Nostr Compass Podcast #40

About this episode
<p>Max, Form* and Infinity x2 discuss encrypted messaging, mesh networking, Nostr application releases, signer improvements, long-form articles, and media attachment metadata.</p><p>Guests: nostr:npub1klkk3vrzme455yh9rl2jshq7rc8dpegj3ndf82c3ks2sk40dxt7qulx3vt · nostr:npub1qu7dsd44275lms4x9snnwvnnmgx926nsppmr7lcw9dlj36n4fltqgs7p98 · nostr:npub15gkmu50rcuv6mzevmslyllppwmeqxulnqfak0gwud3hfwmau6mvqqnpfvg</p><p><a href="https://nostrcompass.org/en/newsletters/2026-09-16-newsletter/">Newsletter 40</a> · <a href="https://gitworkshop.dev/npub1wav4fae3gyfy3xj298kxj2mj8phavz7vavps34przq02j7w902qq902923/relay.ngit.dev/nostr-compass-android">Nostr Compass Android source</a></p><h3>0:00 Episode intro</h3><p>Max introduces episode40 of the asynchronous Nostr Compass podcast and invites listeners to contribute recordings through Logbook.</p><h3>0:24 Marmot Protocol and MDK reach v0.10.0</h3><p><a href="https://github.com/marmot-protocol/mdk/releases/tag/v0.10.0">Marmot Protocol’s MDK v0.10.0</a> adds bounded chat-list and conversation windows, independent account-attention summaries, revision-safe drafts, and viewer reaction state for applications building MLS-based encrypted groups over Nostr. It also restores account-scoped user blocking and counts pending invitations without counting them again as unread messages.</p><h3>2:08 Myco 0.7.0 runs napplets and file sharing over a multi-path FIPS mesh</h3><p><a href="https://github.com/Origami74/myco/releases/tag/v0.7.0">Myco v0.7.0</a> turns the Android mesh application into a host for napplets, single-file Nostr programs described by the open <a href="https://nostrcompass.org/en/topics/nip-5d/">NIP-5D proposal</a>. Each napplet runs in a sandbox without direct network or storage access and requests identity, relay, outbox, mesh, picture, or file capabilities through Myco. The install sheet shows those permissions before approval, users can change them later, and updates that request broader access return to the permission gate.</p><h3>3:33 Dart NDK changes relay, cache, and account behavior</h3><p><a href="https://github.com/relaystr/ndk/releases/tag/v0.10.0-dev.3">Dart NDK v0.10.0-dev.3</a> is a development release of the Dart client library, with breaking changes across relay handling, caching, authentication, and account streams. Client maintainers should expect code and behavioral migration work, especially where an application assumes that cached events, hidden events, or account updates follow the previous release line’s semantics.</p><h3>4:18 Keycast publishes its rebuilt signer release candidate</h3><p><a href="https://github.com/marmot-protocol/keycast/releases/tag/v2.0.0-rc.1">Keycast v2.0.0-rc.1</a> is the first numbered release of the rebuilt self-hosted NIP-46 remote signer. The release candidate adds multiplexed NIP-46 support, shared and per-key relay routing, durable request handling, encrypted key storage, invitations, sessions, and team workspaces.</p><h3>5:08 Nail 0.2.0 restores Nostr-to-email subscriptions</h3><p><a href="https://github.com/formstr-hq/nail/releases/tag/v0.2.0">Nail v0.2.0</a>, a service that delivers Nostr messages through email workflows, adds self-healing gift-wrap subscriptions. The change is aimed at restoring Nostr-to-email delivery after subscription failures instead of leaving the bridge silently stalled. Infinity x2 and Max also discuss PGP end-to-end email encryption in Mailstr and compatibility with providers such as Proton Mail.</p><h3>6:15 Nostr Mail Client 0.15.0 broadens account and relay control</h3><p><a href="https://github.com/nogringo/nostr-mail-client/releases/tag/v0.15.0">Nostr Mail Client v0.15.0</a> adds one-tap account switching, per-account notifications, web push, and recovery of a missing relay list from a relay, Nostr address, or <code>nprofile</code>. It also republishes profiles and relay lists to indexing relays, reconnects when network access returns, and distinguishes a device outage from unreachable mail relays. Those changes tighten account recovery and delivery across desktop, web, and Android clients.</p><h3>7:04 Linky 26.9.17 keeps recovery seeds off its server</h3><p><a href="https://github.com/linky-fit/linky/releases/tag/v26.9.17">Linky v26.9.17</a>, a contacts, private Nostr messaging, and Lightning/Cashu payments application, fixes a path that sent recovery seeds to Linky's server when users saved them through a password manager. The release also hardens payment-file URL handling and disables Android application backups, reducing the places where wallet and identity recovery material can escape the device.</p><h3>8:00 Calendar by Form* 2.4.0 adds Mailstr guest invitations</h3><p><a href="https://github.com/formstr-hq/nostr-calendar/releases/tag/v2.4.0">Calendar by Form* v2.4.0</a>, a Nostr calendar client, adds Mailstr guest invitations and mobile calendar fixes. The invitation path lets organizers include participants through mail-oriented coordination without requiring an existing calendar account.</p><h3>9:32 Hessible 0.1.2 speeds encrypted contact and photo sync</h3><p><a href="https://github.com/circumspace/hessible">Hessible 0.1.2</a>, a privacy-focused Android contacts application that stores encrypted contact data on Nostr relays, reduces synchronization overhead and mirrors encrypted contact photos across Blossom servers. The release also makes the application package smaller, while its own release guidance continues to caution users to back up keys and account for varying relay retention.</p><h3>10:07 Boris 0.12.5 bounds extraction and strengthens offline reading</h3><p><a href="https://github.com/dergigi/boris/releases/tag/v0.12.5">Boris v0.12.5</a>, a reading-list client built around Nostr bookmarks, follows v0.12.4 with bounded content extraction, offline caching, relay-query changes, unsafe-HTML handling, and a fix for nearly invisible text under the Paper White theme. These changes affect both content safety and the reliability of reading saved material without a live network path.</p><h3>10:40 Amethyst 1.15.2 refines media and root-scope replies</h3><p><a href="https://github.com/vitorpamplona/amethyst/releases/tag/v1.15.2">Amethyst v1.15.2</a> nostr:npub142gywvjkq0dv6nupggyn2euhx4nduwc7yz5f24ah9rpmunr2s39se3xrj0, an Android Nostr client, closes a three-release sequence with media fixes, clearer Health Connect permission handling, source-name caching, and dedicated engagement filters for NIP-22 root-scope replies. The release also includes translation and package-metadata updates.</p><h3>11:11 LibreNostr 0.5.17 routes feeds through author write relays</h3><p><a href="https://primal.net/e/c118efbe649823a3258a6e7663f4d8b52195adbde0481019183792eb5274afd4">LibreNostr 0.5.17</a>, a relay-first Android client, now directs feed queries to the NIP-65 write relays of followed authors and defers interaction-count queries until notes enter view. Earlier work in the same release sequence limits concurrent relay queries and closes each relay subscription as soon as that relay answers, reducing self-inflicted request rejection during refreshes.</p><h3>12:07 Voca 1.2.0 improves speech cancellation and recovery</h3><p><a href="https://njump.me/nevent1qqsfcc5zel49t5zt96ufndumrzc2vzhrk7e2rnwq579gcs8yd9cn4pcflqxt3">Voca 1.2.0</a> nostr:npub17h9fn2ny0lycg7kmvxmw6gqdnv2epya9h9excnjw9wvml87nyw8sqy3hpu, an offline-oriented Android text-to-speech reader that can fetch and verify Nostr content, adds distinct cancellation and rendering behavior plus recovery for slow or unreliable speech engines after the 1.0 launch covered in issue #38. It also adds opt-in diagnostics sent with a fresh one-time Nostr key through a NIP-17 private message, with large reports encrypted locally before upload.</p><h3>13:01 Postr 1.1.1 adds dictation and publication recovery</h3><p><a href="https://njump.me/nevent1qqszw3dsskfz3u7pqxn4r5ytslrj0e3u26et90rpy9997vtfw3qkr6g9g0f03">Postr 1.1.1</a> nostr:npub1qwkd5wzftcxquuhtkcg0xn9ed7evksluuppf7qdmdh34ywe9uncs5uqfvl, a focused Android kind <code>1</code> composer, adds dictation and caret-aware mention handling after the launch covered in issue #37. The preceding 1.1.0 release also improves publication recovery by retrying the same signed event after ambiguous outcomes, preventing recovery from creating a duplicate note.</p><h3>13:47 earthly 0.1.10 repairs map sanitization and authoring</h3><p><a href="https://github.com/zeSchlausKwab/earthly/releases/tag/v0.1.10">earthly v0.1.10</a> nostr:npub1dmmh0futyszl4445mv4xrygkgsgj8vpu79yx3qyy9qxmz4pemtzqlqmc87, a collaborative Nostr map editor, materially changes map and story authoring while fixing a critical MapLibre attribution-sanitizer flaw through a MapLibre GL JS upgrade. The release also improves WebGL 2 compatibility messaging, mobile controls, geometry editing, selection, and map-presentation controls.</p><h3>14:20 Routstrd 0.4.10 tightens Nostr request routing</h3><p><a href="https://github.com/Routstr/routstrd/releases/tag/v0.4.10">Routstrd v0.4.10</a> nostr:npub130mznv74rxs032peqym6g3wqavh472623mt3z5w73xq9r6qqdufs7ql29s replaces a stale stored provider list with the list returned by live discovery. The preceding v0.4.9 release added manual and scheduled client refresh controls, named npubs in the CLI, and graceful daemon restarts that wait for active requests. Together, the releases make provider selection and refresh behavior more explicit for operators of the Nostr-routed service.</p><h3>14:53 Whistle 1.9.1 instruments background recovery</h3><p><a href="https://primal.net/e/bb3aae325f707b04dffd3b0b4a2d0c48022999fef7a793be3503b4c53e37eba4">Whistle 1.9.1</a>, an encrypted group location-sharing application built on Nostr, MLS, and Marmot Protocol, adds device-lifecycle instrumentation for iOS background recovery. Version 1.9.0 also introduces per-group sharing pauses and per-group last-event diagnostics, making a stalled group easier to distinguish from a healthy application-wide connection.</p><h3>15:28 nostr-wot-extension 0.7.0 encrypts wallet cache data</h3><p><a href="https://github.com/nostr-wot/nostr-wot-extension/releases/tag/v0.7.0">nostr-wot-extension v0.7.0</a> (maintainer Leon Acosta: nostr:npub1gxdhmu9swqduwhr6zptjy4ya693zp3ql28nemy4hd97kuufyrqdqwe5zfk), a browser extension that manages Nostr identities, signs events, and initiates Lightning payments, encrypts wallet and payment cache data and strengthens vault and account isolation. It also addresses NWC and wallet behavior, payment compatibility, request approvals, account management, backup imports, relay handling, accessibility, and local event decryption.</p><h3>16:01 Lightning.Pub 0.0.41 improves publication recovery</h3><p><a href="https://github.com/shocknet/Lightning.Pub/releases/tag/v0.0.41">Lightning.Pub v0.0.41</a> adds relay URL, timing, socket-state, and DNS details to Nostr publication failures. It also retries liquidity-provider startup calls, removes abandoned callbacks, and withholds invoice routing until a successful balance response proves the provider is ready. Operators now get a clearer split between relay-connectivity failures and backend-readiness failures.</p><h3>16:38 Gittr 1.0.0 advances NIP-34 collaboration</h3><p><a href="https://github.com/arbadacarbaYK/gittr/releases/tag/v1.0.0">Gittr v1.0.0</a>, a client for Nostr-based Git collaboration, advances NIP-34 clone-source handling, issue and discussion state, mobile usability, and interoperability. The v1.0.0 tag follows v0.3.0 and v0.3.1 from earlier this week, giving integrators a stable version marker for the release sequence.</p><h3>17:10 GitWorkshop 4.1.0 makes NIP-34 drafts recoverable</h3><p><a href="https://njump.me/nevent1qqswf45vw8y5metnu8tc2fge0lr7sy8nmuk264kryrd45wqles5kfvqqrtwl3">GitWorkshop 4.1.0</a> (maintainer: nostr:npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr), a Nostr-native client for NIP-34 issues, pull requests, code review, and repository browsing, adds account-scoped local drafts that survive refreshes and browser restarts. It also adds bounded recovery and explicit retry controls across Git reads, relay discovery, repository state, pull-request history, uploads, and release metadata while keeping signing and payment retries manual.</p><h3>17:48 ngit-ci 0.1.1 publishes signed CI coordination</h3><p><a href="https://njump.me/nevent1qqs2y0p5nxkfqsrqguth3hd4wmmel4p2te8q906ex748q35ug79e6eg9hms4s">ngit-ci 0.1.1</a>, a self-hosted coordinator for the proposed NIP-C1 Nostr CI protocol, is its first release published through Nostr. It covers signed workflow coordination, container or microVM execution, logs and artifacts, encrypted repository secrets, NIP-34 maintainer authorization, and signed publication of build results.</p><h3>18:22 pakstr 0.21.1 advances Nostr application packaging</h3><p><a href="https://git.nostrdev.com/stuff/pakstr/releases/tag/v0.21.1">pakstr v0.21.1</a> continues a five-release sequence for Nostr application packaging and app-shell behavior. NostrAppShell references point to this same pakstr release series, so the package and alias describe one shipped change.</p><h3>18:46 @elisym/cli 0.30.0 coordinates agent and delegation packages</h3><p><a href="https://github.com/elisymlabs/elisym/releases/tag/%40elisym/cli%400.30.0">@elisym/cli 0.30.0</a> concludes a coordinated CLI, SDK, and MCP release for Nostr-oriented agent delegation. Delegated jobs now wait for completion instead of sleeping for a fixed interval, and the application avoids paying the same delegation capability once per job. Teams using more than one package should keep CLI 0.30.0, SDK 0.36.0, and MCP 0.26.0 on the matched release line.</p><h3>19:15 Hashtree 0.2.150 advances hash-tree synchronization</h3><p><a href="https://github.com/mmalmi/hashtree/releases/tag/v0.2.150">Hashtree v0.2.150</a> (organization Sirius Business Ltd: nostr:npub1xdhnr9mrv47kkrn95k6cwecearydeh8e895990n3acntwvmgk2dsdeeycm) closes a six-release sequence with Android-safe locking for the embedded social graph. Earlier releases in the sequence keep Nostr subscriptions open briefly after an empty EOSE so delayed signed roots can arrive, select the newest valid root for the exact author and tree, and recover retained FIPS routes after transit outages. The result is more predictable mutable-root discovery and synchronization across relays, embedded clients, and intermittent network paths.</p><h3>19:56 nostr-relay 0.0.266 improves shared-database operation</h3><p><a href="https://github.com/mattn/nostr-relay/releases/tag/v0.0.266">nostr-relay v0.0.266</a> (maintainer Yasuhiro Matsumoto (mattn): nostr:npub1937vv2nf06360qn9y8el6d8sevnndy7tuh5nzre4gj05xc32tnwqauhaj6), a Nostr relay built on the relayer framework, advances shared-database and Redis behavior across six releases. This work is especially relevant to operators running more than one relay process against common persistence or notification infrastructure.</p><h3>20:21 fips-tcp 0.2.2 implements FIPS over TCP</h3><p><a href="https://github.com/mmalmi/fips-tcp/releases/tag/fips-tcp-v0.2.2">fips-tcp v0.2.2</a> repairs missing segments after a timed-out flight as acknowledgments advance. Small writes lost during a transit outage recover together instead of waiting through a growing timeout for every segment, while the Rust and TypeScript implementations preserve identical wire bytes, retry bounds, receive-window checks, sequence wrapping, and RTT sampling.</p><h3>20:57 Nenya marketplace library</h3><p><a href="https://github.com/Erya-Labs/Nenya">Nenya</a> is a new library for a non-custodial Nostr marketplace focused on commissioned digital media with Bitcoin settlement. The repository is pre-release, so its event and settlement interfaces may still change.</p><h3>21:18 GitHub-to-Nostr CI bridging</h3><p><a href="https://github.com/felixfelix-bot/gh-ngit-ci-bridge">gh-ngit-ci-bridge</a> is an early bridge that watches GitHub commits associated with configured identities and turns them into signed Nostr build evidence for NIP-34 workflows. The repository is pre-release, and its integration contract may still change.</p><h3>21:45 noscall encrypts voice attachments</h3><p><a href="https://github.com/sanah9/noscall/commit/3f0b9ef7cf0fbc6e0dced58240c32bb84ed6fea4">noscall’s encrypted voice-attachment commit</a> adds a concrete privacy feature for voice communication. The source-verified change supports encrypted voice attachments, reducing the need to expose recorded media as plaintext when attaching it to a call or messaging flow.</p><h3>22:03 relayer restores notifier fan-out across processes</h3><p><a href="https://github.com/fiatjaf/relayer/pull/167">relayer pull request #167</a> has merged a notifier fix for deployments where several relay processes share one database. The patch restores live fan-out across those processes, addressing the case where an event persisted successfully but connected clients on another process did not receive the corresponding live notification.</p><h3>22:20 Trackstr maps media through dedicated event kinds</h3><p><a href="https://github.com/besoeasy/Trackstr">Trackstr</a> is an unreleased, open-source Nostr media database for discovering and tracking movies, music, television, and other media. Its current design uses event kinds <code>35400</code> through <code>35402</code>, providing a reviewable schema and implementation surface. The kinds remain project-defined and may change before a release.</p><h3>22:55 NIP-A3 clarifies payment-type ambiguity</h3><p><a href="https://nostrcompass.org/en/topics/nip-a3/">NIP-A3 (Payment Targets)</a> standardizes typed payment targets in <code>["payto", "<type>", "<address>"]</code> tags on kind <code>10133</code> events. The merged <a href="https://github.com/nostr-protocol/nips/pull/2463">payment-type clarification</a> adds <code>bitcoincash</code> and <code>tron</code> to the documented type list and clarifies rendering: clients use a type-specific URI scheme when one exists, otherwise they fall back to <code>payto://<type>/<address></code>.</p><h3>23:19 NIP-CD proposes addressable slash commands</h3><p>The open <a href="https://github.com/nostr-protocol/nips/pull/2462">NIP-CD slash-command proposal</a> defines addressable kind <code>31992</code> events whose <code>command</code>, <code>title</code>, <code>description</code>, <code>arg</code>, scope, and ignore tags advertise executable commands. Invocations begin at the first byte of an event's plaintext content, can target one executor by npub, and deliberately require no special client support. The draft also defines positional argument types and scope filters by event kind, relay, author, or tag; none of this is merged protocol behavior yet.</p><h3>23:58 NIP-90 proposes expiring DVM heartbeat events</h3><p><a href="https://nostrcompass.org/en/topics/nip-90/">NIP-90 (Data Vending Machines)</a> defines job requests, results, and feedback for services that perform work over Nostr. An open <a href="https://github.com/nostr-protocol/nips/pull/2465">DVM heartbeat proposal</a> adds optional kind <code>11998</code> events that should carry an <code>expiration</code> tag so clients can distinguish a live machine from a stale NIP-89 announcement. The heartbeat sits outside the NIP-90 job-kind range, lets relays discard expired or superseded heartbeats, and leaves existing DVM flows unchanged when a service does not emit it.</p><h3>24:26 NIP-73 proposes podcast-medium filters</h3><p><a href="https://nostrcompass.org/en/topics/nip-73/">NIP-73 (External Content IDs)</a> standardizes <code>i</code> tags for external identifiers and <code>k</code> tags for their categories. The open draft <a href="https://github.com/nostr-protocol/nips/pull/2468">podcast-medium proposal</a> adds optional <code>podcast:medium:music</code> and <code>podcast:medium:podcast</code> category tags so clients can filter notes by the medium declared in a podcast RSS feed. An absent category continues to imply a podcast feed, though clients should resolve the RSS source when they need to confirm its medium.</p><h3>24:58 NIP-F5 proposes permissioned FIPS transport for web apps</h3><p>The open <a href="https://github.com/nostr-protocol/nips/pull/2469">NIP-F5 browser-transport proposal</a> defines an optional <code>window.fipsTransport</code> API through which a Nostr web application can request user-approved HTTP or WebSocket access to a FIPS-addressed relay, Blossom server, Git service, or other private endpoint. The host binds each grant to the requesting web origin and target while keeping transport separate from Nostr signing, identity, and service authorization. The proposal also requires explicit consent and scoped permissions, but its address forms and browser contract remain draft behavior.</p><h3>25:38 Marmot clarifies KeyPackage relay discovery</h3><p><a href="https://nostrcompass.org/en/topics/marmot/">Marmot</a> carries MLS group state over Nostr events. The open <a href="https://github.com/marmot-protocol/marmot/pull/422">KeyPackage relay-discovery clarification</a> documents the current sequence: publish kind <code>10002</code> relay metadata, fetch the recipient's kind <code>30443</code> KeyPackage from write-capable or unmarked destinations, then use kind <code>10050</code> separately to find the recipient's Welcome inbox. It also states that read-only NIP-65 entries are not KeyPackage destinations and that the removed kind <code>10051</code> list is no longer a discovery step.</p><h3>26:44 Marmot proposes encrypted group reports and shared moderation</h3><p>The open <a href="https://github.com/marmot-protocol/marmot/pull/423">Marmot moderation specification</a> proposes unsigned inner events carried by the protocol's existing encrypted group transport. Kind <code>1984</code> would report a specific message revision, kind <code>1985</code> would let administrators dismiss referenced reports without removing the content, and kind <code>4891</code> would let an authenticated administrator remove a message and its revisions. The proposal also defines deduplication, shared review visibility, ordering, retention, and authority rules, while keeping author deletion on kind <code>5</code> and host-application interfaces outside the wire contract.</p><h3>27:49 NWC adds payment lookup and BOLT12 records</h3><p><a href="https://nostrcompass.org/en/topics/nip-47/">Nostr Wallet Connect</a> lets applications control a wallet through encrypted requests and responses over Nostr. Covered previously as an open proposal, its payment-lookup work has now merged into the repository. The merged <a href="https://github.com/nostr-wallet-connect/nwc/pull/5"><code>lookup_payment</code> and BOLT12 specification</a> defines payment lookup by transaction ID, invoice, payment hash, or payment-type-specific selectors, and adds draft, optional BOLT12 payment records and states.</p><h3>28:30 NWC adds client-initiated connections</h3><p>The merged <a href="https://github.com/nostr-wallet-connect/nwc/pull/3">client-initiated connection flow</a> lets a client generate the connection secret, direct the user through HTTP confirmation or Nostr authorization, negotiate required and optional permissions, and receive the approved connection details. The change gives NWC clients and wallets a repository-hosted draft definition for creating a connection from the client side.</p><h3>29:02 NIP-23: Long-form Content</h3><p><a href="https://nostrcompass.org/en/topics/nip-23/">NIP-23 (Long-form Content)</a> standardizes long-form content on Nostr using addressable kind <code>30023</code> events, as defined in the <a href="https://github.com/nostr-protocol/nips/blob/master/23.md">canonical specification</a>. Publishers gain an editable article identity while kind <code>1</code> remains the short-note format.</p><h3>32:39 NIP-92: Media Attachments Metadata</h3><p><a href="https://nostrcompass.org/en/topics/nip-92/">NIP-92 (Media Attachments Metadata)</a> standardizes metadata for media attachments through <code>imeta</code> tags in the <a href="https://github.com/nostr-protocol/nips/blob/master/92.md">canonical specification</a>. It gives clients a common place to carry structured information about media associated with an event, allowing renderers and upload flows to exchange more than an unadorned media URL.</p> Originally published by [Nostr Compass](https://nostrcompass.org/)