MAQPNADocs

maqpna eval

Score the policy decisions of an evaluation suite

Govern-o json | yaml

Synopsis#

maqpna eval --suite SUITE.yaml [--policy FILE | --gateway URL [--agent-token-file F]] [--mock-listen ADDR]
            [-o table|json|yaml] [--min-score 1.0]       (exit 3 below --min-score)

Description#

Runs the suite's tasks (ordered tool calls of one simulated session each) and scores the policy outcomes against each step's expect / expectRule. Exit status: 0 score >= --min-score, 3 below, 1 error.

Modes:

  local     --policy FILE (or suite "policy:"): pkg/policy engine, offline
  evaluate  --gateway URL: the gateway's live policies via POST /v1/policies:evaluate
            (admin token: --token / --oidc-token-file / env)
  live      --gateway URL --agent-token-file F: real tools/call through
            /mcp/{server} with an agent token (X-Maqpna-Async: 1); all tasks
            share the token's session

In local and evaluate mode session taints are simulated like the gateway does: after an allowed step the tool's toolLabels taints are added and, when its (mock) response is not a JSON-RPC error, its clearTaints removed. --mock-listen ADDR serves the suite's mocks as an MCP server (POST /mcp/{server}, /mcp) for gateways whose upstreams point at it.

Flags#

FlagTypeDescriptionDefault
--agent-token-filestringagent token file: live mode (tools/call through the gateway)none
--formatstringtable|json (same as -o)table
--gatewaystringgateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway)none
--min-scorefloatexit 3 when the score is below this (0..1)1
--mock-listenstringserve the suite mocks as an MCP server on ADDR while runningnone
--oidc-token-filestringfile holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --tokennone
--policystringpolicies for local mode (overrides the suite's policy)none
--suitestringsuite file (YAML or JSON)none
--tokenstringstatic admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna eval --suite suite.yaml --policy policies/
maqpna eval --suite suite.yaml --gateway http://127.0.0.1:8080 --min-score 0.95

What happens when you run it#

  • Talks to the gateway: --gateway, else MAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context).
  • Authenticates to the admin API with the token stored by maqpna login, --oidc-token-file, or a static --token (MAQPNA_ADMIN_TOKEN).
  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.
  • Exits 3 when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch)

Terminal demo#

maqpna eval.cast