import type { OperationEvent, OperationWebhookConfig } from '../types/operations.js'; /** Header that carries a delivery's signature. */ declare const SIGNATURE_HEADER = "x-nexus-signature"; /** * Builds the signature for one delivery. * * The signed value is `${timestamp}.${body}` rather than the body alone, so a captured delivery * cannot be replayed indefinitely: a receiver checks the timestamp is recent and the signature * covers it, and an attacker cannot move the timestamp without invalidating the digest. */ export declare function signOperationWebhook(body: string, secret: string, timestampSeconds: number): string; /** Options for `verifyOperationWebhook()`. */ export interface VerifyOperationWebhookOptions { /** Maximum delivery age in seconds. Defaults to 300. */ toleranceSeconds?: number; /** Current time in seconds, for tests. */ nowSeconds?: number; } /** * Verifies a delivery signature. * * Exported because a receiver needs it: shipping the signing half without the verifying half * pushes every consumer into writing their own HMAC comparison, which is exactly the code most * likely to be written without a constant-time compare. */ export declare function verifyOperationWebhook(body: string, header: string | undefined, secret: string, options?: VerifyOperationWebhookOptions): boolean; /** * Delivers one operation event to a configured endpoint. * * Throws on a failed delivery so the caller can decide what to do. The runner reports the error * through `onWebhookError` and continues: a webhook that a receiver cannot accept must not turn a * successful operation into a failed one. */ export declare function deliverOperationWebhook(config: OperationWebhookConfig, event: OperationEvent, nowSeconds?: number): Promise; export { SIGNATURE_HEADER as OPERATION_WEBHOOK_SIGNATURE_HEADER };