maqpna audit verify
Verify the audit ledger's hash chain, signatures and checkpoints
Synopsis#
maqpna audit verify FILE [--jwks JWKS.json] [--checkpoints FILE.checkpoints.jws]
maqpna audit verify --gateway URL (the gateway verifies its ledger; exit 3 if broken)
maqpna audit verify --postgres DSN-FILE [--schema maqpna] [--chain audit]Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--jwks, --checkpoint-jwks | string | JWKS (from /v1/audit/jwks or an evidence bundle) to verify Ed25519-signed checkpoints offline | none |
--checkpoint-key-env | string | env var holding the checkpoint HMAC key (when set, <FILE>.checkpoints must exist and verify) | MAQPNA_AUDIT_HMAC_KEY |
--checkpoints | string | signed checkpoint file (default <FILE>.checkpoints.jws) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna audit verify audit.jsonl --jwks jwks.json --checkpoints audit.checkpoints.jwsWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON. - Exits
3when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) |