Peridot

Own your settings.

You own the machine. Peridot makes sure you own what's on it: every Omarchy computer you use stays matching, your whole setup is backed up where nobody can read it, and six words bring it back on a bare install. No account. No cloud. Nothing that can change the terms on you.

$ omarchy plugin add https://github.com/derekross/peridot.git --enable
$ ~/.config/omarchy/plugins/derekross.peridot/dist/install.sh

Free software, for Omarchy on Arch. The installer asks before it touches anything.

ghostty ~
$ cat manifesto.txt own the machine.own the network.rebuild the internet. $ peridot own your settings.

The rented web keeps your dotfiles in someone else's drawer

Every other way to carry your setup between computers goes through an account: a private repo, a sync folder, a vendor's cloud. Each one comes with a login you don't control and a page like these.

Your account has been suspended.Appeal reviewed in 30 business days.
We've updated our Terms of Service.Continued use means you agree.
Free API access ends Friday.Upgrade to keep syncing.
Sign in to keep reading.Your session has expired.
Your data export is not available.Try again later.
Not available in your country.We're working on it.

Peridot has no account to suspend, no terms to update, and nothing readable to hand over. Your settings leave your computer encrypted, and only your computers can open them.

Change it once. It's on every computer you own.

Rebind a key on the desk and the laptop offers it before you've stood up. Hyprland, the bar, the menu, your terminal, btop, starship, tmux, lazygit, mpv. Your theme, and the themes and plugins you installed.

Nothing changes on a computer until you apply it, unless you turn on automatic apply. Files that can run commands are always shown to you first. Every apply can be undone.

Two computers editing the same file is a conflict, not a coin toss: Peridot keeps both and lets you choose.

Desk ~/.config/hypr/bindings.lua edited
14bindd("SUPER", "return", "Terminal", "exec", "ghostty") 15bindd("SUPER", "B", "Browser", "exec", "brave") 16bindd("SUPER", "F", "File manager", "exec", "nautilus")
DeskAh+hfrFVD/uqbPBPY9uA7rn5jjNEDJkBPOwBXQI7znXF2EH0pDrelaysoFZJ5BjcGi+9xinbHAn6YmwmccMcubiW6bJWgdEIE6po5oOf0ULaptop
Laptop Peridot
1 setting changed on Desk · Apply 15bindd("SUPER", "B", "Browser", "exec", "brave")

Your disk dies at 2 a.m. Your setup doesn't.

Everything Peridot syncs is also your backup, encrypted, on servers that cannot read it. The recovery kit is a page to print or save, plus six words to write down.

canopyglidersulfurmammaldizzyoverlap

Together, the page and the words bring every setting back. Apart, they are useless to anyone who finds one of them.

  1. 02:14Disk gone. Fine.
  2. 02:20Fresh Omarchy on the spare laptop.
  3. 02:23Install Peridot, choose "Use my recovery kit", type six words.
  4. 02:24Keybindings, theme, terminal, bar, plugins: offered, applied, yours again.

Or skip the words: pair the new laptop from any computer you already use, and it gets everything from there.

Own the network. It knows nothing about you.

Peridot moves your settings over Nostr, an open network of servers anyone can run, including you on a homelab. Pick the relays you trust, or run your own. No relay is special, and none of them is told anything.

Every file is encrypted on your computer before it leaves. Its name is a keyed hash, its size is padded to one of four classes, its timestamp is rounded to the hour, and it is signed by a key that is not your identity. Take a relay's disk and you hold blobs that say nothing.

The full protocol is public, in NIP.md, so anyone can check this rather than trust it.

relay.example what it stores for you
d 7c1e0f4a9b2d8e6f3a5c1b0d9e8f7a6b at 14:00 size 4096 Ah+hfrFVD/uqbPBPY9uA7rn5jjNEDJkBPOwBXQI7znXF2EH0pDoFZJ5Bj… d 2a9f6c3e1d8b4a7f0e5c9d2b6a1f8e3c at 14:00 size 1024 cGi+9xinbHAn6YmwmccMcubiW6bJWgdEIE6po5oOf0UpP//yH1yis1Dh… d e4b1d7a2c9f0e6b3a8d5c2f1b7e0a9d4 at 15:00 size 16384 W/A4xqKU68CKetV2LUa5w5VmO2bAZ18ol3GQbWLy+uIaiZi4nMAbpDeb6M… author a01ed833… (not you) whose? unknown what? unknown how big? unknown

Two ideas that agree

Own the machineOmarchy

A computer you understand, configured in files you can read, with no tollbooths and no gatekeepers between you and it. Your setup is yours, down to the keybinding.

Own the networkNostr

Your identity is a key you hold, not an account someone grants. Servers are interchangeable and expendable. Nobody can suspend you, and nobody can change the terms on you.

Peridot is where they meet: a setup you own, carried by a network you own, readable by no one else. And because your identity is a standard Nostr key, it is already yours to use anywhere else on Nostr, with Opal or any client.

Everything else that rides along

Pair a new computer in a minute

The new one shows a code. Type it on one you already use. Both screens show the same six digits, you both say yes, and it joins. Someone who glimpsed the code cannot: the digits come from a secret exchange the code only starts.

Private links

Share a screenshot, a file or your clipboard from Omarchy's Share menu. Encrypted on your computer; the key rides after the #, the part of a link a browser never sends to a server. Links expire in a week unless you say otherwise, and can be pulled any time.

The Gallery

Every theme and plugin from the community catalogs, with likes and reviews from real Omarchy users, ranked by the people you follow. Install in a click. Publish your own setup so someone else can run it whole.

Peridot's panel on a newly paired laptop, offering the desk's settings

What follows you, and what never does

On by default: Hyprland settings, the bar layout, menu additions and branding, terminal configs, btop, starship, tmux, lazygit, mpv, and your theme, themes and plugins.

Off until you turn them on, because they can run commands: what starts at login, .bashrc, Omarchy hooks, Neovim, Git settings, default apps.

Never, whatever you turn on: keys, tokens, keyrings, browser and Signal profiles, your monitor layout and input devices, and anything that looks like a secret.

~/.config as Peridot sees it
hypr/bindings.lua looknfeel.lua hyprland.lua hypr/autostart.lua ask first hypr/monitors.lua input.lua stays here omarchy/shell.json extensions/ branding/ ghostty/ kitty/ alacritty/ foot/ btop/ starship.toml tmux/ lazygit/ mpv/ nvim/ git/config .bashrc ask first .ssh/ .gnupg/ keyrings/ *token* *.pem never

Said plainly

  • Relays and file servers, even public ones, cannot read your settings or link them to you.
  • Someone who saw a pairing code cannot join. Both people confirm a number the code alone cannot produce.
  • A file that can run commands is never applied without you seeing it, and never keeps an exec bit.
  • A removed computer stops receiving anything new. What it already had stays with it; nothing can wipe it from afar.
  • The daemon runs sandboxed: your home is read-only to it except the settings it syncs, and it reaches the session bus only through a filter.

And what no software can promise

Code already running as you can read the keyring, the socket and the files. Whoever holds your sync secret can push settings that run commands on your other computers, which is what syncing is, so every such file is shown first. A key kept in your login keyring is exactly as safe as your login and your disk encryption; Opal takes it out of Peridot's hands entirely.

Peridot is new. It works end to end, and it says so when it isn't sure. Report a problem as described in SECURITY.md.

Install

Any Omarchy on Arch. The installer records everything it writes, checks every path before it changes anything, and asks before adding Private link entries to the Share menu. Without Rust it downloads the release build and checks it against a hash pinned in the source.

$ omarchy plugin add https://github.com/derekross/peridot.git --enable
$ ~/.config/omarchy/plugins/derekross.peridot/dist/install.sh

Needs xdg-dbus-proxy for the sandbox: sudo pacman -S --needed xdg-dbus-proxy. The installer stops and says so if it is missing.

Update

$ omarchy plugin update derekross.peridot
$ ~/.config/omarchy/plugins/derekross.peridot/dist/install.sh

Remove

$ ~/.config/omarchy/plugins/derekross.peridot/dist/uninstall.sh
$ omarchy plugin remove derekross.peridot

Removing takes out only what Peridot can verify it wrote. A file you edited stays, and the output says so.