Audio

Nostr Compass Podcast #41

Nostr Compass Podcast #41

About this episode

<p>Max and Sam discuss FIPS mesh tools, private messaging, Nostr application releases, relay operations, custom emoji, and video events this week.</p><p>Guests: nostr:npub1klkk3vrzme455yh9rl2jshq7rc8dpegj3ndf82c3ks2sk40dxt7qulx3vt nostr:npub1yzfm42rzr3dj2h50flpvdl0uzrv22kv2y4ghve804w5xqu6lzqcqkyfxu5</p><p><a href="https://nostrcompass.org/en/newsletters/2026-09-23-newsletter/">Newsletter 41</a> · <a href="https://gitworkshop.dev/npub1wav4fae3gyfy3xj298kxj2mj8phavz7vavps34przq02j7w902qq902923/relay.ngit.dev/nostr-compass-android">Nostr Compass Android source</a></p><h3>0:00 Welcome and Nostr Compass Android app</h3><p>Max opens the asynchronous podcast and introduces the <a href="https://gitworkshop.dev/npub1wav4fae3gyfy3xj298kxj2mj8phavz7vavps34przq02j7w902qq902923/relay.ngit.dev/nostr-compass-android">Nostr Compass Android app</a>, which brings the newsletter, podcasts and voice-note contributions together.</p><h3>0:47 fips2go 0.7.0 keeps the mesh connected through bootstrap failures</h3><p><a href="https://github.com/fr34aky/fips2go">fips2go</a> is an Android client that lets selected applications reach peers and services over the FIPS encrypted mesh. The new <a href="https://github.com/fr34aky/fips2go/releases/tag/v0.7.0">0.7.0 release</a> connects to three regional bootstrap peers by default instead of relying on one. It can also retry a configured peer at Nostr-advertised endpoints when its static address changes.</p><h3>1:43 fips-initramfs opens encrypted roots over FIPS before boot</h3><p><a href="https://github.com/jmcorgan/fips-initramfs">fips-initramfs</a> is a Linux initramfs package that starts a FIPS mesh node before normal boot so an operator can remotely open a LUKS-encrypted root through its npub-addressed node. The user-submitted <a href="https://github.com/jmcorgan/fips-initramfs/releases/tag/v0.1.0">0.1.0 release</a>, published September 6, packages the mesh client, SSH access, and passphrase-entry scripts for systems that need unattended or remote encrypted-root startup.</p><h3>2:53 Grain 0.8.0-rc4 turns relay health into an operator dashboard</h3><p><a href="https://github.com/0ceanSlim/grain">Grain</a> is a self-hosted Nostr relay with an integrated reference client and administration interface. <a href="https://github.com/0ceanSlim/grain/releases/tag/v0.8.0-rc4">Version 0.8.0-rc4</a> adds a live vitals panel for event volume, connections, uptime, storage, memory, and writer health, plus per-kind storage charts and reorganized access, policy, and retention controls.</p><h3>3:18 Marmot Protocol 0.10.4 makes local sends durable</h3><p><a href="https://github.com/marmot-protocol/mdk">Marmot Protocol&#x27;s MDK</a> is an SDK for MLS-encrypted group messaging whose transport and discovery run over Nostr. <a href="https://github.com/marmot-protocol/mdk/releases/tag/v0.10.4">Version 0.10.4</a> persists local sends before network completion, lowers draft and pending-message latency, prevents repeated automatic attachment downloads, and exposes retention state in chat-list previews.</p><h3>4:19 MintRadar makes Cashu mints easier to compare</h3><p><a href="https://mintradar.org">MintRadar</a> is a privacy-focused Cashu dashboard that uses Nostr to discover mints and bind community reviews to signed identities. Its <a href="https://github.com/hroomnik007/MintRadar">current source</a> adds persistent NIP-87 mint announcements, same-operator detection from NUT-06 pubkeys, shareable comparison URLs, and Nostr <code>naddr</code> deep links.</p><h3>4:52 Nostr WoT Oracle 0.3.1 makes trust queries restart-safe</h3><p><a href="https://github.com/nostr-wot/nostr-wot-oracle">Nostr WoT Oracle</a> (maintainer Leon Acosta: nostr:npub1gxdhmu9swqduwhr6zptjy4ya693zp3ql28nemy4hd97kuufyrqdqwe5zfk) is a server that ingests public follow and mute events and answers bounded web-of-trust path queries. <a href="https://github.com/nostr-wot/nostr-wot-oracle/releases/tag/v0.3.1">Versions 0.3.0 and 0.3.1</a> add independently persisted public mute evidence, readiness and ingestion status, revision-bound caches, deterministic replaceable-event selection, and rollback behavior that prevents unpersisted graph changes from becoming queryable.</p><h3>5:43 Nostr WoT SDK 1.0.2 compresses browser graph storage</h3><p><a href="https://github.com/nostr-wot/nostr-wot-sdk">Nostr WoT SDK</a> is a JavaScript toolkit for crawling, storing, and querying Nostr follow graphs in applications. <a href="https://github.com/nostr-wot/nostr-wot-sdk/releases/tag/nostr-wot-sdk%401.0.2">Version 1.0.2</a> adopts a graph engine that batches up to 100 authors per relay request, stores edges with compact delta encoding, reuses compatible traversals, and exposes batch distance queries.</p><h3>6:19 napplet.soy publishes small sandboxed Nostr programs</h3><p><a href="https://napplet.soy">napplet.soy</a> is a web playground and creator toolkit for building, publishing, playing, inspecting, and remixing small sandboxed Nostr programs called napplets. NIP-34 defines signed Nostr events for Git repository discovery and collaboration. The <a href="https://github.com/zeSchlausKwab/napplet-soy/releases/tag/soyli-v0.18.2">soyLI 0.18.2 release</a> follows the project&#x27;s September launch with signed listings, Blossom-hosted assets, Git and NIP-34 source references, and relay-discovered manifests.</p><h3>7:10 RelayKit installs a self-hosted Nostr stack</h3><p><a href="https://relayk.it">RelayKit</a> is a one-command installer for a self-hosted Nostr stack that can include relays, Blossom media, nsites, Git services, and notifications. RelayKit now packages a broader stack than the browser relay-discovery client covered in April; its <a href="https://github.com/samthomson/relaykit">current source repository</a> documents the new operator-focused deployment surface.</p><h3>10:15 Threshold Sessions turns coding transcripts into private training data</h3><p><a href="https://gitworkshop.dev/npub17m2ual3pdjvhd8yc6a3m8snzjsgnmtl26hwen48ne937qgyjyshs2zgvse/relay.ngit.dev/threshold">Threshold Sessions</a> is a command-line tool that converts AI coding sessions into normalized, redacted, and encrypted training-data epochs. Its repository supports Codex, Claude Code, Cursor, OpenCode, and pi transcripts, stores encrypted artifacts on Blossom, and publishes signed references through Nostr.</p><h3>10:55 White Noise Android 2026.9.21 improves encrypted-chat reliability and sharing</h3><p><a href="https://github.com/marmot-protocol/whitenoise-android/releases/tag/android-v2026.9.21">White Noise Android</a> is a Nostr-based messenger for private Marmot-encrypted group conversations. Its September 21 release improves message delivery, voice dictation, text-to-speech, conversation navigation, account switching, and AMOLED appearance. It also adds shareable profile and invite QR cards and group actions from profiles.</p><h3>12:40 Nostr Mail Client 0.16.0 adds per-recipient delivery choices</h3><p><a href="https://github.com/nogringo/nostr-mail-client">Nostr Mail Client</a> (maintainer nogringo: nostr:npub1kg4sdvz3l4fr99n2jdz2vdxe2mpacva87hkdetv76ywacsfq5leqquw5te) is a web, desktop, and Android mail client that exchanges messages through Nostr relays while supporting conventional email delivery. <a href="https://github.com/nogringo/nostr-mail-client/releases/tag/v0.16.0">Version 0.16.0</a> lets a sender choose SMTP or Nostr delivery for each recipient and strips location, capture time, and device metadata from photos and videos before upload.</p><h3>13:29 Amber 6.6.5 separates backup encryption from app permissions</h3><p><a href="https://github.com/greenart7c3/Amber">Amber</a> (maintainer: nostr:npub1w4uswmv6lu9yel005l3qgheysmr7tk9uvwluddznju3nuxalevvs2d0jr5) is an Android signer that keeps Nostr private keys outside the applications requesting signatures or encryption. NIP-44 standardizes encrypted payloads between Nostr keys, while NIP-46 lets an application request signing and encryption from a remote signer over relays. <a href="https://github.com/greenart7c3/Amber/releases/tag/v6.6.5">Version 6.6.5</a> encrypts application backups with a dedicated key derived from the account key, preventing an application with remembered NIP-44 decryption permission from reading backup payloads that contain local keys or per-app NIP-46 secrets.</p><h3>14:00 Amethyst 1.16.0 hardens Blossom signing and adds BOLT12 offers</h3><p><a href="https://github.com/vitorpamplona/amethyst">Amethyst</a> nostr:npub142gywvjkq0dv6nupggyn2euhx4nduwc7yz5f24ah9rpmunr2s39se3xrj0 is an Android Nostr client with media, wallet, and signer integrations. <a href="https://github.com/vitorpamplona/amethyst/releases/tag/v1.16.0">Version 1.16.0</a> fixes fast Blossom read authorization so concurrent media requests share one in-flight signer operation and recheck the token cache before asking for another signature. The tagged release also restores standard padded Base64 for Blossom auth tokens.</p><h3>14:46 Alby Extension 3.15.0 hardens website-initiated requests</h3><p><a href="https://github.com/getAlby/lightning-browser-extension">Alby Extension</a> nostr:npub1getal6ykt05fsz5nqu4uld09nfj3y3qxmv8crys4aeut53unfvlqr80nfm is a browser wallet and Nostr signer that grants websites scoped Lightning and signing capabilities. <a href="https://github.com/getAlby/lightning-browser-extension/releases/tag/v3.15.0">Version 3.15.0</a> blocks website-supplied LNURLs from local or private network addresses, requires cross-host LNURL-auth confirmation, and removes remembered approval for raw Schnorr-signing methods.</p><h3>15:28 LaWallet NWC 2.7.1 unifies zap receipts across wallets</h3><p><a href="https://github.com/lawalletio/lawallet-nwc">LaWallet NWC</a> nostr:npub1ek4262k6nv3l9axh403w2e66pzl2pqhhnjrhgv2wpzx2akak285scxv4pd is an open-source Lightning wallet service that exposes accounts to applications through Nostr Wallet Connect. NIP-57 standardizes signed Lightning zap requests and settlement receipts for Nostr profiles and events. <a href="https://github.com/lawalletio/lawallet-nwc/releases/tag/v2.7.0">Version 2.7.0</a> decouples that receipt publication from wallet-specific settlement paths so every supported NWC wallet can emit zap receipts, then <a href="https://github.com/lawalletio/lawallet-nwc/releases/tag/v2.7.1">2.7.1</a> brings receive and activity screens onto the same receipt flow as sends.</p><h3>15:55 NoorNote 1.6.0–1.7.0 adds calendars and booking</h3><p><a href="https://github.com/77elements/noornote">NoorNote</a> (maintainer: nostr:npub175nul9cvufswwsnpy99lvyhg7ad9nkccxhkhusznxfkr7e0zxthql9g6w0) is a Nostr notes application with optional productivity modules and local reminders. <a href="https://github.com/77elements/noornote/releases/tag/v1.6.0">Version 1.6.0</a> adds public and encrypted calendar events, month, week, and list views, Android reminders, and interactive timeline cards for shared events.</p><h3>16:22 Citrine 3.2.0 bounds relay-aggregator memory</h3><p><a href="https://github.com/greenart7c3/Citrine">Citrine</a> is an Android Nostr relay that gives other applications a local event store and relay interface. <a href="https://github.com/greenart7c3/Citrine/releases/tag/v3.2.0">Version 3.2.0</a> streams matching events in batches, caps aggregator fan-out at 200 relays, and bounds caches to prevent large queries from exhausting memory.</p><h3>16:44 Wisp 1.2.4 routes threads through inbox relays</h3><p><a href="https://github.com/barrydeen/wisp">Wisp</a> (maintainer: nostr:npub1utx00neqgqln72j22kej3ux7803c2k986henvvha4thuwfkper4s7r50e8) is a privacy-oriented Nostr client with built-in Cashu and Lightning wallet support. NIP-22 defines generic kind <code>1111</code> comments that can reply to many kinds of Nostr content. <a href="https://github.com/barrydeen/wisp/releases/tag/v1.2.4">Version 1.2.4</a> sends thread and notification reads only to inbox relays, treats those comments as replies, and lets users withdraw their full wallet balance on chain.</p><h3>17:14 nostr-wot-extension 0.8.3 adds scoped NWC connections</h3><p><a href="https://github.com/nostr-wot/nostr-wot-extension">nostr-wot-extension</a> is a browser signer and identity extension with wallet payments and local web-of-trust analysis. <a href="https://github.com/nostr-wot/nostr-wot-extension/releases/tag/v0.8.0">Version 0.8.0</a> restores its experimental web-of-trust API as a menu-only opt-in with local, remote, and hybrid query modes, scalable graph synchronization, mute-aware scoring, and per-account storage controls.</p><h3>18:32 pakstr 0.22.0–0.24.0 adds Android signer handoff</h3><p><a href="https://git.nostrdev.com/stuff/pakstr">pakstr</a> packages web applications with native Nostr capabilities. Last week&#x27;s issue covered its 0.21.x packaging sequence. The new <a href="https://git.nostrdev.com/stuff/pakstr/releases/tag/v0.22.0">0.22.0 release</a> adds NIP-55 signing through the NIP-46 bunker, letting an Android application hand signing requests to an external signer.</p><h3>19:18 Nail 0.2.2 makes mail attachments fail soft</h3><p><a href="https://github.com/formstr-hq/nail">Nail</a> nostr:npub1qu7dsd44275lms4x9snnwvnnmgx926nsppmr7lcw9dlj36n4fltqgs7p98 is a bridge and application that carries Nostr messages into email workflows. <a href="https://github.com/formstr-hq/nail/releases/tag/v0.2.2">Version 0.2.2</a> retries a message without attachments when a relay refuses the attachment payload, adds a size ceiling to prevent bridge restarts, and changes the default bridge relay.</p><h3>19:45 Mostro CLI 0.16.2 removes its legacy chat transport</h3><p><a href="https://github.com/MostroP2P/mostro-cli">Mostro CLI</a> nostr:npub1m0str0d7z2ww8rdh20t2n9lx520xjwhaq24p68umqp06wwrwtsnqen40un is a terminal client for coordinating peer-to-peer Bitcoin trades through Mostro&#x27;s Nostr protocol. <a href="https://github.com/MostroP2P/mostro-cli/releases/tag/v0.16.2">Version 0.16.2</a> removes the version-one gift-wrap dual-read and dual-write path, migrates peer chat to the current envelope, and lets a trader reach the solver through dispute chat.</p><h3>20:17 Dart NDK dev.4–dev.5 adds signed app updates and hardens relay delivery</h3><p><a href="https://github.com/relaystr/ndk">Dart NDK</a> (maintainer: nostr:npub1xpuz4qerklyck9evtg40wgrthq5rce2mumwuuygnxcg6q02lz9ms275ams) is a Dart client library for relay connections, signing, caching, wallet operations, and Nostr application state. NIP-82 standardizes signed application-release metadata and downloadable artifacts. <a href="https://github.com/relaystr/ndk/releases/tag/v0.10.0-dev.4">Version 0.10.0-dev.4</a> adds NIP-82 application-update support; <a href="https://github.com/relaystr/ndk/releases/tag/v0.10.0-dev.5">dev.5</a> makes Cashu quote recovery resumable and lets a broadcast declare the identity to which it may be attributed.</p><h3>20:49 BitBlik 0.11.0 brings disputes into the app</h3><p><a href="https://github.com/bit-blik/bitblik">BitBlik</a> nostr:npub1k3g092rlzvn7nftz3jte9pkx63zp705nh78r6hjpjm55fjg7r2cqx8stj3 is a mobile peer-to-peer Bitcoin trading client that coordinates orders and chat over Nostr. <a href="https://github.com/bit-blik/bitblik/releases/tag/v0.11.0">Version 0.11.0</a> adds coordinator dispute chat, BOLT12 payouts where supported, Android self-updates sourced from NIP-82 release events, and wallet backup and recovery fixes.</p><h3>21:11 Scramble 0.7.2 changes MLS engines and offers two Android views</h3><p><a href="https://github.com/DavidGershony/Scramble">Scramble</a> is a Nostr-based encrypted group-chat application. Its <a href="https://github.com/DavidGershony/Scramble/releases/tag/v0.7.0">0.7.0 release</a> replaces the former MLS engine with Dark Matter, restores encryption at rest for group state, and prevents Android cloud backup of the profile database. The migration has an important limit: groups created in 0.6.x do **not** appear after upgrading, although the account key, contacts, relays, and signer pairing remain.</p><h3>22:19 Morganite 0.0.5 makes onion Blossom media seekable</h3><p><a href="https://github.com/greenart7c3/Morganite">Morganite</a> is an Android Blossom media cache for Nostr clients. <a href="https://github.com/greenart7c3/Morganite/releases/tag/v0.0.5">Version 0.0.5</a> fetches blobs from Tor <code>.onion</code> Blossom servers with Tor-aware retries and honors HTTP Range requests on a cache miss. A player can seek into an uncached video while Morganite fills the full cache in the background instead of storing only disjoint requested slices.</p><h3>22:43 Bitcredit 0.5.16 recovers stalled Nostr bill events</h3><p><a href="https://github.com/BitcreditProtocol/Bitcredit-Core">Bitcredit E-Bills</a> nostr:npub1eajvs8x67vmzsnwaf9ltfgt59e6acmeztx9shduewvfgwftx8ahsagcd93 carries bill, company, and identity chains through Nostr events. <a href="https://github.com/BitcreditProtocol/Bitcredit-Core/releases/tag/v0.5.16">Version 0.5.16</a> repairs event-signature serialization compatibility after its Nostr 0.45 dependency upgrade, exposes failed resend-queue entries for inspection and requeue, and resynchronizes missing chain metadata before retrying a block publication. Those changes target both upgraded-data compatibility and messages that would otherwise remain stuck.</p><h3>23:24 fips-ts 0.0.43 protects concurrent FIPS sessions</h3><p><a href="https://github.com/mmalmi/fips-ts">fips-ts</a> (maintainer: nostr:npub1g53mukxnjkcmr94fhryzkqutdz2ukq4ks0gvy5af25rgmwsl4ngq43drvk) supplies the shared TypeScript FIPS mesh runtime used by compatible clients. Its <a href="https://github.com/mmalmi/fips-ts/releases/tag/runtime-v0.0.43">runtime 0.0.43 release</a> preserves an authenticated identity when concurrent setup or an aliased WebRTC transport hands a session over, while rejecting a different identity. It also prevents canceled negotiations and late callbacks from replacing a working connection.</p><h3>23:59 Bookshelf 0.1.25 makes signed book reviews editable</h3><p><a href="https://github.com/decent-newsroom/bookshelf-app">Bookshelf</a> (organization Decent Newsroom: nostr:npub1ez09adke4vy8udk3y2skwst8q5chjgqzym9lpq4u58zf96zcl7kqyry2lz) is a Nostr-connected Android reader with community book ratings and private highlights. <a href="https://github.com/decent-newsroom/bookshelf-app/releases/tag/v0.1.25">Version 0.1.25</a> lets readers revise their signed rating and written review through a durable outbox. The app displays cached ratings immediately, refreshes them online, and replaces older revisions by the newest event for the same book and author.</p><h3>24:34 Cordn 0.5.0 queues encrypted messages offline</h3><p><a href="https://github.com/Cordn-msg/cordn-web">Cordn</a> (maintainer: nostr:npub1atv4akyv986nswm4f87zdspfgehzgsva82l5jsd2k3dzgrtzpagssl84q8) is an encrypted Nostr group-chat client. <a href="https://github.com/Cordn-msg/cordn-web/releases/tag/v0.5.0">Version 0.5.0</a> queues text sends in a durable offline outbox, makes failed entries terminal until a successful confirmation sweep, and resumes coordinator chats in order. It also checks a signer&#x27;s NIP-44 capability before offering an encrypted action, surfacing unsupported signers instead of failing silently.</p><h3>25:00 21Meetup 1.6.6 restores multi-hop trust paths</h3><p><a href="https://github.com/louisthecat86/Einundzwanzig-Meetup-App">21Meetup</a> nostr:npub1rl4wlgapxcapk0p3242kqcw7az584sjxgssuwh38u2gatk0cwewsudjz85 issues Nostr-backed attendance badges for in-person events. <a href="https://github.com/louisthecat86/Einundzwanzig-Meetup-App/releases/tag/v1.6.6">Version 1.6.6</a> restores second- and third-degree trust paths by fetching contacts&#x27; meetup records in bounded stages. Failed badge publications can be retried, and a send counts as successful only after a relay acknowledges it.</p><h3>25:29 TWENTY ONE Companion 1.13.0 explains public Nostr RSVPs</h3><p><a href="https://github.com/HolgerHatGarKeineNode/twenty-one-companion">TWENTY ONE Companion</a> nostr:npub1pt0kw36ue3w2g4haxq3wgm6a2fhtptmzsjlc2j2vphtcgle72qesgpjyc6 combines Nostr rooms and articles with meetup listings. <a href="https://github.com/HolgerHatGarKeineNode/twenty-one-companion/releases/tag/v1.13.0">Version 1.13.0</a> saves pinned rooms and articles to relays, showing a pin as local until a relay confirms it. Eligible meetup RSVPs are signed public Nostr events; the app warns that third-party relays may retain them even after a user declines.</p><h3>25:56 Armada 0.61.0 adds media privacy and member controls</h3><p><a href="https://github.com/soapbox-pub/armada">Armada</a> is a Nostr-based encrypted community client. <a href="https://primal.net/e/122a06dbab02d207b3aa793b0fedd06fd59d36178a7b9ae5971cfc3b7f3eb6ce">Version 0.61.0</a> adds an opt-in image proxy list so a sender&#x27;s media host need not learn a reader&#x27;s address. Staff can kick, ban, or unban a member from a profile card, and a private-channel key granted with a role now applies without a separate invite.</p><h3>26:30 Ditto 2.40.0 brings Top 8 rankings to Nostr profiles</h3><p><a href="https://gitlab.com/soapbox-pub/ditto">Ditto</a> nostr:npub10qdp2fc9ta6vraczxrcs8prqnv69fru2k6s2dj48gqjcylulmtjsg9arpj is a social client on Nostr. <a href="https://gitlab.com/soapbox-pub/ditto/-/releases/v2.40.0">Version 2.40.0</a> lets a user rank eight favorite people on their profile. Reordering stays local until Save, then the ranked list appears on the profile and its update can appear as a card in followers&#x27; feeds.</p><h3>26:53 XM Arcade 1.1.3 binds mini-app approval to one run</h3><p><a href="https://gitworkshop.dev/r/xm-arcade">XM Arcade</a> runs small games and mini-apps within a Nostr group context. <a href="https://primal.net/e/dec0edda9ff464b4b7598032318cb48e17cf496e29d05031d1f1629409039a4c">Version 1.1.3</a> binds a post approval to an opaque run token, the request, app, account, group, and channel. Expired or replayed approvals no longer authorize another mini-app run.</p><h3>27:34 Zzub 0.0.15–0.0.16 expands mobile project boards</h3><p><a href="https://primal.net/e/70c5efeea2e9314329b8951346d83ad0688b74607a108e8bc820caae545196c2">Zzub</a> is a Nostr-based project and code-review client. Its 0.0.15 release adds status columns, sorting and filtering, threaded comments, named assignees, and approve or request-changes actions to its phone boards. A built-in Git client opens source and files-changed diffs from a pull-request card, bringing the existing desktop review flow onto the phone.</p><h3>28:15 Table Mesh 0.1.0 brings Nostr game discovery to offline board games</h3><p><a href="https://primal.net/e/c5c5ad0eba413e18c10e3cd2be607e550ac818a8abaf97ccbf8fa242fbaff15f">Table Mesh 0.1.0</a> is a first Android release for playing board games across nearby phones over Bluetooth and local Wi-Fi. It includes *Mensch ärgere Dich nicht* and solo bots. A Nostr kind-7529 catalog distributes additional sandboxed game modules through Blossom, with downloaded bytes checked against their announced hashes.</p><h3>28:57 0xchat merges fixes for signing, message-authentication, and redirect flaws</h3><p><a href="https://github.com/0xchat-app/0xchat-app-main/pull/92">0xchat&#x27;s merged security PR</a> addresses four audit findings in its Nostr and Cashu application code. It limits Cashu P2PK witness signing to keys actually authorized by a lock, rejects unsealed gift-wrap contents except MLS Welcome events, accepts infrastructure host-map configuration only from the trusted server key, and requires consent before an embedded web page can call NIP-07 signing or read relay settings.</p><h3>29:17 nos2x-fox closes a PIN exposure path</h3><p><a href="https://github.com/diegogurpegui/nos2x-fox">nos2x-fox</a> is a Firefox extension that offers Nostr signing to websites. A <a href="https://github.com/diegogurpegui/nos2x-fox/pull/69">merged access-control fix</a> stops a website from asking the extension background for the cached PIN that derives its private-key encryption key. The page bridge now forwards only allowed request types, and the background rejects privileged requests unless they originate from an extension page.</p><h3>29:54 nostream publishes relay health events</h3><p><a href="https://github.com/cameri/nostream">nostream</a> is a Nostr relay implementation that also runs a relay monitor. Its <a href="https://github.com/cameri/nostream/pull/741">merged NIP-66 work</a> publishes signed relay-discovery and monitor-announcement events after a probe, giving other clients a way to find the monitor&#x27;s measurements through Nostr. <a href="https://nostrcompass.org/en/topics/nip-66/">NIP-66</a> defines relay-discovery and monitor events so relay status can be shared in a common format.</p><h3>30:24 nostter ties remote signing to the active session</h3><p><a href="https://github.com/SnowCait/nostter">nostter</a> is a web Nostr client for reading and publishing through relays. Its <a href="https://github.com/SnowCait/nostter/pull/2518">NIP-46 connection lifecycle</a> now belongs to the authenticated session&#x27;s signer, so a failed login or session reset can dispose of the remote connection instead of leaving a module-global signer behind. <a href="https://nostrcompass.org/en/topics/nip-46/">NIP-46</a> lets a client ask a separate signer to approve cryptographic operations over Nostr.</p><h3>30:43 Zap Cooking publishes image descriptions and blocks secret-key searches</h3><p><a href="https://github.com/zapcooking/frontend">Zap Cooking</a> is a Nostr recipe and long-form publishing site. Its <a href="https://github.com/zapcooking/frontend/pull/746">NIP-92 image-description work</a> lets authors write alternative text for images in notes, replies, recipes, articles, and products, then carries that text in <code>imeta</code> tags that other clients can render. <a href="https://nostrcompass.org/en/topics/nip-92/">NIP-92</a> standardizes media metadata attached to Nostr events, including image descriptions.</p><h3>31:05 Divine Mobile reconnects idle relay subscriptions</h3><p><a href="https://github.com/divinevideo/divine-mobile">Divine Mobile</a> (maintainer rabble: nostr:npub1wmr34t36fy03m8hvgl96zl3znndyzyaqhwmwdtshwmtkg03fetaqhjg240) is a short-video client that publishes and reads Nostr events. A <a href="https://github.com/divinevideo/divine-mobile/pull/9246">merged relay fix</a> reconnects after an idle timeout or remote closure, including subscriptions that only receive data and never send another request to trigger recovery. That restores a path used by direct-message inboxes and moderation labels after a connection drops.</p><h3>31:30 Conduit uploads product images through Blossom</h3><p><a href="https://github.com/Conduit-BTC/conduit-mono">Conduit</a> is a Nostr-based marketplace with merchant publishing tools. Its <a href="https://github.com/Conduit-BTC/conduit-mono/pull/503">merged image-upload work</a> lets merchants add product images from desktop or mobile through a configured Blossom server while keeping product publication separately signed. Blossom is a media-storage protocol that uses Nostr identities to authorize uploads and let applications retrieve files.</p><h3>31:52 Buzz adds authenticated relay moderation controls</h3><p><a href="https://github.com/block/buzz">Buzz</a> nostr:npub16l0ck0s5zened29dsaqtqm6z0t4fmk2mwtszw64fz7fppcnls8mss3yj9s includes a Nostr relay and community administration tools. Its <a href="https://github.com/block/buzz/pull/7302">merged relay-admin routes</a> let authorized operators list active bans and timeouts and lift them through a signed HTTP request. <a href="https://nostrcompass.org/en/topics/nip-98/">NIP-98</a> defines Nostr-event authorization for HTTP calls, allowing the relay to verify who made the administrative request.</p><h3>32:12 ContextVM SDK shortens publish waits and repairs streams</h3><p><a href="https://github.com/ContextVM/sdk">ContextVM SDK</a> nostr:npub1dvmcpmefwtnn6dctsj3728n64xhrf06p9yude77echmrkgs5zmyqw33jdm is a TypeScript toolkit for applications that exchange signed requests and streams over Nostr relays. Its <a href="https://github.com/ContextVM/sdk/pull/100">relay-pool change</a> sends an event to every connected relay but, by default, finishes the caller&#x27;s wait after the first positive acknowledgement; applications that need all acknowledgements can still request that mode. One slow relay no longer determines the normal publish wait.</p><h3>32:44 Mostro preserves an order's original creation time</h3><p><a href="https://github.com/MostroP2P/mostro">Mostro</a> is a peer-to-peer Bitcoin exchange coordinator that publishes orders over Nostr. Its <a href="https://github.com/MostroP2P/mostro/pull/971">merged kind <code>38383</code> change</a> adds a stable <code>created_at</code> tag from the order record, allowing clients to sort or age an order by when it was opened instead of by its latest status revision. <a href="https://nostrcompass.org/en/topics/nip-69/">NIP-69</a> defines the Nostr order format used by interoperable trading clients.</p><h3>33:11 Amethyst implements DECK-0003 objects and encrypted bag search</h3><p><a href="https://github.com/vitorpamplona/amethyst/pull/4186">Amethyst&#x27;s merged DECK-0003 work</a> reads and renders Simple Nostr Objects, a JSON 3D-mesh format carried in Nostr events. It supports kind <code>11333</code> avatars, kind <code>3330</code> shards, and opening encrypted kind <code>33330</code> region bags from a location hint. CLI commands parse and verify objects or calculate the bounded search needed to open a bag.</p><h3>33:59 Amethyst broadens MLS interoperability and repairs desktop group rendering</h3><p><a href="https://github.com/vitorpamplona/amethyst/pull/4187">Amethyst&#x27;s Quartz library</a> now lets callers choose an MLS group ID and omit Marmot-only required capabilities when interoperating with other MLS stacks. Separate merged changes allow <a href="https://github.com/vitorpamplona/amethyst/pull/4182">extensions supported by every group member</a>, carry <a href="https://github.com/vitorpamplona/amethyst/pull/4184">authenticated application-message data</a>, and set an optional <a href="https://github.com/vitorpamplona/amethyst/pull/4188">key-package lifetime</a>. The Marmot defaults remain unchanged; these are shared-library capabilities, not a claim that every client UI exposes them.</p><h3>34:44 nostter gates signing and private reads on real capabilities</h3><p>Continuing the session-owned NIP-46 work above, <a href="https://github.com/SnowCait/nostter/pull/2570">nostter&#x27;s merged signer migration</a> checks for an actual signer before offering write actions instead of treating every logged-in session as writable. <a href="https://github.com/SnowCait/nostter/pull/2574">Private bookmarks</a> now require NIP-04 or NIP-44 decryption capability, and <a href="https://github.com/SnowCait/nostter/pull/2576">remote-signer settings</a> require NIP-44 support. A read-only or anonymous account can still use non-writing profile actions.</p><h3>35:07 Pensieve makes archive reconciliation bounded and durable</h3><p><a href="https://github.com/andotherstuff/pensieve/pull/48">Pensieve&#x27;s archive receipt work</a> (maintainer: nostr:npub1zuuajd7u3sx8xu92yav9jwxpr839cs0kc3q6t56vd5u9q033xmhsk6c2uc) waits for actual durable event markers before declaring a reconciliation attempt complete, retaining unresolved IDs across recovery. The <a href="https://github.com/andotherstuff/pensieve/pull/49">sealing change</a> separates periodic archive durability from optional Parquet publication, and the <a href="https://github.com/andotherstuff/pensieve/pull/50">bounded inventory</a> scans sealed segments with explicit limits and a persisted cursor.</p><h3>35:28 MDK reduces repeated replay work for parked encrypted messages</h3><p><a href="https://github.com/marmot-protocol/mdk/pull/2007">MDK&#x27;s merged replay fix</a> addresses work repeated after a publish confirmation, publish failure, or group join when messages remain parked because they cannot yet be decrypted. The previous path classified each row&#x27;s lineage again and rewound group state for each row and retained anchor. The new deferred-sweep ingest path skips redundant classification and shares a group-scoped cache of historical contexts, invalidating it when canonical state changes.</p><h3>35:46 NIP-02 clarifies petnames in follow lists</h3><p><a href="https://nostrcompass.org/en/topics/nip-02/">NIP-02 (Follow List)</a> standardizes the kind <code>3</code> event that records whom an account follows and can attach a local petname to each followed key. The <a href="https://github.com/nostr-protocol/nips/pull/2472">merged petname clarification</a> allows display-safe characters while preserving the field as a user&#x27;s local label, not a globally verified name.</p><h3>36:04 NIP-86 adds clear and list methods for relay management</h3><p><a href="https://nostrcompass.org/en/topics/nip-86/">NIP-86 (Relay Management API)</a> standardizes authenticated administrative calls for banning, allowing, inspecting, and configuring a relay. <a href="https://github.com/nostr-protocol/nips/pull/2477">PR #2477</a>, merged September 23, adds methods for clearing pubkeys or events from both allow and ban lists and for listing roles, allowed events, and disallowed kinds, including behavior already present in the khatru relay framework and the go-nostr library.</p><h3>36:21 NIP-69 proposes a stable creation time for trading orders</h3><p><a href="https://nostrcompass.org/en/topics/nip-69/">NIP-69 (Peer-to-Peer Trading)</a> standardizes addressable order events that let multiple trading applications share buy and sell liquidity. <a href="https://github.com/nostr-protocol/nips/pull/2476">PR #2476</a> proposes an optional creation-time tag that stays fixed across status updates, so a returned or republished order retains its original age even when a newer event records a status change.</p><h3>36:45 NIP-A3 proposes proof of payment-address ownership</h3><p><a href="https://nostrcompass.org/en/topics/nip-a3/">NIP-A3 (Payment Targets)</a> lets an account publish portable payment addresses for multiple networks in one replaceable event. <a href="https://github.com/nostr-protocol/nips/pull/2475">PR #2475</a> proposes an optional signature made by the payment address&#x27;s own key, giving compatible address types a proof that binds the destination to the Nostr author while treating missing proofs as neutral.</p><h3>37:13 BUD-16 proposes deterministic directory manifests</h3><p><a href="https://github.com/hzrd149/blossom/pull/105">BUD-16</a> is an open Blossom proposal for grouping content-addressed blobs into named directory trees with reproducible manifest hashes. The draft defines deterministic MessagePack encoding, named links, metadata, optional encryption keys, and <code>.bdir</code> path resolution while leaving servers to store ordinary blobs.</p><h3>37:49 Marmot adds encrypted group polls</h3><p><a href="https://nostrcompass.org/en/topics/marmot/">Marmot Protocol</a> defines interoperable application events inside MLS-encrypted groups carried over Nostr. NIP-88 defines poll questions and signed response events. <a href="https://github.com/marmot-protocol/marmot/pull/425">Merged MIP work</a> recognizes those polls inside a group while keeping relay selection bound to authenticated group routing and explicitly stating that they are not anonymous or election-grade.</p><h3>38:28 Marmot merges group reports and admin deletion</h3><p><a href="https://github.com/marmot-protocol/marmot/pull/423">Marmot group moderation</a> defines encrypted report, dismissal, and administrator-deletion events that converge under the group&#x27;s authenticated state. The proposal covered last week has now merged, fixing a status transition that lets implementations align report review and message removal against the accepted specification.</p><h3>38:59 NWC-13 proposes connection budget queries</h3><p><a href="https://nostrcompass.org/en/topics/nip-47/">Nostr Wallet Connect</a> lets an application request narrowly scoped wallet operations through encrypted Nostr events. <a href="https://github.com/nostr-wallet-connect/nwc/pull/7">NWC-13</a> proposes a separate <code>get_budget</code> permission and response so an application can inspect used, total, and renewal allowance without receiving permission to read the wallet&#x27;s balance.</p><h3>39:31 NIP-30: Custom Emoji</h3><p><a href="https://nostrcompass.org/en/topics/nip-30/">NIP-30 (Custom Emoji)</a> standardizes how a signed event maps readable <code>:shortcodes:</code> to image URLs, with an optional address that points to a reusable emoji set. The <a href="https://github.com/nostr-protocol/nips/blob/master/30.md">specification</a> permits letters, numbers, hyphens, and underscore (<code>_</code>) characters in a shortcode and applies the mapping to profiles, short text notes, comments, reactions, and live activities. NIP-51 defines public and private list formats, including the kind <code>30030</code> parameterized replaceable events that hold named emoji sets.</p><h3>41:54 NIP-71: Video Events</h3><p><a href="https://nostrcompass.org/en/topics/nip-71/">NIP-71 (Video Events)</a> standardizes Nostr events for horizontal and short-form video, including playback metadata, alternate files, captions, chapters, participants, and imported-source provenance. The <a href="https://github.com/nostr-protocol/nips/blob/master/71.md">canonical specification</a> assigns kinds <code>21</code> and <code>22</code> to immutable horizontal and portrait video posts, while kinds <code>34235</code> and <code>34236</code> use a <code>d</code> tag to create addressable videos whose metadata can be updated under a stable coordinate. Each <code>imeta</code> tag describes one playable variant with a URL and media type plus optional dimensions, hash, preview image, fallback, service, bitrate, and duration.</p><h3>43:39 Closing and Nostr Compass app</h3><p>Max thanks the builders and contributors, and invites listeners to join the asynchronous podcast through the Nostr Compass Android app.</p> Originally published by [Nostr Compass](https://nostrcompass.org/)