Beam
Direct peer-to-peer file transfer between family Macs — powered by iroh.
By downloading, you accept that Beam is provided “as is” without warranty (see disclaimer).
Highlights at a Glance#
Direct P2P over iroh
Zero-Friction Delivery
~/Downloads with a native notification.Native Finder & Menu Bar
Auto-Resume & Queue
End-to-End Encrypted
Zero Accounts, Zero Tracking
beam:// invite links.Why Beam?#
AirDrop is miraculous when you and your recipient are sitting in the same living room. But the moment family members live across town, in another city, or across an ocean, AirDrop is out of the question.
The current alternatives are frustratingly clumsy:
- Cloud Drives (iCloud Drive, Google Drive, Dropbox): Great for long-term document collaboration, terrible for single-shot file sends. You upload the file, wait for synchronization, copy a link, paste it in a message, they download it, and both sides eventually have to clean it up so it doesn’t consume paid cloud storage quotas.
- Chat Apps (iMessage, WhatsApp, Signal): Convenient for small photos, but they aggressively recompress images and videos, choke on multi-gigabyte files, and store your family data on third-party servers.
Beam was built to be AirDrop for the rest of the world: pair once with mom, dad, or your siblings, and sending a batch of vacation photos or a 4K home video is as simple as right-clicking the file in Finder.
How It Works#
1. One-Time Pairing#
Pairing creates a permanent mutual cryptographic relationship between two Macs. In the Beam menu, click Pair with… to generate a single-use invite link:
beam://pair?id=4f8b2c...&secret=9w7xdq...&label=Uwe%27s%20MacThe invite contains the node’s public key and a single-use random pairing secret encoded in z-base-32 (chosen because its alphabet avoids visually confusable characters if read aloud). When the recipient clicks or accepts the link, both nodes exchange identities over an authenticated control stream and store each other in their contact list. Replaying the link or attempting unauthorized connections is immediately rejected.
2. Sending Files#
Sending is integrated directly into macOS:
- From Finder: Right-click any file or folder → Send with Beam ▸ [Contact Name].
- From the Menu Bar: Click the Beam icon in the menu bar extra, select the contact, and choose files via the standard macOS open panel.
If the recipient’s Mac is asleep or offline, Beam automatically enqueues the transfer. As soon as the peer wakes up and announces presence, the queue drains in order.
3. Receiving Without Friction#
Every contact has an Auto-Accept Threshold (25 MB by default, adjustable globally and per-contact):
- Under threshold: The file is accepted automatically and silently saved to
~/Downloads. A native macOS notification appears; clicking it immediately reveals the file in Finder. - Over threshold: An unobtrusive prompt appears displaying the sender’s name, file name, file size, and remaining free disk space.
- Non-contacts: Any offer from an unknown node is declined silently with zero disk writes and nothing displayed.
The iroh P2P Foundation#
Under the hood, Beam is powered by iroh (via iroh-ffi v1.1.0), linking a prebuilt Rust core through Swift bindings:
- QUIC & NAT Hole Punching: Nodes communicate over QUIC (RFC 9000). When two nodes connect, they initially coordinate through an n0 relay, concurrently perform UDP hole punching, and rapidly upgrade to a direct peer-to-peer socket.
- Pipelined Stream Transport: File transfers run over a dedicated ALPN protocol (
beam/blobs/1). To minimize round-trip bottlenecks on transatlantic routes, the sender pipelines continuous writes without per-chunk round-trip framing. - Resumable Partial Transfers: Files are verified by SHA-256 upon completion. If a connection drops mid-transfer, re-initiating the transfer reads the receiver’s partial byte offset and resumes instantly from where it stopped.
- Memory Efficiency: Thanks to streaming I/O, peak RSS remains around ~40 MB regardless of whether you’re sending a 5 MB document or a 20 GB video.
Security Architecture#
- Transport-Authenticated Identities: Node IDs are derived directly from Ed25519 public keys. The remote node ID is authenticated by the QUIC handshake before any application bytes are exchanged.
- Filename Sanitization: All incoming filenames are rigorously sanitized against directory traversal attacks (
../, hidden files, absolute paths, null bytes, and malicious Unicode sequences). - Single-Use Pairing with Rate Limiting: Pairing secrets expire upon first use and pairing requests are rate-limited to 5 attempts per minute per peer ID to thwart brute-force attempts.
- Gatekeeper & Notarization: Built and distributed as a signed, notarized, and stapled Apple disk image (
Beam.dmg), fully compliant with modern macOS Gatekeeper requirements.
Privacy: No Tracking, No Phoning Home#
- Zero Analytics or Telemetry: There are no analytics libraries, tracking pixels, or third-party telemetry SDKs inside Beam.
- Does Not Phone Home: The app never pings a centralized server to announce that it was installed, launched, or used. There are no heartbeat pings, no license checks, and no diagnostic uploads.
- No Accounts or Central Directory: You never create an account, enter an email, or register with a central service. Your cryptographic identity (an Ed25519 keypair) is generated locally on your Mac and never leaves it.
- Direct Peer-to-Peer: Your files, filenames, and transfers travel directly between you and your paired contacts.
- Blind Relays: If hole punching is unable to establish a direct connection and packets fall back through an iroh relay, the relay handles only opaque QUIC TLS 1.3 ciphertext. It has no ability to decrypt file contents, filenames, or transfer metadata.
- Strictly Local Storage: Your contact list, transfer queue, and preferences reside exclusively on your Mac in your local application container. Nothing is uploaded to any cloud.
- Contacts Permission (Display Name Only): On first launch, Beam may prompt for access to your Contacts. This is used solely to read your own card to pre-fill your friendly display name for pairing invites. Your address book is never searched, indexed, or transmitted. You can freely deny this permission — Beam will simply fall back to your Mac’s hostname, and you can manually type any name you like in Settings. Everything functions identically either way.
Technology Stack#
- Language & Toolchain: Swift 6.4 (strict concurrency enabled, actor isolation), Xcode 27
- User Interface: SwiftUI (
MenuBarExtra), AppKit, andFIFinderSync - P2P Core: iroh (
iroh-ffi1.1.0) - Target: macOS 27+ (Apple Silicon)
Download & Installation#
Beam for macOS
macOS 27+ • Apple Silicon • Signed & Notarized
By downloading, installing, or running Beam, you acknowledge and agree to the disclaimer and limitation of liability below.
To install, mount Beam.dmg and drag Beam to your /Applications folder. On first launch, grant the Finder extension permission and allow launch at login so presence stays active.
Disclaimer & Limitation of Liability
By downloading, installing, or using Beam, you expressly agree that this software is provided free of charge on an “as is” and “as available” basis, without warranty, representation, or guarantee of any kind, whether express, implied, statutory, or otherwise, including but not limited to any warranties of merchantability, fitness for a particular purpose, non-infringement, quiet enjoyment, data accuracy, or error-free operation.
The author and contributors shall not be held liable for any direct, indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of data, failed or corrupted file transfers, network disruptions, hardware issues, or other claims arising out of or in connection with the software, its download, installation, performance, or use. You download, install, and use this software entirely at your own risk.