/** * `grants` namespace — per-project capability grants and the grant keys minted * against them. * * A grant is the permission row (this principal may do this capability on this * project until this date). A grant key is a credential minted against exactly * one grant: narrower than it, spend-capped, expiring, revocable on its own, * never an owner. An agent with its own wallet needs only the grant (it signs * via SIWX); an agent without one gets a grant key. * * The practical reason keys exist on the client: project API keys are * stateless JWTs handed out once at create and never re-issued, so an agent * that loses local state has no way back into its own project. The owner still * holds a wallet, and SIWX is enough to mint a fresh grant key. * * Every call requires the caller to be an active owner of the project's org. * Exposed both unscoped (`r.grants.create(projectId, …)`) and project-scoped * (`r.project(id).grants.create(…)`), mirroring `r.functions` / `r.jobs`. */ import type { Client } from "../kernel.js"; import type { CreateGrantInput, GrantCreateResult, GrantKeyCreateResult, GrantKeyInput, GrantKeyRevokeResult, GrantKeyRotateResult, GrantListResult, GrantRevokeResult } from "./grants.types.js"; export declare class Grants { private readonly client; constructor(client: Client); /** * Issue a capability grant to a wallet for a project * (`POST /projects/v1/:project_id/grants`). With `key`, also mints the * grant's first grant key in the same transaction; its `key.token` is * returned **once** — persist it immediately, or rotate for a new one. */ create(projectId: string, input: CreateGrantInput): Promise; /** * List a project's grants with their grant keys nested * (`GET /projects/v1/:project_id/grants`). Never returns a token or any * secret material. */ list(projectId: string): Promise; /** * Revoke a capability grant and every grant key minted against it * (`DELETE /projects/v1/:project_id/grants/:grant_id`). */ revoke(projectId: string, grantId: string): Promise; /** * Mint another grant key against an existing grant * (`POST /projects/v1/:project_id/grants/:grant_id/keys`). `key.token` is * returned **once**. */ createKey(projectId: string, grantId: string, input?: GrantKeyInput): Promise; /** * Revoke one grant key (`DELETE /projects/v1/:project_id/grant-keys/:key_id`). * The grant and its other keys stay. */ revokeKey(projectId: string, keyId: string): Promise; /** * Replace a grant key (`POST /projects/v1/:project_id/grant-keys/:key_id/rotate`): * revokes it and mints a fresh one against the same grant with the same * kind, scope, cap and expiry. The new `key.token` is returned **once**. */ rotateKey(projectId: string, keyId: string): Promise; } //# sourceMappingURL=grants.d.ts.map