πŸ”—Matrix Live S13E03 – Homeserver Decentralisation Working Group

πŸ”—Dept of Events and Talks πŸ—£οΈ

πŸ”—The Matrix Conference

HarHarLinks announces

πŸ”—Last Call for The Matrix Conference Merch Preorders!

Matrix events such as the Conference are always great opportunities to do something special with merch, with exclusive designs never to return! At least for me that's one of the many parts I love about it, right next to the souvenir value of course! For 2026, we decided that last year's white on black edition conference T-shirt and zipper hoodie were plenty stylish, but we wanted more than a re-run. So we decided to expand up everyone's wardrobe opportunities and are going to have black on white (well, reasonably bright grey) this time around! The embroidering will return for the zipper hoodie because we love the quality, feel, and effect, while the T-shirt will be printed. You also might remember the baseball caps we had at FOSDEM earlier this year. Since Conf is going to be in autumn on the verge of the cold season, we are making embroidered beanies in the classic Matrix white on black to keep your ears warm when you go outside to explore MalmΓΆ in the evening. Finally we noticed there are still parts of your bodies without Matrix clothing available for them, so I'm really excited to introduce the Matrix socks in Sweden's national colours.

Matrix Conf Merchandise preview showing a grey hoodie, a black beanie, and blue and yellow coloured socks and hoodie

All of this can be preordered before the end of July since we have to make sure we keep to production deadlines. We will do our best to make some of each available for spontaneous decisions on site, but cannot guarantee availability there.

Reserve yours at https://conference.matrix.org/register/!

PS: You will need to make sure your preorder is picked up during the Conference in MalmΓΆ, but you can totally order just your merch today if you're not yet sure which ticket you are going to get!

πŸ”—More Volunteering Slots Available

The Matrix Conference is made possible thanks to our awesome sponsors financing it just as well as our awesome volunteer team staffing the welcome desk, operating video equipment, and generally jumping in whenever an extra hand is needed. We have onboarded a lot of volunteers already and our shift booking system was totally booked out while we worked through all these applications from you amazing people, and some have already asked when more will be available. This is (as of writing) the case! If you were waiting for one to free up again, head to our volunteering system and sign up for two shifts to receive a free ticket to the Conference, the limited edition team-only zipper hoodie in special colours, and of course a lot of experience, satisfaction and fun from helping making The Matrix Conference happen!

If you've already signed up a while ago and have received neither an email nor invite on Matrix from us yet, please reach out to us over at #events-wg:matrix.org.

See you soon, your Events WG.

πŸ”—Dept of Working Groups πŸ’ͺ

πŸ”—Homeserver Decentralisation Working Group (website)

The Homeserver Decentralisation Working Group aims to promote decentralisation of the Matrix network by fostering a smoother onboarding experience (to homeservers and clients) on homeservers other than matrix.org, and might propose additional measures in the ecosystem as a whole.

Nicolas Da Mutten announces

I'm happy to report that the Homeserver Decentralisation Working Group graduated from a community group to an official foundation group! Thanks @thedarkwizard:waywardinn.com for sponsoring us and being so proactive! πŸŽ‰

Since our last report, we now finalized our policy. While it is finished in its current form, PRs are still welcome, if something needs to be changed. It's not supposed to be set in stone but rather to be a living document.

Going forward we will be focusing on the process of maintaining and automating the future server list and onboarding servers.

πŸ”—Dept of Spec πŸ“œ

Andrew Morgan (anoa) {he/him} reports

Here's your weekly spec update! The heart of Matrix is the specification - and this is modified by Matrix Spec Change (MSC) proposals. Learn more about how the process works at https://spec.matrix.org/proposals.

πŸ”—MSC Status

New MSCs:

MSCs in Final Comment Period:

Accepted MSCs:

  • No MSCs were accepted this week.

Closed MSCs:

πŸ”—Spec Updates

Lots of updates in spec world this week! New MSCs, MSCs being closed in favour of others or due to lack of time. Don't forget that a closed MSC can always be opened under a new MSC # if someone thinks its worth pursuing - the idea isn't dead forever!

MSC4319 entered final comment period this week. It proposes that additional m.room.member events be included when receiving room state during an invite or knock. This allows for clients (and users) to receive information about who invited them (or knocked on the room), when the invite (or knock) occurred etc.

FCP ends in 3 days, so go and check the MSC out for any last minute additions/changes if this is an area you're interested in!

πŸ”—Dept of Clients πŸ“±

πŸ”—Nexus (website)

Matrix client made with Flutter and a Gomuks backend.

QuadRadical (Ping) announces

πŸ”—What's new?

Hello TWIM! You may have been wondering what has been happening with Nexus, as there hasn't been an update in a while. Well, here it is:

  • Support for OAuth login, and removal of UIAA login

Nexus's OAuth login screen

  • Support for sending media (images, videos, files, etc)
  • Support for viewing pinned events, thanks to @istalri:federated.nexus for this!
  • A settings page

Nexus's settings page

  • Experimental support for MacOS, if you use MacOS please join our support room to help with testing, it's most appreciated!
  • And a whole lot of bug fixes and smaller features!

πŸ”—Get involved!

If you want to help with development or simply keep up with new features, join our Matrix room at https://matrix.to/#/#nexus:federated.nexus or check out the Git repo at https://nexus.federated.nexus!

πŸ”—Fractal (website)

Matrix messaging app for GNOME written in Rust.

KΓ©vin Commaille says

A regression in Fractal 14 meant that display names could not be changed in account settings anymore for some servers. Fractal 14.1 was just released to address this issue. Thanks to Jack S. for discovering it soon after the 14 release!

This version is available right now on Flathub.

If you want to help us avoid regressions like that in the future, you could use Fractal Nightly. You could even get rid of our remaining bugs yourself!

πŸ”—Element X iOS (website)

A total rewrite of Element iOS using the Matrix Rust SDK underneath and targeting devices running iOS 17+.

Doug says

This week we’ve been hard at work with the 3 next features for the app:

  • We saw our first data syncing to the app from Synapse for User Status πŸŽ‰
  • We’re adding support for Media Galleries to match Element X Android. Sending is merged and we’re now iterating on the timeline rendering. πŸ–ΌοΈ
  • Work on Message Search has resumed after some team holidays and is looking really good! πŸ”

Other than that 26.07.4 landed on the App Store on Monday with all the changes mentioned last week.

πŸ”—Element X Android (website)

Android Matrix messenger application using the Matrix Rust SDK and Jetpack Compose.

Jorge says

This has been a quiet week, mostly focused on continuing the work on WIP features like user status, and fixing bugs and accessibility issues.

Element X Android v26.07.1 has been published and it contains all the changes we told you about in previous TWIM messages.

πŸ”—Dept of SDKs and Frameworks 🧰

πŸ”—matrix-nio

OdoItal reports

matrix-nio 0.26.0

This release swaps the end-to-end encryption backend from libolm to vodozemac, drops end-of-life Python versions, and modernizes the project's tooling.

This is a breaking release. Encryption now runs on vodozemac instead of libolm/python-olm, some encryption defaults have changed, and Python 3.9 and older are no longer supported.

πŸ”—βš οΈ Breaking changes

  • Encryption backend replaced: libolm/python-olm β†’ vodozemac. The e2e extra now depends on vodozemac, and libolm is no longer required as a system dependency.
    • Store migration is automatic on first load. Stores created with a libolm pickle version older than 4 (roughly, pre-December 2021) can only be migrated if the optional python-olm >= 3.2.7 package is installed at upgrade time β€” otherwise those pickles cannot be read.
    • hmac-sha256 is gone for SAS verification. Only hkdf-hmac-sha256 is offered as a message authentication code, so verifying against clients that only support hmac-sha256 is no longer possible.
    • Account.remove_one_time_keys() has been removed, as it is no longer supported by the underlying library.
  • Dropped Python 3.8 and 3.9. The minimum supported version is now Python 3.10. Python 3.14 is now supported. Supported: 3.10, 3.11, 3.12, 3.13, 3.14.

πŸ”—Additions

  • Added unread_thread_notifications to SyncResponse.

πŸ”—Bug fixes

  • Fixed get_openid_token, which requires an empty JSON body to be sent.
  • Fixed printing of FileResponse when a download is saved to a file.

πŸ”—Internal / maintenance

  • Adopted uv for project management, applied pyupgrade and linting, and bumped dependencies.
  • Unpinned dependencies for more flexible version resolution.
  • Upgraded the underlying vodozemac to 0.10.0.

πŸ”—vodozemac-python (website)

Python bindings for vodozemac, the implementation of Olm and Megolm in pure Rust.

OdoItal says

vodozemac-python 0.10.0

This release upgrades the underlying vodozemac Rust library to 0.10.0. The Python package version tracks the Rust crate, so this is 0.10.0.

This is a breaking release. The public Python API is nearly unchanged, but several operations that previously always succeeded can now raise an exception, and Python 3.9 is no longer supported.

πŸ”—βš οΈ Breaking changes

  • Some operations are now fallible. As of upstream vodozemac 0.10.0, Diffie-Hellman can reject malicious/low-order keys, which makes the following methods able to raise where they previously always returned a value:
    • Account.create_outbound_session β†’ may raise SessionCreationException
    • Session.encrypt β†’ may raise the new OlmEncryptionException
    • PkEncryption.encrypt β†’ may raise PkDecodeException Method signatures are unchanged; wrap these calls in error handling if you process untrusted keys.
  • Stricter Ed25519 signature verification is now mandatory. Non-strict verification has been removed upstream. Signatures that were maliciously crafted and previously accepted may now be rejected.
  • Dropped Python 3.9. The minimum supported version is now Python 3.10. Python 3.14 is now supported. Supported: 3.10, 3.11, 3.12, 3.13, 3.14.

πŸ”—Additions

  • New OlmEncryptionException, raised on Olm encryption failures (mirrors the existing OlmDecryptionException).

πŸ”—Internal / maintenance

  • Upgraded pyo3 0.28 β†’ 0.29 and maturin to 1.14.
  • Bumped thiserror and refreshed transitive Rust and Python dev dependencies.
  • Session configuration continues to use protocol version 1 for all Olm/Megolm sessions; this is unchanged from 0.9.

πŸ”—Dept of Ops πŸ› 

πŸ”—Matrix Connectivity Tester (website)

A web interface to debug and troubleshoot Matrix connectivity issues.

MTRNord (they/them) reports

I just released v0.1.0 (and v0.1.1) of the elixir connectivity tester. This one's a bigger change than the last few: the Rust backend and the separate frontend are now merged into a single Elixir/Phoenix app that ships the web UI, API, alerting, and an OAuth2/OIDC provider together in one deployable unit. Development also moved off GitHub, so the old two-repo setup is gone.

πŸ”—What's Changed

  • Unified the previously separate backend (Rust) and frontend into one Elixir/Phoenix app. All existing checks (federation, DNS/well-known, TLS, split-brain detection, MatrixRTC, the OAuth2-backed alerts) carried over
  • New federation checks along the way: an outgoing-federation self-check (does the target server actually reach us back over federation, not just the other way round) (thanks @networkexception:nwex.de for that idea!), dual-stack/protocol asymmetry detection, and signing-key-expiry warnings
  • Public opt-in statistics page now also breaks down MSC/unstable-feature adoption by server software family and timeframe, not just plain pass/fail counts
  • Permalinks: freeze and share the exact result (federation check + client-side probe) you saw, instead of asking someone to re-run the check themselves
  • Export a result as JSON, Markdown, or print/Save-as-PDF
  • Shields.io-style status badge for READMEs (/api/badge/federation.svg)
  • Batch endpoint to check several servers in one call
  • Full OpenAPI spec with an interactive Redoc UI at /api-docs
  • Uptime percentage (7d/14d/30d) per alert in the alerts overview
  • Docs search across the built-in /docs pages
  • Cookieless analytics via self-hosted Plausible (no personal data, no cookies)

Code moved to self-hosted Phorge: https://phorge.mtrnord.blog/source/mcte/repository/main/. The old GitHub repos are no longer where development happens.

Find the deployed version at https://connectivity-tester.mtrnord.blog or, if you're daring, https://stage.connectivity-tester.mtrnord.blog for the staging deployment, which gets changes earlier but at less stability.

If you find issues or want to request features, please direct them at the Phorge repository or the Forum at https://forum.mtrnord.blog/c/matrix-connectivity-tester/5 :)

Weblate has also been updated for this project pivot to elixir. You can find the components over at https://weblate.mtrnord.blog/projects/matrix-connectivity-tester-elixir/

πŸ”—Dept of Interesting Projects πŸ›°οΈ

nex [starstruck] reports

star rewrote my mxtoken tool so that it doesn't explode if you use a machine other than my own: https://starstruck.systems/mxtoken2. It additionally also properly supports SSO. The legacy mxtoken will continue to show existing sessions prior to the rewrite, but no new sessions can be created through it. Use star's rewrite for that.

I don't think I've announced mxtoken before, so for those who haven't already heard about it, mxtoken is a visual (web) interface that supports various login methods to fetch access tokens, which can safely be re-used in bots, webhooks, curl requests, etc, as they do not set up crypto and are not bound to a browser. It stores all sessions in localstorage, and has a couple management options for refreshing tokens and logging out devices.

πŸ”—Matrix Federation Stats πŸ“Š

Aine [etke.cc] says

TWIM

collected by MatrixRooms.info - an MRS instance by etke.cc

As of today, 19800 Matrix federateable servers have been discovered by matrixrooms.info, 4163 (21.0%) of them are publishing their rooms directory over federation. The published directories contain 20314 rooms.

The most popular server software among the online servers is:

  • synapse: 15528 (78.4%)
  • continuwuity: 1669 (8.4%)
  • conduit: 559 (2.8%)
  • dendrite: 322 (1.6%)

Stats timeline is available on πŸ“Š MatrixRooms.info/stats

🧩 Integrations with apps and servers | πŸ’œ Support the project | πŸ‘‰ How to add your server | πŸ™… How to remove your server

πŸ”—Dept of Ping πŸ“

Here we reveal, rank, and applaud the homeservers with the lowest ping, as measured by pingbot, a maubot that you can host on your own server.

Join #ping:maunium.net to experience the fun live, and to find out how to add YOUR server to the game.

RankHostnameMedian MS
1nerdhouse.io268
2cisnt.uk338.5
3ncat.cafe383
4ellis.link435
5victorewik.es458
6matrix.maciej.cloud469
7feralfox.net559
8blahaj.club881
9beeper.com1248
10cwt.grin.hu2706.5

πŸ”—That's all I know

See you next week, and be sure to stop by #twim:matrix.org with your updates!

To learn more about how to prepare an entry for TWIM check out the TWIM guide.

The Foundation needs you

The Matrix.org Foundation is a non-profit and only relies on donations to operate. Its core mission is to maintain the Matrix Specification, but it does much more than that.

It maintains the matrix.org homeserver and hosts several bridges for free. It fights for our collective rights to digital privacy and dignity.

Support us