Check it yourself
Trust & verification
Decide what ProtocolSoup exposes you to, close a security alert, or verify the software before it enters your environment.
Last reviewed: 2026-08-22
Security alert triage
What fired, why it is expected, and how to block it.
Is this malicious?
No. ProtocolSoup is an open-source, browser-based identity protocol sandbox. The indicators below are generated by documented product features. It installs no endpoint agent, extension, service, persistence mechanism, or elevated component. You can verify that conclusion against the public source and the signed image instructions below.
| What may trip a tool | Why ProtocolSoup produces it | Disposition |
|---|---|---|
| JWT-shaped strings, JWK/JWKS data, and certificates | The console renders demo tokens, public verification keys, and certificates so a user can inspect real protocol artefacts. | Expected. Public verification material and short-lived demo tokens are not leaked host secrets. |
| OID4VCI tx_code values that resemble hardcoded secrets | A fresh six-digit, one-time user code is generated for each pre-authorized credential offer. | Expected. Treat it as ephemeral demo flow data, not an application credential. |
| SAML XML containing X.509 material | SAML metadata and signed assertions carry the certificate required to verify the XML signature. | Expected protocol content. |
| did:key or did:jwk key-shaped strings | These DID methods encode public verification material in the identifier or DID document. | Expected protocol content. |
| Synthetic identities ending in @example.com | The hosted demonstrations use reserved example identities instead of real employee records. | Expected test data. |
| WebSocket traffic at /ws/lookingglass/{session_id} | Looking Glass streams live flow events from the server to the open browser session. | Expected first-party application traffic. |
| OIDC dynamic client registration | The sandbox lets a flow register a temporary client. Registrations expire after two hours and the store is capped at 200 clients. | Expected demo control-plane traffic, not permanent enterprise provisioning. |
| OIDC discovery succeeds with GET but fails with HEAD | GET /.well-known/openid-configuration returns the discovery document; HEAD is not implemented consistently on the demo route. | Use GET for validation. A HEAD-only probe can report a false negative. |
Browser-visible hosts and when they are used:
| Host | Purpose |
|---|---|
| protocolsoup.com | User interface, protocol APIs, same-origin Next.js assets, and Looking Glass WebSocket traffic. |
| wallet.protocolsoup.com | Hosted wallet user interface during OID4VCI and OID4VP wallet flows. |
| docs.protocolsoup.com | Documentation, only when a user opens it. |
| static.cloudflareinsights.com / a.nel.cloudflare.com | Cloudflare-managed browser telemetry and network error reporting may appear. |
| github.com / openid.net | Only when a user follows source, verification, or certification links. |
To block ProtocolSoup, deny protocolsoup.com and *.protocolsoup.com in DNS filtering, a secure web gateway, or an outbound proxy. To stop only live event streaming, deny wss://protocolsoup.com/ws/lookingglass/*. Closing the tab stops browser activity; there is no endpoint component to uninstall.
What ProtocolSoup is
The product, hosted service, and data it touches.
ProtocolSoup is an open-source, vendor-neutral reference implementation for identity protocols. It runs real OAuth 2.0, OpenID Connect, OpenID4VCI, OpenID4VP, SAML, SPIFFE/SPIRE, SCIM, and Shared Signals flows so users can inspect the requests, responses, tokens, assertions, and validation decisions.
Hosted demo, not a production control
The public instance is an educational sandbox with mock identity-provider behaviour enabled. Do not depend on it for production authentication, and do not send production credentials, employee directories, or other sensitive data to it.
| Surface | What it touches |
|---|---|
| Browser | Normal site JavaScript, flow state in sessionStorage, and recent command-palette searches in localStorage. |
| Hosted applications | ProtocolSoup, its wallet harness, documentation, and the SPIRE demonstration running on Fly.io in Sydney. |
| Protocol data | Demo tokens, assertions, credentials, public keys, certificates, synthetic identities, and user-entered test values. |
| Durable state | Some SCIM, SSF, signing-key, mdoc PKI, and replay-protection records as described under Hosted data. |
| Endpoint device | No agent, extension, service, privileged component, filesystem scan, or device-management integration. |
Trust boundary
Where requests and state cross an operator or provider boundary.
A browser connects to Cloudflare, which provides DNS and HTTP proxying, then to the ProtocolSoup applications on Fly.io. The wallet is a separate browser origin. Application state is held in memory, on Fly volumes, or in a Fly Redis service depending on the protocol feature.
Browser
-> Cloudflare (DNS and HTTP proxy)
-> Fly.io (ProtocolSoup, wallet, docs, SPIRE)
-> memory / Fly volume / Fly Redis, depending on the flow| Party | Role in the boundary |
|---|---|
| ProtocolSoup / Mason Parle | Application code, configuration, hosted-service operation, and vulnerability response. |
| Cloudflare | DNS, edge TLS, and HTTP proxying. |
| Fly.io | Application compute, volumes, and Redis hosting in Sydney. |
| GitHub / GHCR | Public source, CI history, and published gateway images. |
| Sigstore Fulcio and Rekor | Keyless signing and a public transparency-log record for published images. |
You can inspect public source, endpoints, image signatures, provenance, and the SBOM. You cannot independently inspect the hosted instance’s live environment variables, provider control planes, or whether the running process still matches the most recently published image. Self-hosting removes that operator-runtime assumption.
Self-hosting and verification
Run the published code inside a boundary you control.
Strongest verification option
Build and run ProtocolSoup yourself. Your team then controls ingress, egress, identity data, logs, retention, updates, and availability instead of taking the public instance’s runtime configuration on faith.
git clone https://github.com/ParleSec/ProtocolSoup.git
cd ProtocolSoup/docker
docker compose up -d --buildReview the repository quick start and deployment documentation. For a prebuilt gateway, resolve and pin an immutable signed digest before deployment; do not deploy the moving latest tag as your trust anchor.
Verify the supply chain
Resolve the current digest, then verify that immutable image.
The latest tag moves whenever a new gateway image is published, so this page does not pin a digest that will go stale. Resolve the current multi-platform index digest and substitute it into every command below.
docker buildx imagetools inspect ghcr.io/parlesec/protocolsoup-gateway:latest
# Copy the top-level Digest value, then pin every subsequent command:
IMAGE='ghcr.io/parlesec/protocolsoup-gateway@sha256:<current-index-digest>'Verify GitHub’s provenance attestation and bind the digest to the ProtocolSoup repository (--format json keeps the result explicit and machine-readable):
gh attestation verify "oci://$IMAGE" --repo ParleSec/ProtocolSoup --format jsonVerify the independent Sigstore signature and the publishing workflow identity:
cosign verify \
--certificate-identity-regexp 'https://github.com/ParleSec/ProtocolSoup/.github/workflows/ghcr-publish.yml@refs/heads/master' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
"$IMAGE"Inspect the SPDX SBOM attached to that same immutable digest:
docker buildx imagetools inspect "$IMAGE" --format '{{ json .SBOM }}'The publishing workflow builds linux/amd64 and linux/arm64 images, signs the resulting index, and publishes provenance and an SBOM. Trivy HIGH and CRITICAL findings are reported to code scanning but do not block publication; Snyk scan steps also continue on error. Treat those as visibility controls, not a release gate.
Hosted data and retention
What persists when you use protocolsoup.com.
SCIM requires an Authorization header. The browser keeps short-lived correlation values such as PKCE verifiers, OAuth state, OIDC nonces, and pending wallet flows in sessionStorage. Recent command-palette searches are the only ProtocolSoup value stored in localStorage.
| Store | Retention or lifecycle |
|---|---|
| SCIM users and groups | 24-hour default retention with an hourly cleanup pass. |
| Looking Glass sessions | In memory; 30-minute idle timeout and four-hour absolute timeout. |
| OID4VP request sessions | Five-minute request TTL plus a ten-minute grace period. |
| OIDC dynamic clients | Two-hour TTL; store capped at 200 clients. |
| SSF stream state on /data/ssf | Persistent state; no age-based purge. |
| OP signing keys and mdoc PKI | Persistent by design on the application volume. |
| DPoP and private_key_jwt replay records | Short-lived Redis records bounded by the proof or assertion lifetime plus 60 seconds. |
The public applications run as single Fly machines in Sydney. There is no second replica, published SLA, or public status page. A machine, region, provider, or operator failure can make the demonstration unavailable. Fly volume snapshots are retained for five days.
ProtocolSoup does not deploy first-party product analytics. Cloudflare-managed browser telemetry or network error reporting may still be requested from Cloudflare domains.
Certified surface
Named ProtocolSoup versions and OpenID profiles listed by OIDF.
OpenID Certified™
OpenID Certified™ by ProtocolSoup for the OID4VCI Issuer, OID4VCI Wallet, OID4VP Verifier and OID4VP Wallet profiles.
| Profile | Version | Variant | Test log | Signed result | Register |
|---|---|---|---|---|---|
| OID4VCI Issuer | v4.0.0 | sd_jwt_vc issuer_initiated | test log | signed result | register |
| OID4VCI Issuer | v4.0.0 | sd_jwt_vc wallet_initiated | test log | signed result | register |
| OID4VCI Issuer | v4.0.0 | mdoc issuer_initiated | test log | signed result | register |
| OID4VCI Issuer | v4.0.0 | mdoc wallet_initiated | test log | signed result | register |
| OID4VP Verifier | v4.0.0 | sd_jwt_vc direct_post.jwt | test log | signed result | register |
| OID4VP Verifier | v4.0.0 | iso_mdl direct_post.jwt | test log | signed result | register |
| OID4VP Wallet | v4.0.0 | sd_jwt_vc direct_post.jwt | test log | signed result | register |
| OID4VP Wallet | v4.0.0 | iso_mdl direct_post.jwt | test log | signed result | register |
| OID4VCI Wallet | v4.1.0 | sd_jwt_vc wallet_initiated by_value | test log | signed result | register |
| OID4VCI Wallet | v4.1.0 | sd_jwt_vc issuer_initiated by_value | test log | signed result | register |
| OID4VCI Wallet | v4.1.0 | sd_jwt_vc issuer_initiated by_reference | test log | signed result | register |
| OID4VCI Wallet | v4.1.0 | mdoc wallet_initiated by_value | test log | signed result | register |
| OID4VCI Wallet | v4.1.0 | mdoc issuer_initiated by_value | test log | signed result | register |
| OID4VCI Wallet | v4.1.0 | mdoc issuer_initiated by_reference | test log | signed result | register |
Certification applies to the named ProtocolSoup version and profile pairs published on openid.net. It is not a blanket certification of every ProtocolSoup feature, protocol family, or the moving hosted deployment.
OpenID® and OpenID Certified™ are trademarks of the OpenID Foundation.
Governance and continuity
Who runs it and what happens if that person stops.
ProtocolSoup is maintained by Mason Parle under the ParleSec GitHub account. It is a single-maintainer project: CODEOWNERS assigns the repository to @ParleSec, and there is no separate incorporated ProtocolSoup entity.
| Control | What is public |
|---|---|
| Licence | The repository LICENSE grants Apache License 2.0 terms. |
| Contributions | CONTRIBUTING.md requires Developer Certificate of Origin sign-off. |
| Review ownership | .github/CODEOWNERS assigns all paths to @ParleSec. |
| Release continuity | Source can be forked under Apache 2.0; signed images can be pinned or mirrored by digest. |
Verify these controls in the LICENSE, contribution guide, and CODEOWNERS. If maintenance stops, the licence and public history allow an independent fork; they do not guarantee that one will be maintained.
Limits and assumptions
What has not been independently assured.
No enterprise assurance package
ProtocolSoup has no SOC 2 report, ISO 27001 certification, independent penetration-test report, contractual SLA, support contract, or separate legal entity. It is maintained by one person.
- The hosted service is an educational demonstration, not a production identity provider or availability dependency.
- Single-machine, single-region hosting means an infrastructure or operator failure is an outage.
- Public source and attestations let you verify code-to-image provenance; they do not prove the live runtime configuration, secret handling, or provider control-plane state.
- Published retention behaviour is implemented in code but is not backed by a contractual deletion guarantee.
- Automated dependency and vulnerability findings are reported, but high-severity results do not block every release path.
- SSF state, signing keys, and mdoc PKI persist. Do not put sensitive or production identity data into the hosted instance.
If those assumptions are not acceptable, block the public domains and run a reviewed commit or verified image inside your own environment.
Vulnerability disclosure
A contact that also works without JavaScript.
Report privately to mason@protocolsoup.com. Do not open a public GitHub issue. The acknowledgment target is 48 hours; remediation and disclosure timing are coordinated with the reporter.
In scope: ProtocolSoup application code, official Docker images published to GHCR, and documentation that could lead to insecure configurations. Third-party dependencies and modified self-hosted deployments are outside the project’s control.
Machine-readable policy: /.well-known/security.txt. This page was last reviewed 2026-08-22.
