MAQPNADocs

maqpna token mint

Mint a session token from the identity broker or a local signing key

Run agents-o json | yaml

Synopsis#

maqpna token mint [--broker URL | --key FILE] --namespace NS --agent A --session S [--user EMAIL] [--scope S]... [--tier T] [--ttl 15m] [--json]

Flags#

FlagTypeDescriptionDefault
--agentstringagent namenone
--audiencestringaudience (default: broker default / maqpna-gateway)none
--brokerstringidentity broker base URLnone
--broker-tokenstringbroker bearer token (env MAQPNA_BROKER_TOKEN)none
--issuerstringissuer for offline mintingmaqpna-identity
--jsonswitchprint the full JSON responsenone
--keystringmint offline with this signing key instead of a brokernone
--namespacestringagent namespacenone
--scopestringscope (repeatable or comma-separated)none
--sessionstringsession IDnone
--tierstringsandbox tiernone
--trust-domainstringtrust domain for offline mintingmaqpna.local
--ttldurationtoken lifetime15m0s
--userstringon-behalf-of usernone

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna token mint --key identity.key --namespace team-a --agent coder --session s1 --scope tools:echo

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna token mint.cast