Nostr Signers: Log In Without Exposing Your nsec

Nostr Signers: Log In Without Exposing Your nsec

Once you have a Nostr account, the next question is practical: how do you log in to other websites without giving them your private key?

That is what signers are for.

A signer is an app or browser extension that keeps your private key and signs actions for other apps. The website asks for proof. The signer shows you the request. You approve it. The website receives a signed result, not your secret.

The clean path is simple: the site asks, the signer signs, the nsec stays hidden.

Why signers matter

Nostr apps often need proof that you control your identity. They do not need to see your nsec. They need a signature.

That difference matters. Pasting your nsec into random websites is the fastest way to turn your identity into public property. A signer gives you a cleaner flow: the private key stays in one place, while other apps ask for permission.

For Decaputin, this is the model to keep in mind. Decaputin should receive your public key and signed confirmations. It should not receive your private key.

The main signer paths

PathPlatformBest for
Primal Remote LoginWeb, iOS, AndroidUsers who already started with Primal
AmberAndroidUsers who want a dedicated Android signer
AlbyDesktop browserUsers who want Nostr signing and Lightning tools together
nos2xDesktop browserUsers who want a minimal Nostr browser signer
Soapbox SignerDesktop browserUsers who want another NIP-07 browser signer
Android browser extensionsAndroid onlyAdvanced users who know why they need extensions on mobile

You do not need all of them. Choose the setup that matches your device and how much control you want.

Desktop path: browser extensions

On desktop, Decaputin works best with a Nostr browser extension.

These extensions expose a standard browser object called window.nostr. That lets a website ask for your public key or request a signature. The extension shows you the request, you approve it, and the website gets the signed result.

This is the same idea as a wallet popup, but for Nostr identity.

Good options include:

  • Alby, if you want Bitcoin, Lightning and Nostr tools together;
  • nos2x, if you want a minimal Nostr signer;
  • Soapbox Signer, if you want another NIP-07 signer option.
ToolBrowserLink
Alby ExtensionChrome, Brave, Firefoxgetalby.com
Alby on ChromeChrome / BraveChrome Web Store
Alby on FirefoxFirefoxFirefox Add-ons
nos2xChrome / BraveChrome Web Store
nos2x sourceBrowser extensionGitHub
Soapbox SignerChrome / BraveChrome Web Store
Soapbox Signer for FirefoxFirefoxFirefox Add-ons

Android path: Amber

On Android, the clean signer-first path is Amber.

Amber is a dedicated Android signer. Its job is to keep your private key in one app so other Android apps and compatible web apps can ask it to sign without touching your nsec directly.

Amber can also be used to create or manage a Nostr identity. This makes it a good choice if you already know that you want the key to live in a dedicated signer rather than inside a social client.

ToolPlatformLink
AmberAndroid signernostrapps.com/amber
Amber on F-DroidAndroid signerF-Droid
Amber sourceAndroid signerGitHub

Primal Remote Login

If you started with Primal, you may not need to export your nsec immediately.

Primal can help you authorize activity in compatible Nostr apps through Remote Login. The point is similar: another app asks for permission, and Primal helps you approve it without turning every website into a place where you paste your private key.

For beginners, this is one reason Primal is a good first door. You can create the identity, try the social app, use the built-in wallet experience, and later learn more advanced signing setups when you actually need them.

Android browser path: extensions on mobile

There is also a more advanced Android route: using a mobile browser that supports extensions, then installing a Nostr browser signer.

This can make the phone behave more like a desktop browser. In theory, Decaputin asks the browser for your public key or a signature, the extension handles the request, and your private key stays inside the signer.

But this is not the first path I would recommend to a new user.

The historical example is Kiwi Browser, because it supported Chrome extensions on Android. Kiwi is not an iPhone path, and it is not an F-Droid app. The official Kiwi project has also been archived, so it should be treated as a legacy option, not the clean beginner choice.

The more modern direction is Microsoft Edge for Android or Edge Canary, which has been receiving mobile extension support. This may become useful for Nostr browser signers, but mobile extensions can still be less predictable than desktop extensions.

SituationBetter choice
You are new and on iPhonePrimal
You are new and on AndroidPrimal
You are on Android and want a dedicated key appAmber
You are on desktopAlby, nos2x or Soapbox Signer
You are advanced and want mobile browser extensionsEdge / Edge Canary, or legacy Kiwi with caution

For Decaputin, the safe beginner route is still Primal or Amber. Use mobile browser extensions only if you already understand what a signer is and why you want that setup.

What to avoid

Avoid any setup that makes you paste your nsec everywhere.

A Nostr private key is not a normal password. If a site gets it, the site can sign as you. If another app leaks it, the problem follows your identity everywhere.

Common mistakes:

MistakeWhy it matters
Pasting the nsec into random sitesThe site can act as you
Installing too many signersYou forget where the key lives
Using old mobile browsers casuallyBrowser security matters when keys are involved
Creating new keys in every appYou end up with many identities by accident
Ignoring the approval popupYou should know what you are signing

Which signer should you choose?

For most Decaputin users, keep it simple.

UserRecommended setup
New user on iPhonePrimal
New user on AndroidPrimal
Android user who wants more controlAmber
Desktop userAlby, nos2x or Soapbox Signer
Advanced Android browser userEdge / Edge Canary, or legacy Kiwi with caution

The rule is not complicated. Start with the easiest safe path. Move to a dedicated signer only when you understand why you need it.

Before using Decaputin

Before claiming, buying or signing anything on Decaputin, make sure you know where your Nostr identity lives and which app will approve Decaputin requests.

You should know:

  1. which app or signer holds your private key;
  2. where to find your npub;
  3. how to approve a signature request;
  4. how to approve a Decaputin ownership request after payment;
  5. why Decaputin should never need your nsec.

Once that is clear, the login popup stops looking strange. It is not asking for a password. It is asking your identity to prove itself.

In a standard claim, the Lightning payment claims the Head for your npub. The signer step publishes the ownership proof on Nostr relays. If that step is interrupted after payment, open My Heads, find the paid Head, and sign ownership from there.

Next guides

Tags :
Share :

Related Posts

A Beginner’s Guide to the Nostr Protocol

A Beginner’s Guide to the Nostr Protocol

A clear introduction to Nostr: what it is, how it works, where it comes from, which apps to try, and why Decaputin uses an npub as public identity.

read more
How to Create a Nostr Account with Primal

How to Create a Nostr Account with Primal

Create a Nostr account with Primal, find your npub, understand your nsec, back up your keys, and return to Decaputin ready to claim a Head.

read more
How to Pay with Lightning Sats

How to Pay with Lightning Sats

A beginner guide to Lightning payments for Decaputin: what sats are, what a Lightning invoice is, and how to pay a Head claim with Primal, Wallet of Satoshi or Alby.

read more
How to Claim Your First Head

How to Claim Your First Head

Connect your npub, pay the Lightning invoice, sign ownership, and manage your claimed Head from My Heads.

read more