import type { CredentialRef, CredentialResolver } from "./service.js"; import { type HostIdentityPlan } from "./host_identity.js"; export declare const CREDENTIAL_HOST_BINDING_PATH = "harness/credentials/host-binding.json"; export interface CredentialHostBinding { schemaVersion: "credential-host-binding/1.0"; commonDir: string; hostId: string; hostLabel: string; repository: string; repositoryId: string; endpointHash: string; credentials: Array; bindingHash: string; } export type CredentialBindingInput = Omit & { credentials: Array>; }; export interface CredentialBindingPlan { schemaVersion: "credential-binding-plan/1.0"; beforeHash: string | null; beforeLkgHash: string | null; worktreeBindingHash: string | null; hostIdentity: HostIdentityPlan; createdAt: string; expiresAt: string; binding: CredentialHostBinding; planHash: string; } export declare function planCredentialHostBinding(commonDir: string, input: CredentialBindingInput): CredentialBindingPlan; export declare function applyCredentialHostBinding(commonDir: string, plan: CredentialBindingPlan, approval: string): CredentialHostBinding; export declare function loadCredentialHostBinding(commonDir: string, expected: { repository: string; repositoryId: string; endpointHash: string; }): CredentialHostBinding; /** Fixed macOS Keychain resolver: each read revalidates the current registered binding. */ export declare function macOSKeychainResolver(binding: CredentialHostBinding): CredentialResolver; //# sourceMappingURL=host_binding.d.ts.map