
Terminal-based encrypted messenger with post-quantum cryptography, Double Ratchet protocol, and Tor anonymity. Features duress passphrase, deniable authentication, and OS-level hardening via seccomp-bpf and mlockall.
op4 — Secure Terminal Messenger
Op4 is a terminal-based encrypted messaging application written in Rust. It provides end-to-end encrypted private messaging with post-quantum cryptography, routed entirely through the Tor network so that neither the content of your messages nor your IP address is exposed to anyone — not even the person you are talking to.
op4 lets two people exchange private messages without either party revealing their IP address or real identity. Every message is:
op4 runs entirely in the terminal. It has no GUI, no browser component, and no cloud account. The only external process it contacts is the Tor daemon running on your own machine.
All download options — AppImage, source tarball, clone & build, and automated installer — are documented in the Downloads & Install guide. The latest release is available on the Releases page.
On Debian and Ubuntu, install/setup.sh handles everything in one command:
Rust toolchain, build dependencies, Tor, control port configuration, binary
compilation, system user, data directory, and AppArmor profile.
git clone https://github.com/Opfour/op4.git
cd op4
sudo bash install/setup.sh
After the script finishes, you must log out and log back in before running op4. The installer adds your user to the
debian-torgroup so it can read the Tor cookie file. Linux does not apply group changes to already-open sessions — a fresh login is required.Skipping this step will cause op4 to fail at startup with:
Permission denied reading /run/tor/control.authcookie
Then verify the source hash printed by the script matches the published release hash for your version before trusting the binary.
When op4 starts it prints a source hash covering all Rust source files,
Cargo.toml, Cargo.lock, and build.rs. Compare it against the value
below for the version you installed.
| Version | Source hash |
|---|---|
0.3.0 | 80820cb41a63575d2c139dadd425d13d1e87e62a9d60200ae7b894ae2e9ad8ed |
0.3.1 | 48115efb12747fa78b627ddbf7a56c46169f59e777d7d7508941bf89e4fe7521 |
0.2.0-dev | 35740577f6c4a4f19c5a08fe85b1f78a10347f2ba9dd7642d126552266bfa5a5 |
0.1.0 | e1a94761c7d3fa589ba892b47d5295aa417f95aee126809d51a7e7fb7e78982c |
You can also check it without launching the full app:
op4 --print-hash
If the hash does not match, do not use the binary — it was either built from a different commit or has been tampered with.
Install dependencies first, then run the script:
Rust toolchain (pinned to 1.89.0 via rust-toolchain.toml):
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
source "$HOME/.cargo/env"
Tor and build dependencies:
# Fedora
sudo dnf install tor gcc pkg-config openssl-devel
# Arch
sudo pacman -S tor base-devel pkg-config openssl
Configure Tor control port — add to /etc/tor/torrc:
ControlPort 9051
CookieAuthentication 1
sudo systemctl restart tor
Add your user to the Tor group:
sudo usermod -aG tor $USER # Fedora / Arch
You must log out and log back in after this step. Group membership changes are not applied to active sessions. Until you do, op4 will fail with
Permission denied reading /run/tor/control.authcookie.To apply the change without a full logout, run:
newgrp tor
Build and install:
git clone https://github.com/Opfour/op4.git
cd op4
cargo build --release
sudo bash install/setup.sh
op4
# or, without system install:
./target/release/op4
On first launch op4 will guide you through setting a normal passphrase
and a duress passphrase, then generate your identity keys. Your vault is
stored at ~/.local/share/op4/vault.op4.
| Distro | Status |
|---|---|
| Ubuntu 22.04 / 24.04 | Supported |
| Debian 12 | Supported |
| Fedora 39+ | Supported |
| Arch Linux (current) | Supported |
| Tails OS | Supported (setup guide) |
| macOS / Windows / WSL1 | Not supported |
Minimum kernel: 4.15 (5.4+ recommended). Architecture: x86-64 (aarch64 should work but is untested).
Two people each need op4 installed, Tor running, and their vault unlocked. The exchange is asymmetric: one person sends their contact code first, the other adds it, then sends their first message, which arrives as a pending request that the first person accepts.
On first run op4 prompts for a normal passphrase and a duress
passphrase, then generates your identity keys. This only happens once.
Your vault is stored at ~/.local/share/op4/vault.op4.
$ op4
Your contact code contains your full public key bundle and your .onion
address. The other person needs this to reach you.
2 or →)e to export your contact codeop4:Your contact code is not secret. It is safe to share publicly. It contains only your public keys and onion address — no private material.
Once you have their contact code:
a to add a contactop4: contact code and press Enter↑/↓, then Enter)3 or →)This first message initiates the encrypted handshake and is delivered
to their .onion address over Tor. They will see it as a pending
contact request.
When someone sends you a first message, a badge appears on the Contacts tab showing how many requests are waiting.
2)p to review pending requestsEsc to reject and discard)Once accepted, the Double Ratchet is initialised and the conversation is immediately available in the Messages tab.