Tenna
pub.soapbox.tenna
Team Soapbox _@soapbox.pub An nsite browser. A home screen for the apps that live on Nostr.
Tenna is a browser for nsites — websites published to Nostr instead of to a host. There is no server to go down and no domain to expire: a site is a signed manifest listing every file by path and hash, and the files themselves are content-addressed blobs on Blossom. Tenna finds the manifest, fetches the blobs, verifies them, and serves the site to itself. The home screen is a wall of tiles, and everything on it is yours. Sites sit beside your installed apps in whatever order you drag them into, each with a channel number counted down the wall. Add them from a catalog, from the people you follow, or by pasting an naddr, an npub, a nostr: URI, or a gateway URL. Tenna holds your keys; the sites never do. Each site gets a NIP-07 `window.nostr` that proxies back to Tenna, which asks you before it signs. Permissions are remembered per site and per event kind, and revoked from the shield menu at any time. Every site runs as the top-level document of its own WebView on its own origin, so it is a real secure context — service workers, crypto.subtle, the lot — with its own task in the recents switcher. Sites can also hold push subscriptions open while closed, and take a place in the OS share sheet.
First release: Sep 10, 2026, 21 total releases.
Most recent release: Sep 27, 2026.
Appears in 3 app stacks.
0 sats / 0 zaps received in the past year.
Sats Received
Underlying data available via MCP: app_zaps, app_releases.
Zap Count
Underlying data available via MCP: app_zaps, app_releases.
Releases
- Sep 27, 2026 0.12.2On Android, a site's notifications are back in one row led by the site's own icon, which looked better than the bundle 0.12.1 put them in. A site opened from a link now shows its own icon on its notifications, and following the same link again brings the site back to the front. ### Changed - On Android, a site's notifications are back in a single row led by the site's own icon, as they were before 0.12.1. Once a site had more than one notification out, the bundle Android drew for it lost the site's icon. The
More…
row's buttons and tap belong to the newest notification, and swiping the row clears the site. ### Fixed - A site opened from a link, rather than from its tile, now has its own icon on its notifications and in the app switcher. - Following a link to a site again, after Tenna was opened by that same link, brings the site back to the front instead of doing nothing. - Sep 27, 2026 0.12.1On Android, every notification from a site can now be tapped, answered or swiped away on its own, while a site's notifications still stay together in one bundle. Opening a site from its tile no longer brings back an older version of it. ### Changed - On Android, each notification from a site is now its own row in the site's bundle, so you can tap it, answer it with its own buttons, or swipe it away without touching the others. Swiping the bundle's header still clears the
More…
whole site at once. ### Fixed - Opening a site from its tile no longer puts back an older version of it after the site has updated. Tenna also checks for updated sites whenever you come back to it. - Sep 26, 2026 0.12.0Sites can now refresh in the background: with your permission, a closed site wakes up every so often to fetch what is new. On iPhone, sites catch up with Android — they can ask where you are, save files, show their alert boxes, and open links. Asking for the camera no longer closes Tenna on iPhone. The Android app no longer contains Google Play Services. ### Added - Sites can ask to wake up every so often while closed, to fetch what is new. Tenna asks you first, with a
More…
new **Refresh in the background** permission, and taking it back stops the site straight away. A site woken this way can only put up a notification if you have also let it send notifications. On Android it runs about when the site asked, at most every fifteen minutes. On iPhone the system decides when, and it can be a good while later. - On iPhone, a site can now ask where you are. Tenna asks you first, the same way it does for the camera, and then iPhone asks whether Tenna may know. - On iPhone, a site can now save a file: you pick where it goes. - On iPhone, a site's `alert`, `confirm` and `prompt` boxes now appear, titled with the site's name. ### Removed - A site can no longer sign or decrypt while it is closed, on Android. No site used it. A site can still sign and decrypt in its own window, with the same permissions as before. ### Fixed - On iPhone, a site asking for the camera or microphone no longer closes Tenna. Neither does choosing **Take Photo** when a site asks for a file. - On iPhone, links out of a site now work. A web link opens in your browser, other kinds open the app they belong to, and a link to another site opens that site in Tenna. As on Android, a site can only do this when you tap something. - On iPhone, a site that doesn't draw around the home indicator is framed in its own colour, rather than running under it. ### Security - On iPhone, only a site's own page can ask for your signature. A frame embedded in the site from somewhere else could reach the same channel before. - The Android app no longer contains Google Play Services. Since 0.6.0 it had carried Google's sign-in and account libraries, which came in with the code that saves your key to a password manager. Tenna now uses Android's own password saving, which works with any password manager on Android 14 and up. On older phones your key is saved to a file instead, as it already was on phones without Google. - Sep 26, 2026 0.11.0
- Sep 22, 2026 0.10.2
- Sep 21, 2026 0.10.1
- Sep 21, 2026 0.10.0
- Sep 20, 2026 0.9.0
- Sep 20, 2026 0.8.2
- Sep 17, 2026 0.8.1
- Sep 17, 2026 0.8.0
- Sep 14, 2026 0.7.1
- Sep 14, 2026 0.7.0
- Sep 14, 2026 0.6.1
- Sep 13, 2026 0.6.0
- Sep 13, 2026 0.5.0
- Sep 12, 2026 0.4.0
- Sep 12, 2026 0.3.0
- Sep 11, 2026 0.2.1
- Sep 10, 2026 0.2.0
- Sep 10, 2026 0.1.0