maqpna evidence verify
Verify an evidence pack's signature and every file hash, offline
Synopsis#
maqpna evidence verify DIR|PACK.zip [--pubkey PEM | --jwks URL|FILE] [-o json]
signature and file hashes, offline, no licence needed (exit 3 on tamper)Description#
From the help of maqpna evidence:
generate builds a signed, auditor-ready evidence pack for one framework, one system and one period from the audit ledger and the configuration in force (paid: the evidence-packs licence feature or the Sovereign edition). verify checks a pack offline and needs no licence. frameworks lists the control mappings. A pack supports, and does not certify, compliance (docs/evidence-packs.md).
The register lists every external MCP server, model endpoint and A2A peer with first and last use, call counts, residency and cost (DORA Art. 28(3) register of information).
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--jwks | string | JWKS file or URL (the gateway's /v1/audit/jwks) | none |
--pubkey | string | PEM file with the signing public key(s) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna evidence verify pack.zip --jwks "$GW/v1/audit/jwks"What happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON. - Exits
3when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) |