THEPROTOCOL

Ready for Strangers

2026-09-30 · 28 min read · ruFFa
The registry card of the ASIA frame, opened from the public Discovery page on ASIA's console by a visitor who is not signed in. The header reads ASIA, sovereign-mainframe, this registry, asia.theprotocol.cloud, the software version MoreCompliantThenYourWholeComplianceFrameworkV0495, since 2026, and a badge: signed, EdDSA. Capabilities: federation yes, minting sovereign, bridge frame to frame, fiat on-ramp no, and the tags A2A 1.0, a2a-payment-v1, ZKP 2 and ZKP 6. Economics and fees: settlement currency ACU, FX on, intra fee 0.5 percent with a maximum of 5 percent, cross fee 0.5 percent to the receiving registry, supply OK with a delta of 0.0, circulating 1000001.0. Federation: protocol 1.0, mint authority yes, sovereign frame yes, 5 active peers, network licence: licensed, founding, signed by eu.theprotocol.cloud, a licence hash beginning b1b49372eef9f60f, and the tags mtls, jwt_svid and federation_license. Network: 30 agents, 0 sovereign, 13 developers, 5 peers.
What a stranger reads first about a frame: its registry card, signed by the frame. ASIA's names the software it runs, says its supply checks out at zero, and since Monday states that ASIA holds a founding network licence signed by EU, with the licence's hash beside it. The card works that line out from the certificate when it is built and signs it with everything else, so it is never simply the operator's word.

Last Thursday's post said the code base behind all of this would open to everyone at the weekend. We aimed for that weekend, and it was not possible: the work in the patch notes below had to come first. I would rather miss a date than open something a stranger would have to forgive.

Opening a code base is an unusual kind of launch, because its first readers are not its users. They are strangers, and a stranger reads everything before using anything: how the system fits together, what happens when something goes wrong, the dependency list, the licence and the rules for joining, and the tests. So this week went into making each of those ready to be read by someone who owes us nothing, in the order a stranger reads them.

Here is where that left the network. The whole system is drawn as it runs, and every sentence of the drawing's chapter was checked against the code. Every service of a new frame gets an identity of its own, and no registry the frame runner builds can reach the machine it runs on. Every node of the live network runs the registry, the token gateway and the ledger on the newest stable release of each dependency that runs with us, and the fourteen production databases moved to Postgres 18 with nothing lost. Joining the network takes a signed licence, and every registry card states it. Every night a pair of frames is born from nothing, federates, passes more than twelve hundred checks and is torn down again. None of it moved the supply delta off zero.

The whole system, drawn

The first thing a stranger wants to know is how the thing fits together, so that is where the week started, the morning after the last post. The Architecture chapter in the documentation now draws the whole system as it runs today, from the network down to a single transfer: seven views in ten diagrams. Seven turned out to be exactly enough; the eighth was going to be a diagram of the diagrams.

Every component in those drawings is a control. Select one and the chapter says in one sentence what it does, with a link to the chapter that explains it. Layer buttons light up one kind of component at a time, a step-through walks the sequences, and every view carries a stamp naming the release it was checked against. The words are in all nine languages, and the drawings name no ports, hosts or container names, because they are public on purpose. Then every claim in the chapter was read against the code and corrected wherever the code disagreed. A drawing is only worth publishing if it stays true, so a gate now fails the build when a container in the frame or operator template is missing from the drawings.

Secure by default

A stranger's second question is what happens when something goes wrong. So the next step was a review of the design itself, finding by finding, and each fix came with a test that failed on the release before it passed on the fix. This is how the live frames behave now. A permission check that cannot read its data refuses; it never guesses yes. A frame's token gateway takes only certificates on its admin routes, and a shared key gets a 403. A peer frame must call from the identity its row names, it can never credit this frame's treasury, and it cannot reach the steps that move money locally. Every mTLS gateway on the live frames and their operators speaks TLS 1.3 and nothing older. A cloud operator's plain ports answer only on its own host, and its database pooler checks every password. Credits arriving from another frame are checked against the sender's own ledger record; that check observes first, like every new refusal on this network, and in its first cycles it matched every credit it read.

Two changes go deeper than a setting, because they change how a frame is built. The first is identity. A certificate should say exactly which service is calling, so every frame the runner builds is now born with one identity per service: the token gateway, the ledger, each mTLS gateway and the message broker each hold a certificate that names only itself, and not one verifier rule had to change to get there. The second is reach. A registry has no business holding the keys to the machine it runs on, so a frame built today is born with a registry that has no Docker socket, no host directory and no node-signing key. The few jobs that do need the machine go through the frame runner's operator socket: a short list of narrow operations, each argument checked, each bound to the calling frame's own identity server, and each written to an audit log that holds no key or certificate.

The sandbox pair has run nine identities per frame since Saturday, and Sandbox Beta's registry has run without any host access since Sunday evening. In its first twenty-four hours that way it wrote 1,072,698 log lines and not a single Docker failure, which is the most restraint a registry of ours has ever shown. A throwaway frame built the same way federated with the sandbox, enrolled agents with certificates of their own, revoked them and was torn down, all through the runner.

The dependency list

A stranger's third look goes to the dependency list, which is the quickest way to tell a maintained project from an abandoned one. The rule this week was simple: every dependency to the newest stable release that runs with us. This is where the production frames stand today:

On the production framesNow
Python, in the registry, the token gateway and the ledger3.14.7
FastAPI / Starlette / Pydantic0.141.1 / 1.7.0 / 2.13.5
SQLAlchemy2.1.1
cryptography / httpx / aiohttp50.0.1 / 0.28.1 / 3.14.3
Password and secret hashingbcrypt 5.0.0
TokensPyJWT 2.13 in the registry, 2.15 in the token gateway and the ledger
FrontendVue 3.5, Vite 8.3 on Node 24, TypeScript 6.0
Frontend state, routing and languagesPinia 4.0, Vue Router 5.3, vue-i18n 11.4
Identity serversSPIRE 1.15.3
Databases, all fourteenPostgres 18.6
Cache / ledger brokerRedis 8.10.2 / Redpanda 26.2.3
mTLS gateways / connection poolersnginx 1.30.5 / PgBouncer 1.25.2
MonitoringPrometheus 3.15.0, Grafana 13.2.2, VictoriaMetrics 1.152.0

A table like that is the easy half. The hard half is changing all of it under a network that moves money while you do it, so every change took the same road, and none took a shortcut:

flowchart TB C["a change
and the tests that prove it"]:::f --> B["an image built from a clean checkout
the whole suite run inside it"]:::q B --> S["the sandbox pair
and its two operators"]:::a S --> L{"both suites again, like for like
run by a session that did not write the change"}:::q L -->|"worse"| C L -->|"the same or better"| P["production
EU and ASIA first, then their four operators"]:::g P --> A["the auditor
delta 0.0"]:::g classDef f fill:#2a1f47,stroke:#7a5cc4,color:#eadcff classDef q fill:#1a2740,stroke:#3f6ea8,color:#dce9ff classDef a fill:#0d3a4a,stroke:#2f8fb0,color:#d6f4ff classDef g fill:#0b3d2e,stroke:#1f8a5f,color:#d6ffe9

That road earned its keep twice before anything shipped. The new HTTP client quietly drops a client certificate that it is handed beside a file of trusted roots, which would have sent every mutually authenticated call on the network out without one; the certificate now travels inside the TLS context itself. And the new bcrypt refuses a secret longer than 72 bytes, where the old one simply used the first 72, while every agent secret on this network is 74 bytes long; one module now cuts them exactly as before. Those are the release notes you usually discover after they have ruined your week. This week they ruined nobody's.

Underneath the code, the platform moved one container at a time: the identity servers, the gateways, the connection poolers and Redis. The ledger brokers went from Redpanda 24 to 26 one feature release at a time, seven steps each, and each broker's whole path was rehearsed first on a copy of its own data, which is the most patience I have shown anything this year. On Tuesday evening the fourteen databases of the production frames and their operators moved from Postgres 16 to 18 by dump and restore. Each one was reopened only when its contents matched the stopped original, and the old volumes are kept. The longest write pause was EU's, 112 seconds, which is roughly how long it takes me to find the right terminal.

The public auditor at auditor.theprotocol.cloud in its production view, on Tuesday night. Header: The Auditor, supply invariant guardian, the production, sandbox and legacy tabs, TPSA-1, live, 66,109 audits, 2 frames. Is the money conserved: EU, ECU, conserved, every check passing, delta 0.0; ASIA, ACU, conserved, every check passing, delta 0.0. Every verdict above is signed and hash-chained, with a re-verify button. Two dials read atomic invariant delta 0.0 for EU and ASIA, the invariant tokens issued minus tokens destroyed equals the sum of liquid and staked holds, and a trend chart of the atomic delta is flat at zero. Supply detail for EU and ASIA: tokens issued 1,000,001.00 each, tokens destroyed 0.00, circulating 1,000,001.00, atomic delta 0.000000, live-read delta +0.000000, last check just now.
Where the money was all week. The auditor reads each production ledger's database directly, once a minute, in a single statement per frame, and belongs to no registry. Every verdict it shows is signed and chained to the one before.

Through all of it the auditor kept reading. Since the last post it has checked each of the five frames it watches more than 8,200 times, and not once has it read a delta other than zero. It watched the week's throwaway frames too, for as long as they lived, and all 819 of their checks came back OK. EU has now passed more than 32,000 checks in a row. The auditor does not care that it was a busy week, which is rather the point of it.

What it means to join

Opening the code answers one question and raises another. The server will be published under the AGPL, version 3 or any later version, and the SDKs under Apache 2.0. Whoever takes the code may run it, change it and run a network of their own; that is the point of opening it. We looked at a source-available licence that would have kept anyone from offering it as a competing hosted service for two years, and chose not to use it.

Joining this network is a different question, and since Monday it has a precise answer. A frame crosses into another trust domain only if it holds a network licence: a certificate that names its trust domain, signed by the frame that anchors the network, today EU, or by a chain that leads back to it. Without one, a frame still runs everything, its own cloud operators included. It just cannot cross into anyone else's. Licences are free for now: private, educational, research and non-profit frames with no end date, enterprise and government frames for their first year.

Every registry card states its licence, and that line is never the frame's own claim. The card works it out from the certificate when it is built, signs it with everything else and prints the certificate's hash beside it. A cloud operator rides its frame's licence and holds a free operator licence of its own, signed by its frame. And a card viewed from another frame shows that frame's own verdict first, and the card's claim only as what the card states. Trust is something the reader works out, not something the card asserts.

Before a single production frame depended on it, the licence was tried the way a stranger would meet it. On Monday afternoon the frame runner built a throwaway frame called lickit in six minutes, in production posture, and pointed it at the sandbox pair without a licence. Both sandbox frames answered 403, federation licence required, before any identity work: no peer row and no trust relationship on either side. Then lickit applied the way a real applicant would, through the invitation rail. The sandbox's genesis approved it and issued a research licence, and lickit checked the genesis signature against the root it had been told to expect before it trusted anything. A revoke refused it again on both of its lanes, a new licence restored every crossing, a suspension refused it and the reinstatement restored it. Then lickit was torn down, having done more for the network in one afternoon than most frames do in their lives. EU switched from observing to enforcing at 15:28:19 UTC that day, and ASIA at 15:30:34.

flowchart TB G["EU, the genesis
its own licence"]:::g --> A["ASIA
a founding licence
signed by EU"]:::g G --> EO["Amsterdam and Lisbon
ride EU's licence
operator licences signed by EU"]:::a A --> AO["Shenzhen and Ho Chi Minh City
ride ASIA's licence
operator licences signed by ASIA"]:::a N["a new frame
no licence"]:::f -->|"asks to federate"| R{"refused, 403
federation licence required
before any identity work"}:::x N -->|"applies through the invitation rail"| G G -->|"approves, issues a licence
signed back to the root"| L["licensed
crossings open"]:::g L -->|"revoked or suspended"| RR["refused again
on both of its lanes"]:::x classDef x fill:#3a1a1a,stroke:#a85454,color:#ffd6d6 classDef f fill:#2a1f47,stroke:#7a5cc4,color:#eadcff classDef a fill:#0d3a4a,stroke:#2f8fb0,color:#d6f4ff classDef g fill:#0b3d2e,stroke:#1f8a5f,color:#d6ffe9

Every night, from nothing

A stranger's first frame will not be one of ours. It will be born from a template, on images the stranger pulls, on a machine we have never seen. So every night at 00:30 UTC the frame runner does the nearest thing we can do on our own machine. It stands up a fresh pair of frames from the current template, with their own DNS names and certificates, federates them, gives them an FX pool and a cloud operator each, runs the federation suite and the whole MCP lifecycle sweep against them, copies both runs into EU's test view, tears everything down and checks that nothing was left behind. They are the only frames on this network that have never had a bad week, because none of them has ever lived through one.

All three scheduled nights so far were clean. This is last night's pair, nt260930, which came up in 1,074 seconds and ran both suites in 756:

[2026-09-30 00:56:27Z] [federation] completed in 510s: CLEAN, 546 passed, 1 failed (1 expected red), 39 skipped, 0 hard, 0 bug finds, of 586
[2026-09-30 01:00:30Z] [lifecycle] completed in 240s: CLEAN, 710 passed, 0 failed (0 expected red), 39 skipped, 0 hard, 0 bug finds, of 750
[2026-09-30 01:00:32Z] ledger nt260930a: delta 0.0 (OK)
[2026-09-30 01:00:32Z] ledger nt260930b: delta 0.0 (OK)

Then it went down in 184 seconds, and the leftover check found nothing. The one red is red on purpose. It is the test for the next federation feature: a governance proposal raised to the whole federation should reach every frame's floor, and today it lives only in its home frame's ledger. The suite names it every night until it passes.

Since Tuesday evening, Frame Management offers the same current images by default, so a frame stood up from the console starts on the registry, token gateway, ledger, auditor and index this post describes. The first pair built on those defaults passed both suites too.

What opens, and when

The home is ready and private: one commit with a fresh history, every export check passed, and a fresh clone byte for byte what we built. Contributions have a written road. REVIEWING.md says what a machine checks and what a person reads, asks for a design issue first for anything that touches money, contracts, identity or federation, and promises an acknowledgement within seven days. A review tool recomputes every claim a contributor makes, including that the new tests fail on the release before the change and pass after it, and answers on one page: mergeable, held or refused. Nobody's pull request will depend on my mood, which is good news for everyone involved.

What opens will be the tree these patch notes describe, not the one we had on Sunday. I am not putting another date in writing. The next time this journal mentions the opening, it will be to link the repository. It was a longer week than the calendar says, and it was the right one.

Patchnotes

The last post went out on V0444, which was V0442's code carrying the post itself. What follows is V0445 through V0494, six days of work, every version on the sandbox before production, with the supply delta at zero throughout on every frame the auditor watches. A line that does not name where it runs is live on EU, ASIA, their four cloud operators and the sandbox pair.

Security

One identity per service, and a registry that cannot reach its host

Cloud operators: provision, revoke, purge

Money and agents across frames

Cards and sync

The public showcase

Federation licences

Every dependency current

The platform underneath

Monitoring

The MCP tester and the MCP audit log

Documentation

The code base's home

Kit, new frames and the nightly

The legacy network

Released

Tests

Still open