Community

Apps

Keys Band

Keys Band is a Toastr.Space NIP-07 signing extension for Nostr, built to keep nsecs out of web apps while managing multiple keys, site permissions, relays and signing history.

Keys Band icon
Apps The product layer Clients, signers, publishing tools, wallets and protocol utilities.
Back to Nostr
Apps

Apps shelf

Apps pages collect clients, signers, tools, developer libraries and product research without turning the app into the whole network.

Apps All Apps pages App routeProduct profiles, categories, tools and source links Browse appsClose shelf

App orientation

App categories

App profiles

0xchatadvanced-nostr-searchAegisAlbyAlby GoAlby HubAlby HubAlby SDKAmberAmberAmethystAmethystApp and product researchApplication-specific dataBlossomBlossom spec NIP-B7BookstrBorisBouquetCalendar by FormstrChachiNostr Apps DirectoryCoracleCoracleCorny ChatCreatrDamusDamusDeveloper stack researchDittoDittodiVineDocstrDTANEmojitoFlotillaFlycatFormstrFountainFreeFromFundstrfutrGIF BuddyGittrgo-nostrGossipGossipGrimoireGroups NIP-29HablaHablaHello Nostr — ResourcesHighlighterHiveTalkhomebrew-nostrHORNET StorageHugo2NostrHyperNoteIrisIrisJumblekanbanstrKeys BandListrLNBits NostrmarketLumeLumilumiLUMINAMapstrMarmot Protocolmatrix-nostr-bridgeMeetstrMemestrMindsmonstrmostardMostronaknak — Nostr Army KnifeNalgorithmNarrnashboardNDKNegentropyngitNofluxNosNos Socialnos2xnosbinnosclNostorg Feature MatrixNostr App ManagerNostr Apps Directory GuideNostr clients feature listNostr Compass — ProjectsNostr Developer GuideNostr Development KitNostr Events MonitorNostr MCP ServerNostr NestsNostr PlaygroundNostr Service ProvidersNostr Writernostr-post-checkernostr-protocol/nostrnostr-rubynostr-sdknostr-sdk-ffinostr-sdk-flutternostr-to-rssnostr-toolsNostr.bandnostr.buildnostr.co.uk ClientsNostr.how — Clientsnostr.hsNostrabilityNostrAppsNostrApps category — AudioNostrApps category — CareerNostrApps category — CommunityNostrApps category — CurationNostrApps category — Direct MessageNostrApps category — DiscoveryNostrApps category — File SharingNostrApps category — Group ChatNostrApps category — MeatspaceNostrApps category — OnboardingNostrApps category — SignersNostrApps category — Toolsnostrchecknostrdbnostrdb-rsNostreeNostreonNostriaNostridNostrium / read.nostr.comNostrmoNostrubenoStrudelnoStrudelNostterNosturNosturNotedeckNpub.proNpub.worldnsec.appnsiteNsiteNstart.meObsidian Nostr WriterOlasOpenvibeOracoloOstrich WorkOwn Your PostsP2P BandPazPeridotPhoenixPlebeian MarketPostizPostr / write.nostr.comPrimalPrimalPrimal Article Editor / Reads authoringPrimal Studiopynostrpython-nostrRecommended Application HandlersRelay Toolsrsslayrust-nostrrust-nostr docsSatelliteSatellite EarthSatlantisSatShootShakespeareShopstrSlidestrSnortSnortStemstrswift-nostr-clientTreasuresWavlakeWavlakeWikifreediaWikistrYakiHonneYakiHonneYakiHonne mobile/web app directoryYondar

App pages

Deep dives

Field guides

Awesome Nostr branches

Research and library

Source inventory

Deep Research: Clients, apps and product surfacesDeep Research: Developer stack and toolingResearch Map: nostrapps.comResearch Source: 0xchatResearch Source: 0xchat — NostrApps pageResearch Source: advanced-nostr-searchResearch Source: Aegis — NostrApps pageResearch Source: AlbyResearch Source: Alby — NostrApps pageResearch Source: Alby GoResearch Source: Alby HubResearch Source: Alby Hub GitHubResearch Source: Alby SDKResearch Source: AmberResearch Source: Amber — NostrApps pageResearch Source: AmethystResearch Source: Amethyst GitHubResearch Source: Awesome Nostr ResourcesResearch Source: BookstrResearch Source: BorisResearch Source: Boris — NostrApps pageResearch Source: BouquetResearch Source: Bouquet — NostrApps pageResearch Source: Calendar by FormstrResearch Source: ChachiResearch Source: Chachi — NostrApps pageResearch Source: CoracleResearch Source: Coracle — NostrApps pageResearch Source: Corny ChatResearch Source: DamusResearch Source: Damus — NostrApps pageResearch Source: DittoResearch Source: Ditto — NostrApps pageResearch Source: DocstrResearch Source: DTANResearch Source: DTAN — NostrApps pageResearch Source: EmojitoResearch Source: Emojito — NostrApps pageResearch Source: Flotilla — NostrApps pageResearch Source: FlycatResearch Source: FormstrResearch Source: Formstr — NostrApps pageResearch Source: FountainResearch Source: FreeFromResearch Source: FreeFrom — NostrApps pageResearch Source: FundstrResearch Source: futrResearch Source: futr — NostrApps pageResearch Source: GIF BuddyResearch Source: GIF Buddy — NostrApps pageResearch Source: GittrResearch Source: go-nostr GitHubResearch Source: GossipResearch Source: Gossip — NostrApps pageResearch Source: GrimoireResearch Source: Grimoire — NostrApps pageResearch Source: HablaResearch Source: Habla — NostrApps pageResearch Source: Hello Nostr — ResourcesResearch Source: HighlighterResearch Source: HiveTalkResearch Source: HORNET Storage — NostrCompassResearch Source: IrisResearch Source: Iris — NostrApps pageResearch Source: JumbleResearch Source: Jumble — NostrApps pageResearch Source: Keys BandResearch Source: Keys Band — NostrApps pageResearch Source: ListrResearch Source: LNBits NostrmarketResearch Source: LumeResearch Source: LumilumiResearch Source: LUMINAResearch Source: MapstrResearch Source: Marmot ProtocolResearch Source: MeetstrResearch Source: MemestrResearch Source: MindsResearch Source: monstr GitHubResearch Source: mostardResearch Source: MostroResearch Source: my.nostr.comResearch Source: nak — Nostr Army KnifeResearch Source: nak GitHubResearch Source: NalgorithmResearch Source: Narr — NostrApps pageResearch Source: nashboardResearch Source: NDK GitHubResearch Source: NDK NPMResearch Source: NegentropyResearch Source: Noflux — NostrApps pageResearch Source: Nos SocialResearch Source: Nos Social — NostrApps pageResearch Source: nos2xResearch Source: nos2x — NostrApps pageResearch Source: nosbinResearch Source: noscl GitHubResearch Source: Nostorg Feature MatrixResearch Source: Nostr App ManagerResearch Source: Nostr Book — KindsResearch Source: Nostr DesignResearch Source: Nostr Developer GuideResearch Source: Nostr NestsResearch Source: Nostr Nests — NostrApps pageResearch Source: Nostr PlaygroundResearch Source: nostr-post-checkerResearch Source: nostr-protocol/nostr GitHubResearch Source: nostr-sdk crates.ioResearch Source: nostr-sdk-ffi GitHubResearch Source: nostr-tools GitHubResearch Source: nostr-tools NPMResearch Source: Nostr.BandResearch Source: nostr.buildResearch Source: nostr.co.uk ClientsResearch Source: Nostr.howResearch Source: Nostr.how — ClientsResearch Source: Nostr.how — ProtocolResearch Source: Nostr.how — What is Nostr?Research Source: Nostr.orgResearch Source: NostrabilityResearch Source: NostrAppsResearch Source: NostrApps category — AudioResearch Source: NostrApps category — CareerResearch Source: NostrApps category — CommunityResearch Source: NostrApps category — CurationResearch Source: NostrApps category — Direct MessageResearch Source: NostrApps category — DiscoveryResearch Source: NostrApps category — File SharingResearch Source: NostrApps category — Group ChatResearch Source: NostrApps category — MeatspaceResearch Source: NostrApps category — OnboardingResearch Source: NostrApps category — SignersResearch Source: NostrApps category — ToolsResearch Source: nostrcheckResearch Source: nostrdb GitHubResearch Source: NostreeResearch Source: Nostree — NostrApps pageResearch Source: NostriaResearch Source: Nostria — NostrApps pageResearch Source: NostridResearch Source: Nostrmo — NostrApps pageResearch Source: Nostrmo GitHubResearch Source: NostrubeResearch Source: noStrudelResearch Source: noStrudel — NostrApps pageResearch Source: NostterResearch Source: NosturResearch Source: Nostur — NostrApps pageResearch Source: NotedeckResearch Source: Npub.proResearch Source: Npub.worldResearch Source: nsec.appResearch Source: NsiteResearch Source: Nstart.meResearch Source: Nstart.me — NostrApps pageResearch Source: Obsidian Nostr Writer — NostrApps pageResearch Source: OlasResearch Source: Olas — NostrApps pageResearch Source: OpenvibeResearch Source: OracoloResearch Source: Oracolo — NostrApps pageResearch Source: Ostrich WorkResearch Source: P2P BandResearch Source: PazResearch Source: PeridotResearch Source: Peridot — NostrApps pageResearch Source: PhoenixResearch Source: Phoenix — NostrApps pageResearch Source: Plebeian MarketResearch Source: Plebeian Market — NostrApps pageResearch Source: PrimalResearch Source: Primal — NostrApps pageResearch Source: Primal Article Editor / Reads authoringResearch Source: Primal StudioResearch Source: pynostr GitHubResearch Source: python-nostr GitHubResearch Source: Registry of KindsResearch Source: Relay Tools — NostrApps pageResearch Source: rsslayResearch Source: rust-nostr docsResearch Source: rust-nostr GitHubResearch Source: SatelliteResearch Source: SatShootResearch Source: ShakespeareResearch Source: Shakespeare — NostrApps pageResearch Source: ShopstrResearch Source: Shopstr — NostrApps pageResearch Source: SlidestrResearch Source: SnortResearch Source: start.nostr.netResearch Source: StemstrResearch Source: TreasuresResearch Source: WavlakeResearch Source: WikifreediaResearch Source: Wikifreedia — NostrApps pageResearch Source: WikistrResearch Source: Wikistr — NostrApps pageResearch Source: YakiHonne mobile/web app directoryResearch Source: YondarResearch Source: Yondar — NostrApps page
Apps18 min readNIP-07 signer

Keys Band

Keys Band is a Toastr.Space NIP-07 signing extension for Nostr, built to keep nsecs out of web apps while managing multiple keys, site permissions, relays and signing history.

The quick readKeys Band is not a timeline. It is a browser signer: a small extension that gives web apps `window.nostr` access without making you paste your private key into every client you try.

The signer, not the stage

Keys Band sits in the quiet part of the Nostr stack, which is usually the part you should care about most. A feed client can be beautiful, ugly, fast, slow or full of weird design choices. You can switch it. Your private key is different. Lose it and you lose the account. Leak it and someone else can sign as you. That is why signers matter: they separate the app you are using from the secret that proves you are you.

The public site says it plainly: "Safe nsecs" and "Fortify Your Nostr Keys." The Chrome Web Store description is even more direct: Keys.Band lets you sign Nostr events on web apps without giving those apps your keys. The GitHub README calls it a multi-key Nostr signing extension and says it implements NIP-07. That puts Keys Band in the same family of tools as nos2x, Alby-style browser signing and other `window.nostr` extensions. It is not trying to be your social network. It is trying to be the thing your social network asks before it signs.

The project trail is public. The website credits the Toastr.Space team. The repository lives at `toastr-space/keys-band`, uses an MIT license, and is written mainly in TypeScript and Svelte. As of June 6, 2026, GitHub showed the repo created on June 19, 2023, updated on June 6, 2026, last pushed on January 21, 2026, with 38 stars, 9 forks and 6 open issues. The contributor list is led by `ssakone` and `satoshisound`, with additional contributions from Giszmo and dependabot. The Chrome Web Store listing identifies Keys.Band as a social networking extension and discloses that the developer does not collect or use user data.

What NIP-07 does here

NIP-07 is the browser-extension bridge that lets a website talk to a Nostr signer through `window.nostr`. In practical terms, a web client can ask for your public key, ask for an event to be signed, ask for relay information, or ask for encryption and decryption support. The important part is that the website does not need to hold your private key. It sends a request; the extension decides what to do.

Keys Band's README lists the core methods it exposes: `getPublicKey()`, `signEvent(event)`, `getRelays()`, `nip04.encrypt(pubkey, plaintext)` and `nip04.decrypt(pubkey, ciphertext)`. The background code matches that list. For `getPublicKey`, it derives the public key from the selected private key. For `signEvent`, it fills in the pubkey when needed and finishes the event with `nostr-tools`. For `getRelays`, it returns a NIP-07 style map of relay URLs with read and write policies. For NIP-04 encryption and decryption, it calls the matching `nostr-tools` functions.

That sounds technical, but the user experience is simple: a Nostr web app wants to do something with your identity, and Keys Band becomes the gate. The extension injects a provider script into pages when `window.nostr` is not already present. The content script listens for messages from the page and forwards them to the extension runtime. The background side checks permission state, builds a response, records history, and either returns the signed or decrypted result or sends back a rejection.

This is why signers are such a good teaching tool. They reveal the difference between "logging into a website" and "authorizing an app to ask for signatures." A centralized site can create an account for you. Nostr does not work that way. Your key signs events. The signer makes that act visible enough that you can stop giving your nsec to every web page with a shiny compose box.

Permissions are the product

The strongest part of Keys Band is not the icon or the phrase "safe nsecs." It is the permission model. The website highlights fine-grained control for each website, including duration of authorization and scope of access. It also talks about blocking untrusted websites, tracking activity history and managing notifications for events by priority. That is exactly the right framing. A signer is only useful if it gives you a memory of what you allowed.

The source code shows this idea in motion. A site can be allowed or rejected. A permission can be session-length or persistent. The background controller checks whether the current domain is allowed, rejected or still undecided. The code records request history by domain and request type. If the site is not already authorized, the extension can ask the user before returning a public key, signing an event, decrypting a message or exposing relay data.

That history matters because Nostr activity can be deceptively casual. A small web app might only ask for your public key. Another might ask to sign a post. Another might ask to decrypt something. Another might ask again and again until you stop reading the dialog. Keys Band gives you a place to see and manage that relationship. The best security interface is not one giant warning. It is repeated, understandable friction at the moments where a signature changes something.

Multi-key support also changes the way a reader should think. Many Nostr users eventually carry more than one key: a personal key, a test key, a project key, maybe a throwaway key for experiments. Keys Band's website names multi-key management as a main feature, and the code stores profiles rather than assuming one global identity. That is useful because Nostr identity is portable but not always singular. The tool lets you switch context without treating every website as worthy of your main account.

Relays, multiple keys and code

Keys Band also cares about relays. The website says you can manage relays and toggle notifications. NostrApps calls out saved preferred relays. The utility code has default relays such as `wss://nos.lol`, `wss://relay.damus.io` and `wss://nostr.wine`, checks relay availability, avoids repeatedly hammering recently failed relays, and can read a user's kind 10002 relay list. It also builds NIP-07 relay-policy responses where each relay can be read, write or both.

The relay-writing code is worth reading carefully. It creates a kind 10002 relay-list event, signs it with the selected private key and publishes it through the relay pool. There is a small source-level wrinkle: the code constructs a relay tag with read/write access but then pushes the simpler relay URL tag into the array. That may be intentional, old, or simply an implementation detail that changed around it; there is no need to turn that into drama. The larger point is clear: Keys Band is not only a signing button. It also understands that a Nostr identity carries relay preferences.

The build stack is modern and fairly small: Svelte, Vite, TypeScript, Tailwind, Skeleton UI, daisyUI, `nostr-tools`, webextension-polyfill, Vitest, browser storage tests and relay-publish tests. The public site still frames the extension as a Chromium browser tool, and the README says it is Chromium-only. At the same time, the package scripts include `build:firefox`, and the repository contains a Firefox manifest with a Gecko extension ID. That does not mean every user should assume a polished Firefox distribution exists. It does mean the codebase has moved beyond a one-browser-only idea internally.

The extension manifest is also revealing. The Chrome manifest is Manifest V3, uses a background service worker, popup, side panel, storage permission, scripting, tabs and sidePanel access. It injects `content.js` and exposes the `assets/nostr-provider.js` script to pages. Those details are normal for this class of extension, but they should remind you that a signer is powerful. Browser extension permissions are not decorations. They are the reason this tool can stand between websites and your key.

The caution that matters

Keys Band is useful because it lowers one bad habit: pasting an nsec into every Nostr web app. It does not remove the need for judgment. A browser signer still lives in your browser profile. It still depends on extension updates, local device safety, backup habits and your willingness to read permission prompts. If your computer is compromised, if you install a malicious extension, or if you approve every request without looking, a signer cannot rescue you from yourself.

The right way to test Keys Band is boring and serious. Install it from the official route. Check that the extension and repository match. Create or import a low-risk key first. Pair it with one familiar Nostr web app. Watch exactly what the site requests. Look at the history. Change permissions. Try a second app. Confirm that a rejected request stays rejected. Confirm that your preferred relays look the way you expect. Then decide whether it deserves a more important key.

Who is Keys Band for? It is for readers who use Nostr in Chromium-based browsers and want a cleaner signing workflow than raw nsec login. It is for people with multiple keys. It is for users who try many web clients and need a boundary between curiosity and custody. It is also for developers who want to test NIP-07 flows against a compact open-source extension rather than asking users to trust a custom key box inside every app.

Keys Band is a small app with a large responsibility. That is the right way to respect it. It will not make your feed better, write better posts, or teach relays how to behave. It does one quieter thing: it asks websites to request signatures instead of swallowing your private key whole. In Nostr, that distinction is not a detail. It is the line between using open apps and handing your identity to whichever app you opened last.

Sources worth opening

This article keeps claims close to the public project trail. Start with these pages when you want to verify the product yourself.

Back to the Crays Nostr page
Apps route visual cue 1
Apps route visual cue 2
Apps route visual cue 3
Apps route visual cue 4
Apps route visual cue 5

How to use this page

Find the product surface first.

Search clients, signers, product categories or developer tools when you need a specific app, source file or comparison clue.

AppsKeep exploring AppsApp routeProduct profiles, categories, signer guides and source links.Browse apps
Apps route visual cue 1
Apps route visual cue 2
Apps route visual cue 3
Apps route visual cue 4
Apps route visual cue 5

Bring something back

Ask, suggest, submit or nominate.

Use these links when something is missing, a source is stale, or a public Nostr builder belongs in the map.