import type { BoondAuthProvider, BoondConfig } from "../../types.js"; /** * Auth provider for the HTTP transport: reads the Bearer token from the * per-request AsyncLocalStorage populated by the transport layer and * forwards it verbatim to BoondManager as `Authorization: Bearer …`. * * Errors out clearly if called outside a request context — which would * indicate that the transport layer forgot to wrap the request in * `oauthContext.run(...)`. */ export declare const oauthContextAuth: BoondAuthProvider; /** * Build the BoondManager HS256 JWT. By default the payload is exactly * `{ userToken, clientToken }` (BoondManager's documented scheme). When * `expiresInSeconds` is provided, standard `iat`/`exp` claims are added so the * generated token is no longer replayable forever if it leaks — this requires * regenerating the token per request (see `jwtAuth`). Opt-in because not every * BoondManager deployment is known to honour `exp`. */ export declare function buildJwt(userToken: string, clientToken: string, clientKey: string, options?: { expiresInSeconds?: number; nowSeconds?: number; }): string; export declare const JWT_HEADER_NAME = "X-Jwt-Client-Boondmanager"; export declare function initClient(): void; /** * True when env-based credentials (JWT components, API token, or BasicAuth) are * configured. Used by the HTTP transport in static-auth mode * (`BOOND_HTTP_STATIC_AUTH=true`) to fail fast with a readable message before * `initClient()` throws; the default HTTP mode is an OAuth2 protected resource * and never reads these variables. */ export declare function hasEnvCredentials(): boolean; /** * Install a custom auth provider — used by the HTTP transport bootstrap to * wire in an OAuth2 token source (where the access token is refreshed * transparently per request rather than baked in at startup). */ export declare function initClientWithAuth(auth: BoondAuthProvider, baseUrl?: string): void; /** Test helper — reset the cached config so the next call re-initialises. */ export declare function resetClientForTests(): void; /** The active configuration, initialising from the environment on first use. */ export declare function getConfig(): BoondConfig; //# sourceMappingURL=auth.d.ts.map