/**
* Hand-authored declarations for the "./xkey" export of ardegazu-id-kit —
* the compiled dist/xkey.js. X25519 encryption identity + sealed-box wraps.
* Requires the optional peerDependency @noble/curves at runtime.
*/
import type { Bytes, Identity } from "./index.js";
/** Suite-wide salt: the ONE encryption identity all cross-app features share. */
export declare const SUITE_SALT: string;
export interface XKeyPair {
priv: Bytes;
pubB64: string;
}
/** A sealed box addressed to one identity's certified X25519 pub. */
export interface Wrap {
to: string; // recipient Ed25519 identity pub (b64url)
toX: string; // recipient X25519 pub (b64url)
ephPub: string; // sender's ephemeral X25519 pub (b64url)
iv: string; // b64
ct: string; // b64
}
/** Derive the deterministic X25519 keypair from the 32-byte identity seed. */
export declare function deriveXKeyPair(identitySeedB64url: string, salt: string): Promise<XKeyPair>;
/** The suite-wide encryption keypair (what cross-app envelopes seal to). */
export declare function deriveSuiteXKeyPair(identitySeedB64url: string): Promise<XKeyPair>;
/** Sign our X25519 pub with the Ed25519 identity (the "cert"). */
export declare function signXCert(identity: Identity, salt: string, xPub: string): Promise<string>;
/** Verify a peer's cert binds xPub to their Ed25519 identity. */
export declare function verifyXCert(salt: string, idPub: string, xPub: string, xSigB64url: string): Promise<boolean>;
/** Seal `payload` to an identity's certified X25519 pub, bound to `ctx`. */
export declare function wrapTo(
salt: string,
ctx: string,
toIdPub: string,
toXPubB64: string,
payload: Bytes,
): Promise<Wrap>;
/** Open a wrap addressed to us; null on any failure (wrong key, tampered). */
export declare function unwrap(salt: string, ctx: string, w: Wrap, myX: XKeyPair): Promise<Bytes | null>;