Nectenda

by Nectenda
5
4
3
2
1
Score: 50/100

Description

End-to-end encrypted real-time collaborative editing for Obsidian.

Reviews

  • Cedric Lau
    Reviewed on Oct 1st, 2026
    No review text provided.

Stats

0
stars
254
downloads
0
forks
13
days
1
days
1
days
0
total PRs
0
open PRs
0
closed PRs
0
merged PRs
0
total issues
0
open issues
0
closed issues
13
commits

Latest Version

a day ago

Changelog

Nectenda 0.3.0

Added

  • Canvases are collaborative. Two people moving different cards, or typing in the same card, both keep their changes instead of getting a conflict copy.
  • Open canvases are live: you see other people's moves, edits and typing as they happen. Their mouse pointers show with their names, and stick to the edge of the canvas when they are off-screen. Text they select inside a card is highlighted in their colour. Undo steps back only your own changes.
  • On a live canvas you see a collaborator's caret, with their name, inside the card they are typing in. A card someone is typing in is outlined with their name even when you are only looking at it.
  • Click a person's circle in the header to jump to them: in a note, to their cursor, or to their pointer if they have no cursor there; on a canvas, to their pointer or to the card they are typing in.
  • Invite someone to a shared folder by email in one step, from the folder's right-click menu, the command palette or the folder's people list. They get the folder as soon as they join.
  • Your vault now shares a folder's key with new members automatically. It refuses if a collaborator's key has changed since you last shared with them.
  • A folder someone shares with you is offered once its key arrives: "shared a folder with you — Add to this vault".
  • The people list shows whether you have compared each collaborator's key fingerprint, with a "Mark as compared" button, and lists pending invitations. Editors can open it too, not only owners.
  • Settings are reorganised. There is a "This vault" list with a page per shared folder, "Shared with you" for invitations and folders waiting to be added, a short "Get started" list, and Security, Editing and Advanced pages. Names are clearer throughout ("Stop syncing here", "Add to vault", "People").
  • Choose where Nectenda's status appears: each note's header, the ribbon (now the Nectenda logo) or, on desktop, the status bar. Each shows the same icon and opens the same menu, which lists who is in the note, anything waiting for you, and the folder's settings.
  • New commands: open a shared folder's settings, add a folder shared with you, join an organisation with a link, and forget your passphrase on this device.
  • Right-click a synced folder, or a note in one, for "Nectenda: Folder settings…". Owners also get "Invite to folder…" on notes.
  • Shared folders have an accent-coloured indentation guide in the file explorer, and a note a collaborator changes briefly pulses there.
  • User guides are published at nectenda.com/docs. A new install shows one notice pointing to Nectenda's settings.
  • Owners and admins can turn their organisation's share link off, or replace it with a new one, from the organisation page. The old link stops working at once.
  • If you have lost both your passphrase and your recovery key, you can start over with a new, empty account under the same email address. The reset waits seven days, and any device still signed in can cancel it. A vault left open notices such a request within the hour, or when you return to the window.

Fixed

  • A note's text could be copied into a different note when two notes were open in split panes.
  • A key typed the moment a shared note's pane became active could be erased.
  • A collaborator's cursor and name no longer flash while they type.
  • Deleting or renaming a canvas that was shared before canvases merged no longer brings the old file back on the next restart.
  • A phone or computer that was already signed in when you joined an organisation on another device now syncs that organisation's folders, instead of adding them and staying empty.
  • Adding a shared folder no longer reuses an existing folder of the same name that already holds notes. It goes to " (shared)" instead, so those notes are not shared by accident.
  • The dot and number on the Nectenda status icon now scale with the icon and sit evenly at its corners.
  • The recovery dialogs consistently say "passphrase".

Known

  • Everyone sharing a canvas should update to 0.3.0. A collaborator on an earlier version still syncs canvases as whole files. Their edits reach you as conflict copies beside the canvas, and yours do not reach them. Nothing is lost, but the canvas does not merge until they update.
  • When two people change the same thing on a canvas at once, such as the same card's position or colour, one change is kept and the other person gets a conflict copy of the canvas beside it, with a notice. A card someone deletes can come back if another person was editing it at the same time.
  • If a collaborator moves a card while you are dragging it, your drop wins its position.
  • Live canvases rely on parts of Obsidian that it does not document. If an Obsidian update changes them, the canvas stops being live, with a notice, and syncs through the file instead, as it does before its document is ready. Then it reloads when someone else changes it: you can lose your place in a card you are typing in, undo can undo other people's changes, and a keystroke or change made in the same instant as a remote one can be overwritten.
  • A collaborator's caret shows only while their Obsidian window has focus. Inside an embed in a canvas card, the card is outlined with their name but no caret is drawn.
  • Live canvases have not been run on a phone.
  • Collaborators still on 0.1.5 or earlier will appear to have no cursor. Their edits sync normally.
  • iOS is untested on a device. It should work — it is the same JavaScript as Android — but nobody has run it on an iPhone, so it is not claimed.
  • On Android, all vaults in the app share one secret store: signing one vault in signs them all in.
  • There is no read-only membership. Everyone in a shared folder can edit it.
  • Not audited. The client ships unminified and the build is reproducible, so the claim is checkable — but no third party has checked it.

Installing

Install main.js, manifest.json and styles.css into .obsidian/plugins/nectenda/.

Verifying this build

The bundle is not minified. The code that encrypts your notes is the code you can read, and you can confirm this release was built from this source:

sha256(main.js) = 892589a487f426e13e9060ce41ca9bc76112f8d690abf508d58bec3177f51551
git clone <this repo> && cd nectenda-plugin && git checkout 0.3.0
pnpm install --frozen-lockfile && pnpm build
shasum -a 256 packages/plugin/main.js

The toolchain is part of the answer: packageManager in package.json pins the pnpm version, and the recipe above uses it. A different package manager produces a byte-different bundle with identical behaviour, because esbuild records each module’s resolved path in a comment.

Built from nectenda@47f9d38.

README file from

Github

Nectenda

End-to-end encrypted real-time collaborative editing for Obsidian.

Live cursors, offline editing, shared folders and attachments — on a server that cannot read your notes. Content is encrypted on your device before it is sent; the server stores ciphertext it has no key for, and document paths are HMACs rather than filenames.

This repository

The Obsidian plugin and the shared library it is built from, source-available under the PolyForm Shield License 1.0.0.

This is the code that does the encrypting, and it is why the repository is published: every security property Nectenda claims is enforced here, on your device, before anything leaves it. The server relays ciphertext it cannot read and is not published — doing so would prove little, since nobody can verify which build an operator is actually running.

Start with docs/security-model.md: it states exactly what the server can and cannot see, and names the code implementing each claim so you can check rather than believe.

The published main.js is not minified, so the file that runs in your vault is one you can read directly.

This plugin requires an account and a server

Nectenda is a client for a sync server. It does nothing on its own: there is no offline-only or local-only mode, and with no account nothing syncs. Say so plainly before you install it.

There are two ways to run it, and they differ in what reaches us:

Hosted at nectenda.com. We operate the server, so your encrypted notes pass through our infrastructure and are stored on it. We cannot read them: content is encrypted on your device before it is sent, the keys that decrypt it never leave your device unencrypted, and document paths are HMACs rather than filenames. What the server does see is real and is listed exhaustively in docs/security-model.md — which accounts share which folders, update sizes and timings, device records, and the display name you choose for a shared folder. Signing in talks to accounts.nectenda.com, the one address the plugin knows without being told.

A server you run. The plugin talks to whatever address you give it, and a vault pointed at your own server sends us nothing at all — not the ciphertext and not the metadata above. The server is not something you can obtain today: it will be sold as a licensed image, and that is not yet available. Said here because the plugin will happily connect to a self-hosted server and you should know which of the two you are in.

Both modes run the same encryption. The plugin talks to the server you point it at and to no third party.

What leaves your machine

Nothing about what you do. There is no analytics of any kind.

When you are signed in to the hosted service, the plugin reports its own crashes to an error tracker Nectenda runs itself — not a third party. It is on unless you turn it off, and it sends nothing until it has shown you what a report contains. A report carries the exception and its message, stack frames as line and column numbers in the published main.js, the plugin and Obsidian versions, the platform, and the install identifier every request already carries. It carries no note content, no note, folder or attachment name, no file path, not your vault's name, and no token or key.

The payload is built from a fixed list of fields rather than filtered down from a larger one — packages/plugin/src/error-report.ts, and there is no error-reporting library behind it, because a library owns the event and we would be subtracting from it. docs/security-model.md states the rule and names the code.

Running your own server? None of this applies. The address reports would go to is supplied by the server you sign in to; a self-hosted one supplies none, so none are sent.

Installing

Install it from Obsidian's plugin directory, or find it under Settings → Community plugins → Browse inside Obsidian.

By hand, from the latest release: take main.js, manifest.json and styles.css, put all three in <your vault>/.obsidian/plugins/nectenda/, and enable the plugin under Settings → Community plugins.

Then open Settings → Nectenda and sign in. Signing in creates your own organisation on the free plan; share a folder from the plugin's pane and anyone you invite sees your edits as you type.

What changed in each version is in CHANGELOG.md.

What it costs

The plugin is free and always will be. The hosted service is what is paid for, and an organisation is the billable unit — a person can belong to several and takes one seat in each.

Price Seats Devices per seat Attachments
Free — 3 2 none; text sync only
Personal $5/mo or $48/yr 6 3 10 GB
Team $6 per seat/mo up to 10 4 20 GB + 5 GB per seat
Small Business $18 per seat/mo up to 25 6 100 GB + 20 GB per seat

Free is not a trial: it does not expire and it is not a reduced version of a paid plan. Text sync is never blocked on any plan, and nothing is deleted if you stop paying — an organisation that lapses returns to Free with everything it stored still downloadable.

Plans are bought inside Obsidian rather than on a web page, because the keys that encrypt your vault are derived on your own device from a passphrase that never reaches us. An account cannot be created for you remotely; the last step is always yours. Full pricing at nectenda.com/pricing.

Build

pnpm install
pnpm build          # produces packages/plugin/main.js

Building it yourself is the point of publishing it: scripts/verify-build.mjs rebuilds from this source and compares the result byte for byte against the main.js in a release, so you can check that the file you installed is the file you just read.

Documentation

  • Security model — what the server can and cannot see, the exact cryptographic parameters, and what is deliberately not claimed

Licence

PolyForm Shield 1.0.0 — source-available, not open source.

Any purpose is permitted, commercial use included, except providing a product that competes with Nectenda. Reading this code, auditing it, modifying it for your own use, and building it to check the result against the main.js you installed are all expressly permitted — that is what publishing it is for.

If you redistribute any part of it, PolyForm Shield requires you to pass on the licence terms and this line, which also travels inside every built main.js:

Required Notice: Copyright (c) 2026 Nerchure Ltd (https://nectenda.com)

Getting help, and reporting a vulnerability

Support: [email protected] — accounts, subscriptions and refunds. We reply within three business days.

Security: if you have found a vulnerability, please write to [email protected] rather than opening an issue, and give us a reasonable chance to fix it before disclosing. We will confirm receipt within three business days, tell you what we find, and credit you unless you would rather we did not.

Every claim in docs/security-model.md is meant to be checkable against this code. If you can show one of them is wrong, that is the report we most want.


Generated from Nectenda's development repository; issues and pull requests are welcome here, and changes are applied upstream and mirrored back.