maqpna token verify
Verify a session token's signature and claims against a JWKS
Synopsis#
maqpna token verify TOKEN --jwks URL|FILE [--audience maqpna-gateway] [--issuer ISS] (exit 3 when invalid)Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--audience | string | required audience (e.g. maqpna-gateway) | none |
--issuer | string | required issuer | none |
--jwks | string | JWKS URL (https://.../.well-known/jwks.json) or file | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna token verify "$TOKEN" --jwks http://127.0.0.1:8081/.well-known/jwks.jsonWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON. - Exits
3when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) |