import { z } from "zod"; import type { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js"; import type { RequestHandlerExtra } from "@modelcontextprotocol/sdk/shared/protocol.js"; import type { CallToolResult, ServerNotification, ServerRequest } from "@modelcontextprotocol/sdk/types.js"; import { type Policy, type PolicyMode } from "./policy.js"; export declare const CONFIRM_TTL_S = 120; /** Deterministic JSON: object keys sorted recursively, undefined dropped. */ export declare function canonicalJson(value: unknown): string; export declare function mintToken(tool: string, args: Record, device?: string | null, now?: number): string; export declare function verifyToken(token: string, tool: string, args: Record, device?: string | null, now?: number): boolean; export type TokenCheck = "ok" | "invalid" | "replayed"; /** Verify and spend in one step. `replayed` means the token was already used. */ export declare function consumeToken(token: string, tool: string, args: Record, device?: string | null, now?: number): TokenCheck; /** @internal vitest only — the registry outlives a single test otherwise. */ export declare function resetSpentTokens(): void; /** Output-schema fields a confirmation gate adds to any tool's result. */ export declare const CONFIRMATION_OUTPUT: { resultType: z.ZodOptional; confirmation: z.ZodOptional>; tool: z.ZodOptional; hint: z.ZodOptional; }; export type ConfirmationOutcome = { status: "approved"; } | { status: "declined"; } | { status: "token"; result: CallToolResult; }; export declare function requireConfirmation(server: McpServer, extra: RequestHandlerExtra, tool: string, args: Record, summary: string, device?: string | null): Promise; export declare function confirmationDeclined(tool: string): CallToolResult; export declare function policyDenied(tool: string, mode: PolicyMode): CallToolResult; /** * The single guard every tool callback runs first: * null → proceed; otherwise return the result as-is. */ export declare function enforce(server: McpServer, extra: RequestHandlerExtra, policy: Policy, tool: string, args: Record, summary: string, device?: string | null): Promise;