Overview
Nostr signer. Signs locally, never snoops
Ostrilo holds your Nostr keys and signs events for websites that support window.nostr (NIP-07). Your private keys are encrypted with your master password and stay on this device. Websites receive your public key and signed events, never a private key. There is no server: Ostrilo sends nothing to its developer and has no analytics or telemetry. Every signature traces back to a decision you made, either an approval in the moment or a rule you set for that site. The first time a site asks for your public key, Ostrilo asks you. Each signing request shows the site, the identity it will use, the event kind and the payload before you approve it. Text notes, deletion requests, zap requests, relay authentication and HTTP authentication always prompt, whatever a site's trust level. What it does - Keeps several identities in one vault. Generate a key or import an nsec, name it, pick the active one. - Asks before a site learns your public key, remembers a refusal, and rate-limits sites that keep asking. - Approves or denies each signing request, with per-site trust levels and per-event-kind rules for sites you trust. - Locks after a time you choose and whenever the browser restarts. Deleting a key, raising a site's trust and changing security timeouts ask for your password again. - Encrypts keys at rest with Argon2id and AES-256-GCM. - Keeps an activity log of what each site asked for and what you decided, with export to a local JSON file. - Fetches and publishes your profile through relays you choose. Works in the popup or in Chrome's side panel. - Changes your master password without exporting or re-importing keys. What it does not do yet Ostrilo is version 0.9.0, before 1.0. It implements getPublicKey and signEvent only; getRelays, nip04 and nip44 are absent, so sites that need encrypted direct messages will detect that and decline. It has not had an independent security audit. An encrypted backup file is offered for the first key you create during setup; a key generated inside Ostrilo after setup cannot yet be exported, so import keys you already hold a copy of elsewhere. Start with a test identity while you evaluate it. Permissions storage: the encrypted vault, settings and activity log. windows: the approval window. alarms: the auto-lock timer. idle: whether you are at the computer, used only to decide when to lock. sidePanel: optional side-panel mode. Access to https pages: to offer window.nostr to Nostr websites; the content script reads no page content. Open source under the MIT license. Source, security policy and privacy policy: https://github.com/macro88/ostrilo
0 out of 5No ratings
Details
- Version0.9.0
- UpdatedOctober 9, 2026
- Size1.24MiB
- LanguagesEnglish
- Developer
- TraderThis developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.
- D-U-N-S989162887
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site