/**
 * Auth Client
 *
 * Implements the authentication cascade for Arch MCP tools:
 *   1. Explicit token (if provided)
 *   2. Stored credentials (~/.config/kore-platform/credentials)
 *   3. Device authorization flow (RFC 8628)
 *      - Auto-launches browser
 *      - Polls in a single call (no two-phase handshake)
 *      - Persists credentials on success
 */
import type { HttpClient } from "./http-client.js";
import type { WebSocketClient } from "./websocket-client.js";
export interface AuthResult {
    token: string;
    method: "explicit_token" | "stored_credentials" | "device_auth" | "device_auth_pending";
    message?: string;
    /** Present when method is 'device_auth_pending' — pass back to complete auth */
    deviceCode?: string;
    /** Verification URL for the user to visit */
    verificationUrl?: string;
    /** User-friendly code to display */
    userCode?: string;
    /** Refresh token returned by device auth; persisted but never exposed by tools. */
    refreshToken?: string;
    /** Access-token lifetime returned by the auth server. */
    expiresIn?: number;
}
export interface AuthOptions {
    /** Explicit token to use directly */
    authToken?: string;
    /** Skip stored credentials check */
    skipStoredCredentials?: boolean;
    /** Device code from a previous initiation — skip straight to polling */
    deviceCode?: string;
    /** Max time to poll for device auth completion (default: 60s) */
    pollTimeoutMs?: number;
}
/**
 * Authenticate using the cascade:
 *   explicit token → stored credentials → device auth
 *
 * Sets the token on both HTTP and WS clients on success.
 */
export declare function authenticate(httpClient: HttpClient, wsClient: WebSocketClient, options?: AuthOptions): Promise<AuthResult>;
export declare class DeviceAuthError extends Error {
    constructor(message: string);
}
//# sourceMappingURL=auth-client.d.ts.map