CustID

network.fbo.custr
by FBO Developments Sàrl contact@fbo.network

Your truly sovereign identities in your pocket, secured.

CustID is a mobile identity vault built on Nostr and the SISTR protocol. Governments everywhere are rolling out national e-ID — the EUDI Wallet across the EU, Switzerland's e-ID, and more. Those wallets can work well, yet your recognized identity is still issued, attested and revocable by an authority. CustID flips that: your identity simply IS your key, held on your device, and no one can take it from you. One app to hold your identities, memberships, badges and passes — offline, without Google. - Identity vault: multiple identities, keys protected by the hardware-backed Android Keystore, never held in plaintext during normal operation; moving or backing up an identity only ever exports an encrypted ncryptsec, never a raw key. - Nostr signer (NIP-46 bunker): sign for any NIP-46 compatible client remotely; your key never leaves your device. - No Google: no Firebase Cloud Messaging, no Google Play Services. Distributed via Zapstore only. - NFC challenge-response: answer access-control challenges with a tap (doors, gates, event ticketing, ...). - QR code proofs: scan or present signed proofs as an NFC fallback. - Zero-knowledge proofs: planned in the SISTR project, for privacy-preserving identity claims. 👷 MVP public beta. ⚠ Please backup your keys and don't use CustID for critical applications until a stable release is published.

First release: Jun 29, 2026, 3 total releases.

Most recent release: Aug 13, 2026.

Website Repo

Appears in 2 app stacks.

111 sats / 1 zaps received in the past year.

Sats Received

Underlying data available via MCP: app_zaps, app_releases.

Zap Count

Underlying data available via MCP: app_zaps, app_releases.

Releases

  • Aug 13, 2026 0.1.12-beta beta
    - Show each connected app's relay health directly on its card, and restore the missing connected-since date. - Keep NIP-58 badges available during relay outages, partial discovery, and offline use, while safely applying complete remote badge-list updates. - Keep each identity's relay list aligned with its latest NIP-65 update, including removals made from another Nostr client. - Make signing requests from connected apps much harder to miss: requests received in the background are kept safely, restored after an app restart, opened from the correct notification, and handled one at a time. - Protect signing requests after CustID re-locks: notification actions now require CustID to still be unlocked, and an exact request waits for biometric unlock before its review is shown. - Make new app connections more dependable: setup no longer hangs on an unavailable relay, confirms only after the connection response is delivered, and offers a clear retry when needed. - Improve the Activity Log with one clear history entry per connected-app request, including its approval or rejection and whether the response was delivered. - Restore connected-app relay connections promptly when network access returns, improving the reliability of future signing requests. - Restore the NIP-46 signing channel after Android restarts and keep its active relay subscriptions checked without adding a second background connection layer. - Show every configured relay in connected-app settings instead of only the first one.
    More…
    - Improve badge details with the issuer's name and avatar, plus simple sharing through a Nostr client or a public link. - Return to the connected-app list after saving an app's settings. - Allow newly created or imported identities to pair with a NIP-46 connected app immediately, without restarting CustID. - Make NIP-46 app pairing easier on one device: paste a Nostr Connect URL into CustID or copy a generated Bunker URL instead of scanning a QR code. - Discover new NIP-58 badge awards while CustID is active and show one illustrated, privacy-preserving notification per new award, opening the exact badge after unlock. - Refine the global Settings screen with clearer section hierarchy, a pending Tor proxy control, and fixed interface scaling on Android. - Give NIP-42 relay authentication requests their own persistent accept and reject controls, with clearly managed per-relay lists in connected-app settings.
  • Jul 16, 2026 0.1.11-beta beta
    - Fix and improve activity log display and persistence, and prevent stale NIP-46 request replays after app restarts.
  • Jun 29, 2026 0.1.10+de2f611b beta
    ## v0.1.10-beta 🎉 First public **beta** release of **CustID**. CustID is a mobile identity vault built on Nostr and the SISTR protocol. It stores multiple Nostr identities in hardware-backed secure storage, acts as a NIP-46 remote signer (bunker), and answers physical / online access challenges over NFC and QR codes. This beta is published on Zapstore (`beta` channel) and as a signed APK attached to the GitLab release. It is feature-complete for the NIP-46 signer and NFC challenge-response MVP; ZK-proof flows remain a future milestone. ## v0.1.9
    More…
    ### Battery / background performance - **Removed the native NIP-65 background keep-alive layer** in `Nip46ForegroundService`. The native service no longer opens one OkHttp WebSocket per `(profile, read-relay)` pair; only the NIP-46 sockets required for signing-request notifications are kept alive in the background. - The removed layer accounted for ~N+sum(K) extra sockets (≈3 read relays × #profiles, plus their 30 s OkHttp pings), and consumed kinds that are not used for notifications (kind:0/3/8/10002/10008/30000/30001/30008/30009 — three of which were dropped immediately by the JS ingestor). The profile / badge refresh it provided is already covered at foreground time by `refreshAllProfiles()` + `verifyBadgesAtBoot()`. - Deleted: `src/core/nostr/nip65BackgroundIngestor.ts`, `Nip65SessionInfo`, `buildNativeNip65Payload()` / `_syncNip65Sessions()`, `setNip65NativeRelayState()` / `getNip65NativeRelayState()`, `reconcileNip65Sessions()`, `updateNip65Sessions()` bridge method, `nip65-relay-status` + `nip65event` listener overloads, `nip65RelayStatusBridge` / `nip65EventBridge` lambdas, `custr:nip65-native-sessions` prefs, `"nip65-native"` `RelayStatusSource` member. - The decision cannot be JS-gated at background time: the WebView JS thread is frozen while the app is backgrounded (locked invariant, see `.memory/memory.md`), so any `appStateChange{isActive:false}`-driven logic never runs. Removing the layer entirely is the only fully correct approach. - The only thing lost is real-time background refresh of metadata/badges — an explicitly accepted trade-off. See `.memory/memory.md` (NIP-65-removal entry) for the full rationale. ### Tests - Deleted: `tests/core/nostr/nip65BackgroundIngestor.test.ts`, `tests/plugins/background-service/buildNativeNip65Payload.test.ts`, `tests/hardware/scenario-07-nip65-native-keepalive.test.ts`. - Pruned all NIP-65 test groups in `Nip46ForegroundServiceTest.kt`. - Added regression pin in `Nip46ForegroundServiceTest.kt` asserting that `onStartCommand() + updateSessions()` opens **zero** NIP-65 sockets — any future commit reintroducing the layer will fail this test and force a battery review. ## v0.1.0 🚧 Initial implementation (pre-alpha !). 🏗️