export interface IdentityFinding { account: string; /** The email the registry expects for this profile. */ expected?: string; /** Who the stored token actually belongs to. */ actual?: string; kind: 'ok' | 'mismatch' | 'duplicate' | 'logged-out' | 'unknown'; detail: string; } export interface CheckableAccount { name: string; dir: string; email?: string; } /** * Ask the API which account the credential stored in `dir` belongs to. This is * the only authoritative answer: local files report the identity a profile has * recorded, which can already be wrong. */ export declare function fetchTokenOwner(dir: string, fetchImpl?: typeof fetch): Promise; /** * Check every profile: is it logged in, does its token belong to the expected * account, and are two profiles on the same account? Sequential on purpose, to * stay friendly to the endpoint. * * Scope: this reports duplicate OWNERSHIP only. Whether renewing one profile * would destroy another's login is a different question, answered by comparing * refresh tokens in duplicate-guard, because two profiles can reach one account * through separate logins. */ export declare function verifyAccountIdentities(accounts: CheckableAccount[], fetchImpl?: typeof fetch): Promise;