MAQPNADocs

maqpna audit verify

Verify the audit ledger's hash chain, signatures and checkpoints

Observe-o json | yaml

Synopsis#

maqpna audit verify FILE [--jwks JWKS.json] [--checkpoints FILE.checkpoints.jws]
maqpna audit verify --gateway URL                  (the gateway verifies its ledger; exit 3 if broken)
maqpna audit verify --postgres DSN-FILE [--schema maqpna] [--chain audit]

Flags#

FlagTypeDescriptionDefault
--jwks, --checkpoint-jwksstringJWKS (from /v1/audit/jwks or an evidence bundle) to verify Ed25519-signed checkpoints offlinenone
--checkpoint-key-envstringenv var holding the checkpoint HMAC key (when set, <FILE>.checkpoints must exist and verify)MAQPNA_AUDIT_HMAC_KEY
--checkpointsstringsigned checkpoint file (default <FILE>.checkpoints.jws)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna audit verify audit.jsonl --jwks jwks.json --checkpoints audit.checkpoints.jws

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.
  • Exits 3 when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch)

Terminal demo#

maqpna audit verify.cast