/** Deterministic by construction — one HMAC of a frozen label under the Cloud * key — because a deployment runs many replicas and every one of them enrols: * two that derived different secrets would take turns breaking the other's * knock. base64url, because Cloud keys its HMAC on this string's DECODED BYTES * and the door's `verifySignature` decodes it the same way on the way back in. * WebCrypto only (no node:crypto), like channelInboundSecret, so the module * keeps bundling for edge/Worker targets. */ export declare function deriveTickSecret(apiKey: string): Promise; /** THE secret, singular: what the firing door verifies against AND what * enrolment publishes, so Cloud can never be told a secret the door refuses. * `VENDO_TICK_SECRET` is the BYO override and wins outright (hard BYO rule — a * deployment with no Cloud key keeps a working `/tick`); otherwise VENDO_API_KEY * derives it. Undefined for a deployment that has neither, which is what makes * the door refuse every knock. The door reads the key from the environment; the * composition already resolved one (cloudKeyOptions) and passes THAT, so the two * callers cannot end up deriving from different keys. */ export declare function tickSecret(apiKey?: string | undefined): Promise; /** * Publish this deployment's firing door and the secret that will sign the knock. * * Silent in the three cases where there is nothing to publish and nothing wrong: * no Cloud key (nobody is going to knock), no automations mounted (a knock would * have nothing to fire), and a development process — which fires its own ticks * (compose-automations) behind a URL that is in no deployment inventory, so * enrolling it would register a wire Cloud cannot reach and then alarm about the * silence. */ export declare function enrolForTicks(options: { cloud: { apiKey: string; baseUrl?: string; } | undefined; automationsMounted: boolean; development: boolean; publicUrl: URL | undefined; /** Injection seam for tests; defaults to the global fetch. */ fetch?: typeof fetch; }): Promise;