/** * OAuth 2.1 provider for MCP remote transport. * Uses Discord as upstream IdP, gates on VIP role. */ import type { Response } from "express"; import type { Pool } from "pg"; import type { OAuthServerProvider, AuthorizationParams } from "@modelcontextprotocol/sdk/server/auth/provider.js"; import type { OAuthRegisteredClientsStore } from "@modelcontextprotocol/sdk/server/auth/clients.js"; import type { OAuthClientInformationFull, OAuthTokenRevocationRequest, OAuthTokens } from "@modelcontextprotocol/sdk/shared/auth.js"; import type { AuthInfo } from "@modelcontextprotocol/sdk/server/auth/types.js"; export declare class PostgresClientsStore implements OAuthRegisteredClientsStore { private pool; constructor(pool: Pool); getClient(clientId: string): Promise; registerClient(clientData: OAuthClientInformationFull): Promise; } export declare class ElevateOAuthProvider implements OAuthServerProvider { private pool; private _clientsStore; constructor(pool: Pool); get clientsStore(): OAuthRegisteredClientsStore; /** * Step 1: Redirect user to Discord OAuth. * We store the MCP auth params so we can complete the flow after Discord callback. */ authorize(client: OAuthClientInformationFull, params: AuthorizationParams, res: Response): Promise; /** * Returns the code_challenge stored during authorize. */ challengeForAuthorizationCode(client: OAuthClientInformationFull, authorizationCode: string): Promise; /** * Exchange auth code for tokens. */ exchangeAuthorizationCode(client: OAuthClientInformationFull, authorizationCode: string): Promise; /** * Exchange refresh token for new access token (with refresh token rotation). */ exchangeRefreshToken(client: OAuthClientInformationFull, refreshToken: string): Promise; /** * Verify access token → return AuthInfo with discord_id. */ verifyAccessToken(token: string): Promise; /** * Revoke a token. */ revokeToken(client: OAuthClientInformationFull, request: OAuthTokenRevocationRequest): Promise; /** * Check if a Discord user has the VIP/API role. * Uses a bot token to query guild membership. */ private checkDiscordRole; } /** * Handles the Discord OAuth callback after user logs in. * Verifies role, creates MCP auth code, redirects back to Claude. */ export declare function handleDiscordCallback(pool: Pool, code: string, state: string, res: Response): Promise;