export type MintReuseResult = { status: "created"; token: string; } | { status: "reused"; token: string; } | { status: "mismatch"; }; /** * Default (non-force) mint: create-and-vault, reuse-if-authenticating, or * report a mismatch. NEVER rotates an existing token silently. The plaintext * token in the result is for the operator/env only — callers must not log it. */ export declare function stableMintOrReuse(name: string, role: string, capabilities: string[], opts?: { description?: string | null; }): Promise; /** * Explicit rotation (the `--force` path): rotate the DB token AND write the new * plaintext to the vault so the two halves stay in sync (pre-v2.16.1 the CLI * rotated the DB but never wrote the vault → the classic strand). Invalidates * the previous token by design. */ export declare function forceRotateAndVault(name: string, role: string, capabilities: string[], opts?: { description?: string | null; }): Promise<{ token: string; created: boolean; }>; //# sourceMappingURL=mint-reuse.d.ts.map