maqpna token mint
Mint a session token from the identity broker or a local signing key
Synopsis#
maqpna token mint [--broker URL | --key FILE] --namespace NS --agent A --session S [--user EMAIL] [--scope S]... [--tier T] [--ttl 15m] [--json]Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--agent | string | agent name | none |
--audience | string | audience (default: broker default / maqpna-gateway) | none |
--broker | string | identity broker base URL | none |
--broker-token | string | broker bearer token (env MAQPNA_BROKER_TOKEN) | none |
--issuer | string | issuer for offline minting | maqpna-identity |
--json | switch | print the full JSON response | none |
--key | string | mint offline with this signing key instead of a broker | none |
--namespace | string | agent namespace | none |
--scope | string | scope (repeatable or comma-separated) | none |
--session | string | session ID | none |
--tier | string | sandbox tier | none |
--trust-domain | string | trust domain for offline minting | maqpna.local |
--ttl | duration | token lifetime | 15m0s |
--user | string | on-behalf-of user | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna token mint --key identity.key --namespace team-a --agent coder --session s1 --scope tools:echoWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |