MAQPNADocs

maqpna evidence generate

Generate a signed evidence pack for one framework, system and period

Observe-o json | yaml

Synopsis#

maqpna evidence generate --framework eu-ai-act|dora|iso42001 --system NS/AGENT|namespace:NS|tenant:NAME
                     (--period 2027-Q1|2027-01|2027 | --from DATE --to DATE) [--ledger FILE | --gateway URL]
                     --key KEYURI [--jwks URL|FILE] [--checkpoints FILE] [--license FILE] [--no-cluster] [--out DIR|FILE.zip]
                     signed evidence pack: manifest.json, report.html/.md, CSV workpapers (needs the evidence-packs licence)

Description#

From the help of maqpna evidence:

generate builds a signed, auditor-ready evidence pack for one framework, one system and one period from the audit ledger and the configuration in force (paid: the evidence-packs licence feature or the Sovereign edition). verify checks a pack offline and needs no licence. frameworks lists the control mappings. A pack supports, and does not certify, compliance (docs/evidence-packs.md).

The register lists every external MCP server, model endpoint and A2A peer with first and last use, call counts, residency and cost (DORA Art. 28(3) register of information).

Flags#

FlagTypeDescriptionDefault
--checkpointsstringsigned checkpoint file (default: LEDGER.checkpoints.jws)none
--frameworkstringeu-ai-act | dora | iso42001none
--fromstringperiod start (RFC3339 or YYYY-MM-DD; with --to)none
--gatewaystringgateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway)none
--jwksstringJWKS (file or URL) to verify the ledger's signed checkpointsnone
--keystringsigning key: the audit-checkpoint key (file path, file:///…, pkcs11:… or kms://…; env MAQPNA_EVIDENCE_KEY)none
--ledgerstringread the audit ledger from FILE instead of the gatewaynone
--licensestringlicence file (default: $MAQPNA_LICENSE_FILE, else the licence installed in the cluster)none
--no-clusterswitchdo not read the cluster (agents, tools, policies, tiers, sovereignty); the pack marks those controls partialnone
--oidc-token-filestringfile holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --tokennone
--outstringoutput directory, or FILE.zip (default evidence-FRAMEWORK-SYSTEM-PERIOD)none
--periodstringquarter YYYY-Qn, month YYYY-MM or year YYYY (UTC)none
--systemstringNS/AGENT (agent), namespace:NS, or tenant:NAMEnone
--tostringperiod end, exclusive (RFC3339 or YYYY-MM-DD)none
--tokenstringstatic admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna evidence generate --framework eu-ai-act --system team-a/coder --period 2027-Q1 --gateway "$GW" --key checkpoint.key --out pack.zip

What happens when you run it#

  • Talks to the gateway: --gateway, else MAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context).
  • Authenticates to the admin API with the token stored by maqpna login, --oidc-token-file, or a static --token (MAQPNA_ADMIN_TOKEN).
  • Reads the audit ledger offline with --ledger FILE: read the audit ledger from FILE instead of the gateway.
  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)