Also @Monal I think I might have found a bug in the way you do OMEMO:2. You're doing prekey via Curve25519/Montgomery + XEdDSA. But the specification requires identity keys are encoded per RFC 8032 (Ed25519) while prekeys are RFC 7748 (X25519). I may be confused, however.