import type { Api, Model } from "../types.js"; import type { ClientUsageIdentity } from "../usage.js"; export declare function json(status: number, body: unknown, headers?: Record): Response; /** * Diagnostic response headers for translated inference requests, mirroring the * names existing gateway-aware clients already parse: `x-request-id` / * `request-id` (surfaced as `_request_id` by the OpenAI and Anthropic SDKs, * matches the gateway log line), LiteLLM's model-resolution and cost headers, * and OpenAI's `openai-processing-ms`. Model/request-id headers are always * present; `costUsd` — known only once a non-streaming response has settled — * adds the computed cost, and `startedAt` the wall time. Streaming responses * send headers before usage exists, so they carry only the identity headers. */ export declare function gatewayResponseHeaders(model: Model, info: { requestId: string; costUsd?: number; startedAt?: number; }): Record; /** Use the socket peer unless the gateway explicitly trusts its reverse proxy. */ export declare function resolvePeer(req: Request, socketAddress: string, trustProxyHeaders?: boolean): string; /** Keep configured gateway credentials out of URL and forwarded/logged request fields. */ export declare function hasMisplacedBearer(req: Request, url: URL, tokens: ReadonlySet): boolean; /** * Constant-time byte comparison. Falls back to a manual XOR accumulator if * `node:crypto.timingSafeEqual` isn't available. Always processes every byte * of the longer input so length itself doesn't leak via timing. */ export declare function timingSafeEqual(a: Uint8Array, b: Uint8Array): boolean; export declare function isAuthorized(req: Request, tokens: ReadonlySet): boolean; /** * Extract allow-listed passthrough headers from an inbound request. Keys are * lowercased; empty values are dropped. Called once per request in * `handleFormatEndpoint`; parsers then read `options.headers`. */ export declare function captureRequestHeaders(headers: Headers): Record; /** * Resolve the usage-attribution identity for an inbound gateway request. * * pi-native omp clients send `x-omp-install-id` / `x-omp-hostname` / * `x-omp-app` (see `providers/pi-native-client.ts`); any client may set them. * Requests without an install id fall back to the gateway host's identity * under the `gateway` app label, so unlabeled foreign-SDK traffic (llm-git, * openai/anthropic SDKs) still lands in per-client burn tracking instead of * vanishing. These headers are attribution-only — they are deliberately * absent from {@link captureRequestHeaders}'s allow-list and never reach the * upstream provider. */ export declare function resolveClientIdentity(headers: Headers): ClientUsageIdentity; /** * Resolve a prompt-cache identity from inbound request body + headers. * Order of precedence (first wins): * 1. Body `prompt_cache_key` * 2. Body `metadata.{prompt_cache_key,session_id,conversation_id}` * 3. Header `x-prompt-cache-key` * 4. Header `session_id` / `conversation_id` (Codex / ChatGPT-OAuth surface) * 5. Header `x-session-id` / `x-conversation-id` (common informal) * Returns undefined when none present; the gateway then derives a stable * UUID from the request's stable parts. */ export declare function resolvePromptCacheKey(body: unknown, headers?: Headers): string | undefined; /** * CORS headers for the auth-gateway. Currently echoes a wildcard origin; the * request is accepted so future tightening can mirror `Origin` without * threading the request through every caller. */ export declare function corsHeaders(_req: Request): Record; /** * Re-emit `response` with CORS headers merged. The original response body is * passed through unchanged. Used by the gateway wrapper so every outbound * format-endpoint response carries the same CORS surface as the preflight. */ export declare function withCors(response: Response, req: Request): Response;