2026-02-24T00:27:06Z

EVERY PROTOCOL.
EXECUTABLE.

Cipher suites, handshake sequences, zero-trust boundaries — rendered as navigable, runnable documentation. Not a PDF. A live intelligence layer.

tls1.3_handshake.protoRFC 8446
CLIENTMSGSERVER
ClientHello — RFC 8446 §4.1.2
legacy_version
0x0303 (TLS 1.2 compat)
random
32 bytes (server timestamp removed)
cipher_suites
TLS_AES_256_GCM_SHA384 TLS_CHACHA20_POLY1305_SHA256 TLS_AES_128_GCM_SHA256
supported_versions
0x0304 (TLS 1.3)
key_share_groups
x25519, secp256r1, x448
signature_algorithms
ecdsa_secp256r1_sha256 ed25519 rsa_pss_rsae_sha256
psk_key_exchange_modes
psk_dhe_ke (0x01)
↑ click any message node to inspect fields
847
PROTOCOL FAMILIES
24,391
CVES INDEXED
99.2%
RFC COVERAGE
100%
AUDIT PASS RATE

PROTOCOL
TAXONOMY

Every cipher suite, handshake variant, and vulnerability advisory mapped in a navigable tree. Branches expand as you descend. Nothing is hidden.

Active / Stable standard
Deprecated — migrate away
Critical advisory — CVSS ≥ 8.0
847
PROTOCOLS
3,241
RFC ENTRIES
protocol_tree.index847 nodes · 24,391 CVEs
$search --tree tls
▾TRANSPORT SECURITY
▾TLSRFC 8446
TLS 1.3RFC 8446
TLS 1.2RFC 5246DEPRECATED
DTLS 1.3RFC 9147
▾QUICRFC 9000
QUIC-TLSRFC 9001
QUIC RecoveryRFC 9002
▾IDENTITY & AUTH
▾OAuth 2.0RFC 6749
PKCERFC 7636
JWT / JWSRFC 7519
▾FIDO2 / WebAuthnW3C CR
CTAP2FIDO 2.1
▾ACTIVE ADVISORIES
CVE-2024-3094 (XZ Utils)CVSS 10.0
CVE-2024-6387 (OpenSSH)CVSS 8.1

ZERO-TRUST
ARCHITECTURE

Scroll to assemble. Each boundary layer labels itself as it enters your clearance depth.

NETWORK PERIMETER
Layer 0 — Untrusted Zone
L0
DMZ / EDGE PROXY
Layer 1 — mTLS Enforcement
L1
IDENTITY PLANE
Layer 2 — SPIFFE/SPIRE
L2
WORKLOAD MESH
Layer 3 — Envoy Sidecar
L3
DATA PLANE
Layer 4 — Encryption at Rest
L4
ASSEMBLY PROGRESS
0/5

LIVE
DOC FRAGMENTS

Real documentation. Tab between authentication flows, encryption standards, and incident response playbooks.

protocol docs://
auth_flows.md
1# OAuth 2.0 + PKCE Authorization Flow
2# RFC 6749 § 4.1 + RFC 7636
4## STEP 1 — Code Challenge Generation
5method:
6 S256 # SHA-256 only; plain FORBIDDEN in production
7code_verifier:
8 43–128 chars, [A-Z a-z 0-9 - . _ ~]
9code_challenge:
10 BASE64URL(SHA256(ASCII(code_verifier)))
12## STEP 2 — Authorization Request
13response_type:
14 code
15scope:
16 openid profile email offline_access
17state:
18 cryptographically random, min 128 bits
20## STEP 3 — Token Exchange
21grant_type:
22 authorization_code
23token_endpoint_auth_method:
24 private_key_jwt # RS256 or ES256
26⚠ NEVER store tokens in localStorage — use httpOnly Secure cookies
END OF FILE
3 frameworks — SOC 2 · ISO 27001 · NIST CSF
LIVE · LAST UPDATED 2026-02-24

INSTALL
THE CLI

One command. Every protocol family, every CVE chain, every RFC — navigable from your terminal. No account required.

terminal — macos
# Homebrew tap — macOS 12+ / Apple Silicon native
$brew install protocol
$protocol --version
→Protocol CLI v2.4.1 (build 2026-02-24)
$protocol search tls1.3 --detail
→Loading 847 protocol nodes...
Read in Browser →
🔓No account required
📦MIT licensed
⚡2.1s cold start
ACTIVE ADVISORY — CVE-2024-6387 (OpenSSH RCE)
Affects OpenSSH < 9.8p1 · CVSS 8.1 · Run protocol cve --id CVE-2024-6387 --patch-guide for remediation steps