Your Nostr keys.Your signing decisions.

Sign in to Nostr websites without handing them your private key. Keep your identities in one encrypted browser vault, see what a site is asking for, and choose what gets signed.

Chrome Web Store launch coming soon. Build from source today.

Example data only

A signature starts with your say.

See the request. Make the call.

https://client.exampleA website is asking to publish as you.
First visit
Signing as
Personal identity
Event kind
1 · Short text note
Permission
Always asks for approval
Trying a new Nostr client. Same identity, a different view.
View example event
{
  "kind": 1,
  "content": "Trying a new Nostr client. Same identity, a different view.",
  "tags": [],
  "created_at": 1791374400
}

No extension connection. No real signing.

Local signingKeys stay in the extension
Site-by-site consentYour identity, your permissions
MIT licensedRead it. Build it. Change it.

Your identity goes with you.

Your Nostr identity is a key pair. Ostrilo holds the private key and lets compatible websites request a public key or a signature through your browser.

  1. 01 · Connect

    Choose who sees your identity.

    A website asks for your public key. Ostrilo asks for your consent for that site, even when it has a high trust level. You can refuse.

  2. 02 · Review

    Read what you’re signing.

    Check the requesting site, signing identity, event kind, and content. Text notes, deletions, zap requests, and relay or HTTP authentication always need approval.

  3. 03 · Decide

    Approve it. Or don’t.

    Approved events are signed locally and returned to the website. Your private key stays in the extension. A signature lets the site act as you, so the decision matters.

Room for more than
one side of you.

  • Keep identities separate.

    Create or import keys, give them useful names, and choose your active identity.

  • Make trust a deliberate choice.

    Manage permissions for each site and event kind. Allow selected routine events from a trusted site while protected kinds still ask for approval.

  • See the decisions you’ve made.

    Review signing and public-key disclosure in Activity. Manage your profiles, relays, and security settings in the full options page.

Ostrilo's populated home: two keys, three relays, site permissions, and signed and denied activityOstrilo's populated home in the Deep Ink theme, with identity controls and signing activity
The actual extension, with example identities and real signing activity.

Local by design.
Open to inspection.

Your identity deserves a tool you can understand. Ostrilo keeps private keys in your browser and puts the source, permissions, and signing policy where you can inspect them.

Read the security model

Help shape what comes next.

From everyday signing to broader Nostr support, Ostrilo is growing in the open. Explore what’s built and what we’re working toward.

See the roadmap