The ForgeSworn stack / reconciled 15 September 2026

Every part
has a job.

My Signet for identity. KithMoot for conversations. Bothy for circle infrastructure. Shared libraries underneath.

This catalogue combines the profile's toolbox with relevant local manifests and project documentation. A product you use, a library it declares and a capability still to be connected have different evidence.

Start with the apps

My Signet belongs
at the front of the picture.

Software identity and signing

My Signet

Manages identities, personas, credentials, family relationships, app permissions and identity backup. Its documented signing interfaces include NIP-46 and Android NIP-55.

The app can hold identity keys in software. Identity backup is different from recovery of every application's data.

Hardware alternative

Heartwood and its companion tools

Heartwood holds identity keys on hardware. Bark bridges browser signing; Cambium bridges Android requests. Sapwood manages the device and policies.

Sapwood's current documentation labels the complete new recovery-word hardware ceremony untested alpha. These tools have distinct roles and acceptance boundaries.

My Signet implements Signet. signet-protocol is its protocol library; signet-login is an SDK for consuming apps. A hosted My Signet website is not a mandatory Vennel network service.

How the layers connect

Products above.
Shared mechanisms below.

User-facing components

My Signet / KithMoot / Bothy

Identity, conversations and circle infrastructure

My Signet declares

Identity and relationships

  • signet-protocolIdentity and verification
  • nsec-treePurpose-separated keys
  • kenspeckle / tessera-kitRelationships and presence
  • shamir-words / spoken-tokenBackup shares and spoken verification

KithMoot web declares

Access and conversation

  • signet-loginAuthentication and signer access
  • nostr-contact-cardContact and box information
  • nostr-deaddrop / spoken-tokenQuiet-message machinery and verification
  • @forgesworn/contextContext collections, with context-tools

Bothy workspace declares

Storage and transport

  • shelter-kitStorage and serving
  • link-core / link-endpointLink protocol and endpoints
  • link-blossomFile transport integration

Android packages a native Link bridge separately. Workspace declarations do not mean every crate runs in production.

These edges represent local manifest declarations. They do not establish exact installed transitive versions or deployed features. Sibling checkouts can differ from a consumer's pinned revision.

Explore by responsibility

The wider catalogue.

A declared dependency has manifest evidence. A profile mechanism is named in the design but may need integration. Candidate and reserved work is labelled explicitly. Documentation does not replace release or device acceptance.

Identity, signing and permissions
App / documented capability

My Signet

Identity creation/import, personas, credentials, family relationships, signing permissions and identity backup. Its documented interfaces include NIP-46 remote signing and Android NIP-55. The app can hold identity keys in software.

Declared by My Signet

Signet / signet-protocol

The protocol library, distinct from the My Signet application. Its local manifest declares range-proof, ring-sig, shamir-words, nostr-attestations, nsec-tree and spoken-token.

Declared by KithMoot

Signet Access / signet-login

Authentication and signer-access SDK. The inspected SDK checkout declares signet-verify. A dependency declaration does not prove that every login option is enabled by the consuming app.

SDK family

signet-verify / signet-credentials

Verification and cross-device sign-in; credential publishing and validation. signet-verify is declared by the inspected signet-login checkout and is a development dependency in My Signet. Direct use of signet-credentials by the inspected Vennel clients was not established.

Declared dependency / profile library

nsec-tree / nostr-succession

Purpose-separated identity derivation and verifiable succession. My Signet and the succession library declare nsec-tree. Complete client identity migration is a separate unfinished integration.

Hardware signer / firmware

Heartwood / heartwood-esp32

Holds identity keys on hardware and enforces signing policy. An alternative to software-held keys; it is not a mandatory second signer for every My Signet user.

Signer bridges

Bark / Cambium

Bark exposes NIP-07 to browser apps and forwards over NIP-46. Cambium exposes NIP-55 on Android and forwards to Heartwood. Neither holds the user's identity key itself.

Hardware management app

Sapwood

Manages Heartwood identities, policies and recovery. Its current README calls the complete new recovery-word hardware ceremony untested alpha. Management tools do not establish a proven hardware restore.

Conversations, storage and transport
Messaging apps

KithMoot / KithMoot Android

Conversations, contacts and lane labels. The web manifest declares signet-login, nostr-contact-card, nostr-deaddrop and spoken-token. Android build configuration requires the native Link bridge.

Declared dependencies

nostr-contact-card / spoken-token

Signed contact-card information and spoken verification tokens. Both are declared by KithMoot; spoken-token is also declared by My Signet, Signet and kenspeckle.

Declared by KithMoot

nostr-deaddrop

Quiet-message counters, padding and scheduling primitives. Dependency presence does not close box-owned cadence activation or physical-device acceptance.

Box product / implementation

Bothy / bothy-node

Circle infrastructure for keeper storage, scoped admission and delivery. Its Rust workspace declares shelter-kit and Link components.

Declared native dependency

ForgeSworn Link

Bothy declares link-core, link-endpoint and link-blossom. Android packages Link's native bridge. The workspace's link-relay crate is documented development-only; it does not establish that every box runs a Link relay.

Declared by KithMoot

@forgesworn/context / @forgesworn/context-tools

Signed encrypted context collections and supporting cache, CLI and MCP tooling. Additional product dependencies beyond the core Vennel messaging rules, not another network carrier.

External infrastructure

Tor / Arti / I2P

Carrier technologies used by the design. They are not ForgeSworn libraries. Connection probes, box scheduling and completed message delivery have separate evidence.

Relationships, family and presence
Declared by My Signet

kenspeckle

Bonds, invitations and relationship tiers. Its manifest declares tessera-kit, nostr-attestations and spoken-token.

Declared dependency

tessera-kit

Presence and membership-filter machinery. Directly declared by My Signet and kenspeckle; this does not prove every proposed Vennel discovery journey.

Declared dependency

nostr-attestations

Signed attestation event handling, declared by Signet and kenspeckle. Supports bond and verification mechanisms.

Profile mechanism

charter

Parent-held policy and authority for the intended family mode. Complete Vennel kin-mode integration remains open.

Declared dependency / profile mechanism

range-proof

Value-in-range proofs, declared by Signet. Age-range proof is a family-mode mechanism; the proposed mint-solvency use is separate work.

Profile mechanism / primitive

nostr-veil / ring-sig

Anonymous corroboration and ring signatures. nostr-veil, nostr-anon-vote, Signet and epoch-seal declare ring-sig. Proposed anonymous trust and flood controls are not blanket anonymity guarantees.

History, files and recovery
Reviewed profile library

epoch-seal

Composes dominion-protocol, nostr-anon-vote and ring-sig for sealed history and witnessed recovery. Signer-backed Bothy integration remains open.

Declared by epoch-seal

Dominion / dominion-protocol

Encrypted access and recovery-share machinery. Its manifest declares shamir-core. Dominion is the project; dominion-protocol is the package name.

Declared dependencies

shamir-words / shamir-core

Threshold splitting and reconstruction, with human-readable shares in shamir-words. My Signet and Signet declare shamir-words; shamir-words and Dominion declare shamir-core.

Declared by epoch-seal

nostr-anon-vote

Anonymous ballots for recovery refusal, using ring-sig. This does not make the surrounding recovery process invisible.

Profile mechanism

canary-kit

Duress and verification components. Its manifest declares shamir-words, nsec-tree and spoken-token. Complete signer/box duress integration remains open.

File app / node

Wildbloom / Wildbloom Node

Encrypted content-addressed file delivery. Wildbloom Node's manifest uses the shelter-kit package under the local name wildbloom-core.

Declared by Bothy and Wildbloom Node

shelter-kit

Shared storage and serving machinery for box/file infrastructure. This is a Rust crate, not an omitted npm dependency.

Profile groundwork

VMLS / vmls-core

Vennel's bounded outer-envelope codec has Rust hostile-input tests and Android/WebAssembly build evidence. It has no cryptographic dependency, manages no MLS groups and is not consumed by KithMoot or Bothy yet.

External protocol / candidate

RFC 9420 MLS / OpenMLS

MLS is the intended sheltered-lane message-key protection. OpenMLS 0.9.0 is a compile-proven candidate, not an adopted dependency. Group state, KeyPackages, Welcome delivery, replay handling and client integration remain open.

Implemented in source

Bothy archives / KithMoot history

Encrypted archive export/restore, bounded private history import, encrypted local search and box-first deletion with recorded outcomes. These are product implementation paths, not extra standalone ForgeSworn libraries. Release and fresh-box/two-phone acceptance remain separate.

Protocol groundwork

NIP-77 / Negentropy

Bothy and Android implement bounded authenticated ID comparison, with Link-only Android transport and strict limits. The primitives do not fetch or retain messages and do not establish automatic replication. Browser Link transport and physical acceptance remain open.

Payments in the full profile
Profile mechanism

LNURLcash / LUD-25 libraries

Bearer-note machinery across language implementations. Notes remain claims on a mint, including when the circle operates it.

Payment products

Moneyer / Notecase

Mint and wallet roles in the wider stack. Their inclusion in the toolbox does not establish an integrated private payment journey inside Vennel.

Profile mechanism / proposed use

escrow-kit / range-proof

Hold-invoice escrow for circle trades and proposed range proofs for mint solvency. BOLT12 offers in wraps and threshold circle mints remain unfinished integrations.

Candidates, related tools and exclusions
Candidate profile use

rendezvous-kit / geohash-kit

Meeting-point and location tooling for in-person introductions. rendezvous-kit declares geohash-kit; adoption in the Vennel client journey was not established.

Candidate profile use

Bray / nostr-bray

Proposed relay classification and publishing support. The manifest confirms the project/package alias. It is not shown as an active Vennel routing requirement.

Reserved work

RelaySwarm

A possible peer-assisted path. The toolbox explicitly reserves swarm work; it is not drawn as an implemented carrier.

Related SDK

signet-nip46-client

The portfolio identifies a Rust remote-signer client. Direct use by the inspected Vennel client or box manifests was not established in this reconciliation.

Internal portfolio tooling

Lodestone

Helps maintain the workshop inventory. It does not sit in the message path, hold user keys or provide a service required by Vennel.

No Vennel dependency established

Other workshop projects

Stash, Gopherkind, Toll/402, games and other portfolio products are not included as Vennel runtime dependencies without evidence of a consumer.

What this map covers

The relevant profile toolbox, the omitted My Signet and signer-tool roles, and dependency families found in inspected manifests. Project and package names are distinguished where they differ.

Third-party foundations include nostr-tools, Noble cryptography packages, Rust Nostr tooling and the Tor/I2P ecosystem. They are not ForgeSworn libraries. This catalogue is not an exhaustive lockfile inventory of every third-party dependency.

Full-profile readiness retains the project's recorded boundaries. This catalogue update does not revalidate a software release, live service or hardware recovery.