Nostr Compass #42
Welcome back to Nostr Compass, your weekly guide to Nostr.
Our dedicated Nostr Compass Android app brings newsletters, podcast episodes, topic guides, and contributor voice notes into one place. Its latest signed release notes describe full signature-verified newsletters, saved issues and 110 topic guides available offline, and local search across stories and available transcripts. Contributors can record and reply with voice notes, review a saved take before sending, and sign through Amber without storing their private key in the app. Public recordings are published on Nostr and Blossom.
The latest app update preserves queued recordings and upload checkpoints when Android stops background work, shows when Amber approval is needed, and opens the relevant recording from a notification. Separate episode and voice-note views keep their own scroll positions, while playback resumes from the same point. Notifications for new recordings depend on Android scheduling and permission.
This week: White Noise adds encrypted group polls and notices for incomplete chat history; Holoboard adds private-message promotion commands and an Android app; fips-pub-domains tests signed public names on a mesh; Marmot MDK makes missing encrypted-group history visible; and Myco gives nearby app sharing a Nostr identity and store. nostream adjusts relay admission to load, while Nostr double ratchet closes a removed-member gap. Development repairs Amethyst encrypted-group interoperability, adds Divine’s encrypted video messages, and brings Nostr Atlas online. Protocol updates refine identity proofs, relay invitations, follow sets, and proposed domain claims. The month-end September retrospective follows the same questions through six years of Nostr.
Top Stories
Holoboard adds Nostr promotion commands and an Android app
Holoboard is a board for finding Nostr notes through a ranking that can be boosted with Lightning payments. The original posts remain Nostr events; Holoboard serves its ranking and appearance data through its own HTTP API. That distinction matters if a reader expects the board’s ordering to be a relay-native feed.
Its September 23 changelog records direct-message promotion commands over both encrypted NIP-17 and legacy NIP-04 paths. NIP-17 wraps private messages to hide their content and sender from relays, while NIP-04 is the older direct-message encryption format. A user can request a promotion invoice in the same conversation, receive one labeled quote for the first paid promotion, and opt into expiry reminders by replying YES. The promotion sender retries failed relays, while the September 24 update adds an Android app and simplifies the invoice flow.
The project’s relay integration notes describe ordinary notes and comments on Nostr, encrypted inbox routing, and quote and delete handling. Its signed Zapstore Android listing supports the existence of an app release, but the listing key has not been established as Holoboard’s public board identity. This is the first Compass coverage of the project.
fips-pub-domains tests signed public names for a mesh
fips-pub-domains is a new resolver and naming experiment that binds public domain names to nodes on FIPS, an encrypted mesh that uses Nostr messages for peer discovery. Its first release combines those claims with DNS TXT records, optional DNSSEC validation, locally pinned bindings, a Linux resolver daemon, and Android integration with fips2go, the FIPS client for phones. A signed claim by itself does not establish ownership of a public domain; clients need DNS or DNSSEC evidence, a configured witness, or a previously trusted pin.
The 0.2.0 release adds DNSSEC proofs to claims so a client with only a mesh relay can validate an unpinned name, and lets multiple validated servers serve one domain. It also repairs stale pins and DNS failover. Version 0.2.1 fixes a systemd unit that otherwise failed to start and runs the server without root; existing installs must replace that unit to receive the fix.
On Android, a merged fips2go change follows verified public-name bindings in its DNS proxy. A second merged change carries connections to configured Nostr relays over the mesh, so the resolver can retrieve and verify a previously unseen domain claim while the phone has no internet connection. The device results are reported by the maintainers in those pull requests; they do not establish wider deployment.
The project’s two-node and mesh-only relay tests are maintainer-reported evidence for an early implementation, not a production deployment. Its NIP-DB proposal is still open, and the event kinds in its draft remain placeholders pending registration. Last week’s fips2go story covered mesh bootstrap and peer discovery; this week’s work tackles public names and verification.
Marmot MDK 0.11.0 makes account history gaps visible
Marmot MDK, the Rust runtime and generated bindings for MLS-encrypted Nostr group messaging, follows last week’s durable-send release with version 0.11.0. Account recovery now declares a history gap complete only after every required relay finishes an untruncated event comparison; an unproven gap produces a durable notice that a host can show to the user. A full delivery queue spills to the account database instead of dropping events, and live delivery advances the transport cursor so a restart does not fetch the same history again.
The full release notes also describe optional encrypted group polls, stateless event verification in the bindings, and Android libraries aligned for 16 KB memory pages. Applications must move the generated bindings and native libraries from this source cohort together; account databases migrate through schema 98 on first open, and downgrading the database is unsupported. An existing intermittent catch-up defect can still leave messages more than five group epochs behind undecryptable without raising a notice, so this release does not claim complete history recovery in every case.
Myco 0.8.0–0.8.1 gives nearby apps their own Nostr store
Myco is an Android app for exchanging small Nostr programs, called napplets, with nearby phones, including when they are offline. Version 0.8.0 gives each installation a guest Nostr identity and permits login with an existing key or Amber, an Android signer that approves signatures without sharing the account key. It also replaces the Discover tab with an app store that is itself a napplet. That store reads signed app listings and recommendations, while a downloaded update can pass between phones in a user’s Circle without an internet connection.
Version 0.8.1 makes those listings easier to find by querying the relays an author advertises; earlier builds relied on public defaults. It shows cached profiles and apps immediately, saves slower relay answers for later visits, backs off from failing relays, and keeps subscriptions live while a view is open. Both updates preserve the existing phone-to-phone wire format. Updated phones can download and share napplet updates; older phones forward their announcements alone.
Tagged Releases
White Noise Android adds group polls and account-specific disappearing-message defaults
White Noise Android is a Nostr messenger for private Marmot-encrypted conversations. Following the delivery and sharing improvements covered last week, the September 30 release adds group polls with selectable answers, result bars, and deadlines through the Marmot Development Kit. It also adds device-local disappearing-message defaults for each account: new direct conversations and groups inherit the chosen duration, while existing conversations and their individual settings keep their current policy. Wave hi sends a greeting that mentions a newly added member without disturbing the current draft.
The release lets users choose the focal crop for profile and group images and delete a chat folder without deleting its conversations. Its history notices show when recovery leaves account or group history potentially incomplete, with separate dismissal controls. Conversation paging avoids rebuilding the displayed timeline on a jump to recent messages, and pending-message edits retain their text while the original send obtains its confirmed event ID. That edit handoff covers conversation changes within the running app; it does not establish persistence across process death.
Dictation now chooses Paste or Send for each recording, with automatic finishing placing the transcript in the draft. Offline-provider setup explains on-device processing, keeps its consent separate from other speech providers, and restores interrupted media after capture ends. General-file handling accepts bounded, nonempty documents with accurate filenames, MIME metadata, and failure messages; explicit attachment downloads use Android’s user-initiated transfer jobs with a foreground fallback. Paste controls now use Android’s system action so GrapheneOS Secure Paste can grant clipboard access. Android also renders iOS GIPHY shares as animated media while respecting download policy.
Notification fixes refresh sender nicknames and clean up alerts when a conversation opens. The notification recovery changes preserve pending push work through unavailable foreground ownership and use bounded retries. Amber signing coordinates same-account approval bursts to prevent rate limits from cancelling sends. The new audit configuration asks for a fresh log-sharing choice before uploading to the new receiver. The source also adopts AGPL-3.0-only licensing.
nostream 3.1.0 adjusts relay proof of work to load
nostream is a TypeScript Nostr relay backed by PostgreSQL. Version 3.1.0 can raise or lower the event proof-of-work threshold between operator-set limits as its observed event rate changes. The setting is off by default, uses each worker’s measured rate, and leaves the existing static public-key threshold independent, so operators must opt in before senders see a different admission requirement.
The same release adds an admin dashboard for relay, WebSocket, and event metrics, network-health probe results, and configurable operator notifications. Its admin API is disabled by default. These controls help operators distinguish relay pressure and reachability problems while keeping the new policy under explicit configuration.
After its load-sensitive proof-of-work release, nostream merged actions for trusted-moderator reports. NIP-56 defines content-report events; the new nip56.hideActionableReports option excludes reported events from REQ and COUNT results when reporting is also enabled. An event report hides that event, while a public-key report hides every event by that author. The new option defaults to false, so enabling report collection alone preserves the existing query results.
Nostr double ratchet 0.0.171–0.0.172 closes a removed-member gap
Nostr double ratchet is a TypeScript library for encrypted private chats carried by Nostr. Version 0.0.171 rotates a group’s sender key after membership changes so someone removed with the old keys cannot decrypt later messages from an updated sender, even after that sender restarts. It also refuses sends or key rotation by a removed local owner and aborts a send if membership changes during key distribution.
Version 0.0.172 carries the existing account-signed device approval in an optional encrypted invite response. A recipient using the update can verify the sender’s device before a separate registration event arrives, while linked devices retain their approval across restarts. The invite field is optional and leaves the original handshake and ratchet message format intact.
Versions 0.0.173–0.0.175 extend that removal work with durable group-key handoffs and queued delivery state saved before publication, so interrupted handoffs recover after restart. Publication callbacks carry local group context that lets applications cancel durable retries after removal while keeping membership controls deliverable; queued sends preserve their original inner event IDs. Duplicate invitation responses preserve established sessions, subscriptions remain stable as contacts change, and app-key snapshots retain device names without sharing mutable copies. The signed wire format stays unchanged; the 0.0.173 notes also report Rust 0.0.168 with receive-session fallback and local group-echo filtering.
Scramble 0.7.4–0.7.5 fetches the messages a new group member should see
Scramble is a cross-platform Marmot group messenger with a native Android interface. In version 0.7.5, each group gets its own relay history cutoff: previously the most active conversation’s cutoff was applied to every group, so a newly joined one could remain empty because its post-join messages were never requested. The reconnect path receives the same fix, and a group with no local activity now requests all available messages; MLS still prevents a new member from decrypting messages sent before joining.
The preceding 0.7.4 release fixes repeated invite acceptance caused by recycled Android rows accumulating click handlers, and makes a custom Blossom media server setting persist in the native app. Version 0.7.5 ships only the native Android APK, so users tracking the older Avalonia filename must change their update target. Accounts and history move between those two Android builds, but groups created under the older 0.6.x MLS engine do not migrate to 0.7.x.
Scramble 0.7.6 adds a manual Fetch missing messages control that queries every routing address a group has used, removes the time restriction, repairs a stale stored address, and reports what it recovered. It still cannot decrypt epochs from before the user joined. Native administrators can promote or demote other members, with current roster state and visible failure outcomes; two-person conversations still hide these controls. The group-info Copy action now responds, though invited conversations can still copy an internal chat identifier instead of the protocol group ID. Version 0.7.7 also drains held messages when another member’s commit arrives; 0.7.8 adds a regression test for that passive-member path.
Amber 6.6.6 repairs remote-signer connection secrets
Amber is an Android signer that approves Nostr event signatures without handing an application’s account key to it. After last week’s backup-encryption change, version 6.6.6 fixes its nostrconnect parser: a connection parameter containing =, such as a padded secret, had been altered before Amber answered. That made NDK-based clients fail their secret check even when the signer connection otherwise looked valid.
The release also sends feedback issues to the relays advertised by Amber’s repository announcement, with a fallback to the prior relay if the announcement cannot be fetched. Longer Tor timeouts give slow relays more time to acknowledge that publication. The remaining changes improve icon and text visibility in Amber’s themes.
FIPS 0.5.2 stops a Nostr discovery privacy leak
FIPS is an encrypted mesh that uses Nostr identities and relay messages to discover peers. Its 0.5.2 maintenance release stops signing NAT-traversal deletion requests with the node’s routing key, which had linked that key to traversal traffic on relays. It also updates the TLS library used for relay connections to a version that fixes a published security advisory and repairs several lost-message cases in link and session rekeying.
The release notes call for operators on every platform to upgrade, while detailing separate Windows key-file permission, gateway, and package-service fixes. Ephemeral nodes no longer write a private fips.key that a later restart might overwrite; operators who intended a stable identity should set persistent mode before upgrading. The release does not change the mesh wire format, so mixed-version nodes can be upgraded individually.
napplet soyLI 0.23.1–0.23.4 repairs backend publishing and signer approval
napplet.soy’s soyLI is the creator and publishing toolkit for small sandboxed Nostr programs. After last week’s shared-creations release, version 0.23.1 makes backend manifests, handlers, and schemas part of creator checks and multiplayer previews. It keeps portable provider configuration in the project manifest while leaving private identity bindings and development databases outside the published source snapshot.
Version 0.23.2 lets projects that once committed a generated public backend context publish again after strict validation, while still rejecting private bindings, journals, databases, and credentials from reachable history. The later 0.23.4 release fixes a persistent-backend session failure that could reject a valid extension or remote-signer approval when a person took several seconds to sign. Public hosts need the shared-host fix as well; updating a creator’s CLI alone has not repaired a deployed host.
Dart NDK 0.10.0 scopes Blossom auth and remote signing
Dart NDK is a Flutter and Dart library for Nostr relay access, signing, wallet requests, and media operations. Following last week’s prerelease, 0.10.0-dev.7 changes Blossom media requests to stay anonymous until a server refuses them, then authorizes through an explicit policy that says which identity an operation may reveal. It carries that authorization through the request path and replaces the older useAuth and customSigner options, a breaking integration change for apps using the prerelease API.
Dev.9 stops holding a remote-signer response until the slowest relay acknowledges it. Dev.8 reduces background relay polling and cache work; its other fixes concern wallet seed persistence and settlement deadlines. The stable 0.10.0 release now packages this development series together with the connection-metadata and private subscription-ID changes below. The comparison with dev.9 includes those merged changes. Applications upgrading should review both the media-auth API change and the remote-signer response path.
The stable release includes NIP-46 connection metadata and requested permissions, replacing separate connection fields with a Nip46ClientMetadata value. This is a source API change that lets login widgets pass application identity and requested permissions to the bunker. Another request-ID change uses 32 random hexadecimal characters in production, keeping use-case names and pagination phases out of relay-visible subscription IDs. Explicit IDs remain bounded to NIP-01’s 64-character limit, while debug mode retains a short diagnostic name.
Mostro Core 0.16.0 removes the old gift-wrap transport
Mostro Core supplies the message protocol used by Mostro’s Nostr-based peer-to-peer trading clients and coordinator. Version 0.16.0 removes its protocol-v1 gift-wrap transport and its old wrap and unwrap functions, leaving the newer transport as the library path. That is a breaking change for applications still constructing or reading v1 messages through this library.
The library release precedes the coordinator’s now-published 0.19.0 release. Operators serving older clients need to update both sides of the transport migration. The preceding 0.15.1 tag adds a cooperative-cancellation dispute state, but the transport removal is the compatibility milestone.
Cambium 0.6.0–0.7.1 enrolls an unlock phone through relay messages
Cambium is an Android signing companion for a Heartwood hardware key that can also unlock the board after a restart. Version 0.6.0 lets a phone enroll for unlock through the board’s Nostr relays without a USB cable; the user compares five request words on the phone, the board, and Sapwood, the board’s enrollment interface, before pressing the board’s button. Newly announced relays receive a randomized connection delay so the phone’s first contact does not reveal exactly when it saw the board’s update.
Version 0.7.0 reverses the invitation flow: a phone scans Sapwood’s short-lived QR code and returns one encrypted, one-time event from a throwaway key. Retry republishes that same event if no relay accepts it, while the old code-display path remains for older Sapwood builds. The 0.7.1 patch keeps the final check code visible and improves F-Droid build reproducibility; the QR flow still requires the specified recent Sapwood and Heartwood versions.
Bray 3.5.0–3.5.2 limits agent-initiated Nostr wallet spending
Bray is a Nostr tool server that lets an AI assistant request relay, identity, and wallet actions through a scoped interface. Its 3.5.0 release adds a cap on each Nostr Wallet Connect payment and a persisted daily budget, with human confirmation where the assistant host supports it. Serving separate spending connections now requires an explicit wallet-service setting, rechecks each grant before use, and confines invoice lookups to hashes within that grant.
The release also tells users to keep a wallet connection URI in a private file instead of pasting it into chat, and refuses to retry an uncertain payment as though failure were proven. Version 3.5.2 matches marketplace payment rails locally after relays rejected the requested payment-method filter. These checks limit what a delegated assistant can spend and prevent a relay-filter assumption from hiding matching offers.
Mafrend 1.3.0-alpha moves private map groups to current Marmot
Mafrend is a map-based Nostr social app that lets people explore places and chat around destinations. Its 1.3.0-alpha release upgrades private groups to a newer Marmot encrypted-group specification and adds profile views from chats and reviews. The group format is incompatible with older alpha chats; users should treat this as an alpha migration with a compatibility break.
The same release adds screenshot sharing and chat changes alongside map and marker improvements. Profile features are still marked in progress by the project. The meaningful Nostr change is the private-group interoperability shift; users with older test groups should check the compatibility note before upgrading.
Sonar alpha.15–alpha.15.1 repairs encrypted-group publishing
Sonar is a private messenger that can carry conversations over Bluetooth mesh and Nostr. Alpha.15 adds emoji reactions to messages and private local-time sharing inside encrypted chats, with a setting to revoke that sharing. Its wallet switches to Cashu, but that payment change is separate from the messaging update.
Alpha.15.1 repairs a launch failure that could leave the conversation index empty after an older branch build wrote a foreign schema version. Without the index, the app re-encrypted and republished local-time shares to every group on each reopen, sometimes sending hundreds of events before relay rate limits intervened. The hotfix rebuilds that local state and stops the repeated group publishes.
Elisym’s commerce packages introduce private Nostr orders
Elisym is a Nostr-based agent toolkit now building a signed-event commerce flow. Its merged commerce package defines store products, owner authorization, privately wrapped orders and receipts, and offer verification for the checkout and merchant components. A later commerce 0.2.0 tag derives an order’s payment reference from that order, tying the payment lookup to the signed purchase flow.
The package series also introduces separate payment-core and browser-checkout work, but its release tags do not establish that a complete merchant checkout is deployed. The store-authorization event kind is explicitly provisional in the project’s primary source. The eleven SDK, MCP, CLI, and payment-core tags mark one developing commerce feature.
Elisym’s new package releases package the self-hosted merchant node, while MCP 0.31.0 adds buy_product and get_order for commerce products. Subsequent commerce and merchant-node releases add Tempo payment support inside that same checkout. These packages advance the existing signed-product and private-order integration; the tag list does not make the provisional event schema a standard or establish a complete hosted-service launch.
Flotilla 1.11.2 unsticks signers and incomplete relay feeds
Flotilla is a Nostr client for conversations, rooms, and shared spaces. Version 1.11.2 gives a user a way out when startup stalls waiting for a remote signer, and signs out a session whose local application data has been cleared. A room can now display its messages before its wider space finishes synchronizing, while feeds no longer omit posts simply because one relay answered later than another.
The same release also publishes an F-Droid build signed with the app’s existing key and keeps GitHub releases current for Obtainium. That distribution work matters to users changing update channels, but the relay and signer fixes are the immediate reason to upgrade.
Ditto 2.42.3 shows relay delivery and tightens account boundaries
Ditto is a Nostr social client that lets users choose and authenticate to their relays. In version 2.42.3, a post’s Event Details shows which user and author relays hold it; Broadcast targets only the missing ones. The release also points out unresponsive read relays and gives them a retry control, making a missing post easier to diagnose without sending it everywhere again.
The release notes say that switching accounts no longer sends posts to the previous account’s relays, muted users cannot trigger generic phone alerts, and links or images in posts cannot reach devices on the reader’s local network. Slow-relay posts stop disappearing from Follows and Loved feeds, while live stream chat and webxdc games update without repeatedly downloading the whole view. Torrent and audio browsing are also new, but the relay routing and account isolation are the changes with the widest Nostr impact.
Iris Chat 2026.9.24.4 brings calls into encrypted conversations
Iris Chat is an end-to-end encrypted Nostr messenger using the double-ratchet family of chat protocols. Its September 24 release adds voice and video calls with compatible contacts, including over an existing local connection when the internet is unavailable. A user can lower video quality, answer video as voice, and handle an incoming call through Android’s call interface; answering or declining also stops the other linked devices from ringing.
The release also lets a person sign in through a separate signing app and see which linked devices are connected. Later September 24 patches keep delayed messages’ original timestamps and improve nearby delivery after a lost reconnection packet. These are early cross-device and call behaviors, so the update is most useful to contacts who can run compatible Iris builds.
The later developer-signed September 30 update retains a removed member’s local group history while disabling sends, improves delivery between linked devices and large groups, and repairs read indicators and unread counts. Calls gain audio-device selection and restored outgoing tones; stale microphone status no longer silences incoming audio. Timed muting, image copying, dropped-file attachments, notification routing, and push registration receive fixes, while sign-out clears local caches and device removal ends its session. A second update improves access to files cached by other Iris apps on the same device and keeps local file sharing available with Nearby disabled.
LibreNostr 0.6.0–0.7.0 routes relays through built-in Tor
LibreNostr is an Android Nostr client with configurable relay and privacy settings. Version 0.6.0 bundles an Arti-based Tor engine on ARM64 and applies the chosen Direct, Tor-for-everything, or .onion-only mode to relay WebSockets, HTTP requests, media, uploads, and web pages. Strict Tor mode fails closed when Tor is unavailable and never silently sends a request directly; changing modes reconnects relay sockets through the new route.
Version 0.6.2 adds an on-device web-of-trust filter built from public follow lists and chooses supplemental relays by the additional followed people they reach. Version 0.7.0 then shows notes and notifications before profile and count lookups finish, caps slow relay queries, and stops decrypting an entire DM inbox on every conversation open. Together these releases change both where the client may connect and how long a slow relay can hold up its interface.
Its developer-signed first stable release, 1.0.0, adds saved, per-profile tablet decks with movable columns for feeds, hashtags, profiles, long-form reading, notifications, and messages. Landscape tablets get this layout; phones keep their existing interface. Search gains OR, exclusions, media filters, and working date ranges, returns cached profiles before relay refinements, and moves past refused full-text requests immediately. Hashtags sort chronologically, paging waits for sufficient relay answers, and unused feeds release their subscriptions.
The same release preserves existing public and encrypted mute-list and bookmark entries during edits instead of replacing them with one change. It isolates bookmarks and notifications between accounts and restricts auxiliary author relays to public reads, keeping private requests and relay authentication off them. It also prevents stale profile answers from replacing newer metadata, repairs notification paging and badges, retains older feed items when new ones arrive, and fixes reply undo countdowns, duplicate publication, media URLs with query strings, and unread counts after marking a chat read. Version 1.0.1 fixes a tablet-deck startup crash in the new layout.
Newlay 0.3.45 streams large relay queries instead of closing them
Newlay is an Android-hosted Nostr relay and related local services. Its signed 0.3.45 release announcement says that large query results now stream with backpressure instead of closing the client’s connection. The embedded Git host prunes superseded packs after pushes, while its Cordn encrypted-messaging coordinator accepts oversized client requests and sends an abort frame when a probe times out.
The release also gives the Android operator a live status card for events, storage, address, and administration, and aligns the native cryptography library for devices with 16 KB memory pages. The relay and coordinator changes span several releases since the prior store version, 0.3.39; 0.3.45 is their packaged checkpoint.
ngit-grasp 3.0.5 keeps Git pushes and relay sync moving
ngit-grasp is a self-hosted Nostr relay and Git server for signed repository collaboration. Its signed 3.0.5 release announcement moves slow history reconciliation out of the shared live-sync actor, allowing relay subscriptions to start while earlier events are checked. It backs off separately for rate limits, incomplete history queries, mailbox reads, and identity lookups, so a sick relay no longer monopolizes retry capacity.
The same release reconciles against the local event inventory to avoid refetching stored history and closes incomplete subscriptions before treating their coverage as verified. On the Git side, it accepts pushes that background state promotion already applied, retains conflict protection for changed refs, and drains Git progress output during uploads to prevent a stalled push. Those details matter because a repository can appear live on relays while its Git transfer is still waiting for an authoritative result.
Armada 0.63.0 carries push alerts across signer types
Armada is a Nostr client for encrypted communities, channels, and direct messages. Following last week’s media-privacy release, its signed 0.63.0 announcement describes a new browser push path that works while the app is closed for extension and remote-signer logins as well as other account types. Tenna, a host app that embeds Armada, also gains background notifications for its users.
The release loads older messages in long community channels faster and avoids rereading the whole history for new messages. Direct-message typing indicators use fewer relay connections. Desktop updates gain a restart prompt, while direct upgrades from versions older than 0.50.0 are no longer supported.
The signed 0.63.1 follow-up adds editable emoji packs with folder import and reordering, retrieves quoted messages beyond loaded history, and makes relay-hosted replies interoperable. It reduces Android reconnect traffic, catches up after long disconnects without repeating old alerts, excludes pre-join mentions, and preserves unedited group fields and private server-list entries. Deletions in relay-hosted groups now require the message author or an administrator. Server dragging, malformed relay-information handling, and repository subscriptions also receive fixes.
Version 0.63.2 expands message Markdown to nested quotes and lists, horizontal rules, code fences, underlined headings, and formatting across links or mentions. Tenor and Giphy page links play as GIFs. Read-state synchronization transfers less data, reconnection avoids redundant downloads and logins, and Android background notifications pause relay synchronization when large settings updates flood it.
deed 0.3.0–0.3.2 makes Zig Nostr publishing steadier
deed is a Zig command-line tool for reading and publishing Nostr events. Its September 24 version 0.3.2 adds an agent skill and fixes relay ping deadlines; the preceding 0.3.1 and 0.3.0 releases improve performance and publication reliability. The three tags describe one early tool series. The visible Nostr benefit is a steadier relay connection and event-publishing path for scripts that use the CLI.
Cordn 0.5.1 keeps other groups moving when a coordinator fails
Cordn is an MLS-encrypted group messenger that uses Nostr identities and relays to locate conversation coordinators. Its signed 0.5.1 client release follows last week’s offline-queue work by separating coordinator and outbox scheduling: an unavailable coordinator no longer delays sends for unrelated groups. Resolved relay hints persist after discovery, group documents carry them between devices, and a durable pending-publication record recovers stranded sends. Multi-device recovery overlaps history-chain and gap queries while reading current configuration.
The release also adds dropped-file attachments, pinned groups, profile names in previews and notifications, and coordinator labels. It repairs first-unread positioning, unread counters, duplicate alerts, media and system-message previews, replies attached to captioned media, and image zoom controls. Native downloads use a Save-as picker. A signer that appears late no longer causes a false unsupported-encryption warning, and account switching no longer races background seeding.
Nymbot 1.0.7 adds local document handling and encrypted chat sharing
Nymbot is an assistant reached through encrypted, gift-wrapped Nostr messages. Its developer-signed 1.0.7 release reads documents on the device, selects relevant passages when a file is too large to send whole, and identifies the pages used. Conversations can be shared through an end-to-end encrypted link whose access can later be withdrawn. Python and JavaScript replies can run locally, with their output returned to the conversation.
The same release adds sourced research with a price shown before submission, image editing, per-message model selection, and spending caps per chat and bot. External tools connected through MCP ask for confirmation before changing data. Repository runs can pause changes for review, display CI results, and resume after a busy gateway. Suggested replies, pinned notices, folded source lists, and a searchable model picker complete the update; these claims come from the developer release notes; Compass has not independently audited the privacy of the app.
0xchat 1.5.6 ships its signing and message-authentication fixes
0xchat is a Nostr messenger with private chats, external signing, and wallet features. Version 1.5.6 ships the security fixes covered as source merges last week, including gift-wrap authentication, trusted infrastructure configuration, and consent for embedded-page signing. It also closes Tor proxy bypass paths, validates TLS certificates for non-onion hosts, and stops release builds from writing potentially sensitive credentials and wallet material to the device console. Opt-in developer logs continue to record errors.
The release backs relay reconnects off from three seconds to five minutes, repairs subscriptions after reconnection, and delivers requests queued while a relay is connecting. Account switches stop accumulating duplicate relay listeners, a failed login preserves the already active account, and external-signer connections persist across starts. Failed sends now show errors and retain unsent text or recoverable token-sharing state. Startup key decryption and upload hashing move off the UI thread; chat and video caches avoid repeated rendering and downloads. The release supplies Android and desktop assets with SHA-256 checksums, including the Play-signed Android APK and a Windows installer built from source.
Nostr Mail Client 0.17.0 hides mailbox actions from relays
Nostr Mail Client exchanges email through Nostr while supporting conventional email delivery. Following last week’s per-recipient transport and media-privacy release, version 0.17.0 hides read, archive, folder, and label state and their timing from relays, and lets users delete mail without notifying its sender. The release requires updating every device together because older clients do not see the new state or deletions. It also protects Bcc recipients in mail larger than 32 KB, keeps local contact aliases out of outgoing messages, repairs Amber QR login, and publishes public mail to the recipients’ read relays.
The release adds colored folders and labels with sender, subject, and attachment rules; reply and forward quotes; inline pasted images; attachment previews and renaming; and range selection in mail lists. Forwarding retains original images and attachments, reply quotes start collapsed, and the web editor gains a context menu. HTML tables and inline images render more accurately, plain-text links work, and scheduling supports dates up to five years ahead. Address-book names and pictures appear throughout the interface, and theme colors offer system, suggested, or custom palettes.
The same release keeps file-selected backgrounds local and caches linked backgrounds, with an explicit migration cost: older file backgrounds on native platforms must be added again. It changes the default relay/media recommendations, adds Nostr-app discovery during onboarding and update notices, preserves unfamiliar settings written by other clients, and repairs interrupted mail-store creation and Linux packaging. Startup failures now show details and a prefilled report instead of a blank screen.
Nostr WoT 0.8.7 binds authentication to the destination
Nostr WoT is a browser extension that combines Nostr signing with trust tools. Version 0.8.7 requires consent for NIP-98 signed HTTP authentication against the exact URL, query, method, account, and requesting origin. Older broad approvals require fresh consent. NIP-42 relay authentication has a separate account-bound permission system, with site-specific denials taking precedence over shared relay allows. Authentication requests must come from a verified top-level browser origin, and approval or unlock waits trigger another account/access check.
The release verifies remote NIP-46 signatures and the complete approved event so a returned signature cannot silently substitute content or a destination. Wallet provisioning and address changes use body-bound authentication, one-use backend challenges, and separate transaction tokens; generic website signing cannot mint those internal wallet tokens. The compatible backend must deploy first, and the client refuses to downgrade to retired endpoints. Nostr Wallet Connect payments also verify a returned payment preimage against the requested invoice hash and treat a mismatch as an unknown outcome.
In the request interface, users can inspect full raw events, choose specific requests in a site group, and view private messages locally without approving their return to a website. Local previews conceal themselves after 30 seconds; incoming requests remain unchecked, and ordinary bulk approval excludes authentication. The extension separates per-site and all-sites relay grants, bounds verified profile caching, resolves equal-timestamp replaceable events by lower event ID, and keeps home-popup publication reads local. Chrome and Firefox receive separately verified packages and serialized stable-release submission workflows; those workflows do not prove current store availability.
Iris’s shared runtime keeps relay and peer history consistent
nostr-pubsub supplies a shared Nostr event runtime with persistent event storage and an outgoing publication queue. Versions 0.5.7–0.5.13 batch exact subscriptions, replay them after reconnect, keep local, relay, and peer evidence distinct, and report incomplete history when durable storage fails. Completed queries wait for every received event to finish admission. The default relay batch now contains at most 20 OR filters for compatibility with common servers, while peer batches retain independent matching and cancellation.
Hashtree’s runtime updates replace worker-specific networking with that shared runtime, persistent event indexes, and an outgoing queue, allowing events and cached files to share one FIPS node. FIPS TypeScript 0.0.44–0.0.45 selects routes with enough capacity for complete signaling records, recovers dropped session setup within the handshake deadline, and retries WebRTC answers only after explicit routing rejection. Larger framed WebSocket routes require compatible native peers; the 0.0.44 notes require deploying native FIPS 0.4.85 first.
Iris Kit 0.2.5 adds a persistent plain-event application client and transport-neutral NIP-46 signing while preserving account keys and offline reads. Version 0.2.6 returns an already verified complete event ID from the worker or native backend immediately; prefix and replaceable-event queries still wait for history before choosing the latest value. These are library releases, and the notes do not establish deployment to every Iris application.
Iris Meet’s September 30 source update replaces its NDK integration with persistent publish/subscribe infrastructure and shared identity signers. The patch adds coverage for offline identity restoration, NIP-07 signing and meeting-room isolation. The existing meeting app uses Nostr for encrypted signaling and WebRTC for audio and video. This is default-branch implementation progress; the repository has no tagged release proving that this specific update has reached the live site.
Chama propagates listing cancellation and background alerts
Chama uses signed events for community trading and private conversations. Versions 6.4.14–6.4.16 publish a signed cancellation before deleting a listing locally, so other clients can retire the same cached offer. Recipient wake tags now accompany events independently of the sender’s notification setting, and the alert server deduplicates by signed event so a chat immediately after a join can still trigger a wake. Background jobs replay affected trades from saved cursors, isolate failed chains, and decrypt notification text locally; the release requires redeploying the companion watcher.
The grouped releases also apply participant renewals at their signed event times, quarantine funding locks made after a seat expired, and expose recovery for the saved bearer note. Claim publication waits for confirmed import or payment. Listing filters preserve the viewer’s currency across community scopes, and trade headers use the finalized joined amount. These changes align what two Nostr-connected clients infer from the same event history.
Earthly 0.1.12 adds reusable map configurations
Earthly is a Nostr collaborative map editor with signed publication and encrypted sharing. Version 0.1.12 adds reusable GMapper configurations for public Google My Maps, developer-created Maplet discovery, private configuration storage or public publication, and attributed geometry copying. The same release adds encrypted connection sharing, entity drops, and mobile chat navigation. Google export availability and browser CORS limit importing, executable downloaded Maplets remain unavailable in Tauri, and physical Android upgrade checks remain pending.
The configuration work migrated existing publication addresses and preferences and added review or withdrawal of configuration updates. Its initial Android workflow failed before compilation; a tooling fix prepared the subsequently tagged release.
Mostro 0.19.0 retires its first-generation transport
Mostro coordinates peer-to-peer trades over Nostr. Version 0.19.0 now ships the removal of its first-generation gift-wrap transport, so clients must use the newer protocol. The existing order-creation and dispute-opening timestamp tags are renamed published_at without changing their stored values; the enclosing event’s created_at remains its signing time. Restore responses return the counterparty’s trade key, accepted create/take operations recognize trade keys, and relay publication completes on the first positive relay acknowledgement. The same release updates bond deadlines and cancellation, closes disputes when a trade resolves, notifies the solver, and bounds relayed price staleness.
Mostro’s trade-key admission fix recognizes a key as soon as an introducing order or dispute is committed. Nodes with stricter first-contact proof of work previously could drop a legitimate follow-up message until the periodic known-key refresh; default-equal thresholds were unaffected. A dispute transaction commits the order transition and dispute row atomically, closing inconsistent-state failures. Closure notifications send the assigned solver a best-effort private message when the users resolve a dispute, with the existing replaceable event remaining the offline fallback.
SCRUTINY Lens brings security research onto Nostr
SCRUTINY Lens v0.1.0, its first public release on September 29, is a browser client for security metadata published through Nostr. Analysts can search by CVE, package or certificate identifiers, inspect event histories and retractions, and explore relationships in a subject graph. The browser verifies event signatures and identifiers. Optional AI search and explanations use an endpoint chosen by the user; the app checks quoted citations against the underlying events. The release notes describe relay limitations explicitly and identify local build dependencies that still require sibling repositories.
Mangatsu and Noteds reach Android
Mangatsu v0.1.11 is part of the comic reader and publisher’s first Android release series this week. Its source adds Amber login through NIP-55, the Android interface for asking an external signer to approve Nostr operations. Comics and chapters are Nostr events, while their pages live on Blossom servers; the reader also supports an encrypted saved library and offline reading. Subsequent commits address signer invocation and relay-list refreshes.
Noteds v0.1.2 brings a Nostr classifieds marketplace to Android through Tauri. Its Android signer integration uses Android NIP-55 signing. The app publishes listings and messages over Nostr and builds a local search graph with categories, geographic areas and optional browser embeddings. The latest source fixes native location access for nearby search. Both projects are early releases; their GitHub release pages have no detailed notes, so these capabilities come from the tagged READMEs and implementation commits.
Statim combines Nostr DMs with other networks
Statim v0.4.0 follows its initial September 23 release. The tagged source describes a messenger with NIP-17 Nostr DMs alongside XMTP, Status, Telegram and Matrix. Accounts start from a locally held recovery phrase; each conversation identifies its protocol because those networks provide different privacy properties. Android currently lacks its Telegram integration. These are the project’s documented capabilities, not independently tested guarantees or confirmation of app-store availability.
In Development
Amethyst repairs encrypted-group interoperability
Amethyst is an Android Nostr client with Marmot encrypted-group support. White Noise is another Marmot messenger; an interoperability batch tested with its clients addresses group administration, deletion wording, and other behavior exposed when the two clients share a conversation. More pointed fixes send reactions and deletions inside the Marmot group instead of as separate NIP-17 gift-wrapped private messages and apply edits from another client after restart. Those are source merges; the testing described in the PRs is narrower than a published cross-client release.
A separate Cordn group runtime and interface merge adds another encrypted-group path through coordinator servers. Cordn is distinct from Marmot, so the two changes should not be read as one transport migration.
Amethyst also merged HTTP relay commands in its Geode relay and Quartz client under its NIP-FE proposal, and a backup-conflict review interface for replaceable profile and list events. NIP-FE is project proposal terminology; the backup flow lets a person compare versions before accepting a replacement and prevents silent overwrites of local state.
Amethyst also develops Concord, a separate encrypted-community protocol used by Armada and Accordion. A conformance batch adds fragmented community lists, pin proofs, key rotation and dissolution records, followed by disappearing messages and direct invitations. An invitation stays in a private inbox until accepted; receiving it does not contact the community’s relays. The same change corrects an author comparison that could let another author’s deletion remove a message. Cross-client fixes repair unsigned rumor serialization, missing invitation fields, relay-confirmed community creation and joining without restarting; their reported emulator tests involved live Armada and Accordion peers.
A later private-channel implementation rotates channel keys after relevant access revocations and adds create, privatize, publicize and rekey controls. It also adds rank-checked cooperative kicks and expires message attachments with their parent messages. WebXDC updates can enter a separate channel buffer, but Amethyst still has no WebXDC application host. That later batch reports wire-format and unit tests, with no device or live-relay exercise, so the earlier interoperability result does not certify every newly added control.
Quartz’s MLS engine now preserves skipped message-generation secrets across restart, enabling out-of-order messages to remain decryptable after restoring saved state. Four retained former epochs let callers authenticate late application messages, retain their authenticated data and prevent a consumed generation opening again. A secret-tree update loads unexpanded node secrets from ts-mls-style state; sender-specific stale-generation errors distinguish a client’s own ratchet collision from another member’s replay. The PR explicitly says Marmot’s existing retained-epoch fallback remains separate, so this is an engine capability, not proof that every Amethyst message path uses it.
A Quartz tag-reader audit fixes private geohash entries that could be published in clear text and a parser that treated the private key from an nsec as a public key. It also repairs repost addresses, channel-hide targets, live-room root tags and addressable mint events. The obsolete ForkTag reader is removed, creating a source API change for Quartz consumers; preexisting SQLite mint rows still need a separate migration. Additional event models cover Buzz’s project-container, artifact-revision and team proposals, while video-view and encrypted push-control models follow Divine’s schemas; these additions establish parsing and construction support, not complete client interfaces or adopted numbered NIPs.
The client also renders Ultra HDR photographs in the feed and fullscreen viewer on Android 14 or newer. Android 15 and newer cap the feed’s brightness boost at twice the ordinary range, while fullscreen can use the display’s full range; the reported test devices ran newer Android APIs, leaving Android 14 and 15 untested. A shared UI and upload-port merge brings 140 screens onto common Android/desktop code and moves Android media work off the UI thread. Its audit also restores metadata-removal error reporting, making the refactor more than a file move.
Divine adds encrypted video to direct messages
Divine is a Nostr video client. NIP-17 carries private messages in encrypted gift wraps that hide their sender from relays. Divine’s merged video-message work encrypts an attached video on the device, uploads ciphertext, and sends the decryption key inside that private message. A recipient can verify and decrypt the file for playback or save it. A separate history-restore fix keeps an ambiguous relay refusal from prematurely ending recovery when other relays can still answer.
Divine’s retired-moderation-key fix refuses retired keys in moderation-label resolution and selects the current report recipient when a report is filed. Pending reports addressed to a retired key are redirected to the build’s pinned key, and unresolved conversations remain unwritable. The change also distinguishes retired-key custody when deciding which historical threads a minor may read; custody updates still require an application release. Deleted-comment cache handling prevents a successfully deleted recent comment from reappearing when a thread reloads.
For creators, a live color-mask recording mode previews the replacement backdrop before a take is recorded, and white-wall masking adds brightness-sensitive masking through the video plugin. Word-by-word captions preserve recognized word timings and use approximate timing when the server supplies whole cues only. Stop-motion continuation appends new stills at the existing composition’s pace, while returning detached clips, grouped font selection and speed presets add editing controls without changing the Nostr event format.
Square-export alignment and its smaller-clip follow-up keep text and stickers in place across mixed-resolution clips. Third-party HLS playback avoids an Android heap crash by seeking back at loop boundaries instead of prebuffering repeated imported playlists; those loops can pause briefly at each restart. An account-preference reload keeps account-bound filters at their defaults across a switch while fixing part of a debug sign-in assertion. A separate moderation-label refresh issue remains open, so the PR does not claim every sign-in error is fixed.
Buzz extends its relay’s channel and identity controls
Buzz is a Nostr-based workspace with its own relay and clients. Its merged channel-artifact implementation gives an editable record one channel home and a revision chain; conflicting edits cannot both become the head. The project’s NIP-AR label refers to its own proposal and implementation, not an established Nostr standard.
For protected HTTP ingress, another merged change pairs a federated-identity assertion with the same key proven by NIP-98 authorization. NIP-98 defines signed HTTP authentication events; Buzz’s NIP-FI assertion is a project specification. It also merged HPKE encryption for secret-key backup envelopes. That PR establishes source-level security work; distribution to every client remains unverified.
Buzz desktop 0.5.26 includes the channel-artifact work, native HPKE secret-key backup encryption, and a desktop relay administration console. Its shared changes repair unlisted project-channel requests, synchronize sidebar sections, sorting, stars, and mutes across devices, bound long-thread reads, and tighten Blossom identity assertions. The repository-wide notes separately list relay identity pairing, companion mention delivery, configurable push URLs, atomic administrative deletion, and mobile contextual names. A desktop release establishes the desktop/shared distribution; it does not prove those mobile changes shipped in a mobile build.
Buzz’s WebSocket NIP-FI enforcement checks a federated-identity assertion before accepting frames, then requires its Nostr key to match the key authenticated through NIP-42, which proves a client’s identity to a relay. A session expires at the earliest of the token expiry, maximum assertion age and configured connection lifetime; after expiry it admits no new effect. This project-specific NIP-FI mode is off by default. Already admitted audio commits and subscription setup can still wait on a stalled dependency, so the change does not establish a universal bounded disconnect time.
Owner-deletion preparation moves operator-attested requests through an inventory-bound automatic approval into the existing deletion executor. A relay follow-up makes retrying the same request return its current state and reserves the owner’s active quota until deletion completes; permanently retained host tombstones count toward a 20-community lifetime cap. These are source-level administrative changes, and the follow-up instructs operators to keep deletion disabled until its relay and drain executor are live. Separately, a partition-catalog audit detects catch-all partitions and uncovered months before creating new event and delivery-log partitions, exposing serving-safety and audit freshness to operators.
Buzz mobile now disambiguates people and agents that share a display name. Its identity-name resolver qualifies agents by their owner and adds a short key suffix only when necessary; conversation integration uses those names for authors, mentions and membership notices. Lists, search and Pulse complete the same behavior outside a conversation. The visible qualification changes the local label while a selected mention keeps the identity’s original wire name.
Conduit advances checkout after relay acceptance
Conduit is a Nostr marketplace that sends private order messages to merchants. Progressive relay publishing distinguishes the first positive relay acknowledgement from completion of all relay attempts, and a checkout follow-up persists that first acknowledgement before proceeding. A relay’s acceptance means the signed order reached a relay; it does not prove a merchant read or fulfilled it.
Conduit also merged recoverable remote-signer sessions and transactional signer-relay negotiation. NIP-46 lets an application request signatures from a key held by a separate signer; these changes keep a user’s account workspace while its transport is being repaired, then verify the exact account before resuming. The PRs establish source behavior, not a shipped checkout build.
Conduit’s ranked product-search merge sends one ordinary NIP-50 full-text-search query for kind 30402 products and preserves the relay’s relevance order through signature checks, revision reconciliation and local eligibility filtering. Cards can appear before exact-product background reads finish, while newer signed deletions remain authoritative. Refresh and Retry stay within search and exact-product reads instead of starting broad catalog discovery. A 100-result cap followed by local filtering can miss eligible matches, so a partial empty response offers recovery and does not prove there are no products.
Elisym builds a Nostr commerce checkout
Elisym is developing a commerce toolkit that signs products and carries private order and receipt messages over Nostr. Its merged commerce package defines offer verification and gift-wrapped order events; a checkout interface handles offer review, wallet payment, and delivery status, while a self-hosted merchant node packages the store side. The project calls kind 30490 provisional and describes an October minimum slice. These source merges establish an emerging integration; an accepted Nostr commerce standard or complete public launch has not been demonstrated.
Elisym’s agent checkout tools add buy_product and get_order for its Nostr-advertised products. The first call returns a quote without ordering, and a second call accepts the single-use quote and warnings for the same agent and network; order state is kept durably in the agent’s local file backend. Tempo checkout support adds a browser-wallet payment path with merchant verification and delivery. A sent transaction hash keeps the attempt live until its outcome is established, avoiding an unpaid result while a broadcast could still settle.
A later checkout fix lets the signed-product checkout initialize when a browser wallet announces itself immediately during discovery. The source change moves session declaration before that callback can run; the merge alone does not verify a hosted deployment.
nostter improves signer checks and event retrieval
nostter is a Nostr social client. Its merged signer-capability change asks whether a usable signer is present before offering follow and reaction actions. New pin tags carry the author’s key and a known relay hint without guessing one, and replaceable-event cache ordering follows NIP-01’s timestamp and event-ID tie-break. NIP-01 defines the core Nostr event rules, including how clients choose between replaceable events.
Pensieve prepares isolated archive reconciliation
Pensieve is a Nostr archive and recovery tool. Its merged isolated negentropy runtime gives synchronization a bounded worker and durable completion behavior. The feature is opt-in and the PR explicitly says no production service or configuration was activated; this is groundwork for a safer recovery path, not evidence of a running deployment.
ContextVM avoids duplicate calls across relays
ContextVM’s TypeScript SDK carries tool and resource requests as Nostr events. Its merged inbound deduplication fix recognizes one plaintext request by event ID even when multiple relays or a reconnect deliver it again, matching the existing wrapped-message path. The PR reports one non-idempotent tool running three times for a single call before the fix. A companion resource-notification change sends updates only to subscribed clients; initialized sessions without a subscription no longer receive them.
Cyberspace revises the DECK-0003 object rules
Cyberspace develops the DECK-0003 format for structured Nostr objects and encrypted region bags, which Amethyst began implementing in last week’s issue. New parts and hidden-object rules and bag references let a bag refer to a separately published object instead of embedding every part. A later correction says that an event-ID reference cannot reliably pin an old version of an addressable event, because a relay may discard it after replacement. Readers should use the corrected coordinate reference rule; the earlier merge’s wording has been superseded.
Wisp fixes replies to Nostr comments
Wisp is a Nostr client with relay-routing and wallet features. After last week’s released NIP-22 comment support, a merged follow-up makes a reply to a NIP-22 comment a comment event too, with the proper parent and root references; the previous path always published an ordinary note. NIP-22 lets comments attach to many Nostr content types. The fix merged after Wisp’s 1.2.5 tag, whose notes only bump the version, so this is source-level progress whose release is still unverified.
Cordn sends coordinator locations to a second device
Cordn coordinates encrypted group messaging over Nostr. Its merged multi-device specification change carries a group’s coordinator relay hints in the replicated group document. A newly seeded device can then find a coordinator that is absent from default relays, instead of appearing to join a group whose backlog and live messages it cannot fetch. This is protocol-document work following last week’s Cordn offline-queue release, not a new client release.
Nostr Atlas opens a directory for checkable identities
Nostr Atlas is a new directory that presents Nostr profiles alongside claims to external accounts. Its merged site publication separates the directory from the project’s component demo, and the site responds publicly. A claim-flow merge lets an X account owner publish a signed NIP-39 proof with a browser signer, while profile enrichment reads kind-0 Nostr metadata only after the proof verifies. NIP-39 defines the proof pattern for associating a Nostr key with another online identity; a relay acknowledgement alone does not mark a claim verified.
nostr-java adds media hosting tools and preserves tag positions
nostr-java is a Java library and MCP tool set for Nostr applications. Its merged Blossom tools let a caller upload, find, list, and delete hash-addressed media and manage the user’s server list. A separate publishing fix keeps empty tag values in place: Nostr tags are positional, so dropping an empty relay hint could shift a marker into the wrong field and make the published event differ from the approved preview.
Zap Cooking changes how account history can be recovered
Zap Cooking is a recipe-sharing Nostr client. Its merged Lazarus recovery work replaces a backup built on NIP-78 application-specific data events with an approach that scans relay-retained versions of replaceable events to detect overwritten follows, mutes, or profiles. Lazarus remains a draft protocol; recovery depends on relays that retained the older versions, and a merged web-client PR is not a guarantee that every lost event can be recovered.
The client also merged optional NIP-13 proof-of-work controls for notes and replies and an attachment model that keeps media order and NIP-92 descriptions consistent between preview and publication. NIP-13 lets a sender spend local computation on an event before posting; NIP-92 carries media metadata as event tags.
Zap Cooking’s NIP-05 claim fix requires NIP-98 authorization over the exact request body and rejects a signer different from the public key claiming the name. Previously, that public endpoint accepted unauthenticated claims that could replace another member’s name. Membership tier now comes from the existing membership record, and remote-signer users receive a signing prompt when claiming. The separate trusted server-side registration path remains unchanged.
A mute-list repair stops profile mute actions from replacing the whole kind 10000 list with public-key tags alone. The previous path erased word, hashtag and thread entries plus encrypted content, and one surface could republish decrypted private mute keys publicly. The new path reads the relay copy, preserves unrelated tags and ciphertext, and refuses to publish when that read is unavailable. Removing a private mute requires decryption and re-encryption through the signer.
Opal brings remote signing to Omarchy
Opal is a desktop Nostr signer built for the Omarchy Linux environment. Its September 28 version 0.3.3 follows the first public series with NIP-46 remote-signing support, a local keyring, and a permission interface for requests from connected apps. NIP-46 keeps the account key with the signer while a separate client asks it to approve operations. This is an early release of a platform-specific signer, not a claim of wider desktop support.
WatchTower opens a NIP-86 relay control panel
WatchTower is a newly published panel for relay administration through NIP-86, the protocol for authenticated relay management requests. A public instance responds, giving operators a place to inspect the interface. The repository was created September 22; a reachable site does not establish that its authorization flows have been independently audited or that it works with every relay implementation.
Hubstr Blossom opens a personal media origin
The newly published Hubstr Blossom server lets a Nostr client upload images, video, and files to a self-hosted Blossom endpoint, then put those URLs in events. Its README documents local content-hash storage, a SQLite index, signed kind-24242 authorization for changes, and a range of Blossom operations for upload, mirroring, listings, and deletion. Public reads let other clients render posted media without receiving upload rights.
The server’s documented options also extract file metadata for NIP-94 events, which describe shared media. The server can re-encode images without EXIF metadata and guards mirror requests against private-network targets by default. This is a newly published implementation with deployment instructions, not evidence of a broad production rollout.
Hubstr Relay published its initial source on September 24. It combines a personal SQLite event cache with a public relay: unauthenticated readers see permitted public events, while NIP-42 authenticated tenants can read their cache. NIP-17 gift wraps remain unavailable to guest readers. Its September 25 update corrects records returned by NIP-86 pubkey-list methods.
Meshstr experiments with a permissionless relay mesh
Meshstr is an alpha design for Nostr relays to negotiate peer budgets and exchange signed usage receipts. Its first implementation includes a write-policy bridge for strfry, a Nostr relay, added September 27, with a socket fix the next day. The repository describes DIDComm negotiation and NIP-77 reconciliation, which lets peers compare event sets without exchanging their full inventories, alongside verifiable reports of peers exceeding agreed budgets.
Those project rules are a proposal, not an adopted NIP or a demonstrated public relay network. The concrete progress this week is the published code path connecting a relay’s write policy to the proposed mesh accounting.
Dossier shows what a public Nostr history can reveal
Dossier is a new browser-side self-audit tool for a person’s Nostr and Lightning footprint, with a public demo. It gathers visible profile links, zap trails, posting times, metadata from old NIP-04 encrypted direct messages, and media metadata such as photo EXIF; it can also show where a relay still serves an event someone tried to delete. NIP-07 signer support lets a user authorize cleanup actions without pasting a private key into the page.
The project’s documented limits matter: a scan sees only the relays it reaches, and a delete request cannot erase copies held elsewhere. The repository appeared September 27 and has no tagged release; the demo and source establish an early tool, not a complete inventory of anyone’s past activity.
Marmot MDK extends polls, custom emoji, and account metadata
Marmot MDK supplies the runtime and bindings for encrypted Nostr group messaging. Later MDK source merges expose paginated per-voter poll selections using the same effective-response rules as aggregate tallies. Optional application-owned group components give hosts admin-controlled settings that survive message retention and reach newcomers in their Welcome. Tagged sends and media reactions carry custom-emoji metadata through the runtime and bindings, retain decryption material for attached reaction images after an epoch change, and reject forged attachment tags. That change expands the C upload-request structure, so C consumers must rebuild against the header.
A convergence correction keeps messages pending when no canonical branch was selected instead of invalidating them without trying the live state. An accompanying unreachable-path cleanup routes unresolved staged commits into retained retry behavior. Encrypted-media reads align the HTTP read timeout with resumable-body idle handling, addressing stalled large transfers without claiming the pending incoming-APK device acceptance test passed. Startup-stage markers show which account-opening step timed out, adding diagnostic evidence without claiming the underlying startup stall is solved.
The local agent connector also merges existing profile metadata when publishing a kind 0 update, preserving fields the request omitted. Group-profile updates expose changes to a group’s name and description through the existing current-admin-authorized path. Its socket authentication still grants the whole local API; this merge does not add per-principal capability grants. These source changes follow the tagged 0.11.0 release.
rust-nostr correlates relay count replies
rust-nostr, a Rust library and SDK for Nostr applications, merged correlated COUNT responses and clearer waiter errors. The SDK subscribes before sending COUNT and accepts only the matching reply, preventing a lost or closed receiver from appearing as a legitimate zero. It also preserves receiver errors for publication acknowledgements and relay authentication, so callers can distinguish a missing confirmation from an explicit rejection. Public method signatures stay unchanged.
ZapTracker adds Nostr network and quote metrics
ZapTracker is a creator dashboard for Nostr engagement and wallet activity. A network-dashboard merge replaces Lightning network statistics with online Nostr relay data from nostr.watch and capability information from NIP-11 documents. A quote-metrics change counts kind 1 events carrying q tags alongside likes, reposts, bookmarks and zaps. This lets creators see quotes in content rankings and engagement charts; it remains merged source evidence.
LaWallet NWC routes card top-ups to the card wallet
LaWallet NWC connects Lightning wallets to applications over Nostr Wallet Connect. Its BoltCard top-up merge advertises a LUD-19 pay link that creates an invoice through the card wallet’s NWC make_invoice method. Blocked, disabled or unpaired cards do not advertise a pay link, and the path does not redirect top-ups to the owner’s separate Lightning address. A follow-up exposes the same link in the emulator and carries recipient-accepted payer notes on LNURL sends.
A new khatru relay exposes owner moderation controls
nostr-relay-khatru published its initial source on September 29 as a general relay derived from the discontinued HiveScope-specific implementation. The public instance serves a NIP-11 document naming this repository and advertising authentication, event expiry, protected events, counting, reconciliation and relay administration. A September 30 implementation adds moderation controls to its owner panel. The public metadata verifies a deployed endpoint, not successful testing of every advertised method.
A local web-of-trust builder tracks unfollows
etemiz/wot published a Nostr web-of-trust crawler on September 30. It reads follow lists and NIP-65 relay lists, computes trust from configurable roots, and writes scores to LMDB for relay policies, feeds and spam filters. The project documentation explains the trade-off: live updates increase trust, while scheduled full crawls apply decreases and unfollows. Scores depend on the chosen roots. This is newly published source, with no tagged release or claim of production deployment.
Moyu opens a Marmot workspace client
Moyu has published the source for a Rust workspace chat client built on Marmot, with command-line, terminal, and desktop interfaces. Its September 30 changes use locally recorded membership changes to stop old join requests readmitting removed members, make invitation codes expire after seven days, and let administrators revoke them. Terminal output filters control characters and text-direction overrides supplied by other members. A pinned MDK fork routes Blossom attachment transfers through the configured SOCKS5 proxy, with hostname resolution performed by that proxy. The 0.3.0 changes are in the public source; no public release tag or release entry is available yet.
Protocol and Spec Work
NIP-39 extends identity proofs to Bluesky and Discord
NIP-39 lets a Nostr account point to proof that it controls an identity on another platform. A change merged September 27 gives new proofs one recommended sentence and tells verifiers to accept older proofs that contain the account’s npub, even when their wording differs. It also documents Bluesky posts and Discord messages as proof locations. A Discord claim can only be checked by someone who can read the server where its message was posted.
NIP-86 adds invite-code management for relay administrators
Compass described in the July 8 issue the NIP-86 invitation proposal while it was open; it has now merged. NIP-86 defines a standard relay-management API, and NIP-43 defines how restricted relays announce membership and process admission requests. The September 24 merge adds listclaims, createclaim, and deleteclaim so an administrator can list, issue, and revoke invite codes accepted by a relay. That gives operators a management path for invitations that may grant a member a role after they join; it does not require every relay to support the methods.
A correction to last week’s NIP-86 coverage: the merged specification added unallowevent, unbanevent, listallowedevents, and listdisallowedkinds. The earlier item listed names from an outdated proposal description. The first two methods reverse an event-level allow or ban decision; the others inspect allowed events and disallowed kinds.
NIP-51 moves favorite follow sets to an unused event kind
NIP-51 defines public and private lists, including a list of a user’s favorite follow sets. Compass described the kind-collision proposal in the July 22 issue; it has now merged. The September 27 correction assigns that favorites list kind 10021 because the earlier number was already in use. Its a tags still point to kind 30000 follow sets. The change resolves a number collision in the specification; it does not create a new way to follow people.
NIP-51 proposes hidden replies for each thread
An open NIP-51 proposal would let a thread’s author publish a public hidden-replies set that cooperating clients display behind a toggle. It uses one addressable kind-30027 event per thread, with the root ID as its d tag and e tags naming replies; only a set signed by the root’s author applies. Listing the root asks clients to hide other authors’ replies and stop offering a reply composer, while replies can still be published on relays. The per-thread format limits editing collisions to the same conversation. The author reports an implementation in Nostrich, but public-source inspection did not establish it; the proposal remains unmerged, with its set format still under discussion.
NIP-DB proposes verified domain names for key-addressed services
The open NIP-DB proposal, submitted September 28, describes Nostr events that bind an ordinary Internet domain to the key serving it over a key-addressed network such as FIPS, an encrypted mesh that addresses nodes by Nostr public key. A domain owner can establish the binding with a DNS TXT record or a DNSSEC proof carried with the claim; clients would pin a verified result for later offline use. The proposal explicitly bars resolution through an unverified claim, since anyone can claim someone else’s domain in a Nostr event. fips-pub-domains is the author’s reference implementation, but the event-kind numbers and some overlay-specific wording are still under review. Its reported end-to-end tests are the author’s evidence, not a claim that the proposal is an accepted NIP.
A private-feed draft explores encrypted groups of recipients
A new multi-recipient envelope proposal, opened September 29, sketches private notes, replies, and connections whose intended recipients can find an event without exposing their ordinary public keys in its visible tags. It proposes opaque pairwise alias tags derived from shared secrets and provisional event kinds, including a way to wrap another Nostr event for hundreds of readers. That could give small private feeds a more direct retrieval path than sending a separate message to every member.
The proposal’s author explicitly calls this a work in progress. The draft has no demonstrated implementation or security review, and its kind assignments and byte-level signing rules remain open.
A Blossom proposal lets other people announce mirrored media
An open NIP proposal describes a way for someone who mirrors another author’s Blossom blob to announce that copy through Nostr. A client could then look for the copy if the original server loses the blob. Discussion has also raised checking the mirror’s current BUD-03 server list when an announced server hint has gone stale. This is a proposed discovery path, not a guarantee that clients or archival relays already provide fallback storage.
Road-event reports seek a shared Nostr format
The open Road Event Reports proposal describes reports and confirmations for potholes, closures, cameras, and other road conditions. It uses location tags and NIP-40’s expiration timestamp, which tells relays when to stop serving an event, so a report need not remain current indefinitely. The author based revisions on a sample of events recovered from public relays and on the existing Roadstr clients for reporting road conditions, but the draft still leaves a compact-encoding question open, and the proposed NIP number has not been adopted.
Marmot revisits multi-device coordination
Marmot’s multi-device redesign replaces an unimplemented External Commit draft with a non-normative walkthrough for early feedback. The new direction explores an existing device approving a new one, bringing it into conversations and later removing devices, while keeping open questions visible. IDs reserved by the removed draft are freed because no implementation adopted them. The ideas document allocates no new IDs or wire formats and is not an implemented multi-device feature.
Six Years of Nostr Septembers
The last September issue is a chance to trace how Nostr moved from sketches to a larger set of interoperable tools. A 2021 ride-matching prototype used signed events to coordinate a service; five years later, identity proof wording and list-kind collisions are the sort of details maintainers are resolving. In between, clients learned to present conversations, media and recovery in ways ordinary people can use. The dated sources below show stages in that progression. They do not establish that every experiment launched or that each old design remains recommended.
September 2021: early experiments with useful shapes
A September 4 BUber commit explored a taxi-matching concept using Nostr events. It showed how a signed, relay-carried request could coordinate people without assigning the whole service to one server. The source is a concept, and it does not establish a launched ride service.
Later that month, Loquaz’s September 23 source offered a desktop chat prototype. That was another early attempt to make relay messages feel like an ordinary application. The source does not establish finished end-to-end encryption or a production messenger; the lasting thread is the search for a usable conversation interface on top of simple events. BUber tested ride matching, and Loquaz tested chat; both used signed events before common client patterns had settled. Those trials laid out two recurring problems for later clients: coordinating through relays and presenting events as a usable conversation.
September 2022: chat and delegated actions enter the specifications
The September 10 NIP-28 change described public chat channels with messages and metadata that clients could interpret together. NIP-28 made a shared room an explicit protocol subject and gave clients a common channel convention.
On September 23, NIP-26’s delegated-signing text documented a way for one key to authorize another to sign limited events. It captured an important 2022 design question: how to use a Nostr identity without handing the primary key to every application. NIP-26 is now marked unrecommended, so this is a record of an experiment, not advice for new integrations. Its later status shows how the signing model has moved: a specification can preserve a useful problem statement even when the proposed answer is retired.
September 2023: clients grow up around relay discovery and metadata
Damus is a Nostr social client. Its September 21 changelog recorded work on its local Nostr database, search, and hashtag navigation. Those changes made a busy social feed easier to browse and recover on a phone; the dated changelog is evidence for that client release, not for every later Damus capability.
The protocol details were moving too. A September 26 change to NIP-24 clarified optional profile metadata fields, while NIP-65’s September 29 change addressed relay URI normalization and deduplication. NIP-65 tells clients how to publish the relays they use for reading and writing; consistent URI treatment helps those lists point to the same relay even when strings differ in harmless ways. That small convention moved client design toward reliable discovery: finding a person’s events depends on knowing where they are published.
September 2024: posts acquire richer context
Damus’s September 22 release notes described support for NIP-84 highlights and comments. NIP-84 gives readers a way to quote and discuss a passage of long-form material. The client work shows how a protocol idea became something people could use while reading.
Meanwhile, NIP-34 received a September 20 change refining issue subjects and labels for git collaboration over Nostr, and NIP-73 received a change that day refining external content identifiers. These are separate specification changes: one helps a repository’s issues retain structure, while the other lets an event refer to material outside Nostr. Both extend the meaning a client can preserve when content travels between communities, repositories and other media.
September 2025: access controls and payment context become more precise
A September 6 NIP-42 revision addressed multi-user relay authentication. NIP-42 lets a relay challenge a client to prove which Nostr key is making a request; the update mattered for services that serve more than one authenticated account through the same connection.
A September 15 NIP-47 update added optional payment metadata to Nostr Wallet Connect requests. NIP-47 lets an app ask a wallet to perform actions over Nostr. More context can make a wallet interaction understandable, but the metadata may expose payer details, so clients and wallets still need to treat it as sensitive. The change illustrates how interoperability work now included what a recipient can learn, not just whether a request can be delivered.
September 2026: interoperability details meet public identity
This September, a merged NIP-51 change moved the follow-set event kind away from a collision. NIP-51 defines lists that a person can maintain and share; unique event kinds let clients distinguish one list type from another. An earlier Compass issue discussed the proposal, while the September merge is the status change.
A second merged change to NIP-39 clarified proof text and added more ways to associate an external account with a Nostr identity. NIP-39 is about checkable identity claims, not a central identity registry. Together, the two merges show current protocol work concentrating on the small details that determine whether independent clients interpret the same identity and list events correctly. They also show a shift from inventing new event categories toward reducing ambiguity in existing ones.
Across these six Septembers, the pattern is a progression from proving that a signed event can describe an application request to asking how a client verifies a claim about a person. The old prototypes matter because they expose the questions that later specifications and clients had to answer: who signs, where an event is found, what it means, and how someone knows whether to trust it. That is also why a small, precise protocol correction can matter as much as a new interface.