Stegstr
Steganographic messaging on Nostr

Hide a message in a photo. Send the photo anywhere.

Stegstr embeds encrypted messages and Nostr posts inside ordinary JPEG images. The hidden data survives the recompression and resizing that WhatsApp, Telegram and Instagram apply, and the recipient reads it with Stegstr. No account, no registration, and in local mode nothing ever leaves your device.

Use it in your browser

Embed and detect right now. Runs entirely in the page; nothing is uploaded.

Open the web app

Download the app

Mac, Windows and Linux. Adds the feed, direct messages and relay sync.

Get the desktop app

Drive it from code or an agent

A command line with no install step, an MCP server, and a scriptable API in the running app.

Read the agent guide

How it works

Write

A message, a post, or your whole feed. It is encrypted before anything touches an image.

Embed

Pick a detailed photo. Stegstr hides the data in the frequency domain of the image and checks it can read it back before saving.

Send anywhere

WhatsApp, Telegram, Instagram, email. The default method survives recompression and rescaling; the photo still looks like the photo.

Detect

The recipient drops the image on Stegstr and the message appears. Older Stegstr images from any earlier version still open.

What is in the box

Three hiding methods

Robust (default, survives resizing, three payload sizes), QIM (platform-targeted JPEG), and Dot (lossless PNG, largest capacity). Stegstr tries them all when reading.

Local or online

Network is off until you turn it on. On, the app syncs posts and DMs over Nostr relays, with the Stegstr relay as the default home.

Verified before it ships

Every embed is decoded back before the file is written. Received events are signature-checked before they are shown.

Built for agents too

A dependency-free Node CLI, a Rust CLI with JSON output and stable exit codes, an MCP server, and window.stegstr inside the app.

Open source, MIT

One repository, one place to file issues, a documented way to add a hiding method without forking.

Made by a contest

Built from the winning entry and the best parts of the runners-up in the 2026 Stegstr contest. See the leaderboard.

What does not survive: rotation, crops beyond about two percent per edge, and screenshots. Stegstr says so in the app rather than pretending otherwise.

Made by a contest, open to everyone

Stegstr's current code came out of a 2026 contest: 119 entries, 18 finalists tested with a blind gauntlet and an interaction battery, and a winner chosen on the measurements. The people who built the pieces are named, their work is credited in the source, and the same tests gate every change now. Read how it ran, who built what, and how to take part.

For AI agents

Everything an agent needs is in plain text at /llms.txt and /agents.txt, with copy-paste commands on the agent guide. The shortest path from nothing to a stego image:

git clone https://github.com/brunkstr/Stegstr.git && cd Stegstr
node dist-cli/stegstr.mjs embed cover.jpg -o out.jpg --payload "hello" --json
node dist-cli/stegstr.mjs detect out.jpg --json