/** * Credential storage with a safety net. * * Every write of a credential file keeps the PREVIOUS one alongside it, so a * bad swap (or a token that turns out to be dead) can always be rolled back * instead of leaving an account permanently logged out. Combined with the * identity check below, this is what stops two profiles from silently ending up * on one login, and what stops a killed refresh from destroying a good account. */ export declare const CREDENTIALS_FILE = ".credentials.json"; /** * A short, comparable fingerprint of the login stored in `dir`, or null when * there is none. Used to tell whether a sign-in actually produced a NEW login, * which is the only reliable way to judge one: the browser step can fail while * the person finishes the sign-in by hand, and it can appear to succeed while * nothing was written. * * Never returns the token itself. */ export declare function credentialFingerprint(dir: string): string | null; /** * Identify a credential by the WHOLE FILE, not just its token. * * This is the key a recorded refusal is filed under, so any change to the file * retries rather than staying refused: being stuck costs a working login, and * re-asking costs one request. It must be the same function on both sides, or a * refusal is written under one key and looked up under another and nothing ever * matches, which is exactly what happened before this existed. */ export declare function credentialFileFingerprint(dir: string): string | null; export declare function credentialPath(dir: string): string; export declare function previousCredentialPath(dir: string): string; /** * True when the file actually carries a login, not merely the right shape. * * This distinction matters: when a session is logged out (or a token refresh * fails) Claude leaves a complete, valid-JSON credential whose token strings are * EMPTY. Treating that as a credential and saving it back over a stored account * destroys that login, which is exactly how an account here ended up with empty * tokens and no way back. * * Unrecognised shapes are accepted when they carry any non-empty value, so a * future change to Claude's credential format cannot make ccx refuse everything. */ export declare function isUsableCredential(file: string): boolean; /** * Whether a profile can actually run a session. * * The credential FILE existing is not the same as being signed in: a signed-out * profile keeps a complete file whose tokens are empty. Selecting such an * account starts a session that cannot work, and (worse) mis-reports the * failure as a usage limit. */ export declare function hasUsableLogin(dir: string): boolean; /** * The email a config dir is currently signed in as, or null. Claude keeps this * current for the session it is running, which makes it the reliable answer to * "who is this session actually logged in as right now". */ export declare function sessionIdentityEmail(configDir: string): string | null; /** * A stable identity fingerprint for a config dir's `.claude.json` (account uuid / * email / org), or null when it carries no identity. Used to notice that a * session became a DIFFERENT account (an interactive `/login`), which must never * be written back over the profile it started from. */ export declare function identityKey(configDir: string): string | null; /** * Install `sourceFile` as `dir`'s credential, keeping the existing one as the * previous generation. Refuses to install an unusable (empty/corrupt) source, * because overwriting a good login with garbage is the worst outcome. * Returns false when nothing was installed. */ export declare function installCredential(dir: string, sourceFile: string): boolean; /** * Restore the previous generation (used when a swap fails part-way). Returns * false when there is no usable backup to restore. */ export declare function rollbackCredential(dir: string): boolean; /** Remove a config dir's live credential (used to scrub a shared session dir). */ export declare function clearCredential(dir: string): void;