Poweur
  • Product
  • Use cases
  • Architecture
  • Blog
  • FAQ
  • Docs
  • GitHub
Open app Claim your ID
Questions

FAQ

Answers to what people ask first. Updated 5 October 2026.

The short version

  • Poweur gives you one open ID, a readable name such as alice.poweur.net or a name on your own domain, backed by keys that stay on your devices. It signs you in to apps, carries end-to-end encrypted messages, and holds files you choose to share.
  • It is open source and pre-1.0. It works today, it has not had an external security review, and it is not a finished ecosystem.
  • A hosted name depends on the domain's operator. A name on your own domain is yours.

The basics

What is Poweur?

An open identity, messaging and data-sharing layer. A Poweur ID is a name that is at once an identity (keys that sign things), an address (people, apps and agents can send it end-to-end encrypted messages) and a home for files you can share with other IDs. Apps can accept it as a login. Anyone can run a relay, host IDs on their own domain, or build on the same pieces. The introduction tells the story; the documentation has the details.

How finished is it?

Pre-1.0. Identity, messaging, sharing and sign-in work end to end, with a web app, a CLI and a TypeScript SDK; mobile apps are in beta preparation. The broader app ecosystem, the email bridge and collaborative spaces are on the roadmap, not shipped. Expect rough edges and tell us about them in Discussions.

How do I try it?

Claim a free name in the web app, then message the demo bot and sign the guestbook. Developers can start with npm i @poweur/client.

Why not something else?

Why not email?

Email proved that people on different providers can reach each other, and Poweur borrows that idea. But an email address does not prove who sent a message, messages are not encrypted by default, spam is the default state, and the address is not a login or a place for files. A Poweur ID is built so that a sender is verifiable, content is encrypted end to end, and the same name also signs you in and holds data. An email bridge is planned, not built.

Why not Matrix?

Matrix is a federated chat network: you have an account on a homeserver and talk in rooms. Poweur is not a chat network; it is an identity first. The name and keys are what you own, messaging is one thing you can do with them, and sign-in and files use the same identity. They can coexist, and a Poweur ID could be used to sign in to a Matrix service.

Why not Nostr?

The philosophy overlaps: keys you control, relays you can choose. The differences are practical. A Poweur ID is a readable name backed by a domain rather than a raw public key, keys can be rotated and recovered, each device holds its own key, messages are end-to-end encrypted by default, and there is an encrypted drive and a sign-in protocol. Nostr is built around public notes; Poweur is built around private messages and shared files.

Why not Bluesky or the AT Protocol?

Bluesky shows that a domain name can be a handle, and that idea is in Poweur too. The AT Protocol is a public social network. Poweur is private by default: encrypted messages, files you share with chosen IDs, and sign-in for other apps. It is not trying to be a social feed.

Why not Solid?

Solid is Poweur's closest relative, and the two share a lot: you own your identity, your data lives in a store you control, and apps ask for access instead of keeping their own copy. They may turn out to be partly compatible. Two differences matter.

  • Authentication. Solid sign-in leans on an OpenID provider you choose. With Poweur, ID owners authenticate themselves with passkeys or device keystores, and decrypt their own data with those same keys.
  • Who can read your data. A Solid pod server has to read your data to enforce who may access it. A Poweur relay only sees metadata (who, when, how big, who a folder is shared with); file contents and names are encrypted on your device. That makes Poweur a better fit for private, personal data, where even the operator should not be able to read it.

If Solid fits your project better, use it.

Trust, keys and privacy

Who holds the keys?

You do. Your identity keys are created on your device and wrapped by a secret only your passkey (or the phone's secure storage) can produce. For convenience the relay keeps an encrypted copy of that wrapped key, which lets a new device or a cleared browser be restored, but it cannot open it. You can also keep a recovery kit that rebuilds the keys yourself. Poweur cannot reset your password, because there is none, and cannot recover an ID for which you hold neither a passkey nor a kit. See the key management page.

Can Poweur read my messages or files?

Not the content. Messages are signed and end-to-end encrypted, and file contents and names in your private drive are encrypted on your device. The relay still sees metadata: who messages whom and when, message and file sizes, how folders nest, and who a folder is shared with. Folders you make public are readable by anyone with the address. The threat model lists exactly what each party can and cannot see.

What happens if poweur.net disappears?

Your keys and a recovery kit are yours, so you can export your data and move. But a name under poweur.net belongs to the domain, so if we vanished, that name would go with the domain. A name on your own domain does not depend on us at all: you can point it at any relay, including one you run. If a name matters to you for the long term, use your own domain.

Why do I need a passkey with PRF, and what works?

On the web, your keys are protected by a secret your authenticator derives (the WebAuthn PRF extension). That is what lets a browser protect a key without a password and lets the relay hold only ciphertext. An authenticator that cannot produce the PRF secret is refused rather than silently weakened.

Tested and working: Chrome, Firefox and Safari on macOS, using the built-in macOS passkey keystore (iCloud Keychain, with Touch ID). Security keys that implement PRF, and Google Password Manager passkeys, should work too. Does not work: Bitwarden's passkeys, because they do not provide PRF. If your authenticator cannot, use a platform passkey, the mobile app or the CLI. Tell us what works and what fails on your browser and device in Discussions.

Is it audited?

No. There has been no external security review yet. The cryptography uses standard primitives (Ed25519, X25519, ChaCha20-Poly1305, HKDF), the Go and TypeScript implementations are checked against shared test vectors, and everything is open source so you can read it. Please do not treat an unaudited pre-1.0 system as a vault for secrets that would be dangerous to lose. To report a vulnerability, use the private advisory form or [email protected]; see security.

What does an app learn when I sign in with my ID?

Your ID, and your name and photo only if you allow it. No password and no access to your messages or files. Every request shows you which app is asking and what it would see, and you can revoke an app later. The guestbook is a live example, and adding it to your own site takes one verification call.

What about spam and abuse?

Each ID sets who may message it: contacts only, contact requests, or open with proof of work for strangers. You can block people, relays rate-limit senders, and the operator of a relay can suspend IDs it hosts. Report abuse of poweur.net to [email protected].

Running it

Can I use my own domain?

Yes. Run a relay for your domain today, following the self-hosting guide. Hosting your own domain for you is planned, not available yet.

How do I run my own relay?

One Go binary or container, with a domain and HTTPS. The guide walks through it. People on different relays can still message each other.

What about AI agents?

An agent can have an ID of its own and work with files through the CLI or the SDK, with access limited to what you share. Today you can give an agent an ID, message it, and let it read and write shared files. Finer-grained grants and an app ecosystem built around them are still ahead. See agents.

The project

How do you make money?

Poweur is open source and free to self-host, and hosted names on poweur.net are free. Running servers costs money, so the plan is optional paid plans for things like extra storage and hosting your own domain, plus sponsorship for people who just want to help. What stays free: the ID itself, recovery, end-to-end messaging, sign-in and exporting your data.

Who is behind it?

Poweur is built and operated by Roman Mandryk (legal details). Contributions are welcome through the repository.

What is the licence?

The relay, web app and OAuth bridge are AGPL-3.0. The pieces others embed (the identity library, the TypeScript SDK, the CLI, the conventions and the documentation) are Apache-2.0. The names and logos are covered by a trademark policy.

I have another question

Ask in Discussions, or message support.poweur.net from the app, or write to [email protected].

Poweur

One open ID for identity, messages and data. Open source, self-hostable, yours.

Product

  • ID, messaging & files
  • Use cases
  • Poweured apps
  • Hosting options
  • Try it live
  • Web app

Developers

  • Documentation
  • Architecture
  • TypeScript SDK
  • CLI
  • Sign in with Poweur

Project

  • GitHub
  • Roadmap
  • Contributing
  • Blog
  • FAQ
  • Threat model
  • Press kit
  • Security

Community

  • Discussions
© 2026 Poweur contributors · Open source · Privacy · Terms · Legal & contact Poweur proves control of a name and its keys, not a legal identity.