import { TokenBucket } from "../rate-limiter.js"; export interface RateLimitConfig { rps: number; burst: number; } /** * Read rate-limit env vars. `rps` of 0 (or non-numeric) disables rate * limiting entirely. `burst` falls back to `rps * 2` when unset, mirroring * the documented default behaviour. Exported for unit testing. */ export declare function resolveRateLimitConfig(): RateLimitConfig | null; /** * Upper bound on live per-identity buckets. A bucket is a few numbers, so * 500 idle users cost nothing measurable; the cap exists so an attacker * cycling tokens cannot grow the map without bound. Eviction is LRU: an * evicted identity simply starts again with a full bucket. */ export declare const MAX_RATE_LIMIT_BUCKETS = 500; /** * The token bucket for the *current* caller (issue #232). * * One bucket per process was right for stdio (one user) and wrong for the * HTTP OAuth transport, where every request may belong to a different user: * a single client's burst throttled everyone else, and one buggy client * could hold the whole deployment at the rate limit. Buckets are keyed by * `currentAuthIdentity()` — `sha256(token)` in OAuth, the constant `env` * identity on stdio / static auth, so those keep exactly one bucket. * * Note this is fairness *between* users of the same server, not a change to * the ceiling BoondManager sees: `BOOND_HTTP_RATE_LIMIT_RPS` is per identity. */ export declare function getRateLimiter(): TokenBucket | null; /** Number of live per-identity buckets. Exposed for tests. */ export declare function rateLimiterBucketCountForTests(): number; /** * Reset the rate limiters so the next request re-reads env vars. * Intended for tests that toggle `BOOND_HTTP_RATE_LIMIT_*` between cases. */ export declare function resetRateLimiterForTests(): void; //# sourceMappingURL=rate-limit.d.ts.map