No bullshit, safe, and reliable Nostr signup for normies and hackers



1. Create a profile with Amber.

2. [Settings] β†’ [Backup keys] β†’ enter your encryption password β†’ [Encrypt and copy to clipboard] β†’ paste the ncryptsec to a password manager you trust (like this one) β†’ copy the ncryptsec on paper β†’ ensure you've cleared up your clipboard when you're done.

☠️ Never paste your ncryptsec/nsec to Telegram/WA/ProtonMail/Google Docs/whatever (even to send it as a private message yourself!)β€”that's a fatal mistake, total profile control loss by leaking your private key to a third-party (see "Safety and Responsibility" below).

☠️ Never paste your ncryptsec/nsec to any Nostr Login screen even (same reason, see "Safety and Responsibility").

Safety and Responsibility
Your key = Your data. Someone else's key = someone else's data. Even a server owner can't modify your data, can't read your private messages, can't ban/censor you from the entire Nostr network (in the worst case, they can delete your data or ban you, but only on the server they have control over).

Password β‰  key: password is changeable, key is not. A key is much more powerful: it's full control over your data forever. The point of this step is to safely make several physical backups of your password-protected private key (the ncryptsec, not the unprotected nsec!) to several places: a password manager and on paper.

πŸ”’ the full control means extra responsibility: roughly speaking, you can't undo a compromise of your profile by changing some password, stored on some remote server, because that would mean the server owner authorizes actions with your profile, not you

❌ never ever paste your private key to anything but Amber or a password manager

⚰️ if you've already leaked your private key to something different from Amber or a password manager, that means your profile is probably irreversibly compromised: somebody or something may access it, may read your private messages, may publish posts on your behalf, etc.; don't fuck with it, delete it (login whatever way into Armada β†’ [Settings] β†’ [Delete Account]), and start all over again.

3. Generate a one-time bunker:// URI from Amber with [+] β†’ [Add nsecbunker] β†’ enter name β†’ [Create]. Copy the URI to your Desktop/Laptop whatever preferable way.

Safety
βœ”οΈ it's not perfect, but still acceptable to copy-paste the one-time bunker:// URI over a message to yourself in whatever private messenger (you can reject all Amber requests and revoke the URI if you've accidentally leaked it to somebody malicious).

4. Open this page on Desktop/Laptop β†’ install Bunker46 β†’ click on the extension icon β†’ paste the bunker:// URI copied from Amber β†’ [Connect] β†’ allow and keep allowing whatever needed on both devices β†’ this page.

5. your relay/server lists.

Or select them manually first if you know what you're doing.
Content Relays:

DM Relays:

Marmot Key Package Relays:

Search Relays:

Blossom Servers:

Publish Relay Lists to:


⚠️ Retry the "Publish" button in case of failure. Don't continue if this step hasn't succeeded. Check your phone notifications if something has failed.

6. Use Armada Nostr client (also available as an onion service) for private/group chats:

- use [Log in with Extension] in the Armada browser page
- use [Open signer app] button in the Armada Android app
- use a new bunker:// URI (step 3) in the Armada Desktop/Laptop app
- never paste your nsec1 in the login screens (see step 2).

7. For everything else (but chats!) use YakiHonne or Ditto or Primal or Nostria or noStrudel or whatever Nostr client works for you. Login the same ways (using signer/Amber, extension, or a new bunker:// URI), never with your raw ncryptsec/nsec.

Messengers Privacy
☝️Not all Nostr private chat clients currently support file encryption. Armada supports it, but, for instance, YakiHonne currently doesn't: if you send a file in a private chat using YakiHonneβ€”at least a server owner will have access to your file without any encryption.




For nerds

FAQ
Q: Why not scan the nostrconnect QR generated by Bunker46 (instead of transmitting a bunker:// URI to desktop)?
A: Indeed, that would be both more privacy-friendly and user-friendly. Unfortunately it's currently broken. You might want to check out an Amber-specific Remote NIP-07 browser extension as an alternative to Bunker46 (I didn't test it).

A: iOS?
Q: Currently broken.



For paranoid nerds:

Q: Desktop/Laptop setup only?
A: Only if you know what you are doing. Possible, for instance, with nak bunker, running on a hardened enough OS. I don't recommend storing your nsec/ncryptsec directly in NIP-07 browser extensions (like nos2x) because currently every browser is a critical vulnerabilities honeypot fractal.

Q: I'm scared to carry my private key on my phone, and my mobile client doesn't support bunker:// URI.
A: You can connect Amber to an external bunker (it's slow but works for me) or try FROST (I didn't test it).

Q: Armada/Concord vs White Noise/Marmot vs Cordn?
A: I wish somebody could independently investigate and contribute it here. Don't take my word without verifying it; at least something could be outdated already. In short:

- Armada/Concord is reliable, decentralized, private, and non-secret (it will load all chats from relays and decrypt them after logging in from a new device)

- White Noise is experimental, decentralized, private, and secret (it won't load and decrypt old chats on a new device, because relays don't store chat data after transmission)

- Cordn is reliable, with centralized coordination, private*, secret, and with multi-device sync support.

All of them (even KeyChat, AFAIK) leak metadata (who/whom wrote when, but not what exactly was written) to relay operators (server owners). That's the reason to avoid using your real IP address: use VPN or Tor with all Nostr clients if possible.

Preconfigure relays/servers for your friend
If you want to provide this page to somebody with additional relevant location/invite/WoT/etc.-based preconfigured relays/servers, use hash parameters: content, dm, keypackage, search, blossom, profile, append. Example.



Public domain