# Bitchat Dependencies Guide: Complete Breakdown of Swift Packages and Libraries

> Explore the bitchat dependencies including local Swift packages Arti BitFoundation BitLogger and the swift-secp256k1 cryptographic library for secure communication.

- Repository: [permissionlesstech/bitchat](https://github.com/permissionlesstech/bitchat)
- Tags: how-to-guide
- Published: 2026-08-20

---

**Bitchat relies on four core dependencies managed through Swift Package Manager: three local packages (Arti, BitFoundation, BitLogger) and one remote cryptographic library (swift-secp256k1), plus a pre-compiled Rust binary for Tor networking.**

Bitchat is an open-source iOS and macOS messaging application built entirely with **Swift Package Manager**. Understanding its dependency structure reveals how the project achieves anonymous networking through Tor, cryptographic security, and modular logging. This guide examines every dependency declared in the repository's [`Package.swift`](https://github.com/permissionlesstech/bitchat/blob/main/Package.swift) files with precise file references and usage examples.

---

## Top-Level Dependencies in Package.swift

The root [`Package.swift`](https://github.com/permissionlesstech/bitchat/blob/main/Package.swift) declares four primary dependencies across lines 18–23. These divide into **local path dependencies** (bundled source) and one **remote versioned dependency**.

### Local Packages Under localPackages/

| Package | Location | Purpose |
|---------|----------|---------|
| **Arti** | `localPackages/Arti` | Tor integration via the `Tor` library |
| **BitFoundation** | `localPackages/BitFoundation` | Core utilities and data structures |
| **BitLogger** | `localPackages/BitLogger` | Structured logging throughout the app |

These packages use **path dependencies**, meaning they compile from source within the repository rather than fetching from remote servers.

### Remote Cryptographic Dependency

| Package | Version | Repository |
|---------|---------|------------|
| **swift-secp256k1** | exact 0.21.1 | `https://github.com/21-DOT-DEV/swift-secp256k1` |

This remote package provides the `P256K` module for elliptic-curve cryptography used in key generation and message signing.

---

## Local Package Dependency Graph

Each local package maintains its own [`Package.swift`](https://github.com/permissionlesstech/bitchat/blob/main/Package.swift) with specific relationships:

### BitLogger: Zero-Dependency Foundation

```swift
// localPackages/BitLogger/Package.swift
// Product: BitLogger (library)
// Dependencies: none (pure Swift implementation)

```

BitLogger serves as the logging foundation with no external requirements.

### BitFoundation: Built on BitLogger

```swift
// localPackages/BitFoundation/Package.swift
// Product: BitFoundation (library)
// Dependencies: BitLogger

```

This package extends BitLogger's capabilities with utility functions and shared data structures.

### Arti: Tor Integration with Binary Dependency

```swift
// localPackages/Arti/Package.swift
// Product: Tor (library)
// Dependencies: BitLogger + binaryTarget "arti"

```

The Arti package contains the most complex dependency structure. Lines 40–45 define a **binaryTarget** pointing to `arti.xcframework`—a pre-compiled Rust static library providing the actual Tor protocol implementation.

---

## External Binary Target: arti.xcframework

The `arti.xcframework` represents a compiled Rust codebase packaged for Apple platforms. This binary dependency enables:

- Anonymous networking through the Tor protocol
- Rust-level performance for cryptographic routing
- No Swift compiler overhead for Tor logic

The xcframework ships pre-built, so developers need Rust tooling only if modifying the underlying Arti Rust source separately.

---

## Platform Constraints

All dependencies inherit these minimum versions declared in the root [`Package.swift`](https://github.com/permissionlesstech/bitchat/blob/main/Package.swift):

- **iOS** ≥ 16
- **macOS** ≥ 13

These constraints propagate through every target in the dependency tree, ensuring API compatibility across all packages.

---

## Practical Usage Examples

### Cryptographic Operations with P256K

```swift
import P256K   // from swift-secp256k1 remote package

let privateKey = try P256K.Signing.PrivateKey()
let publicKey = privateKey.publicKey
let signature = try privateKey.signature(for: Data("message".utf8))

```

The `P256K` module wraps secp256k1 operations for Bitchat's cryptographic identity system.

### Structured Logging with BitLogger

```swift
import BitLogger

let logger = Logger(category: "Chat")
logger.info("Chat view appeared")
logger.debug("Message payload: \(payload)")

```

Local package usage requires no version management—changes to `localPackages/BitLogger/` reflect immediately on next build.

### Tor-Enabled Network Requests

```swift
import Tor   // exported by Arti local package

let torSession = TorURLSession()
let url = URL(string: "https://exampleonionaddress.onion")!
torSession.dataTask(with: url) { data, response, error in
    // Handle response routed through Tor network
}.resume()

```

The `Tor` product abstracts the underlying `arti` binary framework and coordinates with `BitLogger` for connection diagnostics.

### Core Utilities from BitFoundation

```swift
import BitFoundation

let uuid = UUIDGenerator.random()
print("Generated identifier: \(uuid)")

```

BitFoundation's dependency on BitLogger ensures consistent logging across all utility operations.

---

## Key Source Files Reference

| File Path | Significance |
|-----------|--------------|
| [`Package.swift`](https://github.com/permissionlesstech/bitchat/blob/main/Package.swift) | Root manifest declaring all four top-level dependencies |
| [`localPackages/BitLogger/Package.swift`](https://github.com/permissionlesstech/bitchat/blob/main/localPackages/BitLogger/Package.swift) | Pure-Swift logging library definition |
| [`localPackages/BitFoundation/Package.swift`](https://github.com/permissionlesstech/bitchat/blob/main/localPackages/BitFoundation/Package.swift) | Utility library with BitLogger dependency |
| [`localPackages/Arti/Package.swift`](https://github.com/permissionlesstech/bitchat/blob/main/localPackages/Arti/Package.swift) | Tor integration including binaryTarget for arti.xcframework |
| [`bitchat/ChatViewModel.swift`](https://github.com/permissionlesstech/bitchat/blob/main/bitchat/ChatViewModel.swift) | Production code demonstrating combined P256K, BitLogger, and Tor usage |

---

## Summary

- **Bitchat dependencies** divide into three local source packages and one remote Swift package
- **Local packages** use path-based references for tight integration and immediate source modification
- **swift-secp256k1** provides exact-versioned cryptographic primitives (0.21.1)
- **arti.xcframework** delivers pre-compiled Tor functionality via Rust binary target
- **Platform requirements** enforce iOS 16+ and macOS 13+ across all targets
- **Dependency hierarchy**: BitLogger ← BitFoundation; BitLogger ← Arti; Arti includes binary target

---

## Frequently Asked Questions

### What package manager does Bitchat use?

Bitchat uses **Swift Package Manager** exclusively. The entire dependency graph—local and remote—declares through [`Package.swift`](https://github.com/permissionlesstech/bitchat/blob/main/Package.swift) manifests with no CocoaPods or Carthage integration found in the repository.

### Why does Bitchat include dependencies as local packages?

Local packages under `localPackages/` enable **source-level modifications** without forking external repositories or waiting for upstream releases. This architecture suits privacy-critical applications where logging, Tor integration, and core utilities require tight control and rapid iteration.

### How is Tor functionality implemented in Bitchat?

The **Arti local package** exports a `Tor` library that wraps a pre-compiled **arti.xcframework**—a Rust static library providing actual Tor protocol implementation. The Swift layer handles API design and logging integration while the binary target manages complex onion routing logic.

### What cryptographic library does Bitchat use for key operations?

Bitchat uses **swift-secp256k1** version 0.21.1, a Swift wrapper around the secp256k1 C library. This provides the `P256K` module for elliptic-curve key generation, signing, and verification operations essential to the messaging protocol's security model.