An nsec bunker produces a string right?
I can make a PWA to generate the nsec bunker that you can paste into the apps I guess
There’s no issue logging in with an nsec as long as the code is open source and is a frontend client deployed from the source code and is not talking to any backends (auditable)
But sneaky ppl can be tricksy