MAQPNADocs

maqpna-identity

The identity broker: mints the short-lived session tokens the gateway verifies.

Server binaries

Synopsis#

maqpna-identity [flags]

Flags#

FlagTypeDescriptionDefault
-audiencestringdefault token audience (aud)maqpna-gateway
-bootstrap-audiencestringaudience of the projected ServiceAccount tokens presented to /v1/bootstrapmaqpna-bootstrap
-bootstrap-listenstringlisten address of the warm-pool bootstrap endpoint (POST /v1/bootstrap; needs in-cluster API access); empty = disablednone
-default-ttldurationtoken lifetime when ttlSeconds is 015m0s
-exchange-configstringJSON allowlist of token-exchange audiencesnone
-generate-keyswitchgenerate the signing key if -key does not existnone
-issuerstringtoken issuer (iss)maqpna-identity
-keystringEd25519 signing key (PKCS#8 PEM)/var/run/maqpna/identity/identity.key
-listenstringlisten address:8081
-max-delegation-depthintmaximum act-chain depth of A2A delegation tokens5
-max-ttldurationmaximum token lifetime1h0m0s
-previous-keysstringcomma-separated PEM files of retired-but-trusted public keys (rotation)none
-sandbox-api-versionstringagent-sandbox API version (Sandbox / SandboxClaim)v1beta1
-tenant-keys-dirstringdirectory of <tenant>.pem signing keys (Secret maqpna-tenant-keys)/var/run/maqpna/tenant-keys
-tenant-reloaddurationhow often -tenants-file and -tenant-keys-dir are re-read10s
-tenants-filestringtenants.json (ConfigMap maqpna-tenants): sign tenant namespaces' tokens with per-tenant keys (F-27)none
-trust-domainstringSPIFFE trust domainmaqpna.local
-txn-token-audiencestringexpected Transaction Token audience (default: the trust domain)none
-txn-token-keysstringcomma-separated PEM public keys trusted for Transaction Tokens used as A2A delegation subjects (the broker key is always trusted)none
-versionswitchprint version and exitnone

What happens when you run it#

  • A long-running server. The Helm chart starts it with these flags; set them through the chart's values rather than by hand.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed

Terminal demo#

maqpna-identity -h.cast