Repository navigation
ONYX v2.0-beta
ONYX no longer depends on a central server. Accounts, messages and calls now work directly between devices over Tor.
Decentralized identity
- Your account is now a cryptographic key generated on your device, not a record on a server.
- A 12-word seed phrase is created with it. You can use it to restore your identity on a new device.
- Each identity has an Account ID (a stable identifier derived from your key) and a fingerprint that contacts can use to verify it's really you.
- New onboarding flow: create a new identity or restore one from a seed phrase, then set up your profile.
- Profiles (display name and avatar) are stored locally. They sync between your own devices through WardLink, and the most recent
Tor transport
- New
onyx_torpackage: a realtordaemon runs as a separate OS process and is controlled over the standard Tor control port. - Tor binaries are bundled for Windows, Linux and macOS. Android uses tor-android.
- All traffic to external groups and channels, and to any
.onionhost, is routed through Tor. If Tor isn't up yet, the request fails instead of silently going out directly. - Every device has its own onion address, and your messages reach all of your devices.
- New "My devices" screen, where you can unlink a device.
- New "View Circuit" dialog shows the Tor relays your traffic goes through (guard, introduction point, rendezvous point), in Simple and Advanced modes.
Contacts and requests
- Add contacts by QR code or by pasting an
xxxx.onionaddress ("Pair over Tor", "Add contact · QR"). - Contacts list with each contact's ID, onion address and shareable QR. You can remove a contact or a single paired device.
- Contact requests:
- Attach an optional comment to your request.
- Accept, decline, or decline and block.
- The sender's onion address and key fingerprint are shown.
- You get a warning when a request uses the name of an existing contact but a different key.
- Until you accept a request, the sender can't see your online status or profile, and can't call you. Messages from non-contacts aren't accepted.
- Requests sent while the other person is offline are delivered once they're online.
Message delivery
- Undelivered messages are saved on the device and resent automatically.
- New "Retry interval" setting, and a delivery status under the message ("Not online · retry #N in Xs").
- Online / offline / connecting status. You can hide your own status; in that case you stop seeing others' status as well.
- If a contact is offline, a dialog explains that the message is queued.
- Forwarding reports the result and warns when the file isn't available on the device.
Calls
- Calls over Tor, only audio.
- Built-in local TURN server tunnels WebRTC traffic over the Tor channel, so no external server is needed and neither side learns the other's IP.
- New call screen with avatar and name, Mute / Video / Speaker / End controls, and minimize / restore.
- Call history entries in chat: outgoing, incoming, missed, cancelled, declined, busy, no answer.
Interface
- New Liquid Glass settings, with General and Advanced tabs and a master toggle:
- Adjustable blur, tint, saturation, chromatic aberration, refraction, light intensity, thickness and jelly stretch.
- Confirmation dialogs when sending a file, an album or a voice message, showing name, size, type and duration.
- Multi-select delete for messages, with separate wording for "delete for both", "delete for me" and mixed selections. You can also delete several favorite chats at once.
- You can edit your display name. Empty names are rejected.
- LAN favorites sync: the sender shows a QR code, waits for the receiver to scan, and has a "Send chat" button.
- WardLink: new "Sync incoming messages" toggle.
- Sensitive actions now ask for your PIN or biometrics when app lock is enabled.
Removed
- HTTP/SOCKS5 proxy support and its settings. Tor replaces it.
- Link previews.
- Everything that depended on server accounts and server-side cache: server media cache management, deletion of the account from the server, and related UI text.