link MAX_SCANNED}. */ maxScanned?: number; }): string; type OAuthRequestFields = Record; /** * Parse a request/response body into flat string fields, so a form-encoded or * JSON body can be redacted by field name rather than by regex. */ declare function parseOAuthRequestFields(body: unknown): OAuthRequestFields | undefined; declare function sanitizeOAuthUrl(rawUrl: string, depth?: number): string; declare function sanitizeOAuthTraceValue(value: unknown): unknown; declare function sanitizeOAuthHeaders(headers: Record): Record; interface OAuthStateMatchDiagnostics { /** Whether the authorization response carried a `state` at all. */ statePresent: boolean; /** * Whether it equals the issued value. `undefined` when there is nothing to * compare against (no issued state recorded). */ stateMatched?: boolean; } /** * The publishable form of a `state` comparison. * * Everything a reader needs to debug a CSRF-check failure — did the server send * one, and did it match — without the nonce itself. Constant-time comparison is * not attempted: both values are already in this process, and the check that * matters (the machine's own) happens elsewhere. */ declare function describeOAuthStateMatch(input: { issuedState?: string | null; callbackState?: string | null; }): OAuthStateMatchDiagnostics; /** What the HTTP history shows in place of a client secret — the real value * is sent on the wire but never enters the logged request. */ declare const CLIENT_SECRET_MASK = "\u2022\u2022\u2022\u2022\u2022\u2022\u2022\u2022"; declare function createXAAStateMachine(config: BaseXAAStateMachineConfig): XAAStateMachine; interface RunXaaStateMachineOptions { /** Max `proceedToNextStep` calls before bailing (hot-loop guard). Default 40. */ maxSteps?: number; /** Stop once the machine reaches this step, before advancing past it. */ stopAtStep?: XAAFlowStep; /** Stop when this predicate returns true for the current state. */ stopWhen?: (state: XAAFlowState) => boolean; } interface XaaStateMachineRunResult { completed: boolean; stoppedAt: XAAFlowStep; error?: string; state: XAAFlowState; } /** * Drive an XAA state machine until completion, a stop predicate/step, an error, * a settled negative-probe, or the max-steps guard — whichever comes first. * Reads state through `getState` (the same callback the machine was configured * with) so it always observes live state. Unlike the machine's own `runAll`, * this supports an explicit stop step/predicate for partial or stepped runs. */ declare function runXaaStateMachine(machine: XAAStateMachine, getState: () => XAAFlowState, options?: RunXaaStateMachineOptions): Promise; /** * Static, browser-safe catalog of every conformance check's title and * one-line description. * * WHY THIS EXISTS SEPARATELY: the canonical title/description strings live * next to the check implementations (`CORE_CHECKS`, `MODERN_CHECK_METADATA`, * the apps/tasks runner metadata, …), and those modules pull the whole * runner graph — raw HTTP probes, the MCP client, Node-only transitive deps. * A UI that wants to show what a suite WILL run, before it has run, cannot * import them. This module carries the same strings with no runtime * dependencies at all, so it is safe from the browser entry. * * DRIFT IS NOT ALLOWED TO PASS SILENTLY: every entry here is asserted equal * to its canonical source in `__tests__/conformance-catalog.test.ts`. Editing * a check's title or description without updating this file fails that test, * and vice versa. Adding a check fails typecheck here, because each record is * exhaustive over its suite's id union. */ interface ConformanceCheckInfo { title: string; description: string; } /** Protocol suite. Keys follow `MCP_CHECK_IDS` order. */ declare const PROTOCOL_CHECK_CATALOG: { readonly "server-initialize": { readonly title: "Server Initialize"; readonly description: "Server responds to initialize and reports capabilities."; }; readonly ping: { readonly title: "Ping"; readonly description: "Server responds to ping requests."; }; readonly "logging-set-level": { readonly title: "Logging Set Level"; readonly description: "Server accepts logging/setLevel requests."; }; readonly "completion-complete": { readonly title: "Completion Complete"; readonly description: "Server responds to completion/complete requests."; }; readonly "capabilities-consistent": { readonly title: "Capabilities Consistent"; readonly description: "Advertised server capabilities match the features actually exposed."; }; readonly "tools-list": { readonly title: "Tools List"; readonly description: "Server lists tools with name, description, and input schema."; }; readonly "tools-input-schemas-valid": { readonly title: "Tool Input Schemas Valid"; readonly description: "Every tool's inputSchema has type \"object\" and valid properties/required fields."; }; readonly "tools-x-mcp-header-declarations-valid": { readonly title: "x-mcp-header Declarations Valid"; readonly description: "Every published tool's SEP-2243 x-mcp-header declarations satisfy the spec's constraints: statically reachable through a chain of `properties`, an RFC 9110 token name, a primitive type, and case-insensitively unique."; }; readonly "prompts-list": { readonly title: "Prompts List"; readonly description: "Server lists prompts with name and description."; }; readonly "resources-list": { readonly title: "Resources List"; readonly description: "Server lists resources with uri and name."; }; readonly "protocol-invalid-method-error": { readonly title: "Invalid Method Error"; readonly description: "Server returns a valid JSON-RPC error for an unrecognized method name."; }; readonly "localhost-host-rebinding-rejected": { readonly title: "Reject Evil Host Header"; readonly description: "Local servers reject initialize requests with a non-localhost Host/Origin header."; }; readonly "localhost-host-valid-accepted": { readonly title: "Accept Valid Local Host Header"; readonly description: "Local servers accept initialize requests with a valid localhost Host/Origin header."; }; readonly "server-sse-polling-session": { readonly title: "SSE Polling Session"; readonly description: "Server provides a streamable HTTP session id."; }; readonly "server-accepts-multiple-post-streams": { readonly title: "Multiple POST Streams"; readonly description: "The server accepts multiple concurrent POST requests."; }; readonly "server-sse-streams-functional": { readonly title: "Functional SSE Streams"; readonly description: "Concurrent SSE streams remain readable."; }; readonly "notification-post-accepted": { readonly title: "Notification POST Accepted"; readonly description: "A POST carrying only a JSON-RPC notification is answered with HTTP 202 Accepted and no body."; }; readonly "get-stream-or-405": { readonly title: "GET Opens SSE Or Returns 405"; readonly description: "A GET to the MCP endpoint either opens a text/event-stream response or returns HTTP 405 Method Not Allowed."; }; readonly "session-id-visible-ascii": { readonly title: "Session Id Visible ASCII"; readonly description: "A minted session id contains only visible ASCII characters (0x21 to 0x7E)."; }; readonly "post-response-content-type": { readonly title: "POST Response Content-Type"; readonly description: "The response to a JSON-RPC request carries Content-Type application/json or text/event-stream."; }; readonly "modern-client-handshake": { readonly title: "Modern Client Handshake"; readonly description: "The official client negotiates the modern revision and receives the server identity and capabilities."; }; readonly "modern-server-discover": { readonly title: "Modern Server Discovery"; readonly description: "server/discover returns the supported protocol versions, capabilities, and server identity."; }; readonly "modern-result-type-present": { readonly title: "Modern Result Type"; readonly description: "Every modern result carries the wire member resultType."; }; readonly "modern-cacheable-result-hints": { readonly title: "Cacheable Result Hints"; readonly description: "Cacheable modern results carry ttlMs and cacheScope."; }; readonly "modern-cache-hint-coverage": { readonly title: "Cache Hints On Every Cacheable Operation"; readonly description: "All six operations the caching utility names — server/discover, tools/list, prompts/list, resources/list, resources/templates/list, resources/read — carry ttlMs and cacheScope on a complete result."; }; readonly "modern-cache-hint-values-valid": { readonly title: "Cache Hint Values Valid"; readonly description: "ttlMs is an integer >= 0 and cacheScope is exactly \"public\" or \"private\"."; }; readonly "modern-cache-scope-stable-across-pages": { readonly title: "Cache Scope Stable Across Pages"; readonly description: "Every page of a paginated list response carries the same cacheScope as the first."; }; readonly "modern-protocol-version-header-mismatch": { readonly title: "Protocol Version Header Mismatch"; readonly description: "A MCP-Protocol-Version header disagreeing with the request envelope is rejected with HTTP 400 and JSON-RPC -32020."; }; readonly "modern-method-header-mismatch": { readonly title: "Mcp-Method Header Mismatch"; readonly description: "An Mcp-Method header disagreeing with the body method is rejected with HTTP 400 and JSON-RPC -32020."; }; readonly "modern-name-header-mismatch": { readonly title: "Mcp-Name Header Mismatch"; readonly description: "An Mcp-Name header disagreeing with the body target is rejected with HTTP 400 and JSON-RPC -32020."; }; readonly "modern-unsupported-version-error": { readonly title: "Unsupported Envelope Version"; readonly description: "An unsupported envelope protocol version is rejected with JSON-RPC -32022 naming the supported versions."; }; readonly "modern-missing-method-header-rejected": { readonly title: "Missing Mcp-Method Header Rejected"; readonly description: "A request that omits the required Mcp-Method header is rejected with HTTP 400 and JSON-RPC -32020."; }; readonly "modern-header-names-case-insensitive": { readonly title: "Header Names Are Case-Insensitive"; readonly description: "The SEP-2243 standard headers are accepted under any case, as RFC 9110 field names require."; }; readonly "modern-undeclared-capability-error": { readonly title: "Undeclared Client Capability"; readonly description: "A server that needs an undeclared client capability for input_required answers JSON-RPC -32021."; }; readonly "modern-no-session-id": { readonly title: "No Session Id Minted"; readonly description: "A modern server never mints an Mcp-Session-Id."; }; readonly "modern-removed-methods-not-found": { readonly title: "Removed Methods Rejected"; readonly description: "Methods removed by the 2026 revision answer JSON-RPC -32601 with HTTP 404."; }; readonly "modern-resource-not-found-invalid-params": { readonly title: "Resource Not Found"; readonly description: "Reading an unknown resource answers in-band JSON-RPC -32602 on HTTP 200."; }; readonly "modern-resource-read-no-empty-contents": { readonly title: "No Empty Contents For A Missing Resource"; readonly description: "Reading a non-existent resource never answers with an empty contents array, which cannot be told apart from an existing but empty resource."; }; readonly "modern-tool-output-schema-conformant": { readonly title: "Tool Output Schema Honored"; readonly description: "For every operator-supplied fixture call whose tool declares an outputSchema, the result's structuredContent validates against that schema."; }; readonly "modern-logs-require-log-level": { readonly title: "Logs Require A Log Level"; readonly description: "No log notifications are emitted for a request that carried no modern log level."; }; readonly "modern-subscription-ack-precedes-notifications": { readonly title: "Subscription Acknowledgement Ordering"; readonly description: "A subscriptions/listen stream acknowledges before it emits any notification."; }; readonly "modern-subscription-filter-and-tagging": { readonly title: "Subscription Filtering And Tagging"; readonly description: "A subscription emits only the requested notification types and tags every message with the subscription id."; }; readonly "modern-subscription-graceful-close": { readonly title: "Subscription Graceful Close"; readonly description: "Closing a subscription gracefully returns the subscriptions/listen completion result."; }; readonly "wire-schema-valid": { readonly title: "Wire Schema Valid"; readonly description: "Every JSON-RPC message the run observed validates against the protocol revision's published JSON Schema, with responses graded against their method's result definition."; }; }; /** MCP Apps suite. Keys follow `MCP_APPS_CHECK_IDS` order. */ declare const APPS_CHECK_CATALOG: { readonly "ui-tools-present": { readonly title: "UI Tools Present"; readonly description: "At least one tool advertises MCP Apps UI metadata through _meta.ui.resourceUri or the deprecated ui/resourceUri field."; }; readonly "ui-tool-metadata-valid": { readonly title: "UI Tool Metadata Valid"; readonly description: "Tools with UI metadata use a ui:// resource URI and valid visibility values."; }; readonly "ui-tool-input-schema-valid": { readonly title: "UI Tool Input Schema Valid"; readonly description: "UI tools provide a non-null JSON Schema object as their inputSchema."; }; readonly "ui-listed-resources-valid": { readonly title: "Listed UI Resources Valid"; readonly description: "UI resources returned by resources/list use ui:// URIs and the MCP Apps HTML MIME type."; }; readonly "ui-resources-readable": { readonly title: "UI Resources Readable"; readonly description: "Every UI resource referenced by a tool or listed by the server can be fetched with resources/read."; }; readonly "ui-resource-contents-valid": { readonly title: "UI Resource Contents Valid"; readonly description: "UI resource contents use the MCP Apps HTML MIME type and provide exactly one HTML payload via text or blob."; }; readonly "ui-resource-meta-valid": { readonly title: "UI Resource Metadata Valid"; readonly description: "UI resource metadata uses valid csp, permissions, domain, and prefersBorder shapes."; }; }; /** Tasks suite. Keys follow `MCP_TASKS_CHECK_IDS` order. */ declare const TASKS_CHECK_CATALOG: { readonly "tasks-wire-resolvable": { readonly title: "Tasks Wire Resolvable"; readonly description: "The negotiated protocol version and advertised capabilities resolve to exactly one tasks wire, and the server does not advertise capabilities for the other era."; }; readonly "tasks-declaration-hygiene": { readonly title: "Per-Version Declaration Hygiene"; readonly description: "Outgoing requests carry `params.task` only on the legacy wire and the tasks extension declaration only on the extension wire; a connection with no tasks wire sends neither."; }; readonly "tasks-result-type-discipline": { readonly title: "Result Type Discipline"; readonly description: "A task-eligible tools/call returns either a normal tool result or a flat CreateTaskResult with resultType \"task\" and a server-generated taskId."; }; readonly "tasks-undeclared-creation-refused": { readonly title: "Undeclared Task Creation Refused"; readonly description: "On the extension wire, a tools/call that did not carry the extension declaration must not come back as a CreateTaskResult: the server either answers normally or rejects with -32021."; }; readonly "tasks-undeclared-capability-rejected": { readonly title: "Undeclared Capability Rejected"; readonly description: "tasks/get, tasks/update, tasks/cancel and a task-filtered subscriptions/listen sent WITHOUT the extension declaration must each be rejected with -32021 (Missing Required Client Capability)."; }; readonly "tasks-ttl-shape": { readonly title: "TTL And Poll Interval Shapes"; readonly description: "Task TTL and poll interval use the era-native shapes: `ttlMs: number|null` / `pollIntervalMs` on the extension, `ttl` / `pollInterval` on the legacy wire."; }; readonly "tasks-inline-result": { readonly title: "Completed Task Carries Its Result"; readonly description: "A completed task exposes its result the era-native way: inline on the extension's tasks/get, via tasks/result on the legacy wire."; }; readonly "tasks-mcp-name-routing": { readonly title: "Mcp-Name Task Routing"; readonly description: "Over HTTP, tasks/get is sent with Mcp-Name set to the task id (captured off the fetch seam) and accepted by the server."; }; readonly "tasks-invalid-task-id-rejected": { readonly title: "Invalid Task Id Rejected"; readonly description: "tasks/get for a task id the server never issued is rejected with -32602 (Invalid params); the same rejection on tasks/update and tasks/cancel is a SHOULD and only warns."; }; readonly "tasks-status-payload-shape": { readonly title: "Status Payload Shape"; readonly description: "Each observed task status carries the payload its status requires: `result` on completed, `error` on failed, `inputRequests` on input_required."; }; readonly "tasks-cancel-ack-shape": { readonly title: "Cancel Acknowledged With An Empty Result"; readonly description: "tasks/cancel is acknowledged with an empty result rather than a task state, and the task's observable status is allowed to remain non-terminal afterwards."; }; readonly "tasks-input-required-update-completes": { readonly title: "Input Required Round Trip Completes"; readonly description: "A task that reports input_required advances past it once tasks/update supplies the requested inputResponses, and reaches a terminal status."; }; readonly "tasks-ttl-integer-shape": { readonly title: "TTL And Poll Interval Are Integers"; readonly description: "ttlMs and pollIntervalMs are integer milliseconds, as the extension's Task interface states."; }; readonly "tasks-undeclared-capability-names-requirements": { readonly title: "Undeclared Capability Error Names What Is Missing"; readonly description: "A -32021 rejection carries error.data.requiredCapabilities naming the capability the client failed to declare."; }; }; export { APPS_CHECK_CATALOG, type AuthorizationResponseIssuerCheck, BaseXAAStateMachineConfig, CLIENT_SECRET_MASK, type ConformanceCheckInfo, type InsufficientScopeChallenge, OAUTH_TRACE_SENSITIVE_FIELD_NAMES, OAuthFlowState, OAuthProtocolVersion, type OAuthRequestFields, type OAuthStateMatchDiagnostics, PROTOCOL_CHECK_CATALOG, RegistrationStrategy2025_03_26, RegistrationStrategy2025_06_18, RegistrationStrategy2025_11_25, RegistrationStrategy2026_07_28, type RunXaaStateMachineOptions, type StepUpAction, type StepUpAuthMode, TASKS_CHECK_CATALOG, UNAUTHENTICATED_PROBE_STEP, type UnauthenticatedProbeOutcome, XAAFlowState, XAAFlowStep, XAAStateMachine, type XaaStateMachineRunResult, auth, buildOAuthSequenceActions, classifyUnauthenticatedProbe, computeScopeUnion, createXAAStateMachine, describeOAuthStateMatch, discoverAuthorizationServerMetadata, discoverOAuthMetadata, discoverOAuthProtectedResourceMetadata, discoverOAuthServerInfo, exchangeAuthorization, fetchToken, hasBearerChallenge, isCredentialShapedAuthValue, isSensitiveHeaderName, isSensitiveQueryParamName, isSensitiveTraceFieldName, isUnauthenticatedProbeChallenge, parseInsufficientScopeChallenge, parseOAuthRequestFields, redactSensitiveTraceValue, refreshAuthorization, registerClient, resolveStepUpAction, runXaaStateMachine, sanitizeOAuthHeaders, sanitizeOAuthTraceValue, sanitizeOAuthUrl, sanitizeTraceErrorMessage, selectResourceURL, startAuthorization, validateAuthorizationResponseIssuer };