Build on Spojiti Private Messenger Core

Spojiti Private Messenger Core — the free text-messaging path, app and relay: identity from the twelve words, the prekey bundle, PQXDH, the Double Ratchet with the post-quantum ratchet, ML-DSA-65 authentication, the safety number, and the relay's registration, keys and routing with the test that proves no account column exists — is published under the GNU AGPL v3. Read it, verify it, run your own relay for the Core. The full product is not open source, by design; Independent audit in progress — expected by end of 2026, on track.

Spojiti on GitHub

Repositories

spojiti-core-app

The client half of the Core: the key tree, X3DH + ML-KEM-1024, the Double Ratchet with the ML-KEM-768 ratchet, ML-DSA-65 + Ed25519 authentication, the safety number and the on-device NIST self-tests — the free text-messaging path, exactly as the shipped app runs it.

spojiti-core-relay

The relay half of the Core: registration by public key, the prekey directory, routing of sealed envelopes by random id and deletion on delivery, with the schema and the test that proves no account column exists. A docker-compose file brings up the Core on one box.

spojiti-docs

The white paper, the protocol reference and the threat model — the same documents this site links, versioned with the Core they describe.

Security research

Report a vulnerability to spojiti@spojiti.world — the contacts and the policy are in /.well-known/security.txt (RFC 9116). You never have to tell us who you are. We answer within two working days, credit every valid report, and publish the fix and the timeline. Coordinated disclosure of 90 days; we will ask for less, never more.

Licence: GNU Affero General Public License v3.0. Run a modified relay for others and you publish your changes — so nobody can quietly operate a weakened Spojiti.