MAQPNADocs

Reference

Every maqpna command, generated from the binary, plus the resource, API and configuration reference.

Get started#

Install MAQPNA, run it on your laptop, and sign in.

maqpna installInstall MAQPNA in a cluster with Helm
maqpna devRun a local MAQPNA (identity broker, gateway, test MCP server) and your agent under itup run timeline env status down
maqpna initPrint a starter manifest for a MAQPNA resource
maqpna explainDocument a MAQPNA resource or field
maqpna loginLog in to a gateway's admin API (browser or device flow) and store the access token
maqpna logoutDelete the context's stored access token
maqpna whoamiShow the identity and roles the gateway sees for you

Run agents#

Apply manifests, start sessions and make tool calls.

maqpna applyValidate manifests, then server-side apply them (agents, policies, trust tiers, ...)
maqpna diffShow what apply would change (server-side dry run)
maqpna validateValidate MAQPNA manifests offline (schemas, policies, sovereignty, references)
maqpna sessionStart, inspect, control and observe sessionsstart list get describe wait suspend resume fork snapshot delete cost exec files liveview
maqpna agentList and inspect agentslist get describe
maqpna tierList and inspect trust tierslist get
maqpna callMake one tool call through the gateway with a session token (debugging)
maqpna consoleOpen the console of an installation
maqpna tokenMint, inspect and verify session tokensmint inspect verify
maqpna keygenGenerate an Ed25519 signing key pair for session identities (dev and CI)

Govern#

Policies, approvals, the kill switch and everything that decides what an agent may do.

maqpna policyTest a tool call against policies, offline or on the live gatewaytest lint list get
maqpna evalScore the policy decisions of an evaluation suite
maqpna replayReplay the audit ledger against a candidate policy
maqpna sovereigntyCheck Agent manifests against a sovereignty policy offlinecheck
maqpna approvalsList pending approvals, and approve or deny themlist approve deny get watch
maqpna deskOpen the approvals inbox and dev window in your browser (what MAQPNA Desk shows)
maqpna killKill switch: revoke sessions, agents, users or tokens at the gateway (break-glass)
maqpna revocationsList or delete revocations (deleting one lifts it)list delete
maqpna mcpList MCP servers, their tools and pins (tool pinning)list tools pin
maqpna a2aList the gateway's agent-to-agent (A2A) routesroutes
maqpna accountsList or revoke users' connected accountslist revoke
maqpna memoryList memory stores, or erase a user's memory with a signed certificate (GDPR Art. 17)stores erase
maqpna taintList, inspect and clear session taintlist get clear

Observe#

Status, logs, the audit ledger, usage and costs.

maqpna statusOne-screen status of an installation: release, workloads, sessions, approvals, audit ledger
maqpna logsPrint the logs of a session's sandbox
maqpna eventsPrint the Kubernetes events of a session, its sandbox and snapshots
maqpna auditVerify, export, stream and tail the audit ledgerverify export stream tail fetch sinks
maqpna usageHourly usage per tenant: sandbox seconds, governed calls, model tokens, approvalsbuckets report verify export
maqpna costsExport costs in FOCUS, the FinOps cost-export formatfocus summary
maqpna budgetsShow budgets and the spend against themlist
maqpna evidenceBuild and verify compliance evidence packs; export the third-party registerregister frameworks generate verify

Operate#

Install, upgrade, back up, verify and keep an installation healthy.

maqpna doctorCheck the health and security posture of an installation
maqpna preflightCheck a cluster before installing MAQPNA (read-only; exit 3 when a check fails)
maqpna upgradeUpgrade MAQPNA; 'upgrade check' says whether it is safecheck
maqpna rollbackRoll the Helm release back to an earlier revision
maqpna uninstallUninstall MAQPNA (resources, keys and agent namespaces are kept unless --purge)
maqpna smokeSmoke-test a running installation end to end (exit 3 when a step fails)
maqpna support-bundleCollect a redacted diagnostics archive for support
maqpna backupBack up the audit ledger, MAQPNA resources, sealed signing keys and PostgreSQL statecreate verify
maqpna restoreRestore a backup (signing keys, MAQPNA resources, PostgreSQL state, audit ledger)
maqpna drDisaster-recovery drill: prove a backup restores, and report recovery time and data-loss windowdrill
maqpna keysRotate signing and encryption keys without downtimerotate
maqpna licenseInstall, show, verify or issue MAQPNA licences (offline EdDSA or ES256 JWS)install status verify issue
maqpna verifyVerify signatures, SBOM attestations and checksums of MAQPNA releasesrelease image chart binary bundle
maqpna airgapBuild, verify and mirror offline (air-gap) install bundlesbundle verify push
maqpna configValidate a gateway configuration file offlinevalidate
maqpna valuesValidate Helm values for the MAQPNA chart offlinevalidate
maqpna tenantsList tenants with their trust domain, signing key and ledger headlist

Configure#

Contexts, shell completion and the CLI itself.

maqpna contextManage named contexts: gateway URL, cluster and namespacelist current use set delete
maqpna completionPrint a shell completion script (bash, zsh, fish, PowerShell)bash zsh fish powershell
maqpna versionPrint the CLI version, or every component's version with the skew check
maqpna helpShow help for maqpna or one command

Server binaries#

Flags of the components the Helm chart runs. You rarely start these by hand.

maqpna-gatewayThe MAQPNA gateway: every tool, model and egress call passes through it.
maqpna-identityThe identity broker: mints the short-lived session tokens the gateway verifies.
maqpna-operatorThe Kubernetes operator: reconciles agents, sessions, trust tiers and policies.

Global flags#

These go before or after the command name and work with every command.

FlagDescription
--context NAMEUse this context from the config file (env MAQPNA_CONTEXT)
--kubeconfig FILEKubeconfig for Kubernetes-backed commands (default $KUBECONFIG)
-o, --output FORMATtable, json or yaml, for commands that print data
--jq EXPRFilter the JSON output with a jq expression
--no-colorPlain output without colour (also NO_COLOR=1)
--gateway URLGateway base URL (before the command; commands also take --gateway)
-n, --namespace NSDefault namespace (before the command)

Environment#

VariableDescription
MAQPNA_GATEWAY_URLgateway base URL (default for --gateway; else the context's gateway)
MAQPNA_CONTEXTcontext name (default for --context)
MAQPNA_CONFIGconfig file (default $XDG_CONFIG_HOME/maqpna/config.yaml or ~/.config/maqpna/config.yaml)
MAQPNA_BROKER_TOKENbearer token for the identity broker (token mint --broker)
MAQPNA_ADMIN_TOKENstatic bearer token for the gateway admin API (adminAuth.mode token/both)
MAQPNA_CAPTURE_KEYkey URI of the argument-capture key (replay --capture-key)
NO_COLORany value: no colour (https://no-color.org)
MAQPNA_ASCII1: ASCII symbols (+ x ! *) instead of ✓ ✗ ! •

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch)