The architecture behind Blink.

This page walks through the cryptographic posture and message model that keep Blink private by design. A documented developer surface is on our roadmap — coming soon.

Protocol posture

Direct and group chats use authenticated encryption with keys agreed and derived on your device, and key epochs that rotate every seven days for forward secrecy.

Ciphertext-only by design

Encryption happens on-device before anything is sent. Servers store only ciphertext, and media is encrypted on your device before it is uploaded.

Transaction messages

Transaction messages are an immortal record type for receipts and records that never expire, sealed with the same end-to-end encryption as every other message.

On-device keys

Your device holds only derived keys and an encrypted vault. Keys are generated on-device and never leave it.

// Conceptual: every message is sealed on-device before it is sent.
// Servers only ever see ciphertext.

const messageKey = deriveKey(agreeSharedSecret(myPrivateKey, peerPublicKey), epochInfo);
const sealed = seal(messageKey, plaintext); // authenticated encryption, on-device

await transport.send(sealed); // server stores ciphertext only