import pino from "pino"; /** * Redaction paths for the structured logger. Defence-in-depth: nothing in the * codebase currently logs auth material, but if a request/error object that * carries credentials is ever passed to the logger, these paths censor it * before it reaches stderr / a log aggregator. Covers the BoondManager JWT * header, OAuth Bearer headers, and raw access tokens at one level of nesting. */ export declare const REDACT_PATHS: string[]; /** * File descriptor every log line is written to: **stderr, on every transport**. * * On the stdio transport stdout *is* the JSON-RPC channel — anything that is * not an MCP message corrupts the stream and the client drops the connection. * Pino defaults to fd 1, and so does the pino-pretty transport when no * `destination` is given, which is exactly how the "Access policy active" * line, the update notice and the dictionary-override warnings used to land in * the middle of the protocol (issue #225). stderr is what Claude Desktop * captures into its log viewer, and it is equally fine for the HTTP transport, * so there is one destination rather than one per transport. */ export declare const LOG_DESTINATION_FD = 2; /** * Read the log level from env, falling back to 'info' for production-friendly * defaults. DEBUG / trace logs are useful during development but too noisy * in production. Pino's level hierarchy: trace < debug < info < warn < error < fatal. */ export declare function resolveLogLevel(env?: NodeJS.ProcessEnv): pino.Level; /** Human-readable (pretty) output in dev, JSON in prod. Override via LOG_FORMAT. */ export declare function usePrettyOutput(env?: NodeJS.ProcessEnv): boolean; /** * `pino-pretty` is a **devDependency** (issue #246): it only serves the * human-readable output of a development shell, and the `.mcpb` bundle and * the Docker image are built with `--omit=dev`. Pino loads a transport by * module name in a worker thread and throws at logger creation when the * target is missing, so the pretty branch is taken only when the module * resolves — otherwise the logger silently falls back to JSON on stderr, * which is the production shape anyway. */ export declare function isPrettyTransportAvailable(): boolean; export type LoggerConfig = { format: "pretty"; options: pino.LoggerOptions & { transport: pino.TransportSingleOptions; }; } | { format: "json"; options: pino.LoggerOptions; destinationFd: number; }; /** * The two shapes the logger can take, as data — so a test can assert where each * one writes without spawning a process. Pino refuses a stream argument when * `transport` is set (the transport runs in a worker thread), which is why the * destination travels inside the pino-pretty options on one branch and as a * `pino.destination()` on the other. */ export declare function resolveLoggerConfig(env?: NodeJS.ProcessEnv, prettyAvailable?: boolean): LoggerConfig; export declare function createLogger(env?: NodeJS.ProcessEnv): pino.Logger; /** * Centralized structured logger. Use this instead of console.log/error for * all application logging — it provides timestamps, levels, and JSON output * (when LOG_FORMAT=json) that plays nicely with log aggregators. It always * writes to stderr (see `LOG_DESTINATION_FD`). * * Example: * logger.info({ sessionId: "abc", userId: 123 }, "Session initialized"); * logger.error({ err, endpoint: "/mcp" }, "HTTP transport error"); */ export declare const logger: pino.Logger; /** * Generate a short correlation ID (8 hex chars) for tracing a single request * through the stack (HTTP handler → tool call → API request). Attach it to * logger child contexts so every log line from that request shares the ID. */ export declare function generateCorrelationId(): string; //# sourceMappingURL=logger.d.ts.map