import * as z from "zod/v3";
import { ClosedEnum } from "../types/enums.js";
import { Result as SafeParseResult } from "../types/fp.js";
import { SDKValidationError } from "./sdkvalidationerror.js";
export type ListKmsIssuersRequest = {
    /**
     * Maximum number of issuers to return.
     */
    limit?: number | undefined;
    /**
     * Continuation cursor to retrieve the next page of results.
     */
    next?: string | undefined;
    /**
     * The Team identifier to perform the request on behalf of.
     */
    teamId?: string | undefined;
    /**
     * The Team slug to perform the request on behalf of.
     */
    slug?: string | undefined;
};
export declare const ListKmsIssuersAlgorithm: {
    readonly Es256: "ES256";
    readonly Es384: "ES384";
    readonly Es512: "ES512";
    readonly EdDSA: "EdDSA";
    readonly Ps256: "PS256";
    readonly Ps384: "PS384";
    readonly Ps512: "PS512";
    readonly Rs256: "RS256";
    readonly Rs384: "RS384";
    readonly Rs512: "RS512";
};
export type ListKmsIssuersAlgorithm = ClosedEnum<typeof ListKmsIssuersAlgorithm>;
export declare const ListKmsIssuersOrigin: {
    readonly External: "external";
    readonly Vercel: "vercel";
};
export type ListKmsIssuersOrigin = ClosedEnum<typeof ListKmsIssuersOrigin>;
export declare const ListKmsIssuersStatus: {
    readonly Active: "active";
    readonly Pending: "pending";
    readonly Revoking: "revoking";
};
export type ListKmsIssuersStatus = ClosedEnum<typeof ListKmsIssuersStatus>;
export type ListKmsIssuersPublicKey = {
    kty?: string | undefined;
    kid?: string | undefined;
    alg?: string | undefined;
    use?: string | undefined;
    keyOps?: Array<string> | undefined;
    /**
     * The X.509 certificate chain (RFC 7517 §4.7). Each entry is the base64 DER (not base64url) of a certificate. For keys minted with a stored certificate this holds the single self-signed cert as `[x5c]`.
     */
    x5c?: Array<string> | undefined;
    /**
     * The base64url SHA-256 thumbprint of the DER certificate in `x5c[0]` (RFC 7517 §4.9).
     */
    x5tNumberS256?: string | undefined;
};
export type ListKmsIssuersSigningKeys = {
    /**
     * The server-minted, unique record identifier. Use this to address the key on the activate / certificate endpoints.
     */
    keyId: string;
    /**
     * The caller-supplied key id (imported keys only), used as the JWT/JWKS `kid`. Not unique across an issuer's keys; omitted for generated keys.
     */
    importKeyId?: string | undefined;
    issuerId: string;
    algorithm: string;
    status: ListKmsIssuersStatus;
    publicKey?: ListKmsIssuersPublicKey | undefined;
    publicKeyFingerprint?: string | undefined;
    /**
     * The public key in SPKI PEM form, ready to render. Present whenever the key has public key material. Derived from `publicKey`; the embedded certificate members (`x5c`/`x5t#S256`) do not affect it.
     */
    publicKeyPem?: string | undefined;
    /**
     * The stored X.509 certificate (from `publicKey.x5c[0]`) in PEM form, ready to render. Present only for keys created with a stored certificate; omitted for keys created before certificates were stored.
     */
    certificatePem?: string | undefined;
    createdAt: string;
    updatedAt: string;
    revokeAt?: string | undefined;
    activateAt?: string | undefined;
    /**
     * When the key became the active signer. Present for active and revoking keys (and absent for pending keys and rows predating this field).
     */
    activatedAt?: string | undefined;
};
export type ListKmsIssuersPolicies2 = {
    kind: "connex-grant";
    clientId: string;
    tokenClaims?: {
        [k: string]: any;
    } | undefined;
    createdAt: string;
    updatedAt: string;
};
export type ListKmsIssuersPolicies1 = {
    kind: "project-grant";
    teamId: string;
    projectId: string;
    /**
     * Environments whose OIDC tokens this grant authorizes. Each entry is either a system environment slug (`production`, `preview`, `development`) or a custom environment ID (prefixed `env_`). Custom environments are matched against the token's `custom_environment_id` claim (the stable ID); system environments against its `environment` claim.
     */
    environments: Array<string>;
    tokenClaims?: {
        [k: string]: any;
    } | undefined;
    createdAt: string;
    updatedAt: string;
};
export type ListKmsIssuersPolicies = ListKmsIssuersPolicies1 | ListKmsIssuersPolicies2;
export type Issuers = {
    id: string;
    ownerId: string;
    name: string;
    algorithm: ListKmsIssuersAlgorithm;
    origin: ListKmsIssuersOrigin;
    managedBy?: string | undefined;
    claimsSchema?: {
        [k: string]: any;
    } | undefined;
    createdAt: string;
    updatedAt: string;
    signingKeys: Array<ListKmsIssuersSigningKeys>;
    policies: Array<ListKmsIssuersPolicies1 | ListKmsIssuersPolicies2>;
};
export type ListKmsIssuersPagination = {
    count: number;
    next: string | null;
};
export type ListKmsIssuersResponseBody = {
    issuers: Array<Issuers>;
    pagination: ListKmsIssuersPagination;
};
/** @internal */
export type ListKmsIssuersRequest$Outbound = {
    limit?: number | undefined;
    next?: string | undefined;
    teamId?: string | undefined;
    slug?: string | undefined;
};
/** @internal */
export declare const ListKmsIssuersRequest$outboundSchema: z.ZodType<ListKmsIssuersRequest$Outbound, z.ZodTypeDef, ListKmsIssuersRequest>;
export declare function listKmsIssuersRequestToJSON(listKmsIssuersRequest: ListKmsIssuersRequest): string;
/** @internal */
export declare const ListKmsIssuersAlgorithm$inboundSchema: z.ZodNativeEnum<typeof ListKmsIssuersAlgorithm>;
/** @internal */
export declare const ListKmsIssuersOrigin$inboundSchema: z.ZodNativeEnum<typeof ListKmsIssuersOrigin>;
/** @internal */
export declare const ListKmsIssuersStatus$inboundSchema: z.ZodNativeEnum<typeof ListKmsIssuersStatus>;
/** @internal */
export declare const ListKmsIssuersPublicKey$inboundSchema: z.ZodType<ListKmsIssuersPublicKey, z.ZodTypeDef, unknown>;
export declare function listKmsIssuersPublicKeyFromJSON(jsonString: string): SafeParseResult<ListKmsIssuersPublicKey, SDKValidationError>;
/** @internal */
export declare const ListKmsIssuersSigningKeys$inboundSchema: z.ZodType<ListKmsIssuersSigningKeys, z.ZodTypeDef, unknown>;
export declare function listKmsIssuersSigningKeysFromJSON(jsonString: string): SafeParseResult<ListKmsIssuersSigningKeys, SDKValidationError>;
/** @internal */
export declare const ListKmsIssuersPolicies2$inboundSchema: z.ZodType<ListKmsIssuersPolicies2, z.ZodTypeDef, unknown>;
export declare function listKmsIssuersPolicies2FromJSON(jsonString: string): SafeParseResult<ListKmsIssuersPolicies2, SDKValidationError>;
/** @internal */
export declare const ListKmsIssuersPolicies1$inboundSchema: z.ZodType<ListKmsIssuersPolicies1, z.ZodTypeDef, unknown>;
export declare function listKmsIssuersPolicies1FromJSON(jsonString: string): SafeParseResult<ListKmsIssuersPolicies1, SDKValidationError>;
/** @internal */
export declare const ListKmsIssuersPolicies$inboundSchema: z.ZodType<ListKmsIssuersPolicies, z.ZodTypeDef, unknown>;
export declare function listKmsIssuersPoliciesFromJSON(jsonString: string): SafeParseResult<ListKmsIssuersPolicies, SDKValidationError>;
/** @internal */
export declare const Issuers$inboundSchema: z.ZodType<Issuers, z.ZodTypeDef, unknown>;
export declare function issuersFromJSON(jsonString: string): SafeParseResult<Issuers, SDKValidationError>;
/** @internal */
export declare const ListKmsIssuersPagination$inboundSchema: z.ZodType<ListKmsIssuersPagination, z.ZodTypeDef, unknown>;
export declare function listKmsIssuersPaginationFromJSON(jsonString: string): SafeParseResult<ListKmsIssuersPagination, SDKValidationError>;
/** @internal */
export declare const ListKmsIssuersResponseBody$inboundSchema: z.ZodType<ListKmsIssuersResponseBody, z.ZodTypeDef, unknown>;
export declare function listKmsIssuersResponseBodyFromJSON(jsonString: string): SafeParseResult<ListKmsIssuersResponseBody, SDKValidationError>;
//# sourceMappingURL=listkmsissuersop.d.ts.map