Skip to the content
Back to Nymchat

Knowledge base Talking to people

Group chats

End-to-end encrypted group conversations that do not leak their own membership. Every message is wrapped separately for every member, addressed to a key that is used once.

Creating a group

/group @alice @bob Weekend plans creates a group with those members and that name. The name is optional. You can also pick Create Group Chat from someone's context menu, or use the + beside the Group Chats section in the sidebar.

A Nymchat group chat conversation.
A group chat.

You become the group's owner. Groups are capped at 100 members, because every message is encrypted separately for each one and the per-message fan-out has to stay bounded. The group's menu shows the count against that cap — 37/100 members — and marks a group that has reached it as Full; a full group cannot add anyone, by name, by link or by request.

Adding members

/addmember @nym, or /invite @nym while you are in the group. Whether anyone besides the owner and admins may do this is the group's allow members to add others setting, in the group's context menu.

/groupinfo lists the current members.

Off by default. The owner or an admin turns on Allow joining via invite link from the group's context menu, after which the link appears there — for them, and for members too when "allow members to add others" is on.

Someone brand new who opens an invite link is asked to pick a nym or log in first; the join then resumes on its own, so they do not have to find the link a second time.

Reset Invite Link revokes every link shared so far in one go. Use it when a link has ended up somewhere you did not intend.

Opening a link shows a preview before anything is sent: the group's name and, from links made by a current app, its description, avatar, member count and up to five of its admins. Those details are signed by the member who made the link, and a preview whose signature does not check out shows the name alone. Joining is a separate, deliberate tap. Anyone holding the link can read that preview, so write a description you are happy for them to see.

Admins approve join requests, in the group's menu, puts a person between the link and the group. With it on, opening the link sends a request instead of joining, the requester sees Waiting for approval, and the owner and admins find the request under Join requests, where they approve or decline it. Requests expire after a week.

Sharing history with new members

Also off by default, also the owner's or an admin's call: Share history with new members in the group's context menu.

With it on, whoever adds someone forwards up to the group's last 50 messages to that new member, as a single encrypted blob, to them alone. Forwarded messages are marked unverified, because the original authors' signatures cannot be re-checked once the text has been relayed by a third party — you are trusting the person who added you not to have edited what they passed on.

Description, slowmode and @everyone

A few settings shape how a group talks. The owner and admins change them from the group's menu.

  • Description. Up to 150 characters, shown on one line under the group's name in the header; tap it to read all of it. It travels inside the group's encrypted messages like the name does.
  • Slowmode. Off, or one message every 10 seconds, 30 seconds, 1 minute, 5 minutes, 15 minutes or 1 hour, per member. The owner, admins and moderators are not limited. The composer tells a member how long to wait, and because there is no server, every member's app also checks the timing of what arrives: a message that came too soon is folded away as Held by slowmode, with a button to show it.
  • @here and @everyone. Either one in a message notifies every member as though they had been mentioned by name. Only the owner, admins and moderators can use them; a member's app refuses to send one, and everyone else's app ignores one from a sender without that role.
A Nymchat group's panel showing the group name, 4/100 members, actions such as Add Members, Create event, Share location, Create call link, Media, files and links and Export chat, and the member list.
A group's panel, with the member count against the 100-member cap.

The group's menu also has Media, files & links and Export chat, described under Messages, and Share location and Create call link, under Sharing a location and Call links. None of these work over the Bluetooth mesh, which does not carry encrypted groups.

Events and RSVPs

Event, in the attach menu, or Create event in the group's menu, posts an event card: a title, a date, a time and time zone, and optionally a place and a note. Any member can create one.

Each member answers Going, Maybe or Can't on the card, which keeps a running count and lists who said what. An answer can be changed; the latest one counts. Remind me sets a reminder on your own device, at the start or 10 minutes, 1 hour or 1 day before. Events and answers are ordinary encrypted group messages, visible to the members and nobody else.

Owners, admins, moderators and members

CommandDoesWho can
/kick @nymRemoves a memberOwner, admins, moderators
/ban @nymRemoves them and blocks their returnOwner, admins, moderators
/unban @nymLifts a banOwner, admins, moderators
/addmod @nymPromotes to moderatorOwner, admins
/removemod @nymDemotes a moderatorOwner, admins
/addadmin @nymPromotes to adminOwner
/removeadmin @nymDemotes an adminOwner
/transferowner @nymHands the group overOwner
/leaveRemoves you from the groupAnyone

A group has exactly one owner, and any number of admins and moderators. The split is between acting on people and acting on the group: moderators remove, ban and unban members, and that is all they do. Admins do that too, and also everything that changes the group itself — its name, its description, its invite link, its settings, who may add members — and they appoint and dismiss moderators. Only the owner appoints admins, and only the owner can hand the group to someone else.

Nobody can act on someone at or above their own role. A moderator cannot kick another moderator, an admin cannot demote another admin, and no one but the owner can act on the owner. Ownership is the one role that moves rather than stacks: /transferowner hands it over, it does not add a second owner.

Roles are enforced on both sides

There is no server to arbitrate, so every client checks the role itself — when sending a moderation action, and again on every moderation event it receives. A client that claims a power it does not have is simply ignored by everyone else.

How group encryption works

Group chats use the same NIP-17 rumors and NIP-59 gift wraps as private messages, one wrap per member, each encrypted to that member. Nymchat then adds something standard NIP-17 does not have.

Rotating recipient keys

With plain NIP-17, someone watching a relay sees N gift wraps appear at the same instant, addressed to N different pubkeys. That is a membership list, and it does not need decrypting to read.

So Nymchat rotates the recipient keys. Every time you send, your client mints a fresh ephemeral keypair and advertises its public half inside the encrypted rumor, as an ephemeral_pk tag. From then on, everybody addresses their messages to that key instead of your real one. To an observer, every message in the group travels between one-time pubkeys that have no visible link to any identity, and no two messages share a recipient.

Post-compromise recovery

That rotation is also the recovery mechanism. If a device is compromised, the user simply sends a message: the new ephemeral key it advertises replaces the old one for every member automatically. There is no out-of-band resync to arrange and nothing for the group to agree on.

Coming back after being away

Ephemeral keys rotate, and the events carrying them expire off relays. A client that has been offline for days can therefore come back holding keys everyone else has moved past. So on reconnect, after a long enough gap, it sends a rate-limited key-resync request to each of its groups and re-exchanges current keys — which is what stops a long holiday from turning into a group you can no longer read.

Group messages between Nymchat users can also use a post-quantum key exchange on top of the above. Because every member already gets their own separately encrypted copy, a group can mix both freely — and a message is only marked quantum-resistant when every member received it that way. See quantum-resistant encryption.