import { type XScalarIgnore } from '../../../schemas/extensions/document/x-scalar-ignore.js'; import { type XDefaultScopes } from '../../../schemas/extensions/security/x-default-scopes.js'; import type { OAuthFlowsObject } from '../../../schemas/v3.2/strict/oauthflows.js'; type Description = { /** A description for security scheme. CommonMark syntax MAY be used for rich text representation. */ description?: string; /** Declares this security scheme to be deprecated. Consumers SHOULD refrain from usage of the declared scheme. Added in OpenAPI 3.2. */ deprecated?: boolean; } & XScalarIgnore; export type ApiKeyObject = Description & { /** REQUIRED. The type of the security scheme. Valid values are "apiKey", "http", "mutualTLS", "oauth2", "openIdConnect". */ type: 'apiKey'; /** REQUIRED. The name of the header, query or cookie parameter to be used. */ name: string; /** REQUIRED. The location of the API key. Valid values are "query", "header", or "cookie". */ in: 'query' | 'header' | 'cookie'; }; export type HttpObject = Description & { /** REQUIRED. The type of the security scheme. Valid values are "apiKey", "http", "mutualTLS", "oauth2", "openIdConnect". */ type: 'http'; /** REQUIRED. The name of the HTTP Authentication scheme to be used in the Authorization header as defined in RFC7235. The values used SHOULD be registered in the IANA Authentication Scheme registry. The value is case-insensitive, as defined in RFC7235. */ scheme: 'basic' | 'bearer'; /** A hint to the client to identify how the bearer token is formatted. Bearer tokens are usually generated by an authorization server, so this information is primarily for documentation purposes. */ bearerFormat?: string; }; export type MutualTlsObject = Description & { /** REQUIRED. The type of the security scheme. Valid values are "apiKey", "http", "mutualTLS", "oauth2", "openIdConnect". */ type: 'mutualTLS'; }; export type OAuth2Object = Description & { /** REQUIRED. The type of the security scheme. Valid values are "apiKey", "http", "mutualTLS", "oauth2", "openIdConnect". */ type: 'oauth2'; /** REQUIRED. An object containing configuration information for the flow types supported. */ flows: OAuthFlowsObject; /** URL to the OAuth2 authorization server metadata (RFC8414). Use HTTPS, or HTTP for local development URLs. Added in OpenAPI 3.2. */ oauth2MetadataUrl?: string; } & XDefaultScopes; export type OpenIdConnectObject = Description & { /** REQUIRED. The type of the security scheme. Valid values are "apiKey", "http", "mutualTLS", "oauth2", "openIdConnect". */ type: 'openIdConnect'; /** REQUIRED. Well-known URL to discover the [[OpenID-Connect-Discovery]] provider metadata. */ openIdConnectUrl: string; }; /** * Defines a security scheme that can be used by the operations. * * Supported schemes are HTTP authentication, an API key (either as a header, a cookie parameter or as a query parameter), mutual TLS (use of a client certificate), OAuth2's common flows (implicit, password, client credentials and authorization code) as defined in RFC6749, and [[OpenID-Connect-Core]]. Please note that as of 2020, the implicit flow is about to be deprecated by OAuth 2.0 Security Best Current Practice. Recommended for most use cases is Authorization Code Grant flow with PKCE. */ export declare const SecuritySchemeObjectSchemaDefinition: import("@scalar/typebox").TUnion<[import("@scalar/typebox").TIntersect<[import("@scalar/typebox").TIntersect<[import("@scalar/typebox").TObject<{ /** A description for security scheme. CommonMark syntax MAY be used for rich text representation. */ description: import("@scalar/typebox").TOptional; /** Declares this security scheme to be deprecated. Consumers SHOULD refrain from usage of the declared scheme. Added in OpenAPI 3.2. */ deprecated: import("@scalar/typebox").TOptional; }>, import("@scalar/typebox").TObject<{ 'x-scalar-ignore': import("@scalar/typebox").TOptional; }>]>, import("@scalar/typebox").TObject<{ /** REQUIRED. The type of the security scheme. Valid values are "apiKey", "http", "mutualTLS", "oauth2", "openIdConnect". */ type: import("@scalar/typebox").TLiteral<"apiKey">; /** REQUIRED. The name of the header, query or cookie parameter to be used. */ name: import("@scalar/typebox").TString; /** REQUIRED. The location of the API key. Valid values are "query", "header", or "cookie". */ in: import("@scalar/typebox").TUnion<[import("@scalar/typebox").TLiteral<"query">, import("@scalar/typebox").TLiteral<"header">, import("@scalar/typebox").TLiteral<"cookie">]>; }>]>, import("@scalar/typebox").TIntersect<[import("@scalar/typebox").TIntersect<[import("@scalar/typebox").TObject<{ /** A description for security scheme. CommonMark syntax MAY be used for rich text representation. */ description: import("@scalar/typebox").TOptional; /** Declares this security scheme to be deprecated. Consumers SHOULD refrain from usage of the declared scheme. Added in OpenAPI 3.2. */ deprecated: import("@scalar/typebox").TOptional; }>, import("@scalar/typebox").TObject<{ 'x-scalar-ignore': import("@scalar/typebox").TOptional; }>]>, import("@scalar/typebox").TObject<{ /** REQUIRED. The type of the security scheme. Valid values are "apiKey", "http", "mutualTLS", "oauth2", "openIdConnect". */ type: import("@scalar/typebox").TLiteral<"http">; /** REQUIRED. The name of the HTTP Authentication scheme to be used in the Authorization header as defined in RFC7235. The values used SHOULD be registered in the IANA Authentication Scheme registry. The value is case-insensitive, as defined in RFC7235. */ scheme: import("@scalar/typebox").TUnion<[import("@scalar/typebox").TLiteral<"basic">, import("@scalar/typebox").TLiteral<"bearer">]>; /** A hint to the client to identify how the bearer token is formatted. Bearer tokens are usually generated by an authorization server, so this information is primarily for documentation purposes. */ bearerFormat: import("@scalar/typebox").TOptional; }>]>, import("@scalar/typebox").TIntersect<[import("@scalar/typebox").TIntersect<[import("@scalar/typebox").TObject<{ /** A description for security scheme. CommonMark syntax MAY be used for rich text representation. */ description: import("@scalar/typebox").TOptional; /** Declares this security scheme to be deprecated. Consumers SHOULD refrain from usage of the declared scheme. Added in OpenAPI 3.2. */ deprecated: import("@scalar/typebox").TOptional; }>, import("@scalar/typebox").TObject<{ 'x-scalar-ignore': import("@scalar/typebox").TOptional; }>]>, import("@scalar/typebox").TObject<{ /** REQUIRED. The type of the security scheme. Valid values are "apiKey", "http", "mutualTLS", "oauth2", "openIdConnect". */ type: import("@scalar/typebox").TLiteral<"mutualTLS">; }>]>, import("@scalar/typebox").TIntersect<[import("@scalar/typebox").TIntersect<[import("@scalar/typebox").TObject<{ /** A description for security scheme. CommonMark syntax MAY be used for rich text representation. */ description: import("@scalar/typebox").TOptional; /** Declares this security scheme to be deprecated. Consumers SHOULD refrain from usage of the declared scheme. Added in OpenAPI 3.2. */ deprecated: import("@scalar/typebox").TOptional; }>, import("@scalar/typebox").TObject<{ 'x-scalar-ignore': import("@scalar/typebox").TOptional; }>]>, import("@scalar/typebox").TObject<{ /** REQUIRED. The type of the security scheme. Valid values are "apiKey", "http", "mutualTLS", "oauth2", "openIdConnect". */ type: import("@scalar/typebox").TLiteral<"oauth2">; /** REQUIRED. An object containing configuration information for the flow types supported. */ flows: import("@scalar/typebox").TRef<"OAuthFlowsObject">; /** URL to the OAuth2 authorization server metadata (RFC8414). Use HTTPS, or HTTP for local development URLs. Added in OpenAPI 3.2. */ oauth2MetadataUrl: import("@scalar/typebox").TOptional; }>, import("@scalar/typebox").TObject<{ 'x-default-scopes': import("@scalar/typebox").TOptional>; }>]>, import("@scalar/typebox").TIntersect<[import("@scalar/typebox").TIntersect<[import("@scalar/typebox").TObject<{ /** A description for security scheme. CommonMark syntax MAY be used for rich text representation. */ description: import("@scalar/typebox").TOptional; /** Declares this security scheme to be deprecated. Consumers SHOULD refrain from usage of the declared scheme. Added in OpenAPI 3.2. */ deprecated: import("@scalar/typebox").TOptional; }>, import("@scalar/typebox").TObject<{ 'x-scalar-ignore': import("@scalar/typebox").TOptional; }>]>, import("@scalar/typebox").TObject<{ /** REQUIRED. The type of the security scheme. Valid values are "apiKey", "http", "mutualTLS", "oauth2", "openIdConnect". */ type: import("@scalar/typebox").TLiteral<"openIdConnect">; /** REQUIRED. Well-known URL to discover the [[OpenID-Connect-Discovery]] provider metadata. */ openIdConnectUrl: import("@scalar/typebox").TString; }>]>]>; export type SecuritySchemeObject = ApiKeyObject | HttpObject | MutualTlsObject | OAuth2Object | OpenIdConnectObject; export {}; //# sourceMappingURL=security-scheme.d.ts.map