import { AtprotoDid, DidCache } from '@atproto-labs/did-resolver';
import { Fetch } from '@atproto-labs/fetch';
import { HandleCache, HandleResolver } from '@atproto-labs/handle-resolver';
import { IdentityResolver } from '@atproto-labs/identity-resolver';
import { Key, Keyset } from '@atproto/jwk';
import { OAuthClientIdDiscoverable, OAuthClientMetadata, OAuthClientMetadataInput, OAuthResponseMode } from '@atproto/oauth-types';
import { AuthorizationServerMetadataCache } from './oauth-authorization-server-metadata-resolver.js';
import { ProtectedResourceMetadataCache } from './oauth-protected-resource-metadata-resolver.js';
import { OAuthResolver } from './oauth-resolver.js';
import { DpopNonceCache, OAuthServerAgent } from './oauth-server-agent.js';
import { OAuthServerFactory } from './oauth-server-factory.js';
import { OAuthSession } from './oauth-session.js';
import { RuntimeImplementation } from './runtime-implementation.js';
import { Runtime } from './runtime.js';
import { SessionEventMap, SessionGetter, SessionStore } from './session-getter.js';
import { InternalStateData, StateStore } from './state-store.js';
import { AuthorizeOptions, ClientMetadata } from './types.js';
import { CustomEventTarget } from './util.js';
export type { AuthorizationServerMetadataCache, DidCache, DpopNonceCache, Fetch, HandleCache, HandleResolver, InternalStateData, Key, Keyset, OAuthClientMetadata, OAuthClientMetadataInput, OAuthResponseMode, ProtectedResourceMetadataCache, RuntimeImplementation, SessionStore, StateStore, };
export type OAuthClientOptions = {
    responseMode: OAuthResponseMode;
    clientMetadata: Readonly<OAuthClientMetadataInput>;
    keyset?: Keyset | Iterable<Key | undefined | null | false>;
    /**
     * Determines if the client will allow communicating with the OAuth Servers
     * (Authorization & Resource), or to retrieve "did:web" documents, over
     * unsafe HTTP connections. It is recommended to set this to `true` only for
     * development purposes.
     *
     * @note This does not affect the identity resolution mechanism, which will
     * allow HTTP connections to the PLC Directory (if the provided directory url
     * is "http:" based).
     * @default false
     * @see {@link OAuthProtectedResourceMetadataResolver.allowHttpResource}
     * @see {@link OAuthAuthorizationServerMetadataResolver.allowHttpIssuer}
     * @see {@link DidResolverCommonOptions.allowHttp}
     */
    allowHttp?: boolean;
    stateStore: StateStore;
    sessionStore: SessionStore;
    didCache?: DidCache;
    handleCache?: HandleCache;
    authorizationServerMetadataCache?: AuthorizationServerMetadataCache;
    protectedResourceMetadataCache?: ProtectedResourceMetadataCache;
    dpopNonceCache?: DpopNonceCache;
    handleResolver: HandleResolver | URL | string;
    plcDirectoryUrl?: URL | string;
    runtimeImplementation: RuntimeImplementation;
    fetch?: Fetch;
};
export type OAuthClientEventMap = SessionEventMap;
export type OAuthClientFetchMetadataOptions = {
    clientId: OAuthClientIdDiscoverable;
    fetch?: Fetch;
    signal?: AbortSignal;
};
export declare class OAuthClient extends CustomEventTarget<OAuthClientEventMap> {
    static fetchMetadata({ clientId, fetch, signal, }: OAuthClientFetchMetadataOptions): Promise<{
        redirect_uris: [`http://[::1]${string}` | "http://127.0.0.1" | `http://127.0.0.1#${string}` | `http://127.0.0.1?${string}` | `http://127.0.0.1/${string}` | `http://127.0.0.1:${string}` | `https://${string}` | `${string}.${string}:/${string}`, ...(`http://[::1]${string}` | "http://127.0.0.1" | `http://127.0.0.1#${string}` | `http://127.0.0.1?${string}` | `http://127.0.0.1/${string}` | `http://127.0.0.1:${string}` | `https://${string}` | `${string}.${string}:/${string}`)[]];
        response_types: ["code" | "none" | "token" | "code id_token token" | "code id_token" | "code token" | "id_token token" | "id_token", ...("code" | "none" | "token" | "code id_token token" | "code id_token" | "code token" | "id_token token" | "id_token")[]];
        grant_types: ["authorization_code" | "implicit" | "refresh_token" | "password" | "client_credentials" | "urn:ietf:params:oauth:grant-type:jwt-bearer" | "urn:ietf:params:oauth:grant-type:saml2-bearer", ...("authorization_code" | "implicit" | "refresh_token" | "password" | "client_credentials" | "urn:ietf:params:oauth:grant-type:jwt-bearer" | "urn:ietf:params:oauth:grant-type:saml2-bearer")[]];
        scope?: string | undefined;
        token_endpoint_auth_method?: "client_secret_basic" | "client_secret_jwt" | "client_secret_post" | "none" | "private_key_jwt" | "self_signed_tls_client_auth" | "tls_client_auth" | undefined;
        token_endpoint_auth_signing_alg?: string | undefined;
        userinfo_signed_response_alg?: string | undefined;
        userinfo_encrypted_response_alg?: string | undefined;
        jwks_uri?: `http://[::1]${string}` | "http://localhost" | `http://localhost#${string}` | `http://localhost?${string}` | `http://localhost/${string}` | `http://localhost:${string}` | "http://127.0.0.1" | `http://127.0.0.1#${string}` | `http://127.0.0.1?${string}` | `http://127.0.0.1/${string}` | `http://127.0.0.1:${string}` | `https://${string}` | undefined;
        jwks?: {
            keys: ({
                kty: "RSA";
                n: string;
                e: string;
                alg?: "RS256" | "RS384" | "RS512" | "PS256" | "PS384" | "PS512" | undefined;
                kid?: string | undefined;
                ext?: boolean | undefined;
                use?: "sig" | "enc" | undefined;
                key_ops?: ("sign" | "verify" | "encrypt" | "decrypt" | "wrapKey" | "unwrapKey" | "deriveKey" | "deriveBits")[] | undefined;
                x5c?: string[] | undefined;
                x5t?: string | undefined;
                "x5t#S256"?: string | undefined;
                x5u?: string | undefined;
                d?: string | undefined;
                p?: string | undefined;
                q?: string | undefined;
                dp?: string | undefined;
                dq?: string | undefined;
                qi?: string | undefined;
                oth?: [{
                    d?: string | undefined;
                    r?: string | undefined;
                    t?: string | undefined;
                }, ...{
                    d?: string | undefined;
                    r?: string | undefined;
                    t?: string | undefined;
                }[]] | undefined;
            } | {
                kty: "EC";
                crv: "P-256" | "P-384" | "P-521";
                x: string;
                y: string;
                alg?: "ES256" | "ES384" | "ES512" | undefined;
                kid?: string | undefined;
                ext?: boolean | undefined;
                use?: "sig" | "enc" | undefined;
                key_ops?: ("sign" | "verify" | "encrypt" | "decrypt" | "wrapKey" | "unwrapKey" | "deriveKey" | "deriveBits")[] | undefined;
                x5c?: string[] | undefined;
                x5t?: string | undefined;
                "x5t#S256"?: string | undefined;
                x5u?: string | undefined;
                d?: string | undefined;
            } | {
                kty: "EC";
                crv: "secp256k1";
                x: string;
                y: string;
                alg?: "ES256K" | undefined;
                kid?: string | undefined;
                ext?: boolean | undefined;
                use?: "sig" | "enc" | undefined;
                key_ops?: ("sign" | "verify" | "encrypt" | "decrypt" | "wrapKey" | "unwrapKey" | "deriveKey" | "deriveBits")[] | undefined;
                x5c?: string[] | undefined;
                x5t?: string | undefined;
                "x5t#S256"?: string | undefined;
                x5u?: string | undefined;
                d?: string | undefined;
            } | {
                kty: "OKP";
                crv: "Ed25519" | "Ed448";
                x: string;
                alg?: "EdDSA" | undefined;
                kid?: string | undefined;
                ext?: boolean | undefined;
                use?: "sig" | "enc" | undefined;
                key_ops?: ("sign" | "verify" | "encrypt" | "decrypt" | "wrapKey" | "unwrapKey" | "deriveKey" | "deriveBits")[] | undefined;
                x5c?: string[] | undefined;
                x5t?: string | undefined;
                "x5t#S256"?: string | undefined;
                x5u?: string | undefined;
                d?: string | undefined;
            } | {
                kty: "oct";
                k: string;
                alg?: "HS256" | "HS384" | "HS512" | undefined;
                kid?: string | undefined;
                ext?: boolean | undefined;
                use?: "sig" | "enc" | undefined;
                key_ops?: ("sign" | "verify" | "encrypt" | "decrypt" | "wrapKey" | "unwrapKey" | "deriveKey" | "deriveBits")[] | undefined;
                x5c?: string[] | undefined;
                x5t?: string | undefined;
                "x5t#S256"?: string | undefined;
                x5u?: string | undefined;
            } | {
                kty: string;
                alg?: string | undefined;
                kid?: string | undefined;
                ext?: boolean | undefined;
                use?: "sig" | "enc" | undefined;
                key_ops?: ("sign" | "verify" | "encrypt" | "decrypt" | "wrapKey" | "unwrapKey" | "deriveKey" | "deriveBits")[] | undefined;
                x5c?: string[] | undefined;
                x5t?: string | undefined;
                "x5t#S256"?: string | undefined;
                x5u?: string | undefined;
            })[];
        } | undefined;
        application_type?: "web" | "native" | undefined;
        subject_type?: "public" | "pairwise" | undefined;
        request_object_signing_alg?: string | undefined;
        id_token_signed_response_alg?: string | undefined;
        authorization_signed_response_alg?: string | undefined;
        authorization_encrypted_response_enc?: "A128CBC-HS256" | undefined;
        authorization_encrypted_response_alg?: string | undefined;
        client_id?: string | undefined;
        client_name?: string | undefined;
        client_uri?: `http://[::1]${string}` | "http://localhost" | `http://localhost#${string}` | `http://localhost?${string}` | `http://localhost/${string}` | `http://localhost:${string}` | "http://127.0.0.1" | `http://127.0.0.1#${string}` | `http://127.0.0.1?${string}` | `http://127.0.0.1/${string}` | `http://127.0.0.1:${string}` | `https://${string}` | undefined;
        policy_uri?: `http://[::1]${string}` | "http://localhost" | `http://localhost#${string}` | `http://localhost?${string}` | `http://localhost/${string}` | `http://localhost:${string}` | "http://127.0.0.1" | `http://127.0.0.1#${string}` | `http://127.0.0.1?${string}` | `http://127.0.0.1/${string}` | `http://127.0.0.1:${string}` | `https://${string}` | undefined;
        tos_uri?: `http://[::1]${string}` | "http://localhost" | `http://localhost#${string}` | `http://localhost?${string}` | `http://localhost/${string}` | `http://localhost:${string}` | "http://127.0.0.1" | `http://127.0.0.1#${string}` | `http://127.0.0.1?${string}` | `http://127.0.0.1/${string}` | `http://127.0.0.1:${string}` | `https://${string}` | undefined;
        logo_uri?: `http://[::1]${string}` | "http://localhost" | `http://localhost#${string}` | `http://localhost?${string}` | `http://localhost/${string}` | `http://localhost:${string}` | "http://127.0.0.1" | `http://127.0.0.1#${string}` | `http://127.0.0.1?${string}` | `http://127.0.0.1/${string}` | `http://127.0.0.1:${string}` | `https://${string}` | undefined;
        default_max_age?: number | undefined;
        require_auth_time?: boolean | undefined;
        contacts?: string[] | undefined;
        tls_client_certificate_bound_access_tokens?: boolean | undefined;
        dpop_bound_access_tokens?: boolean | undefined;
        authorization_details_types?: string[] | undefined;
    }>;
    readonly clientMetadata: ClientMetadata;
    readonly responseMode: OAuthResponseMode;
    readonly keyset?: Keyset;
    readonly runtime: Runtime;
    readonly fetch: Fetch;
    readonly oauthResolver: OAuthResolver;
    readonly serverFactory: OAuthServerFactory;
    protected readonly sessionGetter: SessionGetter;
    protected readonly stateStore: StateStore;
    constructor({ fetch, allowHttp, stateStore, sessionStore, didCache, dpopNonceCache, handleCache, authorizationServerMetadataCache, protectedResourceMetadataCache, responseMode, clientMetadata, handleResolver, plcDirectoryUrl, runtimeImplementation, keyset, }: OAuthClientOptions);
    get identityResolver(): IdentityResolver;
    get didResolver(): import("@atproto-labs/did-resolver").DidResolver<import("@atproto-labs/did-resolver").AtprotoIdentityDidMethods>;
    get handleResolver(): HandleResolver;
    get jwks(): {
        readonly keys: readonly ({
            readonly kty: "RSA";
            readonly n: string;
            readonly e: string;
            readonly alg?: "RS256" | "RS384" | "RS512" | "PS256" | "PS384" | "PS512" | undefined;
            readonly kid?: string | undefined;
            readonly ext?: boolean | undefined;
            readonly use?: "sig" | "enc" | undefined;
            readonly key_ops?: readonly ("sign" | "verify" | "encrypt" | "decrypt" | "wrapKey" | "unwrapKey" | "deriveKey" | "deriveBits")[] | undefined;
            readonly x5c?: readonly string[] | undefined;
            readonly x5t?: string | undefined;
            readonly 'x5t#S256'?: string | undefined;
            readonly x5u?: string | undefined;
            readonly d?: string | undefined;
            readonly p?: string | undefined;
            readonly q?: string | undefined;
            readonly dp?: string | undefined;
            readonly dq?: string | undefined;
            readonly qi?: string | undefined;
            readonly oth?: readonly [{
                readonly d?: string | undefined;
                readonly r?: string | undefined;
                readonly t?: string | undefined;
            }, ...{
                readonly d?: string | undefined;
                readonly r?: string | undefined;
                readonly t?: string | undefined;
            }[]] | undefined;
        } | {
            readonly kty: "EC";
            readonly crv: "P-256" | "P-384" | "P-521";
            readonly x: string;
            readonly y: string;
            readonly alg?: "ES256" | "ES384" | "ES512" | undefined;
            readonly kid?: string | undefined;
            readonly ext?: boolean | undefined;
            readonly use?: "sig" | "enc" | undefined;
            readonly key_ops?: readonly ("sign" | "verify" | "encrypt" | "decrypt" | "wrapKey" | "unwrapKey" | "deriveKey" | "deriveBits")[] | undefined;
            readonly x5c?: readonly string[] | undefined;
            readonly x5t?: string | undefined;
            readonly 'x5t#S256'?: string | undefined;
            readonly x5u?: string | undefined;
            readonly d?: string | undefined;
        } | {
            readonly kty: "EC";
            readonly crv: "secp256k1";
            readonly x: string;
            readonly y: string;
            readonly alg?: "ES256K" | undefined;
            readonly kid?: string | undefined;
            readonly ext?: boolean | undefined;
            readonly use?: "sig" | "enc" | undefined;
            readonly key_ops?: readonly ("sign" | "verify" | "encrypt" | "decrypt" | "wrapKey" | "unwrapKey" | "deriveKey" | "deriveBits")[] | undefined;
            readonly x5c?: readonly string[] | undefined;
            readonly x5t?: string | undefined;
            readonly 'x5t#S256'?: string | undefined;
            readonly x5u?: string | undefined;
            readonly d?: string | undefined;
        } | {
            readonly kty: "OKP";
            readonly crv: "Ed25519" | "Ed448";
            readonly x: string;
            readonly alg?: "EdDSA" | undefined;
            readonly kid?: string | undefined;
            readonly ext?: boolean | undefined;
            readonly use?: "sig" | "enc" | undefined;
            readonly key_ops?: readonly ("sign" | "verify" | "encrypt" | "decrypt" | "wrapKey" | "unwrapKey" | "deriveKey" | "deriveBits")[] | undefined;
            readonly x5c?: readonly string[] | undefined;
            readonly x5t?: string | undefined;
            readonly 'x5t#S256'?: string | undefined;
            readonly x5u?: string | undefined;
            readonly d?: string | undefined;
        } | {
            readonly kty: "oct";
            readonly k: string;
            readonly alg?: "HS256" | "HS384" | "HS512" | undefined;
            readonly kid?: string | undefined;
            readonly ext?: boolean | undefined;
            readonly use?: "sig" | "enc" | undefined;
            readonly key_ops?: readonly ("sign" | "verify" | "encrypt" | "decrypt" | "wrapKey" | "unwrapKey" | "deriveKey" | "deriveBits")[] | undefined;
            readonly x5c?: readonly string[] | undefined;
            readonly x5t?: string | undefined;
            readonly 'x5t#S256'?: string | undefined;
            readonly x5u?: string | undefined;
        } | {
            readonly kty: string;
            readonly alg?: string | undefined;
            readonly kid?: string | undefined;
            readonly ext?: boolean | undefined;
            readonly use?: "sig" | "enc" | undefined;
            readonly key_ops?: readonly ("sign" | "verify" | "encrypt" | "decrypt" | "wrapKey" | "unwrapKey" | "deriveKey" | "deriveBits")[] | undefined;
            readonly x5c?: readonly string[] | undefined;
            readonly x5t?: string | undefined;
            readonly 'x5t#S256'?: string | undefined;
            readonly x5u?: string | undefined;
        })[];
    };
    authorize(input: string, { signal, ...options }?: AuthorizeOptions): Promise<URL>;
    /**
     * This method allows the client to proactively revoke the request_uri it
     * created through PAR.
     */
    abortRequest(authorizeUrl: URL): Promise<void>;
    callback(params: URLSearchParams): Promise<{
        session: OAuthSession;
        state: string | null;
    }>;
    /**
     * Load a stored session. This will refresh the token only if needed (about to
     * expire) by default.
     *
     * @param refresh See {@link SessionGetter.getSession}
     */
    restore(sub: string, refresh?: boolean | 'auto'): Promise<OAuthSession>;
    revoke(sub: string): Promise<void>;
    protected createSession(server: OAuthServerAgent, sub: AtprotoDid): OAuthSession;
}
//# sourceMappingURL=oauth-client.d.ts.map