Astraea
com.example.epochs
LWB lwb89@cosanostr.com A offline-first, end-to-end encrypted calendar app that syncs privately over Nostr, on your terms.
First release: Jul 19, 2026, 7 total releases.
Most recent release: Sep 4, 2026.
Appears in 3 app stacks.
6,300 sats / 3 zaps received in the past year.
Sats Received
Underlying data available via MCP: app_zaps, app_releases.
Zap Count
Underlying data available via MCP: app_zaps, app_releases.
Releases
- Sep 4, 2026 1.0.0# Astraea 1.0.0 π **First stable release.** Astraea is an offline-first, privacy-first calendar. Events live on your device, are end-to-end encrypted with your own Nostr key (NIP-44), and sync through relays you choose yourself β no account, no server of ours. Astraea has carried a `0.x` number since the first commit while the storage format, the Nostr wire contract and the D-Bus API settled. They have now been stable across several releases, the mobile app and the Linux service agree on one contract, and the interface has been rebuilt to match. `1.0.0` says that out loud: **breaking any of those is now a major-version decision, not a patch note.** ---
Moreβ¦
## π¨ A rebuilt interface Every screen has been redrawn on a new shared design system (`lib/widgets/astraea_ui.dart`) β one set of colour, spacing, radius and motion tokens, a single themed surface treatment, and a theme builder that both the light and dark palettes derive from. - **A real week timeline.** The week view is no longer the month grid reused at a different range; it lays events out against the hours of the day. - **Bottom navigation** for switching between month, week, day and list, replacing the segmented control at the top of the screen. - **Calendar, event details, the event editor, onboarding and settings** all follow the same layout language: grouped translucent surfaces, consistent section headers, larger touch targets, a calmer type scale. Your accent colour and your light/dark preference still drive the whole theme β the revamp changes *how* they are applied, not *whether* they are respected. And every transition collapses to zero duration when the platform's **reduce motion** accessibility setting is on. --- ## π¦ Android: pick your APK This release ships **split per ABI**, so the download is roughly a third of the size of a universal build. | Your device | File | Size | | --- | --- | --- | | **Virtually every phone from ~2017 on** | `astraea-1.0.0-arm64-v8a.apk` | 24 MB | | Older / low-end 32-bit ARM | `astraea-1.0.0-armeabi-v7a.apk` | 22 MB | | Emulator, ChromeOS, x86 tablet | `astraea-1.0.0-x86_64.apk` | 26 MB | **If you're not sure, take `arm64-v8a`.** Installing the wrong one fails cleanly at install time β it will not half-install. Minimum Android 7.0 (API 24). ## π§ Linux (Debian / Ubuntu / Pop!_OS) Download the `.deb` files plus `install.sh` into the same folder, then: ```bash chmod +x install.sh sudo ./install.sh # add --no-extension on KDE/COSMIC ``` The packages stay separate on purpose (`astraea-service`, `astraea-desktop`, `astraea-gnome-shell-extension`) so you can skip the GNOME extension and upgrade each part on its own. Passing them all to a single `apt install` is what makes the dependency order correct. Or, without cloning the repo: ```bash curl -fsSL https://raw.githubusercontent.com/Lwb89dev/astraea/v1.0.0/scripts/install-release.sh | sh ``` --- ## What 1.0.0 already includes Carried in from the `0.4.x` line, in case you are coming from `0.3.1`: - **NIP-46 remote signer ("bunker") login on Android and Linux.** Paste a `bunker://` string and your private key never touches the device β Astraea keeps only a throwaway client key your signer can revoke. On Linux it also gives the background service unattended signing with no key material on the machine. - **Sync on launch**, so your agenda is current before you touch anything. - **Real previews for the Android home-screen widgets** in the widget picker. - A hardening round: a total memory budget on relay responses, bounded and back-pressured reads on the local socket, a cap on the configured relay list, and no account public keys in device logs. See [`CHANGELOG.md`](https://github.com/Lwb89dev/astraea/blob/v1.0.0/CHANGELOG.md) for the full history. --- ## π Checksums ``` c02b45f312fae28410cb53305dbf9284b06340900e37a2169eeb899506899714 astraea-1.0.0-arm64-v8a.apk 3ba28bd50f5091762a7d6ba5a789cd142f04004d0c232bb9b1c10d5410f476da astraea-1.0.0-armeabi-v7a.apk 61b89f0b43642cc300235d02f446ffd494ab84600c446c46eecccb469685c9f0 astraea-1.0.0-x86_64.apk c2a958a8f53cac840346817a52be9c022f52a746fbfb4dface0dc14a06e5ad0f astraea-service_1.0.0_amd64.deb 0e1a12573d23e59c38725436356025227824cd646303b66541005dd79260eceb astraea-desktop_1.0.0_amd64.deb 3059b74cecb8d74fb48eec2cd0f571464c1342e13676f15d2d761191eb81cfe9 astraea-gnome-shell-extension_1.0.0_all.deb 0bcdc10d97df4e7b233b04533bfe2095a22827b2bd77c59d10e4d4ac38c6adde astraea-all_1.0.0_all.deb ``` All three APKs are signed with the same project release key as every previous release: ``` SHA-256 E2:A9:EA:50:E0:BB:39:40:06:BD:A3:A0:10:AA:FD:C2:38:ED:06:9E:7A:A2:91:61:95:F2:55:2F:5F:7E:C0:18 ``` --- **Licence:** GPL-3.0-or-later. Audit it, fork it, break it. - Aug 10, 2026 0.4.1Astraea is an offline-first, privacy-first calendar. Events live on your device, are end-to-end encrypted with your own Nostr key (NIP-44), and sync through relays you pick yourself β no account, no server of ours. This release supersedes the unpublished 0.4.0 and carries everything since 0.3.1. --- ## β¨ Sign in without ever handing over your key **NIP-46 remote signer ("bunker") login, on Android *and* Linux.**
Moreβ¦
Paste a `bunker://` connection string and the account private key never reaches the device. Astraea stores only a throwaway client key that your signer authorizes by public key β and can revoke at any time. On Linux this is a login **and** unattended background signing, with no key material on the machine at all. It replaces the old advice to provision a local delegated key: ```bash astraea-service auth connect-bunker # paste bunker://β¦ on stdin astraea-service auth status # signer: remote_nip46, state: ready ``` In the apps it's a "Sign in with a remote signer" field in Settings β Account (and in first-run onboarding on Android). Every reply from the signer is checked before it is trusted: kind, author, NIP-01 event id and Schnorr signature β and for a signed event, that **every field still matches what Astraea asked to have signed**. > Implemented on top of the already-audited NIP-44 and relay-pool code rather than pulling in a NIP-46 client crate, whose dependency subtree compiles deprecated NIP-04 AES-CBC in as a feature-flag side effect. Only the JSON envelope handling is ours. See [`docs/authentication.md`](https://github.com/Lwb89dev/astraea/blob/v0.4.1/docs/authentication.md). ## π Sync when the app opens Every launch now reconciles with your relays before you touch anything, on mobile and through the Linux service alike. Amber (NIP-55) sessions stay manual on purpose β signing there is an intent into another app, so an automatic cycle would throw you into Amber on every launch. ## πΌοΈ Android widgets finally preview properly The widget picker showed an empty placeholder grid instead of the widget. The three providers declared no preview at all, so the picker fell back to inflating the live layout β whose list/grid has no data source outside the app. Each widget now ships a `previewLayout` (API 31+) with static sample content, plus a rendered `previewImage` for API 24β30. The sample data is fictional on purpose: binding your real calendar into a preview would put your event titles in the launcher's widget picker. --- ## π Security & hardening | Area | Change | | --- | --- | | **Relay responses** | Added a **total** memory budget. The existing per-event and per-count caps multiplied out to hundreds of megabytes a hostile relay could make the app hold. | | **Kairos local socket** | Now bounds its read buffer *while reading* instead of after the fact β a peer that never sent a newline could previously be buffered without limit. Adds a connection cap and per-connection backpressure. | | **Relay list** | Capped at 16 on both the service and the mobile store, on read as well as write. Every relay is an open socket, a publish fan-out target, and another operator learning your pubkey and IP. | | **Sign-out** | Now also clears the cached profile and on-disk avatar, drops the live remote-signer connection, and closes bunker sockets. | | **Logs** | No longer record the account public key, deep-link targets or full avatar URLs β each ties a device log to a specific identity. | | **External signers** | Signed events from *any* external signer are verified field by field against the request, not only checked for a valid signature. Previously this held for Amber only. | ## π Fixed - Overlapping sync cycles: the start-up sync racing a manual tap could run two full pull-merge-push passes at once over the same store. - The automatic sync is a start-up action rather than a "calendar screen mounted" action, so returning to the calendar no longer re-triggers it. - Version numbers agree again across `pubspec.yaml`, both Rust crates, AppStream and the RPM/Arch packaging β 0.3.1 had bumped `pubspec.yaml` alone. ## π§Ή Removed - The placeholder `RemoteSigner` backend that reported "not configured in this build" for every operation. --- ## π¦ Install ### Android Download **`astraea-0.4.1.apk`** below and install it. Minimum Android 7.0 (API 24). ### Linux (Debian / Ubuntu / Pop!\_OS) Download the `.deb` files plus `install.sh` into the same folder, then: ```bash chmod +x install.sh sudo ./install.sh # add --no-extension on KDE/COSMIC ``` The packages stay separate on purpose (`astraea-service`, `astraea-desktop`, `astraea-gnome-shell-extension`) so you can skip the GNOME extension and upgrade each part on its own. Passing them all to one `apt install` is what makes the dependency order correct. Or, without cloning the repo: ```bash curl -fsSL https://raw.githubusercontent.com/Lwb89dev/astraea/v0.4.1/scripts/install-release.sh | sh ``` --- ## π Checksums Verify before installing: ``` bfa55b04d4ba50bf1bb034ad7ea1c6d04462850cf52313585616b5f2df378bbb astraea-0.4.1.apk 23f17e46a46a52bcd4d0a8d674e8d01aaa2d1249cccfe4ccf950b8b2de400b43 astraea-service_0.4.1_amd64.deb ed61eceb39c55a88a0ca46604a1c13f6b03666a0a4f0cf9f9ae859af1538970e astraea-desktop_0.4.1_amd64.deb fe5b09ade229fb730b39f45f3b92444b41240dba3f901d371a0715b8da0413ff astraea-gnome-shell-extension_0.4.1_all.deb 1e63a5f1e2f9ab991921cc384ec3b246a995fb1a58282de3ff790cf1e47223c2 astraea-all_0.4.1_all.deb ``` The APK is signed with the project release key: ``` SHA-256 E2:A9:EA:50:E0:BB:39:40:06:BD:A3:A0:10:AA:FD:C2:38:ED:06:9E:7A:A2:91:61:95:F2:55:2F:5F:7E:C0:18 ``` --- **Full changelog:** [`CHANGELOG.md`](https://github.com/Lwb89dev/astraea/blob/v0.4.1/CHANGELOG.md) Β· **Licence:** GPL-3.0-or-later - Jul 28, 2026 0.3.1## [0.3.1] - 2026-07-28 ### Added - Local Kairos β Astraea task bridge on Android and Linux, alongside the existing encrypted Nostr mirror. - Versioned Kairos hand-off contract with idempotent upserts, deletions and notification preferences. - Linux per-user Unix-socket integration for task delivery, with deep-link fallback for desktop integrations.
Moreβ¦
- Linux service-owned reminder scheduler with freedesktop notifications. ### Fixed - Android day, week and month widgets now refresh their cached data reliably and include overlapping and zero-duration events such as Kairos tasks. - Calendar day boundaries now remain correct across daylight-saving changes. - Kairos tasks are shown on the correct day and receive a due notification by default when no reminder is supplied. - NIP-07 login on Linux no longer reports a false missing-extension error when nos2x injects `window.nostr` late or through its browser-extension origin. - NIP-07 login discovery remains retryable instead of locking the page after a short startup timeout. - Jul 28, 2026 0.3.0## [0.3.0] - 2026-07-28 ### Added - Multi-day events now draw as a continuous bar across every day they cover in the month view, instead of a dot on the first day only. - Selectable accent color β navy blue, bitcoin orange, or nostr purple β in Settings > Appearance, applied to the app theme and to home-screen widgets. Widgets can also be themed individually, chosen once when a widget is placed.
Moreβ¦
- Four more suggested relays (`relay.primal.net`, `relay.nostr.band`, `nostr.mom`, `relay.snort.social`) alongside the existing two, for redundancy when one is slow or unreachable. - `scripts/install-release.sh`: downloads and installs the Linux `.deb` packages straight from a GitHub release, for anyone who'd rather not build from source. Verifies against the release's checksums when published, and always asks before running `sudo` β never escalates on its own. - Verified and documented compatibility with Kairos's Astraea calendar mirror (a sibling task manager that can publish a dated task as an Astraea event over the same account's relays). ### Fixed - Home-screen widget theme picker now uses the platform's own Material-You-aware dialog style instead of a legacy Holo theme. - Zero-duration events (a single point in time rather than a start/end span) landing exactly on a day boundary β e.g. a task due at midnight β could vanish from the day agenda, upcoming list, and month view entirely. Affects any zero-duration event, most notably tasks mirrored in from Kairos. - Android widget PREVIOUS/NEXT navigation could go years beyond any cached data for the week and month widgets; the navigable range now matches the actual cache window per widget type. - A workaround for a Lawnchair-beta launcher quirk that could revert a widget's header text right after a correct update. - Saving or deleting an event no longer waits for every configured relay to respond before returning control to the UI β publishing now happens in the background, as the app's offline-first design always intended. - The NIP-07 browser login page could report "no extension found" for a genuinely installed extension, due to a detection race on page load. - A `ws://` (personal/self-hosted) relay saved through Settings would fail every sync and publish, unconditionally β relay validation now uses a single shared check instead of two independently-maintained copies that had drifted apart. ### Security - Sync no longer risks publishing (and thereby decrypt-exposing) one account's event under a different account's identity when switching accounts; the shared pull cursor is also reset on a genuine account change instead of silently resuming from another account's sync progress. - Relay responses and NIP-05 lookups are now read with a hard memory budget enforced while streaming, instead of buffering an entire (potentially attacker-influenced) response before any size check ran. - Incoming attendee invites now bound field lengths and reject implausible event spans before being trusted enough for a notification or local storage. - A remote signer (NIP-46, not yet implemented) no longer reports itself as "ready" when every operation it offers is actually unavailable. - Jul 27, 2026 0.2.0## [0.2.0] - 2026-07-27 ### Added - Full Linux desktop integration: a background Rust daemon (`astraea-service`) exposed over D-Bus, a Flutter desktop app backed by it, a GNOME Shell extension, and a COSMIC applet scaffold. - Attendee invites: invite another Astraea account (by npub, hex public key, or NIP-05) to an event. The invitee can accept or decline, and both sides get a desktop notification of the outcome.
Moreβ¦
- Full app localization into all 27 EU official languages plus Chinese, Japanese and Russian, with a language picker in Settings. - Desktop Settings fully wired to the background service: browser (NIP-07) sign-in, relay management, live sync status β no more dead UI on Linux. - Support for personal/self-hosted relays over unencrypted transport (`ws://`), alongside the existing `wss://`. - Linux packaging: modular .deb packages, RPM spec, Arch PKGBUILD, Flatpak manifest, relocatable tarball, and a one-command `astraea-all` metapackage installer. ### Fixed - Home-screen widget "next" navigation getting stuck on some month/week/day transitions. ### Security - NIP-44 encryption extended to point-to-point messages between two different accounts (attendee invites) β distinct from, and never reusing, the self-encryption used for cross-device calendar sync. - SSRF-hardened NIP-05 identifier resolution: no redirect-following, bounded timeout and response size, shape validated before any network call. - Jul 19, 2026 0.1.1## [0.1.1] - 2026-07-19 ### Fixed - Crash on launch in release builds: R8 code shrinking broke WorkManager's reflective startup database lookup (a transitive dependency pulled in by the home-screen widgets), causing every release install to crash before the app UI could load.
- Jul 19, 2026 0.1.0# Astraea v0.1.0 β First Public Release π Astraea is a private, offline-first calendar with optional end-to-end encrypted synchronization over Nostr. Your calendar works locally without an account, an Internet connection, or a central Astraea server. Network synchronization is entirely optional and remains under your control. ## β¨ Highlights - **Offline-first calendar** β create, edit and manage events entirely on your device. - **Multiple calendar views** β month, week, day and upcoming events.
Moreβ¦
- **Recurring events** β daily, weekly, monthly and yearly recurrence. - **Local reminders** β notifications scheduled directly by the operating system. - **Timezone-aware events** β UTC storage with device or custom timezone display. - **Light and dark themes** β including a privacy-oriented dark default. ## β‘ Encrypted Nostr Sync - Optional multi-device synchronization over Nostr. - Calendar contents encrypted using **NIP-44** before leaving the device. - Support for Nostr kind `30078` parameterized replaceable events. - Encrypted tombstones and **NIP-09** deletion requests. - Local key generation or existing `nsec`/hex key import. - Support for the **Amber NIP-55 external signer** on Android. - Configurable personal relay for additional backup redundancy. > [!NOTE] > Relay operators cannot read event titles, descriptions, locations or reminder details. As with all network services, they may still observe metadata such as IP addresses, public keys, timestamps and event sizes. ## π Relay Onboarding The new first-launch onboarding lets you choose exactly which Nostr relays Astraea should use. Astraea suggests: - `wss://nos.lol` - `wss://relay.damus.io` These are only suggestions. You can enable, disable or replace them with your preferred relays at any time. ## π¦ Import, Export and Backup - Password-protected encrypted exports. - **PBKDF2-HMAC-SHA256** key derivation. - **AES-256-GCM** authenticated encryption. - Standard iCalendar `.ics` import and export. - Local-first storage using Hive. ## π± Android Widgets Add your calendar directly to the Android home screen with: - Daily agenda widget - Weekly agenda widget - Monthly agenda widget ## π Privacy by Design - No Astraea account required. - No central Astraea backend. - No analytics or advertising SDKs. - No mandatory network connection. - Private Nostr keys stored through Android secure storage. - Release builds use a dedicated signing key and never fall back to debug signing. ## π² Platform Support | Platform | Status | | --- | --- | | Android | β Supported | | iOS | Not configured yet | | Desktop | Not configured yet | ## Installation Download the APK from the assets below and install it on your Android device. Android may ask you to authorize installations from your browser or file manager. Always verify that the APK was downloaded from the official Astraea repository. ## Feedback and Security This is Astraea's first public release. Bug reports and focused contributions are welcome through GitHub Issues. Please do not report security vulnerabilities publicly. Follow the private disclosure process described in [`SECURITY.md`](SECURITY.md). --- Built with Flutter and open protocols as part of the Echoes ecosystem. Thank you for trying Astraea. β¨