import { b as TokenStorage, A as Auth, D as DeviceAuthResult, c as DeviceTokenSuccessResponse, T as TokenResponse, a as AuthState } from '../types-BhMPRYcJ.cjs'; export { d as DeviceAuthInitResponse } from '../types-BhMPRYcJ.cjs'; interface AuthenticateOptions { /** * Called when the user needs to visit a URL and enter a code. * You must display the `userCode` and `verifyUrl` to the user. */ onUserCode: (info: { userCode: string; verifyUrl: string; }) => void; /** Where to persist tokens. Defaults to in-memory. */ storage?: TokenStorage; /** * Automatically open the verification URL in the default browser. * - Node.js: uses dynamic `import('open')` — install `open` as a dependency * - Browser: uses `window.open()` * * Default: false. */ openBrowser?: boolean; /** Status updates during polling */ onStatus?: (message: string) => void; /** Abort signal for cancellation */ signal?: AbortSignal; /** Maximum time to poll for authorization in ms (default: 5 minutes) */ timeoutMs?: number; } /** * Authenticate with the Codex backend. * * 1. Checks storage for valid, non-expired tokens → returns immediately * 2. If tokens are expired, attempts a refresh → returns on success * 3. Otherwise, initiates the device code flow and waits for user authorization * * Returns an `Auth` object bundling the token state with storage, * which should be passed directly to `createCodexOAuth()`. */ declare function authenticate(options: AuthenticateOptions): Promise; /** * Initiate the device authorization flow. * Returns the user code and verification URL. */ declare function initiateDeviceAuth(clientId?: string): Promise; interface PollDeviceAuthOptions { /** Device auth ID from initiateDeviceAuth() */ deviceAuthId: string; /** User code from initiateDeviceAuth() */ userCode: string; /** Polling interval in ms */ intervalMs: number; /** Status callback during polling */ onStatus?: (message: string) => void; /** Abort signal for cancellation */ signal?: AbortSignal; /** Maximum time to poll in ms (default: 5 minutes) */ timeoutMs?: number; } /** * Poll the device auth endpoint until the user authorizes. * Returns the authorization code and PKCE verifier. */ declare function pollDeviceAuth(options: PollDeviceAuthOptions): Promise; /** * Exchange an authorization code + PKCE verifier for OAuth tokens. */ declare function exchangeCodeForTokens(code: string, codeVerifier: string, clientId?: string): Promise; /** * Refresh an access token using a refresh token. */ declare function refreshAccessToken(refreshToken: string, clientId?: string): Promise; /** * Build an AuthState from a TokenResponse. */ declare function buildAuthState(tokens: TokenResponse): AuthState; /** * Attempt to refresh an existing AuthState, returning a new one. * Returns null if the refresh fails. */ declare function refreshAuthState(auth: AuthState, clientId?: string): Promise; /** * Minimal JWT decoding (no signature verification). * Works in both browser (atob) and Node.js 16+ (Buffer). */ declare function decodeJwtPayload(token: string): Record | null; /** * Extract a ChatGPT account ID from JWT claims. * Checks multiple known claim locations in order. */ declare function extractAccountId(tokens: { id_token?: string; access_token: string; }): string | undefined; export { Auth, AuthState, type AuthenticateOptions, DeviceAuthResult, DeviceTokenSuccessResponse, type PollDeviceAuthOptions, TokenResponse, authenticate, buildAuthState, decodeJwtPayload, exchangeCodeForTokens, extractAccountId, initiateDeviceAuth, pollDeviceAuth, refreshAccessToken, refreshAuthState };