Here’s where Ostrilo stands.

The core signer is built. Next come better recovery, deeper protocol support, and more ways to use your identity. This is the readable view of our source roadmap.

Current extension 0.9.0 · Pre-1.0

Reviewed 7 October 2026

Full technical roadmap

Built

The local signer foundation.

Implemented in the current 0.9.0 codebase. The signing, identity, and permission controls at the heart of Ostrilo.

  • Sign in and sign events

    NIP-07 getPublicKey and signEvent, background signing, public-key consent, request validation, and a managed approval queue.

    View source detail
  • Manage multiple identities

    Create and import keys, rename them, switch your active identity, and delete with password re-verification. Private keys are encrypted locally.

    View source detail
  • Control site permissions

    Per-site trust, event-kind rules, session grants, and protected kinds that always require approval. Signing and disclosure decisions appear in Activity.

    View source detail
  • Lock, recover, and manage profiles

    Manual and automatic locking, master-password changes, an encrypted first-key onboarding backup, profile editing, and configurable relays.

    View source detail
  • Check the build and signing journeys

    Coverage gates, security tests, Chromium browser tests, Chrome and Firefox builds, bundle checks, dependency audits, and secret scanning.

    View source detail
Next

Make the foundation dependable.

The next steps in recovery, signing clarity, and verification from the source roadmap.

  • A recovery path for every key

    Backup and export for keys added after onboarding, restore outside onboarding, and clearer import/export options. Make it easier to keep every identity portable.

    View source detail
  • Independent security review

    Review the vault, signing path, and RPC privilege boundary. Publish the findings. A planned milestone on the path to 1.0.

    View source detail
  • Further hardening and verification

    Finish sensitive-input isolation and erasure coverage, meter requests that auto-sign, expand accessibility auditing, and work toward reproducible-build checks.

    View source detail
  • Better approvals and activity

    Parsed event previews and risk information. Improve activity export and filtering, then add search, date ranges, and CSV export.

    View source detail
  • A clearer developer surface

    Consistent page-facing errors, accurate API documentation, formal TypeScript definitions, capability detection, and versioning guidance.

    View source detail
Later

Broader Nostr support, deliberately.

Planned or exploratory work. These are directions, with no promised dates or release numbers.

  • More protocol depth

    NIP-44 encryption, NIP-42 authentication, NIP-57 validation, NIP-65 relay lists, and NIP-05 verification.

    View source detail
  • Portable encrypted keys and remote signing

    NIP-49 ncryptsec import, broader standard export formats, and NIP-46 remote signing are roadmap work.

    View source detail
  • Multi-device and advanced key protection

    Authenticated sync, encrypted device transfer, optional seed recovery, and hardware-backed or biometric options are longer-term directions.

    View source detail

Help with the part you care about.

Useful contributions include recovery testing, accessibility findings, documentation corrections, and tests for refusal and locking. The technical roadmap contains more ideas than this page. Priorities can evolve as people use and contribute to Ostrilo.