Overview
What MAQPNA does, the parts it is made of, and where to start reading.
MAQPNA is the sovereign runtime for AI agents. It runs your agents on your own infrastructure and sends every tool, model and egress call through one gateway. The gateway checks the session's identity and your policy, asks a person before risky actions, enforces budgets and data loss prevention (DLP) rules, and writes each decision to a tamper-evident audit ledger.
What happens to a tool call#
sequenceDiagram
participant A as Agent (in its sandbox)
participant G as MAQPNA gateway
participant P as Approver
participant T as MCP server
A->>G: tool call + session token
G->>G: verify identity, evaluate policy, DLP, budget
alt allowed
G->>T: forward the call
T-->>G: result
G-->>A: result
else held for approval
G->>P: approval request
P-->>G: approve or deny
else denied
G-->>A: denied, with the policy and rule
end
G->>G: write the decision to the audit ledger
Every decision names the policy and rule that made it, so "why was this denied?" always has an answer you can
look up with maqpna audit tail or
maqpna dev timeline.
The parts#
| Part | What it does |
|---|---|
Gateway (maqpna-gateway) |
Every tool, model and egress call passes through it. It verifies identity, evaluates policy, checks DLP, budgets and taint, asks for approval and writes the audit record. |
Identity broker (maqpna-identity) |
Mints the short-lived session token each session presents to the gateway. |
Operator (maqpna-operator) |
On Kubernetes, turns Agent and AgentSession resources into isolated sandboxes with their own identity. |
CLI (maqpna) |
Runs a local MAQPNA on your laptop, tests policies offline, approves held calls and operates an installation. Its lifecycle plugin maqpna-install installs and upgrades MAQPNA with Helm. |
Two ways to run it#
- On your laptop, with no cluster:
maqpna dev upstarts the identity broker, the gateway and a test MCP server. Use it to try MAQPNA, develop agents and write policies. Start with the quickstart. - On Kubernetes, for production:
maqpna installinstalls the operator, gateway and identity broker with Helm, and every session runs in its own sandbox. See Install.
Where to go next#
- Install the CLI.
- Follow the quickstart: a governed tool call in three commands.
- Read the concepts to learn the words these pages use: session, policy, rule, decision, approval.