import * as z from "zod/v3";
import { ClosedEnum } from "../types/enums.js";
import { Result as SafeParseResult } from "../types/fp.js";
import { SDKValidationError } from "./sdkvalidationerror.js";
export type RevokeKmsSigningKeyRequest = {
    /**
     * The ID of the issuer.
     */
    issuerId: string;
    /**
     * The ID of the signing key to revoke immediately. The key must already be scheduled for revocation.
     */
    keyId: string;
    /**
     * The Team identifier to perform the request on behalf of.
     */
    teamId?: string | undefined;
    /**
     * The Team slug to perform the request on behalf of.
     */
    slug?: string | undefined;
};
export declare const RevokeKmsSigningKeyAlgorithm: {
    readonly Es256: "ES256";
    readonly Es384: "ES384";
    readonly Es512: "ES512";
    readonly EdDSA: "EdDSA";
    readonly Ps256: "PS256";
    readonly Ps384: "PS384";
    readonly Ps512: "PS512";
    readonly Rs256: "RS256";
    readonly Rs384: "RS384";
    readonly Rs512: "RS512";
};
export type RevokeKmsSigningKeyAlgorithm = ClosedEnum<typeof RevokeKmsSigningKeyAlgorithm>;
export declare const RevokeKmsSigningKeyOrigin: {
    readonly External: "external";
    readonly Vercel: "vercel";
};
export type RevokeKmsSigningKeyOrigin = ClosedEnum<typeof RevokeKmsSigningKeyOrigin>;
export declare const RevokeKmsSigningKeyStatus: {
    readonly Active: "active";
    readonly Pending: "pending";
    readonly Revoking: "revoking";
};
export type RevokeKmsSigningKeyStatus = ClosedEnum<typeof RevokeKmsSigningKeyStatus>;
export type RevokeKmsSigningKeyPublicKey = {
    kty?: string | undefined;
    kid?: string | undefined;
    alg?: string | undefined;
    use?: string | undefined;
    keyOps?: Array<string> | undefined;
    /**
     * The X.509 certificate chain (RFC 7517 §4.7). Each entry is the base64 DER (not base64url) of a certificate. For keys minted with a stored certificate this holds the single self-signed cert as `[x5c]`.
     */
    x5c?: Array<string> | undefined;
    /**
     * The base64url SHA-256 thumbprint of the DER certificate in `x5c[0]` (RFC 7517 §4.9).
     */
    x5tNumberS256?: string | undefined;
};
export type RevokeKmsSigningKeySigningKeys = {
    /**
     * The server-minted, unique record identifier. Use this to address the key on the activate / certificate endpoints.
     */
    keyId: string;
    /**
     * The caller-supplied key id (imported keys only), used as the JWT/JWKS `kid`. Not unique across an issuer's keys; omitted for generated keys.
     */
    importKeyId?: string | undefined;
    issuerId: string;
    algorithm: string;
    status: RevokeKmsSigningKeyStatus;
    publicKey?: RevokeKmsSigningKeyPublicKey | undefined;
    publicKeyFingerprint?: string | undefined;
    /**
     * The public key in SPKI PEM form, ready to render. Present whenever the key has public key material. Derived from `publicKey`; the embedded certificate members (`x5c`/`x5t#S256`) do not affect it.
     */
    publicKeyPem?: string | undefined;
    /**
     * The stored X.509 certificate (from `publicKey.x5c[0]`) in PEM form, ready to render. Present only for keys created with a stored certificate; omitted for keys created before certificates were stored.
     */
    certificatePem?: string | undefined;
    createdAt: string;
    updatedAt: string;
    revokeAt?: string | undefined;
    activateAt?: string | undefined;
    /**
     * When the key became the active signer. Present for active and revoking keys (and absent for pending keys and rows predating this field).
     */
    activatedAt?: string | undefined;
};
export type RevokeKmsSigningKeyPolicies2 = {
    kind: "connex-grant";
    clientId: string;
    tokenClaims?: {
        [k: string]: any;
    } | undefined;
    createdAt: string;
    updatedAt: string;
};
export type RevokeKmsSigningKeyPolicies1 = {
    kind: "project-grant";
    teamId: string;
    projectId: string;
    /**
     * Environments whose OIDC tokens this grant authorizes. Each entry is either a system environment slug (`production`, `preview`, `development`) or a custom environment ID (prefixed `env_`). Custom environments are matched against the token's `custom_environment_id` claim (the stable ID); system environments against its `environment` claim.
     */
    environments: Array<string>;
    tokenClaims?: {
        [k: string]: any;
    } | undefined;
    createdAt: string;
    updatedAt: string;
};
export type RevokeKmsSigningKeyPolicies = RevokeKmsSigningKeyPolicies1 | RevokeKmsSigningKeyPolicies2;
export type RevokeKmsSigningKeyResponseBody = {
    id: string;
    ownerId: string;
    name: string;
    algorithm: RevokeKmsSigningKeyAlgorithm;
    origin: RevokeKmsSigningKeyOrigin;
    managedBy?: string | undefined;
    claimsSchema?: {
        [k: string]: any;
    } | undefined;
    createdAt: string;
    updatedAt: string;
    signingKeys: Array<RevokeKmsSigningKeySigningKeys>;
    policies: Array<RevokeKmsSigningKeyPolicies1 | RevokeKmsSigningKeyPolicies2>;
};
/** @internal */
export type RevokeKmsSigningKeyRequest$Outbound = {
    issuerId: string;
    keyId: string;
    teamId?: string | undefined;
    slug?: string | undefined;
};
/** @internal */
export declare const RevokeKmsSigningKeyRequest$outboundSchema: z.ZodType<RevokeKmsSigningKeyRequest$Outbound, z.ZodTypeDef, RevokeKmsSigningKeyRequest>;
export declare function revokeKmsSigningKeyRequestToJSON(revokeKmsSigningKeyRequest: RevokeKmsSigningKeyRequest): string;
/** @internal */
export declare const RevokeKmsSigningKeyAlgorithm$inboundSchema: z.ZodNativeEnum<typeof RevokeKmsSigningKeyAlgorithm>;
/** @internal */
export declare const RevokeKmsSigningKeyOrigin$inboundSchema: z.ZodNativeEnum<typeof RevokeKmsSigningKeyOrigin>;
/** @internal */
export declare const RevokeKmsSigningKeyStatus$inboundSchema: z.ZodNativeEnum<typeof RevokeKmsSigningKeyStatus>;
/** @internal */
export declare const RevokeKmsSigningKeyPublicKey$inboundSchema: z.ZodType<RevokeKmsSigningKeyPublicKey, z.ZodTypeDef, unknown>;
export declare function revokeKmsSigningKeyPublicKeyFromJSON(jsonString: string): SafeParseResult<RevokeKmsSigningKeyPublicKey, SDKValidationError>;
/** @internal */
export declare const RevokeKmsSigningKeySigningKeys$inboundSchema: z.ZodType<RevokeKmsSigningKeySigningKeys, z.ZodTypeDef, unknown>;
export declare function revokeKmsSigningKeySigningKeysFromJSON(jsonString: string): SafeParseResult<RevokeKmsSigningKeySigningKeys, SDKValidationError>;
/** @internal */
export declare const RevokeKmsSigningKeyPolicies2$inboundSchema: z.ZodType<RevokeKmsSigningKeyPolicies2, z.ZodTypeDef, unknown>;
export declare function revokeKmsSigningKeyPolicies2FromJSON(jsonString: string): SafeParseResult<RevokeKmsSigningKeyPolicies2, SDKValidationError>;
/** @internal */
export declare const RevokeKmsSigningKeyPolicies1$inboundSchema: z.ZodType<RevokeKmsSigningKeyPolicies1, z.ZodTypeDef, unknown>;
export declare function revokeKmsSigningKeyPolicies1FromJSON(jsonString: string): SafeParseResult<RevokeKmsSigningKeyPolicies1, SDKValidationError>;
/** @internal */
export declare const RevokeKmsSigningKeyPolicies$inboundSchema: z.ZodType<RevokeKmsSigningKeyPolicies, z.ZodTypeDef, unknown>;
export declare function revokeKmsSigningKeyPoliciesFromJSON(jsonString: string): SafeParseResult<RevokeKmsSigningKeyPolicies, SDKValidationError>;
/** @internal */
export declare const RevokeKmsSigningKeyResponseBody$inboundSchema: z.ZodType<RevokeKmsSigningKeyResponseBody, z.ZodTypeDef, unknown>;
export declare function revokeKmsSigningKeyResponseBodyFromJSON(jsonString: string): SafeParseResult<RevokeKmsSigningKeyResponseBody, SDKValidationError>;
//# sourceMappingURL=revokekmssigningkeyop.d.ts.map