Session software icon

Session Windows 1.18.1

Private messaging with account IDs, onion-routed transport, and no phone-number signup.

Download for Windows 1.18.1 · 121.57 MB
Windows updated July 10, 2026
Free · Freeware
20 downloads
Windows size 121.57 MB
5.0

Use the arrow keys to choose a rating, then press Enter or Space to submit it.

Excellent 1 user ratings
Listed in our directory since 2026
Developer: Session Technology Foundation
Source checked August 15, 2026
Page updated August 22, 2026

Overview

Session is an encrypted messenger that creates an alphanumeric Account ID from a key pair generated on the device. It does not ask a central account service to attach that identity to a phone number or email address. The user shares the exact Account ID with another person to begin contact. A display name does not replace that identifier.

Session handles direct messages and groups. It also carries encrypted attachments and can place an expiry instruction on messages. Ordinary messages use the Session network. File transfer and live calls follow other paths, so one transport description does not cover every function.

The Recovery Password restores the Account ID

The Recovery Password is a mnemonic form of the account’s long-term private key. Entering it on another device recreates the same Account ID, which lets existing contacts continue addressing the account. Session has no ordinary username-and-password recovery desk that can replace this secret.

Anyone who obtains the Recovery Password gains the same restoration ability. Losing it removes the documented route for recreating the key-derived identity.

Restoration retrieves only the bounded message window that the network still holds. Contact and group recovery also depends on a configuration message with its own expiry. If none of the user’s devices refreshed that configuration before it expired, the restored Account ID can return without those contacts. The Recovery Password therefore restores the cryptographic account while some earlier local state remains absent.

Onion requests end at a temporary storage swarm

Before Session sends a message, it looks up the storage swarm for the recipient’s Account ID. An onion request wraps the message request in multiple encrypted routing layers and passes it through several nodes. A node in the destination swarm then propagates the encrypted message to the other swarm members.

The swarm stores the message until its time-to-live expires. This allows delivery while the recipient is offline, but it is not permanent server-side history. Ordinary messages use a finite storage period unless the selected disappearing-message setting supplies another expiry.

The current protocol does not have Perfect Forward Secrecy. Session documents the lack of Perfect Forward Secrecy as a current protocol limit. The temporary swarm remains a delivery store rather than a permanent personal archive.

Attachments leave the device only after local encryption

Session encrypts an attachment on the sender’s device and uploads the encrypted object to the Session File Server. The recipient receives a message containing the link and decryption key. The file server receives the encrypted object rather than readable attachment content.

This path differs from ordinary small-message routing. The documentation says the TCP onion-request path is not the current route for large transfers. A successful text message therefore does not prove that a larger attachment will use or complete the same transport.

Calls do not use the message onion route

Voice and video calls use peer-to-peer WebRTC. The call partner and Session-operated STUN or TURN infrastructure can see the caller’s IP address. Both people must enable calls and must already appear in each other’s contact lists. The current call path does not support group calls.

Slow Mode adds another practical limit: Session must remain open in the foreground to receive a call notification. Closing the interface can therefore affect ringing even while stored messages continue to arrive through their separate path.

Disappearing messages cannot revoke an outside copy

A disappearing-message timer instructs participating clients and the swarm to remove their managed copies according to the selected mode. It cannot erase a screenshot or another copy that the conversation partner saved outside Session’s managed message state.

The experimental installation channel has a separate recovery cost. It does not support downgrading that experimental build to an older official build. Reinstalling and restoring after trouble can return the Account ID while messages older than the retrieval window remain unavailable.

Key Features

  • No phone number or email required for signup
  • Session ID contact model
  • Onion-routed decentralized message transport
  • Recovery phrase for account restoration
  • Desktop packages for major operating systems

Strengths and limitations

Strengths
  • Reduces reliance on personal signup identifiers
  • Open-source desktop client
  • Independent official platform binaries
Limitations
  • Long identifiers make contact discovery less convenient
  • Delivery can be slower than centralized services
  • Recovery phrase loss can prevent account restoration

Similar Apps