At last year's @BTC Prague #nostr panel, @Alekandar Svetski , @nprofile1q... , @Jordi Llonch Esteve , and @miljan were discussing onboarding and Nostr login, concluding that we are stuck with a brutal tradeoff. We either force newbies to understand remote bunkers (terrible UX) or store raw nsecs directly on a webpage (terrible security).

Today, for #btcprague 2026, I'd like to add another possibility to the discussion: nostr-shard-signer.
One drop-in script tag. One API. Two distinct paths:
🟠 The Purist Path: If the user has @Alby , @AmberApp , or a remote bunker, it acts as a silent proxy for window.nostr.js by @fiatjaf. It gets out of the way and uses pure native Nostr infrastructure.
🟢 The Newbie Path: If they have nothing, it initializes a Web3Auth MPC iframe. They click "Log in with Google," and a sharded nsec is derived seamlessly in an isolated cross-origin context.
⚠️ Warning: The Web2 OAuth flow utilizes an external decentralized MPC validator network to split and secure the key shares. Yes, it uses a shitcoin. But I guess that's still better than losing a newbie, or storing a user's nsec on every random site.
See it live right now in Prague. Go test out the login flow and leave a decentralized review on an OpenStreetMap venue at https://www.worldtrip.guide/osm, or on your favorite place from @BTC Map at https://www.worldtrip.guide/btc.
Developers, grab the alpha code and check out the implementation details here:
🛠️ https://github.com/saintego/nostr-shard-signer
Let's make decentralized identity invisible.
#nostr #bitcoin #btcprague #btcprague2026 #opensource

Today, for #btcprague 2026, I'd like to add another possibility to the discussion: nostr-shard-signer.
One drop-in script tag. One API. Two distinct paths:
🟠 The Purist Path: If the user has @Alby , @AmberApp , or a remote bunker, it acts as a silent proxy for window.nostr.js by @fiatjaf. It gets out of the way and uses pure native Nostr infrastructure.
🟢 The Newbie Path: If they have nothing, it initializes a Web3Auth MPC iframe. They click "Log in with Google," and a sharded nsec is derived seamlessly in an isolated cross-origin context.
⚠️ Warning: The Web2 OAuth flow utilizes an external decentralized MPC validator network to split and secure the key shares. Yes, it uses a shitcoin. But I guess that's still better than losing a newbie, or storing a user's nsec on every random site.
See it live right now in Prague. Go test out the login flow and leave a decentralized review on an OpenStreetMap venue at https://www.worldtrip.guide/osm, or on your favorite place from @BTC Map at https://www.worldtrip.guide/btc.
Developers, grab the alpha code and check out the implementation details here:
🛠️ https://github.com/saintego/nostr-shard-signer
Let's make decentralized identity invisible.
#nostr #bitcoin #btcprague #btcprague2026 #opensource
1