Nostr Private Key Security Guide¶
Understanding Nostr Keys¶
| Key | Format | Purpose |
|---|---|---|
| Private Key | nsec1... (32 bytes, bech32 encoded) |
Signs all your actions — NEVER SHARE |
| Public Key | npub1... |
Your identity — safe to share |
| NIP-05 | user@domain.com |
Human-readable identity verification |
Critical: If someone gets your nsec, they control your identity. There's no password reset in Nostr.
Security Hierarchy (Most → Least Secure)¶
1. Hardware Signers (Best)¶
Air-gapped devices that sign without exposing your key to the internet.
| Device | Platform | Notes |
|---|---|---|
| Nostr Signing Device | DIY (ESP32) | Air-gapped, USB signing |
| Nsec Remote Signer | Dedicated hardware | £39.99, remote signing |
| Trezor/Ledger | Hardware wallets | Limited Nostr support |
| OneKey | Hardware wallet | Full Nostr Signing Device support |
Pros: Key never touches internet, malware can't steal it Cons: Expensive, less convenient, requires physical device
2. Mobile Signers (Recommended for Most Users)¶
Dedicated apps that hold your key and sign requests from other apps.
| App | Platform | How It Works |
|---|---|---|
| Amber | Android | Signs for other Nostr apps via intent system |
| Aegis | iOS | Dedicated signer with remote signing support |
Pros: Convenient, key stays in one app, approve each action Cons: Phone can be lost/stolen
3. Browser Extensions (Good for Desktop)¶
Extensions that sign for web clients without exposing your key to websites.
| Extension | Browser | Features |
|---|---|---|
| Alby | Chrome, Firefox, Brave | Nostr + Lightning wallet |
| nos2x | Chrome, Firefox | Simple Nostr signer |
| Nostore | Chrome, Firefox | Focus on key storage |
| Nostash | Chrome, Firefox, Safari | Open source, encrypted storage, popup signing |
| Keypal / Nostore | Safari | iOS & macOS extension |
| nsec.app | Web-based | Remote signer, syncs devices |
How it works: 1. Install extension 2. Import/create key in extension 3. Websites request signature → Extension prompts you → Key never leaves extension
Pros: Easy to use, works across web clients Cons: Browser vulnerabilities, computer can be compromised
Nostash Deep Dive¶
Modern, open-source browser extension for Nostr key management.
Key Features: - 🔐 Encrypted Storage: Keys encrypted at rest in browser - 🔔 Popup Signing: Approval popup for every signature request - 🌐 Multi-Client: Works with Damus, Iris, Snort, Primal, and other web clients - 📱 Backup: Secure export/import with encrypted backup - 🔓 Open Source: github.com/kind-quest/nostash
Browser Support: | Platform | Support | |----------|---------| | Chrome | ✅ Official | | Firefox | ✅ Official | | Safari | ✅ Official | | Brave | ✅ Compatible |
Setup: 1. Install from Chrome Web Store / Firefox Add-ons / Safari Extensions 2. Create new key or import existing nsec 3. Set encryption password 4. Connect to web clients via NIP-07 (browser extension standard)
Security Notes: - Keys encrypted with user-provided password (AES-256) - Never transmits private keys to websites - Signs locally in extension - No server component, fully local
4. Remote Signers (nsecBunker)¶
Self-hosted signing server for power users.
Setup:
- Run nsecBunker on a server or local machine
- Stores encrypted keys
- Other clients connect via NIP-46 (remote signing)
- Admin UI for key management
Pros: Multi-device access, centralized key management Cons: Technical setup, server must be secured
5. Password Managers (Acceptable Backup)¶
Encrypted storage in password managers.
Recommended: - 1Password (recommended by nostr.how) - Bitwarden (open source) - KeePassXC (offline, open source)
Best Practices:
Entry Type: Secure Note (NOT password field)
Content:
---
Nostr Private Key (NEVER SHARE)
nsec: nsec1...your...key...here
Public Key (safe to share)
npub: npub1...your...key...here
Created: 2025-02-15
Used for: [primary identity]
---
Pros: Encrypted, backed up, cross-device Cons: Clipboard exposure when pasting, not air-gapped
OS-Specific Best Practices¶
macOS¶
| Method | Security Level | Recommendation |
|---|---|---|
| Keychain | Medium | Better than plaintext, but clipboard exposure |
| Browser Extension | Good | Alby or nos2x recommended |
| Hardware Signer | Best | Use Nostr Signing Device or OneKey |
| Password Manager | Good | 1Password, Bitwarden |
macOS Keychain approach:
1. Store nsec in a Secure Note in Keychain Access
2. Or use a password manager
3. Never store in Notes, TextEdit, or desktop files
Warning: macOS clipboard is accessible to apps running in background.
Windows¶
| Method | Security Level | Recommendation |
|---|---|---|
| BitLocker + Password Manager | Good | Encrypt drive, use Bitwarden |
| Hardware Signer | Best | Works well on Windows |
| Browser Extension | Good | Alby or nos2x |
| Windows Credential Manager | Medium | Better than nothing |
Required: - Enable BitLocker (full disk encryption) - Use a password manager (not Credential Manager alone)
Linux¶
| Method | Security Level | Recommendation |
|---|---|---|
| Encrypted Home (LUKS) | Good | Full disk encryption required |
| Hardware Signer | Best | DIY Nostr Signing Device works well |
| Pass (password-store) | Good | GPG-encrypted, CLI-based |
| Browser Extension | Good | Alby or nos2x |
| KeePassXC | Good | Offline, encrypted database |
Linux-specific tools:
- pass - GPG-encrypted password store
- gpg-agent for key caching
- secret-tool (libsecret) for GNOME keyring
Android¶
| Method | Security Level | Recommendation |
|---|---|---|
| Amber | Best | Purpose-built, signs for other apps |
| Hardware Signer | Best | Nsec Remote Signer |
| Password Manager | Good | Bitwarden, Keepass2Android |
Amber (Recommended): 1. Install Amber from F-Droid or Play Store 2. Import your nsec 3. Other Nostr apps (Primal, Amethyst) use Amber to sign 4. Key never leaves Amber
iOS¶
| Method | Security Level | Recommendation |
|---|---|---|
| Aegis | Best | Dedicated signer (remote signing via TestFlight/stable) |
| Safari Extension | Good | Native Nostr signer extension for Safari |
| Built-in (Primal, etc) | Medium | Client apps with integrated key storage |
| Hardware Signer | Best | Works via browser |
| Password Manager | Good | 1Password, Bitwarden |
Key options: - Aegis: Purpose-built iOS signer with remote signing capabilities - Primal: Has built-in key management (no separate signer needed) - Safari Extension (Keypal/Nostore/Nostash): Native browser signing for web clients - Nostash Safari: Encrypted key storage, popup signing for web clients - Keypal: Simple Safari extension for Nostr signing - TestFlight apps: Early access to new signer features
Note: Unlike Android's Amber, iOS apps cannot share keys between each other due to sandboxing. Each app manages its own key storage unless using a signer app like Aegis.
Physical Backup (Always Recommended)¶
Paper Backup (Basic)¶
- Write
nsecon paper - Store in fireproof safe
- Consider metal backup (fireproof)
- Multiple locations
Metal Backup (Best)¶
- Steel plate engraving
- Fireproof, waterproof
- Products: Cryptosteel, Billfodl
Shamir's Secret Sharing (Advanced)¶
- Split key into N parts
- Require M parts to reconstruct
- Example: 3-of-5 shares
- Distribute to trusted contacts/locations
What NEVER To Do¶
| ❌ Bad Practice | Why |
|---|---|
Store nsec in plaintext file |
Malware can read it |
| Save in Notes/TextEdit | Unencrypted |
| Email it to yourself | Email is not secure |
| Message it on Telegram/Discord | Not end-to-end encrypted for storage |
| Paste into multiple web clients | Each client is an attack vector |
| Share with "support" | Nobody needs your nsec — ever |
| Screenshot it | Photos sync to cloud |
| Store in browser localStorage | XSS attacks can steal it |
Security Tiers Summary¶
| Tier | Method | For Who |
|---|---|---|
| 1 (Best) | Hardware signer | High-value accounts, tech-savvy users |
| 2 | Mobile signer (Amber/Aegis) | Most users with phones |
| 3 | Browser extension | Desktop-heavy users |
| 4 | Password manager | Backup + convenience |
| 5 | Physical backup | Everyone (offline insurance) |
Recommended Setup for Most Users¶
┌─────────────────────────────────────────────────────────────┐
│ RECOMMENDED SETUP │
├─────────────────────────────────────────────────────────────┤
│ Primary: Mobile signer (Amber on Android, Aegis on iOS) │
│ Secondary: Browser extension (Alby/Safari) for desktop │
│ Backup: Paper/metal backup in secure location │
│ Digital: Password manager (encrypted secure note) │
├─────────────────────────────────────────────────────────────┤
│ Key rotation: Create backup BEFORE using anywhere │
│ Test: Verify backup works by restoring on another device │
└─────────────────────────────────────────────────────────────┘
Resources¶
- Nostr Signing Device: https://nostrsigningdevice.com/
- Amber (Android): https://github.com/greenart7c3/Amber
- Alby: https://getalby.com/
- nos2x: https://github.com/fiatjaf/nos2x
- nsecBunker: https://github.com/kind-0/nsecbunker
- nsec.app: https://nsec.app/
- Key Management Guide: https://nostr.co.uk/learn/key-management/
- Soapbox Key Guide: https://soapbox.pub/blog/managing-nostr-keys
Last updated: February 19, 2026 Corrections: iOS section updated (Aegis replaces diVine, added Safari extensions, TestFlight note)