import type { Provider } from "../types.js"; import type { RankingStrategyResolver } from "../usage/registry.js"; import type { SessionAffinity } from "./affinity.js"; import type { CredentialBlocks } from "./blocks.js"; import type { KeyCascade, KeyOverrides } from "./cascade.js"; import type { AccountPolicies } from "./policy.js"; import type { CredentialPool } from "./pool.js"; import type { OAuthRefresher } from "./refresh.js"; import type { AuthCredentialStore } from "./store.js"; import type { CheckCredentialsOptions, CredentialHealthResult, HealthApi, ModelUsageHealth, ModelUsageHealthOptions } from "./types.js"; import type { UsageService } from "./usage.js"; /** Dependencies for model pool health and stored credential probes. */ export interface CredentialHealthDeps { store: AuthCredentialStore; pool: CredentialPool; keys: KeyCascade; policies: AccountPolicies; blocks: CredentialBlocks; affinity: SessionAffinity; usage: UsageService; refresher: OAuthRefresher; overrides: KeyOverrides; strategies: RankingStrategyResolver; } /** Model-level pool health and per-credential auth probes. */ export declare class CredentialHealth implements HealthApi { #private; constructor(deps: CredentialHealthDeps); /** * Inspect the credential pool that {@link getApiKey} would use for one model * without advancing round-robin state or changing session stickiness. * * Pool aggregation is deliberately conservative: one healthy sibling makes * the model healthy, while any unknown sibling prevents a depleted/reserve * conclusion. Static runtime/config/env credentials return unknown because * they bypass the managed account pool. */ model(provider: Provider, options: ModelUsageHealthOptions): Promise; /** * Probe each stored credential against its provider's auth-verifying usage * endpoint and report per-credential auth health. * * Surfaces the identity of failing credentials so callers running a * multi-account pool (e.g. a broker-backed auth-gateway) can tell which * row is producing 401s. The probe mirrors the per-credential fan-out * inside {@link UsageService.reports} (OAuth refresh-on-expiry, * then `UsageProvider.fetchUsage`) but does NOT swallow errors — every * credential gets either `ok: true`, `ok: false` with `reason`, or * `ok: null` when no probe is configured for the provider. * * Iterates sequentially to avoid synchronized N-account fan-out that * upstream `/usage` rate limiters (per source IP) treat as a burst. * * Only inspects active rows from {@link AuthCredentialStore.listAuthCredentials}; * soft-disabled rows are already known-bad and don't need a network probe. * Environment-variable API keys are not enumerated — the caller's intent * here is "which of my stored credentials is broken". * * Pass {@link CheckCredentialsOptions.completionProbe} to additionally * exercise each credential against the provider's chat-completion endpoint * (strict mode). The result lands on * {@link CredentialHealthResult.completion}; the usage `ok` field is * unchanged so callers can tell the two signals apart. */ check(options?: CheckCredentialsOptions): Promise; }