Optionalaudit?: AuditSinkOptionalauditContext?: AuditContextOptionsRequired when audit is set; contains stable engine/account/session metadata.
Optionalcapabilities?: CapabilitiesThe capabilities to use for the client
OptionalclientId?: stringDefault d tag value (slot identifier) for key package events.
Used by KeyPackageManager.create when no explicit d is passed.
Set this to a stable per-device string (e.g. "my-app-desktop") so all
key packages from this client share a single addressable slot on relays.
OptionalconvergencePolicy?: ConvergencePolicyConvergence policy applied to every group: branch selection and the
maxRewindCommits rollback horizon. Set maxRewindCommits: Infinity to
preserve the whole MLS history and keep forks of any age eligible for
re-convergence. Defaults to the profile-1 policy
(DEFAULT_CONVERGENCE_POLICY).
OptionalcryptoProvider?: CryptoProviderThe crypto provider to use for cryptographic operations
The backend to store and load the groups from
OptionalingestionPool?: IngestionPoolOptionsIngestion-pool tuning applied to every group: max entries and max epoch-age
for undecryptable events held and retried as history grows. Defaults bound
it; a debugging tool that retains and processes everything can raise both
(e.g. a large maxSize and a very large maxRewindCommits).
OptionalingestStateStore?: GenericKeyValueStore<Uint8Array>Durable terminal-wrapper and convergence-effect evidence.
OptionalinviteStore?: GenericKeyValueStore<StoredInviteEntry>Key value store for the InviteManager class, if non is provided an InMemoryKeyValueStore is used
The backend for key package private material and publish tracking
OptionallifecycleStore?: GenericKeyValueStore<Uint8Array>Durable backend for group lifecycle intent and terminal records. When omitted, lifecycle records share groupStateStore through a disband-key-scoped adapter.
The nostr relay pool to use for the client. Should implement GroupNostrInterface for group operations.
OptionalremovedMarkerStore?: GenericKeyValueStore<boolean>Dedicated backend for the persisted removed-inactive marker (D-12), keyed
by group-id hex like groupStateStore. When provided, the fact that an
involuntary removal was already realized survives a restart, so the
removed event fires exactly once across process boundaries and a
re-convergence that supersedes the removing commit can clear it durably.
Back it with the same durable backend as groupStateStore. Optional —
when omitted, realization is in-memory-only and does not survive a restart.
OptionalrewindStore?: GenericKeyValueStore<Uint8Array>Dedicated backend for the per-group full-fork history tree (the single
persisted source for fork recovery and the MarmotGroup.forkTree
API). When provided, the tree is persisted so fork recovery survives a
restart; back it with the same durable (ideally encrypted) backend as
groupStateStore. Optional — when omitted, history is in-memory only and is
rebuilt from the current tip after each restart.
The signer used for the client's Nostr identity. Also signs the kind-450 account identity proof carried by every KeyPackage and leaf this client creates.
OptionalverifyEvent?: VerifyEventMethodInjectable Nostr event verifier gating the inbound trust boundary (SEC-01)
across all three entry points: the 445 group-message drain, the 1059
gift-wrap ingest, and the 30443 KeyPackage publish/track path. Defaults to
applesauce's verifyEvent (real BIP-340 Schnorr signature verification).
Callers that trust their event source upstream (e.g. already verified by
a relay pool) may inject fakeVerifyEvent instead, or supply a
native/WASM verifier for performance — do not introduce a separate
boolean skip-verification flag.
Optional forensic audit sink inherited by groups. Omitted by default.