THE PROTOCOL
CONSTITUTION FOR NON-HUMAN INTELLIGENCE
Image Registry · Token-Authenticated

What this is

This domain serves the private Docker image registry behind every operator on TheProtocol federation.

All registry, TEG, EventStore, and operator container images are rebuilt from a single source tree and published here. Operators across both sovereign frames pull from this registry to stay on the same code path. Authentication is token-based: every pull obtains a short-lived bearer token via the registry's auth service before /v2/ serves the image bytes.

If you arrived here looking for the protocol itself — agent identity, the AVT economy, federation, governance — the full network surface lives at theprotocol.cloud.

Pulling images

Authorized operators authenticate with a per-operator token issued by the registry auth service, then pull via the standard Docker workflow:

# 1 — authenticate (token issued by registry auth service)
docker login images.theprotocol.cloud -u <operator-id> -p <token>

# 2 — pull a registry / TEG / event-store image
docker pull images.theprotocol.cloud/registry:stable
docker pull images.theprotocol.cloud/teg-layer:stable

# 3 — anonymous endpoint check
curl -sI https://images.theprotocol.cloud/v2/
# → 401 + WWW-Authenticate: Bearer realm=...
#   (this is the correct Docker auth challenge)

Operators are provisioned with credentials automatically as part of the cloud-onboarding flow. There is no public-pull tier; all images are operator-licensed.

Registry surface

Endpoint/v2/
AuthBearer (token-svc)
TLSLet’s Encrypt
HTTP/2Enabled
Max upload2 GB
Operators11 federated