/** * Interface satisfied by both the in-memory NotionTokenStore (stdio / local * single-process) and the KV write-through KvNotionTokenStore (Cloudflare * deploy), so the HTTP transport can select either without branching on the * concrete type. `save`/`clear` allow an async return because the KV variant * writes through to Workers KV; the in-memory store satisfies it synchronously. */ export interface NotionTokenStoreLike { save(sub: string, accessToken: string): Promise | void; /** * Synchronous read of the in-memory cache only (hot path: the Notion client * factory runs per tool invocation). The durable KV variant returns the * cached value here; a cold cache after container recreate is warmed by * ``getAsync`` (called once per request in the HTTP transport's authScope). */ get(sub: string): string | undefined; /** * Read through to the durable layer, warming the cache on a hit. The * in-memory store has no durable layer so this resolves to the cached value. * The KV store loads + decrypts the per-(plugin, sub) blob from Workers KV, * which is what makes a token survive container delete+recreate. */ getAsync(sub: string): Promise; clear(sub: string): Promise | void; /** * Optional durable-store readiness probe (KV deploy). When present, the HTTP * transport calls it at startup so a broken container -> Worker outbound path * surfaces in deploy logs instead of silently dropping the first token write. */ ready?(): Promise; } /** * In-process per-user Notion access token store, keyed by JWT subject. * * Populated by the delegated OAuth `onTokenReceived` callback and consumed * by the Notion client factory on each MCP tool invocation. Tokens are * ephemeral (process lifetime only); refresh is handled by re-running the * delegated OAuth flow when a call returns 401. */ export declare class NotionTokenStore { private tokens; save(sub: string, accessToken: string): void; get(sub: string): string | undefined; getAsync(sub: string): Promise; clear(sub: string): void; } //# sourceMappingURL=notion-token-store.d.ts.map