MAQPNADocs

Editions#

MAQPNA is open core. An edition is a licensing package; the editions are Community, Team, Enterprise, Sovereign and Operator. This page lists what each edition is for and which features it packages. Prices are not part of the documentation.

The rule that never changes#

No licence state ever blocks or degrades agent traffic. Tool calls, model calls, sessions, approvals and the audit ledger behave identically whether a licence is missing, invalid, valid, in its grace period or expired. The gateway test TestLicenseNeverBlocksToolCalls guards this, and the licence is verified offline: there is no licence server and no phone-home. See licensing and entitlements.

What each edition packages#

Edition For Packages
Community Developers, evaluation, small teams The runtime: operator, gateway, identity broker, audit ledger, CLI, SDKs, maqpna dev, the Helm chart, on one cluster
Team Start-ups and departments Community, plus console single sign-on and HA with PostgreSQL state, for a small number of nodes
Enterprise Regulated enterprises running their own agents Team, plus fleet view across clusters, OIDC admin roles and approval routing, SIEM and WORM connectors, policy replay and evaluation at scale
Sovereign Public sector, defence, banks, critical infrastructure Enterprise, plus confidential tiers with attestation, HSM and KMS key custody, air-gap bundles with offline licensing, and signed compliance evidence packs
Operator Service providers hosting agents for their customers Enterprise features, plus a white-label console, multi-tenant fleet view, signed usage reports for billing and tenant self-service

How a licence switches features on#

A licence is a signed file (a compact JWS of type maqpna-license+jwt, signed with EdDSA or ES256, issuer https://maqpna.com) that you install as a Secret. The gateway and the operator re-read it every 30 seconds and verify it against a public key embedded in the binaries. It names the edition, a list of features (or * for all) and reported limits (nodes, tenants, sandbox hours).

Licence state Meaning Paid features
none No licence installed: the Community edition Off
invalid Signature, issuer or format did not verify Off
valid Within nbf and exp On, as listed
grace Up to 30 days after expiry On, with warnings and the MaqpnaLicenseExpiring alert
expired More than 30 days after expiry Off

The paid-feature names in the code are fleet, whitelabel, evidence-packs, usage-reports and sso-console. A paid feature that is not licensed answers on the admin API with HTTP 402 and reason license_required; it never affects agents.

flowchart LR
    L["Licence Secret<br/>(optional)"] -- "re-read every 30 s,<br/>verified offline" --> S{"State"}
    S -- "none, invalid, expired" --> C["Community features"]
    S -- "valid, grace" --> P["Community + listed paid features"]
    C --> T["Agent traffic: identical"]
    P --> T

What you see#

maqpna license status shows the installed licence, its state, days left and the paid features it enables; maqpna license verify FILE checks a licence offline before you install it. See maqpna license status, maqpna license verify and maqpna license install.