import { bj as CreateTaskExtResult, bg as GetTaskExtResult, bk as SkillsDirectoryReadResult, S as SkillEntry, aO as SkillsExtListResult, bl as ElicitationContentValidator, bi as TasksWire, M as MCPClientManager, bm as HostExecutor, c as EvalExpectedToolCall, a as EvalMatchOptions, bn as MCPJamReportingConfig, I as IterationStatus, bo as LatencyBreakdown, bp as PromptResult, f as EvalToolCallMatchResult, v as EvalSuiteFile, D as EvalSuiteFileTarget, g as EvalSuiteFileToolPolicy, N as EvalValidityCoverage, A as EvalSuiteFileProvenance, w as EvalSuiteFileCase, x as EvalSuiteFileCaseImport, C as CustomProvider, bq as HostSource, br as PromptOptions, bs as MCPServerReplayConfig, bt as ToolCall, bu as ReportEvalResultsInput, bv as ReportEvalResultsOutput, bw as EvalResultInput, bx as EvalCiMetadata } from './index-fZyfLCHE.js'; export { aH as CompatibleProtocol, by as CoreAssistantMessage, bz as CoreMessage, bA as CoreToolMessage, bB as CoreUserMessage, bC as DEFAULT_MAX_MRTR_ROUNDS, bD as DEFAULT_SUBSCRIPTION_RECONNECT_POLICY, bE as DEFAULT_TASK_INPUT_LIMITS, bF as DeclaredInputCapabilities, bG as DeliveredSubscriptionNotification, bH as DesiredSubscriptionInterests, bf as DetailedTaskExt, bI as DriveTaskToTerminalArgs, h as EVAL_RATE_MEASUREMENT_STATES, i as EVAL_RUN_VERDICTS, m as EVAL_TRIAL_EXCLUSION_REASONS, o as EVAL_VERDICT_DECISION_REASONS, p as EVAL_VERDICT_POLICY_SCHEMA_ID, q as EVAL_VERDICT_POLICY_VERSION, bJ as EvalArgumentMismatch, r as EvalCaseVerdictAggregation, bK as EvalOutOfOrderToolCall, s as EvalRateMeasurement, t as EvalRateMeasurementState, u as EvalRunVerdict, bL as EvalToolCall, E as EvalTraceInput, bM as EvalTraceSpanCategory, b as EvalTraceSpanInput, J as EvalTrialExclusionReason, K as EvalTrialExclusions, e as EvalVerdictDecision, P as EvalVerdictDecisionReason, Q as EvalVerdictPolicyVersion, R as EvalVerdictValidity, bN as EvalWidgetCsp, bO as EvalWidgetPermissions, bP as EvalWidgetSnapshotInput, aI as Host, bQ as HostRuntime, bR as HostRuntimeDefaults, bS as HostRuntimeManager, bT as HostServerRegistry, bU as INODE_DIRECTORY_MIME_TYPE, bV as LLMConfig, L as LLMProvider, aJ as LiveTasksWire, aK as MCPJAM_TASKS_POLICY_EXTENSION_ID, aL as MCP_SKILLS_EXTENSION_ID, bW as McpSubscriptionHandle, bX as MrtrInputCollector, bY as MrtrInputValidationError, bZ as MrtrLegResult, b_ as MrtrLegSender, b$ as MrtrMethod, c0 as MrtrOperationState, c1 as MrtrSupportedModes, c2 as MrtrUndeclaredInputError, c3 as MrtrUnsupportedElicitationModeError, c4 as MrtrValidateResponse, c5 as PromptResultData, c6 as RejectedSubscriptionNotification, a4 as ResolvedEvalValidityPolicy, c7 as RunInputRequiredOptions, c8 as SUBSCRIPTION_ID_META_KEY, c9 as SUPPORTED_ELICITATION_MODES, aM as SkillIdentityFrontmatter, aN as SkillResourceRef, ca as SkillsDirectoryEntry, aP as SkillsSupport, cb as SubscriptionClientPort, cc as SubscriptionCloseReason, cd as SubscriptionCoordinator, ce as SubscriptionCoordinatorOptions, cf as SubscriptionFilterShape, cg as SubscriptionInterestRejection, ch as SubscriptionNotificationKind, ci as SubscriptionReconnectPolicy, cj as SubscriptionStreamRecord, ck as SubscriptionStreamStatus, cl as SubscriptionsAcknowledgedNotificationMethod, cm as TASK_SEAM_META_KEY, aQ as TERMINAL_LIFECYCLE_STATUSES, cn as TaskAwaitOutcome, co as TaskAwaitResult, cp as TaskCreatedConsumer, cq as TaskCreatedEvent, cr as TaskCreatedSink, cs as TaskCreationSurface, ct as TaskInputDriverOptions, cu as TaskInputHandlerContext, cv as TaskInputHandlers, cw as TaskInputRejectedError, cx as TaskInputRejection, aS as TaskLifecycleEngine, aV as TaskLifecycleIdentity, aW as TaskLifecycleObservation, aY as TaskLifecycleSnapshot, aZ as TaskLifecycleStatus, a_ as TaskMode, b0 as TaskSurface, b1 as TasksPolicy, cy as TasksSupport, cz as TokenUsage, cA as ToolTaskAwaitOptions, cB as ToolTaskSeamContext, cC as ToolTaskSeamMeta, cD as ToolTaskSeamOptions, cE as UpdateTaskExtResult, cF as assertHostServersKnown, cG as canDeclareTasksExtension, b2 as clearTasksPolicy, b3 as clientDeclaresSkillsExtension, cH as defaultResultSchemaForMethod, b4 as describeInvalidTasksPolicy, cI as diffAcknowledgement, cJ as driveTaskToTerminal, a7 as evalCaseVerdictAggregationSchema, aa as evalRateMeasurementSchema, ad as evalRunVerdictSchema, at as evalVerdictDecisionSchema, cK as evaluateToolCalls, cL as executeInputRequiredLeg, cM as initInputRequiredState, cN as isChatGPTAppTool, ay as isEvalRunVerdict, az as isEvalTrialExclusionReason, aB as isEvalVerdictDecisionReason, aC as isEvalVerdictPolicyV2, cO as isHostJson, cP as isMaxRoundsExceeded, cQ as isMcpAppTool, b5 as isTerminalLifecycleStatus, cR as isUnsupportedResultType, cS as makeRequestWithSchemaLegSender, cT as readDeclaredInputCapabilities, b6 as readTasksPolicy, cU as resolveKnownServerIds, cV as resolveRequestedFilter, b7 as resolveSkillsSupport, cW as resolveTasksSupport, aE as resolvedEvalValidityPolicySchema, cX as resumeInputRequiredOperation, cY as runInputRequiredOperation, cZ as runToolTaskSeam, c_ as scrubMetaAndStructuredContentFromToolResult, c$ as scrubMetaFromToolResult, b8 as serverDeclaresSkillsExtension, b9 as setTasksPolicy, ba as skillsDirectoryReadEnabled, d0 as snapshotHostSource, bb as surfaceMayDeclareTasks, bc as taskLifecycleKey, bd as taskModeForSurface, be as toTaskLifecycleSnapshot, d1 as toolTaskSeamOptionsFor, d2 as validateInputRequests, d3 as validateRoundResponses } from './index-fZyfLCHE.js'; import { a5 as CacheEventLogger, L as ListToolsResult, M as MCPServerConfig, R as RpcLogger, a as RetryPolicy, a6 as Tool$1, a7 as AiSdkTool } from './types-CI0Xyszt.js'; export { e as BaseServerConfig, a8 as CacheHitEvent, C as ClientCapabilityOptions, a9 as ConfiguredNegotiationMode, aa as DEFAULT_RETRY_POLICY, ab as ElicitationCallback, ac as ElicitationCallbackRequest, ad as ElicitationHandler, E as ExecuteToolArguments, ae as ExecuteToolRequest, f as HttpExchangeLogEvent, af as HttpExchangeLogger, H as HttpServerConfig, ag as LiveClientState, g as MCPClientManagerConfig, ah as MCPClientManagerOptions, h as MCPConnectionStatus, i as MCPGetPromptResult, j as MCPListTasksResult, b as MCPPrompt, k as MCPPromptListResult, l as MCPReadResourceResult, d as MCPResource, m as MCPResourceListResult, c as MCPResourceTemplate, n as MCPResourceTemplateListResult, ai as MCPServerSummary, o as MCPTask, p as MCPTaskStatus, x as McpParamCrossCheck, aj as NegotiationOutcomeEvent, ak as NegotiationOutcomeLogger, al as ProgressEvent, am as ProgressHandler, an as RegisteredServerState, ao as RpcLogEvent, S as ServerSummary, z as StdioServerConfig, G as TaskOptions, ap as ToolExecuteOptions, aq as UnauthorizedRefreshHandler, ar as UnauthorizedRefreshResult, X as XMcpHeaderDeclaration, K as XMcpHeaderScan, N as buildMcpParamHeaders, O as classifyMcpHeader, Q as decodeMcpHeaderValue, U as encodeMcpHeaderValue, as as isRetryableTransientError, at as normalizeRetryPolicy, au as retryWithPolicy, a2 as scanXMcpHeaderDeclarations, a3 as stripXMcpHeaderAnnotations } from './types-CI0Xyszt.js'; import { ResponseCacheStore, CacheKey, CacheEntry, MaybePromise, jsonSchemaValidator, JsonSchemaType, JsonSchemaValidator, Tool } from '@modelcontextprotocol/client'; export { CacheMode, CacheScope, ElicitResult, InputRequests, InputRequiredResult, InputResponses, isInputRequiredResult, withInputRequired } from '@modelcontextprotocol/client'; import { fY as MCPConformanceConfig, fZ as MCPConformanceResult, f_ as MCPConformanceSuiteConfig, f$ as MCPConformanceSuiteResult, g0 as TrackedRequestFn, g1 as ClientCredentialsResult, g2 as AuthorizationCodeResult, g3 as OAuthConformanceConfig, g4 as ConformanceResult, g5 as OAuthConformanceSuiteConfig, g6 as OAuthConformanceSuiteResult, g7 as MCPAppsConformanceConfig, g8 as MCPAppsConformanceResult, g9 as MCPAppsConformanceSuiteConfig, ga as MCPAppsConformanceSuiteResult, gb as MCPTasksConformanceConfig, gc as MCPTasksConformanceResult, gd as MCPTasksCheckResult, ge as MCPTasksRunOutcome, gf as DirectoryCheckDefinition, a6 as ClaudeReadinessLane, a3 as ClaudePolicySourceRef, aa as ClaudeRunnerCapability, gg as DirectoryCheckStamp, gh as DirectoryReadinessFinding, a5 as ClaudeReadinessFinding, P as ClaudeCapabilityBadge, a4 as ClaudeReadinessAuthMode, a0 as ClaudeObservationState, a8 as ClaudeReadinessResult, ab as ClaudeSubmissionProfile, cN as OutcomeCheckLike, a$ as EvidenceReuseExpectation, a_ as EvidenceReuse, cD as OpenAIReadinessLane, cy as OpenAIPolicySourceRef, cJ as OpenAIRunnerCapability, cK as OpenAISubmissionMode, cv as OpenAIPluginPackageEvidence, cC as OpenAIReadinessFinding, cL as OpenAISubmissionProfile, gi as OpenAIReadinessAuthMode, ck as OpenAIArchiveObservations, gj as XmlParseFn, cu as OpenAIObservationState, cF as OpenAIReadinessResult, cm as OpenAICapabilityBadge, gk as XmlParseResult, aq as ConformanceSuiteKind, ai as ConformanceReport, am as ConformanceRunReportV1, gl as NormalizedOAuthConformanceConfig, bI as OAuthProtocolMode, bK as OAuthRegistrationMode, cZ as ResolvedAuthorizationPlan, gm as VerificationResult, aG as DerivedOAuthEmulation, bE as NegativeTestMode, b8 as IdentityAssertionFormat, da as SubjectIdentifierFormat, dp as XAARequestExecutor, cW as RegistrationStrategy, dJ as XaaRegistrationWarning, dC as XaaCapabilityEvidence } from './model-sampling-support-BwZqY1MR.js'; export { A as AUTH_METHODS, c as AttributableEvidenceSource, d as AuthMethod, e as AuthorizationDiscoverySnapshot, f as AuthorizationPlanCapabilities, g as AuthorizationPlanInput, h as BrandColorCheck, C as CHECK_ERAS, gn as CLAUDE_APP_CONTENT_DOMAIN_HASH_LENGTH, i as CLAUDE_APP_CONTENT_DOMAIN_SUFFIX, j as CLAUDE_APP_DESIGN_BUDGETS, k as CLAUDE_APP_HTML_MIME, l as CLAUDE_ATTESTATIONS, m as CLAUDE_CALLBACK_URLS, n as CLAUDE_DATA_HANDLING_MODES, o as CLAUDE_DECLARED_AUTH_MODES, p as CLAUDE_DOCS_BASE_URL, q as CLAUDE_EVIDENCE_PROVENANCE, r as CLAUDE_FINDING_CLASSES, s as CLAUDE_HOST_PROFILE, t as CLAUDE_INTRUSIVENESS_LEVELS, u as CLAUDE_LATENCY_BUDGETS, go as CLAUDE_LOOPBACK_REDIRECT_IGNORES_PORT, gp as CLAUDE_OBSERVATION_CATALOG, v as CLAUDE_OBSERVATION_IDS, w as CLAUDE_OBSERVATION_KINDS, gq as CLAUDE_OBSERVATION_SCHEMA, x as CLAUDE_OBSERVATION_SCHEMA_VERSION, y as CLAUDE_POLICY_MANIFEST, z as CLAUDE_POLICY_PAGES, D as CLAUDE_POLICY_SNAPSHOT_DATE, E as CLAUDE_READINESS_ENGINE_VERSION, F as CLAUDE_READINESS_LANES, G as CLAUDE_REQUIRED_LANES, H as CLAUDE_RUNNER_CAPABILITIES, I as CLAUDE_SUBMISSION_LIMITS, J as CONFORMANCE_CHECKER_VERSION, K as CONFORMANCE_CHECK_METADATA, L as CONFORMANCE_PROFILE_IDS, M as CONFORMANCE_RUN_SCHEMA_VERSION, N as CONFORMANCE_SUITE_KINDS, O as ClaudeAttestation, Q as ClaudeDataHandlingMode, R as ClaudeDeclaredAuthMode, S as ClaudeEvidenceProvenance, T as ClaudeExperienceObservations, U as ClaudeFindingClass, V as ClaudeFindingStatus, W as ClaudeIntrusiveness, Y as ClaudeLaneCoverage, Z as ClaudeLaneStatus, _ as ClaudeObservationId, $ as ClaudeObservationKind, a1 as ClaudePolicyPage, a2 as ClaudePolicySourceEntry, a7 as ClaudeReadinessLaneResult, a9 as ClaudeReadinessRunContext, ac as ClaudeSubmissionProfileParse, ad as CompletionSafeRedirectPlan, ae as ConformanceAdvisoryTier, af as ConformanceProfile, ag as ConformanceProfileId, ah as ConformanceProfileStamp, gr as ConformanceReportAdvisory, aj as ConformanceReportCase, gs as ConformanceReportCaseStatus, ak as ConformanceReportGroup, gt as ConformanceReportKind, al as ConformanceRunOutcome, an as ConformanceScore, ao as ConformanceSkipReason, gu as ConformanceStepId, ap as ConformanceSuiteId, ar as ConformanceSupport, as as DEFAULT_CONFORMANCE_SUITES, at as DEFAULT_IDENTITY_ASSERTION_FORMAT, av as DEFAULT_NEGATIVE_TEST_MODE, aw as DEFAULT_REGISTRATION_MODE, ax as DEFAULT_REGISTRATION_STRATEGY, ay as DEFAULT_SUBJECT_IDENTIFIER_FORMAT, az as DEFAULT_XAA_CLIENT_AUTH, aA as DIRECTORY_OBSERVATION_CONFIDENCE, aB as DIRECTORY_OBSERVATION_FINDING_CLASSES, aC as DIRECTORY_OBSERVATION_LIMITS, aD as DIRECTORY_OBSERVATION_REASONS, aE as DIRECTORY_OBSERVATION_STATUSES, aF as DecodedJwtParts, aH as DescribeContext, aI as DigestVerification, aJ as DirectoryObservation, gv as DirectoryObservationCatalog, aK as DirectoryObservationConfidence, aL as DirectoryObservationEnvelope, aM as DirectoryObservationFindingClass, gw as DirectoryObservationMapping, gx as DirectoryObservationParseFailure, gy as DirectoryObservationParseResult, aN as DirectoryObservationReason, gz as DirectoryObservationSchema, aO as DirectoryObservationState, aP as DirectoryObservationStatus, aQ as DynamicClientRegistrationCredentials, aR as DynamicClientRegistrationOutcome, aT as ERROR_CATALOG, aU as EVIDENCE_REUSE_REFUSALS, aV as EffectiveSandboxCsp, aW as EffectiveSandboxPermissions, aX as ErrorCatalogEntry, aY as ErrorCatalogSlug, aZ as ErrorOrigin, b0 as EvidenceReuseRefusal, b1 as FrontmatterIdentityCheck, b2 as IDENTITY_ASSERTION_FORMATS, b3 as ID_JAG_GRANT_PROFILE, b4 as ID_JAG_TOKEN_TYPE, b5 as ID_TOKEN_TOKEN_TYPE, b6 as IdJagClientMetadataEvaluation, b7 as IdJagMetadataEvidence, b9 as ImageDimensions, ba as ImageDimensionsResult, bb as JWT_BEARER_GRANT, gA as LEGACY_TASK_STATUSES, gB as MCPAppsCheckCategory, bc as MCPAppsCheckId, gC as MCPAppsCheckResult, gD as MCPAppsCheckStatus, gE as MCPAppsConformanceSuiteDefaults, gF as MCPAppsConformanceSuiteRun, gG as MCPAppsResourceReadOutcome, gH as MCPCheckCategory, bd as MCPCheckEra, gI as MCPCheckEras, be as MCPCheckId, gJ as MCPCheckResult, gK as MCPCheckStatus, gL as MCPConformanceFixtures, gM as MCPReadinessId, gN as MCPReadinessSpecStrength, gO as MCPReadinessWarning, gP as MCPServerSurfaceSnapshot, gQ as MCPTasksCheckCategory, bh as MCPTasksCheckId, gR as MCPTasksCheckStatus, gS as MCPTasksSkipReason, gT as MCP_APPS_CHECK_CATEGORIES, bi as MCP_APPS_CHECK_IDS, bj as MCP_CHECK_CATEGORIES, bk as MCP_CHECK_IDS, bl as MCP_DIRECT_IMAGE_MAX_BYTES, bm as MCP_IMAGE_MAX_MEDIA_PARTS, bn as MCP_IMAGE_MAX_TOTAL_BYTES, bo as MCP_INIT_ID, bp as MCP_LINKED_RESOURCE_MAX_READS, gU as MCP_PRESERVE_RAW_RESULT_FOR_UI, bq as MCP_PROTOCOL_VERSION, gV as MCP_PROTOCOL_VERSION_ERA_IDS, gW as MCP_READINESS_IDS, gX as MCP_TASKS_CHECK_CATEGORIES, br as MCP_TASKS_CHECK_IDS, bs as MCP_UI_EXTENSION_ID, bt as MCP_UI_RESOURCE_MIME_TYPE, bu as McpInitializeRequest, bv as McpLinkedResourceReader, bw as McpModelOutputContent, bx as McpModelOutputContentPart, by as McpModelOutputOptions, bz as McpModelOutputWithLinkedResourcesOptions, bA as McpModelVisibleToolResultPolicy, bB as NEGATIVE_TEST_MODES, bC as NEGATIVE_TEST_MODE_DETAILS, bD as NOT_REQUESTED_OBSERVATIONS, bF as NormalizedError, bG as OAuthAuthorizationRequestResult, gY as OAuthConformanceAuthConfig, bH as OAuthConformanceCheckId, gZ as OAuthConformanceClientConfig, gu as OAuthConformanceStepId, g_ as OAuthConformanceStepResult, g$ as OAuthConformanceSuiteDefaults, h0 as OAuthConformanceSuiteFlow, bL as OAuthRegistrationStrategy, bM as OAuthStateMachineRunConfig, bN as OAuthStateMachineRunResult, bO as OAuthTraceProjectionContext, bP as OAuthTraceSnapshot, bQ as OAuthTraceStepSnapshot, bR as OAuthTraceStepStatus, h1 as OAuthVerificationConfig, h2 as OPENAI_AGENT_METADATA_PATH, h3 as OPENAI_APP_HTML_MIME, bS as OPENAI_ARCHIVE_LIMITS, bT as OPENAI_ATTESTATIONS, bU as OPENAI_BRAND_COLOR_CONTRAST, bV as OPENAI_DATA_TYPES, h4 as OPENAI_DEMO_CREDENTIAL_DELIVERY, h5 as OPENAI_DOMAIN_VERIFICATION_PATH, h6 as OPENAI_EXPECTED_MCP_PATH, h7 as OPENAI_EXTERNAL_POLICY_PAGES, bW as OPENAI_FIELD_LIMITS, bX as OPENAI_HEADLINE_STAGE, bY as OPENAI_HOST_PROFILE, bZ as OPENAI_IMAGE_CONSTRAINTS, b_ as OPENAI_LISTING_CATEGORIES, h8 as OPENAI_MANIFEST_LOCATIONS, h9 as OPENAI_MCP_SKILLS_EXTENSION, ha as OPENAI_MCP_SKILLS_METHODS, b$ as OPENAI_MCP_SKILL_LIMITS, hb as OPENAI_OBSERVATION_CATALOG, c0 as OPENAI_OBSERVATION_IDS, c1 as OPENAI_OBSERVATION_KINDS, hc as OPENAI_OBSERVATION_SCHEMA, c2 as OPENAI_OBSERVATION_SCHEMA_VERSION, hd as OPENAI_PLUGINS_CHANGELOG_URL, he as OPENAI_PLUGINS_DOCS_BASE_URL, hf as OPENAI_PLUGINS_LLMS_INDEX_URL, hg as OPENAI_PLUGINS_POLICY_PAGES, c3 as OPENAI_POLICY_MANIFEST, c4 as OPENAI_POLICY_PAGES, c5 as OPENAI_POLICY_SNAPSHOT_DATE, c6 as OPENAI_PORTAL_ERRORS, c7 as OPENAI_PORTAL_ERRORS_BY_ID, c8 as OPENAI_PORTAL_ERROR_CATEGORIES, c9 as OPENAI_READINESS_ENGINE_VERSION, ca as OPENAI_READINESS_INPUTS, cb as OPENAI_READINESS_LANES, cc as OPENAI_READINESS_STAGES, hh as OPENAI_RELEASE_RULES, hi as OPENAI_REQUIRED_TOOL_ANNOTATIONS, cd as OPENAI_RUNNER_CAPABILITIES, hj as OPENAI_SKILL_METADATA_PATH, ce as OPENAI_STAGE_LANES, cf as OPENAI_SUBMISSION_MODES, cg as OPENAI_SUBMISSION_MODE_SHAPES, hk as OPENAI_SUBMISSION_TEST_CASES, hl as OpenAIAgentInterface, ch as OpenAIAgentMetadata, ci as OpenAIAgentMetadataIssue, cj as OpenAIAgentMetadataParse, hm as OpenAIAgentPolicy, hn as OpenAIAgentToolDependency, cl as OpenAIAttestation, cn as OpenAIDataType, co as OpenAIExperienceObservations, ho as OpenAIExternalPolicyPage, cp as OpenAILaneCoverage, cq as OpenAILaneStatus, cr as OpenAIListingCategory, hp as OpenAIManifestLocation, cs as OpenAIObservationId, ct as OpenAIObservationKind, hq as OpenAIPackageAsset, hr as OpenAIPackageEntryStats, hs as OpenAIPackageGap, ht as OpenAIPackageManifest, hu as OpenAIPackageSkill, hv as OpenAIPackageSurface, hw as OpenAIPluginsPolicyPage, cw as OpenAIPolicyPage, hx as OpenAIPolicyPageFormat, cx as OpenAIPolicySourceEntry, cz as OpenAIPortalErrorCategory, cA as OpenAIPortalErrorDefinition, hy as OpenAIPortalErrorId, hz as OpenAIPortalErrorSeverity, cB as OpenAIPortalIssue, hA as OpenAIReadinessInputName, cE as OpenAIReadinessLaneResult, cG as OpenAIReadinessRunContext, cH as OpenAIReadinessStage, cI as OpenAIReadinessStageResult, cM as OpenAISubmissionProfileParse, cO as PROTOCOL_VERSION_ERAS, cQ as ParsedDigest, cR as ProfileCheckLike, cS as REDACTED, cT as REGISTRATION_STRATEGIES, cU as RETRYABLE_NODE_ERROR_CODES, hB as ReadOpenAIPluginPackageOptions, cV as RegistrationMode, cX as ResolveSandboxCspArgs, cY as ResolveSandboxPermissionsArgs, c_ as ResourceDeclaredCsp, hC as RgbColor, c$ as RunServerDoctorInput, d0 as SAML2_TOKEN_TYPE, d1 as SUBJECT_IDENTIFIER_FORMATS, d2 as SandboxCspDomainSet, d3 as SandboxCspMode, d4 as SandboxCspPolicy, d5 as SandboxPermissionsMode, d6 as SandboxPermissionsPolicy, d7 as ScoredAdvisory, d8 as ServerDoctorDependencies, d9 as SkillIntegrityError, g_ as StepResult, hD as SupportedConformanceResult, db as SupportedDigestAlgorithm, dc as TASKS_DECLARATION_REQUIRED_ERROR_CODE, dd as TOKEN_EXCHANGE_GRANT, de as UNKNOWN_TASK_ERROR_CODE, hE as UNVERIFIED_CONFIDENTIAL_CIMD_CLIENT_NAME, df as UnsupportedCharacter, du as XAA_AS_METADATA_NAMES, dv as XAA_CLIENT_AUTH_METHODS, hF as XAA_CONFIDENTIAL_CIMD_ORIGIN, hG as XAA_CONFIDENTIAL_CIMD_PATH_PREFIX, dw as XAA_DEBUG_CLIENT_ID_METADATA_URL, dx as XAA_DEBUG_IDP_CLIENT_ID, dy as XAA_ENTERPRISE_POLICY_EXTENSION, dz as XAA_ENTERPRISE_POLICY_IDPS, dA as XAA_IDP_KID, dB as XAA_MCP_EXTENSION, dD as XaaClientAuthMethod, dF as XaaEnterprisePolicy, dG as XaaEnterprisePolicyIdp, dH as XaaEnterprisePolicyState, dN as applyRuntimeClientCapabilities, dP as buildAuthorizationServerMetadataCandidates, hH as buildConfidentialCimdUrl, dQ as buildConformanceProfileStamp, dR as buildConformanceRunReport, dS as buildDynamicClientRegistrationRequest, dT as buildIssuerPublicationCandidates, dU as buildMcpInitializeRequest, dV as buildOutcomeSummary, dW as buildProtectedResourceMetadataCandidates, dY as canRunConformance, dZ as canonicalSkillJson, d_ as canonicalizeMcpResource, d$ as checkBrandColor, hI as checkEvidenceReuse, e0 as checkFrontmatterDrift, e1 as checkSkillIdentity, e2 as claudePolicySource, e3 as claudeSubmissionProfileSchema, hJ as collectConnectedServerDoctorState, e4 as comparableAdvertisedFrontmatter, e5 as computeConformanceScore, e6 as computeSkillVersionHash, e7 as conformanceProfile, e8 as conformanceProfileDigest, hK as contrastRatio, eb as createOAuthTraceProjectionContext, hL as crossCheckToolDependencies, ec as decideConformanceOutcome, ed as decideLaneStatus, hM as decodeConfidentialCimdKey, ee as decodeJWT, ef as decodeJWTParts, eh as deriveOAuthEmulation, hN as derivedFrom, ei as describeAsSlug, ej as describeConformanceScore, ek as describeError, em as evaluateIdJagClientMetadata, en as evaluateMcpInitializeResponse, eo as executeDynamicClientRegistration, ep as extensionTaskToObservation, eq as extractNodeErrno, er as findListedResource, es as findUnsupportedCharacters, et as formatJWTTimestamp, hO as getConfidentialCimdReflectorMetadata, ev as getDefaultClientCapabilities, eA as getXaaConnectClientMetadata, eB as getXaaDebugClientMetadata, eC as groupPortalIssues, eD as hasBlockingPortalIssue, eE as hasSurroundingWhitespace, eF as isDispositiveClaudeFinding, eG as isHttpServerConfig, eH as isInapplicableCheck, eI as isInvalidRedirectUriRejection, eJ as isLaneApplicableInMode, eK as isListedResource, eL as isLoopbackClientMetadataUrl, eM as isLoopbackHost, eN as isNegativeTestMode, eO as isNormalizedError, eP as isOpenAIPolicyCorpusVerified, eQ as isOpenAIReadinessResult, eR as isPolicyCorpusVerified, eS as isPolicyDependentNegativeTestMode, eT as isSkillIntegrityError, eU as isSupportedText, eV as isTasksDeclarationRequiredError, eW as isUnknownTaskError, eX as isUnrunCheck, eZ as legacyTaskToObservation, hP as mapClaudeObservationsToFindings, hQ as mapObservationsToFindings, hR as mapOpenAIObservationsToFindings, e_ as mcpCallToolResultToModelOutput, e$ as mcpCallToolResultToModelOutputWithLinkedResources, f0 as mcpInitializeExtensionEvidence, f1 as mergeClientCapabilities, f2 as modelRejectsTemperature, f3 as normalizeAuthMethod, f4 as normalizeClientCapabilities, f5 as normalizeConformanceSuites, f6 as normalizeIdentityAssertionFormat, f7 as normalizeRegistrationMode, f8 as normalizeRegistrationStrategy, f9 as normalizeSubjectIdentifierFormat, fa as normalizeXaaClientAuth, hS as observationFailure, fb as openaiPolicySource, hT as openaiPortalIssue, fc as openaiSubmissionProfileSchema, fd as originOf, hU as parseClaudeExperienceObservations, fe as parseClaudeSubmissionProfile, ff as parseDigest, hV as parseDirectoryObservationEnvelope, fg as parseHexColor, fh as parseOpenAIAgentMetadata, hW as parseOpenAIExperienceObservations, fi as parseOpenAISubmissionProfile, fj as parseRetryAfterMs, fk as partitionByProfile, fl as partitionByStamp, fm as planCompletionSafeRedirects, fn as pooledConformanceScore, fo as projectOAuthTraceSnapshot, fp as readImageDimensions, fq as readOpenAIPluginPackage, fr as readXaaEnterprisePolicy, fs as redactConformanceReportForSharing, ft as redactSharedServerUrl, fu as redactUrlSecrets, hX as relativeLuminance, hY as renderConformanceReportJUnitXml, hZ as renderConformanceReportJson, fv as resolveAuthorizationPlan, fw as resolveRegistrationStrategies, fx as resolveSandboxCsp, fy as resolveSandboxPermissions, h_ as retryAfterMsFromError, fz as rollUpLaneStatus, fA as runOAuthStateMachine, h$ as runServerDoctor, fB as sameReadinessTarget, fC as scoreFromAppsResult, fD as scoreFromOAuthResult, fE as scoreFromProtocolResult, fF as scoreFromTasksResult, fH as sha256HexOfBytes, fI as sha256HexOfText, fJ as skillNameFromUri, fK as sniffImageMimeType, fL as splitAdvertisedFrontmatter, fM as splitSkillMarkdown, fN as stageLanesFor, fO as summarizeLaneCoverage, fP as summarizeTestCases, fQ as toConformanceReport, fR as unscoredCheckIds, fS as validateClientIdMetadataUrl, fT as verifyDigest, fU as verifySkillMarkdown, fV as withSkillsExtensionCapability, fW as withXaaEnterprisePolicy, fX as withoutXaaEnterprisePolicy } from './model-sampling-support-BwZqY1MR.js'; import { M as McpProtocolVersion } from './types-HXAijHji.js'; export { o as CspDomainSet, f as Harness, c as HostStyleId, J as MCP_PROTOCOL_VERSIONS, j as McpAppsCapabilities, i as McpToolResultImageRenderPlacement, e as McpToolResultImageRendering, h as McpToolResultImageRenderingPolicy, d as ModelVisibleMcpToolResults, K as MrtrSupport, L as OpenAiAppsCapabilities, P as PaginationTraversalMode, S as ServerId, T as ToolParamHeaderMirroring, N as isKnownProtocolVersion, Q as isStatelessProtocolVersion, R as protocolVersionLabel } from './types-HXAijHji.js'; import { i as PlatformEvalRun, Y as PlatformEvalIteration, l as PlatformRunCompare, z as PlatformEvalCase } from './eval-decision-summary-chLr2s0E.js'; export { cW as EvalDecisionSummary, cX as EvalDecisionSummaryCase, cY as EvalDecisionSummaryInput, cZ as EvalDecisionVerdict, c_ as EvalReportingError, c$ as NormalizedEvalDecisionCase, S as SdkError, d0 as StageChainStatus, d1 as buildEvalDecisionSummary, d2 as buildEvalDecisionSummaryFromIterations, d3 as buildEvalRunDecisionSummary, d4 as formatEvalDecisionSummary, d5 as formatEvalRunDecisionSummary, cS as readEvalRunDecisionSummary } from './eval-decision-summary-chLr2s0E.js'; import { O as OAuthProtocolVersion, m as OAuthFlowState, n as EmulatedAuthAttempt, o as EmulatedRegistrationPreference, H as HttpHistoryEntry, z as OAuthRequestExecutor, u as OAuthEmulationCoverage, v as OAuthEmulationDivergence } from './server-doctor-core-DFaTigIr.js'; export { C as ConnectedServerDoctorState, r as OAUTH_EMULATION_FIELDS, t as OAuthEmulationConfig, w as OAuthEmulationField, x as OAuthEmulationFieldStatus, P as ProbeHttpAttempt, a as ProbeInitializeInfo, b as ProbeMcpServerConfig, c as ProbeMcpServerResult, d as ProbeOAuthDetails, e as ProbeTransportResult, f as ServerDoctorCheck, g as ServerDoctorChecks, h as ServerDoctorConnection, i as ServerDoctorError, S as ServerDoctorResult, X as normalizeServerDoctorError, p as probeMcpServer } from './server-doctor-core-DFaTigIr.js'; import { d as EvalRunDecisionSummary, a as ScoreDefinition, Q as ScorerContextV1, b as ScoreRawOutcome, S as ScoreResult, E as EvaluationConfigSnapshot, R as ResolvedScoreDefinition, e as ScorerRole, T as ScorerErrorPolicy } from './decision-summary-CksWu77D.js'; export { g as EVAL_RUN_DECISION_SUMMARY_SCHEMA_VERSION, r as EvalRunDecisionCounts, s as EvalRunDecisionDiagnostic, A as EvalRunDecisionVerdict, P as PREDICATES_VERSION, O as ScoreStatus, U as ScorerIdSource, a6 as assembleEvalRunDecisionSummary, ag as evalRunDecisionSummarySchema } from './decision-summary-CksWu77D.js'; import { H as HostJson } from './public-types-CX8stXC3.js'; export { e as HostComputer, a as HostConnectionDefaults, b as HostInit, c as HostMcp, d as HostServerOverride } from './public-types-CX8stXC3.js'; import { b as Predicate, c as PredicateResult } from './types-BBk0lTBo.js'; export { r as redactForTelemetry, r as redactSensitiveValue } from './telemetry-redaction-DooVPae5.js'; export { a as DECISION_SUMMARY_FALLBACK_NEXT_ACTION, N as NEXT_ACTION_BY_FAILURE_CATEGORY, c as aggregateEvaluationConfigHash, d as allGatingScorersPassed, e as buildEvaluationConfigSnapshot, f as canonicalDigest, g as canonicalJson, h as definitionHash, i as errorScoreResult, j as evaluationConfigHash, k as evaluationConfigSnapshotSchema, l as finalizeScoreResult, n as notApplicableScoreResult, r as resolveScoreDefinition, m as resolvedScoreDefinitionSchema, o as scorePassed, q as scoreResultSchema, x as sha256Hex, y as skippedScoreResult } from './decision-labels-KRlswm7m.js'; import { P as PluginFileSource } from './types-m3TBGFFa.js'; import { KeyObject } from 'crypto'; import { ToolSet } from 'ai'; export { StopCondition, hasToolCall, stepCountIs } from 'ai'; import { H as HostExecutionPolicy } from './tool-visibility-B8MWtym0.js'; export { F as FinalizeEvalPassedParams, f as finalizePassedForEval, i as isCallToolResultError, t as traceIndicatesToolExecutionFailure, a as traceMessagePartIndicatesToolFailure } from './eval-tool-execution-CcInGlXP.js'; import { CreateModelOptions } from './model-factory.js'; export { BaseUrls, PROVIDER_PRESETS, ParsedLLMString, ProviderLanguageModel, createCustomProvider, createModelFromString, parseLLMString, parseModelIds } from './model-factory.js'; export { O as OAuthProxyError, a as OAuthProxyRequest, b as OAuthProxyResponse, e as executeDebugOAuthProxy, c as executeOAuthProxy, f as fetchOAuthMetadata, v as validateUrl } from './oauth-proxy-DP5EGDJ4.js'; export { EXPLORE_TO_SDK_EVALS_SKILL_MD, SKILL_MD } from './skill-reference.js'; import { z } from 'zod'; export { GetPromptParams, ListAllServerSkillsParams, ListAllServerSkillsResult, ListPromptsMultiParams, ListPromptsParams, ListResourcesParams, ListToolsParams, ReadResourceParams, WithEphemeralClientOptions, getPrompt, listAllServerSkills, listPrompts, listPromptsMulti, listResources, listTools, readResource, withDisposableManager, withEphemeralClient } from './operations.js'; import '@modelcontextprotocol/client/stdio'; import '@ai-sdk/openai'; /** * `ObservableResponseCache` — a `ResponseCacheStore` decorator that surfaces * PROVENANCE for the SEP-2549 response cache. * * ## Why this exists * * The upstream client (`@modelcontextprotocol/client`) serves a cacheable verb * from cache — with ZERO wire exchange — whenever a still-fresh entry exists * under `cacheMode: "use"` (the default). Freshness requires the server to have * sent `ttlMs > 0` (`defaultCacheTtlMs` stays `0`, so a hint-less result is * stored but never served). A debugger MUST NOT let such an invisible serve * look like a real request: MCPJam surfaces the serve (and its age) so the * operator can tell "the server answered this" from "the cache answered this". * * This wrapper reports each fresh `get` hit to a {@link CacheEventLogger}. That * is a channel wholly SEPARATE from the rpc/wire logger: a cache hit is exactly * the case where no JSON-RPC request left the process, so it must never be * injected into the wire log. * * ## Known imprecision of the "fresh get ⇒ served" heuristic * * The store cannot see the caller's `cacheMode`. The upstream client only calls * `store.get` on the READ path, which it takes ONLY under `cacheMode: "use"` * (verified: `'refresh'`/`'bypass'` short-circuit before consulting the store). * So a fresh `get` observed here corresponds to a real serve under `"use"`. * The one caveat: the client also probes `tools/list` internally to back * `callTool` output-validation / header mirroring, so a fresh `get` for * `tools/list` can be an internal derived-view read rather than a user-facing * list serve. We report both and accept that over-count — an extra provenance * signal is safe; a missed one (an invisible serve shown as a wire request) * is not. `ageMs` is best-effort: it is `now − storeTime` for entries THIS * wrapper stored; a hit on an entry written by a different wrapper instance * (e.g. a shared store) reports `ageMs: 0`. */ interface ObservableResponseCacheOptions { /** Server whose connection this store backs (stamped onto every event). */ serverId: string; /** Provenance sink for fresh serves. */ onHit: CacheEventLogger; /** Clock injection point (tests). Defaults to `Date.now`. */ now?: () => number; } /** * Wrap a {@link ResponseCacheStore} (default: a fresh in-memory store) so fresh * `get` hits are reported to {@link ObservableResponseCacheOptions.onHit}. All * mutation/read semantics are delegated verbatim to the wrapped store — the * only added behavior is the out-of-band provenance emission and a store-time * side table used to compute `ageMs`. */ declare class ObservableResponseCache implements ResponseCacheStore { private readonly inner; private readonly serverId; private readonly onHit; private readonly now; /** key → wall-clock ms at which THIS wrapper last stored the entry. */ private readonly storedAt; constructor(inner: ResponseCacheStore | undefined, options: ObservableResponseCacheOptions); get(key: CacheKey): Promise; set(key: CacheKey, entry: { value: string; expiresAt?: number; scope?: CacheEntry["scope"]; }): MaybePromise; delete(key: CacheKey): MaybePromise; evict(method: string): MaybePromise; clear(): MaybePromise; } /** * Custom error classes for MCP SDK */ /** * Base error class for all MCP SDK errors */ declare class MCPError extends Error { readonly code: string; constructor(message: string, code: string, options?: { cause?: unknown; }); } /** * Authentication error - thrown for 401, token expired, invalid token, etc. */ declare class MCPAuthError extends MCPError { readonly statusCode?: number | undefined; constructor(message: string, statusCode?: number | undefined, options?: { cause?: unknown; }); } /** * Tasks wire mismatch — a tasks operation was requested against a server whose * negotiated protocol version / advertised capabilities resolve to a different * wire (or to no tasks wire at all). Nothing is sent when this throws. */ declare class MCPTasksWireError extends MCPError { readonly wire: string; constructor(message: string, wire: string, options?: { cause?: unknown; }); } /** Type guard for {@link MCPTasksWireError}. */ declare function isMCPTasksWireError(error: unknown): error is MCPTasksWireError; /** * Type guard to check if an error is an MCPAuthError */ declare function isMCPAuthError(error: unknown): error is MCPAuthError; /** * Unwrap the underlying transport error carried by an auto-negotiation probe * failure. * * With auto activation an UNCONFIGURED connection probes with * `server/discover`; when that probe hits an OAuth-gated endpoint the upstream * client raises `SdkError(EraNegotiationFailed)` carrying the real transport * error (e.g. `UnauthorizedError`) at `error.data.cause`. 401 recovery and * connection telemetry must see the real 401 through that wrapper rather than * treating the whole connect as an opaque negotiation failure — otherwise an * unconfigured connect to a protected server would surface a generic * negotiation error instead of triggering OAuth. * * Returns the innermost non-wrapper error; returns the input UNCHANGED when it * is not an era-negotiation wrapper — a non-wrapper transport error (e.g. a * bare `UnauthorizedError` from an explicit legacy pin, where no probe and * therefore no wrapper ever occurs) passes through byte-identically. */ declare function unwrapEraNegotiationCause(error: unknown): unknown; /** * Classify a connection failure into the short, string `failureClass` reported * on a negotiation-outcome telemetry event. * * Prefers the error's `name`, then its `code`, then the string form of a string * cause, falling back to `"unknown"`. A transport `code` is frequently numeric * at runtime (e.g. `401` / `403`), so it is normalized with `String(...)` — a * bare cast would let a number escape into the `failureClass?: string` public * contract. The caller is expected to pass the UNWRAPPED cause (see * {@link unwrapEraNegotiationCause}) so the real transport class is reported * rather than the opaque era-negotiation wrapper. */ declare function classifyNegotiationFailureClass(cause: unknown): string; /** * Strictly detects HTTP 401 authorization failures. * * Unlike isAuthError, this intentionally does not treat 403 or generic * auth-looking messages as refreshable. OAuth refresh can repair an expired or * rejected access token; it cannot repair insufficient scope. * * Sees through an `SdkError(EraNegotiationFailed)` wrapper so an auto-probe * 401 (unconfigured connect to an OAuth-gated server) is recognized — see * {@link unwrapEraNegotiationCause}. */ declare function isUnauthorized401(error: unknown): boolean; /** The `WWW-Authenticate` step-up challenge fields surfaced to a caller. */ type InsufficientScopeChallenge = { requiredScope?: string; resourceMetadataUrl?: string; errorDescription?: string; }; /** * Strictly detects an upstream `InsufficientScopeError` (SEP-2350 runtime scope * step-up) anywhere in the error / cause chain. * * Used to keep a connect-time 403 `insufficient_scope` from being swallowed / * downgraded by the Streamable→SSE transport fallback, which would strip the * challenge fields. * * Deliberately NOT `extractInsufficientScopeChallenge(error) !== undefined`: * this returns true for a branded error carrying no challenge fields at all, * because the transport-fallback protection cares that the class was seen, not * that it was actionable. */ declare function isInsufficientScopeError(error: unknown): boolean; /** * Recognize an upstream `InsufficientScopeError` (SEP-2350) anywhere in the * error / cause chain and return its `WWW-Authenticate` challenge fields. * * A runtime `403 insufficient_scope` from a live MCP request surfaces as this * transport-layer error (the transport is constructed with * `onInsufficientScope: "throw"`, so it never attempts a doomed server-side * interactive re-authorization). Returning the challenge lets a client drive * the union-scope step-up re-authorization. * * The fields originate from the resource server's header, so treat them as * UNTRUSTED when rendering. * * Returns `undefined` when no challenge field is present — a bare name match * carries nothing actionable — and keeps walking in that case, so a branded but * empty wrapper does not hide a populated challenge deeper in the chain. */ declare function extractInsufficientScopeChallenge(error: unknown): InsufficientScopeChallenge | undefined; /** * Checks if an error is an authentication-related error. * Detects auth errors by: * 1. Error class name (UnauthorizedError from MCP SDK, OAuthResponseError) * 2. HTTP status codes (401, 403) from transport errors * 3. Common auth-related patterns in error messages (case-insensitive) */ declare function isAuthError(error: unknown): { isAuth: boolean; statusCode?: number; }; /** * Wire-boundary guards for `io.modelcontextprotocol/tasks` (SEP-2663) * payloads. Every guard validates against the vendored zod mirrors in * `tasks-ext-schemas.ts` — untrusted server input is never merely sniffed. * * The legacy (2025-11-25) guards in `result-guards.ts` are untouched: the two * wires are not compatible and must not share a validator. */ /** * Thrown when a server sends a task payload that fails validation. * * This is an INVALID-SERVER-RESPONSE condition, distinct from "this connection * does not speak the tasks extension" (`MCPTasksWireError`). Routes must not * collapse the two: an unsupported wire is permanent, whereas a bad payload is * a server bug worth surfacing with its method and violations. */ declare class InvalidTaskExtPayloadError extends TypeError { readonly issues: string[]; /** The extension method whose response failed, e.g. `"tasks/get"`. */ readonly method?: string; /** Always the extension wire — the legacy guards live in `result-guards.ts`. */ readonly wire: "extension"; /** Truncated, control-character-free violation summary, safe to log. */ readonly summary: string; constructor(context: string, issues: string[], options?: { method?: string; }); } /** Type guard for {@link InvalidTaskExtPayloadError}. */ declare function isInvalidTaskExtPayloadError(error: unknown): error is InvalidTaskExtPayloadError; /** * A `tools/call` result is a task creation iff it carries * `resultType: "task"`. A non-task result is valid — the server decides — so * this is a predicate, not an assertion. */ declare function isCreateTaskExtResult(value: unknown): value is CreateTaskExtResult; declare function assertCreateTaskExtResult(value: unknown, context?: string, method?: string): CreateTaskExtResult; declare function assertGetTaskExtResult(value: unknown, context?: string, method?: string): GetTaskExtResult; /** * `io.modelcontextprotocol/skills` (SEP-2640) client operations. * * The extension is negotiated CONNECTION-LEVEL (SEP-2133): both sides declare * it in `initialize`, and nothing rides `params._meta`. That makes this module * much thinner than its tasks counterpart — there is no per-request * eligibility envelope to reconstruct, no `subscriptions/listen` seam, and no * era gate (see `skills-dispatch.ts` for why `skills/*` is era-blind). * * What remains is the ONE upstream construct that still stands between an * extension method and a socket: the result-schema seam. The schema-less * `Protocol.request` overload resolves its validator from the negotiated era's * codec registry, which returns `undefined` for every extension method and * makes the call throw "'…' is not a spec method". So every request here rides * `requestWithSchema` with a deliberately loose wire schema, and the real * validation is the zod mirror in `skills-ext-guards.ts` — which can report * WHICH field of WHICH entry failed, where upstream would report only * "invalid result". */ /** The extension's request methods. */ declare const SkillsExtListMethod: "skills/list"; declare const SkillsExtGetMethod: "skills/get"; /** OPTIONAL, gated on the server's `{ directoryRead: true }` setting. */ declare const SkillsExtDirectoryReadMethod: "resources/directory/read"; /** * The JSON-RPC code a conforming server answers for a `skills/get` on a URI it * does not serve — `-32602`, which is the GENERIC *Invalid params*. */ declare const SKILL_NOT_FOUND_ERROR_CODE = -32602; /** * Whether the server rejected the params for this `skills/get`. * * ## What this does and does NOT prove * * `-32602` is generic. A conforming server also returns it for a malformed * `uri`, a wrong parameter type, or a missing parameter, and nothing in * SEP-2640 mandates a discriminator that would separate those from "no such * skill". So this predicate means "the server rejected these params", NOT "the * skill does not exist". * * That distinction matters because the capture path uses this signal to record * disappearance. A client-side request defect must not be written down as a * skill deletion — the one conclusion the SEP forbids drawing from absence. A * caller recording disappearance therefore needs the URI to have been captured * successfully BEFORE (so the params are known-good), which is exactly the * condition the capture coordinator probes under. * * The code is read from the top level and from a nested `error.code`, because * transports and adapters wrap JSON-RPC errors differently and a missed * unwrap would silently turn "rejected" into "inconclusive". */ declare function isSkillNotFoundError(error: unknown): boolean; /** * Wire-boundary guards for `io.modelcontextprotocol/skills` (SEP-2640) * payloads. Every guard validates against the vendored zod mirrors in * `skills-ext-schemas.ts` — untrusted server input is never merely sniffed. * * Mirrors `tasks-ext-guards.ts` in structure (a dedicated error type carrying * a truncated, control-character-free issue list) because the failure mode is * the same: the caller is a debugger, and "invalid result" without the field * that failed is not a diagnosis. */ /** * Thrown when a server sends a skills payload that fails validation. * * This is an INVALID-SERVER-RESPONSE condition, distinct from "this connection * does not speak the skills extension" ({@link MCPSkillsWireError}) and from * "the content did not match its digest" (`SkillIntegrityError`). All three * are separate because they call for different UI: a bad payload is a server * bug, an inactive wire is a configuration fact, and an integrity failure is a * security event. */ declare class InvalidSkillsPayloadError extends TypeError { readonly issues: string[]; /** The extension method whose response failed, e.g. `"skills/list"`. */ readonly method?: string; /** Truncated, control-character-free violation summary, safe to log. */ readonly summary: string; constructor(context: string, issues: string[], options?: { method?: string; }); } /** * Type guard for {@link InvalidSkillsPayloadError}. * * `instanceof` the concrete class, not a `name` sniff: a name check accepts any * error that happens to carry the same string, and routes branch on this to * decide retry and status mapping. */ declare function isInvalidSkillsPayloadError(error: unknown): error is InvalidSkillsPayloadError; /** * Raised when a `skills/*` call is attempted on a connection where the * extension is not mutually declared. * * Deliberately a THROW rather than an empty result: "this server has no * skills" and "this client never declared the extension" are different facts, * and collapsing them would let a capability bug read as an empty catalog. */ declare class MCPSkillsWireError extends Error { readonly method: string; readonly serverId: string; readonly advertised: boolean; readonly declared: boolean; /** * Set when the extension IS mutually declared but an OPTIONAL setting the * method depends on is off — today only `directoryRead`. * * Its own field rather than folded into `declared`: the message is derived * from these fields, and reporting `declared: false` for a server that * declared correctly would name the wrong defect. In a debugger the * diagnostic message is the product. */ readonly missingSetting?: string; constructor(args: { method: string; serverId: string; advertised: boolean; declared: boolean; missingSetting?: string; }); } declare function isMCPSkillsWireError(error: unknown): error is MCPSkillsWireError; /** Validates a `skills/list` result, preserving SEP-2549 cache attributes. */ declare function assertSkillsListResult(value: unknown, context?: string): SkillsExtListResult; /** * Validates ONE skill entry — a listing element, or the contents of a * `skills/get` envelope. * * SEP-2640 gives the entry inside `skills/get` the same shape as a listing * element, so this shares the entry mirror rather than duplicating it. It does * NOT accept a `skills/get` result directly; see {@link assertSkillsGetResult}. */ declare function assertSkillEntry(value: unknown, context?: string): SkillEntry; /** * Validates a `skills/get` RESULT and unwraps it. * * The result is `{ skill: SkillEntry }`. Validating the envelope as though it * were the entry looks for `uri` at the top level, where a conforming server * never puts it — so every conforming server fails and only a server that * flattens the envelope passes. Unwrapping here keeps that shape knowledge in * the one place that mirrors the wire. */ declare function assertSkillsGetResult(value: unknown, context?: string): SkillEntry; /** Validates a `resources/directory/read` result. */ declare function assertDirectoryReadResult(value: unknown, context?: string): SkillsDirectoryReadResult; /** * The strict elicitation-content validator, as a shared factory. * * One rule, two consumers: the manager's standalone MRTR path and any task * `input_required` driver must judge accepted elicitation content against the * request's `requestedSchema` with the SAME strictness, or a response the * interactive path would refuse sails through the task path. The closure was * previously a private member of `MCPClientManager`; it lives here so a * surface wiring `TaskInputDriverOptions.validateElicitationContent` (the CLI) * uses the identical authority instead of a hand-rolled copy free to drift. * * Unlike tool-output validation, an unknown JSON-Schema dialect is treated as * INVALID (not fail-open): elicitation content is untrusted, so an exotic * dialect must not wave it through. The dialect-aware validator is constructed * per call so the throwing `onUnknownDialect` never leaks state between * validations. * * Node-only: `DialectAwareJsonSchemaValidator` compiles via `new Function`. * Browser/workerd surfaces build their own from * `CspSafeDialectAwareJsonSchemaValidator`. */ declare function createStrictElicitationContentValidator(): ElicitationContentValidator; /** * Engine-agnostic core for dialect-aware JSON Schema validation. * * The upstream v2 defaults (`AjvJsonSchemaValidator` on Node, * `CfWorkerJsonSchemaValidator` on browser/workerd) reject any schema whose * `$schema` is not 2020-12, which hard-fails `tools/call` for every v1-SDK * server: `zod-to-json-schema` stamps * `"$schema": "http://json-schema.org/draft-07/schema#"` on emitted schemas. * The spec allows an explicitly declared draft-07 dialect on every protocol * version ("Tool with explicit draft-07 schema" is a published valid example; * 2020-12 is only the default when `$schema` is absent), so an inspector * must validate the declared dialect rather than reject it. * * Dispatch rule, per schema: * - no `$schema`, or a 2020-12 URI -> the 2020-12 engine * - a draft-07 URI -> the draft-07 engine * - anything else -> no validation; warn, don't fail the call * * This module deliberately imports no validation engine: the Ajv-backed * subclass would drag `new Function`-based Ajv into browser/workerd bundles * (where it is CSP-hostile and breaks outright on Cloudflare Workers), so the * engines live in per-runtime subclasses. */ interface DialectAwareJsonSchemaValidatorOptions { /** * Called when a schema declares a dialect that is neither 2020-12 nor * draft-07. That schema is not validated (the returned validator accepts * every input) so an exotic-but-legal dialect never blocks the tool call * itself. Defaults to a `console.warn`, emitted once per dialect per * instance — pass a handler to route the diagnostic elsewhere. */ onUnknownDialect?: (declaredDialect: string) => void; } /** Lazy per-dialect engine factories supplied by a runtime-specific subclass. */ interface DialectEngineFactories { draft2020: () => jsonSchemaValidator; draft07: () => jsonSchemaValidator; } /** * `jsonSchemaValidator` implementation that picks the engine from the * schema's declared `$schema`. Use one instance per `Client` via * `ClientOptions.jsonSchemaValidator` (engines may cache compiled schemas by * `$id`, so sharing an instance across servers could cross-pollinate `$id` * lookups). */ declare class DialectDispatchingJsonSchemaValidator implements jsonSchemaValidator { private draft2020Validator?; private draft07Validator?; private readonly engines; private readonly onUnknownDialect; private readonly warnedDialects; constructor(engines: DialectEngineFactories, options?: DialectAwareJsonSchemaValidatorOptions); getValidator(schema: JsonSchemaType): JsonSchemaValidator; } /** * Ajv-backed dialect-aware validator for Node runtimes (see * `dialect-dispatch-json-schema-validator.ts` for the dispatch rationale). * * Both engines mirror the upstream Node default configuration * (`strict: false`, `validateFormats: true`, `validateSchema: false`, * `allErrors: true`, with `ajv-formats` registered) and are created lazily. * Ajv compiles schemas via `new Function` — do not import this module from * browser/workerd entry points; use * `CspSafeDialectAwareJsonSchemaValidator` there instead. */ declare class DialectAwareJsonSchemaValidator extends DialectDispatchingJsonSchemaValidator { constructor(options?: DialectAwareJsonSchemaValidatorOptions); } /** * CSP-safe dialect-aware validator for browser/workerd runtimes (see * `dialect-dispatch-json-schema-validator.ts` for the dispatch rationale). * * Built on `@cfworker/json-schema` (via the upstream `validators/cf-worker` * provider), which interprets schemas instead of compiling them with * `new Function` — Ajv is CSP-hostile in browsers and breaks outright on * Cloudflare Workers, which is why the upstream browser/workerd shims default * to this engine. Passing an explicit `draft` skips the provider's own * 2020-12-only `$schema` gate (the caller owns dialect choice), mirroring how * the Ajv flavor passes a pre-configured engine. */ declare class CspSafeDialectAwareJsonSchemaValidator extends DialectDispatchingJsonSchemaValidator { constructor(options?: DialectAwareJsonSchemaValidatorOptions); } interface RawSseEvent { /** `event:` field, if present. */ event?: string; /** Concatenated `data:` lines (newline-joined), verbatim. */ data: string; /** `id:` field, if present. */ id?: string; /** Parsed `data` payload when it is a single JSON document, else undefined. */ json?: unknown; /** * Whether the frame was closed by a blank-line delimiter. A truncated tail * (connection cut mid-frame) parses into a frame with `terminated: false`; * callers judging stream health must not count it as a delivered event. */ terminated: boolean; } interface RawRequest { method: string; url: string; /** Header names lowercased (per the Fetch `Headers` iteration contract). */ headers: Record; bodyText: string; /** Parsed request body when JSON, else undefined. */ json?: unknown; } interface RawResponse { status: number; statusText: string; headers: Record; /** Full response body as text ("" for a body-less response). */ bodyText: string; /** Parsed body when the payload is a single JSON document, else undefined. */ json?: unknown; /** Parsed SSE frames when `content-type` is `text/event-stream`. */ sse?: RawSseEvent[]; /** * Set when the body could not be read to completion (a mid-stream error). * Status and headers are still captured verbatim — the server DID answer — * so a check can separate "request accepted" from "body delivered". */ bodyError?: string; } interface RawExchange { request: RawRequest; response: RawResponse; } /** * The run-wide record of what actually came off the wire. * * WHY THIS EXISTS. Before it, "everything this run observed" was not a thing * that existed anywhere. The raw check families (`protocol`, `security`, * `transport`, `modern`) run concurrently, each building its own requests and * reading its own responses; `ModernRunState.observed` was the closest thing * to a shared view and it covers exactly one family. So a check that has to * reason about EVERY message — which is what schema validation is — had no * input to read. This is that input. * * TWO FEEDS, NO OVERLAP. * - The raw path records at one seam, inside `rawRequest`, so every raw * probe in every family is covered by construction and a new check cannot * forget to opt in. * - The client path records by wrapping the fetch the official Client dials * through, which is the only place its traffic is visible unnormalized * (by the time a result reaches app code the client has already consumed * the wire-only members a schema check exists to inspect). * The two never see the same exchange: `rawRequest` builds its own capturing * fetch over `ctx.fetchFn`, and the client wrapper sits on the Client's * `baseFetch`. Recording at both levels of one stack would double-count. * * CORRELATION IS THE POINT. A response validated against the generic * `JSONRPCMessage` union is nearly vacuous: the union's `Result` branch * carries `additionalProperties: {}` and requires almost nothing, so a * `tools/list` result missing `ttlMs` and `cacheScope` sails through. Only * knowing that a given response answers `tools/list` selects `ListToolsResult` * — which does require them. So each observation carries the METHOD of the * request it answers, paired by JSON-RPC id within the exchange that produced * it. */ /** A JSON-RPC id as it appeared on the wire — including illegal values. */ type ObservedRequestId = string | number | null | undefined; interface ObservedWireMessage { /** The message verbatim, before any normalization. */ message: unknown; /** * The method of the request this message answers, when the recorder could * pair them. Absent for a notification, for a message whose id matched no * request in its exchange, and for anything observed without a request. */ requestMethod?: string; /** The id carried by the message itself, for the failure report. */ id?: ObservedRequestId; /** * Whether the REQUEST this message answers carried a determinable JSON-RPC * id. False for a body that did not parse as JSON, or that parsed without an * `id` member. * * Load-bearing for one narrow case: JSON-RPC 2.0 says an error response's id * "MUST be the same as the value of the id member in the Request Object" but * that "if there was an error in detecting the id … it MUST be Null". The * MCP schemas type `RequestId` as `["string","integer"]` and do not model * that null, so a server answering a deliberately malformed frame CORRECTLY * would otherwise be reported as violating the schema. Knowing whether the * id was detectable is what separates "answered a garbage frame properly" * from "dropped an id it had". */ requestIdDeterminable?: boolean; /** * Set when the message paired with its request only after comparing ids * ACROSS types — the request sent `1` and the response echoed `"1"`, or the * reverse. Correlation still succeeds (see {@link sameId}), but the echo is * wrong: "the response MUST contain the same ID as the request", and `1` and * `"1"` are different JSON values. Reported by the wire check so a loose * pairing cannot silently absorb a real defect. */ idEchoMismatch?: { sent: string | number; echoed: string | number; }; /** Human-readable provenance, e.g. `POST tools/list`. Never a verdict. */ origin: string; } declare class WireObservationRecorder { private readonly entries; /** * Record one bounded request/response exchange. The request side is read for * correlation only — the check judges what the SERVER sent, never what we * sent it. */ recordExchange(exchange: RawExchange, origin?: string): void; /** * Record messages read off a long-lived stream, which `recordExchange` * cannot cover: the capturing fetch reads a body to completion, and a * `subscriptions/listen` body legitimately never ends. */ recordStreamMessages(messages: readonly unknown[], options: { origin: string; requestMethod?: string; requestId?: ObservedRequestId; }): void; get observations(): readonly ObservedWireMessage[]; get size(): number; } declare class MCPConformanceTest { private readonly config; constructor(config: MCPConformanceConfig); run(): Promise; } declare class MCPConformanceSuite { private readonly config; constructor(config: MCPConformanceSuiteConfig); run(): Promise; } /** * Wire-schema validation: does what the server actually sent match the spec's * own JSON Schema for the revision it is speaking? * * THIS IS THE GAP THE SWEEP FOUND. Our conformance pool asserted individual * fields it had thought to name — and abstained on seven of nine production * connectors — while the official suite's `wire-schema-valid` found 74 real * violations on six of nine: `tools/list` results missing the REQUIRED * `cacheScope` / `resultType` / `ttlMs`, and response envelopes carrying * `"id": null` where `RequestId` is `["string", "integer"]`. A hand-written * field check can only catch what its author remembered; the schema is the * complete statement. * * CORRELATION IS WHAT MAKES IT NON-VACUOUS. `ServerResult` includes a branch * for the base `Result`, which requires only `resultType` and allows every * other property. Validating a `tools/list` response against the generic * `JSONRPCMessage` union therefore accepts a result missing `ttlMs` and * `cacheScope` — the exact defect the sweep found. Selecting `ListToolsResult` * because the observation says it answers `tools/list` is the whole value; the * generic union is only the fallback for a message we could not attribute. * * THE METHOD → RESULT MAP IS DERIVED, NOT TYPED OUT. Each schema names its * request definitions with a `method` const (`ListToolsRequest` ⇒ * `"tools/list"`), and the matching result is the same name with * `Request` ⇒ `Result`. Deriving it means a revision that renames a method * cannot leave a stale hand-written table behind — the map moves when the * vendored schema moves. * * EXTENSION-AWARE. When the tasks extension is in play, `tools/call` may * legitimately answer with a `CreateTaskResult`, which the CORE schema's * `CallToolResult` (it requires `content`) rejects. The target then becomes * `anyOf: [core CallToolResult, ext-tasks CreateTaskResult]` — composed across * two registered documents rather than by inlining, because each document's * internal `$ref`s are relative to its own root. * * NODE-ONLY. Ajv compiles with `new Function`, which is CSP-hostile in a * browser and broken outright on workerd — the same reason * `dialect-aware-json-schema-validator.ts` keeps its engines out of the * browser entry. This module is reachable only from the conformance runner, * which is already Node-only. */ /** * The tasks extension id, re-exported rather than re-spelled: a second literal * that must match the dispatch layer's is a literal that will eventually not. */ declare const TASKS_EXTENSION_ID: "io.modelcontextprotocol/tasks"; /** What a message was validated against, and whether it held. */ interface WireSchemaViolation { /** `POST tools/list`, `subscriptions/listen frame`, … */ origin: string; /** The schema definition the message was graded against. */ definition: string; /** The message's own JSON-RPC id, when it carried one. */ id?: string | number | null; /** One line per failing keyword, in Ajv's vocabulary. */ errors: string[]; } interface WireSchemaValidationReport { /** Revision whose schema was used. */ protocolVersion: McpProtocolVersion; /** Extension ids composed into the targets. */ extensionIds: string[]; /** Extension id → the schema revision validated against. */ extensionRevisions: Record; /** SHA-256 over the exact documents used, for the profile stamp. */ schemaDigest: string; /** How many observed messages were graded. */ validated: number; /** How many were graded against a METHOD-SPECIFIC definition. */ correlated: number; violations: WireSchemaViolation[]; } /** * A validator bound to one revision and one set of negotiated extensions. * Compiled targets are memoized: a run observes many messages per method, and * Ajv compilation is the expensive half. */ declare class WireSchemaValidator { private readonly engine; private readonly defsKey; private readonly resultDefinitions; private readonly errorResponseDefinition?; private readonly compiled; private readonly extensionResultOverrides; readonly protocolVersion: McpProtocolVersion; readonly extensionIds: string[]; readonly schemaDigest: string; constructor(options: { protocolVersion: McpProtocolVersion; /** Extension ids the run negotiated. Unknown ids are ignored, not an error. */ extensionIds?: readonly string[]; }); private compileRef; /** * The schema target for one observation: the method-specific result when the * message answers a request we can attribute, the generic message union * otherwise. */ private targetFor; /** * The envelope MEMBERS of a response whose result is being graded against a * method-specific definition. Without this, correlation traded envelope * coverage for payload coverage instead of adding to it. * * Deliberately NOT the whole frame against `JSONRPCMessage`: that union's * response branch re-validates `result`, so a bad payload also came back as * "must match a schema in anyOf" plus a duplicate of every payload error — * noise that buries the envelope fact the reader needs. This grades exactly * the two members the payload schema does not cover, and takes `id`'s shape * from the document's own `RequestId` rather than restating it. */ private validateEnvelope; private compileEnvelope; validate(observations: readonly ObservedWireMessage[]): WireSchemaValidationReport; } /** * VENDORED SPEC SCHEMAS — the JSON Schema documents the wire-schema check * validates against. * * PIN: modelcontextprotocol/modelcontextprotocol @ * 4e67bdc2f3403a8602f72025b28ac27fe7fd4e44 (`schema//schema.json`) * PIN: modelcontextprotocol/ext-tasks @ * e4345978be1f602f1fc48d89051e8559dd5302a6 (`schema/draft/schema.json`) * * Re-diff against those commits when re-syncing. The files are VERBATIM copies, * descriptions and all, precisely so that re-syncing is a plain `diff` against * upstream rather than a re-derivation. Pruning them would save bytes and cost * the one property that makes a vendored artifact maintainable. * * WHY VENDOR AT ALL. The schemas are the only machine-readable statement of * what a conforming message looks like, and no npm package ships them (the * client package ships TypeScript types, which are not a validator and which * the client itself relaxes at the decode seam). Fetching them at run time * would make a conformance verdict depend on a network round trip to a third * party — a run must be reproducible offline and must not change its answer * because someone merged a schema PR mid-sweep. * * DIALECTS ARE NOT UNIFORM: 2025-03-26 and 2025-06-18 are draft-07 * (`definitions`), 2025-11-25 and 2026-07-28 are 2020-12 (`$defs`). That is why * the validator needs both Ajv engines and why the defs pointer is read off * each document rather than assumed. */ /** * A vendored schema document, widened at the import boundary. * * DELIBERATELY `unknown`-valued: `resolveJsonModule` would otherwise infer the * whole 180KB literal as the export's type and inline it into the emitted * `.d.ts`. Nothing downstream reads these structurally except the validator, * which walks them dynamically anyway. */ interface WireSchemaDocument { $schema?: string; definitions?: Record; $defs?: Record; [key: string]: unknown; } /** Core spec schema per protocol revision. Total over `McpProtocolVersion`. */ declare const CORE_WIRE_SCHEMAS: Record; /** * Extension schemas, keyed by the extension id a server declares. * * Only `io.modelcontextprotocol/tasks` today. Apps is deliberately absent * rather than stubbed: composing a schema for an extension whose results we do * not yet correlate would add a code path with no assertion behind it. */ declare const EXTENSION_WIRE_SCHEMAS: Record; /** * The revision directory each extension schema was vendored from, so a profile * stamp names what was actually validated against rather than a guess. The * tasks extension has published only `schema/draft/` to date; when it cuts a * dated revision this becomes that date, and the stamp moves with it. */ declare const EXTENSION_SCHEMA_REVISIONS: Record; interface ClientCredentialsInput { tokenEndpoint: string; clientId: string; clientSecret: string; tokenEndpointAuthMethod?: string; scope?: string; resource?: string; request: TrackedRequestFn; } declare function performClientCredentialsGrant({ tokenEndpoint, clientId, clientSecret, tokenEndpointAuthMethod, scope, resource, request, }: ClientCredentialsInput): Promise; interface HeadlessAuthorizationInput { authorizationUrl: string; redirectUrl: string; expectedState?: string; request: TrackedRequestFn; } declare function completeHeadlessAuthorization({ authorizationUrl, redirectUrl, expectedState, request, }: HeadlessAuthorizationInput): Promise; interface InteractiveAuthorizationSession { redirectUrl: string; authorize(input: { authorizationUrl: string; expectedState?: string; timeoutMs: number; openUrl?: (url: string) => Promise; }): Promise; stop(): Promise; } declare function openUrlInBrowser(url: string): Promise; declare function createInteractiveAuthorizationSession(options?: { redirectUrl?: string; }): Promise; interface OAuthConformanceRunnerDependencies { createInteractiveAuthorizationSession?: typeof createInteractiveAuthorizationSession; completeHeadlessAuthorization?: typeof completeHeadlessAuthorization; performClientCredentialsGrant?: typeof performClientCredentialsGrant; createDefaultRedirectUrl?: () => string; } declare class OAuthConformanceTest { private readonly config; private readonly deps; constructor(config: OAuthConformanceConfig, deps?: OAuthConformanceRunnerDependencies); run(): Promise; } /** * Runs a matrix of OAuth conformance flows against a single MCP server. * * Each flow inherits shared `defaults` from the suite config and can * override any field. Flows run sequentially to avoid overwhelming * authorization servers with concurrent registrations. */ declare class OAuthConformanceSuite { private readonly config; constructor(config: OAuthConformanceSuiteConfig); run(): Promise; } declare function formatOAuthConformanceHuman(result: ConformanceResult): string; declare function formatOAuthConformanceSuiteHuman(result: OAuthConformanceSuiteResult): string; /** * Input produced by the OAuth conformance runner when it reaches the * authorization step and is waiting for a code. */ interface RemoteBrowserAuthorizationInput { authorizationUrl: string; expectedState?: string; } interface RemoteBrowserAuthorizationCode { code: string; state?: string; } /** * Controller for driving an interactive OAuth conformance run from a host that * cannot use a local loopback redirect — for example, the MCP Inspector server * (local or hosted mode), where the browser redirect comes back to a public * `/oauth/callback` route rather than a `127.0.0.1:NNNN/callback` loopback. * * Pass {@link RemoteBrowserAuthorizationController.createSession} as the * `createInteractiveAuthorizationSession` dependency of `OAuthConformanceTest`. * Then `await` {@link RemoteBrowserAuthorizationController.awaitAuthorizationUrl} * to learn the URL to show the user, and call * {@link RemoteBrowserAuthorizationController.deliverCode} from your callback * handler once the user completes authorization. */ interface RemoteBrowserAuthorizationController { /** * Resolves when the OAuth runner has produced an authorization URL and is * waiting for a code. Rejects if the runner fails before reaching that step. */ readonly awaitAuthorizationUrl: Promise; /** * Deliver an authorization code from your user-facing callback. If * `expectedState` was captured and `state` here does not match, the pending * `authorize` call is rejected with a state-mismatch error. */ deliverCode(result: RemoteBrowserAuthorizationCode): void; /** * Abort the flow with an error. Any pending `authorize` call — and the * `awaitAuthorizationUrl` promise if it has not yet resolved — are rejected. */ fail(error: Error): void; /** * Pass this as the `createInteractiveAuthorizationSession` dep of * `OAuthConformanceTest`. The returned session shares state with the * controller: its `authorize` call resolves when `deliverCode` is invoked. */ createSession(options?: { redirectUrl?: string; }): Promise; } interface RemoteBrowserAuthorizationControllerOptions { /** * Public URL of the OAuth callback your host exposes, e.g. * `https://app.example.com/oauth/callback/debug`. This is sent to the * authorization server as the `redirect_uri` parameter. */ redirectUrl: string; /** * Optional hard timeout in milliseconds to wait for a code after the auth * URL is surfaced. When omitted, the timeout passed by the runner * (`stepTimeout`) is used. */ codeTimeoutMs?: number; } declare function createRemoteBrowserAuthorizationController(options: RemoteBrowserAuthorizationControllerOptions): RemoteBrowserAuthorizationController; /** * Zod schema for the "OAuth conformance profile" input shape that hosts pass * from their UI/API layer into the runner. Mirrors the tunable subset of * {@link OAuthConformanceConfig} so callers don't have to reinvent it for * each route. * * All fields are optional — hosts can layer this on top of a resolved * `serverUrl` and fill in only what the user overrode. */ declare const oauthConformanceProfileSchema: z.ZodObject<{ serverUrl: z.ZodOptional; protocolVersion: z.ZodOptional>; registrationStrategy: z.ZodOptional>; clientId: z.ZodOptional; clientSecret: z.ZodOptional; scopes: z.ZodOptional; customHeaders: z.ZodOptional>>; }, z.core.$strip>; type OAuthConformanceProfile = z.infer; /** * Flatten the `customHeaders: [{ key, value }]` array form that UIs use into * the `Record` form the runner expects. Empty keys are * dropped so partially-filled UI rows don't create `""` headers. */ declare function normalizeCustomHeaders(input: OAuthConformanceProfile["customHeaders"] | undefined): Record | undefined; declare class MCPAppsConformanceTest { private readonly config; constructor(config: MCPAppsConformanceConfig); run(): Promise; } declare class MCPAppsConformanceSuite { private readonly config; private readonly target; constructor(config: MCPAppsConformanceSuiteConfig); run(): Promise; } /** * MCP Tasks conformance runner. * * Mirrors `apps-conformance/` in shape, but the subject is the *wire*: which * tasks wire the connection resolves to, whether the client-side declaration * hygiene holds for that wire, and whether the server honours the parts of the * contract a debugger can observe from the outside (result-type discipline, * `-32021` on an undeclared capability, inline results, TTL shapes, and * `Mcp-Name` routing for HTTP transports). * * Every check is derived from a single connection and, where a task is needed, * a single provoked task, so running the suite costs one server session. */ type MCPListedTool = NonNullable[number]; /** * The run's verdict, plus the reason when it is `incomplete`. * * `passed` requires that every SELECTED check actually produced a verdict — * either it ran, or it was inapplicable to this server. A check that could not * run is neither a violation nor a pass, and collapsing it into "not failed" * is what let a two-of-eight run report success. */ declare function decideOutcome(checks: MCPTasksCheckResult[]): { outcome: MCPTasksRunOutcome; incompleteReason?: string; }; /** * The outcome of choosing a tool to provoke a task with. * * The FAILURE half is the point. `pickProbeTool` alone cannot say why it came * back empty, and the caller treated "no tool" as a skip — so on the extension * wire, where `execution.taskSupport` is stripped by the 2026 `ToolSchema` and * auto-selection can therefore NEVER succeed, six task-dependent checks skipped * and the run still reported `passed: true`. A resolution carries both a * user-actionable reason and whether that reason leaves work untested * (`blocking`) or is simply inapplicable (no tasks wire at all). */ interface ProbeToolResolution { tool?: MCPListedTool; /** Why no tool resolved, in terms the caller can act on. */ reason?: string; /** True when the missing tool leaves applicable checks unexercised. */ blocking?: boolean; } /** * Resolves the probe tool, or explains — actionably — why it could not. * * An explicit `requestedName` that the server does not list is a resolution * FAILURE, not a silent miss: a typo would otherwise skip every task-dependent * check while the run still read as conformant. */ declare function resolveProbeTool(wire: TasksWire, tools: MCPListedTool[], requestedName?: string): ProbeToolResolution; declare class MCPTasksConformanceTest { private readonly config; constructor(config: MCPTasksConformanceConfig); run(): Promise; /** * Task id out of a creation result. Shape-based (`taskId`), but it reads a * result the manager has ALREADY discriminated on `resultType === "task"`, * so it identifies the task rather than detecting one. */ private extractTaskId; /** * Runs a `tools/call` WITHOUT the extension declaration (`allowTaskResult` * omitted, so the manager sends no capability envelope) and reports what the * server did. * * The outcome is deliberately four-valued rather than a boolean. A boolean * `taskCreated: false` collapses "the server honoured tasks.md:61" with "the * probe blew up before it proved anything", and the check counted BOTH as a * pass. Only an actual server response can pass here: * * - `created` — a `CreateTaskResult` came back: the violation. * - `answered` — a normal tool result: conformant. * - `refused` — a JSON-RPC error response: also conformant (no task was * handed to a non-declaring client), with `-32021` being the refusal the * spec names and any other code carried through as a warning. * - `errored` — no JSON-RPC response exists at all. Same v2 discriminator * as {@link runUndeclaredProbe}: `ProtocolError` carries a NUMERIC code * and is minted only from a server error response, while local and * transport faults are `SdkError`s with STRING codes. This is a check * FAILURE, because nothing about the server was observed. * * THREE places have to be read, and the wire is the last word. Beyond the * decoded result and the manager's `_meta` stash, the RAW response decides: * a task payload with no `resultType: "task"` is invisible to both of the * others (see {@link findRawTaskResponse}), so a server that violates * tasks.md:61 AND tasks.md:102 at once would otherwise score a pass on the * strength of its second violation. */ private probeUndeclaredCreation; /** * Sends every request the extension requires a server to refuse from a * non-declaring client, WITHOUT the declaration, and reports each outcome. * The manager's task APIs always attach the declaration, so these go through * the connection's raw request seam; `undefined` means there is no such seam. * * Probe order is least- to most-invasive against the (already terminal) * task: read, then a no-op update, then the listen subscription, and * `tasks/cancel` last — a server that wrongly accepts one of these must not * change what the next one observes. * * ERA GATE: on a 2026-07-28 connection, upstream refuses to SEND `tasks/get` * and `tasks/cancel` (they are 2025-registry members the modern registry * dropped); `tasks-ext-era-gate.ts` shadows that gate, and installs the shadow * LAZILY on the first extension tasks operation. These probes bypass the * manager's tasks APIs, so they must ask for the shadow themselves rather * than lean on an earlier `getTaskExt` having triggered it — `ensure…` is * idempotent and a no-op for a client the factory never registered. * Belt and braces: if the gate ever did fire, it throws an `SdkError` with a * STRING code, so the probe reports `probe-failed` (an offender), never a pass. */ private probeUndeclaredTaskMethods; /** * Polls until terminal, the deadline, or the first poll error. * * The poll error is RETURNED rather than swallowed: a `tasks/get` that throws * is the difference between "the server never produced a task to inspect" * (a genuine skip) and "the task exists but reading it failed" (which the * dependent checks must name, not silently skip past). */ /** * Drive `input_required → tasks/update → completion`, the one leg of the * task lifecycle a poll-only runner can never reach. * * Returns what happened rather than a verdict, so the check below can tell * "the operator supplied no answers" (a skip) from "the update was rejected" * and from "the update was acknowledged but the task never moved" (both * failures). The ack shape is asserted here because the spec is specific * about it: "On success, the server MUST acknowledge the request with an * empty result." */ private runInputRequiredLeg; /** * Ask for a task the server never issued. * * The id is deliberately fabricated rather than derived from a real one: a * mutated real id could collide with a live task on a busy server, and this * probe must never touch one. * * All three methods are probed, but they are NOT graded alike — the extension * makes `-32602` a MUST for `tasks/get` and only a SHOULD for `tasks/update` * and `tasks/cancel`, so the caller fails on the first and advises on the * others. `tasks/update` carries an EMPTY `inputResponses`, so even a server * that wrongly accepts it cannot advance anything. */ private probeUnknownTaskId; /** * `tasks/cancel` on a real task. * * Asserts ONLY what the extension states: "On success, the server MUST * acknowledge the request with an empty result." It deliberately does NOT * require the task to become `cancelled` — the spec says cancellation is * eventually consistent, that the status "MAY remain working (or some other * non-terminal status) after the ack", and "MAY ultimately reach a terminal * status other than cancelled if the work finished before cancellation could * take effect". A check that demanded `cancelled` would fail servers for * behavior the spec explicitly permits. */ private probeCancelAck; private pollToTerminal; } interface ServerSnapshotTool { name: string; description?: string; inputSchema?: unknown; outputSchema?: unknown; } interface ServerSnapshotResource { uri: string; name?: string; description?: string; mimeType?: string; } interface ServerSnapshotResourceTemplate { uriTemplate: string; name?: string; description?: string; mimeType?: string; } interface ServerSnapshotPrompt { name: string; description?: string; arguments?: unknown; } interface CollectedServerSnapshot { target: TTarget; generatedAt: string; initInfo: unknown | null; capabilities: unknown | null; tools: ServerSnapshotTool[]; toolsMetadata: Record; resources: ServerSnapshotResource[]; resourceTemplates: ServerSnapshotResourceTemplate[]; resourceTemplatesSupported: boolean; prompts: ServerSnapshotPrompt[]; warnings?: string[]; } interface RawServerSnapshot { target: TTarget; exportedAt: string; initInfo: unknown | null; capabilities: unknown | null; tools: ServerSnapshotTool[]; toolsMetadata: Record; resources: ServerSnapshotResource[]; resourceTemplates: ServerSnapshotResourceTemplate[]; prompts: ServerSnapshotPrompt[]; } interface StableServerSnapshot { kind: "server-snapshot"; schemaVersion: 1; target: TTarget; initInfo: unknown | null; capabilities: unknown | null; tools: ServerSnapshotTool[]; toolsMetadata: Record; resources: ServerSnapshotResource[]; resourceTemplates: ServerSnapshotResourceTemplate[]; resourceTemplatesSupported: boolean; prompts: ServerSnapshotPrompt[]; } interface NormalizedServerSnapshot { target: TTarget; initInfo: unknown | null; capabilities: unknown | null; tools: ServerSnapshotTool[]; toolsMetadata: Record; resources: ServerSnapshotResource[]; resourceTemplates: ServerSnapshotResourceTemplate[]; resourceTemplatesSupported: boolean | null; prompts: ServerSnapshotPrompt[]; } interface CollectServerSnapshotInput { config: MCPServerConfig; target: TTarget; timeout: number; rpcLogger?: RpcLogger; retryPolicy?: RetryPolicy; clientName?: string; serverId?: string; } type WithSnapshotManager = (config: MCPServerConfig, fn: (manager: MCPClientManager, serverId: string) => Promise, options?: { timeout?: number; rpcLogger?: RpcLogger; retryPolicy?: RetryPolicy; clientName?: string; serverId?: string; }) => Promise; interface ServerSnapshotDependencies { withManager?: WithSnapshotManager; now?: () => Date; } declare class ServerSnapshotFormatError extends Error { constructor(message: string); } declare function collectServerSnapshot(input: CollectServerSnapshotInput, dependencies?: ServerSnapshotDependencies): Promise>; declare function collectConnectedServerSnapshot(manager: MCPClientManager, serverId: string, target: TTarget, dependencies?: Pick): Promise>; declare function serializeServerSnapshot(snapshot: CollectedServerSnapshot, options?: { mode?: "raw" | "stable"; now?: () => Date; }): RawServerSnapshot | StableServerSnapshot; declare function serializeStableServerSnapshot(snapshot: CollectedServerSnapshot): StableServerSnapshot; declare function normalizeServerSnapshot(snapshot: unknown): NormalizedServerSnapshot; type StructuredCaseClassification = "breaking" | "non_breaking" | "informational"; interface StructuredCaseResult { id: string; title: string; category: string; passed: boolean; classification?: StructuredCaseClassification; durationMs?: number; error?: string; details?: unknown; /** * An authorized override of THIS case's verdict, on the record. * * Set only on a gate case whose failure was waived. It is the single home * for the waiver payload in a structured report — every renderer reads it * from here rather than each carrying its own copy, so the three facts the * charter requires cannot drift between the JSON, the JUnit and the HTML. * * A case carrying this is `passed: true` (the gate did not block the build) * but is never rendered as a plain pass: JUnit marks it ``, HTML * gives it its own section, and the report's `verdict` says `waived`. */ waiver?: StructuredCaseWaiver; } /** * The waiver facts a CI artifact must carry: WHO waived, WHY, and UNTIL WHEN. * * `createdByEmail` is carried alongside the opaque `createdBy` id because a * JUnit file read six months from now cannot resolve a user id, and it is * `null` rather than absent when it could not be resolved — a deleted user * must not make a waiver look authorless. */ interface StructuredCaseWaiver { id: string; reason: string; expiresAt: number; createdAt: number; createdBy: string; createdByEmail: string | null; policySnapshot?: { minimumPassRate: number; } | null; } interface StructuredSummaryBucket { total: number; passed: number; failed: number; } interface StructuredRunSummary { total: number; passed: number; failed: number; byCategory: Record; byClassification?: Record; } interface StructuredRunReport { schemaVersion: 1; kind: string; passed: boolean; /** * The backend's verdict, carried through rather than recomputed. Absent on a * report built from anything but eval runs. * * `passed` alone cannot express `inconclusive`: a run the platform could not * measure is not a pass, but calling it a failure reports a defect nothing * observed. So `passed` stays false and this says WHY, and no synthetic * failing case is fabricated for it — which is also why an inconclusive run * leaves `summary.failed` untouched. */ verdict?: StructuredRunVerdict; summary: StructuredRunSummary; cases: StructuredCaseResult[]; durationMs: number; metadata: Record; /** * The canonical run decision contract, VERBATIM. * * Carries its own `schemaVersion`, so a consumer identifies the shape from * the object rather than from this report's version. It replaced an * unversioned per-case summary whose verdict was computed by counting * iterations — see the release note; a reader of the old shape looked for * `passRate.percent` and `cases[]`, and now reads `counts` (with its * `measurementUnit`) and `diagnostics.items[]`. */ decisionSummary?: EvalRunDecisionSummary; } type StructuredRunVerdict = "passed" | "failed" | "inconclusive" | "notEstablished" | /** * A measured failure an authorized human overrode. Its own value rather * than `passed`, because the two are not the same claim and only one of * them is a clean run — see `gateOutcomeVerdict` in `gates.ts`. */ "waived"; interface StructuredEvalRunInput { run: PlatformEvalRun; iterations: readonly PlatformEvalIteration[]; iterationsComplete: boolean; iterationError?: string; } declare function buildEvalRunReport(inputs: readonly StructuredEvalRunInput[], options?: { cases?: StructuredCaseResult[]; metadata?: Record; decisionSummary?: EvalRunDecisionSummary; /** * Overrides the verdict this would otherwise compute from `inputs`. * * For a gate/compare report, `inputs` describes the underlying eval * run — not the gate's own outcome, which is a separate policy decision * layered on top (a run can pass while its gate is non-gateable). Pass * the gate's verdict (e.g. via `gateOutcomeVerdict`) explicitly rather * than letting this fall back to a verdict about the wrong thing, or to * no verdict at all — which a renderer with no verdict falls back to * reading off `passed`, painting an unmeasured gate as a measured * failure. */ verdict?: StructuredRunVerdict; }): StructuredRunReport; declare function summarizeStructuredCases(cases: StructuredCaseResult[]): StructuredRunSummary; declare function renderStructuredRunJson(report: StructuredRunReport): StructuredRunReport; declare function renderStructuredRunJUnitXml(report: StructuredRunReport): string; /** * Minimal HTML report: decision summary + failures, self-contained (inline * `"; declare function buildRuntimeConfigScript(config: Record): string; declare function injectScripts(html: string, headContent: string): string; type CspMode = "permissive" | "widget-declared"; interface WidgetCspMeta { connect_domains?: string[]; resource_domains?: string[]; frame_domains?: string[]; } interface CspConfig { mode: CspMode; connectDomains: string[]; resourceDomains: string[]; frameDomains: string[]; headerString: string; } declare function normalizeWidgetCspMeta(resourceMeta?: Record | null): WidgetCspMeta | undefined; declare function buildCspHeader(mode: CspMode, widgetCsp?: WidgetCspMeta | null, options?: { frameAncestors?: string; }): CspConfig; declare function buildCspMetaContent(headerString: string): string; declare function buildChatGptRuntimeHead(options: { htmlContent: string; runtimeConfig: Record; baseHref?: string; includeUrlPolyfill?: boolean; }): string; /** * Bounded execution of a set of scorers against one iteration. * * Two bounds, both enforced by the RUNNER rather than trusted to the scorer: * * - **A hard timeout per scorer.** `AbortSignal` is cooperative, and a custom * scorer that ignores it would otherwise hold an iteration open forever. The * `Promise.race` is the enforcement; the signal is the courtesy that lets a * well-behaved scorer cancel its HTTP request too. * - **A concurrency cap.** N judges × 30 iterations would otherwise stampede a * provider into rate-limiting the whole run. * * Every failure mode lands as an `error` result, never as a low score, and the * gate engine decides what that means by reading the definition's `onError`. */ /** * Grade an iteration with every scorer, in authored order, under the runner's * bounds. Results come back in authored order regardless of completion order, * so a dashboard renders the same list every time. */ declare function runScorers(scorers: Scorer[], context: ScorerContextV1, options?: ScorerRunOptions): Promise; /** * Whether a set of scores clears the gate. * * The one place `passed` is decided for an iteration, and it reads policy off * the DEFINITIONS rather than the rows — results deliberately do not repeat * `role`/`onError`/`onSkipped`, so there is no second copy to disagree with. * * - advisory scores never gate, whatever their status; * - `not_applicable` never gates (and never enters a denominator); * - a gating `scored` row must have passed; * - a gating `error` / `skipped` row fails unless its policy says ignore. * * The join is on `definitionHash`, not `scorerId`. Matching by id would let a * row produced under one configuration be graded against another — which is * precisely the substitution an integrity check exists to catch. A result with * no matching definition is treated as GATING and failing: an unjoinable row is * evidence something is wrong with the run, and the whole point of this * contract is that missing evidence never reads as a pass. */ declare function scoresPassed(scores: ScoreResult[], definitions: ResolvedScoreDefinition[]): boolean; /** * The deterministic predicate scorer. * * Wraps one authored {@link Predicate} so it reports through the same contract * as everything else. It is a projection, not a re-implementation: the verdict * still comes from `evaluatePredicates`, so a predicate scored through this * path and a predicate evaluated the old way cannot disagree. */ type PredicateScorerOptions = { /** * Stable id. Omit and a positional `predicate:#` id is minted * — fine for local reporting, but UNSTABLE across config edits, so anything * gated in CI should name itself. */ id?: string; /** * Position in the authored list; feeds the generated id. * * Omit it and the id is derived from the predicate's CONTENT instead of its * position, so two anonymous scorers of the same type cannot both mint * `predicate:#0` and collide in the snapshot. Either way the id is * `idSource: "generated"` and therefore not gateable. */ ordinal?: number; /** Predicates gate by default — determinism is what a release gate needs. */ role?: ScorerRole; }; declare function predicateScorer(predicate: Predicate, options?: PredicateScorerOptions): Scorer; /** * The LLM judge scorer. * * Advisory by default — the hosted stance ("never mutates the run's `passed`") * applies here too, because a stochastic grader is an insight layer, not a * release gate. An author who wants one to gate must say so, and then the * fail-closed policies apply: a judge outage fails the iteration rather than * silently vanishing from the verdict. * * Not browser-safe (it reaches the model factory), which is why it lives in the * main entry rather than in `@mcpjam/sdk/contract`. */ /** * Version of the prompt TEMPLATE this file renders. Distinct from the author's * rubric or instruction, which is hashed separately: changing how we frame the * task changes what the judge does even when the author changed nothing, and * both must reach the evaluation config hash. */ declare const JUDGE_TEMPLATE_VERSION = "2"; /** The hosted default (`judgeConfig.ts`), kept identical so verdicts agree. */ declare const DEFAULT_JUDGE_THRESHOLD = 0.7; type JudgeScorerOptions = { /** * REQUIRED. Judges are always explicit-id: they are the scorers most likely * to be gated and tracked across runs, and a positional id would silently * detach that history the first time a scorer is inserted above them. */ id: string; /** `provider/model`, e.g. `"anthropic/claude-sonnet-4-6"`. */ model: string; apiKey: string; baseUrls?: CreateModelOptions["baseUrls"]; customProviders?: CreateModelOptions["customProviders"]; /** Criteria to grade against. Mutually exclusive with {@link prompt}. */ rubric?: string[]; /** A full custom instruction. Mutually exclusive with {@link rubric}. */ prompt?: string; /** Defaults to {@link DEFAULT_JUDGE_THRESHOLD}. */ threshold?: number; /** Judges are advisory unless the author says otherwise. */ role?: ScorerRole; onError?: ScorerErrorPolicy; onSkipped?: ScorerErrorPolicy; /** Its OWN bound, not the iteration timeout. Default 60s. */ timeoutMs?: number; label?: string; scorerVersion?: string; }; declare function judgeScorer(options: JudgeScorerOptions): Scorer; /** * Comparative gates: "is the compare run worse than the baseline?" * * Separate from `evaluateGates` because the question is different. A single-run * gate asks whether a run cleared an absolute bar; this asks whether two runs * measured the SAME THING and, if so, whether the second one got worse. The * first half of that is most of the work. * * --- The population rule --- * * Whole-run statistics compare populations, not runs. If the compare run added * a case, dropped one, re-graded one, changed a scenario's prompt, or simply * ran a case a different number of times, then its pass rate is measured over * a different population than the baseline's and the difference between them * is not a regression signal — it is an artefact of the change. * * So `passRateRegression` and `maximumP95LatencyIncreaseMs` are NON-GATEABLE * (⇒ incomplete ⇒ exit 3) unless ALL of these hold: * * - no `new_case` / `removed_case` rows (`caseSetChanged`) * - no case's own scenario config changed (`scenarioConfigChanged`) * - the run-level evaluation config matches (`evaluationConfigChanged`) * - every shared case ran the same number of * iterations on both sides (`iterationWeightingEqual`) * * The last one is the quietest and the most dangerous: unequal weighting * silently reweights the whole-run totals, so a run that "improved" may only * have run its easy cases more often. * * DETERMINISTIC per-case regressions are exempt. They join per caseKey, so * they are still meaningful when the population changed around them: a case * that used to pass its gating tool-match and now does not, under the same * definition, regressed regardless of what happened to its neighbours. * * --- Integrity --- * * Both sides must have verified score evidence. `undefined` counts as invalid, * the same tri-state rule `evaluateGates` applies. */ /** One deterministic gating scorer that flipped `passed: true` -> `false`. */ type DeterministicScoreRegression = { caseKey: string; scorerId: string; }; type CompareGateInput = { base: GateInput; compare: GateInput; /** * Already filtered by the caller to rows that are gating, deterministic, and * graded under an UNCHANGED definition. A definition that changed did not * measure the same thing twice, so its flip is not a regression. */ deterministicScoreRegressions: DeterministicScoreRegression[]; /** Whether per-case score deltas were available at all. */ scoreDeltasAvailable: boolean; /** Any `new_case` or `removed_case` row. */ caseSetChanged: boolean; /** Any `cases[].configChanged` row — a scenario's own prompt/steps moved. */ scenarioConfigChanged: boolean; /** Run-level `evaluationConfigHash` mismatch. */ evaluationConfigChanged: boolean; /** For every shared caseKey, base and compare ran the same iteration count. */ iterationWeightingEqual: boolean; }; /** * Evaluate the comparative half of a gate policy. * * Outcome folding is IDENTICAL to `evaluateGates`: a broken policy outranks a * failure, which outranks an undecidable gate. A run that both regressed and * had one undecidable gate DID regress, and reporting "incomplete" would bury * that. */ declare function evaluateCompareGates(input: CompareGateInput, policy: GatePolicy): GateReport; export { type AdaptAppsResultToClaudeOptions, type AdaptAppsResultToOpenAIOptions, type AdaptableAppsConformanceResult$1 as AdaptableAppsConformanceResult, AiSdkTool, type BuildCorpusInput, type BuildXaaJwtBearerRequestArgs, CLAUDE_APPS_EVIDENCE_KIND, CLAUDE_APPS_RESULT_INPUT, CLAUDE_AUTHORIZATION_REQUESTS_INPUT, CLAUDE_GATED_INPUTS, CLAUDE_READINESS_INPUTS, CLAUDE_SUBMISSION_PROFILE_INPUT, CLAUDE_TOOL_LISTING_INPUT, COMPARATIVE_GATE_FIELDS, CORE_WIRE_SCHEMAS, CORPUS_LOCK_VERSION, CacheEventLogger, type ClaudeAppResourceEvidence, type ClaudeAppToolEvidence, type ClaudeAppsEvidence, type ClaudeAuthCheckOutput, type ClaudeAuthEvidence, ClaudeCapabilityBadge, type ClaudeCheckDefinition, type ClaudeCheckStamp, type ClaudeDiscoveryOptions, type ClaudeEndpointEvidence, type ClaudeGrantOrigin, type ClaudeIntrusiveConfig, type ClaudeIntrusiveMode, type ClaudeIntrusiveObservations, ClaudeObservationState, type ClaudeOptionalFeatureEvidence, type ClaudeOptionalFeatureOutput, ClaudePolicySourceRef, type ClaudePrmDiscoveryStep, ClaudeReadinessAuthMode, ClaudeReadinessFinding, type ClaudeReadinessInput, ClaudeReadinessLane, ClaudeReadinessResult, type ClaudeRedirectHop, ClaudeRunnerCapability, type ClaudeSubmissionEvidence, ClaudeSubmissionProfile, type ClaudeToolListingCompleteness, type CollectAndDiffServerSnapshotInput, type CollectServerSnapshotInput, type CollectedServerSnapshot, type CompareGateInput, type ConfidenceInterval, type ConfidentialCimdProvider, type ConformanceCiMetadata, ConformanceReport, ConformanceResult, type ConformanceRunProgress, ConformanceRunReportV1, type ConformanceRunReporter, type ConformanceRunSource, ConformanceSuiteKind, type ConformanceTargetInput, type CorpusCase, type CorpusDrift, type CorpusLock, type CorpusSkip, type CreateEvalRunReporterInput, CreateModelOptions, type CspConfig, type CspMode, CspSafeDialectAwareJsonSchemaValidator, CustomProvider, DEFAULT_JUDGE_THRESHOLD, DEFAULT_MIN_EFFECT_SIZE, DEFAULT_MIN_SAMPLE_SIZE, DEFAULT_SCORER_CONCURRENCY, DEFAULT_SCORER_TIMEOUT_MS, DIRECTORY_ARCHIVE_OBSERVATIONS, DIRECTORY_DIAL_CLIENT_INFO, DIRECTORY_DIAL_DEFAULTS, DIRECTORY_DIAL_PROTOCOL_VERSION, DerivedOAuthEmulation, type DeterministicScoreRegression, DialectAwareJsonSchemaValidator, type DiffServerSnapshotsOptions, type DifferenceInterval, type DirectoryAppResourceEvidence, type DirectoryDialEvidence, type DirectoryDialOptions, type DirectoryDialRequest, type DirectoryInitializeEvidence, type DirectoryListingEvidence, type DirectoryResourceEvidence, type DirectoryToolEvidence, EXTENSION_SCHEMA_REVISIONS, EXTENSION_WIRE_SCHEMAS, ElicitationContentValidator, EmulatedAuthAttempt, type EmulatedAuthAttemptResult, type EmulatedOAuthPreflightConfig, type EmulatedOAuthPreflightOutcome, type EmulatedOAuthPreflightResult, EmulatedRegistrationPreference, type EvalArtifactFormat, EvalCiMetadata, EvalExpectedToolCall, EvalMatchOptions, EvalResultInput, EvalRunDecisionSummary, type EvalRunReporter, type EvalRunResult, EvalSuite, type EvalSuiteConfig, type EvalSuiteResult, EvalTest, type EvalTestConfig, type EvalTestFromCaseOptions, type EvalTestRunOptions, EvalToolCallMatchResult, EvalValidityCoverage, EvaluationConfigSnapshot, EvidenceReuse, EvidenceReuseExpectation, type FlakyCase, GATE_WAIVER_MAX_DURATION_MS, GATE_WAIVER_MAX_REASON_LENGTH, GATE_WAIVER_REASON_NOTICE, GateError, type GateInput, type GatePolicy, type GateReport, type GateScore, type GateStatus, type GateVerdict, type GateWaiver, type GatherClaudeReadinessEvidenceOptions, type GatherOpenAIReadinessEvidenceOptions, GetTaskExtResult, HostExecutor, HostJson, HostRunner, type HostRunnerConfig, HostSource, HostedOnlyCaseError, type IdJagSubjectId, IdentityAssertionFormat, type InProcessXaaExecutorOptions, type InsufficientScopeChallenge, type InteractiveAuthorizationSession, InvalidSkillsPayloadError, InvalidTaskExtPayloadError, type IssueAccessTokenParams, type IssueAuthorizationCodeParams, type IssueIdJagParams, type IssueMockIdTokenParams, type IssueMockSamlAssertionParams, type IssuedMockSamlAssertion, type IterationResult, JUDGE_TEMPLATE_VERSION, type JudgeScorerOptions, LatencyBreakdown, type LatencyStats, ListToolsResult, type LoadEvalSuiteFileOptions, type LoadedCorpus, MAX_SUITE_FILE_BYTES, MCPAppsConformanceConfig, MCPAppsConformanceResult, MCPAppsConformanceSuite, MCPAppsConformanceSuiteConfig, MCPAppsConformanceSuiteResult, MCPAppsConformanceTest, MCPAuthError, MCPClientManager, MCPConformanceConfig, MCPConformanceResult, MCPConformanceSuite, MCPConformanceSuiteConfig, MCPConformanceSuiteResult, MCPConformanceTest, MCPError, MCPJamReportingConfig, MCPServerConfig, MCPServerReplayConfig, MCPSkillsWireError, MCPTasksCheckResult, MCPTasksConformanceConfig, MCPTasksConformanceResult, MCPTasksConformanceTest, MCPTasksRunOutcome, MCPTasksWireError, McpProtocolVersion, NegativeTestMode, type NormalizedServerSnapshot, OAuthConformanceConfig, type OAuthConformanceProfile, ConformanceResult as OAuthConformanceResult, OAuthConformanceSuite, OAuthConformanceSuiteConfig, OAuthConformanceSuiteResult, OAuthConformanceTest, OAuthEmulationCoverage, OAuthEmulationDivergence, type OAuthLoginConfig, type OAuthLoginDependencies, type OAuthLoginResult, OAuthProtocolMode, OAuthRegistrationMode, VerificationResult as OAuthVerificationResult, OPENAI_APPS_EVIDENCE_KIND, ObservableResponseCache, type ObservableResponseCacheOptions, type ObservedRequestId, type ObservedWireMessage, type OpenAIAppsUiEvidence, OpenAIArchiveObservations, type OpenAIAuthEvidence, type OpenAIAuthorizationServerEvidence, OpenAICapabilityBadge, type OpenAICheckDefinition, type OpenAICheckStamp, type OpenAIDiscoveryOptions, type OpenAIDomainVerificationEvidence, type OpenAIDomainVerificationInput, type OpenAIEndpointEvidence, type OpenAIMetadataSnapshot, OpenAIObservationState, type OpenAIOptionalFeatureEvidence, type OpenAIOptionalFeatureOutput, type OpenAIPackageEvidenceInput, OpenAIPluginPackageEvidence, type OpenAIPolicyEvidence, OpenAIPolicySourceRef, OpenAIReadinessAuthMode, type OpenAIReadinessEvidence, OpenAIReadinessFinding, OpenAIReadinessLane, OpenAIReadinessResult, type OpenAIReleaseContractInput, type OpenAIReleaseDelta, type OpenAIReleaseImpact, OpenAIRunnerCapability, type OpenAISkillsCheckInput, type OpenAISubmissionEvidence, OpenAISubmissionMode, OpenAISubmissionProfile, type OpenAIToolEvidence, type OpenAIToolListingCompleteness, type OpenAIToolSnapshot, type OpenAIUiResourceEvidence, type OpenAIUiResourceSnapshot, OutcomeCheckLike, type PredicateScorerOptions, PromptOptions, PromptResult, type PromptsToEvalResultOverrides, type ProportionSample, type PublicCheckOverride, type PublicMatchOptions, type RawServerSnapshot, RegistrationStrategy, type RegressionAssessment, type RegressionVerdict, type RemoteBrowserAuthorizationCode, type RemoteBrowserAuthorizationController, type RemoteBrowserAuthorizationControllerOptions, type RemoteBrowserAuthorizationInput, type ReportConformanceRunOptions, type ReportConformanceRunOutput, ReportEvalResultsInput, ReportEvalResultsOutput, ResolvedAuthorizationPlan, type ResolvedEvalSuiteFile, type ResolvedEvalSuiteFileCase, type ResolvedEvalSuiteFileValidity, ResolvedScoreDefinition, RetryPolicy, RpcLogger, type RunConformanceConfig, type RunToEvalResultsOptions, SAML_NAMEID_FORMAT_PERSISTENT, SKILL_NOT_FOUND_ERROR_CODE, SUITE_FILE_DEFAULT_CAPTURE_LEVEL, SUITE_FILE_DEFAULT_COVERAGE, SUITE_FILE_FINDING_CODES, SUITE_FILE_VALIDITY_DEFAULTS, type SamlAssertionSubject, ScoreDefinition, type ScoreIntegrity, ScoreRawOutcome, ScoreResult, type Scorer, ScorerContextV1, ScorerErrorPolicy, ScorerRole, type ScorerRunOptions, type ServerSnapshotDependencies, type ServerSnapshotDiffResult, ServerSnapshotFormatError, type ServerSnapshotPrompt, type ServerSnapshotResource, type ServerSnapshotResourceTemplate, type ServerSnapshotTool, SkillEntry, SkillsDirectoryReadResult, SkillsExtDirectoryReadMethod, SkillsExtGetMethod, SkillsExtListMethod, SkillsExtListResult, type SnapshotDiffChangeType, type SnapshotDiffClassification, type SnapshotDiffEntityType, type SnapshotDiffFailOn, type SnapshotDiffSummary, type SnapshotEntityChange, type SnapshotEntityClassificationSummary, type SnapshotFieldChange, type SnapshotSurfaceSummary, type StableServerSnapshot, type StructuredCaseClassification, type StructuredCaseResult, type StructuredCaseWaiver, type StructuredEvalRunInput, type StructuredRunReport, type StructuredRunSummary, type StructuredRunVerdict, type StructuredSummaryBucket, SubjectIdentifierFormat, type SuiteFileFailureStage, type SuiteFileFinding, type SuiteFileFindingCode, type SuiteFileLoadFailure, type SuiteFileLoadResult, type SuiteFileLoadSuccess, type SuiteFileLocation, type SuiteRunToEvalResultsOptions, TASKS_EXTENSION_ID, TasksWire, type TestResult, Tool$1 as Tool, ToolCall, type ToolCallEnvelopeValidationDetails, type ToolCallEnvelopeValidationResult, type ToolCallOutcomeEvaluationResult, type ToolCallOutcomePolicy, type ToolCallValidationResult, type UnsafeSamlAssertionSubject, type UploadEvalArtifactInput, VerificationResult, type VerifiedSamlAssertionSubject, type VerifyMockSamlAssertionExpectations, WIDGET_BASE_CSS, type WidgetCspMeta, WireObservationRecorder, type WireSchemaDocument, type WireSchemaValidationReport, WireSchemaValidator, type WireSchemaViolation, type XAAIdpJwk, XAA_ACCESS_TOKEN_TYP, XAA_CLIENT_KID, XAA_CODE_JWT_TYP, XAA_RAS_CLIENT_ID_CLAIM, type XaaAuthenticateParams, XaaCapabilityEvidence, type XaaFlowConfig, type XaaFlowResult, type XaaFlowStep, type XaaIdpLogger, type XaaJsonTokenExchangeParams, type XaaMintHandlerResult, type XaaRedemptionResult, type XaaTokenEndpointAuthMethod, type XaaTokenExchangeSubject, type XaaValidatedTokenExchangeGrant, Z_95, adaptAppsResultToClaudeEvidence, adaptAppsResultToOpenAIUiEvidence, annotatedToolNames, applyGateWaiver, assertCreateTaskExtResult, assertDirectoryReadResult, assertGate, assertGetTaskExtResult, assertSkillEntry, assertSkillsGetResult, assertSkillsListResult, assessPassRateRegression, buildChatGptRuntimeHead, buildCorpus, buildCorpusLock, buildCspHeader, buildCspMetaContent, buildEvalRunReport, buildJwtBearerBody, buildJwtBearerRequest, buildRunCompareReport, buildRuntimeConfigScript, buildServerDiffReport, buildToolCallValidationReport, buildXaaJwtBearerRequest, calculateLatencyStats, calculatePercentile, canonicalResourceIndicator, captureOpenAIMetadataSnapshot, classifyNegotiationFailureClass, claudeAppContentDomain, claudeAppResourceEvidenceFrom, claudeAppToolEvidenceFrom, collectAndDiffServerSnapshot, collectConnectedServerSnapshot, collectServerSnapshot, collectZipArchiveObservations, compareOpenAISnapshots, createConformanceRunReporter, createDerivedConfidentialCimdProviderFactory, createDirectoryPluginFileSource, createEvalRunReporter, createInProcessXaaExecutor, createInteractiveAuthorizationSession, createRemoteBrowserAuthorizationController, createStrictElicitationContentValidator, createZipPluginFileSource, decideOutcome, decodeIdentityAssertionClaimsUnsafe, decodeSamlAssertionSubjectUnsafe, detectConformanceCiMetadata, detectFlakyCases, dialAppResources, dialInitialize, dialMcpServer, dialResourceListing, dialToolListing, diffServerSnapshots, discoverClaudeAuthEvidence, discoverOpenAIAuthEvidence, discoverOpenAIImportedSkills, evalTestFromPlatformCase, evaluateCompareGates, evaluateGates, evaluateToolCallOutcome, extractBaseUrl, extractInsufficientScopeChallenge, fetchOpenAIDomainVerification, finalizeConformanceRun, formatGateReport, formatGateWaiverLine, formatOAuthConformanceHuman, formatOAuthConformanceSuiteHuman, formatSuiteFileFindings, gateInputFromPlatformRun, gateInputFromRunResult, gateInputFromSuiteResult, gateOutcomeVerdict, gatherClaudeReadinessEvidence, gatherOpenAIReadinessEvidence, generateCodeChallenge, generateRandomString, generateUrlPolyfillScript, getLocalConfidentialCimdProvider, getXAAIdpJwks, getXAAIdpPrivateKey, getXAAIdpPublicKeyObject, getXAAIssuerUrl, getXaaClientJwks, githubActionExternalRunId, gradeClaudeIntrusiveObservations, gradeClaudeReadiness, gradeOpenAIReadiness, handleXaaAuthenticate, handleXaaJsonTokenExchange, handleXaaTokenExchangeGrant, heartbeatConformanceRun, informational, initXAAIdpKeyPair, initXaaClientKeyPair, injectOpenAICompat, injectScripts, isAuthError, isConformanceReportingConfigured, isCreateTaskExtResult, isGateWaiverInForce, isInsufficientScopeError, isInvalidSkillsPayloadError, isInvalidTaskExtPayloadError, isMCPAuthError, isMCPSkillsWireError, isMCPTasksWireError, isSkillNotFoundError, isUnauthorized401, issueAccessToken, issueAuthorizationCode, issueIdJag, issueMockIdToken, issueMockSamlAssertion, issueNegativeIdJag, judgeScorer, loadCorpusFromLock, loadEvalSuiteFile, matchAnyToolCall, matchNoToolCalls, matchToolArgument, matchToolArgumentWith, matchToolCallCount, matchToolCallWithArgs, matchToolCallWithPartialArgs, matchToolCalls, matchToolCallsSubset, mintXaaTokenExchangeGrant, newcombeDifferenceInterval, normalizeCustomHeaders, normalizeServerSnapshot, normalizeWidgetCspMeta, notApplicable, notEvaluated, oauthConformanceProfileSchema, openUrlInBrowser, passRateFractionFromPercent, predicateScorer, probeDynamicRegistration, probeRefreshRotation, promptsToEvalResult, renderStructuredRunHtml, renderStructuredRunJUnitXml, renderStructuredRunJson, reportConformanceRun, reportConformanceRunSafely, reportEvalResults, reportEvalResultsSafely, resetXAAIdpKeyPairForTests, resetXaaClientKeyPairForTests, resolveCaseNames, resolveClaudeIntrusiveMode, resolveEffectiveChecks, resolveEvalSuiteFile, resolveProbeTool, resourceIndicatorsFrom, runClaudeAppsChecks, runClaudeAuthChecks, runClaudeEndpointChecks, runClaudeOptionalFeatureChecks, runClaudeSubmissionChecks, runClaudeToolChecks, runConformance, runEmulatedOAuthPreflight, runOAuthLogin, runOpenAIAnnotationChecks, runOpenAIAppsUiChecks, runOpenAIAuthChecks, runOpenAIDomainVerificationChecks, runOpenAIEndpointChecks, runOpenAIMcpSkillChecks, runOpenAIMigrationChecks, runOpenAIOptionalFeatureChecks, runOpenAIPackageChecks, runOpenAIPolicyChecks, runOpenAIReleaseContractChecks, runOpenAISubmissionChecks, runScorers, runXaaFlow, satisfied, scenarioContentHash, scoresPassed, sdkMatchOptionsFromPublic, serializeEvalSuiteFile, serializeForInlineScript, serializeServerSnapshot, serializeStableServerSnapshot, setXaaIdpLogger, splitEndpoint, startConformanceRun, suiteFilePointer, summarizeStructuredCases, traceConnectorRedirects, traceOpenAIEndpoint, unwrapEraNegotiationCause, uploadConformanceSuiteReport, uploadEvalArtifact, validateToolCallEnvelope, validateToolCallResult, validateXaaTokenExchangeGrant, validateXaaTokenExchangeSubject, verifyCorpusLock, verifyMockSamlAssertion, verifyXaaJwt, violated, wilsonInterval, xmldomParseXml };