End-to-end encrypted
Ephemeral X25519 keys and AES-256-GCM on every message. The control service only ever carries ciphertext.
Peer to peer · End-to-end encrypted · No accounts
MeshTalk finds the peers on your network and punches through the NATs to reach the ones that aren't. Nothing is stored in a cloud inbox, because there isn't one.
Install
Binaries bundle the backend, CLI, and TUI. Nothing else to install at runtime.
Run with --help (bash) or -Help (PowerShell) for all options. Manual archives on every release.
How it connects
MeshTalk tries the cheapest route first, and only reaches for the relay when nothing else gets through.
A broadcast finds peers on your network. The two devices open an authenticated, encrypted TCP session. No internet required.
STUN discovers each side's public endpoint, both punch a hole, and they speak reliable UDP directly. This is the preferred remote path.
If direct setup fails, the control service relays frames it cannot read, then hands back to a direct path the moment one returns.
What you get
Ephemeral X25519 keys and AES-256-GCM on every message. The control service only ever carries ciphertext.
A UDP broadcast finds peers on your network and opens an authenticated TCP session. No router setup, no internet.
STUN discovers public endpoints, then devices punch a direct UDP path. A relay stands by when NATs refuse.
Group chats encrypt each message independently per member. Offline peers get their messages queued.
Send up to 50 MiB per file, chunked and individually encrypted, with resume on a dropped connection.
A full TUI and a scriptable CLI. Works over SSH, in tmux, and anywhere your terminal goes.
No middlemen
MeshTalk keeps it that way: direct connections when it can, encrypted relay when it must, and no copy anywhere in between.