For developers
Let people bring their own signer.
Ostrilo exposes the core NIP-07 browser interface through window.nostr. Your app requests a public key or a signed event, and the extension handles consent and signing.
Two methods. A familiar interface.
Check that a provider and the methods you need are available. Ostrilo makes the provider available to top-level HTTPS pages.
| Method | What your app receives |
|---|---|
getPublicKey() | The active identity’s public key, as hex, after site consent. |
signEvent(event) | The event with id, pubkey, and sig added. |
Request a signature.
This example runs in your app after a user chooses to connect and publish. Handle rejections in your own interface, and let the user decide when to try again.
const signer = window.nostr;
if (!signer?.getPublicKey || !signer?.signEvent) {
throw new Error('Choose a browser signer to continue.');
}
const publicKey = await signer.getPublicKey();
const signedEvent = await signer.signEvent({
kind: 1,
created_at: Math.floor(Date.now() / 1000),
tags: [],
content: 'Hello from my Nostr app.',
});
// Your app decides where to publish signedEvent.Ostrilo returns the signed event to your app. Your app chooses where to publish it. Asking for a signature does not itself publish a note.
A refusal is a normal result.
Your app should handle public-key refusal, denied signing, a locked vault, and rate limits. Avoid repeated requests that turn consent into a stream of prompts.
Check individual capabilities as your app’s needs grow. The RPC reference and provider source are the starting points for integration details. The roadmap tracks additions to protocol support.
Local development also needs HTTPS. Use the repository’s local HTTPS setup to exercise the real extension boundary.
Help make the next version better.
Ostrilo is MIT licensed. Start with the contribution guide, then follow the architecture and development standards. Substantive changes begin with an OpenSpec proposal.
- Architecture primer for the request and signing layers.
- Development standards for implementation and verification.
- Agent loop for driving real signing journeys.
- Issues for bugs, proposals, and useful feedback.
Documentation, accessibility work, and tests for recovery, refusal, and locking are all useful contributions.