#Amethyst v1.13.0: Web Apps, Concord, Buzz, Log in with Amethyst, Git, Bolt12 and lots more.
Highlights:
- Adds an **in-app Browser** for Nostr WebApps
- Adds support for **napplets (NIP-5D)** and **nsites (NIP-5A)**
- Adds **Concord Support (Armada)**.
- Adds **NIP-29 Groups (Flotilla)**.
- Adds **Buzz workspaces, with agents**.
- Adds a **Remote Signer (NIP-46)**.
- Adds **Git Clone Support (NIP-34)**.
- Adds **Relay Auth permissions (NIP-42)**.
- Adds **BitChat Geo-channels**.
- Adds **Blossom file display and sync**.
- Adds **Podcasting 2.0**.
- Adds **BOLT12 payments and zaps (NIP-B1)**.
- Adds **proof-of-work (NIP-13)** publishing.
- Redesigns **chat messages**.
- Redesigns **accent colors**.
- Redesigns **push notifications**
## New Features
### Web Apps, Sites & the Browser
- Opens Nostr web apps (NIP-5D napplets) and static websites (NIP-5A nSites)
directly inside Amethyst, rendered in an isolated, keyless sandbox process that
cannot reach your private key, storage, or data.
- Adds an in-app Browser — a drawer entry and pinnable bottom-bar tab — with an
omnibox address bar, autocomplete, history, favorites, recents, and captured
favicons. The address bar is drawn by Amethyst, never by the page, so its URL
cannot be spoofed.
- Adds "Log in with Amethyst": nSites open with a NIP-07 `window.nostr`
provider, so standard Nostr web apps can sign in and request signatures as your
active account — consent-gated, sign-only, and scoped per site.
- Lets web apps, with your permission, pay through your wallet (NWC), run live
relay subscriptions and queries, and read your identity (profile, lists, zaps,
badges) — every capability brokered and permission-gated (once / this session /
always). Payments always prompt with the amount shown.
- Pins favorite web apps to the bottom bar as embedded, swap-in-place tabs that
stay warm between visits.
- Discovers web apps: the empty browser suggests a curated list plus nSites and
napplets published by people you follow, and profiles gain an "Apps & Sites"
tab.
- Adds a Connected Apps / permissions screen to review and revoke what each app
can do.
- Routes nSite web traffic through Tor by default when Tor is active, with a
per-site onion/globe toggle.
- Gives each account its own web storage — cookies, logins, and site data no
longer leak between the accounts on your device. Sites you were already signed
into are signed out once; signing back in stores the session under the account
you are using, and switching away and back keeps it.
- Scopes granted permissions per account too, so each app asks once more under
each account you use it with. A grant by one account no longer applies to the
others.
### Communities (Concord)
- Adds Concord: an end-to-end-encrypted communities protocol with channels,
membership, invites, roles, moderation, and history — reachable from a hub in
the drawer and pinnable to the bottom nav.
- Creates and edits communities with encrypted icon/banner, relay editing, and
channel management.
- Invites and joins via minted invites with QR codes, tappable invite links,
paste-to-redeem from Search, deep links, and direct member invites.
- Chats in channels with a rich composer (@mentions, custom-emoji autocomplete,
reply preview), encrypted image messages, reactions, replies, and typing
indicators.
- Adds threaded replies (inline or minichat modes) and delivery ticks for your
own messages.
- Groups channels by community in Messages with last-message previews, unread
dots, facepiles, live typing, and per-type load toggles.
- Adds moderation: ban/unban with read-time enforcement, role grants, a "Make
admin" toggle, and a full member roster. A ban hides a member's posts for
everyone else; removing their access to the community's keys takes a
Refounding.
- Backfills channel history across epochs, paging back to the true start of a
channel.
- Surfaces Concord replies and reactions on the Notifications tab with a
community pill.
- Lets authors edit their own channel messages (kind 3302). Latest edit wins,
and it is non-destructive, so reactions and replies stay attached. Only the
original author's edits take effect.
### Git Collaboration (NIP-34)
- Browses Nostr git repositories in-app: a Git Repositories feed and a per-repo
screen with README and Code tabs.
- Reads code with branch/tag switching, file search, image preview, commit
history, syntax highlighting, and word-level diff highlighting.
- Reviews patches and pull requests with computed diffs and status actions; PR
updates surface on the repo screen. The code browser needs a repository with an
http(s) clone URL.
- Manages issues: Issues and Patches & PRs tabs split by open/closed, issue
labels with filtering, and a full-screen New Issue composer.
- Edits a repository announcement from the repo screen, bookmarks repositories,
and filters the feed to your own repos.
- Adds a project-home dashboard with stats, languages, recent activity, and
last-commit rows.
### Location Channels
- Adds Location Channels: geohash-based public rooms that interoperate with
BitChat, browsable from a dedicated drawer list and pinnable to the bottom nav.
- Posts under an unlinkable per-area anonymous identity, or opt in to post as
your real account. An optional nickname survives restarts, but it is a single
handle reused in every area — setting one links your posts across areas.
- Teleports to any place from a map picker or the feed-filter dialog to read and
post to distant rooms, and follows a teleported place to keep its feed.
- Reacts, zaps, and replies on location messages, with a "live near you" bubble
on Home surfacing nearby rooms.
- Adds a "pick on map" location picker to the short-note and all other composers.
### Groups (NIP-29)
- Adds relay groups: group chat, a discovery feed with a top-bar filter and
favorites, and join / leave / create / invite actions.
- Adds subgroups (parent/child hierarchy), custom roles (kind 39003), threads,
and message pinning.
- Shares groups via `naddr` and invite links with one-tap join; inline group
links render as self-loading cards.
- Adds a map-based location picker when creating a group, and lets pinned group
tabs act as bottom-nav roots.
### Buzz (Agent Workspaces)
- Adds Buzz: a self-hosted workspace where humans and AI agents build together on
a relay you own, built on the NIP-29 relay-group family with plaintext content
so the relay can run search, audit, and workflows. Reachable from a "Buzz
Workspaces" bottom-nav tab and the drawer Feeds list.
- Renders workspace channels natively and composes messages; sections a community
into Channels, Forums, inline DMs, and an Agent Console; and renders forum posts
as Concord-style threads with the full chat composer.
- Adds an agent-owner console with cost and personas tabs, an agent-fleet cost
aggregator, live observer telemetry, persona create/edit, and NIP-OA attestation
issuance.
- Adds live typing indicators, presence dots, collapsible sections with unread and
stars, a workspace canvas viewer and edit composer, and a bot "Working…"
indicator.
- Invites people to a channel or community and mints invite links; redeems invite
links (intercepted into the in-app browser) and auto-invites mentioned
non-members.
- Wires Buzz direct messages end to end, titles a DM by its participant, and
surfaces Buzz DMs in the Notification feed rendered as messages.
- Discovers workspaces and DMs via the relay's own kinds, imports workspace
channels from a relay in "Find groups", and routes Tor workspaces to clearnet
when needed.
- Adds a shared **Agent Work board**. Any channel member files a task, upvotes
to reprioritize it, and watches the workspace's agent carry it to a pull
request. Jobs that ship directly and gated workflow runs fold into one board,
grouped by Needs approval / Working / Up next / Shipped.
- Approves or denies a gated run in place. The "Approve & open PR" step
authorizes a push and PR, but never merges or deploys. Adds a confirm step, an
approver and workflow-definition picker, and Buzz Agent Persona editors for
model, provider, and runtime.
- Asks before adding you to a channel someone else put you in (Accept / Ignore /
Leave). Narrates channel changes as plain-language system lines: "Bob added
Alice", topic, visibility, and TTL changes, and more.
- Notifies the requester when their agent job finishes or fails. Lets a
self-hosted geode relay be the private Buzz workspace via a member-and-agent
membership policy.
### Chat & Messages
- Redesigns message rendering across every chat — DMs, public chats, groups, and
communities — with modern bubbles, swipe-to-reply, send motion and press
feedback, per-author name colors, jumbo emoji, day headers drawn above the
messages they introduce, and a timestamp on the last message of each author
run.
- Replaces the message 3-dot menu with a compact two-stage long-press sheet that
unpacks wrapping reactions and zap-amount presets in place.
- Renders channel admin events as centered system messages, and hides a reply
quote when it targets the message directly above.
- Replaces the Messages FAB speed-dial with a full-screen, color-coded
new-conversation chooser, and adds a Messages settings screen with a
grouped-by-relay view and per-type load toggles.
- Warns about DMs from senders reported by people you follow: flags a reported
counterpart on the chat-list row and inside the room, with a per-user
report-warning flow.
### Notifications
- Redesigns push notifications into per-kind, observable, richly-rendered
notifications that resolve inline @npub mentions to display names, render an
inline image link as the big picture, and attribute a reply's parent to its real
author.
- Adds push notifications for Buzz DMs and for bare reactions and reposts to your
notes, with repost-mute parity. Auto-dismisses a tray notification once its
event is read in-app.
- Rebuilds the in-app Notifications tab with infinite-scroll paging via a
look-ahead buffer, time-based history paging with in-feed load markers, and
auto-retry of stalled or faulty relays with an actionable relay detail.
### Remote Signer & Security
- Lets other apps and websites sign through Amethyst for the first time
(NIP-46): connect by scanning or pasting a `nostrconnect://` code, and keep
signing in the background — whether your key is stored directly in Amethyst or
delegated to an external signer like Amber (NIP-55).
- Asks for informed consent before authorizing an app — showing its name and
icon, which account will sign, the exact permissions, and an event preview —
with per-account sheets and one-tap batched approval.
- Manages connected apps from a dedicated screen with per-app relay list, live
health, time-bound grants, and instant "forget this app".
- Adds interactive relay login prompts (NIP-42): choose Once / Always / Never
per relay, with venue-aware prompts for public chats, communities, and live
streams, and one-tap rules to trust relays used by people you follow. Apps
connected through the remote signer now ask before signing a relay login,
instead of approving it automatically under "Let's be reasonable".
### Web of Trust (GrapeRank)
- Discovers Web-of-Trust score providers via NIP-85 and shows hop distance and
follower count on trust cards. Computing the scores — crawling the social graph,
reverse-follower crawling, and publishing NIP-85 cards — is done by the `amy`
command-line tool, not the app; see the Cli section.
### Publishing & Sync
- Adds proof-of-work (NIP-13) publishing: a fire-and-forget mining queue with
per-account difficulty and per-category settings, scheduled-post mining, and
per-post overrides, shielded by a foreground service and mined across half the
device's cores.
- Adds NIP-77 negentropy sync as a first-class capability, with deletion
(NIP-09/62) propagation so scoped syncs no longer strand deletions.
- Shows PoW mining progress, and surfaces PoW, OpenTimestamps, and location
markers as tap-to-explain pills in the note header.
### Podcasts
- Adds Podcasting 2.0: renders shows in detail and thread views, surfaces
episodes in the merged podcast feed, and plays trailers.
- Shows person credits as real Nostr profiles, soundbites, in-app chapters, a
transcript viewer, and a Top Supporters leaderboard.
- Adds per-episode reactions and NIP-22 comments, a Podcast Bookmarks screen, and
value-for-value Lightning splits paid per-minute during real playback.
- Adds in-app podcast authoring: create and edit shows, episodes, and trailers
from an authoring hub, with a value-for-value split editor that adds Nostr
recipients by search. Verifies NIP-F4 podcast authors against their kind-10064
counter-claims.
### BOLT12 Payments & Zaps (NIP-B1)
- Adds BOLT12 zaps: self-verifying kind-9736 events that prove a real BOLT12
Lightning payment. They carry a settlement proof instead of relying on an
LNURL receipt. They fold into the same zap total and reactions row as Lightning
zaps, with anonymous and receiptless (pay-only) variants. Only cryptographically
verified proofs count toward the total.
- Publishes and edits your own BOLT12 offer list (kind 10058) from an in-app
editor. The list is cached, kept live, and restored across restarts.
- Pays a recipient's published offer. Hand it to an external wallet as a
`bitcoin:?lno=` (BIP21) intent, or pay in-app over a NWC wallet that supports
it.
- Sends zaps over NWC, using the new `pay`/`receive` methods
(nostr-wallet-connect/nwc#2). Prefers BOLT12 over Lightning when the recipient
offers it and the wallet supports it, and falls back to a Lightning zap
otherwise.
- Verifies payer proofs cryptographically: payment-hash preimage, invoice and
proof signatures, and BOLT12 merkle reconstruction of selectively disclosed
fields. Dims and does not count a proof that can't be bound to the offer.
### Wallet & Payments
- Adds a Cashu wallet setup wizard: find-or-create with cross-relay discovery,
mint suggestions, and a CashuMints screen; the wallet auto-publishes on mint
add/remove.
- Claims P2PK-locked Cashu tokens (NUT-11). Matches the lock against your wallet
or identity key, and redeems all-or-nothing. Gives a clear error when a token
is locked to a key this wallet can't sign for.
- Adds a setting to hide the on-chain (Bitcoin) wallet, including from zap
buttons.
- Prefers NIP-44 encryption for NWC when the wallet advertises it. Adds a NWC-07
deep-link pairing helper. Posts a tray notification for incoming non-zap
Lightning payments.
### Battery, Data & Background Service
- Adds a resource-usage ledger: on-device battery and data accounting across
relay connections, media, HTTP, proof-of-work, Tor, calls, decrypts, and
remote signs, with per-screen foreground time and reconnect-churn tracking.
Optional NIP-17 reports mail the summary to yourself.
- Presents it on a usage screen with stat tiles, a trend chart, proportion bars,
cellular-first bars, a Tor card, actionable insights, and a live memory card.
- Adds a master switch for the always-on background notification service with
per-account participation, a cost card that links to notification settings,
and a distinct status-bar icon.
- Scales `LocalCache` pruning to the OS memory-pressure level, and trims feed
lists, rich-text/robohash/relay-info caches, the image cache, and the player
warm pool under pressure.
### Look, Media & Navigation
- Adds theme customization: pick an accent color (with a swatch picker), font,
and font size. The accent now drives Material 3 containers, buttons, FABs,
switches, unread dots, selected-reaction highlights, verified NIP-05 / image
marks, and the Following badge.
- Redesigns UI Preferences into grouped in-screen options with live font
previews, and adds a settings search filter in the app bar.
- Adds a Blossom media file manager: browse and manage stored blobs with per-file
controls, mirror and `/media` toggles, an app-level "Sync all" with progress,
and BUD-07 confirm-then-pay mirroring for paid servers.
- Extends the Blossom manager with a gallery grid (video thumbnails and a
full-screen zoomable viewer) and a per-file detail sheet. Adds an importer that
copies blobs from other Blossom servers into yours. Falls back to a verified
download-and-reupload when a target has no `/mirror`.
- Redesigns the Media Servers screen as a single auto-saving canvas with a
reorderable priority list and cached health probes.
- Redesigns the bottom-bar setup with a live preview, drag-to-reorder, and real
favicons; the default bar becomes Home, Messages, Wallet, Browser,
Notifications.
- Adapts the app shell to large screens: tier-scaled navigation transitions, a
reading-column width cap on wide panes, and a two-pane Messages layout.
- Nicknames people with NIP-85 contact cards (kind 30382) signed by your account
key. The nickname shows above their real display name on the profile and
supports custom emoji.
- Adds fitness support: renders POWR strength workouts (kind 1301) and exercise
templates (kind 33401) as cards, and merges close-by Health Connect sessions of
the same type.
- Renders Birdstar bird detections (kind 2473) with common-name titles and
Wikidata links, surfaces Birdex life lists on home and profile, and renders PS1
memory-card saves (kind 38192) with an animated BIOS icon.
- Adds a compose signature pre-filled in text-based post screens, and an optional
subject/title field in the short-note composer.
- Renders NIP-30 custom-emoji reactions as an avatar badge, a lone zap/nutzap as
a large activity card, and NIP-84 highlights from web highlighter clients.
- Supports NIP-51 mute-list hashtag entries and public-chat reply notifications.
- Modernizes the Privacy, Profile UI, Home Tabs, and Calendar Reminder settings
screens into grouped in-screen options.
- Adds "Share as QR" for a note, with a choice of `note` or `naddr` payload and an
image thumbnail for image-only notes.
- Resolves NIP-05 identifiers (including Namecoin `.bit`) in the @-mention
popover, wiring them to `nostr:` mentions.
## Performance
- Speeds up napplet/nSite opens by overlapping WebView init, prefetching blobs in
parallel, and fast-serving content-addressed blobs from cache.
- Substantially faster GrapeRank crawls (background IO, mass pre-connect with
cached DNS, batched contact reads, parallel outbox fetches, early dead-relay
pruning) and faster scoring via Gauss-Seidel sweeps over a compact integer
graph.
- Speeds up NIP-77 reconcile with direct-built wire frames (~2.5x), O(1) range
fingerprints, a live negentropy index, and an allocation-free idle watchdog.
- Prefetches media and pre-parses note text ahead of the viewport, adds a k-way
merge for the home feed, and pins indexes for multi-author queries.
- Adopts a caching event decoder across Android/Desktop/CLI, batches Schnorr
verification off the receive path, and keeps light/dark resolution O(1) after
an accent change.
- Parallelizes Blossom "Sync all", prefetches a joined group's history, and mines
proof-of-work on half the device's cores.
- Orders NIP-50 relay search by bm25 relevance and scales search and tag-watcher
queries with corpus size, picking the SQLite filesystem driver by cost and
materializing indexes at runtime.
- Removes live-path allocations in `LiveEventStore` and `FilterIndex` (and on the
frame/search paths), and snapshots `FilterIndex` with a persistent map.
## Improvements and Bug fixes
- Normalizes accent theming: contrast-picks onPrimary so filled buttons/FABs stop
washing out, bases light/dark on background luminance, and fixes accent
regressions.
- Keeps live HLS streams playing and caches only proven on-demand HLS; shows a
browser-fallback overlay when a decoder stalls and pauses looping videos after
5 plays.
- Adds an HTTP/2 keepalive ping to stop stale-connection image stalls.
- Hardens the relay client: enforces blocked relays on every REQ/COUNT/publish,
backs off from REQs relays repeatedly refuse, drops relays that fail hard
during crawls, caches each relay's advertised LIMITS, and fixes reconnect
backoff on network/transport changes.
- Shows and edits Marmot (MLS) group icons in the feed and in group metadata,
interoperable with other Marmot clients.
- Opens zaps and reactions in their own thread view, turns Notify chips into bell
mute-toggles that list every thread member, and replies with kind 1111 to
Amethyst's own kind-1 thread roots.
- Adds search, a local filter, and a top-nav feed filter to the App
Recommendations screen, and shows a website's favicon and domain across every
browser-connected app view.
- Fixes nutzap relay routing to receive/advertise on inbox/DM (kind 10019)
relays instead of outbox.
- Fixes Concord invite handling (revocation, keyless CORD-05, clearer failure
copy, no hang on bad links, skip re-join) and channel rows stuck on "No
messages yet".
- Persists the Concord community list and loads pinned communities from their own
relays so cold boot no longer refetches, shows channels on Messages as soon as
the control plane folds, warms channel previews so the list fills without opening
each channel, and rank-gates the Ban/Remove affordances (CORD-04).
- Sizes the video player box so live streams stop rendering black bars, and
enforces the decoder budget when acquiring players.
- Stops stamping our client tag on someone else's event template so external
signers sign it unchanged.
- Keeps calendar RSVP buttons on a single line, drops dead top padding on Home
when there are no live bubbles, and modernizes the Zap the Devs donation card.
- Rejects NIP-29 group state not signed by the relay, opens group posts in the
group chat, and fixes subgroup edit safety and pinned-message jump.
- Makes tapping a message timestamp open delivery info instead of toggling the
time format, and right-aligns your own messages.
- Recovers a media file's type from its extension when the imeta MIME is
malformed, and moves several disk reads (boot receiver, signer policy) off the
main thread.
- Serializes account construction so concurrent loaders can't build duplicate
accounts.
- Routes Onion-Location through the Android app's HTTP clients and maps Tor/Arti
errors to accurate SOCKS reply codes.
- Extracts the rich-text renderer and many event cards (calendar/RSVP, podcast
atoms/splits, relay discovery, code snippet, ecash mint, activity, Git
diff/status, and more) into shared commons so Desktop and Android render
identically.
- Sends pictures in minichat thread replies (encrypted in Concord, plaintext in
public chats). Resolves @-mentions in the minichat composer and tray
quick-replies. Adds `p` tags for people cited in kind 9/11/1111 and Buzz stream
messages, so mentions notify and resolve.
- Stops the inline audio player from painting over the note below it. Marks
every room type read from the Messages "mark as read" action.
- Fixes numeric HTML entities in link-preview meta tags. Routes kind-39005 by tag
shape, so Buzz thread summaries no longer parse as NIP-29 pin lists.
- Shortens over-long translated strings across 23 locales and fixes duplicate
and CDATA translation issues.
## Desktop
- Redesigns notifications with a reworked inbox and native OS toast
notifications.
- Adds NIP-42 relay AUTH with an inline Once / Always / Never approval banner and
persisted grants.
- Makes NIP-17 private DMs reliable: resolves recipient inbox relays, fetches DM
relay lists and account/Blossom config from outbox relays, and stops falling
back to connected relays.
- Adds Web-of-Trust score badges, Follow Packs (NIP-51) discovery with one-tap
follow, note scheduling, opt-in NIP-37 draft sync, and a hashtag-spam filter.
- Adds a Privacy Lock: gate the Messages and Wallet columns behind a password,
with an auto-lock timeout. It is a screen gate, not encryption at rest —
messages continue to sync while it is locked.
- Renders rich text through the shared core (removes the desktop-only fork) and
ships as a Flatpak bundle.
- Adds moderation & safety: mute/block and NIP-56 report actions in the note menu
with feed, thread, and profile enforcement (previously a silent no-op), NIP-36
content-warning blur with tap-to-reveal, a sensitive-content toggle, and
management screens — with snackbar feedback and zero-relay send warnings.
- Adds NIP-88 polls (render, vote, create) with a "Polls" search facet, and
unifies the note ⋮ overflow and right-click menus.
- Fixes a desktop-cache race that could wipe the follow list, and makes sidebar
navigation replace the detail overlay instead of hiding behind it.
## Cli
- Adds nak-style primitives: `amy decode`/`encode` (NIP-19/21), `verify`, `key`
(generate/public/encrypt/decrypt/validate, NIP-49), and `filter`.
- Adds query verbs: `amy fetch` (one-shot with code-mode outbox resolution),
`subscribe` (live NDJSON), `count` (NIP-45), and `outbox USER` (NIP-65).
- Adds `amy sync` — NIP-77 negentropy reconcile with deletion propagation — and
`amy event` / `amy publish` for raw and pre-signed events.
- Adds `amy encrypt`/`decrypt` (NIP-44/04) and `amy gift wrap`/`unwrap` (NIP-59).
- Adds `amy blossom` (upload/download/list/delete/check/mirror, NIP-B7) with a
live interop smoke test.
- Adds `amy git` (NIP-34), `amy podcast` and `amy podcast20` (Podcasting 2.0 with
V4V splits).
- Rounds out `amy git` to full NIP-34 parity: `browse`/`cat`/`log` over
smart-HTTP, `init` from a local checkout, `label` (NIP-32), `apply` a patch to
the working tree, and `grasp list`/`set` (GRASP server list, kind 10317).
- Adds `amy buzz` for block/buzz workspaces (channels, DMs, invite-link
redemption), verified against a live Buzz relay.
- Turns `amy` into the Buzz workflow/agent runner. `buzz agent serve`/`up`/
`doctor` run gated or parallel-backlog agents in isolated git worktrees that
open PRs. `buzz workflow trigger`/`run`/`approve`/`deny` drive the human
approval gate.
- Adds `amy bolt12` (NIP-B1): decode offers and payer proofs, verify a zap,
get/set a kind-10058 offer list, and a two-step intent → zap send.
- Adds the `amy cashu` wallet (NIP-60/61): wallet lifecycle, balance, mint,
receive/send (LN / token / nutzap), and maintenance.
- Adds `amy admin` (NIP-86 relay moderation) and `amy serve` (run a relay by
embedding geode).
- Adds NIP-46 remote signing: `amy bunker` server, `amy login bunker://…`, and
`amy login --nostrconnect`, gated with `--perms` and interactive approval.
- Adds the `amy graperank` suite (crawl/score/publish/followers/rank/…),
account-less crawl/score, and NIP-85 card publishing.
- Adds `amy fof` (follows-of-follows, renamed from `amy wot`), `amy concord`
(encrypted communities), `amy relaygroup` (NIP-29), and `amy geochat`
(BitChat-interoperable geohash channels).
- Adds NIP-13 proof of work (`amy pow`, `--pow` on posts), `amy kind`, `amy nip`,
`amy namecoin`, `amy status`, and `amy logoff`.
- Expands `amy nsite`/`napplet` with `publish`, `serve`, and `list`.
- Switches the default event store to SQLite and hardens the output contract:
single-line `--json`, exit codes 0/1/2/124, publish results carry each relay's
rejection reason, and read-only verbs run without an account.
## Quartz
- Adds NIP-77 negentropy sync (pipelined worker pool, multi-connection fan-out,
bounded-memory streaming, `LiveNegentropyIndex`) and NIP-09/62 deletion
propagation.
- Adds NIP-13 proof-of-work publishing: a cooperative-cancellation miner and a
`PoWNostrSigner` decorator that composes with any signer, plus NIP-59
gift-wrap mining on the outer wrap only.
- Adds NIP-66 `RelayReachabilityStore` — a durable, shareable dead-relay cache
backed by kind:30166 events.
- Adds the Concord/CORD protocol foundation (key derivation, envelope layer,
authority resolver, roles/moderation, CORD-05/06/07) and the NIP-5D/5A
trust-boundary core (capability model, permission ledger, broker, wire
protocol).
- Implements Marmot (MLS-over-Nostr) group icons byte-for-byte with the
mdk/whitenoise scheme, and fixes SecretTree ratchet preservation across
restore.
- Adds an OutboxDispatcher to fetch profile/contact events via each author's
outbox relays, and richer NIP-89 app-handler parsing.
- Adds the Buzz protocol surface (~78 event kinds spanning NIP-OA owner
attestation, NIP-AM agent turn metrics, personas/teams/managed agents, streams,
DMs, forums, presence, and moderation), verified against vectors generated by
Buzz's own Rust reference.
- Adds the BOLT12 zaps protocol layer (NIP-B1): kind-9736 zaps, kind-9737 zap
intents, kind-10058 offer lists, full spec validation, and a payer-proof
verifier with BOLT12 merkle reconstruction. NWC gains `pay`/`receive` methods.
- Widens NIP-50 search indexing to more event kinds and tag-borne text. Indexes
only the public petname and summary on contact cards (kind 30382), never the
encrypted fields.
## Geode (standalone relay)
- Adds relay-to-relay mirroring with strfry-router parity: a two-phase model
(NIP-77 negentropy sync catch-up plus a live REQ tail), `down` / `up` / `both`
directions, per-upstream mirror filters, and relay-to-relay trust.
- Keeps mirrors alive across upstream restarts with a retry pump and ping
keepalive, and advances the since-watermark correctly on reconnect.
- Adds `import` / `export` NDJSON verbs and an optional no-full-text-search mode
(`--no-search`) for lighter deployments.
- Adds `[database]` tuning knobs with periodic `PRAGMA optimize`, and validates
config knobs and mirror filters at boot.
- Runs embedded in the CLI via `amy serve`.
- Serves full-set negentropy NEG-OPENs from a live index and streams mirror
catch-up IDs instead of materializing them.
- Adds relayBench, a head-to-head benchmark harness (geode vs strfry vs any
relay) measuring ingest, query, and NIP-77 sync over a shared corpus.
- Enables a combined tag+kind+pubkey index, a cost-based filesystem-driver pick,
and runtime index materialization, with new tag∩author and driver-selection
relayBench shapes.
- Ships a release pipeline: a GHCR Docker image, `.deb`/`.rpm` packages with a
bundled JRE and systemd unit, a portable jlink'd tarball, and a Homebrew
formula. Adds `--version`/`--help` and a boot smoke test in CI.
- Lets operators pick any Quartz `IEventStore` backend via `[database].backend`:
SQLite (default), filesystem, or a custom store loaded by class name.
## Build & Documentation
- Rebuilds the Tor/Arti native library for the SOCKS reply-code fix, ships a
Homebrew formula for `amy`, and seeds the Gradle distribution from a verified
mirror in the web sandbox.
- Adds NIP-29 group-chat test coverage across every assembler, filter shape, and
relay integration.
- Targets JVM 17 for Quartz, upgrades AGP, and replaces the abandoned
android-test-report action with `mikepenz/action-junit-report`.
- Adds a coding standard banning raw invisible/bidirectional Unicode in source
(Trojan-Source, CVE-2021-42574) and replaces existing occurrences with `\u`
escapes.
## Contributors
- @nprofile…vhl6
- @nprofile…m3sx
- @nprofile…94k8
- @nprofile…mjk6
- @nprofile…xcpk
- @nprofile…9ccm
- roguehashrate
- LubuSeb
## Translations
- Czech, German, Brazilian Portuguese, and Swedish by @nprofile…m3sx
- Spanish (Spain, Mexico, and US) by @nprofile…yhdq
- French by @nprofile…d26f
- Hungarian by @nprofile…ns2l
- Dutch by @nprofile…ge6h
- Hindi by @nprofile…z0lu
- Polish by @nprofile…8c53
- Slovenian by @nprofile…406e
- Chinese Simplified by hypnotichemionus4
- German by crowdin.pretended462