/** * Retrieve the stored secret for the given agent. * Tries OS keyring first, then encrypted file fallback. * Returns null if nothing is stored. */ export declare function getSecret(agentId: string): string | null; /** * Store a secret for the given agent. Writes to OS keyring and/or * encrypted file (both, so the file serves as a cross-platform fallback). */ export declare function setSecret(agentId: string, secret: string): void; /** * Delete a stored secret for the given agent. */ export declare function deleteSecret(agentId: string): void; /** * One-time migration: move a plaintext key from config.json into the * secret store and return the keyRef to write into config. */ export declare function migratePlaintextKey(agentId: string, plaintextKey: string): string; /** * Returns the secret store backend name for diagnostics. */ export declare function secretStoreBackend(): 'keyring' | 'encrypted-file';