import type { DeploymentRootKeyProvider } from './DeploymentRootKeyProvider'; declare const AES_GCM_ALGORITHM: "AES-256-GCM"; declare const PAYLOAD_AAD_PURPOSE = "xpod.secret-cell.payload"; declare const DEK_WRAP_AAD_PURPOSE = "xpod.secret-cell.dek-wrap"; declare const AAD_VERSION = "v1"; declare const DEK_WRAP_ALGORITHM = "xpod-secret-cell-root-hkdf-aes-256-gcm"; export interface SecretCellContext { ownerWebId: string; resourceIri: string; predicate: string; field: string; schemaVersion: string; provider?: string; extra?: Record; } export interface SecretCellWrappedDataKey { algorithm: typeof DEK_WRAP_ALGORITHM; keyId: string; aadPurpose: typeof DEK_WRAP_AAD_PURPOSE; aadVersion: typeof AAD_VERSION; nonce: string; ciphertext: string; } export interface SecretCellEnvelope { algorithm: typeof AES_GCM_ALGORITHM; aadPurpose: typeof PAYLOAD_AAD_PURPOSE; aadVersion: typeof AAD_VERSION; context: SecretCellContext; nonce: string; ciphertext: string; wrappedDek: SecretCellWrappedDataKey; } export interface SecretCellVaultOptions { rootKeys: DeploymentRootKeyProvider; } export declare class SecretCellError extends Error { constructor(); toJSON(): { name: string; message: string; }; } export declare class SecretCellVault { private readonly rootKeys; constructor(options: SecretCellVaultOptions); needsRewrap(keyId: string): boolean; seal(plaintext: Uint8Array, context: SecretCellContext): Promise; open(envelope: SecretCellEnvelope, context: SecretCellContext): Promise; rewrap(envelope: SecretCellEnvelope, context: SecretCellContext): Promise; wrapDataKey(dek: Uint8Array, context: SecretCellContext): Promise; unwrapDataKey(wrapped: SecretCellWrappedDataKey, context: SecretCellContext): Promise; private assertEnvelopeContext; } export declare function normalizeContext(context: SecretCellContext): SecretCellContext; export {};