import { type Guard, type StoreAdapter, type ToolRegistry } from "../core/index.js"; import type { ToolDoorPort } from "../harnesses/index.js"; import { type LiveTurn } from "../mcp/index.js"; /** Where the host mounts {@link AgentDoor.handler}, and the path the box dials. * The umbrella's mount, deliberately: a deployment that later wraps this agent * in `createVendo` does not have to move its box's dial-back path. */ export declare const DOOR_PATH = "/api/vendo/mcp"; export interface DoorConfig { /** The PUBLIC origin a sandbox box can reach — `https://app.example.com`. * Only the origin is used; behind a reverse proxy this is the outside * address, never the proxy-internal one the request arrives on. */ baseUrl: string; } export interface AgentDoor { /** Fetch-style, for the host to mount at {@link DOOR_PATH}. */ handler(request: Request): Promise; /** What the harness reads at turn time: where to dial, and one credential per * conversation. */ port: ToolDoorPort; /** The runtime's `liveTurn` seam. Publishing is not a grant — it is the only * thing that makes an already-minted credential resolve, and its authority * window is exactly the turn. */ publish(threadId: string, turn: LiveTurn): () => void; /** Loopback rung only: resolves once the listener is bound, so `session()` * can guarantee `port.url` is never read mid-bind. A named origin needs no * waiting and carries none. */ ready?: Promise; } /** Everything the internal door serves a live turn from. All of it already * exists at `agent()` time — the door composes from parts, it never builds * a second registry or a second guard. */ export interface DoorParts { /** Guard-bound already — the one choke point, shared with `session.stream`. */ tools: ToolRegistry; guard: Guard; store: StoreAdapter; } /** * The ladder, and what an EMPTY ladder means here — the same division * `resolveSandbox` keeps with `selectSandbox`. */ export declare function resolveDoor(configured: DoorConfig | undefined, harness: { name: string; sandboxed: boolean; }, parts: DoorParts): AgentDoor;