Accounts are Nostr-key based only. No email, password, or recovery. If your Nostr key is lost, the account is lost by design.
Desktop login uses NIP-07 when available. Phone login uses NIP-46 pairing via QR/deep-link.
Accounts are created on first successful signer approval and are permanently tied to that Nostr key.
Login is tied to your Nostr key, not your username. Usernames must be unique.
Scan this with your phone signer app (Nostr Connect / NIP-46), or open via deep link.
Open nostrconnect:// linkRecommended: Amethyst
Manual fallback: sign the challenge event outside this page and paste signed JSON.
Your account identity is your Nostr public key. The site verifies signed events and never asks for private keys.
Desktop sign-in uses a NIP-07 extension. Phone sign-in uses Nostr Connect (NIP-46) pairing via QR/deep link.
For full details, visit the official Nostr NIPs repository.
This page explains how login works on this site, in plain language.
P_user).P_user is lost, account access is lost by
design.nsec).You can sign in using:
nostrconnect:// deep link/QR.Recommended signer apps: - Desktop: nos2x-fox - Mobile: Amethyst
Every login requires a server-issued challenge that is:
nsec) into any
form.You can choose:
P_sess/S_sess) in your browser, default 30
days (range 1-90).Delegation is signed by your account key (P_user) and
includes domain + expiry.
During the delegation window, the browser can authenticate with
S_sess without repeated prompts.
If you enable Require direct signer approval for sensitive actions, delegated sessions are not accepted for mutating admin actions, and a direct signer flow is required.
P_user and revokes all active device delegations.