Nostr WoT

Nostr ecosystem directory

Discover Nostr projects, their status and the people building them.

Curated content · English

Explore the Nostr ecosystem

Discover projects, their current status and the people behind them. Inclusion in this directory does not imply a Nostr WoT integration or endorsement.

Directory checked: . Expand a project to inspect its evidence. Unknown means status could not be verified.

Fortnightly new-project roundup

The planned editorial cadence is every two weeks, covering new projects and notable updates. Browse the blog for published articles and the newsroom for industry reporting.

6 of 6 projects

Social clientActive

Damus

Nostr social client for iPhone, iPad and macOS.

People, status & sources for Damus

Status evidence: Checked 2026-09-08: repository is not archived; reviewed maintenance commit dated 2026-09-08. Active describes observed development, not availability, stability or security. Founder credit is explicit on the official team page and corroborated by the README Awards section.

Last checked: . Status reflects the cited evidence at that time.

Social clientActive

Amethyst

Nostr client with Android and desktop installation paths documented in its official README.

People, status & sources for Amethyst

Status evidence: Checked 2026-09-22: repository is not archived; reviewed published release v1.16.0 dated 2026-09-17. Active describes observed development, not availability, stability or security. Android and desktop feature parity was not tested.

Latest recorded update: · Amethyst v1.16.0 adds BOLT12 payment paths and a personal fitness dashboard

Last checked: . Status reflects the cited evidence at that time.

Social clientActive

Primal

Nostr client project with a web app for custom feeds and an Android app; this profile links the web repository and separately tracks the Android release.

People, status & sources for Primal

Status evidence: Repository unarchived when checked; reviewed web maintenance commit dated 2026-08-13 and Android release 3.5.27 published 2026-09-03. Active describes observed development, not availability, stability or security. Founder and maintainer roles have not yet been verified for this directory. Android release changes do not imply web or iOS feature parity.

People

Founder: not verified.

Latest recorded update: · Primal Android 3.5.27: signer identity checks and NWC authentication hardening

Last checked: . Status reflects the cited evidence at that time.

Social clientActive

Coracle

Nostr web client documenting relay management, customizable feeds and Web of Trust moderation.

People, status & sources for Coracle

Status evidence: Checked 2026-09-08: repository is not archived; reviewed maintenance commit dated 2026-09-07. Active describes observed development, not availability, stability or security. Repository describes the client as experimental. Active development is not a stable-release designation.

Latest recorded update: · Coracle 0.6.35, latest release observed, outside the news window

Last checked: . Status reflects the cited evidence at that time.

SignerActive

Amber

Android Nostr event signer designed to keep signing keys in a dedicated app, with NIP-46 and NIP-55 integration documented by the project.

People, status & sources for Amber

Status evidence: Checked 2026-09-22: repository is not archived; reviewed published releases v6.6.4 and v6.6.5. Active describes observed development, not availability, stability or security. The official repository is used as the project website; no separate product domain was inferred. Maintainer is qualified from repository ownership, developer-owned continued-development statement and release work, not a single commit; no founder title verified.

Latest recorded update: · Amber v6.6.5 separates backup encryption from remembered app permissions

Last checked: . Status reflects the cited evidence at that time.

Social clientActive

Nostur

Nostr social client for Mac, iPhone and iPad; its release notes document Web of Trust controls and media discovery.

People, status & sources for Nostur

Status evidence: Checked 2026-09-08: repository is not archived; reviewed maintenance commit dated 2026-09-08. Active describes observed development, not availability, stability or security. The verified repository is nostur-com/nostur-ios-public. No surname or founder title is inferred. Maintainer is qualified from the official named support contact plus release authorship and current maintenance, not a formal title or founder claim.

People

Founder: not verified.

Latest recorded update: · Nostur 1.31.0: media discovery choices and Web of Trust controls

Last checked: . Status reflects the cited evidence at that time.

Recent ecosystem news

Selected reports from cited sources; this is not a complete incident or industry record.

  • Date:

    Amber v6.6.5 separates backup encryption from remembered app permissions

    Summary & evidence for Amber v6.6.5 separates backup encryption from remembered app permissions

    Release notes say kind 30078 backups now use a dedicated HKDF-derived key outside the NIP-44 derive-key namespace, so apps with remembered nip44_decrypt permission cannot read backup payloads containing per-app NIP-46 secrets and local keys. Legacy restore remains available until a later publish overwrites the old backup.

  • Date:

    Amethyst v1.16.0 adds BOLT12 payment paths and a personal fitness dashboard

    Summary & evidence for Amethyst v1.16.0 adds BOLT12 payment paths and a personal fitness dashboard

    The published release includes BOLT12 offers in profile payments and the zap picker with BOLT11 fallback on refused offers, plus a personal Health Connect dashboard. Downloadable Android and desktop artifacts are attached; feature behavior was not independently tested.

  • Date:

    Amber v6.6.4 fixes a Tor startup clearnet race

    Summary & evidence for Amber v6.6.4 fixes a Tor startup clearnet race

    Release notes say profile fetches and startup callbacks could contact relays directly before the Tor setting finished loading. The same release bounds Tor bootstrap retries and restores relay connections when the daemon returns. No exploitation claim is made.

  • Date:

    relayer v2.2.19 adds a union path for overlapping COUNT filters

    Summary & evidence for relayer v2.2.19 adds a union path for overlapping COUNT filters

    The release diff adds FiltersCounter.CountEventsFilters for multiple filters. Exact union counting depends on the storage backend implementing that interface; older backends still sum individual counts.

  • Date:

    Amber v6.6.1 fixes permission parsing and rejected request matching

    Summary & evidence for Amber v6.6.1 fixes permission parsing and rejected request matching

    Release notes describe handling permissions without a kind field and returning request IDs with rejected signer requests so callers can match responses.

  • Date:

    NIP-01 clarifies live subscriptions with limit zero

    Summary & evidence for NIP-01 clarifies live subscriptions with limit zero

    The merged diff says limit: 0 MUST skip stored events, still send EOSE after initial queries, and keep the subscription active for newly received matching events.

  • Date:

    Primal Android 3.5.27 hardens signer and NWC request handling

    Summary & evidence for Primal Android 3.5.27 hardens signer and NWC request handling

    Release notes state that local signer requests with a mismatched signing identity are rejected and incoming Nostr Wallet Connect requests receive authentication hardening before processing. No exploitation claim is made.

  • Date:

    NIP-78 adds owner authentication guidance for app data

    Summary & evidence for NIP-78 adds owner authentication guidance for app data

    The merged text covers both kinds 78 and 30078: relays SHOULD require NIP-42 AUTH before accepting or serving them and SHOULD serve them only to the authenticated author. A specification change does not establish deployed enforcement.

  • Date:

    NIP-84 adds structured highlight sources

    Summary & evidence for NIP-84 adds structured highlight sources

    The merged diff permits NIP-73 i tags for structured sources and r tags containing URLs or text. It also changes quote-highlight rendering from MUST to SHOULD.

  • Date:

    NIP-67 adds an auth hint to EOSE

    Summary & evidence for NIP-67 adds an auth hint to EOSE

    The merged NIP-42 and NIP-67 changes allow an auth hint when authentication may reveal additional results; the relay MUST send its AUTH challenge before the hinted EOSE.

  • Date:

    Amber v6.6.0 adds permission pre-approval controls

    Summary & evidence for Amber v6.6.0 adds permission pre-approval controls

    Release notes add individual permission pre-approval under manual approval policy, a prompt for NIP-46 connections while the kill switch is enabled, and biometric authentication before changing the biometrics setting.

  • Date:

    NIP-A3 payment targets revised after the initial merge

    Summary & evidence for NIP-A3 payment targets revised after the initial merge

    Following the August 26 merge, the August 27 commit changes the payto tag to type and address, marks the NIP draft and optional, and allows network-specific URI schemes with payto as fallback. This summary follows the revision, not the superseded initial instructions.

  • Commit date:

    strfry 1.1.2 tagged code documents a WebSocket memory DoS fix

    Summary & evidence for strfry 1.1.2 tagged code documents a WebSocket memory DoS fix

    The tagged changelog lists a WebSocket fragment memory DoS fix, a reused negentropy subscription ID crash fix and a reconnect fix. Date is the tagged commit date; the release API returns 404 and lightweight-tag creation time was not established.

    Date basis: Tagged commit; a commit date, not a verified release date.

  • Date:

    Nostur 1.31.0 adds media discovery choices

    Summary & evidence for Nostur 1.31.0 adds media discovery choices

    Release notes describe choosing followed people, Web of Trust or selected relays for Divine, Photos and Yaks discovery, an On/Off Web of Trust control, and hiding out-of-network replies in nested threads. Behavior was not independently tested.

Security reports

Selected reports from cited sources; this is not a complete incident or industry record.

  • HardeningDate:

    Amber v6.6.5: dedicated encryption boundary for relay backups

    Summary & evidence for Amber v6.6.5: dedicated encryption boundary for relay backups

    Maintainer release notes describe moving kind 30078 backups to a dedicated HKDF-derived key outside NIP-44 app permissions. This is classified as hardening; the source does not report observed exploitation.

    Coverage: Current

  • Privacy fixDate:

    Amber v6.6.4: Tor startup clearnet race fixed

    Summary & evidence for Amber v6.6.4: Tor startup clearnet race fixed

    Maintainer release notes state that startup network activity could reach relays directly before the Tor preference loaded. This is a documented privacy fix, not evidence of an exploited incident.

    Coverage: Current

  • HardeningDate:

    Primal Android 3.5.27: signer identity and NWC authentication hardening

    Summary & evidence for Primal Android 3.5.27: signer identity and NWC authentication hardening

    Maintainer release notes report identity-mismatch rejection and authentication hardening. They do not establish a compromised account, stolen funds or exploitation.

    Coverage: Current

  • Protocol guidanceDate:

    NIP-78: authentication guidance for private app data

    Summary & evidence for NIP-78: authentication guidance for private app data

    Protocol guidance uses SHOULD for authentication and owner-only serving of kinds 78 and 30078. This is neither an incident report nor proof that a relay enforces the guidance.

    Coverage: Current

  • HardeningDate:

    Amber v6.6.0: biometric setting change requires authentication

    Summary & evidence for Amber v6.6.0: biometric setting change requires authentication

    Release notes describe biometric authentication before toggling the biometrics setting. Listed as hardening, with no claim of observed exploitation.

    Coverage: Current

  • Vulnerability fixCommit date:

    strfry 1.1.2: documented memory DoS fix

    Summary & evidence for strfry 1.1.2: documented memory DoS fix

    Tagged changelog identifies the vulnerability fix; the upstream diff adds a check on accumulated WebSocket fragment-buffer size. Reviewed sources do not establish exploitation or a victim incident.

    Coverage: Current

    Date basis: Tagged commit; a commit date, not a verified release date.

  • AdvisoryDate:

    Baseline: Amber advisories and v6.5.0 fixes predate this fortnight

    Summary & evidence for Baseline: Amber advisories and v6.5.0 fixes predate this fortnight

    Four published advisories cover relay-auth authorization, NIP-46 replay protection, plaintext connection-secret storage and defense-in-depth items. Advisory ranges identify versions <= 6.4.0; patched_versions fields are null. Version 6.5.0 release notes explicitly list corresponding fixes. These are disclosures and reported fixes, not confirmed exploited incidents.

    Coverage: Baseline

Building with Nostr WoT?

If your project uses Web of Trust, let us know and we'll add it here.