/** * HTTP client for the TracePass v1 API, used by the MCP tools. * * Design decision — why the MCP tools talk to the v1 API over HTTP * rather than calling `lib/` functions in-process: * - The v1 route handlers already encapsulate API-key auth, * idempotency, the overage (402) flow, plan-gating, and the * per-day write/read counter bumps. Re-implementing that inside * the MCP tools would inevitably drift from the routes. * - It is the SAME code path the standalone npm package will use, * so the MCP core is genuinely transport-agnostic — the hosted * /mcp endpoint and the local npm package differ only in base * URL and where the key comes from. * - One bug surface, not two. * The cost is a loopback HTTP hop when hosted — negligible. * * The client is intentionally thin: it forwards the Bearer key, * sets Idempotency-Key on writes, and returns the parsed JSON plus * the status code. Interpreting a 402 overage / 403 plan-gate / * 429 rate-limit is the tool's job — those are meaningful results an * AI agent must see and act on, not errors to swallow. */ /** Value sent in the `X-Source` header on every request, so the TracePass * request log can attribute v1 traffic to this client (vs n8n / raw api). */ export declare const SOURCE_TAG = "mcp"; export interface TracePassApiResponse { /** HTTP status code. */ status: number; /** `true` for 2xx. */ ok: boolean; /** Parsed JSON body, or null when the body was empty / not JSON. */ body: unknown; } export interface TracePassClientConfig { /** Base URL of the TracePass app, no trailing slash — * e.g. "https://app.tracepass.eu". */ baseUrl: string; /** The caller's tp_ API key. */ apiKey: string; } export declare class TracePassClient { private readonly baseUrl; private readonly apiKey; constructor(config: TracePassClientConfig); /** * Perform a v1 API request. * * @param method HTTP method * @param path path under the base URL, must start with "/" * @param body JSON body for write methods (omitted for GET) * * Write methods automatically carry an `Idempotency-Key` header so * a retried tool call doesn't double-execute. Never throws on a * non-2xx response — the status + body come back for the tool to * interpret. Throws only on a genuine network/transport failure. */ request(method: "GET" | "POST" | "PATCH" | "DELETE", path: string, body?: unknown): Promise; get(path: string): Promise; post(path: string, body?: unknown): Promise; patch(path: string, body?: unknown): Promise; delete(path: string): Promise; } //# sourceMappingURL=api-client.d.ts.map