MAQPNADocs

maqpna dev up

Start a local MAQPNA: identity broker, gateway and the mcp-echo test MCP server

Get started-o json | yaml

Synopsis#

maqpna dev up [--dir .maqpna] [--gateway-port 8080] [--identity-port 8081] [--echo-port 8090] [--policy FILE]
              [--upstream NAME=URL]... [--model NAME=URL[,MODEL]] [--stub-llm [--stub-llm-script F]] [--no-echo] [--from-source]
              [--dlp-profile FILE] [--checkpoint-key FILE] [--gateway-config FILE]

Description#

From the help of maqpna dev:

up starts maqpna-identity, maqpna-gateway and (unless --no-echo) mcp-echo from the installed binaries (next to maqpna or on PATH); in a source checkout with --from-source, or when they are missing, they are built with go build. run mints a session token from the local broker and runs CMD with the same environment the operator gives a sandbox (MAQPNA_GATEWAY_URL, MAQPNA_TOKEN, MAQPNA_SESSION, MAQPNA_AGENT, MAQPNA_TOOL_<NAME>_URL), then prints what the session did. Exit code: CMD's.

Flags#

FlagTypeDescriptionDefault
--checkpoint-keystringaudit checkpoint signing key (Ed25519 PKCS#8 PEM file; auditCheckpointKey)none
--dirstringstate directory (keys, config, ledger, logs).maqpna
--dlp-profilestringDLP profile JSON file, applied to all traffic as profile "dev" (dlpProfiles.dev, dlp.defaultProfile)none
--echo-portintmcp-echo port8090
--from-sourceswitchbuild the servers from this source checkout with go buildnone
--gateway-configstringJSON object merged over the generated .maqpna/gateway.json (top-level keys replace; e.g. auditSinks, pricingFile)none
--gateway-portintgateway port8080
--identity-portintidentity broker port8081
--modelstringOpenAI-compatible model route NAME=URL[,MODEL] (repeatable)none
--no-echoswitchdo not start the mcp-echo test servernone
--policystringpolicy JSON file (default: the built-in dev policy)none
--stub-llmswitchalso start stub-llm (scripted OpenAI-compatible model, no API key) as model route "stub"none
--stub-llm-portintstub-llm port8000
--stub-llm-scriptstringstub-llm script (YAML; default: call echo, then a denied delete, then answer)none
--upstreamstringextra MCP server NAME=URL (repeatable)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

# Start a local MAQPNA, run your agent under it, then see what it did
maqpna dev up
# Use a model route backed by the scripted stub model
maqpna dev up --stub-llm

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna dev up.cast