Nostr Signers: Log In Without Exposing Your nsec
Once you have a Nostr account, the next question is practical: how do you log in to other websites without giving them your private key?
That is what signers are for.
A signer is an app or browser extension that keeps your private key and signs actions for other apps. The website asks for proof. The signer shows you the request. You approve it. The website receives a signed result, not your secret.
The clean path is simple: the site asks, the signer signs, the nsec stays hidden.
Why signers matter
Nostr apps often need proof that you control your identity. They do not need to see your nsec. They need a signature.
That difference matters. Pasting your nsec into random websites is the fastest way to turn your identity into public property. A signer gives you a cleaner flow: the private key stays in one place, while other apps ask for permission.
For Decaputin, this is the model to keep in mind. Decaputin should receive your public key and signed confirmations. It should not receive your private key.
The main signer paths
| Path | Platform | Best for |
|---|---|---|
| Primal Remote Login | Web, iOS, Android | Users who already started with Primal |
| Amber | Android | Users who want a dedicated Android signer |
| Alby | Desktop browser | Users who want Nostr signing and Lightning tools together |
| nos2x | Desktop browser | Users who want a minimal Nostr browser signer |
| Soapbox Signer | Desktop browser | Users who want another NIP-07 browser signer |
| Android browser extensions | Android only | Advanced users who know why they need extensions on mobile |
You do not need all of them. Choose the setup that matches your device and how much control you want.
Desktop path: browser extensions
On desktop, Decaputin works best with a Nostr browser extension.
These extensions expose a standard browser object called window.nostr. That lets a website ask for your public key or request a signature. The extension shows you the request, you approve it, and the website gets the signed result.
This is the same idea as a wallet popup, but for Nostr identity.
Good options include:
- Alby, if you want Bitcoin, Lightning and Nostr tools together;
- nos2x, if you want a minimal Nostr signer;
- Soapbox Signer, if you want another NIP-07 signer option.
Desktop download links
| Tool | Browser | Link |
|---|---|---|
| Alby Extension | Chrome, Brave, Firefox | getalby.com |
| Alby on Chrome | Chrome / Brave | Chrome Web Store |
| Alby on Firefox | Firefox | Firefox Add-ons |
| nos2x | Chrome / Brave | Chrome Web Store |
| nos2x source | Browser extension | GitHub |
| Soapbox Signer | Chrome / Brave | Chrome Web Store |
| Soapbox Signer for Firefox | Firefox | Firefox Add-ons |
Android path: Amber
On Android, the clean signer-first path is Amber.
Amber is a dedicated Android signer. Its job is to keep your private key in one app so other Android apps and compatible web apps can ask it to sign without touching your nsec directly.
Amber can also be used to create or manage a Nostr identity. This makes it a good choice if you already know that you want the key to live in a dedicated signer rather than inside a social client.
| Tool | Platform | Link |
|---|---|---|
| Amber | Android signer | nostrapps.com/amber |
| Amber on F-Droid | Android signer | F-Droid |
| Amber source | Android signer | GitHub |
Primal Remote Login
If you started with Primal, you may not need to export your nsec immediately.
Primal can help you authorize activity in compatible Nostr apps through Remote Login. The point is similar: another app asks for permission, and Primal helps you approve it without turning every website into a place where you paste your private key.
For beginners, this is one reason Primal is a good first door. You can create the identity, try the social app, use the built-in wallet experience, and later learn more advanced signing setups when you actually need them.
Android browser path: extensions on mobile
There is also a more advanced Android route: using a mobile browser that supports extensions, then installing a Nostr browser signer.
This can make the phone behave more like a desktop browser. In theory, Decaputin asks the browser for your public key or a signature, the extension handles the request, and your private key stays inside the signer.
But this is not the first path I would recommend to a new user.
The historical example is Kiwi Browser, because it supported Chrome extensions on Android. Kiwi is not an iPhone path, and it is not an F-Droid app. The official Kiwi project has also been archived, so it should be treated as a legacy option, not the clean beginner choice.
The more modern direction is Microsoft Edge for Android or Edge Canary, which has been receiving mobile extension support. This may become useful for Nostr browser signers, but mobile extensions can still be less predictable than desktop extensions.
| Situation | Better choice |
|---|---|
| You are new and on iPhone | Primal |
| You are new and on Android | Primal |
| You are on Android and want a dedicated key app | Amber |
| You are on desktop | Alby, nos2x or Soapbox Signer |
| You are advanced and want mobile browser extensions | Edge / Edge Canary, or legacy Kiwi with caution |
For Decaputin, the safe beginner route is still Primal or Amber. Use mobile browser extensions only if you already understand what a signer is and why you want that setup.
What to avoid
Avoid any setup that makes you paste your nsec everywhere.
A Nostr private key is not a normal password. If a site gets it, the site can sign as you. If another app leaks it, the problem follows your identity everywhere.
Common mistakes:
| Mistake | Why it matters |
|---|---|
| Pasting the nsec into random sites | The site can act as you |
| Installing too many signers | You forget where the key lives |
| Using old mobile browsers casually | Browser security matters when keys are involved |
| Creating new keys in every app | You end up with many identities by accident |
| Ignoring the approval popup | You should know what you are signing |
Which signer should you choose?
For most Decaputin users, keep it simple.
| User | Recommended setup |
|---|---|
| New user on iPhone | Primal |
| New user on Android | Primal |
| Android user who wants more control | Amber |
| Desktop user | Alby, nos2x or Soapbox Signer |
| Advanced Android browser user | Edge / Edge Canary, or legacy Kiwi with caution |
The rule is not complicated. Start with the easiest safe path. Move to a dedicated signer only when you understand why you need it.
Before using Decaputin
Before claiming, buying or signing anything on Decaputin, make sure you know where your Nostr identity lives and which app will approve Decaputin requests.
You should know:
- which app or signer holds your private key;
- where to find your npub;
- how to approve a signature request;
- how to approve a Decaputin ownership request after payment;
- why Decaputin should never need your nsec.
Once that is clear, the login popup stops looking strange. It is not asking for a password. It is asking your identity to prove itself.
In a standard claim, the Lightning payment claims the Head for your npub. The signer step publishes the ownership proof on Nostr relays. If that step is interrupted after payment, open My Heads, find the paid Head, and sign ownership from there.