Library / SDK
BandarLabs/Cobalt avatar
BandarLabs/Cobalt

Cobalt: an app store and Rust SDK for Kobo e-readers

SDK for building apps & an app store for your Kobo eInk reader

372 stars41 forksRustAGPL-3.0

At a glance

What is it?
A platform that puts apps on Kobo e-readers with one USB install, after which a launcher, a store, a Rust SDK, a per-app sandboxed runtime and a desktop simulator do the work. It is deliberately conservative about untested hardware, refuses to touch your existing reader, and ships under AGPL-3.0, which is the part an SDK author should read first.
Who is it for?
Cobalt is worth a look if you own one of the listed Kobo models and want to write or install real apps on it, since the per-app process model and the simulator remove the two things that usually make e-reader development miserable. Three things to check first.
Can I use it commercially?
Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly Rust, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

One install over USB, then everything moves to Wi-Fi

The deployment model is the first thing to understand, and it is unusual for e-reader software. Cobalt itself is installed once over USB, and after that the app lifecycle happens over Wi-Fi: apps install, update and uninstall without a computer in the loop. That inversion is what makes the platform usable rather than a curiosity, because the alternative for most Kobo software is reconnecting the device every time you want to change anything. Two details make the transition less invasive than it sounds. The Kobo's own reader stays as it was, so the stock reading experience is not replaced, and if you already use NickelMenu, Cobalt is added to it and your other entries are kept rather than being overwritten. The launcher, the store, settings and a terminal come as part of Cobalt, and the first launch after installation happens from the Kobo's own menu once the reader has restarted.

Every app runs in its own restricted process

The runtime is the part of the architecture that a developer should care about most, because it decides what an app can do to the device and to its neighbours. Each app runs in its own restricted process rather than sharing one interpreter with everything else, which means a crash in one app is contained and a misbehaving app has a defined surface rather than the whole system. The workspace layout shows how seriously this is taken: alongside the user facing crates for the store, the reader, the shell, the user interface and the streaming layer there are dedicated crates whose names describe failure handling rather than features, including a guard crate that is the natural home for the restriction policy, a doctor crate that reads the state of an installation, a smoke crate for tests, and a trace crate for Wi-Fi diagnostics. There is also a separate host crate for each kind of privileged bridge, which is how frame, music and vault access are kept out of ordinary apps.

Firmware 5.x is out, and untested hardware gets one question

The support statement is specific in a way most hobby projects are not, and it is worth reading before installing. The tested list covers the Kobo Clara BW in both the N365 and the 2025 P365 revisions, Clara Colour, Clara HD, Elipsa 2E, Libra 2, Libra Colour and Libra H2O, each at the firmware version listed in the device support matrix, which lives in the documentation rather than in the readme. The important line is the next one: other Kobos can run it too, but Cobalt lists what has not been tested and asks once before it starts. That is the right behaviour for something that flashes a device, since a silent attempt on unsupported hardware is how readers get bricked, and a single confirmation at least leaves a record of the decision. Kobo firmware 5.x is stated as unsupported outright, and the project is explicit that it is not affiliated with Rakuten Kobo, which matters for anyone thinking about long-term firmware compatibility.

The installer checks every download against a signed manifest

The install path has two entry points, and both are worth understanding before you run either. The easiest is a browser installer that works in Chrome, Edge or Opera: plug the reader in and follow the steps. On macOS or Linux there is a single command:

sh
curl -fsSL https://bandarlabs.github.io/Cobalt/install.sh | sh

The project's answer to the obvious objection, that piping a script from the internet into a shell is how people get owned, is a signed manifest. Everything the script downloads is verified against the signed release manifest before it is used, and there is a documented signed-bootstrap procedure for verifying the install script itself rather than trusting the first fetch. That is the correct layering: the bootstrap is the one artefact you cannot check against something you already have, so the documentation tells you how to check it out of band, and everything after that is checked against the release signature. The same installation document covers updates, recovery, uninstalling and building from source, which is where you should look if the happy path does not work for you.

Three update paths that deliberately do not overlap

Updates are split by what they change, and the split prevents the most common way a platform like this breaks. Cobalt itself updates from Settings on the reader, and that same screen switches between the Stable and Beta channels while keeping your apps and your data. Apps update from Store, which means the store is the only thing that can change an app and it does so on the device's own terms. The kobo command on your computer is the third path, updating the host-side tooling with kobo update or kobo update --channel beta, and it never changes the reader. Keeping the computer-side tool separate from the device-side firmware is what makes it safe to run that command casually. The release tags show the two channels are genuinely used rather than declared and forgotten, with v0.3.23 tagged on 2026-09-24 and a beta of 0.3.24 on 2026-09-25.

The simulator is a workspace member, not a separate tool

Building without hardware is treated as a first-class path, and the way it is wired tells you it is not an afterthought. The simulator is a crate inside the same Cargo workspace as the runtime, the SDK and the apps, so the code you run in the simulator is the code that runs on the reader, compiled from the same sources in the same build. Next to it sits an examples directory containing eighteen separate example applications, including the obligatory hello world and todo, and then reference implementations of the parts that make a device feel like a platform: the launcher, the store, settings, a terminal, a gallery, and readers for feeds, chat, news and OPDS book libraries. There is also a components app whose stated purpose is to show every user interface component on the device in a single reference, which is the sort of artefact that saves a developer from reverse engineering spacing and touch behaviour from a screenshot. Templates and tooling directories sit alongside, and a full set of app sources lives under apps/ in the same workspace.

Four apps you install once and cannot remove

The store is not a completely open field, and the exception list is short enough to state exactly. The launcher, the store, settings and the terminal ship with Cobalt and cannot be removed. Everything else can be installed and removed from Store on the reader, or from an app's page on the website, and the mechanism for the second route is worth noting: you open the install links in Store to pair a phone or computer, and then use the install action on any app page. That is a deliberate design choice against the older pattern where sideloading meant manually copying files over USB, and it also means a removed app is genuinely removed rather than left behind in a directory. The catalogue itself is broad for a device that runs at e-ink refresh rates, covering a command center for asking questions and reading answers with touch navigation, an audiobook studio, backgammon, crossword, flashcards, a daily news brief built in the background, a remote control for your computer, a photo slideshow, a habit tracker with local streaks, and readers for Hacker News, RSS feeds and OPDS libraries.

AGPL-3.0 across a workspace of about forty crates

The licensing is the first thing to settle if you intend to ship an app or a derived runtime, and it is AGPL-3.0. For a platform whose SDK is the product, that is a consequential choice, since copyleft obligations on a library you link into reach further than a permissive license would. The project is otherwise organised like a serious piece of systems work, with a workspace of roughly forty crates under a kobo- prefix, a lock file, a dedicated clippy configuration and a rustfmt configuration, a security policy, a third-party licensing document, a separate licenses and third_party directory, a publishing guide, a roadmap and an SDK document at the top level. The release cadence is fast and the project is not archived, with the last push on 2026-10-01, but the versions are all below one, which under semantic versioning is a standing reminder that the platform interfaces may still move under you.

Editorial conclusion

Cobalt is worth a look if you own one of the listed Kobo models and want to write or install real apps on it, since the per-app process model and the simulator remove the two things that usually make e-reader development miserable. Three things to check first. Firmware 5.x is not supported at all, and the tested list is explicit about which hardware revisions were exercised, so verify your model against the device support matrix before planning anything. The license is AGPL-3.0, which is a real consideration for an SDK because it reaches derived works. And the project asks for confirmation before starting on an untested device rather than pretending support it has not verified. The last push was on 2026-10-01, the newest stable tag is v0.3.23 from 2026-09-24, and a beta tag shipped the following day.

Frequently asked questions

What is Cobalt for Kobo?

It is a set of apps and an SDK for Kobo e-readers, providing a launcher, an app store, a Rust SDK, a runtime that runs each app in its own restricted process, and a simulator for building apps without a device. Cobalt is installed once over USB and the Kobo's own reader is left as it was.

Which Kobo e-readers does Cobalt support?

It is tested on the Clara BW in both the N365 and 2025 P365 revisions, Clara Colour, Clara HD, Elipsa 2E, Libra 2, Libra Colour and Libra H2O, at the firmware versions listed in the device support matrix. Other Kobos can run it, with Cobalt listing what is untested and asking once before starting, but firmware 5.x is not supported.

Do I need a computer to install Cobalt apps after setup?

No. Cobalt itself is installed once over USB, either through a browser installer in Chrome, Edge or Opera or by running the install script on macOS or Linux. After that, apps install, update and uninstall over Wi-Fi from Store on the reader, and the kobo command on your computer only updates the host tooling and never changes the reader.

Can I build Cobalt apps without a Kobo device?

Yes. The simulator is a crate in the same Cargo workspace as the runtime and SDK, so simulator and device builds come from the same sources, and the repository ships eighteen example applications including hello, todo, launcher, store, settings, terminal, gallery and several readers.

What license is Cobalt released under?

AGPL-3.0, which is worth considering carefully if you plan to ship an app or a derived runtime, since a copyleft SDK license reaches further than a permissive one. The repository also carries a security policy, a third-party licensing document and a separate third_party and licenses directory.

Official sources

  1. BandarLabs/Cobalt on GitHub
  2. License: AGPL-3.0
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/bandarlabs-cobalt.svg)](https://hysenlabs.com/projects/bandarlabs-cobalt)