import { CredentialReader } from './CredentialReader'; import type { AiCredential } from './types'; import { type AiCredentialSecretDecoder } from './AiCredentialSecret'; export interface CredentialReaderImplOptions { /** * Reads the Pod credential secret. Defaults to the plaintext decoder, which * covers bare `apiKey` rows, `plaintext-v1` payloads, and the `PLAINTEXT` * envelope AI Connections writes; the container injects a vault-backed decoder * so wrapped Cloud secrets resolve too. */ secretDecoder?: AiCredentialSecretDecoder; } export declare class CredentialReaderImpl extends CredentialReader { protected readonly logger: import("global-logger-factory").Logger; private readonly secretDecoder; constructor(options?: CredentialReaderImplOptions); getAiCredential(podBaseUrl: string, providerId: string, authenticatedFetch: typeof fetch, webId?: string, options?: { credentialId?: string; }): Promise; /** * AI Connections stores the provider secret in `encryptedSecret`; the shared * selector only understands a plain `apiKey`. Decode each row first so the * extension runtime sees the same credentials the Gateway does. */ private withDecodedSecrets; }