Envelope is a tool I built for opening a Nostr app in a particular state from a link or QR code.
A link can select the app and carry the context it should receive: a message to display, for example, or a particular floor in a building explorer. Sharing that link shares the starting point for the experience.
How it works
Envelope runs as an nsite, a static site published through Nostr, using a customized Paja runtime. It launches signed napplets, small apps described by NIP-5D manifests.
The URL fragment carries the app pointer and launch state. A separately published, signed opener decodes that fragment, asks the runtime to load the target, and delivers the state after the target signals that it is ready. The runtime verifies the signed pointer and app content before use.
Because URL fragments are not sent in HTTP requests, the launch payload stays out of the gateway’s request URL. Envelope also supports encrypted fragments. The target app receives the state through an explicit intent contract, so it needs to support that incoming context.
Try the QR demo
The QR demo includes building-explorer links and message examples. Each link carries its complete launch payload and opens the corresponding published napplet.
Envelope also resolves content-addressed Blossom resources used by apps such as Mapplets and Mappy.
Self-contained launch state
The complete launch state is contained in the URL fragment. Envelope decodes it directly from the link; it does not fetch that state from a server. Decoding the launch state needs no internet connection and does not depend on having opened the link before.
Loading the runtime and app code is a separate concern. Envelope can cache those resources for offline use, while an app’s own network-dependent features may still need connectivity. The launch state itself always travels with the link.