Editions#
MAQPNA is open core. An edition is a licensing package; the editions are Community, Team, Enterprise, Sovereign and Operator. This page lists what each edition is for and which features it packages. Prices are not part of the documentation.
The rule that never changes#
No licence state ever blocks or degrades agent traffic. Tool calls, model calls, sessions, approvals and the audit ledger behave identically whether a licence is missing, invalid, valid, in its grace period or expired. The gateway test TestLicenseNeverBlocksToolCalls guards this, and the licence is verified offline: there is no licence server and no phone-home. See licensing and entitlements.
What each edition packages#
| Edition | For | Packages |
|---|---|---|
| Community | Developers, evaluation, small teams | The runtime: operator, gateway, identity broker, audit ledger, CLI, SDKs, maqpna dev, the Helm chart, on one cluster |
| Team | Start-ups and departments | Community, plus console single sign-on and HA with PostgreSQL state, for a small number of nodes |
| Enterprise | Regulated enterprises running their own agents | Team, plus fleet view across clusters, OIDC admin roles and approval routing, SIEM and WORM connectors, policy replay and evaluation at scale |
| Sovereign | Public sector, defence, banks, critical infrastructure | Enterprise, plus confidential tiers with attestation, HSM and KMS key custody, air-gap bundles with offline licensing, and signed compliance evidence packs |
| Operator | Service providers hosting agents for their customers | Enterprise features, plus a white-label console, multi-tenant fleet view, signed usage reports for billing and tenant self-service |
How a licence switches features on#
A licence is a signed file (a compact JWS of type maqpna-license+jwt, signed with EdDSA or ES256, issuer https://maqpna.com) that you install as a Secret. The gateway and the operator re-read it every 30 seconds and verify it against a public key embedded in the binaries. It names the edition, a list of features (or * for all) and reported limits (nodes, tenants, sandbox hours).
| Licence state | Meaning | Paid features |
|---|---|---|
none |
No licence installed: the Community edition | Off |
invalid |
Signature, issuer or format did not verify | Off |
valid |
Within nbf and exp |
On, as listed |
grace |
Up to 30 days after expiry | On, with warnings and the MaqpnaLicenseExpiring alert |
expired |
More than 30 days after expiry | Off |
The paid-feature names in the code are fleet, whitelabel, evidence-packs, usage-reports and sso-console. A paid feature that is not licensed answers on the admin API with HTTP 402 and reason license_required; it never affects agents.
flowchart LR
L["Licence Secret<br/>(optional)"] -- "re-read every 30 s,<br/>verified offline" --> S{"State"}
S -- "none, invalid, expired" --> C["Community features"]
S -- "valid, grace" --> P["Community + listed paid features"]
C --> T["Agent traffic: identical"]
P --> T
What you see#
maqpna license status shows the installed licence, its state, days left and the paid features it enables; maqpna license verify FILE checks a licence offline before you install it. See maqpna license status, maqpna license verify and maqpna license install.