import { CloudEnvironment, Credentials, IToken, TokenProvider } from '@microsoft/teams.api';
import { ILogger } from '@microsoft/teams.common';
/**
 * Graph falls back to the multi-tenant `common` endpoint when no tenant is
 * known, unlike other scopes which fall back to the cloud's login tenant.
 */
export declare const DEFAULT_TENANT_FOR_GRAPH_TOKEN = "common";
export type TokenManagerOptions = {
    readonly clientId?: string;
    readonly clientSecret?: string;
    readonly tenantId?: string;
    readonly token?: TokenProvider;
    managedIdentityClientId?: 'system' | (string & {});
    readonly cloud?: CloudEnvironment;
};
export declare class TokenManager {
    readonly credentials?: Credentials;
    private logger;
    private _msalLogger;
    private cloud;
    private confidentialClientsByTenantId;
    private federatedIdentityClientsByTenantId;
    private agenticAppClientsByTenantAndAppId;
    private managedIdentityClient;
    constructor(options: TokenManagerOptions, logger: ILogger);
    getBotToken(): Promise<IToken | null>;
    getAppToken(scope: string, tenantId?: string): Promise<IToken | null>;
    getGraphToken(tenantId?: string): Promise<IToken | null>;
    /**
     * Acquires an Agentic User-scoped token.
     *
     * @param scope the scope to request the final token for.
     * @param agenticAppId the agentic app ID that owns the user.
     * @param agenticUserId the agentic user ID to act as.
     * @param tenantId the tenant to acquire the token in. Defaults to the tenant
     * configured on the credentials.
     * @returns the token, or `null` when the app has no credentials configured.
     */
    getAgenticUserToken(scope: string, agenticAppId: string, agenticUserId: string, tenantId?: string): Promise<IToken | null>;
    /**
     * Acquires an agentic app-scoped token.
     *
     * @param scope the scope to request the final token for.
     * @param agenticAppId the agentic app ID to act as.
     * @param tenantId the tenant to acquire the token in. Defaults to the tenant
     * configured on the credentials.
     * @returns the token, or `null` when the app has no credentials configured.
     */
    getAgenticAppToken(scope: string, agenticAppId: string, tenantId?: string): Promise<IToken | null>;
    /**
     * Rung 1 of the agentic token ladder: an ordinary confidential-client grant
     * for the app's own credentials, requesting the token exchange scope with an
     * `fmiPath` naming the agentic app.
     *
     * Returned as a callback rather than a token because MSAL resolves client
     * assertions lazily and re-invokes them when the assertion expires.
     */
    private blueprintAssertionFor;
    /**
     * Rung 2 of the agentic token ladder: a client-credentials grant made *as the
     * agentic app*, authenticated by the rung 1 blueprint assertion.
     *
     * Also returns the MSAL client so callers that need to climb to rung 3 can
     * reuse it instead of re-resolving it.
     */
    private acquireAgenticAppToken;
    private requireAgenticAppId;
    private requireAgenticUserId;
    private resolveAgenticTenantId;
    private requireClientCredentials;
    private initializeCredentials;
    private getToken;
    private getTokenWithClientCredentials;
    private getTokenWithTokenProvider;
    /**
     * Normalizes whatever a token provider returned into an `IToken`. `null` /
     * `undefined` pass through as `null`.
     */
    private toProviderToken;
    /**
     * Resolves a capability off a custom token provider, or throws when it is
     * missing rather than falling back under an identity the caller did not ask for.
     */
    private requireTokenProviderCapability;
    private getTokenWithManagedIdentity;
    private getTokenWithFederatedCredentials;
    private resolveTenantId;
    private getConfidentialClient;
    private getFederatedIdentityClient;
    private getAgenticAppClient;
    private getManagedIdentityClient;
    private handleTokenResponse;
    private getAccessTokenOrThrow;
    private buildLoggerOptions;
}
