MeshTalk

Features

Private by default, direct by design.

MeshTalk does encrypted peer-to-peer messaging and not much else. That restraint is the feature.

End-to-end encryption

Every message is sealed with ephemeral X25519 keys and AES-256-GCM. The transport adds its own authenticated layer on top, and the control service never holds a key.

  • Ed25519 identity signatures authenticate every peer
  • Per-chunk forward secrecy for file transfers
  • AES-GCM protects contents and routing metadata
# what the relay can see peer identities, endpoints frame fixed-size ciphertext body nothing readable

LAN-first discovery

MeshTalk broadcasts on UDP port 24890 to find peers on your local network. The lower peer ID opens an authenticated, encrypted TCP session. No router configuration and no internet connection needed.

  • Zero-configuration peer discovery
  • Works on air-gapped networks
  • Automatic path order: LAN, then direct UDP, then relay
# on a shared network ✓ discovered Alice (a3f8…c12) ✓ encrypted TCP session open you › Hello Alice!

Remote connections

On different networks, STUN discovers each side's public endpoint and both devices punch a direct UDP path. When that fails, the embedded relay carries the same encrypted frames and quietly steps aside when direct returns.

  • STUN-assisted NAT hole punching
  • Reliable, fragmented, authenticated UDP
  • Seamless hand-off from relay back to direct
STUN → discover public endpoint UDP → punch via NAT mapping SIGN → Ed25519 handshake proof → authenticated encrypted channel fallback: relay over wss://

Named group chats

Create named rooms and share an invite. Each message is encrypted independently for every member, so there is no shared group key to steal. Offline peers get a durable queue that flushes on reconnect.

  • Per-recipient encryption, no group key
  • Queued delivery with per-member status
  • History stays local, no server-side replay
$ meshtalk room create "Project team" ✓ invite copied to clipboard $ meshtalk group_send "Project team" "Meeting at 3?" ✓ delivered · Alice ✓ queued · Bob (offline)

Encrypted file transfer

Send files up to 50 MiB directly. Each chunk carries its own ephemeral key, transfers resume where they stopped, and received images preview inline.

  • 50 MiB per file, chunked and encrypted
  • Resume after a dropped connection
  • Paste an image straight from the clipboard
OFFER → name, size, chunk map CHUNK → fresh key per chunk ACK → completion or missing ranges → resume from where you left off

Terminal native

A full TUI and a scriptable CLI, built for people who live in a shell. It works over SSH, inside tmux, and anywhere your terminal goes.

  • Keyboard-first TUI with a peer sidebar
  • CLI commands for scripting and automation
  • Runs in Docker, or from a single archive
# launch the TUI (backend attached) $ ./meshtalk # Ctrl+P opens the command menu # peers on your LAN appear automatically

Specifications

The numbers.

TransportLAN UDP broadcast on 24890; encrypted TCP on 24891; reliable UDP for remote peers
Key agreementX25519 ephemeral keys, Ed25519 identity signatures
EncryptionAES-256-GCM, directional keys derived with HKDF-SHA256
File sizeUp to 50 MiB per file, per-chunk ephemeral keys
PlatformsmacOS, Linux (x64 / ARM64), Windows (x64), Docker
LicenceGPLv3, source on GitHub

Key agreement uses X25519 and is not post-quantum secure.

Ready when you are

Install it, share an invite, talk.