/** * HTTP Transport -- single remote-oauth multi-user mode. * * Post stdio-pure + http-multi-user split (2026-05-01): the MCP_MODE flavor * (``local-relay`` vs ``remote-oauth``) is gone. HTTP mode is always * delegated OAuth 2.1 redirect flow to Notion at * ``https://api.notion.com/v1/oauth/authorize`` with per-JWT-sub Notion * token storage. Single-user paste-token relay form is no longer supported * here -- use stdio mode with NOTION_TOKEN env for single-user setups. * * Required env: NOTION_OAUTH_CLIENT_ID, NOTION_OAUTH_CLIENT_SECRET. */ import { AsyncLocalStorage } from 'node:async_hooks'; import { type NotionTokenStoreLike } from '../auth/notion-token-store.js'; export declare const subjectContext: AsyncLocalStorage<{ sub: string; }>; /** * Select the per-sub Notion token store. The cf-kv backend -> KV write-through * (durable across container recreate; the Cloudflare deployment store). Any other * backend (stdio / local single-process) -> in-memory store. Read once at * startup; on CF, MCP_STORAGE_BACKEND=cf-kv is set by wrangler vars, so the * durable KV store is always selected there. */ export declare function selectTokenStore(): NotionTokenStoreLike; /** * Derive the JWT subject from the upstream Notion token response. * * Notion's OAuth token payload identifies the authorizing principal by * ``owner.user.id`` (user-level integrations) and ALWAYS carries * ``workspace_id`` + ``bot_id``. There is NO ``owner_user_id`` field. Prefer the * human user id for per-user isolation, then fall back to the workspace, then * the bot, so the JWT ``sub`` (and thus the per-sub Durable Object + KV token * bucket) is a stable real identity rather than the shared ``'default'`` bucket * — collapsing every caller onto ``'default'`` would silently break multi-user * isolation. ``'default'`` is reserved for a malformed response only. */ export declare function deriveSubject(tokens: Record): string; export declare function startHttp(): Promise; //# sourceMappingURL=http.d.ts.map