import type { OAuthProviderId } from "../registry/oauth/types.js"; import type { SessionAffinity } from "./affinity.js"; import type { KeyOverrides } from "./cascade.js"; import type { AccountPolicies } from "./policy.js"; import type { CredentialPool } from "./pool.js"; import type { OAuthRefresher } from "./refresh.js"; import type { CredentialSelector } from "./select.js"; import type { AuthAccountPolicy, AuthApiKeyOptions, AuthCredentialSnapshotEntry, OAuthAccess, OAuthAccessResolution, OAuthAccountIdentity, OAuthAccountSummary, OAuthApi, OAuthCredential, OAuthLoginController, OAuthLoginIdentity, OAuthRefreshByIdOptions, StoredOAuthRefreshOptions, StoredOAuthRefreshResult } from "./types.js"; /** Dependencies used by the OAuth account operations. */ export interface OAuthAccountsDeps { pool: CredentialPool; overrides: KeyOverrides; policies: AccountPolicies; selector: CredentialSelector; affinity: SessionAffinity; refresher: OAuthRefresher; } /** OAuth login, per-account access resolution, and account listings. */ export declare class OAuthAccounts implements OAuthApi { #private; constructor(deps: OAuthAccountsDeps); /** * Login to an OAuth provider. Resolves with the stored credential's * identity slice (or `undefined` when nothing was stored) so callers can * surface which account — and for Anthropic, which organization — the * login registered. */ login(provider: OAuthProviderId, ctrl: OAuthLoginController): Promise; /** * Resolve the OAuth credential for `provider`, refreshing through the same * pipeline as API-key resolution but returning the refreshed * {@link OAuthAccess} (raw access token + identity metadata) instead of * the API-key bytes. * * Use this when the caller needs to inject identity headers alongside the * bearer (Codex `chatgpt-account-id`, Google `project`, GitHub * `enterpriseUrl`). For pure "give me the bytes for `Authorization`" * scenarios, prefer API-key resolution. * * Returns `undefined` when no OAuth credential is available, the * credential fails to refresh, or runtime/config overrides have replaced * OAuth with an explicit API key. */ access(provider: string, sessionId?: string, options?: AuthApiKeyOptions): Promise; /** * Read-only list of stored OAuth accounts for `provider` in stable storage * order, WITHOUT refreshing any token. The array position (0-based) is the * selector displayed by a "pick the Nth account" UI as `position + 1`. * * When `sessionId` is supplied, the session-sticky OAuth credential is marked * `active`. No account is active before that session has resolved or pinned a * credential. */ accounts(provider: string, sessionId?: string): OAuthAccountSummary[]; /** * Resolve every stored OAuth credential for `provider` independently. * * Refreshes credentials through the same broker/local path as * {@link OAuthAccounts.access}, but does not rank, round-robin, or * stop after the first usable account. Intended for diagnostics that must * exercise each stored account exactly once. */ accessAll(provider: string, options?: AuthApiKeyOptions): Promise; /** * Resolve one stored OAuth credential by its durable storage row id. * * Unlike the normal session resolver, this method never ranks, rotates, or * falls back to sibling credentials. A forced refresh re-mints only the * requested row, preserving exact-account affinity for operations whose * provenance and policy boundary are tied to one workspace. * * Returns `undefined` when the row does not exist for `provider` or an * explicit runtime/config API-key override suppresses OAuth. */ accessById(provider: string, credentialId: number, options?: AuthApiKeyOptions): Promise; /** * Get the OAuth account identity for a provider, preferring the credential that * is session-sticky for `sessionId`. This is a read-only lookup for display and * metadata paths; it does not refresh tokens, rank usage, or advance selection. */ identity(provider: string, sessionId?: string): OAuthAccountIdentity | undefined; /** * Return the configured account policy matching an OAuth identity. * * This is a read-only diagnostics surface: it performs the same conjunctive * selector match as routing and never refreshes, ranks, or mutates credentials. */ policy(provider: string, identity: OAuthAccountIdentity): AuthAccountPolicy | undefined; /** Force-refresh one stored credential by its durable row id. */ refresh(id: number, signal?: AbortSignal, options?: OAuthRefreshByIdOptions): Promise; /** Refresh one stored OAuth credential through the durable ownership path. */ refreshStored(provider: string, options: StoredOAuthRefreshOptions): Promise>; }