import type { ProviderStatus } from "../../types.js"; export declare const serviceName = "clai"; export declare const keysFile: string; type KeytarLike = { getPassword(service: string, account: string): Promise; setPassword(service: string, account: string, password: string): Promise; deletePassword(service: string, account: string): Promise; }; export type SecretNamespace = 'llm' | 'search'; export type SecretSource = ProviderStatus['source']; export declare let keychainRuntimeUnavailable: boolean; export declare function loadKeytar(): Promise; export declare function isMissingKeychainError(error: unknown): boolean; /** * Compose the keychain account name used for a `(namespace, id)` pair. * Exposed so tests and callers can inspect the exact account string. */ export declare function secretAccount(namespace: SecretNamespace, id: string): string; /** * Read a secret out of the OS keychain (preferred) or the restricted-permission * plaintext fallback file. Returns `{ source: 'missing' }` when neither * backend has a value. * * Legacy LLM entries that still live under the bare `` account * name (no namespace prefix) are migrated lazily into `llm:` on * first read so older installs keep working without manual intervention. */ export declare function getSecret(namespace: SecretNamespace, id: string): Promise<{ value?: string; source: SecretSource; }>; export declare function setSecret(namespace: SecretNamespace, id: string, value: string): Promise<'keychain' | 'fallback'>; /** * Best-effort delete: removes the secret from both the keychain and the * fallback file. Never throws on keychain errors so unset always cleans * up the on-disk fallback even when the OS keystore is unreachable. */ export declare function unsetSecret(namespace: SecretNamespace, id: string): Promise; export declare function setKeychainRuntimeUnavailable(value: boolean): void; export {};