import type { AuthAccountPolicies, AuthAccountPolicy, AuthAccountSelector, AuthCredential, OAuthAccountIdentity } from "./types.js"; /** Whether every identity field set on `selector` matches `identity`. */ export declare function matchesAuthAccountSelector(selector: AuthAccountSelector, identity: OAuthAccountIdentity): boolean; /** Validated per-account routing policies (priority/reserve) plus the global reserve fallback. */ export declare class AccountPolicies { #private; constructor(policies: AuthAccountPolicies, defaultReservePct: number | undefined); /** Global usage reserve (0–100) for accounts without a per-account `reservePct`. */ get defaultReservePct(): number; /** * Replace the policy set and global reserve in place (live settings change). * Validates the configuration and every provider in `storedCredentials` before * committing; on error the previous policies stay active. */ replace(policies: AuthAccountPolicies, defaultReservePct: number | undefined, storedCredentials?: ReadonlyMap): void; validateUsageCapability(provider: string, canFetchUsage: boolean): void; validateFor(provider: string, credentials: readonly AuthCredential[]): void; /** * Return the configured account policy matching an OAuth identity. * * This is a read-only diagnostics surface: it performs the same conjunctive * selector match as routing and never refreshes, ranks, or mutates credentials. */ find(provider: string, identity: OAuthAccountIdentity): AuthAccountPolicy | undefined; /** Return the configured policy for a stored OAuth credential. */ forCredential(provider: string, credential: AuthCredential): AuthAccountPolicy | undefined; }