/** * log10x_rotate_api_key — destructive: replace the user's Log10x API * key with a freshly-minted one via `POST /api/v1/user/rotate-key`. * * Backend handler: backend/lambdas/user-service-go/cmd/user/main.go * (handleRotateKey). Documented at mksite/docs/api/manage.md * "Rotate API Key". * * What this tool does on success (in order): * 1. POST to the BE → get back `{ user, api_key: }`. The * previous key is invalidated immediately on the server side. * 2. Write the new key to `~/.log10x/credentials` (overwriting any * existing entry) so other MCP hosts on the same machine pick it * up next time they read. * 3. Update `process.env.LOG10X_API_KEY` in this process so the * file path takes precedence on the next reload (mirrors the * symmetric env-var-clear pattern signin/signout already do). * 4. Reload envs in-place so the next tool call uses the new key * seamlessly — no MCP-host restart needed for THIS server. * * What it does NOT do: * - Revoke the old key on other machines / hosts. Other devices * holding the old key will start receiving 401 on the next * request. They need to be updated manually (or rotate again * from there). * - Edit the user's MCP host config files (claude_desktop_config.json * etc.). The new key is in `process.env.LOG10X_API_KEY` for this * session, but on next host restart, whatever the host config * specifies will be re-injected. The result message tells the * user to also update their host config to make the rotation * stick across restarts. * * Confirm pattern: the caller must pass the literal string * `rotate-now` to proceed. Prevents an LLM from accidentally rotating * via a chained tool call without explicit user assent. * * Demo accounts: the backend returns 403 Forbidden, surfaced cleanly. */ import { z } from 'zod'; import type { Environments } from '../lib/environments.js'; import { type StructuredOutput } from '../lib/output-types.js'; export declare const rotateApiKeySchema: { confirm: z.ZodLiteral<"rotate-now">; }; export declare function executeRotateApiKey(args: { confirm: 'rotate-now'; }, envs: Environments): Promise;