import * as z from "zod/v3";
import { ClosedEnum } from "../types/enums.js";
import { Result as SafeParseResult } from "../types/fp.js";
import { SDKValidationError } from "./sdkvalidationerror.js";
export type GetKmsIssuerRequest = {
    /**
     * The ID of the issuer.
     */
    issuerId: string;
    /**
     * The Team identifier to perform the request on behalf of.
     */
    teamId?: string | undefined;
    /**
     * The Team slug to perform the request on behalf of.
     */
    slug?: string | undefined;
};
export declare const GetKmsIssuerAlgorithm: {
    readonly Es256: "ES256";
    readonly Es384: "ES384";
    readonly Es512: "ES512";
    readonly EdDSA: "EdDSA";
    readonly Ps256: "PS256";
    readonly Ps384: "PS384";
    readonly Ps512: "PS512";
    readonly Rs256: "RS256";
    readonly Rs384: "RS384";
    readonly Rs512: "RS512";
};
export type GetKmsIssuerAlgorithm = ClosedEnum<typeof GetKmsIssuerAlgorithm>;
export declare const GetKmsIssuerOrigin: {
    readonly External: "external";
    readonly Vercel: "vercel";
};
export type GetKmsIssuerOrigin = ClosedEnum<typeof GetKmsIssuerOrigin>;
export declare const GetKmsIssuerStatus: {
    readonly Active: "active";
    readonly Pending: "pending";
    readonly Revoking: "revoking";
};
export type GetKmsIssuerStatus = ClosedEnum<typeof GetKmsIssuerStatus>;
export type GetKmsIssuerPublicKey = {
    kty?: string | undefined;
    kid?: string | undefined;
    alg?: string | undefined;
    use?: string | undefined;
    keyOps?: Array<string> | undefined;
    /**
     * The X.509 certificate chain (RFC 7517 §4.7). Each entry is the base64 DER (not base64url) of a certificate. For keys minted with a stored certificate this holds the single self-signed cert as `[x5c]`.
     */
    x5c?: Array<string> | undefined;
    /**
     * The base64url SHA-256 thumbprint of the DER certificate in `x5c[0]` (RFC 7517 §4.9).
     */
    x5tNumberS256?: string | undefined;
};
export type GetKmsIssuerSigningKeys = {
    /**
     * The server-minted, unique record identifier. Use this to address the key on the activate / certificate endpoints.
     */
    keyId: string;
    /**
     * The caller-supplied key id (imported keys only), used as the JWT/JWKS `kid`. Not unique across an issuer's keys; omitted for generated keys.
     */
    importKeyId?: string | undefined;
    issuerId: string;
    algorithm: string;
    status: GetKmsIssuerStatus;
    publicKey?: GetKmsIssuerPublicKey | undefined;
    publicKeyFingerprint?: string | undefined;
    /**
     * The public key in SPKI PEM form, ready to render. Present whenever the key has public key material. Derived from `publicKey`; the embedded certificate members (`x5c`/`x5t#S256`) do not affect it.
     */
    publicKeyPem?: string | undefined;
    /**
     * The stored X.509 certificate (from `publicKey.x5c[0]`) in PEM form, ready to render. Present only for keys created with a stored certificate; omitted for keys created before certificates were stored.
     */
    certificatePem?: string | undefined;
    createdAt: string;
    updatedAt: string;
    revokeAt?: string | undefined;
    activateAt?: string | undefined;
    /**
     * When the key became the active signer. Present for active and revoking keys (and absent for pending keys and rows predating this field).
     */
    activatedAt?: string | undefined;
};
export type GetKmsIssuerPolicies2 = {
    kind: "connex-grant";
    clientId: string;
    tokenClaims?: {
        [k: string]: any;
    } | undefined;
    createdAt: string;
    updatedAt: string;
};
export type GetKmsIssuerPolicies1 = {
    kind: "project-grant";
    teamId: string;
    projectId: string;
    /**
     * Environments whose OIDC tokens this grant authorizes. Each entry is either a system environment slug (`production`, `preview`, `development`) or a custom environment ID (prefixed `env_`). Custom environments are matched against the token's `custom_environment_id` claim (the stable ID); system environments against its `environment` claim.
     */
    environments: Array<string>;
    tokenClaims?: {
        [k: string]: any;
    } | undefined;
    createdAt: string;
    updatedAt: string;
};
export type GetKmsIssuerPolicies = GetKmsIssuerPolicies1 | GetKmsIssuerPolicies2;
export type GetKmsIssuerResponseBody = {
    id: string;
    ownerId: string;
    name: string;
    algorithm: GetKmsIssuerAlgorithm;
    origin: GetKmsIssuerOrigin;
    managedBy?: string | undefined;
    claimsSchema?: {
        [k: string]: any;
    } | undefined;
    createdAt: string;
    updatedAt: string;
    signingKeys: Array<GetKmsIssuerSigningKeys>;
    policies: Array<GetKmsIssuerPolicies1 | GetKmsIssuerPolicies2>;
};
/** @internal */
export type GetKmsIssuerRequest$Outbound = {
    issuerId: string;
    teamId?: string | undefined;
    slug?: string | undefined;
};
/** @internal */
export declare const GetKmsIssuerRequest$outboundSchema: z.ZodType<GetKmsIssuerRequest$Outbound, z.ZodTypeDef, GetKmsIssuerRequest>;
export declare function getKmsIssuerRequestToJSON(getKmsIssuerRequest: GetKmsIssuerRequest): string;
/** @internal */
export declare const GetKmsIssuerAlgorithm$inboundSchema: z.ZodNativeEnum<typeof GetKmsIssuerAlgorithm>;
/** @internal */
export declare const GetKmsIssuerOrigin$inboundSchema: z.ZodNativeEnum<typeof GetKmsIssuerOrigin>;
/** @internal */
export declare const GetKmsIssuerStatus$inboundSchema: z.ZodNativeEnum<typeof GetKmsIssuerStatus>;
/** @internal */
export declare const GetKmsIssuerPublicKey$inboundSchema: z.ZodType<GetKmsIssuerPublicKey, z.ZodTypeDef, unknown>;
export declare function getKmsIssuerPublicKeyFromJSON(jsonString: string): SafeParseResult<GetKmsIssuerPublicKey, SDKValidationError>;
/** @internal */
export declare const GetKmsIssuerSigningKeys$inboundSchema: z.ZodType<GetKmsIssuerSigningKeys, z.ZodTypeDef, unknown>;
export declare function getKmsIssuerSigningKeysFromJSON(jsonString: string): SafeParseResult<GetKmsIssuerSigningKeys, SDKValidationError>;
/** @internal */
export declare const GetKmsIssuerPolicies2$inboundSchema: z.ZodType<GetKmsIssuerPolicies2, z.ZodTypeDef, unknown>;
export declare function getKmsIssuerPolicies2FromJSON(jsonString: string): SafeParseResult<GetKmsIssuerPolicies2, SDKValidationError>;
/** @internal */
export declare const GetKmsIssuerPolicies1$inboundSchema: z.ZodType<GetKmsIssuerPolicies1, z.ZodTypeDef, unknown>;
export declare function getKmsIssuerPolicies1FromJSON(jsonString: string): SafeParseResult<GetKmsIssuerPolicies1, SDKValidationError>;
/** @internal */
export declare const GetKmsIssuerPolicies$inboundSchema: z.ZodType<GetKmsIssuerPolicies, z.ZodTypeDef, unknown>;
export declare function getKmsIssuerPoliciesFromJSON(jsonString: string): SafeParseResult<GetKmsIssuerPolicies, SDKValidationError>;
/** @internal */
export declare const GetKmsIssuerResponseBody$inboundSchema: z.ZodType<GetKmsIssuerResponseBody, z.ZodTypeDef, unknown>;
export declare function getKmsIssuerResponseBodyFromJSON(jsonString: string): SafeParseResult<GetKmsIssuerResponseBody, SDKValidationError>;
//# sourceMappingURL=getkmsissuerop.d.ts.map