Skip to content

Encrypted messaging on Algorand

Your keys,
your words.

Raven is end-to-end encrypted, self-custodial messaging on Algorand. No servers, no phone number, no sign-up. Your Algorand key is your account, every message is encrypted on your device, and only ciphertext ever touches the chain.

Raven running as a web app: Alice on a light theme and Bob on a dark theme exchange an end-to-end encrypted conversation that settles on Algorand.
The Contacts screen: save a peer by label and 58-character Algorand address, or scan their address QR. Labeled 'verify before you trust'.
Add a contact by Algorand address or QR. Verify before you trust.
The desktop chat: a thread header marked 'End-to-end encrypted' and 'On Algorand', with a 'Who can reach you' filter set to contacts or anyone.
Every thread is labeled end-to-end encrypted and on Algorand. You choose who can reach you.
0
servers
your client talks straight to Algorand
~2.8s
to settle
typical Algorand finality
0
sign-ups
no phone number, no password, no email
25 words
your whole account
a self-custodial keypair you can recover

Status
v0.12.0, a beta open to everyone. Raven runs as an Angular web app, as a desktop app for Linux and Windows, and as iOS and Android shells via Capacitor. Release builds use MainNet, where messages and payments spend real ALGO. Your 25-word recovery phrase is created on your device, stored encrypted in this browser, and never sent to us. Back it up before you start chatting. If you lose the device and the phrase, nobody can restore the account.

01

Messaging you actually own.

Most chat apps put a company between you and the people you talk to: a server that holds your account, a phone number that names you, a database that keeps your messages. Raven removes the middle. Your identity is an Algorand keypair you create and hold, the encryption happens on your device, and the ledger carries the rest. There is nothing for us to read, because there is no us in the path.

No account to grant

No sign-up, no phone number, no email. You generate a key on this device, and you can message. The phrase stays in this browser unless you write it down. Lose both, and the account is gone.

No server to trust

Your client talks directly to Algorand's algod and indexer. There is no Raven backend to breach, subpoena, or shut down.

No crypto of our own

Every envelope comes from AlgoChat, an audited, cross-language wire format. Raven writes zero cryptography itself.

02

What's protected, and what's public.

End-to-end encryption hides what you say. A public ledger cannot hide that you said something. Raven never promises what the blockchain can't deliver, so here is the line, plainly.

Protected

  • Message contents. Encrypted on your device; only the recipient's key decrypts them.
  • Your keys. Generated and stored on this device. Never sent to CorvidLabs. There is no mnemonic server.
  • Who can read a thread. Decryption is keyed to the participants, no one else.

Public, by design

  • That a message was sent. A transaction on the ledger is public by design.
  • Sender and recipient addresses, the timing, and the rough size of each message.
  • Group membership shape, since each member receives their own envelope.
  • No forward secrecy. Anyone with a party's long-term key or recovery phrase can decrypt old everyday chats. Extra lock adds a second secret you both hold; it is still not a Signal-style ratchet.
03

A real messenger, not a demo.

No roadmap, no promises. Just what is built and runs in the beta.

End-to-end encrypted

One-to-one messages are wrapped on your device with X25519 and ChaCha20-Poly1305 before they ever leave. The chain only sees ciphertext.

Group chats

Fixed-member groups send one encrypted transaction per other member, then collapse into a single thread for you. Same 1:1 encryption, more people. Not a group ratchet.

Self-custodial identity

Create or recover a 25-word Algorand keypair on this device. No registration, no usernames. Your address is your account. The phrase is never uploaded.

Names and avatars

NFD names are a public registry lookup. A custom field named raven can point chat at a different address; that field is typed by the owner, not a proof they hold the key. NFT avatars check the holder on chain.

Photos

Without extra setup, a photo is shrunk and split across network fees. Add your own Pinata key to lock the file on this device, store only the locked bytes, and send one chat that points at that file. Not an NFT. CorvidLabs does not pin files for you.

Multipart text

Each transaction carries one Algorand note (under 1 KB of plaintext). A long message auto-splits and reassembles. The cap is about 8 to 10 KB of ASCII, less for emoji or JSON.

Extra lock

Everyday chat is already private for today. Extra lock adds a second secret you copy, paste, or scan with one person. Mark as verified only records that you compared a safety number. It does not turn Extra lock on.

Keys stay on this device

The 25-word phrase is generated in the browser and stored encrypted here (IndexedDB / local storage). There is no Raven account server. Without a passphrase, a device key wraps it. With a passphrase, PBKDF2 (600k) plus AES-GCM wraps it. We cannot see it or reset it.

Verify your contact

Confirm you are talking to the right key with a QR exchange and an emoji-plus-word safety number, then mark the contact verified. NFD names are not that check.

04

How a message travels.

A message in Raven is an Algorand transaction. Four steps, no backend in any of them.

  1. Encrypt on device

    Raven wraps your text in an AlgoChat envelope (X25519 + ChaCha20-Poly1305). Plaintext never leaves your device.

  2. Post to Algorand

    The ciphertext rides in the note field of a 0-amount transaction. No Raven server sits in the middle of it.

  3. Settle in seconds

    Algorand reaches finality in about 2.8 seconds. The thread updates the moment the block confirms.

  4. Decrypt on arrival

    Your contact's client reads the note from the indexer and decrypts it with their key. Only they can.

05

On your computer.

Raven also comes as a desktop app for Linux and Windows. The app is bundled inside it, so it opens even when a website cannot be reached, and what runs is exactly what you installed. Messages still go straight to Algorand. It keeps its own copy of your account: open it, choose Restore my account, and enter your 25 words.

The first desktop release is on its way. It will be on Raven's download page as soon as it is published.

06

Built on AlgoChat.

Raven implements no cryptography of its own. Every envelope it sends comes from @corvidlabs/ts-algochat, one of six implementations of the same wire format (Swift, Rust, TypeScript, Python, Kotlin, Go). Five pass one shared conformance harness; Go is implemented and still being brought into it. The protocol is the trust boundary; Raven is the app on top of it.

# One envelope, one wire format, many languages
  envelope    algochat/v1
  suite       X25519 + ChaCha20-Poly1305
  extra      optional Extra lock (copy, paste, or scan)
  carrier     Algorand transaction note

  → the same spec the other clients speak
07

Where it ships

Frontend
Angular 22 (standalone, signals, zoneless)
Desktop
Linux + Windows via Electron, the web app bundled inside
Mobile
iOS + Android via Capacitor
Chain
Algorand MainNet (release builds)
Crypto
@corvidlabs/ts-algochat (X25519 + ChaCha20-Poly1305)
Identity
25-word phrase, generated and stored on this device only
Status
v0.12.0, public beta

Messaging you hold the keys to.

Raven is open to everyone on MainNet (v0.12.0). No NFT or connected holder wallet is required. Create or restore your Raven account to start chatting.