import './auth-model.js'; export interface Credentials { /** Long-lived Log10x API key minted by the BE. */ apiKey: string; /** ISO-8601 timestamp when these credentials were written. */ signedInAt?: string; /** * Auth0 access token retained from the device-flow signin. Needed by * the install wizard to mint a user-scoped license JWT via * `POST /api/v1/license` (which only accepts Bearer Auth0 tokens, not * the Log10x API key). Absent on the pasted-API-key signin path — * the wizard falls back to the anonymous demo license in that case. */ auth0AccessToken?: string; /** * Auth0 refresh token. The device flow asks for the `offline_access` * scope, so one is always issued. Used to refresh the access token when it * expires (typically 24h) without forcing the user to re-sign in. */ auth0RefreshToken?: string; /** ISO-8601 expiry of `auth0AccessToken`. */ auth0AccessTokenExpiresAt?: string; } /** * Read the saved credentials. Returns `null` when the file is missing * (the common case on a fresh machine) — callers should treat that as * "not signed in" rather than an error. * * Throws on other I/O errors (permission denied, malformed JSON) so a * misconfigured machine fails loudly instead of silently downgrading * to demo. */ export declare function readCredentials(): Promise; /** * Write credentials to disk with restrictive permissions. Creates the * parent directory if missing. */ export declare function writeCredentials(c: Credentials): Promise; /** * Delete the credentials file. Idempotent: returns `false` if the file * was already absent, `true` if it was actually removed. */ export declare function clearCredentials(): Promise; /** Exposed for diagnostics / status messages. */ export declare function getCredentialsPath(): string;