/** * Companies-door view over the ONE Agentcard config (~/.agent-cards/config.json). * * This used to be a separate store (~/.agent-cards-admin.json) with its own * session — you could be signed into the two CLIs as two different people. * Both doors share one account space (companies are created FROM personal * accounts), so they now share one session; only companies context (mode, * active company) is namespaced. The old admin file is adopted once by the * unified config's migration and then left alone. */ export declare function writeConfig(updates: { apiUrl?: string; jwt?: string; accessToken?: string; refreshToken?: string; email?: string; }): void; /** * Session-credential writes (login: email + token pair) go through the shared * session lock so they can never interleave with an in-flight token rotation — * same contract as the consumer door's writeSessionConfig. */ export declare function writeSessionConfig(updates: { jwt?: string; accessToken?: string; refreshToken?: string; email?: string; }): Promise; export declare function getApiUrl(): string; /** Bearer token for API calls — prefers the WorkOS access token, else a legacy JWT, else env. */ export declare function getJwt(): string | undefined; /** The WorkOS refresh token, if this is a WorkOS session (used to rotate on 401). */ export declare function getRefreshToken(): string | undefined; export declare function getEmail(): string | undefined; /** Remove stored auth (jwt + email) so user can log in as someone else. */ export declare function clearAuth(): Promise; /** * Guard: exit with message if not logged in or if the stored JWT is no longer * accepted by the server. Validates against /auth/me before any side effects * (banners, spinners, API calls) so commands fail fast with a clear message. * * On 401 we rotate via the refresh token first (short-lived WorkOS access * tokens make a 401 minutes after sign-in the NORMAL case); only then wipe. * On network failure we soft-skip and let the actual command surface the error. */ export declare function requireAuth(): Promise; /** The mode new OAuth clients are created in (UI: test / production). */ export declare function getMode(): 'sandbox' | 'production'; export declare function setMode(mode: 'sandbox' | 'production'): void; /** Default company for `companies` commands (set via `agent-cards companies use`). */ export declare function getActiveOrg(): { id: string; name?: string; } | undefined; export declare function setActiveOrg(id: string, name?: string): void; //# sourceMappingURL=config.d.ts.map