MAQPNADocs

maqpna backup verify

Verify a backup's checksums and, with its key, its sealed Secrets

Operate-o json | yaml

Synopsis#

maqpna backup verify DIR [--open-key RECIPIENT.key]

Description#

From the help of maqpna backup:

Secrets are sealed with X25519 (maqpna-sovereign x25519-keygen) and are skipped without --seal-to. HSM/KMS key URIs are referenced by the Secrets and never exported. verify exits 3 on any failure. See docs/runbooks/backup-restore.md.

Flags#

FlagTypeDescriptionDefault
--open-keystringX25519 recipient private key: also open every sealed Secretnone

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna backup verify /backups/2026-10-02 --open-key recipient.key

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna backup verify.cast