/**
 * The same server over HTTP: the Streamable HTTP transport of MCP, stateless.
 *
 * `bin.ts` is a process a client starts on its own machine, and it reads who
 * it acts as from its environment. A server somebody reaches by URL is the
 * other shape: one process answers many people, so **who a request acts as
 * is decided per request**, by whatever put the server on the network — its
 * own sign-in, its own tokens — and handed in here as a connection. This
 * file knows nothing about how that host authenticates anybody. It takes a
 * request and the connection that request is allowed to use, and answers.
 *
 * ## Stateless, in JSON
 *
 * Each request builds a server, answers, and closes it. Nothing is kept
 * between two requests — no session id, no stream, no cache of whose books
 * were open — so a host can run it on a function platform, behind a load
 * balancer, or on one machine, and two people never share a thing. The
 * answers are plain JSON (`enableJsonResponse`): every tool of this server
 * answers once, and an open event stream would hold a connection for nothing.
 * A `GET` — the stream a client may open for messages the server sends on its
 * own — is answered `405`, which the protocol allows and which is the truth:
 * this server never speaks first.
 *
 * ## What a connection may be
 *
 *   - **A person's session on the instance**: the project address, its
 *     publishable key and an access token. Row level security decides, as it
 *     does for that person in a browser.
 *   - **A key of Ekwo OS**: the same two, and a key `create_api_key()` issued.
 *     It travels in `X-Ekwo-Api-Key`, the core's pre-request hook presents it
 *     (decision 0062), and the caller is on the key's one company with the
 *     key's capabilities.
 *   - **A backend already built**, for a host that reaches the database some
 *     other way — and for the tests, which run the real schema in PGlite.
 *
 * A `service_role` key is refused in every slot it could arrive in, as it is
 * on stdio: this server has no privilege of its own, over any transport.
 */
import type { IncomingMessage, ServerResponse } from 'node:http';
import { type Backend } from './backend.js';
/** Who one request acts as, over PostgREST. Exactly one of the two credentials. */
export interface HttpConnection {
    /** The project, `https://<ref>.supabase.co`. */
    supabaseUrl: string;
    /** Its publishable (anon) key. Never the `service_role` key. */
    anonKey: string;
    /** A person's access token on that project. */
    accessToken?: string | undefined;
    /** A key of Ekwo OS, issued on one company of that project. */
    apiKey?: string | undefined;
}
export interface HttpHandlerOptions {
    /**
     * The modules whose tools are offered. Left out, the database is asked on
     * every request that needs to know — a host that knows already, or caches
     * the answer, passes it and saves the round trip.
     */
    modules?: readonly string[] | undefined;
    /** The `fetch` the PostgREST backend uses. A host or a test may hand its own. */
    fetch?: typeof globalThis.fetch | undefined;
}
/**
 * Checks a connection and says what is wrong with it, without a network.
 *
 * The three refusals of `readConfig`, for a connection that did not come from
 * an environment: nothing to act as, two things to act as, and a
 * `service_role` key in any of the three slots.
 */
export declare function checkConnection(connection: HttpConnection): void;
/** The backend a connection describes. The caller closes it. */
export declare function openHttpBackend(connection: HttpConnection, options?: {
    fetch?: typeof globalThis.fetch | undefined;
}): Promise<Backend>;
/**
 * Answers one HTTP request of the MCP Streamable HTTP transport.
 *
 * `connection` is who this request acts as, decided by the host before it
 * calls this. Nothing about it is remembered once the response is built.
 */
export declare function handleHttpRequest(request: Request, connection: HttpConnection | Backend, options?: HttpHandlerOptions): Promise<Response>;
/**
 * The same handler for `node:http` (and anything built on it).
 *
 * The request is read into a web `Request`, answered by `handleHttpRequest`,
 * and the `Response` written back — one path, whichever server a host runs.
 * `origin` is the address this server is reached at, which `node:http` does
 * not know: `https://mcp.example.org`.
 */
export declare function handleNodeRequest(req: IncomingMessage, res: ServerResponse, connection: HttpConnection | Backend, options: HttpHandlerOptions & {
    origin: string;
}): Promise<void>;
//# sourceMappingURL=http.d.ts.map