import { type KeyObject } from 'node:crypto'; export interface MeshLinkAuthIdentity { processId: string; endpointId?: string; requesterEndpointId?: string; requestNonce?: string; /** The endpoint the request proof is intended for (v2). */ audienceEndpointId?: string; endpointPublicKey?: string; endpointSignature?: string; timestamp: number; nonce: string; signature: string; } export type MeshLinkAuthPurpose = 'request' | 'response'; export interface MeshLinkEndpointKeyPair { privateKey: KeyObject; /** SPKI DER, base64 encoded for publication in MeshNode metadata. */ publicKey: string; } export declare function createMeshLinkEndpointKeyPair(): MeshLinkEndpointKeyPair; export declare function signMeshLinkEndpointProof(privateKey: KeyObject, identity: MeshLinkAuthIdentity, path: string, purpose: MeshLinkAuthPurpose, responseTo?: { endpointId: string; nonce: string; }): string; export declare function verifyMeshLinkEndpointProof(identity: MeshLinkAuthIdentity, path: string, purpose: MeshLinkAuthPurpose, responseTo?: { endpointId: string; nonce: string; }): boolean; export declare class MeshLinkAuthenticator { private readonly secret; private readonly clockSkewMs; private readonly seenNonces; /** A timing wheel makes expiry bounded by one bucket, rather than scanning the * entire cache on every handshake. When full we reject new handshakes: evicting * a live nonce would turn a resource limit into a replay vulnerability. */ private readonly nonceBuckets; private lastPrunedBucket; constructor(secret: string, clockSkewMs?: number); createIdentity(processId: string, path: string, purpose?: MeshLinkAuthPurpose, endpointId?: string, responseTo?: { endpointId: string; nonce: string; }, audienceEndpointId?: string): MeshLinkAuthIdentity; verify(identity: MeshLinkAuthIdentity, path: string, purpose?: MeshLinkAuthPurpose, responseTo?: { endpointId: string; nonce: string; }): void; private sign; private pruneNonces; } //# sourceMappingURL=auth.d.ts.map