MAQPNADocs

maqpna token verify

Verify a session token's signature and claims against a JWKS

Run agents-o json | yaml

Synopsis#

maqpna token verify TOKEN --jwks URL|FILE [--audience maqpna-gateway] [--issuer ISS]   (exit 3 when invalid)

Flags#

FlagTypeDescriptionDefault
--audiencestringrequired audience (e.g. maqpna-gateway)none
--issuerstringrequired issuernone
--jwksstringJWKS URL (https://.../.well-known/jwks.json) or filenone

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna token verify "$TOKEN" --jwks http://127.0.0.1:8081/.well-known/jwks.json

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.
  • Exits 3 when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch)

Terminal demo#

maqpna token verify.cast