p2p.kiwi logo

Docs 📚

E2EE, configuration, threat model, ...

Process and protocol boundaries

This note maps the live room, WebRTC, and native surfaces so later sidecar and E2EE work reuse existing names instead of replacing them.

docs

End-to-end encryption threat model

p2p.kiwi is a desktop WebRTC mesh. There is no application signaling server. Invite URLs carry SDP out of band. STUN/TURN may still observe connection metadata.

docs

MLS implementation for p2p.kiwi

ts-mls (MIT, RFC 9420) behind the `RoomCrypto` interface for group membership and epoch key management. Media keys and high-frequency application keys are derived with MLS exporters and domain-separated labels.

docs

Native overlay sidecar

p2p.kiwi ships an Odin helper (`p2p-kiwi-sidecar`) for always-on-top, click-through cursor overlays. Electron main is the only process that starts it. The renderer never executes sidecar commands.

docs

macOS sidecar manual checklist

Interactive checks for overlays, permissions, and emergency stop on a Mac. Signing and notarization are enforced in GitHub Actions.

docs