Amber
com.greenart7c3.nostrsigner
Zapstore _@zapstore.dev Republished from GitHub / F-Droid by the Zapstore main account.
Amber is a nostr event signer for Android. It allows users to keep their nsec segregated in a single, dedicated app. The goal of Amber is to have your smartphone act as a NIP-46 signing device without any need for servers or additional hardware. "Private keys should be exposed to as few systems as possible as each system adds to the attack surface," as the rationale of said NIP states. In addition to native apps, Amber aims to support all current nostr web applications without requiring any extensions or web servers.
First release: Sep 19, 2025, 18 total releases.
Most recent release: Sep 28, 2026.
Appears in 2 app stacks.
2,100 sats / 1 zaps received in the past year.
Sats Received
Underlying data available via MCP: app_zaps, app_releases.
Zap Count
Underlying data available via MCP: app_zaps, app_releases.
Releases
- Sep 28, 2026 6.6.6# Changelog ## Amber 6.6.6 - Fix the nostrconnect parser corrupting connect-param values that contain `=` (such as base64-padded secrets): the connect response returned mangled values instead of the original secret, so NDK-based clients failed their secret check - Fix white text and icons on light-amber surfaces in dark theme (Edit Relays floating action button, add-relay icon buttons, selected filter chips on the feedback screen) - Fix the Tor/proxy status icon in the top app bar being nearly invisible in light theme — status icons now use theme-aware colors in both themes, and the relay reconnect icon matches the adjacent relay count - Feedback issues are now published to the relays advertised on Amber's repository announcement instead of a hardcoded relay, falling back to the previous behavior when the announcement can't be fetched; longer timeouts on Tor so slow relays still confirm the publish Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.6.6)
More…
If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.6.6.txt` and `manifest-v6.6.6.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.6.6.txt.sig manifest-v6.6.6.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.6.6.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md). - Sep 21, 2026 6.6.5# Changelog ## Amber 6.6.5 - Harden application backups: backup events published to relays are now encrypted with a dedicated key derived from your account key (via HKDF, outside the NIP-44 derive-key namespace) instead of your main identity key, so apps holding a remembered `nip44_decrypt` permission can no longer fetch the kind 30078 backup and read its payload, including per-app NIP-46 secrets and local keys; existing identity-encrypted backups still restore through a fallback until the next publish overwrites them - Fix the backup restore prompt never appearing after logging out and back in when backup publishing is disabled — the exact case restore exists for Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.6.5) If you like my work consider making a [donation](https://greenart7c3.com)
More…
## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.6.5.txt` and `manifest-v6.6.5.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.6.5.txt.sig manifest-v6.6.5.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.6.5.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md). - Sep 14, 2026 6.6.4## Amber 6.6.4 - Fix a clearnet leak for Tor users during the startup settings race: profile fetches and boot-time network callbacks could dial relays directly before the Tor setting finished loading - Reduce background battery drain: the connectivity safety-net tick now runs every 5 minutes instead of every 30 seconds, and the built-in Tor daemon gives up after a bounded bootstrap window instead of restarting forever (a notification lets you retry) - Relay connections now recover automatically when the built-in Tor daemon comes back, including after a manual Tor restart - Sync the relay WebSocket layer with upstream quartz: relay-initiated CLOSE frames are answered so sockets close promptly instead of lingering half-open until the ping timeout - Add sign-event labels for the Armada event kinds (presence and typing indicators, NIP-29 group management, Buzz forum kinds, webxdc app data, and more) Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.6.4)
More…
If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.6.4.txt` and `manifest-v6.6.4.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.6.4.txt.sig manifest-v6.6.4.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.6.4.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md). - Sep 9, 2026 6.6.3# Changelog ## Amber 6.6.3 - Fix the "start service on boot" setting not being respected after an app update - Fix a crash on the offline flavor caused by a `SecurityException` from WorkManager network tracking left over from an upgrade - Fix the Russian translation of the "Amber is a free and open source project" string - Fix a release build failure caused by an AGP 9.4.0 regression Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.6.3)
More…
If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.6.3.txt` and `manifest-v6.6.3.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.6.3.txt.sig manifest-v6.6.3.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.6.3.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md). - Sep 4, 2026 6.6.1# Changelog ## Amber 6.6.1 - Fix parsing of incoming permission lists when a permission has no `kind` field in its JSON, so the whole list no longer fails to load - Fix rejected signer requests not returning the request id in the result, leaving calling apps unable to match the rejection to their request - Update the default signer relays to `auth.nostr1.com`, `bucket.coracle.social`, `nrs.primal.net` and `relay.nip46.com`, and add `indexer.coracle.social` to the default indexer relays (#518) - Add missing translations for Marmot protocol event kinds Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.6.1)
More…
If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.6.1.txt` and `manifest-v6.6.1.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.6.1.txt.sig manifest-v6.6.1.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.6.1.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md). - Aug 31, 2026 6.6.0## Amber 6.6.0 - New: pre-approve individual permissions when connecting an app under the "Manually approve each permission" policy — an "Add permission" button lets you pick from the full permission catalog (searchable, including custom sign-event kinds) so those requests are approved automatically while everything else still asks - New: when a NIP-46 connect request arrives while the kill switch is enabled, Amber now asks whether to disable it so the request can be answered, and the kill switch gained a toggle in the Settings network section - Toggling the "Enable biometrics" setting now requires biometric authentication first, so the setting cannot be deactivated without authorization and broken sensors are caught before activation - Toggling "require unlocked device" now shows a progress indicator with a do-not-close warning while every stored secret is re-encrypted, instead of silently freezing - Fix the account picker not scrolling and its title not being visible - Fix a crash in profile feed subscriptions when an account is removed while its events are being processed - Trim the image and trust-score caches when the system reports memory pressure, so the 32 MB bitmap cache no longer stays fully resident while the app is in the background - Performance: cache decrypted application lists so periodic relay refreshes stop re-decrypting every application row through the Keystore (the dominant native memory user on populated accounts), and warm up timezone data off the main thread to remove a ~170 ms disk read during the Applications screen's first composition
More…
- Update Kotlin to 2.4.10, Gradle to 9.7.1, Quartz to 1.14.0 and the rest of the dependency stack Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.6.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.6.0.txt` and `manifest-v6.6.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.6.0.txt.sig manifest-v6.6.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.6.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md). - Aug 18, 2026 6.5.2# Changelog ## Amber 6.5.2 - Fix the Applications screen taking several seconds to load on populated accounts: the list no longer decrypts the encrypted `secret`/`localKey` columns it doesn't render, and the Keystore key handle is cached instead of re-fetched for every decryption - Warm the account cache at app start so the switch-accounts button lists all accounts again instead of only the current one - Fix a crash when scrolling the activity history screens caused by the same row appearing in two loaded pages at once - Debounce relay status-counter notification updates so the status notification no longer freezes on stale text during bursts of relay traffic Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.5.2)
More…
If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.5.2.txt` and `manifest-v6.5.2.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.5.2.txt.sig manifest-v6.5.2.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.5.2.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md). - Aug 14, 2026 6.5.1# Changelog ## Amber 6.5.1 - Re-encrypt NIP-46 connection secrets stored in the per-account database during Keystore key rotation, so toggling "require unlocked device for key access" no longer leaves connections undecryptable - Fix crash in EditPermission due to an invalid localKey Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.5.1) If you like my work consider making a [donation](https://greenart7c3.com)
More…
## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.5.1.txt` and `manifest-v6.5.1.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.5.1.txt.sig manifest-v6.5.1.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.5.1.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md). - Aug 14, 2026 6.5.0# Changelog ## Amber 6.5.0 - Fix relay-auth whitelist authorizing any requester (GHSA-vx4h-56qj-wcp7) - Fix NIP-46 freshness and replay protection (GHSA-h9fv-9247-3582) - Envelope-encrypt NIP-46 connection secrets at rest (GHSA-5fjp-ghh8-wch8) - Add opt-in unlocked-device requirement for Keystore key (GHSA-8844) - Authorize before decrypt in SignerProviderQuery (GHSA-8844) - Redact key material from logs and crash reports (GHSA-8844)
More…
- Set FLAG_SECURE on sensitive QR surfaces (GHSA-8844) - Warn on insecure ws:// connections to non-onion relays (GHSA-8844) - Parse unknown permission remember types as NEVER to fail closed (GHSA-8844) - Lazy-load account keys on cache miss and properly zeroize them on logout (GHSA-8844) - Update translations for new string resources - Fix CI test failures and linter violations Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.5.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.5.0.txt` and `manifest-v6.5.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.5.0.txt.sig manifest-v6.5.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.5.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md). - Aug 7, 2026 6.4.0## Amber 6.4.0 - Redesign the multi-request approval screen with explicit Approve/Deny toggles per request and per group, replacing the select-and-confirm flow, with proper error responses for denied bunker requests - Add support for 113 more event kinds with localized labels across all shipped locales, including the Concord kinds, NIP-51 git repository bookmarks and NIP-53 room presence - Add light/dark Compose previews for the multi-event approval screens - Ignore platform finalizer-watchdog TimeoutExceptions in crash reports - Fix a NegativeArraySizeException crash in relay subscriptions by guarding shared maps for concurrent access - Translate the new approval strings (approve, confirm, remember my choice for) in all supported locales - Update translations
More…
Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.4.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.4.0.txt` and `manifest-v6.4.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.4.0.txt.sig manifest-v6.4.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.4.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md). - Jul 20, 2026 6.3.0# Changelog ## Amber 6.3.0 - Group multi-request approval lists by type and kind, with collapsible groups and per-group remember and scope options - Only use the fullscreen layout when there is a single bunker request - Add support for Expert List (kind 12022) and Expert Pack (kind 32022) events - Add a privacy mode setting to disable logs and activity stats - Add a setting to disable relay trust scores - Add a restart action and live status to the built-in Tor notification
More…
- Fetch the user's NIP-65 relay list before fetching profile metadata - Remove relay.damus.io from the default relay lists - Fix the event date shown as Jan 1970 in the Show Details modals - Fix all Android Lint warnings and enforce lint in the git hooks - Upgrade Gradle to 9.6.1 and AGP to 9.3.0 - Move older release notes to per-version files under docs/changelogs - Update translations Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.3.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.3.0.txt` and `manifest-v6.3.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.3.0.txt.sig manifest-v6.3.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.3.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md). - Jul 1, 2026 6.2.3## Amber 6.2.3 - Add a configurable profile fetch interval setting with never/always options - Show a profile picture in the account switch bottom sheet - Scope profile subscriptions by the current account, driven by composables - Add error handling to bunker permission parsing - Trim the shipped languages to the curated set of locales - Set the benchmark build app name to "Amber Benchmark" - Fix a StrictMode DiskReadViolation in Coil onSuccess logging - Load the account off the main thread to fix a StrictMode keystore violation
More…
- Read account name and picture off the main thread in the account switch sheet - Avoid eager KeyPair() on the main thread in the login/signup screens - Fix the settings section header contrast in the light theme - Fix an unescaped apostrophe in the Turkish profile fetch interval string - Update translations Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.2.3) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.2.3.txt` and `manifest-v6.2.3.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.2.3.txt.sig manifest-v6.2.3.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.2.3.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. - Jun 12, 2026 6.2.1## Amber 6.2.1 - Reduce battery drain from relay reconnects and websocket pings - Drop dead relays from the subscription pool instead of only backing off reconnects - Do not wake the device when updating the relay notification - Modernize the settings screen with grouped Material 3 cards and distinct icons - Fix navigation crash when opening application permissions - Fix a crash when writing the Bunker connect screen state off the main thread - Reply with an error for invalid bunker request methods - Add NIP-46 logout method support
More…
- Add support for event kind 39701 (Public web bookmark) - Fix a per-account database connection leak by building databases atomically - Refresh app bar titles when the language changes - Update Kotlin to 2.4.0 and Gradle to 9.5.1 - Update translations Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.2.1) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.2.1.txt` and `manifest-v6.2.1.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.2.1.txt.sig manifest-v6.2.1.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.2.1.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. - Apr 15, 2026 6.0.3## Amber 6.0.3 - Fix racing condition when receiving intents - Upgrade gradle and agp - Add account index option when using seed words - Fix relay reconnection on startup if the relay is offline - Add missing periodic worker for app updates - Check for empty request ids when receiving intents Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.0.3)
More…
If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.0.3.txt` and `manifest-v6.0.3.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.0.3.txt.sig manifest-v6.0.3.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.0.3.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. - Apr 10, 2026 6.0.1## Amber 6.0.1 - Fix missing event validation when checking for app updates and profile events - Fix racing condition when receiving intents - Fix subscriptions never closing when removing an app - Remove richtext dependency - Update Quartz library to 1.08.0 - Add two new backup options, webdav and share to google drive - Implement exponential backoff for relay reconnections
More…
Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.0.1) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.0.1.txt` and `manifest-v6.0.1.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.0.1.txt.sig manifest-v6.0.1.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.0.1.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. - Mar 27, 2026 5.0.4## Amber 5.0.4 - Do not start service, tor or notifications when using the offline version - Do not re-add bunker requests when failed to send response - Better performance when receiving multiple requests - Add a 30 second timeout for profile subscriptions - Remove the tabs from the connect screen - Fix rejection not respecting the scoped encrypt/decrypt - Show alt tags when there's no translation for a event kind - use a boolean for the intent rejection
More…
- Fix the accept/reject button not showing when scanning a nostrconnect qrcode Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v5.0.4) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v5.0.4.txt` and `manifest-v5.0.4.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v5.0.4.txt.sig manifest-v5.0.4.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v5.0.4.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. - Mar 11, 2026 4.1.3## Amber 4.1.3 - Profile relays: Remove relay.nostr.band. Add user.kindpag.es, profiles.nostr1.com, directory.yabu.me - Better relay notification text - Fix relay icon when more than 10 relays - Hide icon and relay notification if not using apps that connect to relays - Change backup screen from icon buttons to text buttons to avoid confusion when using ncryptsec - Do not use strongBox when it's a mediatek device, it's breaking all the time - Use AlarmManager to start the service to see if it fixes the crash on graphene os restart app button press - Remove relay.nsec.app from defaults (it's not working properly sometimes)
More…
- Close profile subscriptions once receiving EOSE from relays - Fix icon size and themed icon - Show the account that is signing the event - Show a button to report unknown event kinds - Better relay connection management - Refactor start service - Use bottom sheet for requests instead of showing the full application - Display the "Sign as" widget in the multi event screen - Decrease the timeout of sending response to relays - Show request content in the activities screen - Client auth permissions by relay - Fix a crash when loading profile image - Do not group events when receiving multiple events Download it with [Zapstore](https://zapstore.dev/apps/naddr1qvzqqqr7pvpzqateqake4lc2fn77lflzq30jfpk8uhvtccalc66989er8cdmljceqqdkxmmd9enhyet9deshyaphvvejumn0wd68yumfvahx2usx8zmj2), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v4.1.3) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v4.1.3.txt` and `manifest-v4.1.3.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v4.1.3.txt.sig manifest-v4.1.3.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v4.1.3.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. - ## Amber 4.0.2 - Change Dockerfile to build from the local repo - Show all accounts in the backup screen - Show the backup dialog if any account needs backup - Enable gradle configuration cache - Fix migration from old version - Fix 404 link in README by @npub1lczxedq435kkzvuhf04kpxh67alqs4sa4glv24xfy6nw5tvwnwxqhwwxyr Download it with [zapstore.dev](https://zapstore.dev/download), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v4.0.2)
More…
If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v4.0.2.txt` and `manifest-v4.0.2.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v4.0.2.txt.sig manifest-v4.0.2.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v4.0.2.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.