Architecture

Keys on devices. Relays in between. Nothing in the middle you have to trust.

An ID is a DNS name that publishes public keys and a relay. Clients sign and encrypt locally; relays verify, route, store and push. Any relay can talk to any other — hosted or self-hosted — using the same open protocol.

The network at a glance

Alice and Bob use the hosted relay at poweur.net. Carl runs his own relay for carl.example.com. Files can live on the relay's disk or in separate cloud object storage.

DNS · HTTPS /.well-known/poweur/id.json public keys + home relay for every ID relay.poweur.net SHARED · HOSTED Identity host · alice, bob · wildcard names Verify · route · inbox spool · SSE push File homes · sync · share grants Sign-in · OAuth / OIDC bridge alice.poweur.net laptop · phone (web, iOS) Ed25519 + X25519 keys stay on her devices passkey-gated bob.poweur.net phone · CLI + his agent with its own ID helper.bob.poweur.net Poweured app static bundle · no backend state in /apps/<app>/ of the user carl.example.com Carl's laptop · shop tablet + order agent orders.carl.example.com relay.carl.example.com SELF-HOSTED one Go binary / container inbox · files · shares for *.carl.example.com IDs own hardware / EU cloud Cloud object storage S3-compatible · separable files service storage v2: relay-blind encryption HTTPS · SSE HTTPS · SSE scoped grant signed E2EE resolve IDs blobs client ↔ its relay relay ↔ relay (federation) lookup / storage app access, user-granted
IDs are DNS namesResolved web-first from /.well-known/poweur/id.json, DNS TXT as fallback. Conflicts fail closed.
Relays hold no private keysThey verify signatures, enforce inbox policy, spool and push. Message bodies are end-to-end encrypted.
Federation is the defaultrelay.poweur.net and relay.carl.example.com speak the same protocol; neither needs permission from the other.
Move freelyExport an ID, point the name at a new relay, keep every contact.
Flow 1

Alice says “Hello” to Carl

Two IDs on two different relays. Nobody in the middle can read it, forge it or claim to be Alice.

  1. Alice's app looks up carl.example.com's public keys and home relay over HTTPS — the same way a browser finds a website.
  2. The message is encrypted to Carl's key and signed with Alice's, on her device.
  3. Carl's relay checks the signature and Carl's inbox policy: contacts go straight in, strangers need a request or a proof-of-work stamp.
Flow 2 · typed messages

Ordering a pepperoni pizza — no platform in between

Alice asks her agent (or taps in a Poweured pizza app). Carl's pizzeria at carl.example.com runs an order agent. Four typed messages replace a delivery platform, its fees and its tracking.

① order.request{"type":"food.order.request","items":[{"sku":"pepperoni","size":"L"}],"deliver_to":"home"}
② payment.request{"type":"payment.request","pay_to":"IBAN X","amount":"14.50 EUR","reference":"N"}
③ payment.proof{"type":"payment.proof","reference":"N","tx":"…"} — signed by Alice's ID
④ order.confirmed{"type":"food.order.confirmed","order":184,"eta_min":35}
  1. Every message is signed: Carl knows the order really came from alice.poweur.net, Alice knows the payment details really came from carl.example.com — no phishing invoice can slip in.
  2. A human stays in the loop where money moves. The agent drafts; Alice approves.
  3. No server of the app's own: the order history lives in Alice's home, the ticket in Carl's. Message types shown are illustrative; payment conventions are on the roadmap.
Flow 3 · system messages

Adding a new phone to your ID

The same messaging layer carries protocol traffic. Enrolling a device is a short, verifiable ceremony between two devices you own — the relay only relays.

  1. Commit-then-reveal means a relay or a shoulder-surfer can't slip their own key in.
  2. Every other device is told, so a surprise enrollment is visible immediately — and removable in one tap.
Flow 4 · data sharing

Co-working on a folder with people and an agent

Alice shares a folder with Bob and with Carl's research agent. Grants are signed by Alice, checked by her relay on every access, and revocable at once.

Read the protocol.

Identity model, message format, sync protocol, sharing and conventions — all documented and open.