/** * Central secret vault: named secrets stored ONCE, referenced by profiles. * Stored OUTSIDE any repo at ~/.shadok-ai/secrets.json (600) and injected as * environment variables into an agent's `claude` process at spawn — never * written into the working directory. A flat `{ NAME: value }` map; a profile * lists the NAMES it wants injected (see profiles.ts). */ export type Vault = Record; /** * Normalize a parsed secrets.json into a flat vault. Migrates the old per-repo * shape (`{ "": { NAME: value } }`) by flattening every repo's entries * into the single vault (last value wins on a name collision). */ export declare function normalizeVault(raw: unknown): Vault; export type SecretWrite = "created" | "updated" | "refused"; /** * Pure: what a write to `name` should do. Overwriting is the only destructive * move the vault allows — it replaces a live credential and leaves no trace, * and the vault keeps no history to undo it. So it takes an explicit intent, * which the human surfaces carry and a machine does not. */ export declare function secretWriteVerdict(exists: boolean, overwrite: boolean): SecretWrite; export declare function loadVault(): Vault; export declare function saveVault(v: Vault): void; /** All secret names (never the values), sorted. */ export declare function secretNames(): string[]; export declare function setSecret(name: string, value: string): void; export declare function deleteSecret(name: string): void; /** The `{ NAME: value }` env for a set of referenced names (unknown ones skipped). */ export declare function secretsFor(names: string[] | undefined): Record;