MeshTalk

Peer to peer · End-to-end encrypted · No accounts

Encrypted messages, straight between devices.

MeshTalk finds the peers on your network and punches through the NATs to reach the ones that aren't. Nothing is stored in a cloud inbox, because there isn't one.

Latest ... GPLv3 Works offline on LAN

NAT / firewall device A you device B peer 1 · same network (UDP 24890) 2 · direct UDP after STUN hole punch 3 · relayed through control (fallback) control + relay sees only ciphertext Every path carries the same end-to-end encrypted frames

Install

One line to running.

Binaries bundle the backend, CLI, and TUI. Nothing else to install at runtime.

macOS · Linux
Windows · PowerShell

Run with --help (bash) or -Help (PowerShell) for all options. Manual archives on every release.

  • macOSIntel + Apple silicon
  • Linuxx64 · ARM64
  • Windowsx64
  • Dockercontrol + client images

How it connects

The shortest path wins.

MeshTalk tries the cheapest route first, and only reaches for the relay when nothing else gets through.

  1. 01 / LAN

    In the same room

    A broadcast finds peers on your network. The two devices open an authenticated, encrypted TCP session. No internet required.

    UDP 24890 · TCP 24891
  2. 02 / Direct

    Across the internet

    STUN discovers each side's public endpoint, both punch a hole, and they speak reliable UDP directly. This is the preferred remote path.

    STUN + reliable UDP
  3. 03 / Relay

    When NATs refuse

    If direct setup fails, the control service relays frames it cannot read, then hands back to a direct path the moment one returns.

    wss:// fallback

What you get

A small tool that does the hard part.

End-to-end encrypted

Ephemeral X25519 keys and AES-256-GCM on every message. The control service only ever carries ciphertext.

LAN first

A UDP broadcast finds peers on your network and opens an authenticated TCP session. No router setup, no internet.

NAT traversal

STUN discovers public endpoints, then devices punch a direct UDP path. A relay stands by when NATs refuse.

Named rooms

Group chats encrypt each message independently per member. Offline peers get their messages queued.

File transfer

Send up to 50 MiB per file, chunked and individually encrypted, with resume on a dropped connection.

Terminal native

A full TUI and a scriptable CLI. Works over SSH, in tmux, and anywhere your terminal goes.

No middlemen

Your messages only need to reach one person.

MeshTalk keeps it that way: direct connections when it can, encrypted relay when it must, and no copy anywhere in between.