mikakimikaki.org

mikaki conformance results — OpenID, FAPI and FIDO

This index collects conformance evidence published in the mikaki repository. mikaki has no formal OpenID, FAPI or FIDO certification. Results apply only to the recorded date, version and configuration. They do not certify the current production deployment or every device.

Reading verdicts#

PASSED means the module succeeded. REVIEW requires human assessment, SKIPPED was not executed for the selected configuration, and WARNING retains a warning. Reviews and skips are not passes. Zero failures does not establish optional-feature coverage or completed certification review.

Counts below describe the latest recorded run units. Individual reruns are not added to inflate module totals; native and Wasm are separate executions.

OpenID Connect OP#

September 29, 2026 / OIDF Conformance Suite 5.3.1, rev 4bfcdf8. Isolated Rust Worker, workerd, disposable D1, HTTPS and Chromium virtual passkeys.

PlanResult
Config OP1 PASSED
Basic OP, 35 modules22 PASSED, 4 REVIEW, 8 SKIPPED, 1 WARNING, 0 FAILED

Reviews include authentication and unregistered-redirect screenshots. An optional name request retains a warning; unsupported optional scopes, request objects and refresh tokens can be skipped. No fabricated profile attribute was added to silence the warning.

See the run record and machine-readable module/version/build evidence.

OpenID Connect logout#

September 27, 2026 / OIDF Conformance Suite 5.3.1. Local OP fixture, Code flow and Chromium virtual passkeys.

PlanResult
RP-Initiated Logout, 11 modules3 PASSED, 8 REVIEW, none unfinished
Back-Channel Logout2 PASSED: Discovery and RP-initiated notification

Local screenshot inspection did not change the eight REVIEW verdicts. Back-Channel evidence covers one successful delivery path. Certificate verification was disabled only in that local test process to work around the fixture/receiver hostname mismatch. This does not qualify production TLS, all retries or receiver failures. Read the execution and limitations.

FAPI 2.0 Security Profile#

September 30, 2026 / OIDF Conformance Suite 5.3.1, rev 4bfcdf8. Isolated Final AS with the selected plain_fapi, private_key_jwt, DPoP and OIDC profile; local HTTPS relay and virtual passkeys.

Latest complete runResult
Final AS, 52 modules45 PASSED, 4 REVIEW, 3 SKIPPED, 0 FAILED, none unfinished

Four reviews cover direct authorization without PAR and reused, expired or wrong-client references. Three conditional skips concern claims selection, an RSA client-signature case for the selected configuration, and refresh tokens. The first traversal recorded 36 PASSED, 8 FAILED, 3 REVIEW, 3 SKIPPED and 2 unfinished; implementation fixes and execution corrections produced the result above.

See the fixes and rerun record and readiness report. Production-edge TLS, independent client/resource-server qualification and human review remain separate work.

FIDO2 Server#

September 29, 2026 / FIDO Conformance Tools 1.9.2. Development runs of isolated adapters with all Server Tests and ten optional checkboxes selected.

TargetResult
Native adapter167 passes, 0 failures
Wasm adapter167 passes, 0 failures

The test configuration accepts broader algorithms and attestation than normal product settings. MDS explicitly used mds3.0; strict defaults were retained. The tool marked ES256K pending and did not execute it. Submission, frozen target version/configuration, MDS requirements and interoperability testing remain open.

See certification readiness, detailed runs and real-device evidence.

Bounded OID4VC component tests#

September 29, 2026 / OIDF Conformance Suite 5.3.1, rev 4bfcdf8. Separate synthetic-data components, not the public IdP.

TargetResult and scope
OID4VCI issuer metadata1 PASSED; metadata from OWF 0.6.0 only
Nine selected OID4VP verifier modules7 PASSED, 2 REVIEW; verifier integration using @openeudi/openid4vp 0.12.0

The OID4VCI adapter exposes no token, nonce or credential endpoint. Metadata success does not qualify issuance or DPoP. OID4VP covers synthetic PID, URL query, direct_post, and dc+sd-jwt/ES256. Happy flow and minimal cnf.jwk were accepted and retain REVIEW with receipt evidence. Seven negative cases cover signatures, audience, nonce, sd_hash and times. Full wallet/verifier plans, HAIP, mdoc and signed requests are outside the subset. See the targets and evidence.

Supplementary checks and certification#

CI, component tests and device checks are separate from these conformance runs. Supplementary DPoP evidence, including 45 component/policy scenarios and 11 loopback HTTPS scenarios, is not added to official module pass counts.

Formal certification follows the target-version, profile, submission and review requirements of the OpenID Foundation or FIDO Alliance. A newer implementation passing CI does not change these dates or certification status. This index changes when a rerun configuration and verdicts have a published record. Private keys, tokens and raw user data are not publication artifacts.