maqpna token
Mint, inspect and verify session tokens
Synopsis#
maqpna token mint [--broker URL | --key FILE] --namespace NS --agent A --session S [--user EMAIL] [--scope S]... [--tier T] [--ttl 15m] [--json]
maqpna token inspect TOKEN
maqpna token verify TOKEN --jwks URL|FILE [--audience maqpna-gateway] [--issuer ISS] (exit 3 when invalid)Subcommands#
maqpna token mintMint a session token from the identity broker or a local signing key
maqpna token inspectDecode a session token and print its claims (no verification)
maqpna token verifyVerify a session token's signature and claims against a JWKS
Examples#
maqpna token mint --key identity.key --namespace team-a --agent coder --session s1 --scope tools:echo
maqpna token inspect "$TOKEN"
maqpna token verify "$TOKEN" --jwks http://127.0.0.1:8081/.well-known/jwks.jsonWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON. - Exits
3when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) |