import { ICacheService } from "@medusajs/framework/types";
import { Client, Issuer, IssuerMetadata } from "openid-client";
import { OidcAuthorizationUrlResult, OidcBuildAuthorizationUrlInput, OidcEngineOptions, OidcExchangeCodeInput, OidcExchangeCodeResult, OidcMappedClaims } from "./types";
/**
 * A reusable OIDC engine built on `openid-client`. It handles discovery,
 * building the authorization URL (PKCE + nonce), exchanging the authorization
 * code with full ID-token validation, and mapping validated claims to an
 * auth-identity shape.
 */
export declare class OidcEngine {
    protected readonly options_: OidcEngineOptions;
    protected readonly discoveryCacheTtlMs_: number;
    protected readonly httpTimeoutMs_: number;
    protected readonly cache_?: ICacheService;
    /**
     * The memoized OIDC client. `openid-client` v5 caches the JWKS keystore per
     * `Issuer` instance, so building a fresh client on every call would refetch
     * the JWKS over HTTP on every login callback. The client is built lazily and
     * reused until the discovery cache entry expires; when all endpoints are
     * configured explicitly (no discovery), it's cached indefinitely, since the
     * engine's options are immutable per instance.
     */
    protected clientPromise_?: Promise<Client>;
    protected clientExpiresAt_: number;
    constructor(options: OidcEngineOptions, cache?: ICacheService);
    /**
     * Builds the authorization URL to redirect the browser to, generating a fresh
     * PKCE code verifier/challenge (S256) and nonce. The returned `nonce` and
     * `codeVerifier` must be persisted alongside the state so they can be replayed
     * when validating the callback.
     */
    buildAuthorizationUrl(input: OidcBuildAuthorizationUrlInput): Promise<OidcAuthorizationUrlResult>;
    /**
     * Exchanges the authorization code for tokens and performs full ID-token
     * validation via `openid-client` (signature through JWKS, `iss`, `aud`/`azp`,
     * `exp`/`iat`/`nbf` with clock tolerance, and `nonce`). Returns the validated
     * claims plus the tokens.
     */
    exchangeCode(input: OidcExchangeCodeInput): Promise<OidcExchangeCodeResult>;
    /**
     * Maps validated ID-token claims to an auth-identity shape, applying the
     * `require_verified_email` and `allowed_email_domains` policy checks.
     *
     * `entity_id` defaults to the `sub` claim (never the email, which is mutable
     * and reassignable).
     */
    mapClaims(claims: Record<string, unknown>): OidcMappedClaims;
    protected getClient_(): Promise<Client>;
    protected buildClient_(): Promise<Client>;
    protected hasAllEndpointOverrides_(): boolean;
    protected resolveIssuer_(): Promise<Issuer>;
    protected discoverMetadata_(): Promise<IssuerMetadata>;
}
//# sourceMappingURL=engine.d.ts.map