import { a as StytchProjectConfigurationInput, h as IHeadlessB2BOAuthClient, i as IHeadlessB2BMagicLinksClient, j as IHeadlessB2BOrganizationClient, k as IHeadlessB2BSSOClient, l as IHeadlessB2BDiscoveryClient, m as IHeadlessB2BPasswordClient, n as IHeadlessB2BOTPsClient, o as IHeadlessB2BTOTPsClient, p as IHeadlessB2BRecoveryCodesClient, q as IHeadlessB2BImpersonationClient, B as B2BState, g as StytchClientOptions } from './DFPProtectedAuthProvider-0rW0WKz_.js'; import { m as IHeadlessB2BIDPClient, a as INetworkClient, B as B2BOAuthAuthorizeStartOptions, n as B2BOAuthAuthorizeStartResponse, o as B2BOAuthAuthorizeSubmitOptions, p as B2BOAuthAuthorizeSubmitResponse, q as B2BOAuthLogoutStartOptions, r as B2BOAuthLogoutStartResponse, h as OneTapRenderResult, s as IHeadlessB2BSessionClient, t as IHeadlessB2BMemberClient, u as IHeadlessB2BSelfClient, v as IHeadlessB2BRBACClient, w as IHeadlessB2BSCIMClient, S as StateChangeRegisterFunction, P as ParseAuthenticateUrl, A as AuthenticateByUrl } from './GoogleOneTapClient-C8tXxrMo.js'; declare class HeadlessB2BIDPClient implements IHeadlessB2BIDPClient { private _networkClient; constructor(_networkClient: INetworkClient); /** * Initiates a request for authorization of a Connected App to access a Member's account. * * Call this endpoint using the query parameters from an OAuth Authorization request. This endpoint validates various fields (scope, client_id, redirect_uri, prompt, etc...) are correct and returns relevant information for rendering an OAuth Consent Screen. * * @example * const response = await stytch.idp.oauthAuthorizeStart({ * client_id: 'client_123', * redirect_uri: 'https://example.com/callback', * scope: 'openid email profile', * }); */ oauthAuthorizeStart: (data: B2BOAuthAuthorizeStartOptions) => Promise; /** * Completes a request for authorization of a Connected App to access a Member's account. * * Call this endpoint using the query parameters from an OAuth Authorization request, after previously validating those parameters using the Preflight Check API. Note that this endpoint takes in a few additional parameters the preflight check does not- state, nonce, and code_challenge. * * If the authorization was successful, the redirect_uri will contain a valid authorization_code embedded as a query parameter. If the authorization was unsuccessful, the redirect_uri will contain an OAuth2.1 error_code. In both cases, redirect the Member to the location for the response to be consumed by the Connected App. * * Exactly one of the following must be provided to identify the Member granting authorization: * organization_id + member_id * session_token * session_jwt * * If a session_token or session_jwt is passed, the OAuth Authorization will be linked to the Member's session for tracking purposes. One of these fields must be used if the Connected App intends to complete the Exchange Access Token flow. * * @example * const response = await stytch.idp.oauthAuthorizeSubmit({ * client_id: 'client_123', * redirect_uri: 'https://example.com/callback', * scope: 'openid email profile', * }); */ oauthAuthorizeSubmit: (data: B2BOAuthAuthorizeSubmitOptions) => Promise; oauthLogoutStart: (data: B2BOAuthLogoutStartOptions) => Promise; } type B2BGoogleOneTapDiscoveryOAuthOptions = { /** * The URL that Stytch redirects to after the Google One Tap discovery flow is completed. * This should be a URL that verifies the request by querying Stytch's /oauth/discovery/authenticate endpoint. * If this value is not passed, the default discovery redirect URL that you set in your Dashboard is used. * If you have not set a default discovery redirect URL, an error is returned. */ discovery_redirect_url?: string; /** * Controls whether clicking outside the One Tap prompt dismisses the prompt. * Defaults to true. */ cancel_on_tap_outside?: boolean; }; type B2BGoogleOneTapOAuthOptions = { /** * The ID of the organization that the end user is logging in to. */ organization_id: string; /** * The URL that Stytch redirects to after the Google One Tap flow is completed for a member who already exists. * This should be a URL that verifies the request by querying Stytch's /oauth/authenticate endpoint. * If this value is not passed, the default login redirect URL that you set in your Dashboard is used. * If you have not set a default login redirect URL, an error is returned. */ login_redirect_url?: string; /** * The URL that Stytch redirects to after the Google One Tap flow is completed for a member who does not yet exist. * This should be a URL that verifies the request by querying Stytch's /oauth/authenticate endpoint. * If this value is not passed, the default signup redirect URL that you set in your Dashboard is used. * If you have not set a default signup redirect URL, an error is returned. */ signup_redirect_url?: string; /** * Controls whether clicking outside the One Tap prompt dismisses the prompt. * Defaults to true. */ cancel_on_tap_outside?: boolean; }; interface IB2BGoogleOneTapOAuthProvider { discovery: { /** * Start a discovery OAuth flow by showing the Google one tap prompt in the top right corner of the user's browser. * You can configure this to be started by a user action (i.e Button click) or on load/render. * @example * const showGoogleOneTap = useCallback(()=> { * stytch.oauth.googleOneTap.discovery.start({ * discovery_redirect_url: 'https://example.com/oauth/callback', * }) * }, [stytch]); * return ( * * ); * * @param options - A {@link B2BGoogleOneTapDiscoveryOAuthOptions} object * * @returns A {@link OneTapRenderResult} object. The result object includes if the one-tap prompt * was rendered, and a reason if it couldn't be rendered. * * @throws An Error if the one tap client cannot be created. */ start(options?: B2BGoogleOneTapDiscoveryOAuthOptions): Promise; }; /** * Start an OAuth flow by showing the Google one tap prompt in the top right corner of the user's browser. * You can configure this to be started by a user action (i.e Button click) or on load/render. * @example * const showGoogleOneTap = useCallback(()=> { * stytch.oauth.googleOneTap.start({ * organization_id: 'organization-test-123', * }) * }, [stytch]); * return ( * * ); * * @param options - A {@link B2BGoogleOneTapOAuthOptions} object * * @returns A {@link OneTapRenderResult} object. The result object includes if the one-tap prompt * was rendered, and a reason if it couldn't be rendered. * * @throws An Error if the one tap client cannot be created. */ start(options?: B2BGoogleOneTapOAuthOptions): Promise; } interface IWebB2BOAuthClient extends IHeadlessB2BOAuthClient { googleOneTap: IB2BGoogleOneTapOAuthProvider; } type HandledTokenType = 'discovery' | 'discovery_oauth' | 'oauth' | 'sso' | 'multi_tenant_magic_links' | 'multi_tenant_impersonation'; /** * A headless client used for invoking Stytch's B2B APIs. * The Stytch Headless Client can be used as a drop-in solution for authentication and session management. * Full documentation can be found {@link https://stytch.com/docs/b2b/sdks/javascript-sdk online}. * * @example * const stytch = new StytchB2BClient('public-token-'); * stytch.magicLinks.email.loginOrCreate({ * email: 'sandbox@stytch.com', * organization_id: 'organization-test-123', * }); */ declare class StytchB2BClient { private readonly _subscriptionService; private readonly _sessionManager; private readonly _networkClient; private readonly _dataLayer; private readonly _stateChangeClient; magicLinks: IHeadlessB2BMagicLinksClient; session: IHeadlessB2BSessionClient; /** @deprecated Please use client.self instead. This will be removed in a future release. */ member: IHeadlessB2BMemberClient; self: IHeadlessB2BSelfClient; organization: IHeadlessB2BOrganizationClient; oauth: IWebB2BOAuthClient; sso: IHeadlessB2BSSOClient; discovery: IHeadlessB2BDiscoveryClient; passwords: IHeadlessB2BPasswordClient; otps: IHeadlessB2BOTPsClient; totp: IHeadlessB2BTOTPsClient; recoveryCodes: IHeadlessB2BRecoveryCodesClient; rbac: IHeadlessB2BRBACClient; scim: IHeadlessB2BSCIMClient; impersonation: IHeadlessB2BImpersonationClient; idp: HeadlessB2BIDPClient; /** * Register a callback function to be invoked whenever certain state changes * occur, like a member or session object being updated. * * This is an alternative to more specific methods like `self.onChange` and * `session.onChange`. It can be helpful if you want to be notified of related * changes to different parts of state at once. * * If you are only interested in specific state changes, consider using more * specific methods like `self.onChange` and `session.onChange` instead. */ onStateChange: StateChangeRegisterFunction; /** * Extracts token and token type from the current page URL's query parameters. * If the current URL do not have the required query params, this will return null. * Otherwise, returns an object { handled: boolean, tokenType: string, token: string } */ parseAuthenticateUrl: ParseAuthenticateUrl; /** * Call this method to authenticate the user when the user has been redirected * to this page with a token in the query parameters, such as after OAuth * or through an email magic link. This method currently supports * * - Magic links * - OAuth * - SSO * - Impersonation * * If the current URL do not have the required query params, the promise returned will resolve to null. * If the token type is not supported (e.g. reset_password), the promise returned will resolve to this * object allowing you to handle the token. * { * handled: false, * tokenType: 'token_type', * token: '' * } */ authenticateByUrl: AuthenticateByUrl; constructor(rawPublicToken: string, options?: StytchClientOptions); } export { StytchB2BClient as S };