maqpna usage
Hourly usage per tenant: sandbox seconds, governed calls, model tokens, approvals
Synopsis#
maqpna usage buckets [--from 24h|RFC3339] [--to RFC3339] [--tenant T] [--ledger FILE | --gateway URL]
[--no-sessions] [--format table|csv] [-o json]
maqpna usage report (--period 2027-01 | --from DATE --to DATE) --key KEYURI [--tenant T] [--out DIR]
[--price-file prices.yaml] [--ledger FILE | --gateway URL] [--no-sessions]
[--installation-id ID] [--license FILE] [--default-vcpu 1] [-o json]
signed report.json + report.focus.csv (FOCUS 1.2, list price × quantity) + summary
maqpna usage verify report.json (--pubkey PEM | --jwks URL|FILE) [--ledger FILE] [-o json]
signature + totals recomputed from the buckets (exit 3 on tamper or bad signature)
maqpna usage export (--period 2027-01 | --from DATE --to DATE) --key KEYURI [--out FILE] [source flags as report]
signed, pseudonymized JSON for an air-gapped true-up with MAQPNA (O-4; nothing is sent)Description#
Sandbox seconds come from AgentSessions (status.readyAt to status.outcome.finishedAt, or now while running; sessions that never became ready are not billed). Calls, tokens and approval requests come from the audit ledger (--ledger FILE offline, or the gateway's /v1/audit/records). Namespaces map to tenants through Tenant.spec.namespaces; usage outside any tenant has an empty tenant. Buckets carry counts only.
Finished sessions' sandbox time is also recorded by the gateway in the ledger (usageReporting, decision "usage"), so it survives AgentSession garbage collection; sessions found in the ledger are not counted twice.
Subcommands#
maqpna usage bucketsPrint hourly usage buckets per tenant
maqpna usage reportWrite a signed usage report and its FOCUS cost export
maqpna usage verifyVerify a usage report's signature and recompute its totals
maqpna usage exportWrite signed, pseudonymized usage for an air-gapped true-up
Examples#
maqpna usage buckets --from 24h --gateway "$GW"
maqpna usage report --period 2027-01 --key checkpoint.key --out reports/
maqpna usage verify reports/report.json --pubkey usage.pubWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON. - Exits
3when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) |