Two different actions, and confusing them is costly:
- a new place for two or a few — a quick link of five words;
- letting someone into a place that already exists — an invitation from inside that place.
The quick link never leads into an existing space. The interface says so as well, because this is where people make mistakes most often.
The quick link: five words
The me screen, the block “Five words someone can read out loud”.
Five words from a fixed dictionary — you can dictate them by voice, over the phone, over the radio. The link next to them is the same thing, but clickable.
Two doors
| choice | what it means |
|---|---|
| Just us | one device can enter, after which the link closes |
| A few people | 2, 3, 5 or 10 devices; the words live for 1 hour / 24 hours / a week |
Under the buttons it says “devices”, not “people”, and that is not pedantry: the protocol can prove that a device entered, and cannot prove that a specific person is behind it. Promising “one person” would be promising something no signature confirms.
Who decides whether to let them in
Only for the “A few people” option:
| choice | what happens |
|---|---|
| They walk straight in | they enter — and they are inside |
| Let them in myself | the request waits for your answer; you get a strip saying “bob is at the door · let in · not now” |
Until you press “let in”, the guest is not a participant and not a single key has moved. Refusing costs you nothing: an entry is spent on consent, not on request.
What to know about the words
- The words are not stored. They are shown once — copy them right away. The node remembers that a link was issued, but not the words themselves.
- The words are access. Whoever has them can enter. Treat them like a password.
- “Just us” is spent on opening. The first person to enter the words uses the link up; their device remembers the way in. A shared link is not spent that way — it stays open until it expires.
- The quick link goes through a relay. It is the only invitation path that needs the internet: the words have to wait somewhere for the person you gave them to. Without a configured relay the button will honestly refuse.
- It can be revoked — in the list of issued links. Revoking closes the entrance; those who already entered stay.
An invitation from inside a space
The invite button in the space header. This is how something that already exists grows: a conversation between two becomes a group without relocating anyone.
An invitation is a pass: how many entries and for how long.
| field | options |
|---|---|
| who can enter | one entry / up to ten |
| duration | 1 hour / 24 hours / 7 days |
A pass can be copied, shown as a QR code, and revoked. Revoking stops only new entries — those inside stay.
Next to it is a verification phrase: read it out loud to the person you are inviting, so they know the pass really is from you.
Further down is the technical route: invite a specific device by its
device id and public key (the person gets them from their own
“me → Technical details”). Useful when you know exactly whom you are
calling in.
How to join
The join button in the app header. It accepts both five words and a link.
Then the app first shows you where you are going, and only afterwards asks for consent. The preview shows what the link claims and what it costs:
personal → These words are spent. The device has remembered the way.
shared → Shared words — open until <time>. Up to N devices can be let in.
States you may see
| state | what it means |
|---|---|
| request sent | waiting for the owner’s device to confirm; the window can be closed |
| owner’s device is offline | the request is stored and will be delivered when either of you comes online |
| entry confirmed | the space is ready |
| you were turned away | the person decided not to let you in. This is a distinct state, not a failure |
| time ran out | the pass expired; ask for a new one |
| pass revoked | it was closed before the entry was confirmed |
“Turned away” and “something broke” deliberately look different here: the first is someone’s answer, the second is the absence of one.
All of this survives a restart on both sides: the guest’s request and the owner’s queue at the door. You can close the app and come back.
Public places
A public space has a Share link button — the link can be given to anyone, and no joining is needed: it is enough for reading.
If the place is in Community mode, a reader gets Join to write — a separate, deliberate action. Reading never makes you a participant by itself.
A post someone sent you from a public space opens without any joining at all — forwarding.
Meeting over the radio
If no one has internet, you can meet over the radio: your name and key go out on the air, a neighbour sees you in the list and offers a line. No relay and no network are needed for this.
The step-by-step version — radio.