/** * Auth0-token → **api_key** exchange — bootstraps the USER-ACTION * surface (see `./auth-model.ts` for the full model). * * Kept separate from `api.ts` because these are credential-exchange * calls that don't take a `LOG10X_API_KEY` (the goal IS to get one). * * Sibling: `./license-api.ts` does the Auth0-token → **license JWT** * exchange, which is the OTHER thing an Auth0 access token can mint. * Same source token (one Auth0 session), two different output credentials * for two different gateway surfaces. Don't conflate them. */ import './auth-model.js'; export interface SigninResponse { /** Long-lived Log10x API key. Persist this. */ api_key: string; /** User's email. The backend reads it from the Auth0 user record's * email attribute. May be empty if Auth0 didn't capture one * (e.g. a misconfigured social connection); the MCP should treat * empty as "no email" and continue. */ username: string; } /** * POST /api/v1/auth/token with an Auth0 access_token (issued via the * Device Authorization Flow against `auth.log10x.com`). The BE calls * Auth0's `/userinfo` to resolve the `sub`, then looks up the user * record via the Management API and returns the long-lived api_key * stored in `app_metadata.api_key`. * * The Auth0 access_token is single-use from the MCP's perspective: it is * not retained after this exchange. The api_key is what * authenticates every subsequent log10x call. */ export declare function exchangeAuth0TokenForApiKey(auth0AccessToken: string): Promise;