* Add voice call API types, protobuf definitions, and build dependencies
Define call method interfaces in Manager, create API records (CallInfo,
CallOffer, TurnServer), and hand-coded protobuf parsers for RingRTC
signaling messages (ConnectionParametersV4, RtpDataMessage).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Implement call signaling state machine and message routing
Add CallSignalingHelper for x25519 key generation and HKDF-based SRTP
key derivation. Add CallManager for tracking active calls, spawning
call tunnel subprocesses, and handling call lifecycle (offer, answer,
ICE candidates, hangup, busy). Wire call message routing in
IncomingMessageHandler and implement Manager call methods in ManagerImpl.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Add call state notification mechanism for JSON-RPC clients
Implement CallEventListener callback pattern that fires on every call
state transition (RINGING_INCOMING, RINGING_OUTGOING, CONNECTING,
CONNECTED, ENDED). The JSON-RPC layer auto-subscribes and pushes
callEvent notifications alongside receive notifications.
Changes:
- Manager.java: Add CallEventListener interface and methods
- ManagerImpl.java: Implement add/removeCallEventListener with cleanup
- DbusManagerImpl.java: Add stub implementation (not supported over DBus)
- JsonCallEvent.java: JSON notification record for call events
- SignalJsonRpcDispatcherHandler.java: Auto-subscribe call event listeners
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Add JSON-RPC commands for voice call control
Add startCall, acceptCall, hangupCall, rejectCall, and listCalls
commands for the JSON-RPC daemon interface. Register commands and
update GraalVM metadata for native image support.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Add call tunnel documentation
Add documentation about the architecture, protocol, and implementation of
signal-call-tunnel, the secure tunnel subprocess for voice calling.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Remove unused integration test tag from lib/build.gradle.kts
The excludeTags("integration") block was added but no tests use the
@Tag("integration") annotation. Revert to upstream's simple
useJUnitPlatform() call.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Derive install dir from jar location instead of nonexistent property
The signal.cli.install.dir system property was never set by the Gradle
start script or anywhere else. Replace it with code source detection:
resolve the jar's parent directory to find the install root, then look
for bin/signal-call-tunnel relative to that.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Remove explicit success responses from hangup and reject commands
Successful commands with no additional information should not return
a response, matching the pattern used by other signal-cli commands
like SendSyncRequestCommand and UpdateConfigurationCommand.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Use instanceof pattern matching for call ID extraction
Replace explicit null check and Number cast with instanceof pattern
matching in AcceptCallCommand, HangupCallCommand, and
RejectCallCommand.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Guard handleIncoming* methods against missing call event listeners
Skip processing incoming call offers when no call event listeners are
registered, since there is nobody to notify about the call. For hangup
and busy, also guard when there are no listeners AND no active call
(the tunnel may still need cleanup if already spawned).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Use Jackson JSON serialization in CallManager
Replace all manual JSON string concatenation with Jackson ObjectNode
construction and ObjectMapper serialization. Use BigInteger for call
IDs to properly represent unsigned 64-bit values in JSON.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Add subscribeCallEvents command for opt-in call event notifications
Call events are no longer subscribed by default. JSON-RPC clients must
explicitly call subscribeCallEvents to receive callEvent notifications
and enable incoming call handling. This avoids sending unwanted call
events to clients that don't use voice calling.
Also adds unsubscribeCallEvents for cleanup, idempotent subscription
guard, and updates CALL_TUNNEL.md to document the subscription step.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Replace Unix socket with stdin/stdout for tunnel communication
Use the tunnel subprocess' stdin for sending control messages and
stdout for receiving control events, instead of a separate Unix
domain socket. This eliminates:
- Temporary directory creation (/tmp/sc-<random>/)
- Socket path and auth token in config JSON
- Connection retry loop (50x at 200ms)
- Auth message handshake
- Socket cleanup on call end
The tunnel's stderr is captured separately for logging. Config JSON
is written as the first line on stdin, followed by control messages.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
signal-cli
signal-cli is a commandline interface for the Signal messenger. It supports registering, verifying, sending and receiving messages. signal-cli uses a patched libsignal-service-java, extracted from the Signal-Android source code. For registering you need a phone number where you can receive SMS or incoming calls.
signal-cli is primarily intended to be used on servers to notify admins of important events. For this use-case, it has a daemon mode with JSON-RPC interface (man page) and D-BUS interface (man page). For the JSON-RPC interface there's also a simple example client, written in Rust.
signal-cli needs to be kept up-to-date to keep up with Signal-Server changes. The official Signal clients expire after three months and then the Signal-Server can make incompatible changes. So signal-cli releases older than three months may not work correctly.
Installation
You can build signal-cli yourself or use the provided binary files, which should work on Linux, macOS and Windows. There's also a docker image and some Linux packages provided by the community.
System requirements:
-
at least Java Runtime Environment (JRE) 25
-
native library: libsignal-client
The native libs are bundled for x86_64 Linux (with recent enough glibc), Windows and MacOS. For other systems/architectures see: Provide native lib for libsignal
Install system-wide on Linux [ JVM build ]
See latest version.
VERSION=$(curl -Ls -o /dev/null -w %{url_effective} https://github.com/AsamK/signal-cli/releases/latest | sed -e 's/^.*\/v//')
curl -L -O https://github.com/AsamK/signal-cli/releases/download/v"${VERSION}"/signal-cli-"${VERSION}".tar.gz
sudo tar xf signal-cli-"${VERSION}".tar.gz -C /opt
sudo ln -sf /opt/signal-cli-"${VERSION}"/bin/signal-cli /usr/local/bin/
Install system-wide on Linux [ GraalVM native build ]
VERSION=$(curl -Ls -o /dev/null -w %{url_effective} https://github.com/AsamK/signal-cli/releases/latest | sed -e 's/^.*\/v//')
curl -L -O https://github.com/AsamK/signal-cli/releases/download/v"${VERSION}"/signal-cli-"${VERSION}"-Linux-native.tar.gz
sudo tar xf signal-cli-"${VERSION}"-Linux-native.tar.gz -C /opt
sudo ln -sf /opt/signal-cli /usr/local/bin/
You can find further instructions on the Wiki:
Usage
For a complete usage overview please read the man page and the wiki.
Important: The ACCOUNT is your phone number in international format and must include the country calling code. Hence it should start with a "+" sign. (See Wikipedia for a list of all country codes.)
-
Register a number (with SMS verification)
signal-cli -a ACCOUNT registerYou can register Signal using a landline number. In this case, you need to follow the procedure below:
-
Attempt a SMS verification process first (
signal-cli -a ACCOUNT register)- You will get an error
400 (InvalidTransportModeException), this is normal
- You will get an error
-
Wait 60 seconds
-
Attempt a voice call verification by adding the
--voiceswitch and wait for the call:signal-cli -a ACCOUNT register --voice
Registering may require solving a CAPTCHA challenge: Registration with captcha
-
-
Verify the number using the code received via SMS or voice, optionally add
--pin PIN_CODEif you've added a pin code to your accountsignal-cli -a ACCOUNT verify CODE -
Send a message
signal-cli -a ACCOUNT send -m "This is a message" RECIPIENT -
Send a message to a username, usernames need to be prefixed with
u:signal-cli -a ACCOUNT send -m "This is a message" u:USERNAME.000 -
Pipe the message content from another process.
uname -a | signal-cli -a ACCOUNT send --message-from-stdin RECIPIENT -
Receive messages
signal-cli -a ACCOUNT receive
Hint: The Signal protocol expects that incoming messages are regularly received (using daemon or receive
command). This is required for the encryption to work efficiently and for getting updates to groups, expiration timer
and other features.
Storage
The password and cryptographic keys are created when registering and stored in the current users home directory:
$XDG_DATA_HOME/signal-cli/data/
$HOME/.local/share/signal-cli/data/
Building
This project uses Gradle for building and maintaining dependencies. If you have a recent gradle
version installed, you can replace ./gradlew with gradle in the following steps.
-
Checkout the source somewhere on your filesystem with
git clone https://github.com/AsamK/signal-cli.git -
Execute Gradle:
./gradlew build2a. Create shell wrapper in build/install/signal-cli/bin:
./gradlew installDist2b. Create tar file in build/distributions:
./gradlew distTar2c. Create a fat tar file in build/libs/signal-cli-fat:
./gradlew fatJar2d. Compile and run signal-cli:
./gradlew run --args="--help"
Building a native binary with GraalVM (EXPERIMENTAL)
It is possible to build a native binary with GraalVM. This is still experimental and will not work in all situations.
-
Execute Gradle:
./gradlew nativeCompileThe binary is available at build/native/nativeCompile/signal-cli
FAQ and Troubleshooting
For frequently asked questions and issues have a look at the wiki.
License
This project uses libsignal-service-java from Open Whisper Systems:
https://github.com/WhisperSystems/libsignal-service-java
Licensed under the GPLv3: http://www.gnu.org/licenses/gpl-3.0.html