MAQPNADocs

Overview

What MAQPNA does, the parts it is made of, and where to start reading.

MAQPNA is the sovereign runtime for AI agents. It runs your agents on your own infrastructure and sends every tool, model and egress call through one gateway. The gateway checks the session's identity and your policy, asks a person before risky actions, enforces budgets and data loss prevention (DLP) rules, and writes each decision to a tamper-evident audit ledger.

What happens to a tool call#

sequenceDiagram
    participant A as Agent (in its sandbox)
    participant G as MAQPNA gateway
    participant P as Approver
    participant T as MCP server
    A->>G: tool call + session token
    G->>G: verify identity, evaluate policy, DLP, budget
    alt allowed
        G->>T: forward the call
        T-->>G: result
        G-->>A: result
    else held for approval
        G->>P: approval request
        P-->>G: approve or deny
    else denied
        G-->>A: denied, with the policy and rule
    end
    G->>G: write the decision to the audit ledger

Every decision names the policy and rule that made it, so "why was this denied?" always has an answer you can look up with maqpna audit tail or maqpna dev timeline.

The parts#

Part What it does
Gateway (maqpna-gateway) Every tool, model and egress call passes through it. It verifies identity, evaluates policy, checks DLP, budgets and taint, asks for approval and writes the audit record.
Identity broker (maqpna-identity) Mints the short-lived session token each session presents to the gateway.
Operator (maqpna-operator) On Kubernetes, turns Agent and AgentSession resources into isolated sandboxes with their own identity.
CLI (maqpna) Runs a local MAQPNA on your laptop, tests policies offline, approves held calls and operates an installation. Its lifecycle plugin maqpna-install installs and upgrades MAQPNA with Helm.

Two ways to run it#

  • On your laptop, with no cluster: maqpna dev up starts the identity broker, the gateway and a test MCP server. Use it to try MAQPNA, develop agents and write policies. Start with the quickstart.
  • On Kubernetes, for production: maqpna install installs the operator, gateway and identity broker with Helm, and every session runs in its own sandbox. See Install.

Where to go next#

  1. Install the CLI.
  2. Follow the quickstart: a governed tool call in three commands.
  3. Read the concepts to learn the words these pages use: session, policy, rule, decision, approval.