/** * License JWT fetch helpers — mints credentials for the **ENGINE-ACTION * surface** of the gateway (see `./auth-model.ts` for the full model). * * The engine (Reporter, Receiver, Retriever) takes a license JWT as * its credential — the helm chart's `log10xLicenseJwt` value, mounted * as a file at `TENX_LICENSE_FILE` inside the pod. The JWT is ES256- * signed by the Log10x backend and verified locally by the engine * against an embedded public key (no online check required at engine * startup). * * Two ways to mint one, both via the public gateway: * * - `POST /api/v1/license/demo` — public, no auth. Mints a 14-day * anonymous demo JWT bound to the demo tenant id. Used when the * MCP user hasn't signed in and wants to try an install. * * - `POST /api/v1/license` — Auth0 access token in `Authorization: * Bearer`. Mints a JWT bound to the caller's default-environment * tenant id. Idempotent — same license_id + same exp on repeat * calls within the trial window. * * **Important separation** — distinct from the api_key * (`LOG10X_API_KEY` / `X-10X-Auth`), which authenticates the MCP * against the user-action surface (`./api.ts`, `tenx_api_authorizer`). * The license JWT is engine-only: it flows into the helm values the * MCP emits, and from there into the engine pod's Kubernetes Secret. * The MCP itself never sends a license JWT on its own requests — those * routes (`/write`, `/agent/whoami`) belong to the engine. Conversely, * never send an api_key to `tenx_license_authorizer`-gated routes; * the authorizer will reject it. * * The Auth0-token → license JWT path exists specifically so MCP and * web-console tools can mint engine credentials directly from the * user's signin session, without needing the api_key as an intermediate. */ import './auth-model.js'; /** Common error class so callers can pattern-match on auth vs network. */ export declare class LicenseFetchError extends Error { readonly status?: number | undefined; constructor(message: string, status?: number | undefined); } export interface LicenseResult { /** The JWT itself, suitable for piping into helm `log10xLicenseJwt`. */ jwt: string; /** Unix epoch seconds when the JWT expires. Parsed from the JWT payload. */ expiresAtEpochSec?: number; /** License id from the JWT payload (when present). */ licenseId?: string; } /** * Fetch a 14-day anonymous demo license JWT. No auth required. Safe to * call from any context — including from a not-logged-in MCP session * that's been asked to produce an install plan. */ export declare function fetchDemoLicense(): Promise; /** * Return a usable demo license JWT, reusing the persisted one while it is * still valid and minting + persisting a fresh one otherwise. * * Both the install wizard (which hands the JWT to the engine via helm) and the * MCP query path (`environments.ts`, which reads back what the engine wrote via * `/api/v1/demo/*`) call this, so they share ONE demo identity — the engine * writes, and the MCP reads, the SAME demo tenant. Minting a fresh license each * time would point the MCP at an empty tenant the engine never wrote to. */ export declare function getOrMintDemoLicense(): Promise; /** * Fetch an authenticated user license JWT. The caller provides an Auth0 * access token (obtained via the device flow in `signin_*`). The minted * JWT is bound to the user's default environment. * * Re-issuance is idempotent: same `license_id` and `exp` on repeat calls * within the trial window. */ export declare function fetchUserLicense(auth0AccessToken: string): Promise; /** * Higher-level license acquisition for the install wizard. Routes between * the user-scoped and demo paths based on what credentials are on hand: * * 1. Signed in with a non-expired Auth0 access token → fetch user JWT * 2. Signed in with an expired access token + refresh token → refresh, * persist the new tokens, then fetch user JWT * 3. Signed in via pasted API key (no Auth0 tokens) → fall back to demo * JWT (we can't mint a user license without Auth0 credentials) * 4. Not signed in → fetch demo JWT * * Always returns *something* on success. Callers get `{ jwt, isDemoLicense, ... }` * and can render appropriate UI based on which path was taken. */ export interface AcquireLicenseResult extends LicenseResult { /** True when the demo endpoint was used (anonymous, 14-day). */ isDemoLicense: boolean; /** * Why this path was taken — surfaced in wizard output for transparency. * * User-scoped (`isDemoLicense: false`): * - 'signed-in-user' — Auth0 access token worked first try * - 'refreshed-then-user' — access token was stale, refresh succeeded * * Demo fallbacks (`isDemoLicense: true`) — distinguished so the wizard * can give the user the right next step (sign in via device flow, * retry, etc.) instead of a one-size-fits-all "you pasted your key" * message: * - 'not-signed-in' — no credentials on disk at all * - 'pasted-key-fallback' — API key present, but no Auth0 tokens * (sign-in was via pasted key) * - 'access-token-expired-no-refresh' — access token expired, no refresh token * to recover with (sign in again) * - 'refresh-failed' — refresh attempt errored (network or * Auth0 rejection) * - 'user-license-fetch-failed' — Auth0 worked, but /api/v1/license * errored (gateway issue) */ reason: 'signed-in-user' | 'refreshed-then-user' | 'not-signed-in' | 'pasted-key-fallback' | 'access-token-expired-no-refresh' | 'refresh-failed' | 'user-license-fetch-failed'; } export declare function acquireLicenseForWizard(): Promise;