Solidus Pod
How this works, explained once
Sixty articles on personal data stores, verifiable credentials and Web Access Control — what a Solidus Pod does, how it does it, and where it stops.
60 articles
- What's Actually Live in Solidus Pod (and What Isn't Yet)pod.solidus.network runs Community Solid Server 7.1.9, pinned and unmodified.
- How Solidus Pod WorksSolidus Pod runs Community Solid Server 7.1.9, pinned and unmodified.
- Solidus Pod and the Solid Protocol, Compatible, Not Conformant, YetSolidus Pod is Solid-compatible and migration-ready. It is not Solid-conformant.
- What Is a Personal Data Pod?Right now, your data doesn't live in one place, it lives in whoever's app you happened to use.
- DID vs WebID. Two Ways to Answer "Who Are You" on the WebEvery system that lets a stranger read or write your data has to answer the same question first: who are you, and how do I check it without asking a company to vouch for you?
- What Is Web Access Control (WAC)?Web Access Control (WAC) is a small, RDF-based vocabulary for saying who is allowed to read, write, append to, or control a given resource on the web.
- Where Do Your Verifiable Credentials Actually Live?This page is about one narrow question: after a credential is issued, where does the holder keep it?
- What Makes Personal Data Actually Portable?"Portable" is not one property. It's three, and conflating them is the actual mistake: the one that lets a vendor say "your data is portable" while quietly meaning only one-third of that sentence.
- What is Solid-OIDC? The Login Layer We Did Not BuildSolid-OIDC is how a Solid server that has never met you becomes convinced you control a particular identifier.
- What is RDF (Resource Description Framework)?RDF is the data model the Solid protocol is built on, and Solidus builds nothing for it.
- What is Turtle, the RDF syntax a Solid pod speaks by default?Turtle is a way of writing RDF down, and Solidus writes none of it.
- What is JSON-LD, and where does a pod actually use it?JSON-LD is JSON that is also RDF. We emit exactly one such document and we process none of them.
- A DID document and a WebID profile document aren't the same shape
- Dereferencing a WebID vs resolving a DID: two ways to look someone upBoth answer "who is this identifier, and what keys do they hold." One is an HTTP request.
- Can generic DID tooling resolve a Solidus pod's identity yet?
- What secures a Solidus pod's identity, if not a certificate authority?The thing you believe without checking anything else. Every verification chain terminates somewhere; the anchor is where it stops.
- Does a WebID leak more than a DID does? An open, unaudited questionThe unlinkability implementation described here is unaudited.
- GDPR and a personal data pod: what changes, what doesn'tA pod changes where your data sits. It does not change who owes duties under the regulation, and we build nothing for compliance today, gdpr is not-built in our own lexicon, and no Solidus product…
- Can you actually delete your data from a Solid pod?A file, yes. Your account, no, and we have no erasure workflow anybody could test.
- Where does a Solidus pod physically live? One server, and a longer answerOne origin server, hosted by Hetzner in Germany. No regional deployment, no multi-region infrastructure, no contractual residency guarantee offered to anybody, and no date on the roadmap when that changes.
- Vendor lock-in and your pod: what you'd still depend on us forAdopting us today trades one kind of lock-in for another.
- Read, write, append, control: the four permission modes in a pod
- A grant is not a consent receipt: two different questionsOne asks whether a piece of software may touch a file. The other asks whether a person agreed to something, and whether you can show it.
- Who actually built the Solid protocol, and what its standing isNot us. We implement none of it. solid-protocol is not-built on our side; the server running this surface is the Solid community's own, and our contribution is the integration layer around it.
- Is anyone actually running Solid in production? Yes, and none of it is oursSomebody is, and it is not us. solid-protocol is not-built on our side, and every deployment named on this page belongs to another organisation with no connection to Solidus.
- What is Community Solid Server, and what does pod.solidus.network run on top of it?Community Solid Server is the Solid community's reference implementation, and it is not ours.
- Run a real Solid pod on your own machine in two commandsThis works, it takes about a minute, and it involves us in no way at all.
- How to check Solid compatibility yourself, with tools we don't controlDo not take our word for any of it. Compatibility is the one property a vendor should never be the source of, and every check below is one you run, with software that is not ours.
- What does the Solid Conformance Test Suite actually test?Less than the name suggests, and it tells you so itself, which is the best thing about it.
- Store and fetch your first resource in a pod
- Set a permission on a pod resource, and watch it get enforcedThe transcript is from a pod running on a laptop, two commands, not from our deployed host, which needs an authenticated session.
- Solidus Pod vs Inrupt PodSpaces: two bets on what a Solid pod becomesBoth are development-stage offerings, and only one of them has a production product behind it.
- Solidus Pod vs Vana: custody or monetization, you probably want one, not bothTheir model is monetization. People contribute personal data into pools, collectively governed, so it can be licensed, to model builders, among others, and contributors are rewarded.
- Personal data pods, data-monetization platforms, and where Solidus Pod sits1 · Custody, personal data stores. Your data sits in storage you control; applications read what you permit.
- The storage idea in Solidus's 2017 founding letter, before \"Solid\" was in the vocabularyNine years ago the proposal was to stop storing data on rented hosting.
- Why hasn't everyone switched to a personal data pod yet? The cold-start problem, honestlyAn outside review of an early Solidus plan put it without decoration: the value proposition needs users, operators and content, and you begin with none of them.
- Could a Solid pod hold your social graph and messages too? An unbuilt research question
- The original research question: could a Solid pod safely hold a cryptocurrency wallet?Mostly no, and that answer contradicts our own earliest sketch, which is why it is worth publishing.
- Why Solidus Pod doesn't gate access with biometricsBecause a biometric answers a question a pod never asks. Pod gates access with Web Access Control, and there is no biometric capability anywhere in its code.
- What's inside a consent receipt: the five claimsRead as a set, they answer the question a grant cannot: not "may this software open this file", but "did this person agree to this use, and is that agreement still good."
- Why a patient's identity credential and their consent receipt have to stay two separate objectsBecause one says who someone is and the other says what they allowed, and merging them breaks both.
- Inrupt's move toward \"agentic wallets\", what it signals, and what our own note got wrongIt is not a retreat from pods. The wallet sits on top of one.
- Who governs the Solid Protocol today? The Open Data Institute's 2024 stewardshipNot the people who wrote it, and not us. Since October 2024 the Solid project, protocol and community have sat with the Open Data Institute.
- Why you don't buy Solidus Pod on its ownThis page exists because a customer-facing surface should say that plainly rather than let a reader hunt for a pricing link that does not exist.
- Can a WAC grant let one person act on someone else's behalf?Not in the sense that phrase usually means, and this page poses the question rather than claiming we solved it.
- The personal-data-vault graveyard: Skiff, Datacoup, Streamr, and the patternEvery force that ended these applies to us, and by the measures that ended them we are earlier and weaker than any of them ever were.
- A bank-issued data wallet and a personal data pod are different betsTheirs is a bet that the valuable thing is where the data came from.
- Bluesky calls its store a \"PDS\" too, here's how it differs from a Solid podSame three letters, different problem, and on the property this page is really about, theirs is the stronger design.
- Who owns your follower list? DSNP, Lens, and Farcaster's three answersThree designs, and in January 2026 two of them were tested by a corporate event rather than by an argument.
- MyData, and what a \"personal data operator\" is supposed to beSomebody named this pattern before we existed, and it was not us.
- Your files are encrypted. That's not the same as controlling who can read themEncryption answers one question: can the server read this. Access control answers a different one: which agent may read, write, append to, or control this particular resource.
- \"Provider-independent security\": the idea underneath every data pod, named in 2007The intuition that you should not have to trust whoever stores your data is older than Solid, older than Inrupt, and much older than us.
- A CID and a URL are not the same promiseA content identifier is a hash of the bytes. Ask for it, and you can check that what came back is what you asked for, without trusting whoever handed it to you.
- \"Pay once, stored forever\" and the right to erasure are in direct tensionOne product promises your data outlives your relationship with any company.
- CryptPad, and what an EU public body already deploysA government ministry writing documents in a suite whose server cannot read them is not a proposal.
- Proton's vault is expanding. What does that mean for personal data?A password manager that also holds passkeys, identities and seed phrases is not a password manager any more.
- Should your personal data live on the chain itself?For a public social graph, there is a real argument that it should, and somebody built a chain for exactly that.
- Compute-to-data: send the algorithm to the data instead of the data to the algorithmThe usual way to analyse someone's data is to get a copy of it.
- What is a data union, and did any of them work?A data union is a group of people pooling the data they individually produce, so that together they have something worth buying.
- Anchoring permissions on a chain, versus a server enforcing an ACLPod does not anchor access control on a chain. A permission here is a small document beside the resource, and a server reads it and decides.