Features
Private by default, direct by design.
MeshTalk does encrypted peer-to-peer messaging and not much else. That restraint is the feature.
End-to-end encryption
Every message is sealed with ephemeral X25519 keys and AES-256-GCM. The transport adds its own authenticated layer on top, and the control service never holds a key.
- Ed25519 identity signatures authenticate every peer
- Per-chunk forward secrecy for file transfers
- AES-GCM protects contents and routing metadata
LAN-first discovery
MeshTalk broadcasts on UDP port 24890 to find peers on your local network. The lower peer ID opens an authenticated, encrypted TCP session. No router configuration and no internet connection needed.
- Zero-configuration peer discovery
- Works on air-gapped networks
- Automatic path order: LAN, then direct UDP, then relay
Remote connections
On different networks, STUN discovers each side's public endpoint and both devices punch a direct UDP path. When that fails, the embedded relay carries the same encrypted frames and quietly steps aside when direct returns.
- STUN-assisted NAT hole punching
- Reliable, fragmented, authenticated UDP
- Seamless hand-off from relay back to direct
Named group chats
Create named rooms and share an invite. Each message is encrypted independently for every member, so there is no shared group key to steal. Offline peers get a durable queue that flushes on reconnect.
- Per-recipient encryption, no group key
- Queued delivery with per-member status
- History stays local, no server-side replay
Encrypted file transfer
Send files up to 50 MiB directly. Each chunk carries its own ephemeral key, transfers resume where they stopped, and received images preview inline.
- 50 MiB per file, chunked and encrypted
- Resume after a dropped connection
- Paste an image straight from the clipboard
Terminal native
A full TUI and a scriptable CLI, built for people who live in a shell. It works over SSH, inside tmux, and anywhere your terminal goes.
- Keyboard-first TUI with a peer sidebar
- CLI commands for scripting and automation
- Runs in Docker, or from a single archive
Specifications
The numbers.
| Transport | LAN UDP broadcast on 24890; encrypted TCP on 24891; reliable UDP for remote peers |
|---|---|
| Key agreement | X25519 ephemeral keys, Ed25519 identity signatures |
| Encryption | AES-256-GCM, directional keys derived with HKDF-SHA256 |
| File size | Up to 50 MiB per file, per-chunk ephemeral keys |
| Platforms | macOS, Linux (x64 / ARM64), Windows (x64), Docker |
| Licence | GPLv3, source on GitHub |
Key agreement uses X25519 and is not post-quantum secure.