Ringdrop is a secure, frugal streamed P2P file transfer tool, with ring-based access control, built on iroh-blobs and iroh-rings.
To share a file, associate it with one or more rings and get back an rdrop:// ticket to hand to peers.
Only peers who are members of those rings can download it.
Transfers resume automatically if interrupted — no verified data is re-transferred after a crash or disconnect.
Access control is enforced at the connection level. Ring–resource associations carry typed permissions (Read, Write, Delete). When a peer requests to download a blob, the sender checks that the peer holds Read permission on it — either through ring membership or the built-in open ring — and denies the transfer before any data is sent if not.
- Ring-based access control — share with specific peers or groups via private rings, or open to everyone
- Crash-safe resumption — BLAKE3 bitfield tracks verified chunks; interrupted downloads pick up where they left off
- Verified streaming — every 16 KiB chunk is verified against the BLAKE3 hash tree before being written to disk
- Directory support — import and share entire directories as a single ticket
Here below the available CLI commands; full flag reference in docs/cli.md.
| Command | Description |
|---|---|
rdrop id |
Print your peer-id so others can add you to their rings |
rdrop daemon |
Start, stop, and inspect the background daemon |
rdrop ring |
Manage rings (create, list, add/remove peers, view members) |
rdrop peer |
Manage the local peer address book with optional nicknames |
rdrop import |
Import a file or directory and get a shareable ticket |
rdrop blob |
Full blob lifecycle: import, list, remove, attach, detach |
rdrop receive |
Download from a ticket (automatically resumes if interrupted) |
rdrop grant |
Grant specific rights to remote peers on your local node |
rdrop remote |
Perform a command in a remote node |
| Platform | Quick command |
|---|---|
| Fedora 42+ | dnf copr enable rikettsie/ringdrop && dnf install ringdrop |
| Linux (all distributions) | cargo install ringdrop |
| macOS | brew tap rikettsie/tap && brew install rdrop |
| Windows (PowerShell) | scoop bucket add rikettsie https://github.com/rikettsie/scoop-bucket; scoop install rdrop |
| All platforms (pre-built bin) | cargo binstall ringdrop |
The crate's name is ringdrop; the CLI binary is rdrop, more succinct to type in the command line.
For prerequisites, alternative install methods, and troubleshooting see docs/install.md.
ringdrop-gui is the native desktop app (based on tauri v2) connecting to the same daemon as the CLI — the rdrop CLI and the GUI are both IPC clients, fully interchangeable.
By default ringdrop uses the public relay infrastructure provided by Number 0 (relay.iroh.network). You can point the node to a relay you control by adding a relay_url field to config.json (located in your data directory, ~/.local/share/ringdrop/ by default):
{
"relay_url": "https://relay.yourdomain.com"
}When the field is absent the default n0 relay is used. An invalid URL or an unreachable relay causes the daemon to fail at startup with a clear error rather than silently falling back.
Self-hosting a relay: see the iroh-relay README for instructions on running your own relay instance. Peer discovery (pkarr/DNS) continues to use n0's
iroh.linkinfrastructure regardless of which relay you choose.
rdrop receive saves into the current directory unless you pass --dest. To always save somewhere else, add a default_receive_dir field to config.json:
{
"default_receive_dir": "~/Downloads/ringdrop"
}--dest always takes precedence. A leading ~ is expanded, the directory is created if it does not exist, and an empty value is treated as unset. The setting is read when the daemon starts, so restart it (rdrop daemon stop then rdrop daemon start) after editing config.json. The GUI honors it too, since the daemon resolves the directory.
If you have ideas/contributions or anything is not working the way you expect (in which case, please include an output with RUST_LOG=debug) and feel free to open an issue or PR.
After cloning, activate the pre-commit hooks (it runs cargo fmt --check and cargo clippy before every commit, and tag verifications before every push):
git config core.hooksPath .githooks| ALPN | Purpose |
|---|---|
/iroh-rings/2 |
Blob transfer — gate enforces ring membership and Read permission before any data is transferred |
/ringdrop/catalog/0 |
Catalog queries — lets a peer list the blobs accessible to them on a remote node (requires blob-list grant) |
ringdrop is built on:
| Crate | Role |
|---|---|
| iroh | QUIC transport, NAT traversal, relay fallback |
| iroh-rings | Ring-based access control, grant management |
| iroh-blobs | BLAKE3 chunking, FsStore, verified streaming |
| bao-tree | bao encoding/decoding, ChunkRanges, bitfield conversion |
| redb | Embedded persistent store for the ring registry |
| tokio | Async runtime |
MIT — see LICENSE.
