import type { AuthCredentialStore } from "./auth/store.js"; import type { AuthAccountPolicies, AuthApiKeyOptions, AuthStorageOptions, BlocksApi, CredentialsApi, HealthApi, KeysApi, LimitsApi, OAuthApi, ResetsApi, SessionsApi, UsageApi } from "./auth/types.js"; export { isSqliteBusyError, isSqliteCorruptionError, SqliteAuthCredentialStore } from "./auth/sqlite-credential-store.js"; export * from "./auth/store.js"; export * from "./auth/types.js"; /** * Credential management over an {@link AuthCredentialStore}: multi-account * selection with usage-aware ranking, rate-limit blocks, OAuth refresh, and * usage reporting. See the module doc for the namespace layout. * * Namespaces resolve against the current store on every access, so holders of * this instance follow {@link AuthStorage.replaceStore} without re-wiring. */ export declare class AuthStorage { #private; constructor(store: AuthCredentialStore, options?: AuthStorageOptions); /** Stored credential rows, change/disable events, broker snapshot. */ get credentials(): CredentialsApi; /** Provider auth cascade and key overrides. */ get keys(): KeysApi; /** OAuth login, account access, listings, refresh. */ get oauth(): OAuthApi; /** Session → account pins. */ get sessions(): SessionsApi; /** Usage reports, header ingestion, history. */ get usage(): UsageApi; /** Model pool health and per-credential probes. */ get health(): HealthApi; /** Usage-limit marking and credential rotation. */ get limits(): LimitsApi; /** Saved rate-limit resets. */ get resets(): ResetsApi; /** Persisted rate-limit blocks (auth-broker server seam). */ get blocks(): BlocksApi; /** * Apply new account routing policy (live `auth.accountPolicies` / * `retry.usageReservePct` change). Throws a configuration error, leaving the * active policy untouched, when the policy is malformed or does not match the * stored OAuth accounts. */ setAccountPolicies(config: { accountPolicies: AuthAccountPolicies; defaultReservePct: number; }): void; /** * Swap the backing credential store in place (live `auth.broker.url` change). * Loads `store` into fresh store-bound state — pins, blocks, and usage caches are * keyed by the old store's row ids — then closes the previous store. Runtime key * overrides, account policies, usage-provider overrides, and credential event * subscribers carry over. On a load failure `store` is closed and the current * store stays active. */ replaceStore(store: AuthCredentialStore, options?: { sourceLabel?: string; }): Promise; /** Open the SQLite store at `dbPath` and wrap it (standalone use, e.g. the pi-ai CLI). */ static create(dbPath: string, options?: AuthStorageOptions): Promise; /** Close the underlying credential store; the instance must not be reused. */ close(): void; /** * Legacy redirect for callers of the pre-namespace flat API (e.g. repo scripts). * @deprecated Use {@link AuthStorage.keys}`.get`. */ getApiKey(provider: string, sessionId?: string, options?: AuthApiKeyOptions): Promise; /** * Legacy redirect for callers of the pre-namespace flat API (e.g. repo scripts). * @deprecated Use {@link AuthStorage.credentials}`.reload`. */ reload(): Promise; }