Replying to Avatar Derek Ross

What is "remote signing" NIP-46 and NIP-55 Nostr key management? #HOWDONOSTR

Across Nostr's ecosystem, where decentralization and user control are paramount, managing private keys securely should be a top priority. There is no central authority to reset your "password" or help you recover your "account" if your private key is leaked. Once leaked, your "account" is essentially burned and you no longer have control.

Remote signing your social transactions with NIP-46 (Nostr Remote Signing) and NIP-55 (Android Signer Application) provides a safer and more convenient way to interact with Nostr applications without exposing your private key.

By entering your private key into multiple applications, you increase the risk of it being compromised. To protect your key, only trust a minimal number of applications and avoid entering it into more apps than absolutely necessary. Proper private key management with remote signing applications can help here.

What are NIP-46 and NIP-55?

NIP-46 (Nostr Remote Signing) and NIP-55 (Android Signer Application) allow you to use a remote signer—a separate tool or device—to approve actions on your behalf. Instead of entering your private key into every app, you authorize trusted applications to sign messages remotely. This lets you create temporary keys that can sign events on your behalf, without exposing your private key. You can limit what these keys can do, such as only allowing them to post notes but not change your profile.

Using the NIP-46 method, a user would login to a Nostr application with a long string similar to this example:

bunker://?relay=&relay=&secret=

Using the NIP-55 method, a user would simply tap or click a 'Login with Amber' or 'Login with Android Signer' button in their Nostr application. All of the heavy lifting and configuration items are handled by the Android signer.

Why use remote signing?

* Better Security – Your private key stays in a secure location, such as Knox, NAK, or Keycast, rather than being exposed in multiple applications.

* More Control – You decide which apps can sign messages and revoke access anytime.

* Seamless Experience – There is no need to copy and paste private keys between apps. It just works in the background.

How can you use it?

The easiest method is Amber for Android. (A new application named nowser recently launched. I have not tested or used this application. However, it supports Android, iOS, Windows, and Linux.)

* Amber: https://github.com/greenart7c3/Amber or download from nostr:npub10r8xl2njyepcw2zwv3a6dyufj4e4ajx86hz6v4ehu4gnpupxxp7stjt2p8!

* nowser: https://github.com/haorendashu/nowser (Remember, I have not used this application. Please use at your own risk!)

If you're more technical and you have a Bitcoin node or a Nostr relay, you may want to consider running either NAK, Knox, or Keycast. These will require a dedicated computer or server.

* NAK (Nostr Army Knife): https://github.com/fiatjaf/nak (This requires almost no setup. You download a simple program and run it with the command 'nak bunker' and keep the terminal window open or run this on a server.)

* Knox: https://gitlab.com/soapbox-pub/knox (nostr:npub1q3sle0kvfsehgsuexttt3ugjd8xdklxfwwkh559wxckmzddywnws6cd26p actually wrote a great article on this nostr:naddr1qvzqqqr4gupzqprpljlvcnpnw3pejvkkhrc3y6wvmd7vjuad0fg2ud3dky66gaxaqqykkmn00qkkyet5vyhjuvda)

* Keycast: https://github.com/erskingardner/keycast (nostr:npub1zuuajd7u3sx8xu92yav9jwxpr839cs0kc3q6t56vd5u9q033xmhsk6c2uc wrote more about Keycast here: nostr:note1327htu9gr327h38yu5f6tueye4cajp3kc69cs3gl7w6q6rz09ufqukl74j)

Examples of Android applications with support:

* Amethyst, Wavlake, Fountain, 0xchat, Coracle, Flotilla, and more!

Examples of iOS applications with support:

...

Examples of Web applications with support:

* Coracle, Nostrudel, Jumble, Snort, Nests, Habla, and more!

Many, many Nostr applications support NIP-46 or NIP-55. However, popular applications such as Damus and Primal do not support these login methods at this time. If your favorite application does not support these login methods, you'll need to ask your app developer and zap them accordingly 😉

Happy remote signing!

maybe you can read about nostr connect and let me know how its different or the same as a bunker. and if i can use my own relay with nostr connect or if it's just the same as a bunker but with a hardcoded relay for nsec.app?

this was what confused me a few days ago i decided to try logging into coop and its only options were nostr connect(QR) or paste nsec..

when i run a bunker with nak, im unsure how this listening string can be entered into an app, when every app is showing me a QR.. shouldnt it be the other way around?

enjoy the confusion 😂

Reply to this note

Please Login to reply.

Discussion

some apps allow you to paste a connection string, some have a qr code to scan, some have both, some have amber.