Iwakura#
Iwakura is an experimental browser-based instant messenger combining portable atproto identity, authenticated Iroh device connectivity, decentralized BeeKEM group key agreement, and peer-retained asynchronous message delivery.
A signed-in launch opens local state for the account named by the OAuth
client's stored session pointer and restores the OAuth session
concurrently; the session gates only network work. Transient restore
failures retry with bounded backoff instead of signing out, and a launch
without connectivity opens local history.
- The OAuth client loads on demand, publication builds embed their exact
client metadata, and the shell's three atproto calls are direct XRPC
requests, replacing @atproto/api. The JavaScript loaded before
interaction is about 182 KiB (52 KiB gzip), enforced by a new budget.
- The page's startup script fetches and compiles the protocol engine
before any module loads when a session or authorization callback is
present; sign-in prefetches it.
- The conversation list renders from the persisted index and histories
decrypt in the background, open conversation first. Timeline caches key
on the replica's conversation revision, and system-event labels never
wait for the network.
- A stored session launches into the inert skeleton shell instead of the
startup gate, and startup forces no layout of its own.
- A signed-in device registers a service worker that precaches one
verified build and serves later launches from it.
See ADR 0054.
Claude-Session: https://claude.ai/code/session_01JjaUrKBr26r2etFVi717go
Restoring the browser replica replays every persisted event once, in
canonical causal order (causal depth, then event ID), through the same
signature, authorization, and BeeKEM validation as network ingest. The
store maintains each event's causal depth and message frontier and each
group's replay order, heads, authorization state, and message references
incrementally, so restore, message frontiers, and state queries are
linear in the history they describe.
- ProtocolStore validates an event against the store, applies it to the
BeeKEM verifier atomically, and commits without cloning the store.
- BeeKEM operations are verified once with the strict Ed25519 check,
which implies upstream Signed::try_verify over the same key and bytes.
- conversationRevision exposes an opaque per-conversation revision that
changes whenever that conversation's visible history changes.
- verifyEventSignatures strictly verifies persisted event encodings
without touching storage, and openPersistentConversationReplica accepts
an optional verifier so large histories verify signatures concurrently
in workers. The restore verifies every event a verifier does not
confirm.
- One IndexedDB connection serves each database, restore reads its
history in one transaction, and connections close on versionchange.
- Signature, hashing, DRISL, bincode, BeeKEM, and AEAD crates compile at
opt-level 3 in the size-optimized wasm-release profile.
See ADR 0053.
Claude-Session: https://claude.ai/code/session_01JjaUrKBr26r2etFVi717go
Iwakura is an experimental browser-based instant messenger combining portable atproto identity, authenticated Iroh device connectivity, decentralized BeeKEM group key agreement, and peer-retained asynchronous message delivery.