Download MAQPNA
Command-line tools for Linux, macOS and Windows, server binaries, Linux packages, multi-arch container images and the Helm chart. Every file has a SHA256 checksum, a cosign keyless signature and an SBOM, built reproducibly from the tagged source.
| Latest release | v0.1.0 · 2026-10-02 |
|---|---|
| Release | github.com/AzmxAI/maqpna-releases/releases/tag/v0.1.0 |
| Checksums | checksums.txt · signature: bundle, .sig + .pem |
| Current stable | github.com/AzmxAI/maqpna-releases/releases/latest |
| Mirror | https://dl.maqpna.com · SHA256SUMS · stable.txt |
Quick install
The install scripts download the CLIs (maqpna and maqpna-sovereign) for your
platform from the GitHub release, check the SHA256 against the release's checksums.txt and — if
cosign is installed — the signature, and install them to /usr/local/bin (or
~/.local/bin) or %LOCALAPPDATA%\Programs\maqpna\bin.
Linux and macOS
curl -fsSL https://maqpna.com/install.sh | sh
# a specific version, one binary, require a cosign signature:
curl -fsSL https://maqpna.com/install.sh | sh -s -- --version v0.1.0 --bin maqpna --cosign
# from the dl.maqpna.com mirror instead of GitHub:
curl -fsSL https://maqpna.com/install.sh | sh -s -- --mirrorWindows (PowerShell)
irm https://maqpna.com/install.ps1 | iexPackage managers
| Platform | Command |
|---|---|
| Homebrew (macOS, Linux) | brew install azmxai/maqpna/maqpna |
| winget (Windows) | winget install MAQPNA.maqpna |
| Scoop (Windows) | scoop bucket add maqpna https://github.com/AzmxAI/scoop-maqpnascoop install maqpna/maqpna |
| Debian, Ubuntu (.deb) | curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/maqpna_0.1.0_linux_amd64.debsudo apt install ./maqpna_0.1.0_linux_amd64.deb |
| RHEL, Fedora, SUSE (.rpm) | sudo dnf install https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/maqpna_0.1.0_linux_amd64.rpm |
| Alpine (.apk) | curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/maqpna_0.1.0_linux_amd64.apksudo apk add --allow-untrusted ./maqpna_0.1.0_linux_amd64.apk |
The Homebrew tap (AzmxAI/homebrew-maqpna)
serves the formula from the first public release. The Scoop bucket (AzmxAI/scoop-maqpna), the winget
package and the signed apt / yum repositories are planned and open later. Until then use the install scripts, the
packages above or the binaries below. Package files for other architectures are listed under
Linux packages.
Binaries
Every file is a GitHub release asset:
https://github.com/AzmxAI/maqpna-releases/releases/download/<version>/<binary>_<os>_<arch>
(.exe on Windows), with its cosign signature bundle next to it as
<file>.sigstore.json and its digest in the release's checksums.txt. The mirror at
https://dl.maqpna.com serves the same files in the dl.k8s.io layout,
https://dl.maqpna.com/<version>/bin/<os>/<arch>/<binary>, each with a
.sha256 (the hex digest) and a .sigstore.json.
All binaries are static (CGO_ENABLED=0).
Linux 22 files
CLIs for amd64, arm64, ppc64le and s390x; servers for amd64 and arm64.
macOS 10 files
Apple silicon (arm64), Intel (amd64) and universal CLIs; gateway and identity for local development.
| Binary | Architecture | Download | Verify | Mirror | Size |
|---|---|---|---|---|---|
maqpna | amd64 (x86-64) | maqpna_darwin_amd64 | signature | GitHub only | 75.0 MiB |
maqpna | arm64 | maqpna_darwin_arm64 | signature | mirror sha256 | |
maqpna | universal (arm64 and amd64) | maqpna_darwin_universal | signature | GitHub only | 145.0 MiB |
maqpna-sovereign | amd64 (x86-64) | maqpna-sovereign_darwin_amd64 | signature | mirror sha256 | 10.1 MiB |
maqpna-sovereign | arm64 | maqpna-sovereign_darwin_arm64 | signature | mirror sha256 | 9.3 MiB |
maqpna-sovereign | universal (arm64 and amd64) | maqpna-sovereign_darwin_universal | signature | mirror sha256 | 19.4 MiB |
maqpna-gateway | amd64 (x86-64) | maqpna-gateway_darwin_amd64 | signature | mirror sha256 | 17.0 MiB |
maqpna-gateway | arm64 | maqpna-gateway_darwin_arm64 | signature | mirror sha256 | 15.7 MiB |
maqpna-identity | amd64 (x86-64) | maqpna-identity_darwin_amd64 | signature | mirror sha256 | |
maqpna-identity | arm64 | maqpna-identity_darwin_arm64 | signature | mirror sha256 |
Windows 8 files
CLIs for amd64 and arm64; gateway and identity for local development.
| Binary | Architecture | Download | Verify | Mirror | Size |
|---|---|---|---|---|---|
maqpna | amd64 (x86-64) | maqpna_windows_amd64.exe | signature | GitHub only | 74.5 MiB |
maqpna | arm64 | maqpna_windows_arm64.exe | signature | mirror sha256 | |
maqpna-sovereign | amd64 (x86-64) | maqpna-sovereign_windows_amd64.exe | signature | mirror sha256 | 10.0 MiB |
maqpna-sovereign | arm64 | maqpna-sovereign_windows_arm64.exe | signature | mirror sha256 | 9.1 MiB |
maqpna-gateway | amd64 (x86-64) | maqpna-gateway_windows_amd64.exe | signature | mirror sha256 | 16.9 MiB |
maqpna-gateway | arm64 | maqpna-gateway_windows_arm64.exe | signature | mirror sha256 | 15.4 MiB |
maqpna-identity | amd64 (x86-64) | maqpna-identity_windows_amd64.exe | signature | mirror sha256 | |
maqpna-identity | arm64 | maqpna-identity_windows_arm64.exe | signature | mirror sha256 |
On the mirror, binaries larger than 25 MiB are served as a .tar.gz (or
.zip) of the single binary plus LICENSE and README; GitHub serves every raw binary.
Archives and SBOMs 46 files
maqpna_<version>_* holds both CLIs (used by Homebrew, Scoop and winget); the other archives hold one
binary each. macOS and Windows archives are .zip, Linux .tar.gz. Every archive has an SPDX SBOM.
Linux packages 12 files
The maqpna package installs both CLIs to /usr/bin.
| Package | Verify | Mirror | Size |
|---|---|---|---|
| maqpna_0.1.0_linux_amd64.apk | signature | GitHub only (over the mirror's 25 MiB limit) | 27.4 MiB |
| maqpna_0.1.0_linux_amd64.deb | signature | GitHub only (over the mirror's 25 MiB limit) | 26.2 MiB |
| maqpna_0.1.0_linux_amd64.rpm | signature | GitHub only (over the mirror's 25 MiB limit) | 26.2 MiB |
| maqpna_0.1.0_linux_arm64.apk | signature | mirror sha256 | 24.4 MiB |
| maqpna_0.1.0_linux_arm64.deb | signature | mirror sha256 | 23.4 MiB |
| maqpna_0.1.0_linux_arm64.rpm | signature | mirror sha256 | 23.4 MiB |
| maqpna_0.1.0_linux_ppc64le.apk | signature | mirror sha256 | 24.3 MiB |
| maqpna_0.1.0_linux_ppc64le.deb | signature | mirror sha256 | 23.3 MiB |
| maqpna_0.1.0_linux_ppc64le.rpm | signature | mirror sha256 | 23.3 MiB |
| maqpna_0.1.0_linux_s390x.apk | signature | GitHub only (over the mirror's 25 MiB limit) | 26.7 MiB |
| maqpna_0.1.0_linux_s390x.deb | signature | GitHub only (over the mirror's 25 MiB limit) | 25.1 MiB |
| maqpna_0.1.0_linux_s390x.rpm | signature | GitHub only (over the mirror's 25 MiB limit) | 25.1 MiB |
Verify downloads
Checksum
curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/maqpna_linux_amd64
curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/checksums.txt
grep ' maqpna_linux_amd64$' checksums.txt | sha256sum --checkcurl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/maqpna_darwin_arm64
curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/checksums.txt
grep ' maqpna_darwin_arm64$' checksums.txt | shasum -a 256 --checkInvoke-WebRequest https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/maqpna_windows_amd64.exe -OutFile maqpna_windows_amd64.exe
Invoke-WebRequest https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/checksums.txt -OutFile checksums.txt
$want = ((Select-String -Path checksums.txt -Pattern ' maqpna_windows_amd64\.exe$').Line -split '\s+')[0]
(Get-FileHash .\maqpna_windows_amd64.exe -Algorithm SHA256).Hash -eq $want # TrueOn the mirror every file has a .sha256 next to it (the hex digest), e.g.
https://dl.maqpna.com/v0.1.0/bin/linux/amd64/maqpna.sha256; its SHA256SUMS is the release's
checksums.txt.
Signature (cosign keyless)
Release files are signed in GitHub Actions with Sigstore keyless signing: the certificate binds the signature to the workflow that built and signed the release (the identity below). There is no long-lived signing key. Verify with cosign 2.x or later:
curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/maqpna_linux_amd64.sigstore.json
cosign verify-blob maqpna_linux_amd64 \
--bundle maqpna_linux_amd64.sigstore.json \
--certificate-identity-regexp '^https://github\.com/AzmxAI/azmx-ai/\.github/workflows/maqpna-signed-release\.yml@refs/.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comchecksums.txt lists every release asset and is signed the same way:
curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/checksums.txt
curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/checksums.txt.sigstore.json
cosign verify-blob checksums.txt --bundle checksums.txt.sigstore.json \
--certificate-identity-regexp '^https://github\.com/AzmxAI/azmx-ai/\.github/workflows/maqpna-signed-release\.yml@refs/.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
sha256sum --ignore-missing --check checksums.txtBuild provenance and SBOMs
Archives and packages carry SLSA build provenance attestations generated by GitHub Actions. Check one with the GitHub CLI:
gh attestation verify maqpna_0.1.0_linux_amd64.tar.gz --owner AzmxAIEvery archive has an SPDX 2.3 SBOM next to it (<archive>.spdx.json); container images carry
their SBOM as a signed cosign attestation.
Container images
Multi-arch images (linux/amd64, linux/arm64) are published to
ghcr.io/azmxai/maqpna. The runtime images are distroless and run as UID 65532.
| Image | Platforms | Digest |
|---|---|---|
ghcr.io/azmxai/maqpna/maqpna-operator:0.1.0 | linux/amd64, linux/arm64 | 5fe44700001a |
ghcr.io/azmxai/maqpna/maqpna-gateway:0.1.0 | linux/amd64, linux/arm64 | 7ac0e3592ad7 |
ghcr.io/azmxai/maqpna/maqpna-identity:0.1.0 | linux/amd64, linux/arm64 | 6b6bf6dacb01 |
ghcr.io/azmxai/maqpna/maqpna-attest:0.1.0 | linux/amd64, linux/arm64 | 53f35a46b6d5 |
ghcr.io/azmxai/maqpna/maqpna-attest-agent:0.1.0 | linux/amd64, linux/arm64 | 1fad4bb710a8 |
ghcr.io/azmxai/maqpna/maqpna-exec:0.1.0 | linux/amd64, linux/arm64 | b8b20fc9510d |
ghcr.io/azmxai/maqpna/maqpna-egress-relay:0.1.0 | linux/amd64, linux/arm64 | bcf54db26d62 |
ghcr.io/azmxai/maqpna/maqpna-browser:0.1.0 | linux/amd64, linux/arm64 | 34eac01d0969 |
ghcr.io/azmxai/maqpna/maqpna-code-interpreter:0.1.0 | linux/amd64, linux/arm64 | e6f3363be0b6 |
ghcr.io/azmxai/maqpna/maqpna-cli:0.1.0 | linux/amd64, linux/arm64 | 7965b5bb1de2 |
ghcr.io/azmxai/maqpna/mcp-echo:0.1.0 | linux/amd64, linux/arm64 | d34ee9b3d41e |
Pin images by digest in production. Verify the signature and the SBOM attestation:
cosign verify ghcr.io/azmxai/maqpna/maqpna-gateway:0.1.0 \
--certificate-identity https://github.com/AzmxAI/maqpna/.github/workflows/release.yml@refs/tags/v0.1.0 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
cosign verify-attestation --type spdxjson ghcr.io/azmxai/maqpna/maqpna-gateway:0.1.0 \
--certificate-identity https://github.com/AzmxAI/maqpna/.github/workflows/release.yml@refs/tags/v0.1.0 \
--certificate-oidc-issuer https://token.actions.githubusercontent.comHelm chart
The chart is published as an OCI artifact. The values-sovereign-eu.yaml profile ships inside the chart.
helm pull oci://ghcr.io/azmxai/maqpna/charts/maqpna --version 0.1.0 --untar
helm install maqpna ./maqpna \
--namespace maqpna-system --create-namespace \
--set image.registry=ghcr.io/azmxai/maqpna \
-f maqpna/values-sovereign-eu.yamlPlatform guides: Azure AKS · Amazon EKS · Google GKE · OpenShift · k3s and kind. Air-gapped clusters: see air-gapped install.
macOS notes
Release builds of the macOS binaries are code-signed with an Apple Developer ID (hardened runtime) and the
.zip archives are notarized by Apple. Homebrew, the install script and curl do not
set the quarantine attribute in any case. If you have an unsigned build (for example a development snapshot)
and macOS refuses to open a binary downloaded with a browser, verify the checksum and signature first, then
clear the attribute:
xattr -d com.apple.quarantine ./maqpna
chmod +x ./maqpnaOlder releases
v0.1.0 is the first release. Older versions will be listed here, and stay available on
github.com/AzmxAI/maqpna-releases/releases and at
https://dl.maqpna.com/<version>/….