import { type AuthAccountPolicies, type AuthCredentialStore, AuthStorage, type AuthStorageOptions } from "../auth-storage.js"; import { type AuthBrokerAccountPool } from "./remote-store.js"; export interface AuthBrokerClientConfig { url: string; token: string; } export interface ResolveAuthBrokerConfigOptions { agentDir?: string; configValueResolver?: (config: string) => Promise; } export interface DiscoverAuthStorageOptions { agentDir?: string; configValueResolver?: (config: string) => Promise; cachePath?: string; sourceLabel?: string; /** Programmatic pool for SDK hosts. Takes precedence over the environment file. */ accountPool?: AuthBrokerAccountPool; accountPolicies?: AuthAccountPolicies; authStorageOptions?: Omit; } /** Path to the local bearer token file. Created by `omp auth-broker token`. */ export declare function getAuthBrokerTokenFilePath(): string; export interface AuthAccountPolicyConfig { accountPolicies: AuthAccountPolicies; defaultReservePct: number; } export interface LoadAuthAccountPolicyConfigOptions { agentDir?: string; accountPolicies?: unknown; usageReservePct?: unknown; } /** Load and strictly validate account-selection policy configuration, with main-config fallback. */ export declare function loadAuthAccountPolicyConfig(options?: LoadAuthAccountPolicyConfigOptions): Promise; export declare function loadAuthBrokerAccountPool(): Promise; /** * Resolve broker connection configuration using the same precedence as the TUI: * * 1. `OMP_AUTH_BROKER_URL` / `OMP_AUTH_BROKER_TOKEN` env vars. * 2. `auth.broker.url` / `auth.broker.token` in `/config.yml` or `/config.yaml`. * 3. `/auth-broker.token` file (paired with a URL from env/config). * * Returns `null` when no broker URL is configured — callers should fall back to * the local SQLite store. Throws when a URL is configured but no token is * available, matching the TUI behavior. */ export declare function resolveAuthBrokerConfig(options?: ResolveAuthBrokerConfigOptions): Promise; export interface OpenAuthCredentialStoreOptions { /** Broker to connect to; `null` opens the local SQLite store under `agentDir`. */ brokerConfig: AuthBrokerClientConfig | null; agentDir?: string; cachePath?: string; sourceLabel?: string; /** Programmatic pool for SDK hosts. Takes precedence over the environment file. */ accountPool?: AuthBrokerAccountPool; } /** Credential store opened by {@link openAuthCredentialStore} plus its diagnostics label. */ export interface OpenedAuthCredentialStore { store: AuthCredentialStore; sourceLabel: string; } /** * Open the credential store {@link discoverAuthStorage} would use for * `brokerConfig`: the remote broker store (fails fast when the broker has no * usable snapshot) or the local SQLite store. Also feeds * {@link AuthStorage.replaceStore} when broker settings change at runtime. */ export declare function openAuthCredentialStore(options: OpenAuthCredentialStoreOptions): Promise; /** * Create an AuthStorage instance, using the broker when configured and falling * back to the local SQLite store otherwise. This is the single source of truth * for the TUI and the catalog generator. */ export declare function discoverAuthStorage(options?: DiscoverAuthStorageOptions): Promise;