NexaChat — End-to-End Encrypted Real-Time Messaging Platform
High-security real-time messaging platform engineered with Next.js 16, Express, Socket.io, MongoDB, and zero-knowledge client-side End-to-End Encryption (ECDH NIST P-256 + AES-GCM 256).
Demo Accounts & Test Credentials
2 Test RolesUse these pre-configured accounts to test live features across different user roles without registering.
••••••••••••
Technologies & Architecture Stack
Project Overview
NexaChat is an enterprise-grade, high-security real-time messaging platform engineered with Next.js 16 (App Router), React 19, TypeScript, and an Express.js / Socket.io backend. The platform provides true zero-knowledge privacy through browser-native End-to-End Encryption (E2EE) powered by the Web Crypto API (SubtleCrypto). Asymmetric key agreement using ECDH (NIST P-256) establishes ephemeral 256-bit AES-GCM symmetric session keys directly between communicating peers, guaranteeing that private keys never leave client-side IndexedDB vaults and the server never encounters unencrypted plaintext.
The Engineering Problem
Most modern web-based chat applications suffer from critical security and privacy flaws: 1. Server-Side Plaintext Exposure: Messages are either transmitted in plaintext over WebSockets or decrypted on the server before database insertion, exposing private user communications to database breaches, rogue server admins, or MITM interception. 2. Inefficient Crypto Dependencies: Third-party JavaScript crypto bundles add significant bundle bloat, lack side-channel resistance, and introduce supply-chain vulnerabilities. 3. Broken Real-Time Synchronization: Synchronizing message states (read receipts, delivery indicators, dynamic online presence, and message retraction) across concurrent mobile and desktop clients without causing UI race conditions or data loss is notoriously difficult. 4. Responsive Mobile Keyboard Layout Shifts: Dynamic virtual keyboards on iOS and Android frequently break viewport height calculations in standard CSS chat boxes.
The Solution
Architected a zero-knowledge real-time messaging system rooted in native browser cryptography and reactive WebSockets: 1. Zero-Knowledge E2EE Protocol: Integrated the native Web Crypto API (window.crypto.subtle) without third-party dependencies. Users generate ECDH NIST P-256 keypairs during registration; private keys are stored exclusively in IndexedDB (ChatApp_E2EE_Keys). Communicating clients derive identical 256-bit AES-GCM keys on the fly using ECDH shared secrets. 2. Fresh IV Randomization: Every individual message is encrypted with a cryptographically secure 12-byte initialization vector (crypto.getRandomValues), preventing replay attacks and ciphertext pattern frequency analysis. 3. Targeted Socket.io Rooms: Structured WebSocket connections into isolated private rooms (user_<id>), eliminating broadcast eavesdropping and ensuring messages are relayed strictly to authorized recipient sockets. 4. Delete-For-Everyone Lifecycle: Engineered real-time message revocation events (chatDeleted / chatMessageDeleted) that purge ciphertext from MongoDB while simultaneously commanding recipient DOM instances to unmount the decrypted bubble. 5. Keyboard-Aware Responsive Design: Utilized Tailwind CSS v4 and dynamic viewport units (100dvh) with touch-first single-pane/dual-pane adaptive breakpoints.
System Architecture & Data Flow
Client-Side Cryptographic Pipeline & Socket Routing: [Alice Browser (Next.js 16)] [Bob Browser (Next.js 16)] │ │ 1. Web Crypto API 1. Web Crypto API - ECDH P-256 Keypair - ECDH P-256 Keypair - PrivKey -> IndexedDB - PrivKey -> IndexedDB - PubKey -> Server - PubKey -> Server │ │ 2. Derives AES-GCM-256 2. Derives AES-GCM-256 (AlicePriv + BobPub) (BobPriv + AlicePub) │ │ 3. Encrypts with 12B IV 4. Decrypts with 12B IV │ ▲ ▼ │ [Socket.io Client] [Socket.io Client] │ │ ▼ (Ciphertext + IV) │ (Ciphertext + IV) ┌────────────────────────────────────────────────────────┴─────────┐ │ Express.js & Socket.io Server │ │ - Zero-Knowledge Routing (user_<id> Private Rooms) │ │ - Live Presence Detection (getOnlineUser / getOfflineUser) │ │ - MongoDB Atlas (Persists ONLY Base64 Ciphertext + IV) │ └──────────────────────────────────────────────────────────────────┘
Core Engineering Features
Technical Challenges & Overcoming Them
Results & Impact
- Zero-Knowledge Message Architecture: 0 bytes of plaintext stored in MongoDB or handled by Node.js server memory. - Native Web Crypto Performance: Sub-2ms client-side encryption and decryption latency using browser-accelerated SubtleCrypto. - Sub-50ms Real-Time Delivery: Socket.io targeted room dispatch delivers encrypted packets to active recipients in <50ms. - 100% Mobile Responsiveness: Seamless transition between single-pane mobile contact view and desktop dual-pane messaging with 100dvh keyboard adaptation. - Ephemeral Key Security: Private keys stored in non-exportable IndexedDB domains with zero server exposure.
Key Takeaways
- Native Browser Cryptography: Deepened mastery of Web Crypto API, Diffie-Hellman key exchange protocols (ECDH P-256), and authenticated symmetric ciphers (AES-GCM 256). - WebSockets & Room Architecture: Learned best practices for stateful real-time bidirectional communication, connection recovery, and targeted user room isolation. - IndexedDB Persistence: Managed asynchronous browser-level key storage and retrieval pipelines without compromising UI responsiveness. - Modern Full-Stack Integration: Combined Next.js 16 App Router client components with a decoupled Express Socket.io backend using proxy rewrites and CORS session synchronization.
Future Roadmap
- Double Ratchet Algorithm: Upgrade E2EE to Signal's Double Ratchet protocol for post-compromise security and continuous session key rotation. - Encrypted Media & Voice Notes: Client-side chunked AES-GCM file encryption for photos, videos, and audio voice messages. - Multi-Device Synchronization: Secure cross-device private key import via QR code exchange. - WebRTC Peer-to-Peer Voice & Video Calling: End-to-end encrypted peer audio and video calls.