MAQPNADocs

maqpna usage verify

Verify a usage report's signature and recompute its totals

Observe-o json | yaml

Synopsis#

maqpna usage verify report.json (--pubkey PEM | --jwks URL|FILE) [--ledger FILE] [-o json]
                     signature + totals recomputed from the buckets (exit 3 on tamper or bad signature)

Description#

From the help of maqpna usage:

Sandbox seconds come from AgentSessions (status.readyAt to status.outcome.finishedAt, or now while running; sessions that never became ready are not billed). Calls, tokens and approval requests come from the audit ledger (--ledger FILE offline, or the gateway's /v1/audit/records). Namespaces map to tenants through Tenant.spec.namespaces; usage outside any tenant has an empty tenant. Buckets carry counts only.

Finished sessions' sandbox time is also recorded by the gateway in the ledger (usageReporting, decision "usage"), so it survives AgentSession garbage collection; sessions found in the ledger are not counted twice.

Flags#

FlagTypeDescriptionDefault
--jwksstringJWKS file or URL (the gateway's /v1/audit/jwks)none
--ledgerstringalso check the report's ledger head against this ledger copynone
--pubkeystringPEM file with the signing public key(s)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna usage verify reports/report.json --pubkey usage.pub

What happens when you run it#

  • Reads the audit ledger offline with --ledger FILE: also check the report's ledger head against this ledger copy.
  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.
  • Exits 3 when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch)

Terminal demo#

maqpna usage verify.cast