import type { NativeIntegrationTool } from "./native-integrations.js"; export type NativeCredentialHelper = { command: string; args: string[]; }; type NativeCredentialHelperOptions = { cliEntrypoint?: string; execPath?: string; platform?: NodeJS.Platform; }; /** * Serialize a helper for clients that only accept a POSIX shell command * string. Keep this separate from the argument-vector form used by Codex so * platforms with incompatible shell grammars fail explicitly rather than * receiving an incorrectly quoted command. */ export declare function nativeCredentialShellCommand(helper: NativeCredentialHelper, platform?: NodeJS.Platform): string; /** * Build an absolute, PATH-independent invocation of this RouteKit CLI. Native * clients can therefore pull a token from the protected store even when they * were launched by an IDE, Finder, launchd, or another non-login process. * * T3 launches Codex app-server as a Node child and can leave Node's private * IPC metadata in the app-server environment. A credential helper is not that * IPC child, so macOS and Linux must remove those variables before starting a * second Node process. `/usr/bin/env -u` is supported by both platforms and * preserves the argument-vector contract without adding shell parsing. */ export declare function nativeCredentialHelper(tool: NativeIntegrationTool, configPath: string, options?: NativeCredentialHelperOptions): NativeCredentialHelper; export {};