import type { RegisterAgentInput, DiscoverAgentsInput, UnregisterAgentInput, AbandonRegistrationInput, RotateTokenInput, RotateTokenAdminInput, RevokeTokenInput, ExpandCapabilitiesInput } from "../types.js"; export declare function handleRegisterAgent(input: RegisterAgentInput): { content: { type: "text"; text: string; }[]; isError: boolean; } | { content: { type: "text"; text: string; }[]; isError?: undefined; }; export declare function handleUnregisterAgent(input: UnregisterAgentInput): { content: { type: "text"; text: string; }[]; }; /** * ADR-0005 — abandon_registration: self-serve cleanup of the caller's OWN * orphaned registration via the one-time registration-recovery handle (NOT the * lost agent_token). No auth token required — the handle is the proof, and the * keystone (only-never-authed rows) makes it safe by construction. See * db.abandonRegistration. */ export declare function handleAbandonRegistration(input: AbandonRegistrationInput): { isError?: boolean | undefined; content: { type: "text"; text: string; }[]; }; /** * v2.1 Phase 4b.1 — rotate the caller's own token. Dispatcher auth already * verified `agent_token` matches `agent_name`'s current bcrypt hash; so we * can safely read the hash, CAS-swap it, and return the fresh plaintext. * CAS protects against concurrent rotate / revoke races. */ export declare function handleRotateToken(input: RotateTokenInput): { content: { type: "text"; text: string; }[]; isError: boolean; } | { content: { type: "text"; text: string; }[]; isError?: undefined; }; /** * v2.1 Phase 4b.2 — admin-initiated cross-agent token rotation. Dispatcher * has already cap-checked `rotate_others` on the rotator. This handler * rejects self-rotation (use `rotate_token` instead), looks up the target's * `managed` flag, and dispatches to db.ts's `rotateAgentTokenAdmin`. Response * shape mirrors `handleRotateToken`: managed → grace + push-message to * target; unmanaged → new token returned to ROTATOR + restart_required. */ export declare function handleRotateTokenAdmin(input: RotateTokenAdminInput): { content: { type: "text"; text: string; }[]; isError: boolean; } | { content: { type: "text"; text: string; }[]; isError?: undefined; }; /** * v2.1 Phase 4b.1 — nullify another agent's token_hash. Dispatcher has * already verified revoker holds the `admin` capability. Target falls into * the legacy-null-hash state; plain `register_agent` re-bootstraps via * Phase 2b's migration path. */ export declare function handleRevokeToken(input: RevokeTokenInput): { content: { type: "text"; text: string; }[]; isError: boolean; } | { content: { type: "text"; text: string; }[]; isError?: undefined; }; export declare function handleDiscoverAgents(input: DiscoverAgentsInput): { content: { type: "text"; text: string; }[]; }; /** * v2.1.4 (I11) — self-managed additive cap expansion. * * Dispatcher has already authenticated the caller by token (no explicit caller * field → token-resolution path) AND verified `agent_name` matches the authed * row (the explicit `agent_name` field routes through enforceAuth's * explicit-caller branch). That means by the time we're in the handler, the * caller proved they own the row. All that remains is the additive-only + * no-op policy, which lives in `expandAgentCapabilities`. */ export declare function handleExpandCapabilities(input: ExpandCapabilitiesInput): { content: { type: "text"; text: string; }[]; isError?: undefined; } | { content: { type: "text"; text: string; }[]; isError: boolean; }; //# sourceMappingURL=identity.d.ts.map