MAQPNADocs

maqpna evidence verify

Verify an evidence pack's signature and every file hash, offline

Observe-o json | yaml

Synopsis#

maqpna evidence verify DIR|PACK.zip [--pubkey PEM | --jwks URL|FILE] [-o json]
                     signature and file hashes, offline, no licence needed (exit 3 on tamper)

Description#

From the help of maqpna evidence:

generate builds a signed, auditor-ready evidence pack for one framework, one system and one period from the audit ledger and the configuration in force (paid: the evidence-packs licence feature or the Sovereign edition). verify checks a pack offline and needs no licence. frameworks lists the control mappings. A pack supports, and does not certify, compliance (docs/evidence-packs.md).

The register lists every external MCP server, model endpoint and A2A peer with first and last use, call counts, residency and cost (DORA Art. 28(3) register of information).

Flags#

FlagTypeDescriptionDefault
--jwksstringJWKS file or URL (the gateway's /v1/audit/jwks)none
--pubkeystringPEM file with the signing public key(s)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna evidence verify pack.zip --jwks "$GW/v1/audit/jwks"

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.
  • Exits 3 when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch)