import type { HostAuthPreset, HostAuthPresetOptions } from "./shared.js"; /** * 09-vendo §2.1 — the Clerk host-identity preset. Zero-argument in the * standard case: session verification reads Clerk's own env (CLERK_SECRET_KEY; * CLERK_JWT_KEY when set enables Clerk's networkless path and is preferred), * the session token comes off the request per Clerk's conventions (the * `__session` cookie or Authorization: Bearer), and display derives from * name/email claims. The optional subject→user resolver has the same * semantics as authJs (null = subject unknown → decline/null). * * Clerk holds the private keys for its RS256 sessions, so the actAs half is * the shipped away-token producer (`clerkPreset`, 04 §2.1) — minting a * host-owned `VendoAway` token under VENDO_AWAY_TOKEN_SECRET; the matching * verify half stays host-mounted middleware (producer/verify split). The * `secret` option therefore overrides the AWAY-TOKEN secret (the preset's * system-equivalent shared secret), never the Clerk secret key, which is an * API credential and stays env-only. * * The door's sessionless redirect follows Clerk's sign-in convention: * NEXT_PUBLIC_CLERK_SIGN_IN_URL when set, else /sign-in, carrying both the * standard returnTo and Clerk's redirect_url. */ export declare function clerk(options?: HostAuthPresetOptions): HostAuthPreset;