rChat documentation
rChat is a truly private messaging platform. Every message is protected by end-to-end encryption, and the server is architecturally incapable of reading your messages — even if it is fully compromised.
Key features
Section titled “Key features”True end-to-end encryption Every conversation uses X3DH key agreement followed by the Double Ratchet algorithm. Each message gets a unique key and provides perfect forward secrecy — past messages stay safe even if keys are later compromised.
Zero-trust server The server cannot read your messages, see your contacts, or know who is talking to whom. It relays opaque encrypted packets only. A compromised server gains nothing.
Self-hostable Run your own server on any Linux, FreeBSD, or macOS machine. No cloud dependencies, no third-party accounts, no telemetry.
Cross-platform Available for iOS, macOS, Linux, and FreeBSD. Native apps for mobile and a full-featured CLI for desktop.
DPI-resistant transport All traffic runs over WebSocket + TLS 1.3 on port 443. The TLS fingerprint matches real browser traffic, and frame sizes are randomised, so passive network analysis cannot distinguish rChat from ordinary HTTPS API traffic.
How it works
Section titled “How it works”Your device rChat Server Contact────────── ──────────── ───────Message → [X3DH+Ratchet] → WebSocket/TLS → [relay] → [Decrypt]- The client connects to the server over TLS 1.3
- An X3DH handshake derives a shared secret (no pre-shared passwords)
- All messages are encrypted with the Double Ratchet
- The server relays encrypted packets — it cannot read them