Community

Apps

nos2x

nos2x is small enough to overlook and important enough to change how you read every Nostr web app. It gives the browser a window.nostr signer, so a site can ask for a signature without taking custody of your private key.

nos2x icon
Apps The product layer Clients, signers, publishing tools, wallets and protocol utilities.
Back to Nostr
Apps

Apps shelf

Apps pages collect clients, signers, tools, developer libraries and product research without turning the app into the whole network.

Apps All Apps pages App routeProduct profiles, categories, tools and source links Browse appsClose shelf

App orientation

App categories

App profiles

0xchatadvanced-nostr-searchAegisAlbyAlby GoAlby HubAlby HubAlby SDKAmberAmberAmethystAmethystApp and product researchApplication-specific dataBlossomBlossom spec NIP-B7BookstrBorisBouquetCalendar by FormstrChachiNostr Apps DirectoryCoracleCoracleCorny ChatCreatrDamusDamusDeveloper stack researchDittoDittodiVineDocstrDTANEmojitoFlotillaFlycatFormstrFountainFreeFromFundstrfutrGIF BuddyGittrgo-nostrGossipGossipGrimoireGroups NIP-29HablaHablaHello Nostr — ResourcesHighlighterHiveTalkhomebrew-nostrHORNET StorageHugo2NostrHyperNoteIrisIrisJumblekanbanstrKeys BandListrLNBits NostrmarketLumeLumilumiLUMINAMapstrMarmot Protocolmatrix-nostr-bridgeMeetstrMemestrMindsmonstrmostardMostronaknak — Nostr Army KnifeNalgorithmNarrnashboardNDKNegentropyngitNofluxNosNos Socialnos2xnosbinnosclNostorg Feature MatrixNostr App ManagerNostr Apps Directory GuideNostr clients feature listNostr Compass — ProjectsNostr Developer GuideNostr Development KitNostr Events MonitorNostr MCP ServerNostr NestsNostr PlaygroundNostr Service ProvidersNostr Writernostr-post-checkernostr-protocol/nostrnostr-rubynostr-sdknostr-sdk-ffinostr-sdk-flutternostr-to-rssnostr-toolsNostr.bandnostr.buildnostr.co.uk ClientsNostr.how — Clientsnostr.hsNostrabilityNostrAppsNostrApps category — AudioNostrApps category — CareerNostrApps category — CommunityNostrApps category — CurationNostrApps category — Direct MessageNostrApps category — DiscoveryNostrApps category — File SharingNostrApps category — Group ChatNostrApps category — MeatspaceNostrApps category — OnboardingNostrApps category — SignersNostrApps category — Toolsnostrchecknostrdbnostrdb-rsNostreeNostreonNostriaNostridNostrium / read.nostr.comNostrmoNostrubenoStrudelnoStrudelNostterNosturNosturNotedeckNpub.proNpub.worldnsec.appnsiteNsiteNstart.meObsidian Nostr WriterOlasOpenvibeOracoloOstrich WorkOwn Your PostsP2P BandPazPeridotPhoenixPlebeian MarketPostizPostr / write.nostr.comPrimalPrimalPrimal Article Editor / Reads authoringPrimal Studiopynostrpython-nostrRecommended Application HandlersRelay Toolsrsslayrust-nostrrust-nostr docsSatelliteSatellite EarthSatlantisSatShootShakespeareShopstrSlidestrSnortSnortStemstrswift-nostr-clientTreasuresWavlakeWavlakeWikifreediaWikistrYakiHonneYakiHonneYakiHonne mobile/web app directoryYondar

App pages

Deep dives

Field guides

Awesome Nostr branches

Research and library

Source inventory

Deep Research: Clients, apps and product surfacesDeep Research: Developer stack and toolingResearch Map: nostrapps.comResearch Source: 0xchatResearch Source: 0xchat — NostrApps pageResearch Source: advanced-nostr-searchResearch Source: Aegis — NostrApps pageResearch Source: AlbyResearch Source: Alby — NostrApps pageResearch Source: Alby GoResearch Source: Alby HubResearch Source: Alby Hub GitHubResearch Source: Alby SDKResearch Source: AmberResearch Source: Amber — NostrApps pageResearch Source: AmethystResearch Source: Amethyst GitHubResearch Source: Awesome Nostr ResourcesResearch Source: BookstrResearch Source: BorisResearch Source: Boris — NostrApps pageResearch Source: BouquetResearch Source: Bouquet — NostrApps pageResearch Source: Calendar by FormstrResearch Source: ChachiResearch Source: Chachi — NostrApps pageResearch Source: CoracleResearch Source: Coracle — NostrApps pageResearch Source: Corny ChatResearch Source: DamusResearch Source: Damus — NostrApps pageResearch Source: DittoResearch Source: Ditto — NostrApps pageResearch Source: DocstrResearch Source: DTANResearch Source: DTAN — NostrApps pageResearch Source: EmojitoResearch Source: Emojito — NostrApps pageResearch Source: Flotilla — NostrApps pageResearch Source: FlycatResearch Source: FormstrResearch Source: Formstr — NostrApps pageResearch Source: FountainResearch Source: FreeFromResearch Source: FreeFrom — NostrApps pageResearch Source: FundstrResearch Source: futrResearch Source: futr — NostrApps pageResearch Source: GIF BuddyResearch Source: GIF Buddy — NostrApps pageResearch Source: GittrResearch Source: go-nostr GitHubResearch Source: GossipResearch Source: Gossip — NostrApps pageResearch Source: GrimoireResearch Source: Grimoire — NostrApps pageResearch Source: HablaResearch Source: Habla — NostrApps pageResearch Source: Hello Nostr — ResourcesResearch Source: HighlighterResearch Source: HiveTalkResearch Source: HORNET Storage — NostrCompassResearch Source: IrisResearch Source: Iris — NostrApps pageResearch Source: JumbleResearch Source: Jumble — NostrApps pageResearch Source: Keys BandResearch Source: Keys Band — NostrApps pageResearch Source: ListrResearch Source: LNBits NostrmarketResearch Source: LumeResearch Source: LumilumiResearch Source: LUMINAResearch Source: MapstrResearch Source: Marmot ProtocolResearch Source: MeetstrResearch Source: MemestrResearch Source: MindsResearch Source: monstr GitHubResearch Source: mostardResearch Source: MostroResearch Source: my.nostr.comResearch Source: nak — Nostr Army KnifeResearch Source: nak GitHubResearch Source: NalgorithmResearch Source: Narr — NostrApps pageResearch Source: nashboardResearch Source: NDK GitHubResearch Source: NDK NPMResearch Source: NegentropyResearch Source: Noflux — NostrApps pageResearch Source: Nos SocialResearch Source: Nos Social — NostrApps pageResearch Source: nos2xResearch Source: nos2x — NostrApps pageResearch Source: nosbinResearch Source: noscl GitHubResearch Source: Nostorg Feature MatrixResearch Source: Nostr App ManagerResearch Source: Nostr Book — KindsResearch Source: Nostr DesignResearch Source: Nostr Developer GuideResearch Source: Nostr NestsResearch Source: Nostr Nests — NostrApps pageResearch Source: Nostr PlaygroundResearch Source: nostr-post-checkerResearch Source: nostr-protocol/nostr GitHubResearch Source: nostr-sdk crates.ioResearch Source: nostr-sdk-ffi GitHubResearch Source: nostr-tools GitHubResearch Source: nostr-tools NPMResearch Source: Nostr.BandResearch Source: nostr.buildResearch Source: nostr.co.uk ClientsResearch Source: Nostr.howResearch Source: Nostr.how — ClientsResearch Source: Nostr.how — ProtocolResearch Source: Nostr.how — What is Nostr?Research Source: Nostr.orgResearch Source: NostrabilityResearch Source: NostrAppsResearch Source: NostrApps category — AudioResearch Source: NostrApps category — CareerResearch Source: NostrApps category — CommunityResearch Source: NostrApps category — CurationResearch Source: NostrApps category — Direct MessageResearch Source: NostrApps category — DiscoveryResearch Source: NostrApps category — File SharingResearch Source: NostrApps category — Group ChatResearch Source: NostrApps category — MeatspaceResearch Source: NostrApps category — OnboardingResearch Source: NostrApps category — SignersResearch Source: NostrApps category — ToolsResearch Source: nostrcheckResearch Source: nostrdb GitHubResearch Source: NostreeResearch Source: Nostree — NostrApps pageResearch Source: NostriaResearch Source: Nostria — NostrApps pageResearch Source: NostridResearch Source: Nostrmo — NostrApps pageResearch Source: Nostrmo GitHubResearch Source: NostrubeResearch Source: noStrudelResearch Source: noStrudel — NostrApps pageResearch Source: NostterResearch Source: NosturResearch Source: Nostur — NostrApps pageResearch Source: NotedeckResearch Source: Npub.proResearch Source: Npub.worldResearch Source: nsec.appResearch Source: NsiteResearch Source: Nstart.meResearch Source: Nstart.me — NostrApps pageResearch Source: Obsidian Nostr Writer — NostrApps pageResearch Source: OlasResearch Source: Olas — NostrApps pageResearch Source: OpenvibeResearch Source: OracoloResearch Source: Oracolo — NostrApps pageResearch Source: Ostrich WorkResearch Source: P2P BandResearch Source: PazResearch Source: PeridotResearch Source: Peridot — NostrApps pageResearch Source: PhoenixResearch Source: Phoenix — NostrApps pageResearch Source: Plebeian MarketResearch Source: Plebeian Market — NostrApps pageResearch Source: PrimalResearch Source: Primal — NostrApps pageResearch Source: Primal Article Editor / Reads authoringResearch Source: Primal StudioResearch Source: pynostr GitHubResearch Source: python-nostr GitHubResearch Source: Registry of KindsResearch Source: Relay Tools — NostrApps pageResearch Source: rsslayResearch Source: rust-nostr docsResearch Source: rust-nostr GitHubResearch Source: SatelliteResearch Source: SatShootResearch Source: ShakespeareResearch Source: Shakespeare — NostrApps pageResearch Source: ShopstrResearch Source: Shopstr — NostrApps pageResearch Source: SlidestrResearch Source: SnortResearch Source: start.nostr.netResearch Source: StemstrResearch Source: TreasuresResearch Source: WavlakeResearch Source: WikifreediaResearch Source: Wikifreedia — NostrApps pageResearch Source: WikistrResearch Source: Wikistr — NostrApps pageResearch Source: YakiHonne mobile/web app directoryResearch Source: YondarResearch Source: Yondar — NostrApps page
Apps16 min readNIP-07 browser signer

nos2x

nos2x is one of the early pieces of Nostr plumbing that made web clients safer to use. It is not a feed, not a wallet, not a social network. It is the little signer sitting between a website and your secret key, asking one hard question every time: should this site be allowed to sign that?

The quick readnos2x is fiatjaf's Chromium Nostr signer extension. It implements NIP-07, exposes window.nostr to web apps, signs events with nostr-tools, supports NIP-04 and NIP-44 encryption methods, stores permissions per host and keeps the private key inside extension storage instead of handing it to every site you visit.

The browser should not own your key

nos2x exists because the early Nostr web had a dangerous temptation: paste your private key into a website, then hope the website behaves. That can work once. It cannot become a sane social protocol. Your Nostr key is not a password you reset when a service leaks it. It is the signing identity behind your notes, follows, profile metadata, deletions, reactions and encrypted conversations. Lose control of it and someone else can speak as you until the rest of the network learns to distrust that key.

The clean idea behind nos2x is brutally simple. Let the web app ask the browser for a Nostr capability, but keep the private key in the extension. The site does not receive your secret. It receives a public key, a signed event or an encrypted/decrypted payload after you have allowed the action. That is why NostrApps calls nos2x the original signer and why the project still matters even now that newer signers exist.

When you use a Nostr web client, the client wants to do something on your behalf. Maybe it wants your public key so it can load your profile. Maybe it wants to sign a note. Maybe it wants to decrypt a direct message. A signer is the person at the door asking whether that request is reasonable. nos2x is not a glamorous door. It is plain, small and direct. But the entire safety model of Nostr web apps depends on doors like this existing.

The project comes from fiatjaf, one of the original names attached to Nostr itself. The public GitHub repository was created in January 2022, lives at fiatjaf/nos2x, is written mostly in JavaScript, and its README describes the tool as a Nostr signer extension. The Chrome Web Store lists it as offered by fiatjaf, version 2.5.2, updated on April 3, 2025, with thousands of users. So the right way to read nos2x is not nostalgia. It is early infrastructure that is still being touched.

What nos2x actually injects

NIP-07 is the center of the story. The standard defines a browser-side window.nostr object. Websites can check whether it exists and call methods on it. The required core is small: get the public key and sign an event. Optional methods cover older NIP-04 encryption and newer NIP-44 encrypted payloads. nos2x implements that shape directly.

The extension injects a provider script into pages. The content script appends nostr-provider.js to the document, listens for messages from that provider and passes requests to the background service worker with the current host attached. The provider then exposes window.nostr.getPublicKey(), window.nostr.signEvent(event), NIP-04 encrypt/decrypt methods and NIP-44 encrypt/decrypt methods. It also has peekPublicKey() and a small nostr-link replacement helper for nostr: links.

The background script is where the sensitive work happens. It reads the private key from browser extension storage, derives the public key with nostr-tools, signs events with finalizeEvent, validates them, and performs NIP-04 or NIP-44 encryption and decryption. For NIP-44 it caches conversation keys in a small LRU cache and clears that cache when the signing key changes. That detail is not flashy, but it tells you the extension is handling the repeated cryptographic work as a living browser tool, not as a static demo.

The manifest tells another part of the story. nos2x is Manifest V3, Chromium-focused, with a background service worker, an options page, a popup, a content script running at document_end across frames, and permissions for storage, active tab and windows. Notifications are optional. The build is bundled with esbuild from source files such as background.js, content-script.js, prompt.jsx and options.jsx. That is useful because it keeps the article honest: this is not magic. It is a browser extension with the normal moving parts of a browser extension.

Permission is the product

The main user interface of a signer is not a feed. It is a permission moment. nos2x opens a prompt when a site asks for a protected operation. The prompt shows the host, explains the requested permission, and, when an event is involved, displays the event data. The buttons are not merely yes and no. You can authorize once, authorize a kind forever, reject once or reject a kind forever. That means nos2x understands that not all signatures carry the same risk.

That matters because Nostr event kinds are behavior. A kind 1 text note is not the same as a metadata update, a deletion, a list, a report or a direct-message payload. A signer that lets you allow only a kind is giving you a practical language for trust. You might trust a web client to ask for read-only public-key access. You might trust it to sign normal notes. You may not want it signing every possible event forever.

The permissions live as per-host policies in extension storage. The common helper checks whether a host already has an allow or deny rule for a permission, and for signing it can match conditions against the event kind. The options page then shows these policies in a table, including the domain, permission, answer, conditions and timestamp, with a revoke flow. This is the part many Nostr users never inspect, and it is exactly the part they should. A signer is only as good as the permissions you let accumulate inside it.

The options page also handles the key. It accepts a private key as nsec or hex, can generate a new key, stores the raw key in extension local storage after validation, and can display a QR code when you reveal it. It also supports an encrypted ncryptsec path through NIP-49 tooling: a password can be used to decrypt an imported encrypted key, and the page can also produce an encrypted display value. That does not remove the need for care. It does show that nos2x is not only a signer prompt; it is a small key and permission console.

The old signer is still live

The phrase "OG signer" can make a project sound frozen in amber. nos2x is older than many apps around it, but it is not dead. The Chrome Web Store page lists version 2.5.2 and an April 2025 update. The GitHub repository shows recent activity, hundreds of stars, dozens of forks and a public issue tracker. The package uses current Nostr libraries such as nostr-tools, plus webextension-polyfill, React for the extension pages and esbuild for the build.

Still, you should read its age with clear eyes. The README says Chromium-only and points Firefox users to nos2x-fox. The provider currently returns an empty object from getRelays(), so when old directory text talks about relay preference storage, do not turn that into a big modern feature claim without testing the current build. The real center of nos2x today is NIP-07 signing, encryption/decryption support, per-host permissions and link handling.

The Chrome Web Store privacy disclosure says the developer states that the extension does not collect or use your data. That is good to see, but with signers you should always think one layer deeper. The most important privacy fact is not a store badge. It is that the code is public, the extension purpose is narrow, and the website never needs the raw private key to request signatures. Store pages can be stale. Source code can be inspected.

There is also a larger historical point. nos2x helped make NIP-07 feel normal. Before Nostr Connect flows, mobile signer apps and polished wallet/signing hybrids became common, the browser signer extension was the obvious bridge between web clients and key custody. It let web Nostr grow without teaching every user the worst possible habit. That is the kind of product contribution that does not always look impressive in screenshots. It changes the default behavior of an ecosystem.

How to read it today

If you are new to Nostr, nos2x teaches one lesson better than any explainer: your private key should not be the login form. Install a signer, let sites request signatures, and make the permission prompt part of your reading. Do not click forever because the site feels familiar. Notice the host. Notice the event kind. Notice whether the request matches the thing you are trying to do.

If you are building a Nostr web app, nos2x gives you the baseline etiquette. Check for window.nostr. Ask for the public key only when you need it. Ask to sign only the event the user is actually trying to publish. Do not hide important event content behind clever UI. Do not ask for broad permission just because it is easier for your code. A signer makes bad permission design visible.

If you already use a newer signer, nos2x is still worth understanding because it is the clean old shape of the idea. Newer tools may add remote signing, mobile approval, Lightning features, account switching, better UI or stronger key-management patterns. But the core remains the same: the app prepares an unsigned event, the signer holds the key, the user approves or refuses, and the signed event can travel through relays.

That is why nos2x deserves a real article rather than a tiny catalog note. It is not just another app tile. It is one of the pieces that helped separate Nostr identity from web-client custody. Once you understand nos2x, a lot of Nostr becomes clearer. You start asking better questions: who has the key, what is being signed, which host gets permission, can I revoke it, and will the signed result still make sense outside this website?

Sources worth opening

This article keeps claims close to the public project trail. Start with these pages when you want to verify the product yourself.

Back to the Crays Nostr page
Apps route visual cue 1
Apps route visual cue 2
Apps route visual cue 3
Apps route visual cue 4
Apps route visual cue 5

How to use this page

Find the product surface first.

Search clients, signers, product categories or developer tools when you need a specific app, source file or comparison clue.

AppsKeep exploring AppsApp routeProduct profiles, categories, signer guides and source links.Browse apps
Apps route visual cue 1
Apps route visual cue 2
Apps route visual cue 3
Apps route visual cue 4
Apps route visual cue 5

Bring something back

Ask, suggest, submit or nominate.

Use these links when something is missing, a source is stale, or a public Nostr builder belongs in the map.