import { type Output, type TelemetryOptions } from "../shared.js"; export interface DeviceLoginOptions { output?: Output; fetchImpl?: typeof fetch; env?: Record; /** Where .env.local lives (default: the current working directory). */ root?: string; /** Injectable pacing seam — tests run the ceremony in microseconds. */ sleep?: (ms: number) => Promise; now?: () => number; /** TTY seam — a watching human gets the browser opened for them. What the ceremony PRINTS is `pretty`'s call, not this one: the numbered URL + code contract holds on every non-pretty path, TTY or not. */ isTty?: boolean; openBrowser?: (url: string) => void; /** init runs the ceremony inline and picks the key up in the same run — it suppresses the standalone "re-run `vendo init`" tail. */ rerunHint?: boolean; /** * The pretty renderer is driving this ceremony, so a human is reading a rail * and the machine-readable receipt below is noise sitting under the three * lines of state. Suppressed there — and, `isTty` above, on any terminal a * human is watching: nothing parses a TTY, and standalone `vendo login` * printed that JSON block at a human who read it as a crash. `--agent`, * piped, non-TTY and CI runs keep it byte for byte. * * Passed explicitly rather than inferred. `usePrettyOutput()` answers "is * this terminal colour-capable", which is a different question — standalone * `vendo login` in the same terminal has no renderer and must keep its * receipt — and inferring it from `rerunHint` would give that flag a second * meaning for the next reader to break silently. */ pretty?: boolean; /** Where ~/.vendo lives (default: the home directory) — the pending-claim file that lets a fresh run resume a still-open ceremony (#479). */ home?: string; } /** * Write-preflight (0.4.1 E2E cert M4): prove `.env.local` is writable BEFORE * any claim is opened or redeemed. Sandboxed agent runs — headless Claude * Code protects env files even under --dangerously-skip-permissions — can * deny the write; without this check the ceremony redeems the single-use * claim, the key mints server-side, and the write failure loses it. A real * append-mode open is the probe (permission checks like `access(W_OK)` don't * see sandbox policies, which deny at open time); a probe-created empty file * is removed again. Returns the failure detail, or null when writable. */ export declare function preflightEnvLocalWrite(root: string): Promise; /** * `vendo login` — the top-level command surface: the identical ceremony * wrapped in one `command_run` row (command "login", TELEMETRY.md). The * ceremony's other two callers stay untracked here: `vendo cloud * device-login` (the alias) calls runDeviceLogin directly, and init's * embedded step already tracks itself as "cloud-init". */ export declare function runLoginCommand(args: string[], options?: DeviceLoginOptions & { telemetry?: TelemetryOptions; }): Promise; export declare function runDeviceLogin(args: string[], options?: DeviceLoginOptions): Promise;